Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - mic

#1
26.7 Series / High CPU usage after upgrade to 26.7.1_1
August 10, 2026, 03:29:43 PM
Hello,

after updating to 26.7.1_1, I'm experiencing high CPU (Intel N355 and 16 GB RAM) usage and can't figure out what's causing it. Below are the outputs of some commands:

root@opnsense:~ # ps auxww | sort -rnk3 | head -20
root       11 433.4  0.0       0     128  -  RNL  15:02   46:37.01 [idle]
root    48076  64.7  0.1   38432   22836  -  R    15:11    0:02.71 /sbin/pfctl -t Bad_Nations -T replace -f /var/db/aliastables/Bad_Nations.txt
root    80207  40.7  3.3  692700  546892  -  S    15:11    0:18.02 /usr/local/bin/python3 /usr/local/opnsense/scripts/filter/update_tables.py --quick (python3.13)
root    62235  11.5  0.3   91024   55620  -  R    15:11    0:01.23 /usr/local/bin/php /usr/local/sbin/pluginctl -S
root    61976  11.5  0.3   91024   55836  -  R    15:11    0:01.26 /usr/local/bin/php /usr/local/sbin/pluginctl -S
root        0   8.6  0.0       0    3552  -  DLs  15:02    3:13.13 [kernel]
root    56231   6.2  0.1   26036   11860  -  S    15:05    0:05.23 /usr/local/sbin/lighttpd -f /usr/local/etc/lighttpd_webgui/lighttpd.conf
root    74333   5.0  0.1   25236   10520  -  S    15:05    0:09.69 sshd-session: root@pts/0 (sshd-session)
root    34690   4.7  1.0 1597168  157680  -  S    15:05    1:12.01 /usr/local/bin/crowdsec -c /usr/local/etc/crowdsec/config.yaml
root      616   4.0  0.3  131584   54020  -  S    15:02    0:42.93 /usr/local/bin/python3 /usr/local/opnsense/service/configd.py console (python3.13)
root    67491   3.0  0.3  211860   52252  -  S    15:06    0:01.50 /usr/local/bin/php-cgi
root    56864   1.2  0.3  211860   50000  -  S    15:05    0:02.82 /usr/local/bin/php-cgi
root    57188   0.6  0.3  211860   49964  -  S    15:05    0:03.13 /usr/local/bin/php-cgi
root    84395   0.5  0.3  206740   48388  -  S    15:07    0:00.30 /usr/local/bin/php-cgi
root    57090   0.5  0.3  206740   45532  -  S    15:05    0:01.46 /usr/local/bin/php-cgi
root    84354   0.4  0.3  211860   49000  -  S    15:07    0:02.18 /usr/local/bin/php-cgi
root    67847   0.4  0.3  218004   54440  -  S    15:06    0:01.57 /usr/local/bin/php-cgi
root    56733   0.4  0.3  206884   47576  -  S    15:05    0:02.27 /usr/local/bin/php-cgi
root    10892   0.3  0.1   48048   16636  -  Ss   15:04    0:04.21 /usr/local/sbin/syslog-ng -f /usr/local/etc/syslog-ng.conf -p /var/run/syslog-ng.pid
unbound 85591   0.2  0.4  140880   72956  -  Is   15:05    0:02.58 /usr/local/sbin/unbound -c /var/unbound/unbound.conf

root@opnsense:~ # vmstat -i
interrupt                          total       rate
irq4: uart0                          758          1
cpu0:timer                        282474        480
cpu1:timer                        297565        505
cpu2:timer                        261579        444
cpu3:timer                        270483        459
cpu4:timer                        289978        493
cpu5:timer                        283443        481
cpu6:timer                        306429        520
cpu7:timer                        275806        468
irq129: xhci1                        642          1
irq148: igc0:rxq0                   1191          2
irq149: igc0:rxq1                   3331          6
irq150: igc0:rxq2                  12971         22
irq151: igc0:rxq3                   1095          2
irq152: igc0:aq                        2          0
irq153: igc1:rxq0                   1052          2
irq154: igc1:rxq1                    564          1
irq155: igc1:rxq2                    972          2
irq156: igc1:rxq3                    407          1
irq157: igc1:aq                        2          0
irq163: igc3:rxq0                    240          0
irq164: igc3:rxq1                    283          0
irq165: igc3:rxq2                    133          0
irq166: igc3:rxq3                    138          0
irq167: igc3:aq                        2          0
irq168: nvme0:admin                   25          0
irq169: nvme0:io0                   2130          4
irq170: nvme0:io1                   2126          4
irq171: nvme0:io2                   2022          3
irq172: nvme0:io3                   1757          3
irq173: nvme0:io4                   1967          3
irq174: nvme0:io5                   2223          4
irq175: nvme0:io6                   1872          3
irq176: nvme0:io7                   1902          3
irq177: hdac0                         15          0

root@opnsense:~ # systat -vmstat 1
    1 users    Load  3.63  3.93  2.36                  Aug 10 15:12:48
   Mem usage:  24%Phy  9%Kmem                           VN PAGER   SWAP PAGER
Mem:      REAL           VIRTUAL                        in   out     in   out
       Tot   Share     Tot    Share     Free   count     
Act  1955M    170M   4616G     307M   11954M   pages
All  1959M    174M   4616G     360M                       ioflt  Interrupts
Proc:                                                3388 cow    2998 total
  r   p   d    s   w   Csw  Trp  Sys  Int  Sof  Flt   11K zfod        uart0 4
  5          138        2K  15K  12K   50    6  16K       ozfod   405 cpu0:timer
                                                         %ozfod   318 cpu1:timer
 8.8%Sys   0.0%Intr 17.8%User  0.0%Nice 73.4%Idle         daefr   233 cpu2:timer
|    |    |    |    |    |    |    |    |    |    |   15K prcfr   406 cpu3:timer
====>>>>>>>>>                                         33K totfr   426 cpu4:timer
                                           dtbuf          react   346 cpu5:timer
Namei     Name-cache   Dir-cache    573310 maxvn          pdwak   324 cpu6:timer
   Calls    hits   %    hits   %     48156 numvn      584 pdpgs   490 cpu7:timer
    7745    7727 100                 24948 frevn        7 intrn       xhci1 129
                                                    1573M wire        igc0:rxq0
Disks  nda0 pass0                                   1358M act       7 igc0:rxq1
KB/t   0.00  0.00                                    798M inact    42 igc0:rxq2
tps       0     0                                       0 laund       igc0:rxq3
MB/s   0.00  0.00                                     12G free        igc0:aq
%busy     0     0                                     57K buf       1 igc1:rxq0
                                                                      igc1:rxq1
                                                                      igc1:rxq2
                                                                      igc1:rxq3
                                                                      igc1:aq
                                                                      igc3:rxq0
                                                                      igc3:rxq1
                                                                      igc3:rxq2
                                                                      igc3:rxq3
                                                                      igc3:aq
                                                                      nvme0:admi
                                                                      nvme0:io0
                                                                      nvme0:io1
                                                                      nvme0:io2
                                                                      nvme0:io3
                                                                      nvme0:io4
                                                                      nvme0:io5
                                                                      nvme0:io6
                                                                      nvme0:io7
                                                                      hdac0 177


root@opnsense:~ # gstat -p                                     
dT: 1.002s  w: 1.000s
 L(q)  ops/s    r/s   kBps   ms/r    w/s   kBps   ms/w   %busy Name
    0      0      0      0  0.000      0      0  0.000    0.0| nda0

root@opnsense:~ # top -m io
last pid: 56452;  load averages:    4.44,    4.22,    2.66
76 processes:  4 running, 72 sleeping
CPU: 19.4% user,  0.0% nice,  9.2% system,  0.0% interrupt, 71.4% idle
Mem: 1362M Active, 823M Inact, 1577M Wired, 56K Buf, 12G Free
ARC: 572M Total, 258M MFU, 267M MRU, 8256K Anon, 3092K Header, 36M Other
     468M Compressed, 910M Uncompressed, 1.94:1 Ratio
Swap: 8192M Total, 8192M Free

  PID USERNAME     VCSW  IVCSW   READ  WRITE  FAULT  TOTAL PERCENT COMMAND
  616 root         125      2      0      0      0      0   0.00% python3.13
57299 root           6      2      0      0      0      0   0.00% php-cgi
84516 root           2      1      0      0      0      0   0.00% php-cgi
67739 root           4      0      0      0      0      0   0.00% php-cgi
34690 root         563      1      0      0      0      0   0.00% crowdsec
84354 root           3      2      0      0      0      0   0.00% php-cgi
10892 root          61      1      0     12      0     12  57.14% syslog-ng
84395 root           3      0      0      1      0      1   4.76% php-cgi
67847 root           3      0      0      0      0      0   0.00% php-cgi
57361 root          12      0      0      0      0      0   0.00% php
25315 root          10      0      0      0      0      0   0.00% python3.13
93597 root           2      0      0      0      0      0   0.00% top
56231 root          11      7      0      0      0      0   0.00% lighttpd
51724 hostd         29      0      0      8      0      8  38.10% hostwatch
87391 root           4      0      0      0      0      0   0.00% python3.13
44522 root           3      0      0      0      0      0   0.00% zenarmor-agent-supe
56864 root           6      0      0      0      0      0   0.00% php-cgi
24927 root           4      0      0      0      0      0   0.00% python3.13
87964 root           4      0      0      0      0      0   0.00% iostat
79913 root           8      0      0      0      0      0   0.00% powerd
74333 root           2      0      0      0      0      0   0.00% sshd-session
56968 root           4      0      0      0      0      0   0.00% php-cgi
59359 root           2      0      0      0      0      0   0.00% ntpd
16075 root           2      0      0      0      0      0   0.00% kea-dhcp4
58289 root           2      0      0      0      0      0   0.00% filterlog
56697 clamav         0      0      0      0      0      0   0.00% clamd
  608 root           0      0      0      0      0      0   0.00% python3.13
67404 root           0      0      0      0      0      0   0.00% php-cgi
57188 root           0      0      0      0      0      0   0.00% php-cgi
67630 root           0      0      0      0      0      0   0.00% php-cgi
41184 root           0      0      0      0      0      0   0.00% crowdsec-firewall-b
56733 root           0      0      0      0      0      0   0.00% php-cgi
67491 root           0      0      0      0      0      0   0.00% php-cgi
56701 root           0      0      0      0      0      0   0.00% php-cgi
85591 unbound        0      0      0      0      0      0   0.00% unbound
57090 root           0      0      0      0      0      0   0.00% php-cgi
57279 root           0      0      0      0      0      0   0.00% php-cgi
84740 root           0      0      0      0      0      0   0.00% php-cgi
57530 root           0      0      0      0      0      0   0.00% php-cgi
56300 root           0      0      0      0      0      0   0.00% php-cgi
56540 root           0      0      0      0      0      0   0.00% php-cgi
56432 root           0      0      0      0      0      0   0.00% php-cgi
84196 root           0      0      0      0      0      0   0.00% php-cgi
67034 root           0      0      0      0      0      0   0.00% php-cgi
56024 root           1      3      0      0      0      0   0.00% php
79031 root           0      0      0      0      0      0   0.00% csh
56392 root           1      2      0      0      0      0   0.00% php
56452 root           1      2      0      0      0      0   0.00% php
 4000 root           0      0      0      0      0      0   0.00% devd
71193 root           0      0      0      0      0      0   0.00% sshd-session
43625 root           0      0      0      0      0      0   0.00% cron
28841 _dhcp          0      0      0      0      0      0   0.00% dhclient

Can you help me, please?

Thank you

PS: I use ipinfo as GEOIP
PS2: I've noticed, using the top command, that Python 3.13 often takes up over 90% of the CPU (WCPU column in top).
PS3: I've noticed also that "/usr/local/bin/python3 /usr/local/opnsense/scripts/filter/update_tables.py --quick" is using high percent of CUP
#2
Ok I follow this steps:

1. Check bootloader version:

root@firewall:~ # strings /boot/efi/efi/boot/bootx64.efi | grep "Revision"
DFreeBSD/amd64 EFI loader, Revision 3.0

2. Show partition with fstab and be careful to /dev/ada0p3:

root@firewall:~ # cat /etc/fstab
# Device                Mountpoint      FStype  Options         Dump    Pass#
/dev/gpt/efiboot0               /boot/efi       msdosfs rw              2       2
/dev/ada0p3             none    swap    sw              0       0

3. Show Partition:
root@firewall:~ # gpart show
=>       40  488397088  nda0  GPT  (233G)
         40     532480     1  efi  (260M)
     532520       1024     2  freebsd-boot  (512K)
     533544        984        - free -  (492K)
     534528   16777216     3  freebsd-swap  (8.0G)
   17311744  471085056     4  freebsd-zfs  (225G)
  488396800        328        - free -  (164K)

4. Uninstall os-cpu-microcode-* plugin

5. Reboot

6. upgrade to 26.7.1_1

7. Update bootloader:

root@firewall:~ # mkdir -p /boot/efi/efi/boot /boot/efi/efi/freebsd
root@firewall:~ # cp /boot/loader.efi /boot/efi/efi/boot/bootx64.efi
root@firewall:~ # cp /boot/loader.efi /boot/efi/efi/freebsd/loader.efi
root@firewall:~ # gpart bootcode -b /boot/pmbr -p /boot/gptzfsboot -i 2 ada0
partcode written to ada0p2
bootcode written to ada0
root@firewall:~ #


8. Reboot

9. Install os-cpu-microcode-* plugin


Now, do I have to ad the following lines to /boot/loader.conf before reboot?

cpu_microcode_load="YES"
cpu_microcode_name="/boot/firmware/intel-ucode.bin"

Thank you
#3
Hello,

just to recap, these are the steps in the correct order:

  • uninstall os-cpu-microcode-* plugin
  • upgrade to 26.7.1
  • update your boot loader
  • install 26.7.1, os-cpu-microcode-* plugin

My OPNsense version is: 26.1.11_10 and bootloader is:
DFreeBSD/amd64 EFI loader, Revision 3.0

Now the question is: what are the exact steps to update the bootloader?

Thank you
#4
26.1, 26,4 Series / Re: Suricata - Divert (IPS)
May 07, 2026, 05:09:33 PM
Hello,

in case of Destination NAT (formerly Port Forward), where should I configure divert-to? I think in the rule associated with the Destination NAT rule, which must be created manually on the WAN interface?

Thank you

Michele
#5
Hello,

we're trying to upgrade OPNsense 26.1.2_5 to 26.1.3, but we're getting the following error, as per the attachment: "Could not find the repository on the selected mirror." This is most likely caused by the SunnyValley repositories.

How can I fix this?

Thank you very much.
#6
Hello,

I have the same problem, after one or two hours the traffic stops, but the Tunnel (phase 1 and 2) is up. Attached yoc can find screenshosts of configuration.

Thank you
#7
bartjsmit you are right!  ;D

This is my configuration.

Firewall A

VXLAN
Quote
VNI: 100200
Source Address: a.a.a.a
Source port: 5248
Remote address: b.b.b.b
Remote port: 5248
Multicast group: none
Device: none

I assigned (without IP address) and activated an interface using as device VXLAN_100200
I created a bridge with members VXLAN_200 and VLAN_200
On WAN interface:
Quote
Protocol: IPv4 UDP
Source: b.b.b.b
Destination: a.a.a.a (WAN Address)
Destination port: 5248

Firewall B

VXLAN:
Quote
VNI: 100200
Source Address: b.b.b.b
Source port: 5248
Remote address: a.a.a.a
Remote port: 5248
Multicast group: none
Device: none

I assigned (without IP address) and activated an interface using as device VXLAN_100200
On Firewall B I have no VLANs to associate with VXLAN 100200

On WAN interface:
Quote
Protocol: IPv4 UDP
Source: a.a.a.a
Destination: b.b.b.b (WAN Address)
Destination port: 5248

On both Firewall in rules for VXLAN interface I add only one rule, permit any to any

First of all, I think there is some missing configuration on Firewall B...

Thank you
#8
Virtual private networks / VXLAN between two OPNsense
August 28, 2024, 11:50:47 AM
Hi,

I need to configure VXLAN between two OPNsense. This is my situation
OPNsense A as a phisical Firewall in head office
Quote
IP Public: a.a.a.a
LAN 1: 192.168.100.1/24
VLAN 200: 192.168.200.1/24
VLAN 210: 192.168.210.1/24
VLAN 220: 192.168.220.1/24

OPNSense B as VM in a DC:
Quote
IP Public: b.b.b.b
LAN 1: 192.168.2.1/24

Mi goal is to transport VLANs 200, 210 and 220 of Firewall A to Firewall B in DC so as to allow VLANs 200, 210 and 220 to surf the Internet through Firewall B using its IP Public b.b.b.b .

For various reasons I cannot use any other VPN than VXLAN

I tried some configuration but without luck.

Could you help me, please?

Thank you
#9
Hi,

the solution proposed by doktornotor works!

Thank you
#10
Hello,

after some attempts I found a workaround. The problem is that OPNsense does not load the mlx4en module at startup even though the command mlx4en_load="YES" is present in the file /boot/loader.conf.local. A workaround is to create in
/usr/local/etc/rc.syshook.d/early/

the file
16-mlx4en-load

with the following content:

#!/bin/sh
kldload mlx4en


Now you have to set execute permissions to the file:
chmod +x 16-mlx4en-load

The last step is to reboot the system.

I hope this workaround can help someone

#11
Hello,

I have a AOC-MCX312C-XCCT (2 x 10 Gb SPP+) installed on a Supermicro AS-5019D-FTN4 and after update to 24.7 the ports do not work anymore. I tried the following actions:


  • Remove from /boot/loader.conf.local the only row with mlx4en_load="YES"
  • Reboot
  • Load mlx4en with kldload mlx4en
  • Reload all interfaces with configctl interface reconfigure <interface_name>

My interfaces are lagg0 and 3 VLANs so to reload interfaces I run the following commands:

  • configctl interface reconfigure lagg0
  • configctl interface reconfigure lagg0_vlan20
  • configctl interface reconfigure lagg0_vlan3
  • configctl interface reconfigure lagg0_vlan9

After all these steps the interfaces do not work....

This is the message at boot time (before I load the module):

This is the messages at boot time:
Quotemlx4_core0: <mlx4_core> mem 0xef800000-0xef8fffff,0x1fff8000000-0x1ffffffffff irq 54 at device 0.0 on pci4
mlx4_core: Mellanox ConnectX core driver v3.7.1 (November 2021)
mlx4_core: Initializing 0000:04:00.0
mlx4_core0: Unable to determine PCI device chain minimum BW
intsmb0: <AMD FCH SMBus Controller> at device 20.0 on pci0
smbus0: <System Management Bus> on intsmb0
ig4iic0: <Designware I2C Controller> iomem 0xfedc2000-0xfedc2fff irq 10 on acpi0
iicbus0: <Philips I2C bus (ACPI-hinted)> on ig4iic0
ig4iic1: <Designware I2C Controller> iomem 0xfedc3000-0xfedc3fff irq 11 on acpi0
iicbus1: <Philips I2C bus (ACPI-hinted)> on ig4iic1
ig4iic2: <Designware I2C Controller> iomem 0xfedc4000-0xfedc4fff irq 12 on acpi0
iicbus2: <Philips I2C bus (ACPI-hinted)> on ig4iic2
ig4iic3: <Designware I2C Controller> iomem 0xfedc5000-0xfedc5fff irq 13 on acpi0
iicbus3: <Philips I2C bus (ACPI-hinted)> on ig4iic3
ig4iic4: <Designware I2C Controller> iomem 0xfedc6000-0xfedc6fff irq 14 on acpi0
iicbus4: <Philips I2C bus (ACPI-hinted)> on ig4iic4
ig4iic5: <Designware I2C Controller> iomem 0xfedcb000-0xfedcbfff irq 15 on acpi0
iicbus5: <Philips I2C bus (ACPI-hinted)> on ig4iic5
driver bug: Unable to set devclass (class: ppc devname: (unknown))

Could you help me, please?

Thank you
#12
Virtual private networks / Wireguard 2 WANs IP
July 26, 2024, 05:22:02 PM
Hello,

I have the following configuration:

  • Virtualized OPNSense in a DC witn 1 Static Public IP: a.b.c.d
  • An Hardware OPNSense in the Customer Headquarter with 2 WAN (different ISPs) Connections and therefore 2 WANs IPs Addresses (say e.f.g.h and i.j.k.l)
Now in the Customer HQ the first WAN Connection is the primary and the second WAN is the backup. I configured a Wireguard tunnel between DC OPNSense and HQ OPNSense using as peer endpoint IP address (in DC OPNSense) e.f.g.h (primary WAN IP of the HQ OPNSense). Now if the primary WAN connection of the HQ goes down also the Wireguard tunnel goes down because, in the Virtual OPNSense in DC, Wireguard endpoint peer address is set to e.f.g.h (primary WAN  IP address of HQ Connection).
Now the question is: how can I configure, in Virtual OPNSense in DC, a second endpoint peer address ( i.j.k.l) as backup, so if the HQ primary WAN ISP goes down the Wireguard tunnel switch versus the secondary WAN using as peer endopint IP address i.j.k.l ?

Thank you
#13
Hi Franco,

I sent you the unbound section of config.xml via email.

Thak you
#14
@Franco

Hi,

I have the same issue, after upgrade to 23.7.3 Unboud was disabled so I enable it but all my overrides dosn't work.
I run the following command:
/usr/local/opnsense/mvc/script/run_migrations.php

** OPNsense\Unbound\Unbound Migration failed, check log for details


and then
opnsense-log | grep run_migrations

<147>1 2023-09-13T08:23:04+02:00 localhost config 2076 - [meta sequenceId="29"] #1 /usr/local/opnsense/mvc/script/run_migrations.php(54): OPNsense\Base\BaseModel->runMigrations()
<147>1 2023-09-13T08:27:54+02:00 opnsense-casa.proximanet.net config 80369 - [meta sequenceId="8"] #1 /usr/local/opnsense/mvc/script/run_migrations.php(54): OPNsense\Base\BaseModel->runMigrations()
<147>1 2023-09-13T09:56:22+02:00 opnsense-casa.proximanet.net config 50858 - [meta sequenceId="6"] #1 /usr/local/opnsense/mvc/script/run_migrations.php(54): OPNsense\Base\BaseModel->runMigrations()


Then I tried also to enable the access list and insert my subnets, but it still doesn't work...

Can you help me, please?

Thank you
#15
Hi to all,

I know this topic has been covered before, but I would like to know if there is any forecast if this feature will be implemented and if so when. The functionality I'm talking about is that the DHCP Server is able to release, and reserve, IPs even for remote Subnets not directly connected to OPNSense. These requests all arrive over the same interface from remote routers, say cisco, which use the dhcp-relay feature. OPNsense, based on the IP of the cisco router that sends the request, responds to the latter by issuing a valid IP.

Thank you