Upgradethread 23.1.11_1 to 23.7

Started by seed, July 31, 2023, 03:07:59 PM

Previous topic - Next topic
Quote from: mimugmail on August 09, 2023, 08:17:21 AM
Quote from: bobbysmithers on August 09, 2023, 02:39:33 AM
Quote from: bobbysmithers on August 01, 2023, 01:32:51 AM
This update kills all my WireGuard tunnels on startup.
I have to disable and re-enable my WireGuard gateways every time I reboot to get them working again.
Any ideas on a fix or is this a new bug?
Previous version 23.1.11 worked perfectly.

Edit:
So, I can get everything working again just by disabling the WireGuard plugin for a few seconds and re-enabling it.
Did the startup order just change and WireGuard starts too quickly now before it can make a connection?
Is there a way to delay WireGuard from starting by like 10-15 seconds? I think that may fix it.

WireGuard is still broken for me after the 23.7.1 update. Everything else is fine, but all the WireGuard tunnels are down when OPNSense first starts up. I need to disable the WG plugin and re-enable it for the tunnels to reconnect and start working again. It's a minor inconvenience, but it would be nice if this bug could be fixed. Please.

Sounds like wireguard is starting before dns works and you use fqdn as peers?

Thanks for your input, but I don't use domains or dns for my WireGuard setup. They are all strictly IP based.
It definitely seems like WireGuard is starting too early though, just not dns.
Any idea on how I can delay WireGuard startup by 15-30 seconds?
Appreciate anyone who can help.
@franco any chance you can look into this bug? I've been using OPNSense for years and this weird thing just started with the 23.7 update. I know it could be the WireGuard plugin and not OPNSense itself, but I'd appreciate your input as well.
Thanks.

Since you mentioned the keyword "gateways" check if this patch works or you.

https://forum.opnsense.org/index.php?topic=35363.0


If not it would be best to open a ticket on Github and be more specific - otherwise to all that you said in this thread I can answer with "Nope, works fine here on multiple firewalls" - so clearly there's something else in your particular setup that hasn't surfaced yet.


August 13, 2023, 05:48:15 PM #123 Last Edit: October 14, 2023, 11:51:04 PM by lilsense
OK. So, I rebuilt my OPNsense from scratch and switched over to ZFS.

on 23.7 version I saw no issues with the Surricata running in IPS mode.


edit: I meant 23.1.11 ... I seem to have this issue with Suricata on WAN interface even after 23.7.6.

Update seemed to relatively smooth.  It did get stuck the first time I was able to log back into the web UI with a message that the router was still booting up, tho it did report traffic, some services were not running (tho I was able to start them manually), and was not able to access the repos (reported no internet connection).  I nervously rebooted, and everything came back up perfectly, including VPN clients.