Confused by 26.7 upgrade

Started by Plethodon, August 31, 2026, 12:29:18 AM

Previous topic - Next topic
After I upgraded to 26.7 everything worked, so I thought I was done.  But when I went to enable some rules that I generally keep disabled, the rules weren't even there. Then I noticed that the interface didn't even let me select a rule (no checkboxes on the left side). I'm starting to think that I missed something big about this upgrade.

Then I noticed a Migration assistant under Firewall. Can anyone direct me to what I should do about this situation? I've read some posts about the Migration assistant, but I'm not clear whether that even applies to my situation. Thanks.

The rule UI was replaced, entirely. You need to migrate your rules to the new system. Use the migration assistant. Detailed instructions are on the migration assistant UI page. Just do as is documented there.

You might need to install the legacy rule plugin to finally delete all the legacy rules.

This was announced months ago for 26.1 - you could have gone through the migration in 26.1 already to be prepared for 26.7.
Deciso DEC750
People who think they know everything are a great annoyance to those of us who do. (Isaac Asimov)

I'm on 26.7.3 and need to disable a FW rule, but I don'T see any option to do so unter "FW rules". Just need this rule disabled, no time for playing arround with stuff this morning. Help!
kind regards
chemlud
____
"The price of reliability is the pursuit of the utmost simplicity."
C.A.R. Hoare

felix eichhorns premium katzenfutter mit der extraportion energie

A router is not a switch - A router is not a switch - A router is not a switch - A rou....

Install the legacy rules plugin.
Deciso DEC750
People who think they know everything are a great annoyance to those of us who do. (Isaac Asimov)

To use a firewall system a reading of release news is mandatory.
Only press update is not the target.

Not "you have no time today", you spent no time in the past to get a clean system.

Why you ignore the rule migration - one of the biggest changes in opnsense - for half a year ?

Quote from: Patrick M. Hausen on August 31, 2026, 12:36:24 AMYou might need to install the legacy rule plugin to finally delete all the legacy rules.
I thought so too, but it turns out you don't : The Migration Assistant does that for you :)

Quote from: notspam on August 31, 2026, 10:42:50 AMTo use a firewall system a reading of release news is mandatory.
Only press update is not the target.

"you have no time today" is not an excuse!
Totally agree! ;)
Weird guy who likes everything Linux and *BSD on PC/Laptop/Tablet/Mobile and funny little ARM based boards :)

Quote from: Patrick M. Hausen on August 31, 2026, 12:36:24 AMThe rule UI was replaced, entirely. You need to migrate your rules to the new system. Use the migration assistant. Detailed instructions are on the migration assistant UI page. Just do as is documented there.

You might need to install the legacy rule plugin to finally delete all the legacy rules.

This was announced months ago for 26.1 - you could have gone through the migration in 26.1 already to be prepared for 26.7.

Patrick, thank you for this clarity. Clearly I'm not attending to changes closely enough. Is there a recommended site to follow (like RSS) or something similar so I can keep up to date?

Quote from: Plethodon on September 01, 2026, 01:57:23 AMIs there a recommended site to follow (like RSS) or something similar so I can keep up to date?

OPNSense will show a changelog on every update. Read it.

If you want to read release notes outside of the UI, there are these places:

https://forum.opnsense.org/index.php?board=11.0
https://opnsense.org/blog/

Today at 03:35:32 AM #8 Last Edit: Today at 03:43:17 AM by defaultuserfoo
Interesting, a couple weeks ago when I found that the migration broke all my firewall rules, I was told that I shouldn't have used it and there would be years before before anyone would have to migrate.

And now suddenly the migration has apparently become mandatory.  That kind of behaviour means that we can no longer trust the developers in any way ever again, if we ever did.

You read the release notes for 26.7 ?

https://forum.opnsense.org/index.php?topic=52375.0

o firewall: legacy rules pages move to plugin


Quote from: defaultuserfoo on Today at 03:35:32 AMInteresting, a couple weeks ago when I found that the migration broke all my firewall rules, I was told that I shouldn't have used it and there would be years before before anyone would have to migrate.

And now suddenly the migration has apparently become mandatory.  That kind of behaviour means that we can no longer trust the developers in any way ever again, if we ever did.


No, like I said before, I read the release notes that are being displayed before updating.  I don't remember seeing anything mentioned about such a plugin.

If you want ppl to read stuff you need to show it there.

Quote from: defaultuserfoo on Today at 04:32:54 PMNo, like I said before, I read the release notes that are being displayed before updating.  I don't remember seeing anything mentioned about such a plugin.

If you want ppl to read stuff you need to show it there.

Quote from the release notes:

Quoteo firewall: move config.xml default LAN allow rules to new rules GUI
o firewall: legacy rules pages move to plugin

Deciso DEC750
People who think they know everything are a great annoyance to those of us who do. (Isaac Asimov)

If you're not able to read and understand release notes before updating critical components, OPNsense may not be the correct solution for you. Consider switching to a consumer product.

Today at 07:07:32 PM #13 Last Edit: Today at 07:35:39 PM by defaultuserfoo
Quote from: bamf on Today at 06:31:23 PMIf you're not able to read and understand release notes before updating critical components, OPNsense may not be the correct solution for you. Consider switching to a consumer product.

Obviously, I can't read or understand what I'm not being presented with.  It also matters what the presentation is like.

BTW, that was an utterly stupid remark.  You need to first assess the requirements before suggesting what product to use.  Plus you're implying that OPNsense is not intended to be user friendly while 'consumer products' are, which is not true.  Consumer products aren't intended to be user friendly or useful or anything at all, they are only made to generate profits.

Do you think it is helpful to suggest to use a different product when someone suggests how OPNsense could be more user friendly?

Today at 07:14:02 PM #14 Last Edit: Today at 07:27:53 PM by defaultuserfoo
Quote from: Patrick M. Hausen on Today at 04:44:14 PM
Quote from: defaultuserfoo on Today at 04:32:54 PMNo, like I said before, I read the release notes that are being displayed before updating.  I don't remember seeing anything mentioned about such a plugin.

If you want ppl to read stuff you need to show it there.

Quote from the release notes:

Quoteo firewall: move config.xml default LAN allow rules to new rules GUI
o firewall: legacy rules pages move to plugin



Was that shown in the notes that are being displayed when updating?

I used to read the whole list of details and stopped doing that a while ago because the items in the list effectively don't tell me anything.  Even if I did read them, I wouldn't remember them.  And even if I did read and remembered them, I still only have a choice between updating and not updating.  Not updating isn't really an option, so what's the point of all these items?

In any case, how do you expect users to conclude from these items that they need to install such a plugin when they find out that they suddenly can't en-/disable firewall rules and either migrating and/or the plugin are suddenly mandatory?

And what is 'config.xml'?

I've said before that this was handled badly, and now it seems being handled even worse.