how to recover using an old configuration?

Started by defaultuserfoo, October 09, 2026, 12:50:12 AM

Previous topic - Next topic
Quote from: defaultuserfoo on Today at 02:23:16 AMI had only one plugin installed, so I don't expect that any plugin conflicts would need resolving

Referring to page 6, after you powered on the restored system, did you check the 'Status' page and was the 'Resolve plugin conflicts' button there!?

Today at 04:34:23 AM #16 Last Edit: Today at 05:49:45 AM by (MARLOO)
@defaultuserfoo 
 I understand your position because I have been in a similar situation before, but the firewall rules are not necessarily lost, and OPNsense has not become obsolete.

In 25.x, firewall rules were managed through the legacy Rules interface.
In 26.1, OPNsense introduced the new MVC/API-based Rules [new] interface. Both systems existed side by side at that point, and migrating the rules was optional.

Before doing anything else, I would first try to recover the current configuration from the old disk using the steps below.

Boot from an OPNsense live/installer USB, with the damaged disk connected and select Shell from the console menu.

First, check whether the old disk is detected:

********************************
camcontrol devlist
gpart show
*****************************

Then look for the ZFS pool:

***********
zpool import
*************

If the pool is shown, import it read-only:

**********************************************************
mkdir /mnt2
zpool import -f -o readonly=on -o altroot=/mnt2 -N zroot
*********************************************************

Then locate and mount the root dataset:

******************************************************
zfs list -r zroot
mount -t zfs -o ro zroot/ROOT/default /mnt2
*********************************************

Copy the configuration:

*********************************************************
cp /mnt2/conf/config.xml /tmp/config.xml
***********************************************************

Finally, plug in a FAT32 USB stick and copy the file to it:


*************************************
mount -t msdosfs /dev/da1s1 /mnt
cp /tmp/config.xml /mnt/config.xml
umount /mnt
***************************************

The USB device name may be different, so check it first with gpart show or camcontrol devlist.



---------------------------------------------------If the disk is not readable-----------------------------------------------------------------------------------

First, check whether the disk is detected at all:

******************************
camcontrol devlist
dmesg | tail -50
gpart show
****************************


If the disk is detected but the ZFS pool will not import, try importing it directly from the ZFS partition:

*******************************************************************************
zpool import
zpool import -d /dev/ada0p3 -f -o readonly=on -o altroot=/mnt2 -N zroot
Check the actual device name with gpart show; it may be ada0p3, da0p3, and so on.
*************************************************************************************

You can also inspect the ZFS labels:

*********************************************************
zdb -l /dev/ada0p3
*********************************************************************

If the pool imports read-only, immediately copy the configuration:

************************************************
zfs list -r zroot
mount -t zfs -o ro zroot/ROOT/default /mnt2
cp /mnt2/conf/config.xml /tmp/config.xml
******************************************

Then copy it to a FAT32 USB stick.

------------------------------------------------If the disk or ZFS pool is corrupted---------------------------------------------------------------------

Check the pool status:

**********************************
zpool import
zpool status
************************************

Try a normal read-only import first

******************************************
mkdir /mnt2
zpool import -f -o readonly=on -o altroot=/mnt2 -N zroot
**************************************************************

If that fails, try importing directly from the ZFS partition

***********************************************************
zpool import -d /dev/ada0p3 -f -o readonly=on -o altroot=/mnt2 -N zroot
********************************************************************************
Check the actual partition name with:

*****************
gpart show
*********************

You can also inspect the ZFS metadata

**************************************
zdb -l /dev/ada0p3
***************************************
If the pool imports read-only, immediately copy the configuration

*********************************************
zfs list -r zroot
mount -t zfs -o ro zroot/ROOT/default /mnt2
cp /mnt2/conf/config.xml /tmp/config.xml
***********************************************

Then copy it to a FAT32 USB stick

-----------------------------------------------------------------------------------------------------------------------------------------------------------
                                                                                                                After recovery

Once you have either recovered the current config.xml from the old disk, I would install OPNsense 25.7 to a new disk or a empty disk installed inside your firewall, then import the latest backup you have recovered.

Do not update for now. First verify that everything works. If it worked before, it should work again after restoring the configuration.

Check the following:

Interface assignments

Installed plugins

Firewall rules

NAT rules

VPN, DNS, DHCP, and any other services you use

Once the system is stable and the interfaces, plugins, firewall rules, and NAT rules are working as expected, immediately create a new backup:

System → Configuration → Backups → Download configuration

Save it outside the firewall, for example on another PC, NAS, or USB drive.

After that, update gradually and test after each step.



Remember that the firewall rules system changed in 26.x. If you import an old configuration with legacy rules, it is normal that they may appear messed up or not editable in the new interface until you migrate them using Firewall → Rules → Migration assistant.
Hardware: N5105 Intel Celeron  
                       OPNsense | Home Lab | Linux & Home Automation
                               "Secure the network, automate the rest."

Today at 04:57:54 AM #17 Last Edit: Today at 05:28:57 AM by (MARLOO)
Quote from: defaultuserfoo on Today at 02:18:03 AMWhat's the point of installing an old version of OPNsense to import an old configuration when it can't be upgraded to the current version?  There is no difference between installing the current version and importing the old configuration and installing an old version and importing the old configuration because the result is the same: All the firewall rules are messed up and can't be edited.  They can't be deleted either.


As I said   in the previus post 


There is a point: the firewall rules system has changed.

Firewall → Rules → Migration assistant.
https://docs.opnsense.org/manual/firewall.html

In 25.x, the rules use the legacy Rules system.

In 26.x, OPNsense uses the new MVC/API-based rules system. When you import an old configuration directly into 26.x, the legacy rules are imported, but they need to be migrated to the new system before they can be edited or deleted there.

That is why installing 25.x first is the correct approach: you can restore and verify the old configuration in its original format, then migrate the rules before upgrading to 26.7....

Than you can setup your manual backup,sftp backup with cron job,screenshoot of your plugin and many other things you like.

Regards
Hardware: N5105 Intel Celeron  
                       OPNsense | Home Lab | Linux & Home Automation
                               "Secure the network, automate the rest."