Upgrade advice to OPNsense 26.7 with Zenarmor (os-sensei) and active plugin stac

Started by GrepZilla, September 08, 2026, 10:26:38 AM

Previous topic - Next topic
Hi everyone,

I am planning to upgrade my OPNsense firewall from version 26.1.11_10 to 26.7. Since this instance manages a primary network environment, I want to double-check for any known regressions, bugs, or compatibility issues with my current plugin setup before proceeding.

Here are my current system details:

System Information:

OPNsense: 26.1.11_10-amd64

FreeBSD: 14.3-RELEASE-p16

OpenSSL: 3.0.21

Installed Plugins:

os-acme-client (4.16_1)

os-cpu-microcode-intel (1.1)

os-crowdsec (1.0.12)

os-mdns-repeater (1.2)

os-q-feeds-connector (1.6)

os-sensei / Zenarmor (2.6.2)

os-sensei-agent (2.6.1)

os-sensei-updater (2.0)

os-sunnyvalley (1.5_2)

os-sftp-backup (1.1_2)

os-tailscale (1.4)

Specifically, I would like to know if there are any known caveats or breaking changes regarding Zenarmor (os-sensei), CrowdSec, or Tailscale on the 26.7 release branch, or if it is recommended to hold off for a couple more minor updates.

Has anyone performed this upgrade with a similar plugin stack? Any feedback or advice would be greatly appreciated.

Thanks in advance for your support!

Best regards.

I upgraded 5 weeks ago to 26.7.1_1 with Zenarmor, Crowdsec, QFeeds and Tailscale installed and I didn't have any problem with the upgrade, but I paid attention to the things below:

- There were some issues with the newer FreeBSD version in 27.1, which manifested when running the os-cpu-microcode-intel plugin. At the time the recommendation was to uninstall this plugin before upgrading, update the OPNsense bootloader and only afterwards reinstall the plugin. I suggest that you search the forum for this, since there were plenty of posts on this subject.

- If you have not yet migrated the firewall and NAT rules to the new UI, you will need to install a new plugin in 26.7 to be able to edit them. That plugin (os-firewall-legacy IIRC) is already available in later versions of 26.1, at which time I installed it. I waited with the migration until after the upgrade to 26.7, but it's probably better to execute that migration before the upgrade. I found the migration to be very easy, just follow the instruction in the migration tool and remember to go through all the tabs of that tool.

As always, read the release notes and download your config before the upgrade and (if you run ZFS, which I hope everyone does) create a snapshot.