Hi,
so the storage medium of the router failed because one of the disks of the RAID1 failed and the other disk was removed while the system was still running. Now it won't boot anymore.
I put in new disks and installed the current OPNsense version and imported the latest configuration I have which is well over a year old. The import was successful but the firewall rules are totally messed up and need to be redone.
And I can't edit the firewall rules. I guess I need to install the plugin for that, but I didn't see it in the list of plugins, and I don't know what it's called.
Is there no way to edit the firewalls rules now?
Because the backup is more than a year old, I would suggest:
Install the same OPNsense version that was running before the disk failure.
Restore the configuration and verify the interface assignments.
Check that all required plugins are installed again.
First check the interfaces, then the firewall rules, and test one change at a time.
Keep the original backup untouched and create a new backup before making any major changes.
This way, you can troubleshoot the problem calmly and avoid making several changes at once.
That's a good idea and I'd have tried that, but I don't have a version that old, only older ones. I looked at the website and didn't see an archive of old versions so I could download a version of the right age. Is there one?
The backup is from August of last year.
PS: Oh I found this: https://pkg.opnsense.org/releases/25.7/
I'll try that tomorrow ...
Does it somewhere say in the config from which version it is? I looked and didn't find that info in the file.
Open OPNsense Download. https://opnsense.org/download/
Scroll down to Full mirror listing.
Choose a mirror.
Open the releases/ folder.
Select the required version, for example 25.7/.
Download the image suitable for your system, usually:
OPNsense-25.7-OpenSSL-dvd-amd64.iso.bz2
For an amd64 system, you can use the dvd or vga image. The serial image is intended for systems using a serial console.
You can also access the release archive directly here:
OPNsense release archive https://pkg.opnsense.org/releases/
--------No, unfortunately the original OPNsense firmware version is usually not stored in config.xml------------
You can only determine the version from external information, such as:
The backup filename or its date.
Old installation media.
System emails, screenshots, or update logs.
The old disk, if it is still readable.
The configuration history stored on the previous installation....
Thanks! I didn't realise that the mirror list also has the old versions.
I'm not sure if the old disk is still readable. One has failed and the other one can't be booted from. It would be great if I could read the current configuration from the disk, but that is very difficult because the file system on it is ZFS.
Is the current configuration even stored on the disk or can it only be gathered and exported by a running instance?
It sucks that we can't automatically store the config on an ftp server or send it by email at least once daily when it has been changed. If that were possible I would have set that up and I'd have the current config now.