Recent posts

#1
26.7 Series / Re: how to recover using an ol...
Last post by (MARLOO) - Today at 04:34:23 AM
I understand your position because I have been in a similar situation before, but the firewall rules are not necessarily lost, and OPNsense has not become obsolete.

In 25.x, firewall rules were managed through the legacy Rules interface.
In 26.1, OPNsense introduced the new MVC/API-based Rules [new] interface. Both systems existed side by side at that point, and migrating the rules was optional.

Before doing anything else, I would first try to recover the current configuration from the old disk using the steps below.

Boot from an OPNsense live/installer USB and select Shell from the console menu.

First, check whether the old disk is detected:

********************************
camcontrol devlist
gpart show
*****************************

Then look for the ZFS pool:

***********
zpool import
*************

If the pool is shown, import it read-only:

**********************************************************
mkdir /mnt2
zpool import -f -o readonly=on -o altroot=/mnt2 -N zroot
*********************************************************

Then locate and mount the root dataset:

******************************************************
zfs list -r zroot
mount -t zfs -o ro zroot/ROOT/default /mnt2
*********************************************

Copy the configuration:

*********************************************************
cp /mnt2/conf/config.xml /tmp/config.xml
***********************************************************

Finally, plug in a FAT32 USB stick and copy the file to it:


*************************************
mount -t msdosfs /dev/da1s1 /mnt
cp /tmp/config.xml /mnt/config.xml
umount /mnt
***************************************

The USB device name may be different, so check it first with gpart show or camcontrol devlist.



---------------------------------------------------If the disk is not readable-----------------------------------------------------------------------------------

First, check whether the disk is detected at all:

******************************
camcontrol devlist
dmesg | tail -50
gpart show
****************************


If the disk is detected but the ZFS pool will not import, try importing it directly from the ZFS partition:

*******************************************************************************
zpool import
zpool import -d /dev/ada0p3 -f -o readonly=on -o altroot=/mnt2 -N zroot
Check the actual device name with gpart show; it may be ada0p3, da0p3, and so on.
*************************************************************************************

You can also inspect the ZFS labels:

*********************************************************
zdb -l /dev/ada0p3
*********************************************************************

If the pool imports read-only, immediately copy the configuration:

************************************************
zfs list -r zroot
mount -t zfs -o ro zroot/ROOT/default /mnt2
cp /mnt2/conf/config.xml /tmp/config.xml
******************************************

Then copy it to a FAT32 USB stick.

------------------------------------------------If the disk or ZFS pool is corrupted---------------------------------------------------------------------

Check the pool status:

**********************************
zpool import
zpool status
************************************

Try a normal read-only import first

******************************************
mkdir /mnt2
zpool import -f -o readonly=on -o altroot=/mnt2 -N zroot
**************************************************************

If that fails, try importing directly from the ZFS partition

***********************************************************
zpool import -d /dev/ada0p3 -f -o readonly=on -o altroot=/mnt2 -N zroot
********************************************************************************
Check the actual partition name with:

*****************
gpart show
*********************

You can also inspect the ZFS metadata

**************************************
zdb -l /dev/ada0p3
***************************************
If the pool imports read-only, immediately copy the configuration

*********************************************
zfs list -r zroot
mount -t zfs -o ro zroot/ROOT/default /mnt2
cp /mnt2/conf/config.xml /tmp/config.xml
***********************************************

Then copy it to a FAT32 USB stick

-----------------------------------------------------------------------------------------------------------------------------------------------------------
                                                                                                                After recovery

Once you have either recovered the current config.xml from the old disk or confirmed that it is no longer readable, I would install OPNsense 25.7 and import the latest backup you have.

Do not update for now. First verify that everything works. If it worked before, it should work again after restoring the configuration.

Check the following:

Interface assignments

Installed plugins

Firewall rules

NAT rules

VPN, DNS, DHCP, and any other services you use

Once the system is stable and the interfaces, plugins, firewall rules, and NAT rules are working as expected, immediately create a new backup:

System → Configuration → Backups → Download configuration

Save it outside the firewall, for example on another PC, NAS, or USB drive.

After that, update gradually and test after each step.



Remember that the firewall rules system changed in 26.x. If you import an old configuration with legacy rules, it is normal that they may appear messed up or not editable in the new interface until you migrate them using Firewall → Rules → Migration assistant.
#2
26.7 Series / Re: how to recover using an ol...
Last post by lmoore - Today at 04:29:11 AM
Quote from: defaultuserfoo on Today at 02:23:16 AMI had only one plugin installed, so I don't expect that any plugin conflicts would need resolving

Referring to page 6, after you powered on the restored system, did you check the 'Status' page and was the 'Resolve plugin conflicts' button there!?
#3
26.7 Series / Re: KEA DHCPv4 serivce down af...
Last post by Lucid1010 - Today at 04:05:30 AM
Not Kea, but nut always fails to start automatically after a reboot. I have to start the service manually. In dmesg, the USB connection is shown as normal during boot.
#4
26.7 Series / Re: how to recover using an ol...
Last post by lmoore - Today at 02:32:11 AM
Quote from: defaultuserfoo on Today at 02:23:16 AMMigrating the rules does not work

Sorry to hear that.

The notes were written and tested using a configuration file from February 2022 and this process was what worked the smoothest.

Migrating the firewall and NAT rules prior to upgrading to 26.7 allows you to edit them in 26.7.
#5
26.7 Series / Re: how to recover using an ol...
Last post by defaultuserfoo - Today at 02:23:16 AM
Quote from: lmoore on Today at 02:10:14 AM
Quote from: defaultuserfoo on Today at 01:58:03 AMWhere is the plugin needed to edit these rules

In the steps I provided, after updating to 26.1.11_10 the next step after verifying the dashboard is to migrate the firewall rules to Rules [new].


It only mentions resolving plugin conflicts.  I had only one plugin installed, so I don't expect that any plugin conflicts would need resolving.  I didn't notice any.

I don't see a plugin mentioned that will make it possible to edit the firewall rules again.  There is no such plugin in the list of plugins that can be installed.  Or what's it called?

Migrating the rules does not work.  And I was told it will be many years before a migration is needed.
#6
26.7 Series / Re: how to recover using an ol...
Last post by defaultuserfoo - Today at 02:18:03 AM
Quote from: lmoore on October 09, 2026, 05:14:00 PMA similar question came up recently, with someone wanting to restore their configuration file from 21.7.8

I've attached notes to restore an old configuration file and get up to date using 25.1.12. Of course, there have been additional updates since the notes were written.

Hope the notes helps you get going relatively smoothly.

The mirrors still include old versions and 25.1 is still listed.

Thanks!  There is nothing anywhere near smoothly about this.

What's the point of installing an old version of OPNsense to import an old configuration when it can't be upgraded to the current version?  There is no difference between installing the current version and importing the old configuration and installing an old version and importing the old configuration because the result is the same: All the firewall rules are messed up and can't be edited.  They can't be deleted either.
#7
26.7 Series / KEA DHCPv4 serivce down after ...
Last post by Vincent Chen - Today at 02:13:30 AM
Hi all,

After recent release update including 26.7.5, 26.7.6, several services including KEA DHCPv4 are down after update reboot.
It require another reboot to start those services. Does anyone have similar experience?


Thanks,

#8
26.7 Series / Re: how to recover using an ol...
Last post by lmoore - Today at 02:10:14 AM
Quote from: defaultuserfoo on Today at 01:58:03 AMWhere is the plugin needed to edit these rules

In the steps I provided, after updating to 26.1.11_10 the next step after verifying the dashboard is to migrate the firewall rules to Rules [new].
#9
26.7 Series / Re: how to recover using an ol...
Last post by defaultuserfoo - Today at 02:05:47 AM
Quote from: (MARLOO) on October 09, 2026, 02:51:21 PM
Quote from: defaultuserfoo on October 09, 2026, 05:21:05 AMIs the current configuration even stored on the disk or can it only be gathered and exported by a running instance?

It sucks that we can't automatically store the config on an ftp server or send it by email at least once daily when it has been changed.  If that were possible I would have set that up and I'd have the current config now.



------------------------------------------------------------------------------------------------------------------------------------------------------------
Yes — the current OPNsense configuration is stored on the disk, in:

/conf/config.xml

On a default ZFS install, it is usually:

/zroot/ROOT/default/conf/config.xml

You do not need a running OPNsense instance to export it. You can read it from the disk with a live OPNsense USB.


Thanks, I could try that.  It's possible that the disk has become unreadable, though.

But since I can't update to the current version without loosing all firewall rules I'm already screwed and it doesn't really matter.

There is no option to make backups with sftp.  I always had to make manual backups.
#10
26.7 Series / Re: how to recover using an ol...
Last post by defaultuserfoo - Today at 01:58:03 AM
This is not working :(((((((((  I started with 25.1, updated so I could install a needed plugin, imported the configuration and then wasted many hours updating OPNsense to get it up to date.  At some point before I'm even finished, I'm again left with totally messed up firewall rules which I can't even edit :(((((((((((((((((((((((((((((((((((((((((((((((((((((((

Where is the plugin needed to edit these rules?  This totally sucks and is unacceptable.  Apparently at some point we can't update anymore without redoing all firewall rules from scratch.  That makes OPNsense obsolete.  Or what is your solution for that?

I've said before that this has been handled badly.  Now it turns out this is far beyond only 'badly'.