Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - payback007

#1
Problem is gone again after migration at my internet provider back to real dual stack configuration. So it seems there was a topic from Unbound with DSlite-stack.
#2
No I'm wondering why I don't get IPv4 and IPv6 with Unbound but I get it with DNSmasq. If the reason is DSlite, I'm fine -> not a missconfiguration. But if there is a reason within my config, I want to fix it ;-)
#3
tested with "nslookup" directly in opnsense_shell as well as with a LAN client. Always same result. At the moment, because of using HAproxy in IPv4 mode, I need to resolve IPv4 address. With DNSmasq all is working as expected. I will try to get the old "real dual stack" configuration again, but if this fails, I will need to switch to IPv6 at least for the part "Internet <-> HAproxy" and will then redirect into local IPv4 network.

And of course "Enable AAAA-only mode" is not checked in Unbound.

Settings in Unbound:
General is checked:
- Enable DNSSEC Support
- Register ISC DHCP4 Leases
- Register DHCP Static Mappings
- TXT Comment Support
- Flush DNS Cache during reload (new, tested today)

Overrides:
nothing

Advanced is checked:
-  Aggressive NSEC

Query forwarding is checked:
- use system nameservers: 208.67.222.222, 208.67.220.220, 8.8.8.8, 8.8.4.4, 4.2.2.1, 4.2.2.2

DNS over TLS is checked:
- use system nameservers: 208.67.222.222, 208.67.220.220, 8.8.8.8, 8.8.4.4, 4.2.2.1, 4.2.2.2
#4
Tested following conditions:

unbound: resolve of google.de -> both records found
unbound: resolve of my own domain -> only AAAA-record (but at Strato A-record and AAAA-record can be seen)

DNSmasq: resolve of google.de -> both records found
DNSmasq: resolve of my own domain -> both records found (same as at Strato can be seen)

IPv4 I only get the special CGN-IP, not the real IP.
#5
Maybe an additional information: could it be caused by a change at internet provider from "real dual stack" to "DS lite"? I just found out, Strato is showing a different IP compared to whatismyIP -> I suppose such a change.
#6
Hi,

I'm using my configuration opnsense 25.7.6/unbound/DynDSN/HAproxy since several years, no change at all. Even no update was done at all the last 2 days. Yesterday I saw, no IPv4 address is resolved any more using nslookup, only IPv6 was reported. Looking at strato DynDNS, A-record and AAAA-record is seen. Also if I do DNS resolve for example against 8.8.8.8 both records are available. If I use DNSmasq for testing, also both records are available and HAproxy is working.

Any idea, why unbound stopped reporting A-record and does only report AAAA-record? As I mentioned, no config change was done the last days.
#7
22.1 Legacy Series / powerD seem not working
June 29, 2022, 11:37:27 PM
Dear all,

I'm trying to enable powerD functionality, but it seems powerD is not working:

from BIOS: CPU frequency 800-2100 MHz possible
P-states: enabled
C-states: enabled
HWP-states: enabled

Mainboard: Supermicro X11SSH-LN4F
CPU: Intel XEON E3-1240L v5

Is there anything I need to enable too?

sysctl dev.cpu.0 show following output:

dev.cpu.0.temperature: 45.0C
dev.cpu.0.coretemp.throttle_log: 0
dev.cpu.0.coretemp.tjmax: 100.0C
dev.cpu.0.coretemp.resolution: 1
dev.cpu.0.coretemp.delta: 55
dev.cpu.0.cx_method: C1/mwait/hwc C2/mwait/hwc C3/mwait/hwc
dev.cpu.0.cx_usage_counters: 313694 0 0
dev.cpu.0.cx_usage: 100.00% 0.00% 0.00% last 335us
dev.cpu.0.cx_lowest: C1
dev.cpu.0.cx_supported: C1/1/1 C2/2/151 C3/3/256
dev.cpu.0.freq_levels: 2100/-1
dev.cpu.0.freq: 2914
dev.cpu.0.%parent: acpi0
dev.cpu.0.%pnpinfo: _HID=none _UID=0 _CID=none
dev.cpu.0.%location: handle=\_PR_.CPU0
dev.cpu.0.%driver: cpu
dev.cpu.0.%desc: ACPI CPU


result: there is only one CPU level. Is there anything wrong in configuration or do I have to enable something different?
#8
German - Deutsch / powerD funktioniert nicht
June 25, 2022, 12:39:39 AM
Hallo zusammen,

ich versuche gerade powerD zu aktivieren, aber es scheint irgendwie nicht zu funktionieren.

lt BIOS: CPU-Tak von 800-2100 MHz möglich
P-States: aktiviert
C-States: aktiviert
HWP-States: aktiviert

Mainboard: Supermicro X11SSH-LN4F
CPU: Intel XEON E3-1240L v5

Ich wüsste nicht, was ich noch einstellen könnte.

sysctl dev.cpu.0 wirft folgendes aus:

dev.cpu.0.temperature: 45.0C
dev.cpu.0.coretemp.throttle_log: 0
dev.cpu.0.coretemp.tjmax: 100.0C
dev.cpu.0.coretemp.resolution: 1
dev.cpu.0.coretemp.delta: 55
dev.cpu.0.cx_method: C1/mwait/hwc C2/mwait/hwc C3/mwait/hwc
dev.cpu.0.cx_usage_counters: 313694 0 0
dev.cpu.0.cx_usage: 100.00% 0.00% 0.00% last 335us
dev.cpu.0.cx_lowest: C1
dev.cpu.0.cx_supported: C1/1/1 C2/2/151 C3/3/256
dev.cpu.0.freq_levels: 2100/-1
dev.cpu.0.freq: 2914
dev.cpu.0.%parent: acpi0
dev.cpu.0.%pnpinfo: _HID=none _UID=0 _CID=none
dev.cpu.0.%location: handle=\_PR_.CPU0
dev.cpu.0.%driver: cpu
dev.cpu.0.%desc: ACPI CPU


Lt. der Ausgabe kann die CPU nicht takten, lt. BIOS aber sehr wohl. Hat jemand eine Idee, an was das liegen könnte?
#9
Even with "netflow off" the CPU usage is still higher than 19.1! I summarized my different trials with the different OPNsense version and I can also confirm with "netflow off" the GUI is reacting faster.

Summary see attachment.
#10
update: now also working for my installation -> I did stop the web proxy, did a reset in GUI as decribed by AndyX90 but then followed this code

https://github.com/opnsense/core/commit/981a718da087b37e4a505b0323967a24bc1d40bc

and what I had to do was to reboot OPNsense. Without reboot squid never came up. After reboot start web proxy without any issues... No idea, what the reboot did exactly changed, but it seems now working stable.
#11
I'm sorry, but also with this explaination it's still not working.
#12
No, no custom directories. Only standard values. It's also no matter of update or fresh install, tried this already. But I did backup the settings, maybe it is related to the settings?
#13
I also see the same issue, increased work load and also in combination with a very slow WebUI... any ideas?

It also seems traffic is abnormally high too.
#14
after upgrade also not working:
- reset by reset button not working
- manual instruction not working

tried with and without reboot, always the same result -> squid not possible to restart.
#15
Hi all,

I installed a well working transparent SSL proxy. It is all working, but I get some errors calling some websites. I think, the CA authority is missing.

Please find attached example if the error coming up in the web browser trying to call the website. Is there any possibiltiy to install the CA authority or is it another failure?

Tanks all for the support!