how to recover using an old configuration?

Started by defaultuserfoo, October 09, 2026, 12:50:12 AM

Previous topic - Next topic
Hi,

so the storage medium of the router failed because one of the disks of the RAID1 failed and the other disk was removed while the system was still running.  Now it won't boot anymore.

I put in new disks and installed the current OPNsense version and imported the latest configuration I have which is well over a year old.  The import was successful but the firewall rules are totally messed up and need to be redone.

And I can't edit the firewall rules.  I guess I need to install the plugin for that, but I didn't see it in the list of plugins, and I don't know what it's called.

Is there no way to edit the firewalls rules now?
PowerEdge R210II

Because the backup is more than a year old, I would suggest:

Install the same OPNsense version that was running before the disk failure.

Restore the configuration and verify the interface assignments.

Check that all required plugins are installed again.

First check the interfaces, then the firewall rules, and test one change at a time.

Keep the original backup untouched and create a new backup before making any major changes.

This way, you can troubleshoot the problem calmly and avoid making several changes at once.
Hardware: N5105 Intel Celeron  
                       OPNsense | Home Lab | Linux & Home Automation
                               "Secure the network, automate the rest."

October 09, 2026, 02:48:03 AM #2 Last Edit: October 09, 2026, 02:55:19 AM by defaultuserfoo
That's a good idea and I'd have tried that, but I don't have a version that old, only older ones.  I looked at the website and didn't see an archive of old versions so I could download a version of the right age.  Is there one?

The backup is from August of last year.

PS: Oh I found this: https://pkg.opnsense.org/releases/25.7/

I'll try that tomorrow ...

Does it somewhere say in the config from which version it is?  I looked and didn't find that info in the file.
PowerEdge R210II

October 09, 2026, 02:51:07 AM #3 Last Edit: October 09, 2026, 03:20:11 AM by (MARLOO)
Open OPNsense Download.             https://opnsense.org/download/

Scroll down to Full mirror listing.

Choose a mirror.

Open the releases/ folder.

Select the required version, for example 25.7/.

Download the image suitable for your system, usually:


OPNsense-25.7-OpenSSL-dvd-amd64.iso.bz2
For an amd64 system, you can use the dvd or vga image. The serial image is intended for systems using a serial console.

You can also access the release archive directly here:

OPNsense release archive               https://pkg.opnsense.org/releases/

--------No, unfortunately the original OPNsense firmware version is usually not stored in config.xml------------

You can only determine the version from external information, such as:

The backup filename or its date.

Old installation media.

System emails, screenshots, or update logs.

The old disk, if it is still readable.

The configuration history stored on the previous installation....
Hardware: N5105 Intel Celeron  
                       OPNsense | Home Lab | Linux & Home Automation
                               "Secure the network, automate the rest."

Thanks!  I didn't realise that the mirror list also has the old versions.

I'm not sure if the old disk is still readable.  One has failed and the other one can't be booted from.  It would be great if I could read the current configuration from the disk, but that is very difficult because the file system on it is ZFS.

Is the current configuration even stored on the disk or can it only be gathered and exported by a running instance?

It sucks that we can't automatically store the config on an ftp server or send it by email at least once daily when it has been changed.  If that were possible I would have set that up and I'd have the current config now.
PowerEdge R210II

The only OPNsense Community Edition version released in August 2025 was 25.7.2, which came out on August 21, 2025. It belongs to the 25.7 "Visionary Viper" series.

These releases came out around August:

25.7 came out on July 23, 2025. It was the main release, with FreeBSD 14.3, Dnsmasq DHCP and a new grid interface (Tabulator).
25.7.1 came out on July 31, 2025, just before August. It mostly contained cosmetic UI fixes.
25.7.3 came out on September 9, 2025, so after August.

Good luck!
//me

October 09, 2026, 02:51:21 PM #6 Last Edit: October 09, 2026, 03:29:17 PM by (MARLOO)
Quote from: defaultuserfoo on October 09, 2026, 05:21:05 AMThanks!  I didn't realise that the mirror list also has the old versions.

I'm not sure if the old disk is still readable.  One has failed and the other one can't be booted from.  It would be great if I could read the current configuration from the disk, but that is very difficult because the file system on it is ZFS.

Is the current configuration even stored on the disk or can it only be gathered and exported by a running instance?

It sucks that we can't automatically store the config on an ftp server or send it by email at least once daily when it has been changed.  If that were possible I would have set that up and I'd have the current config now.



------------------------------------------------------------------------------------------------------------------------------------------------------------
Yes — the current OPNsense configuration is stored on the disk, in:

/conf/config.xml

On a default ZFS install, it is usually:

/zroot/ROOT/default/conf/config.xml

You do not need a running OPNsense instance to export it. You can read it from the disk with a live OPNsense USB.

Recovery steps
1)Boot the OPNsense installer USB and select Shell.

Check that the disk is detected:
**********************************
camcontrol devlist
gpart show
***********************************

2)Look for the ZFS pool:

*************************
zpool import
*****************************

Import it read-only:

**************************************************************
mkdir /mnt2
zpool import -f -o readonly=on -o altroot=/mnt2 -N zroot
***************************************************************

3)Mount the OPNsense root dataset:

*************************************************
zfs list -r zroot
mount -t zfs -o ro zroot/ROOT/default /mnt2
*****************************************************

4)Copy the configuration:

*******************************************************
cp /mnt2/conf/config.xml /tmp/config.xml
*****************************************************

5)Copy it to a second FAT32 USB drive:

****************************************************
mount -t msdosfs /dev/da1s1 /mnt
cp /mnt2/conf/config.xml /mnt/config.xml
umount /mnt
***************************************************

If the pool will not import
Try importing directly from the ZFS partition:

************************************************************************************
zpool import -d /dev/ada0p3 -f -o readonly=on -o altroot=/mnt2 -N zroot
**************************************************************************************

6)Inspect the ZFS label:

************************************
zdb -l /dev/ada0p3
*************************************

Do not run zpool import -F, zpool clear, or zpool labelclear before saving config.xml


-------------------------------------------------------------------------------------------------------------------------------------------------------------

Enable automatic SFTP backups in OPNsense:


System → Configuration → Backups → SFTP

Schedule it with:

System → Settings → Cron
-------------------------------------------------------------------------------------------------------------------------------------------------------------
Also save manual backups

In addition to automatic remote backups, periodically download a manual backup:

Go to System → Configuration → Backups.

Click Download configuration.

Save the resulting config-<hostname>-<date>.xml file to an external USB drive or another offline location.

Rename it to include the OPNsense version, for example:


Opnsense--25.7_1-2026-10-09.xml
Hardware: N5105 Intel Celeron  
                       OPNsense | Home Lab | Linux & Home Automation
                               "Secure the network, automate the rest."

Quote from: defaultuserfoo on October 09, 2026, 12:50:12 AMAnd I can't edit the firewall rules.  I guess I need to install the plugin for that, but I didn't see it in the list of plugins, and I don't know what it's called.

Is there no way to edit the firewalls rules now?
Just migrate them and then edit any that need editing and you are done ?!

When you combine the latest OPNsense release with an old config.xml the following things can happen :
- ISC configuration inaccessible.
There is a plug-in for that, however consider migrating to DNSmasq/KEA instead.
You can easily Import/Export the Static DHCP Mappings based on the MAC Address between all 3 of them ;)
- Firewall Rules can not be edited.
Also a plug-in for them, but you should migrate them to the new system.
- Outbound NAT rules can not be edited.
Another plug-in available, but they should also be migrated to the new Source NAT Rules.

Just some stuff that I can remember right now... There might be more stuff, but it's not a big deal overall...
Weird guy who likes everything Linux and *BSD on PC/Laptop/Tablet/Mobile and funny little ARM based boards :)

A similar question came up recently, with someone wanting to restore their configuration file from 21.7.8

I've attached notes to restore an old configuration file and get up to date using 25.1.12. Of course, there have been additional updates since the notes were written.

Hope the notes helps you get going relatively smoothly.

The mirrors still include old versions and 25.1 is still listed.

This is not working :(((((((((  I started with 25.1, updated so I could install a needed plugin, imported the configuration and then wasted many hours updating OPNsense to get it up to date.  At some point before I'm even finished, I'm again left with totally messed up firewall rules which I can't even edit :(((((((((((((((((((((((((((((((((((((((((((((((((((((((

Where is the plugin needed to edit these rules?  This totally sucks and is unacceptable.  Apparently at some point we can't update anymore without redoing all firewall rules from scratch.  That makes OPNsense obsolete.  Or what is your solution for that?

I've said before that this has been handled badly.  Now it turns out this is far beyond only 'badly'.
PowerEdge R210II

Today at 02:05:47 AM #10 Last Edit: Today at 02:08:19 AM by defaultuserfoo
Quote from: (MARLOO) on October 09, 2026, 02:51:21 PM
Quote from: defaultuserfoo on October 09, 2026, 05:21:05 AMIs the current configuration even stored on the disk or can it only be gathered and exported by a running instance?

It sucks that we can't automatically store the config on an ftp server or send it by email at least once daily when it has been changed.  If that were possible I would have set that up and I'd have the current config now.



------------------------------------------------------------------------------------------------------------------------------------------------------------
Yes — the current OPNsense configuration is stored on the disk, in:

/conf/config.xml

On a default ZFS install, it is usually:

/zroot/ROOT/default/conf/config.xml

You do not need a running OPNsense instance to export it. You can read it from the disk with a live OPNsense USB.


Thanks, I could try that.  It's possible that the disk has become unreadable, though.

But since I can't update to the current version without loosing all firewall rules I'm already screwed and it doesn't really matter.

There is no option to make backups with sftp.  I always had to make manual backups.
PowerEdge R210II

Quote from: defaultuserfoo on Today at 01:58:03 AMWhere is the plugin needed to edit these rules

In the steps I provided, after updating to 26.1.11_10 the next step after verifying the dashboard is to migrate the firewall rules to Rules [new].

Quote from: lmoore on October 09, 2026, 05:14:00 PMA similar question came up recently, with someone wanting to restore their configuration file from 21.7.8

I've attached notes to restore an old configuration file and get up to date using 25.1.12. Of course, there have been additional updates since the notes were written.

Hope the notes helps you get going relatively smoothly.

The mirrors still include old versions and 25.1 is still listed.

Thanks!  There is nothing anywhere near smoothly about this.

What's the point of installing an old version of OPNsense to import an old configuration when it can't be upgraded to the current version?  There is no difference between installing the current version and importing the old configuration and installing an old version and importing the old configuration because the result is the same: All the firewall rules are messed up and can't be edited.  They can't be deleted either.
PowerEdge R210II

Today at 02:23:16 AM #13 Last Edit: Today at 02:27:05 AM by defaultuserfoo
Quote from: lmoore on Today at 02:10:14 AM
Quote from: defaultuserfoo on Today at 01:58:03 AMWhere is the plugin needed to edit these rules

In the steps I provided, after updating to 26.1.11_10 the next step after verifying the dashboard is to migrate the firewall rules to Rules [new].


It only mentions resolving plugin conflicts.  I had only one plugin installed, so I don't expect that any plugin conflicts would need resolving.  I didn't notice any.

I don't see a plugin mentioned that will make it possible to edit the firewall rules again.  There is no such plugin in the list of plugins that can be installed.  Or what's it called?

Migrating the rules does not work.  And I was told it will be many years before a migration is needed.
PowerEdge R210II

Quote from: defaultuserfoo on Today at 02:23:16 AMMigrating the rules does not work

Sorry to hear that.

The notes were written and tested using a configuration file from February 2022 and this process was what worked the smoothest.

Migrating the firewall and NAT rules prior to upgrading to 26.7 allows you to edit them in 26.7.