Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - Taomyn

#1
Quote from: franco on October 14, 2025, 06:46:31 PMTicket sounds good, even just to dig into the specifics.


Cheers,
Franco
Done https://github.com/opnsense/core/issues/9290
#2
Checked again this morning and it eventually worked

Last updated 2025-10-13T22:15:01.504926
Total number of ranges 4550698

So for me, the lack of an "update now" feature hampers any simple diagnosis - perhaps something for the feature list?
#3
I tried using curl from the OPNsense shell but I couldn't figure out how to get it to follow the redirect as I got that as the result - it did also needed quotes around the URL to take care of the ? character before the token:

Found. Redirecting to https://dl.ipinfo.io/artifacts/v1/ipinfo_lite.csv.gz?gener<redacted>

But doing the same on my Fedora server, but using wget, the file comes down correctly.
#4
Nope, they are still the same as the last run against the old MaxMind URL

I've tried making a change to a rule on my WAN connection and that didn't cause an update, and checking some log files doesn't show anything but I'm not sure where to be looking.

Last updated 2025-10-10T10:06:14   
Total number of ranges 1298663
#5
I updated to 25.7.5 at the weekend and today wanted to try out IPInfo. I followed the directions from the release notes, I signed up and replaced the MaxMind URL with the new one from my account but so far I see no change or any error. How can I check the status and maybe force an update? I did check the new URL manually through my browser and the file does download.
#6
25.7, 25.10 Series / Re: wireguard not passing traffic?
September 19, 2025, 07:40:14 AM
I think for me it's been a combination of things, and the WireGuard service just not letting traffic through was one perhaps caused by too many reconnect attempts. The final fix for me was a setting for the APN on my new provider, they were still sending out as default a profile with proxy enabled, once I cleared those WireGuard and some other strange issues suddenly cleared up, as well as getting better 4G/5G performance.
#7
I've had this issue with nearly all my certificates for quite some time and found that if I re-enable OCSP, save, disable OCSP, save, the next time round it was ok.
#8
25.7, 25.10 Series / Re: wireguard not passing traffic?
September 15, 2025, 09:51:39 AM
Quote from: Taomyn on September 05, 2025, 08:49:28 AMI believe I've resolved it for myself and so far it's only happened once which I think was just a bad connection while I was travelling home on the tram.

The Android WireGuard app was missing the permission to Run in Background:Unrestricted Battery it was on the default Optimised. Once I enabled this the connection became reliable again - I can only guess Android would over time pause the app in some way. Every other app after transferring across phones would prompt me the first time I ran them, as it seems this permission doesn't transfer at least not for me, so why WireGuard I don't know.
Unfortunately this was only part of it, I think it was making the issue worse as randomly I still have the same problem with the connection blocking all traffic to the Internet and my DNS. Like before only restarting WireGuard or disconnecting then waiting a few hours gets it working again. For now I have added a cron job to restart WireGuard each midnight, and I have noted the command so I can use SSH manually restart it if I need it urgently.
#9
25.7, 25.10 Series / Re: wireguard not passing traffic?
September 05, 2025, 08:49:28 AM
I believe I've resolved it for myself and so far it's only happened once which I think was just a bad connection while I was travelling home on the tram.

The Android WireGuard app was missing the permission to Run in Background:Unrestricted Battery it was on the default Optimised. Once I enabled this the connection became reliable again - I can only guess Android would over time pause the app in some way. Every other app after transferring across phones would prompt me the first time I ran them, as it seems this permission doesn't transfer at least not for me, so why WireGuard I don't know.
#10
25.7, 25.10 Series / Re: wireguard not passing traffic?
September 04, 2025, 12:41:35 PM
Quote from: meyergru on September 04, 2025, 10:19:51 AM@Taomin: Probably, either your IP sometimes changes

Nope, my firewall has a proper fixed IP, business account, as does my company office WiFi - I'm using the guest account which has no restrictions, just cannot access on the corporate LAN.

Quote from: meyergru on September 04, 2025, 10:19:51 AMyou have not enabled the cron job to detect a stale connection and restart Wireguard automatically (on both sides of the connection!)

No, I see the connection from my phone on the firewall changing state connected/stale/disconnected, and it doesn't matter how often I manually disconnect/reconnect on the phone. As for the cronjob, I have no clue about that as it's never been anything I needed to configure or even knew I needed.

Quote from: meyergru on September 04, 2025, 10:19:51 AMyour new provider has DS-Lite with CG-NAT and you cannot be reached via IPv4 any more.

It's happening on WiFi with a fixed IP

Only manually restarting Wireguard on the firewall do things start working again, and then only for some random amount of time at which point the traffic going external comes to a halt and from the looks of things so does the firewall Winguard logging. On the phone Wireguard is oblivious to the issue because the gateway IP and everything else internal still responds.

It's very bizzarre.
#11
25.7, 25.10 Series / Re: wireguard not passing traffic?
September 04, 2025, 07:48:42 AM
I've suddenly started getting issues with my Wireguard connection, couldn't be at the worst time when I'm switching phone and provider. No problems on the old and new phone, and even after switching provider all was well until about 2 days ago.

Now I can connect and traffic local to my remote network is fine, but pass through to the Internet just gets stuck. The GUI shows the connection is fine, but what I did notice this time was that since restarting the Wireguard service which seemed to fix it for a while, when I went to check it again just now there was zero logging since then and restarting the service brought that back as well as my traffic.

Versions
OPNsense 25.7.2-amd64
FreeBSD 14.3-RELEASE-p2
OpenSSL 3.0.17
#12
I was searching the documentation site when suddenly I was unable to access the site any longer - after checking settings, other OPNsense sites and other providers, I can only conclude that my fixed IP is being blocked. Perhaps my searches triggered something.

Is there an OPNsense admin that can check the status of my fixed IP on your side? I'll PM it to whomever can help me if you cannot see it from my connection history of the forum.

Thanks.

** Update: seems to be ok now
#13
But my NAT rule already has an associated rule assigned, it's not set to "pass".

You cannot view this attachment.You cannot view this attachment.

#14
Since the new forum I've never received an email notification despite having the option enabled everywhere that I can find. This never happened on the old forum software. Even today someone replied to my new post and I never received an email. My address is a Gmail account and I see no sign of the emails getting diverted to spam.

Can a moderator or someone with access to the forum logs take a look to see if any alerts are failing for my account?
#15
Ok, I see, but what do you mean by "associate a firewall rule to the NAT rule and then prioritize it"?