Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - rudiservo

#1
State tables are at ~7K

Max State setting is currently at 1000000

Resolving DNS is the issue, I learned that torrents make a lot of DNS requests, that is probably making unbound very laggy.
#2
I am having sort of an issue with Unbound taking a long time to respond to a query when I turn on qBittorrent.
I tried tweeking Unbound but it hasn't made that much of a difference.

The network is fine, ping is fine, speedtest is fine, qBittorrent has speed limits, its really just unbound taking a long time to respond to a query.
A dig command with @ my router sometimes results in a timeout.

Anyone has any advice on how to deal with this?
#3
Quote from: burntoc on February 01, 2025, 06:56:42 PMWaited 4 days for these guys to give the okay before updating and then - yep - same mongodb errors multiple users here are reporting.  ZA is so frustrating.

EDIT -- Thanks @bandit8623 - your fix eliminated my crash report as well.  When I get some more cycles I'll have to dig deeper to ensure it did actually eliminate the log flood of those messages, but it's promising.

Most of zenarmor upgrade issues I ever had was with databases, usually a reset would work, but recently I put elasticsearch on another machine to lower the load on the router so I had no issues with the upgrade.

I would advice you to try and reset/reinstall zenarmor, but backup your data first if you can, or use and external database.
#4
Quote from: amichel on January 31, 2025, 03:47:56 PM
Quote from: rudiservo on January 31, 2025, 01:00:31 PMIs it safe for those that have external DB?

I can only share that for me, using an external elastic database it works without problems. But I have to admit I am a home user and I can rebuild the box easily (proxmox snapshot).
So in case you use opnsense on a business relevant machine I would recommend waiting for an official announcement.

Already did the upgrade, so far so good, no issues.

I have dedicated hardware for opnsense but all my security SIEM and other security software is on a seperate box, ELK stack, crowdsec, wazuh, etc.
#5
Is it safe for those that have external DB?
#6
24.7, 24.10 Legacy Series / Re: IPv6 Track on Loopback
September 26, 2024, 12:01:23 AM
Thanks Franco.

Not the ideal solution, should I add an issue in github to brainstorm a better solution for this?
#7
24.7, 24.10 Legacy Series / IPv6 Track on Loopback
September 25, 2024, 09:30:07 PM
hey guys, I tried to put a loopback with track interface to use with NPTv6.

At first it kind of worked but then dhcpv6 started throwing some errors

Unsupported device type 24 for "lo1"

here is the full line:

/usr/local/sbin/pluginctl: The command '/usr/local/sbin/dhcpd -6 -user dhcpd -group dhcpd -chroot /var/dhcpd -cf /etc/dhcpdv6.conf -pf /var/run/dhcpdv6.pid vlan0.3.200 lo1' returned exit code '1', the output was 'Internet Systems Consortium DHCP Server 4.4.3-P1 Copyright 2004-2022 Internet Systems Consortium. All rights reserved. For info, please visit https://www.isc.org/software/dhcp/ Config file: /etc/dhcpdv6.conf Database file: /var/db/dhcpd6.leases PID file: /var/run/dhcpdv6.pid Wrote 3 NA, 0 TA, 0 PD leases to lease file. Bound to *:547 Unsupported device type 24 for "lo1" If you think you have received this message due to a bug rather than a configuration issue please read the section on submitting bugs on either our web page at www.isc.org or in the README file before submitting a bug. These pages explain the proper process and the information we find helpful for debugging. exiting.'


It works if I add a VLAN that I do not use, is there a better way of doing this instead of VLAN?

My reason for using track with NPTv6 is the IPv6 /56 is provided dynamically by ISP, this way I can have my local resources always with the same IPv6 and I do not have to change the firewall rules.
#8
I am getting this error on the latest update to 24.1.8

I did confirm, I have 3 different systems and all of them have this issue after the update.


2024-06-07T22:41:11   Error   unbound   [50402:0] error: remote control failed ssl crypto error:0A000415:SSL routines::sslv3 alert certificate expired


OPNsense 24.1.8-amd64
FreeBSD 13.2-RELEASE-p11
OpenSSL 3.0.13

#9
24.1, 24.4 Legacy Series / Re: 24.1 IDS breaks internet
January 31, 2024, 01:17:51 AM
Same here, had to disable it.

Going out on a limb here franco, sorry, I know you are the maintainer of the package, is it compiled with --enable-netmap?

I don't see it in Makefile of the master branch.

https://docs.suricata.io/en/suricata-7.0.2/capture-hardware/netmap.html

"To build Suricata with NETMAP, add --enable-netmap to the configure line. The location of the NETMAP includes (/usr/src/sys/net/) does not have to be specified."
#10
Somehow the upgrade deleted the upstream Gateway.

The system has a fixed IP address on a WAN with vlan.
#11
Not only that, it generates generic rules on all interfaces, do not open stuff where you don't need be open.
#12
It's listening on all of them, some are disabled, can that be an issue?
#13
Did that already twice before, here is the output.

Enter an option: 12

Fetching change log information, please wait... done

This will automatically fetch all available updates and apply them.

Proceed with this action? [y/N]: h

>>> Check installed kernel version
Version 23.7.1 is correct.
>>> Check for missing or altered kernel files
No problems detected.
>>> Check installed base version
Version 23.7.1 is correct.
>>> Check for missing or altered base files
No problems detected.
>>> Check installed repositories
SunnyValley
OPNsense
>>> Check installed plugins
os-acme-client 3.19
os-ddclient 1.14
os-frr 1.34_1
os-hw-probe 1.0_1
os-mdns-repeater 1.1
os-nginx 1.32.1_3
os-sensei 1.14.3
os-sensei-updater 1.14
os-smart 2.2_2
os-sunnyvalley 1.2_3
os-theme-vicuna 1.45
os-upnp 1.5_3
os-wol 2.4_1
os-zerotier 1.3.2_4
>>> Check locked packages
No locks found.
>>> Check for missing package dependencies
Checking all packages: .......... done
>>> Check for missing or altered package files
Checking all packages: .......... done
>>> Check for core packages consistency
Core package "opnsense" has 67 dependencies to check.
Checking packages: .................................................................... done

Press any key to return to menu.
#14
I dont know why but I have one machine that is having issues with creating the socket.

I have checked the logs for it I cant find who or where creates the link to /var/run/php-webgui.socket and why it fails

The lighthttpd just complains about the socker is non existent

******************** lighttpd 95143 - [meta sequenceId="3"] (/usr/obj/usr/ports/www/lighttpd/work/lighttpd-1.4.71/src/gw_backend.c.281) establishing connection failed: socket: unix:/tmp/php-fastcgi.socket-0: No such file or directory


Does anyone have any idea why this happens?
#15
I was able to fix it, I had to reset to factory defaults.

It's in the uninstall tab.

Nonetheless there is another issue, even if you haverouted native netmap, ZA will use emulated netmap.
It's in the Opnsense general logs (debug)