OPNsense 26.1.2 aarch64 packages and sets released.
This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.
Show posts MenuQuote from: Monviech (Cedrik) on February 11, 2026, 11:52:12 AMDynamic prefixes are not designed to be used at more hops than the exact edge between the "real" ISP and the "real" customer.That's the only point where I'd disagree. DHCPv6-PD is absolutely designed to work over multiple hierarchy levels. And it's further gaining importance with recent developments like RFC 9762 (P flag in RAs) and Android now starting to prefer DHCPv6-PD over SLAAC.
Quote from: jonny5 on February 09, 2026, 07:34:09 PMI'm curious where the configuration/direction for OPNSense's firewall to resolve hosts comes from - which DNS source of truth is it using?Should be whatever is configured in System: Settings: General.
Quote from: OPNenthu on February 06, 2026, 10:48:33 PMUnder System->Settings->General I have "Allow DNS server list to be overridden by DHCP/PPP on WAN" unticked. In that case, does this WAN setting have any effect?The technical difference is that DNS servers are either request via DHCPv6 but then ignored by OPNsense, or they are not requested at all. There are probably very few use cases where this really makes a difference.
Quote from: franco on February 05, 2026, 04:47:40 PMIt's a brave new world since https://github.com/opnsense/dhcp6c/commit/369b4dcf ;)Indeed, optional prefix ID / interface ID for WAN interfaces has proven to be very useful for some uses cases.
Quote from: franco on February 05, 2026, 04:31:44 PMYes but not necessarily on the WAN side.Technically correct, but I've seen so many side effects when the WAN interface itself is left without a GUA that I don't recommend that. Some services really don't like that.
Quote from: nero355 on February 05, 2026, 03:33:48 PMNo. This disables requesting an address via DHCPv6, but it doesn't disable SLAAC. There's currently no way to disable SLAAC on a DHCPv6 interface.Quote from: franco on February 05, 2026, 03:25:21 PMIn some cases there's a bad SLAAC address on the WAN. It's not easy to get rid of it programmatically.Isn't that easily fixed with the setting "Request a Prefix Only" on the WAN Interface ?
Quote from: nero355 on February 05, 2026, 03:33:48 PMUsually you don't need more than that since your OPNsense will use the Link-Local address to communicate with your ISP's Router :)OPNsense needs a GUA as a source address for many local services (DNS resolver, firmware updater etc).