Hi, this was also posted here as well, I've been monitoring my firewall since however all seems to be working fine so far.
Regards
Regards
This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.
Show posts MenuQuote from: spetrillo on November 15, 2025, 06:52:45 PMHello all,
My client runs an OPNsense firewall on VMware. It runs really well and takes no real resources. I am building a replacement 25.7 firewall. As I got to the storage config I stopped thinking...should I allocate two disks and run these in a ZFS raid 1 pair. Well can someone comment if this makes any sense under VMware?
Thanks,
Steve
Quote from: Patrick M. Hausen on November 15, 2025, 07:03:51 PMWhat are your specific questions? Just go ahead and ask them ;-)
You have read the documentation on transparent filtering bridge?
Interfaces: [WAN] -> igb0
IPv4 Configuration Type: DHCP (It was: NONE)
IPv6 Configuration Type: NONE (It was: DHCPv6)
Interfaces: [LAN] -> igb1
IPv4 Configuration Type: NONE
IPv6 Configuration Type: NONE (It was: Track Interface)
Interfaces: [TFB] -> igb0 + igb1
IPv4 Configuration Type: NONE
IPv6 Configuration Type: NONE
Interfaces: [ADM] -> vtnet0
IPv4 Configuration Type: Static IPv4
IPv6 Configuration Type: NONE
Quote from: franco on September 30, 2025, 01:56:23 PMNice, thank you. May consider picking this up in core in the future if boot code incompatibilities are to become more common.
Cheers,
Franco
root@nas-mserver: ~# bootcode-update -v
bootcode-update 0.3.6
root@nas-mserver: ~# bootcode-update -e
UEFI Partition: [ ada0p1 ]
Disk Serial: [ TNS519GYXXXXXX ]
Proceed with EFI bootcode update for the following geom: [ada0p1] (Y/n)?: y
Proceeding...
=> Updating EFI bootcode on ada0p1
/boot/loader.efi -> /boot/efi/efi/boot/bootx64.efi
/boot/loader.efi -> /boot/efi/efi/freebsd/loader.efi
=> Success!
UEFI Partition: [ ada1p1 ]
Disk Serial: [ 140817TM85A3TDXXXXXX ]
Proceed with EFI bootcode update for the following geom: [ada1p1] (Y/n)?: y
Proceeding...
=> Updating EFI bootcode on ada1p1
/boot/loader.efi -> /tmp/boot_esp/efi/boot/bootx64.efi
/boot/loader.efi -> /tmp/boot_esp/efi/freebsd/loader.efi
=> Success!
root@fw-opnsense:~ # uname -a
FreeBSD fw-opnsense.arpa 14.3-RELEASE-p2 FreeBSD 14.3-RELEASE-p2 stable/25.7-n271676-ab2281de1853 SMP amd64
root@fw-opnsense:~ # bootcode-update -v
bootcode-update 0.3.6
root@fw-opnsense:~ # bootcode-update -e
UEFI Partition: [ vtbd0p1 ]
Disk Serial: [ BHYVE-125E-B3XX-XXXX ]
Proceed with EFI bootcode update for the following geom: [vtbd0p1] (Y/n)?: y
Proceeding...
=> Updating EFI bootcode on vtbd0p1
/boot/loader.efi -> /boot/efi/efi/boot/bootx64.efi
/boot/loader.efi -> /boot/efi/efi/freebsd/loader.efi
=> Success!
root@nas-mserver: ~# bootcode-update -g
Boot Partition: [ ada0p2 ]
Disk Serial: [ TNS519GYXXXXXX ]
Pool Member: [ zroot: '/dev/ada0p4' ]
Proceed with GPT/ZFS bootcode update for the following geom: [ada0p2] (Y/n)?: y
Proceeding...
=> Updating GPT/ZFS bootcode on ada0p2
partcode written to ada0p2
bootcode written to ada0
=> Success!
Boot Partition: [ ada1p2 ]
Disk Serial: [ 140817TM85A3TDXXXXXX ]
Pool Member: [ zroot: '/dev/ada1p4' ]
Proceed with GPT/ZFS bootcode update for the following geom: [ada1p2] (Y/n)?: y
Proceeding...
=> Updating GPT/ZFS bootcode on ada1p2
partcode written to ada1p2
bootcode written to ada1
=> Success!
Quote from: jade_nekotenshi on September 17, 2025, 04:49:10 PMWith a mirror, a three-way mirror almost makes more sense than a hot spare. Hot spares are more useful for RAIDZ/RAIDZ2.
Quote from: franco on September 29, 2025, 12:47:38 PMFrom the first validation screenshots you can see there is an extra whitespace at the end "3478 ", maybe that's a CR (\r) from Windows line endings or a spurious LF (\n) altogether being converted into a space, but that is strange input like
3478
,4379
What are you actually pasting? Just paste it here in the forum...
Cheers,
Franco
Quote from: Monviech (Cedrik) on September 29, 2025, 11:24:06 AMYou can click on "text" below that field.Hi, yes I've selected the text icon and copied them and they populated as new lined and worked just fine.
And then copy paste them as newline separated list:172.16.1.1
172.16.1.2
172.16.1.3
Quote from: Monviech (Cedrik) on September 29, 2025, 08:14:30 AM10.0.0.300 is not a valid IP address
it only goes up to .255