Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - franco

#1
26.1 Series / Re: Firewall rules migration
Today at 07:31:37 PM
That's because the old rules don't have as much integrity checks. "opt2" is gone I think so you don't need these rules?


Cheers,
Franco
#2
Yeah, that's the issue that can happen where the plugin doesn't update. I'm working on it. Sorry for the trouble.


Cheers,
Franco
#3
It's going to be configurable in 26.1.2, see https://github.com/opnsense/core/issues/9767

Yay for tickets :D


Cheers,
Franco
#4
If you run the command on the shell you can see if it's still stored ;)


Cheers,
Franco
#5
I think it's working as described, but it doesn't work on reboots (by initial design).

We discussed it here https://github.com/opnsense/core/issues/9774

Cheers,
Franco
#6
For a static IPv6 prefix in Kea yes. For a dynamic one no. We'll be discussing some things related to Kea in the upcoming roadmap discussion for 26.7.


Cheers,
Franco
#7
This will be changed in a future 26.1.x, see https://github.com/opnsense/src/issues/280


Cheers,
Franco
#8
Do you have the update log?

# opnsense-update -g


Cheers,
Franco
#9
Can you paste the PHP error from System: Firmware: Reporter here?


Thanks,
Franco
#10
FWIW, the pkg bug could also be a kernel bug. We're adding a soft-retry along the lines of https://github.com/opnsense/pkg/commit/94e5e97a5 which should help and gather a bit more data.

@jmcgee do you have the upgrade log (firmware audit) for me?


Cheers,
Franco
#11
Still no idea on "permission denied". It indicates insufficient permission, but Suricata runs as root and there should be no restrictions placed on a default install GUI only use regarding what Suricata can do.


Cheers,
Franco
#12
Yes, you only need this when you already have manual servers listed there. DNS servers (and monitoring IPs) should not overlap between gateways. This ensures that each DNS server stays on its own WAN connection. The underlying cause is that host routes are set up for each one and you cannot connect the same IP over two different gateways.


Cheers,
Franco
#13
Hi Evert,

You're right. The VIP support was removed a while back and the "Link Priority" really refers to the tier selection. I've cleared that up in

https://github.com/opnsense/core/commit/53d61b9d


Cheers,
Franco
#14
25.10.2 is out since yesterday. We're planning for 26.1.2 at the end of this week to pick up the newer Python batch into community as well.


Cheers,
Franco
#15
26.1 Series / Re: zfs and sqlite
February 09, 2026, 08:10:08 PM
Yes, it's opnsense-revert, not opnsense-update. Thanks!


Cheers,
Franco