Hi,
I'm fairly new to OPNsense and would appreciate some advice regarding an upgrade plan.
I'm currently running 25.1.7 and am considering doing a clean install of 26.1.1 and restoring my configuration backup, instead of performing incremental upgrades (25.1.7 - 25.1.12 - 25.7 - 25.7.11 - 26.1.1).
This firewall is in production, so maintenance windows are limited. An incremental upgrade path would likely take 7+ hours, not including potential troubleshooting.
Our setup is relatively simple:
2 VLANs (IPv4)
1 WireGuard tunnel (multiple peers)
Unbound DNS
ISC DHCPv4
Zabbix agent
IDS
Since ISC DHCP is no longer supported in 26.1, I have already configured Kea DHCP to match the current ISC configuration. It is not enabled yet, but I plan to test it thoroughly before saving the final configuration backup.
My question is: would you advise against doing a clean 26.1.1 install and restoring the config? If so, what are the main risks, and what alternative approach would you recommend?
If this plan is reasonable, are there specific areas (services, plugins, config sections, etc.) that I should pay particular attention to after the restore?
Thanks in advance!
I'm fairly new to OPNsense and would appreciate some advice regarding an upgrade plan.
I'm currently running 25.1.7 and am considering doing a clean install of 26.1.1 and restoring my configuration backup, instead of performing incremental upgrades (25.1.7 - 25.1.12 - 25.7 - 25.7.11 - 26.1.1).
This firewall is in production, so maintenance windows are limited. An incremental upgrade path would likely take 7+ hours, not including potential troubleshooting.
Our setup is relatively simple:
2 VLANs (IPv4)
1 WireGuard tunnel (multiple peers)
Unbound DNS
ISC DHCPv4
Zabbix agent
IDS
Since ISC DHCP is no longer supported in 26.1, I have already configured Kea DHCP to match the current ISC configuration. It is not enabled yet, but I plan to test it thoroughly before saving the final configuration backup.
My question is: would you advise against doing a clean 26.1.1 install and restoring the config? If so, what are the main risks, and what alternative approach would you recommend?
If this plan is reasonable, are there specific areas (services, plugins, config sections, etc.) that I should pay particular attention to after the restore?
Thanks in advance!
"