Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login
    Introducing Netgate Nexus: Multi-Instance Management at Your Fingertips.

    New pfSense UI Questions...

    Scheduled Pinned Locked Moved Netgate Nexus
    11 Posts 5 Posters 810 Views 9 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • keyserK Offline
      keyser Rebel Alliance
      last edited by

      I just noticed the new pfSense UI has been launched - or rather revealed, as it is also available in a limited form (no packages UI support) in 26.03.1.

      https://www.netgate.com/blog/the-new-gui-for-pfsense-plus

      Seems 26.07 will bring UI support for packages as well, but I assume that requires all packages maintainers to rewrite their packages which could be both delayed and cause missing/dead packages if a current maintainer is not ready to work on it?

      https://forum.netgate.com/topic/201056/netgate-nexus-gui-missing-haproxy-management

      A few other questions arise quickly:

      1: Will the new UI be default in 26.07 even though the old one will still be there?

      2: Does the new UI support configuration of everything the old does (fx. HA)?

      3: My read is Threatgate replaces pfBlockerNG, which I assume means no pfBlockerNG package for 26.07? Does threat gate adopt/migrate current pfBlockerNG configuration, or is that "start from scratch"?

      Love the no fuss of using the official appliances :-)

      1 Reply Last reply Reply Quote 1
      • stephenw10S Offline
        stephenw10 Netgate Administrator
        last edited by

        It's not default in 26.07.

        It doesn't yet support every option that can be set in the PHP GUI. Like packages as you say.

        Threatgate doesn't import settings from pfBlocker. At least not currently. I'm not sure if that was ever considered because it's different in some fundamental ways. I imagine it would be non-trival!

        keyserK 1 Reply Last reply Reply Quote 1
        • keyserK Offline
          keyser Rebel Alliance @stephenw10
          last edited by keyser

          @stephenw10 Okay, but is pfBlockerNG gone in 26.07, or are they so fundementally different they can co-exist, and it will be the administrators task to decide when to “mimick” the configuration in pfBlockerNG and remove that package?

          I think it would be wise to post some more details on what your roadmap for the migration and deprecation of the old UI including packages is - a little before release of 26.07 so the word “spreads”, instead of mistakes are made by people pressing upgrade at the first chance they have.

          Love the no fuss of using the official appliances :-)

          Bob.DigB 1 Reply Last reply Reply Quote 0
          • Bob.DigB Offline
            Bob.Dig LAYER 8 @keyser
            last edited by Bob.Dig

            Looks like Win11 to me... nobody asked for it. Lets hope, Netgate is not in a hurry to move over.

            1 Reply Last reply Reply Quote 3
            • stephenw10S Offline
              stephenw10 Netgate Administrator
              last edited by

              Hmm, good question. They work differently. pfBlocker via Unbound for example and Threatgate via CoreDNS. I don't think I've tried but you probably could run both. For DNS filtering it would depend which service clients were looking at. I'll try and test it....

              keyserK 1 Reply Last reply Reply Quote 0
              • keyserK Offline
                keyser Rebel Alliance @stephenw10
                last edited by

                @stephenw10 Oookay… So CoreDNS is a third DNS service for pfSense - apart from Resolver and forwarder?
                I really hope there is a higher plan here, because that sounds like something that will take ages to mature enough to fullfill the roles unbound has in current pfSense.

                Love the no fuss of using the official appliances :-)

                GertjanG keyserK 2 Replies Last reply Reply Quote 0
                • GertjanG Offline
                  Gertjan @keyser
                  last edited by

                  @keyser said in New pfSense UI Questions...:

                  So CoreDNS is a third DNS service for pfSense - apart from Resolver and forwarder?

                  And thus somewhat mutual exclusive ?

                  No "help me" PM's please. Use the forum, the community will thank you.

                  1 Reply Last reply Reply Quote 0
                  • stephenw10S Offline
                    stephenw10 Netgate Administrator
                    last edited by

                    Usually they would be but it's possible to run both as long as they don't try to listen on the same IP/ports.

                    1 Reply Last reply Reply Quote 0
                    • keyserK Offline
                      keyser Rebel Alliance @keyser
                      last edited by

                      said in New pfSense UI Questions...:

                      @stephenw10 Oookay… So CoreDNS is a third DNS service for pfSense - apart from Resolver and forwarder?
                      I really hope there is a higher plan here, because that sounds like something that will take ages to mature enough to fullfill the roles unbound has in current pfSense.

                      Okay the idea behind ThreatGate and coreDNS is not a bad one. I have been reading up on the documentation released so far, and it certain does provide some new options that could be handy if they really "just work".

                      https://docs.netgate.com/pfsense/en/latest/nexus/threatgate/index.html#threatgate

                      With Snort 3 being built in as well, this may move the IDS/IPS part of pfSense up a great deal on the "ease of use" scale and make it more competitive vs. other established vendors. Still we need the MIM manager to get a GUI to actually manage settings on many boxes at once. Right now its just at centralised UI collection where you can click on each box in turn - or use API entirely outside the UI.

                      Love the no fuss of using the official appliances :-)

                      1 Reply Last reply Reply Quote 0
                      • stephenw10S Offline
                        stephenw10 Netgate Administrator
                        last edited by

                        Yup more orchestration options are coming. Upgrading multiple boxes at the same time has become an invaluable feature for me. But I do upgrade a lot!

                        1 Reply Last reply Reply Quote 1
                        • M marcosm moved this topic from General pfSense Questions on
                        • B Offline
                          balb
                          last edited by

                          First impressions of the new GUI after a couple of hours of 'looking around': less than a pass.

                          I will be interested to see when the entries for packages in the pull-down menus. I use Traffic Totals quite a lot and would be quite disappointed if not included.

                          As for the pull down menus, I find that having to scroll in the menu quite annoying.
                          Developers: how about tightening the spacing to scrolling is NOT needed.

                          1 Reply Last reply Reply Quote 1
                          • First post
                            Last post
                          Copyright 2026 Rubicon Communications LLC (Netgate). All rights reserved.
                          Privacy Policy · Cookie Policy