Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - datenimperator

#1
Thx for that, I do know about the "late import". I'd really like to learn how to get it right first time. Because, if a default DHCP server starts handing out faulty IP addresses, lots of devices are confused. So, I'd need to first start it in a separate LAN, to stop that. After all, getting the config right from the start would make my installation a lot easier.
#2
I'll upgrade my machine, so I'd love to move my existing installation. During the last installation of 26.7 I noticed there's an "import config" step during the process. I had created the installation media on a USB stick larger than needed, and formatted the remaining space as FAT32. I also created a path `conf` and placed a backup of my config als `/conf/config.xml` in it.

However, that wasn't recognized, no matter which device I entered.

  • Is it reasonable to format the remaining space on my USB media like that? I did this because my machine had only 2 USB ports, one being used by the keyboard. No, I did not have a spare USB hub.
  • Does the importer need anything else to recognize the data?
  • Should I create a complete copy of the original `/conf` path, instead of only the .xml file?

Regards, Christian
#3
Quote from: Patrick M. Hausen on August 26, 2026, 09:08:52 AMAlternatively create a dedicated user from the UI and in their home directory create a virtual environment.

https://docs.python.org/3/library/venv.html

I like the idea of having a non-admin user building and running that daemon. However, creating a non-root user won't let me give him a login shell: "The login shell for this non-admin user is not active for security reasons."

Is this a setting?
#4
I feel honored seeing you remember me. :-) Yes, it has been a while, though I sticked with OpnSense ever since my m0n0wall days.

Quote from: franco on August 26, 2026, 08:42:10 AMSo you wouldn't break the kernel with ports but a major upgrade could fail although in reality your custom packages will just stop working.

Current Python is 3.13 and most Python ports are flavoured now so I'm not entirely sure how to build them from the command line.  But anyway load the ports tree:

# opnsense-code ports

The ports unfortunately don't include all three packages, just pyyaml. So that won't work.

Can I safely delete /usr/ports after I learned that?
#5
I broke my 26.7 system by tinkering with packages, resulting in an incompatible kernel which would not boot. So I started new, restored my backup and ditched ISC on my way. Fresh 26.7 with no custom packages again.

The question remains: I'd like to install a daemon written in Python, which would require a number of Python extensions. In particular

- psutil
- paho-mqtt
- pyyaml

The packages names relate to the base python version, eg py312-psutil. How would I install that, without putting my system at risk? Regards

Christian
#6
Quote from: Seimus on October 01, 2024, 03:07:05 PM
To check if Ports are not disabled they are actually on the PCIe lines, check the input from Beck

Thx for that. I checked it and to my knowledge the settings are as described. Doesn't make a difference though.

Quote from: Greg_E on October 01, 2024, 03:20:43 PM
Jumpers inside the case to turn them on/off? Is there a BIOS that you can flash, even if the same version?

Also thank you for that. While you might be correct, I won't spend that much time, given that there's not even some technicals docs for the device. I'll return it, and will use an external modem for now.

Thank you all.
#7
Thx both  :)

Quote from: Seimus on October 01, 2024, 11:43:09 AM
As new mentioned check the dmesg, if those NIC are recognized and visible during bootup

I would advice to not only reset the BIOS but to actually inspect what is set in BIOS. The NICs can be by default disabled in BIOS you have to check it out.
they aren't visible during bootup.

I've spent some time to understand the BIOS but didn't find anything that read like "disable NICs here". Tried a few options but no avail:

Quote from: Seimus on October 01, 2024, 11:43:09 AM
If NIC are turned on in BIOS but OPNsense does not recognize them, try to boot up a liveusb of any linux distro and see if they are there.

If the above is done and verified and they wont show, its possible those NICs are cooked.

In fact that's what I did. Apart from the fresh install of OpnSense 24.7 I also tried a FreeBSD 14 live image as well as a current Manjaro Linux. No traces of those NICs whatsoever.

I need to get in contact with the seller.

Regards

Christian
#8
I'm trying to install OpnSense on a new mini PC.

https://www.aliexpress.com/item/1005007278560105.html

During startup, only the SFP+ ports are detected. The RJ45 ports aren't even activated. I already reset the BIOS to defaults and am certainly running a fresh install, but no avail.

EDIT Running "pciconf -lcbv" lists two 82599ES 10Gb devices but nothing else.

I'd like to use the SFP and RJ45 ports in parallel. Is that even possible? What am I missing?

Regards

Christian
#9
Thank you both. The picopc is nice, but I don't need Wifi. The protectli hardware is nice but pricey. I'm currently running OpnSense on a barebone pc that has exactly the same specs as the Protectli F4W, at a third the price.

Checking eg aliexpress, I see this: https://de.aliexpress.com/item/1005007278560105.html

Two SFP 10g slots, two 2.5Gb ethernet ports. Under 280 EUR with enough RAM and storage to run OpnSense. I assume that's one way to go. Or, doers anybody see any other options to evaluate? Regards

Christian
#10
Hi, I'd like to run OpnSense on a device providing at least one SFP+ port for a fiber connector.

The standard decisio hardware surely is great but too expensive for my home use.

Is there any budget recommendation for this? I'm using OpnSense on a $150 4c NUC currently, and that thing is vastly overpowered (although fun :-) for what it does. I'd simply need something similar, but with a SFP slot.

Any ideas? Kind regards

Christian
#11
Hi all,

I'm writing to this old thread because it's exactly my question: Why is the health graph so complicated to read?

The label of the y-axis reads "seconds/%". What does that even mean? How does it relate to the selected granularity?

If you set the granularity to 60 minutes or 24 hours, the x-axis label becomes labeled by "days of the year" or "week of the year". While I would be able to calculate that into something understandable - why is it so hard in the first place?

I'd really appreciate a simplification there. Kind regards

Christian
#12
Hi all,

I was using the DNS blocklist feature of Unbound to save my home lan from ads and other malicious stuff. In particular, I activated the "blocklist.site ads" element.

Seems this overdid it a little. Eg the Deezer client on my Linux PC stated that it was offline every few minutes. Playing songs worked, however. Also, my Smart TV reported it wasn't able to download software updates.

I switched to the AdAway list recently, and the issues went away. Here's my question:

How would I log/monitor blocklist activities in particular? I'd like to keep an eye on blocklisted replies, along with the IP from where the request originated. Simply increasing the Unbound log level quickly filly my HD with GB worth of log data. Too much.

Regards

Christian
#13
So I had my OpnSense running smoothly on a NUC-like mini PC (like the Protectly Vault FW4B). I wanted to upgrade my home network to 2.5GBit and upgraded the router hardware as well.

On my old appliance, the Intel I210at interfaces were numbered as igb[0,1,2,3]

On the new one, it is Intel I225-V, and they are named igc[0,1,2,3]

I did not expect the network interface names to change. So when I swapped the m.2 drive from the old to the new hardware, a lot of settings were broken, because they referred to non-existing interfaces.

Is there a smarter way to do this, something that would have accounted for the change in interface names? Regards

Christian
#14
Quote from: franco on April 12, 2022, 04:51:32 PM
# opnsense-code dhcp6c
# cd /usr/dhcp6c
# curl https://patch-diff.githubusercontent.com/raw/opnsense/dhcp6c/pull/32.patch | patch -p1
# ./configure
# make all install

Eingespielt, neu gestartet, Config wiederhergestellt - funktioniert. Danke.

Quote from: franco on April 12, 2022, 04:51:32 PM
Sicher bin ich mir beim Patch nicht ob das selbst wenn es hilft nicht gleich ne Sicherheitslücke ist ohne echte Implementation des Befehls.

Ich verstehe das so, dass durch den zuvor fehlenden case-Zweig der default angesprungen wurde, und in dem steht fail. Deshalb ging überhaupt nichts mehr.
#15
Passt an sich genau, aber müsste ich im Log nicht irgendwo den Text "unsupported authentication protocol:" finden?

Ich würde das ja testen, aber wie? Code runterladen, "configure, make, make install"?