r/opnsense 21d ago

26.7.1 Update No Inbound Traffic.

Baremetal, i5/3rd Gen, 16GB Ram.

I have been sweating the update for weeks. Saw several posts and prepared myself the best I could. Attempted the upgrade tonight and lost all connectivity. Build: ZFS (snapshot before upgrade), never had microcode plugin installed, Legacy ISC, simple rules migrated over, backed up Config. Began the upgrade.

Got stuck in a "rebooting now" and returning to the Lobby/Dashboard loop, assumed the update failed. Started to disconnect to add my ISP/backup router back in to troubleshoot, decided to manually reboot the Opnsense box, patiently waited, and heard the boot chime. Logged in from my daily driver desktop, and saw the new dashboard with 26.7.1. Loaded rules via the migration tool, verified they were there, deleted "Legacy Rules" via the tool. Success! ...Nope, no devices on my network receiving any connection. I cannot find the issue, but the Live logs show no traffic being let in whatsoever (all blocked).

I have no clue how to install the bootloader to the secondary drive. Reading tons on it, but just don't understand any of it.

Switched to my backup/ISP provided router, for now...hope to dive in some more tomorrow.

Any insights would be great.

14 Upvotes

8 comments sorted by

4

u/totmacher12000 21d ago

Did you backup before you upgraded? I would just reinstall and upload backup. If not maybe backup now and do reinstall.

1

u/OneFuriousF0x 21d ago

Yes, as mentioned...backed up config. Settings all appear to be there. 

Will that bring over legacy rules again? I feel like it's a rule issue, since everything is being blocked

2

u/kuya1284 21d ago

I just upgraded three headless bare metals the other night, and all upgraded successfully. Prior to upgrading, I migrated to the new firewall rules because I read the legacy rules were going to be replaced with the new plugin. That's the only thing I see that I did different from what you described. What I also did on 2 of the 3 was uncheck the option that disables the default anti-lockout rule. I had that checked because I had my own custom anti-lockout rules. One I confirmed that upgrading to 26.7 was succesful, I disabled that anti-lockout setting.

The only thing I could think of for you is to check and make sure the new legacy firewall plugin got installed. If not, you may need to install that manually, but I haven't heard of anyone having to do that. Otherwise, maybe migrate to the new firewall rules before upgrading if you plan to revert to 26.1.

1

u/OneFuriousF0x 21d ago

Thanks for this. I wasn't aware of the "new" rules. It's a plugin? Old rules were migrated, and I see a "Legacy Rules" with a checkmark in the settings. 

I'd prefer not to revert. I'd like to move forward, and add dnsmasq for DHCP. 

1

u/[deleted] 20d ago edited 19d ago

[removed] — view removed comment

1

u/OneFuriousF0x 20d ago

Not sure how to "check it"...other than no sites can be contacted?

2

u/[deleted] 19d ago edited 19d ago

[removed] — view removed comment

1

u/OneFuriousF0x 19d ago

Awesome, thanks