Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - Hover

#1
Quote from: dseven on July 06, 2026, 12:22:12 PMhe same problem? In your case, I'd guess a full filesystem, pe
Quote from: dseven on July 06, 2026, 12:22:12 PM
Quote from: Hover on July 06, 2026, 12:10:14 PMI'm having the same problem

Doesn't look like the same problem? In your case, I'd guess a full filesystem, perhaps?

The problem started with the installation of version 26.1.11 (since I do health checks after every major upgrade).


Strangely after installing, base-26.1.11-amd64.txz and kernel-26.1.11-amd64.txz from another source than the OPNsense NL Server the problem disappeared completely.

Broken .txz because of a "overloaded server"? Hash mismatch for:

usr/bin/lldb
usr/lib/libkvm.a
usr/lib/i18n/libHZ.so.5
usr/lib/i18n/libUTF7.so.5
usr/lib/i18n/libVIQR.so.5
usr/lib/i18n/libZW.so.5
usr/lib/i18n/libISO2022.so.5
usr/lib/libalias_smedia.a
usr/lib/libprocstat.a
usr/lib/libzpool.a
usr/lib/libnvpair.a
usr/lib/libprocstat.so.1
usr/include/vm/vm_object.h
usr/include/sys/proc.h
usr/include/sys/imgact.h
usr/include/sys/ptrace.h


Looked very suspicious to me.
#2
Quote from: franco on July 03, 2026, 08:01:26 AMMaybe the main mirror was particularly slow yesterday on release day as people were already updating? Need to keep this under observation in the coming days.


Cheers,
Franco

Will try it with a different mirror than the OPNsense Mirror in .nl (https) and report.
#3
I'm having the same problem:
With the latest update from version 26.1.10 to 26.1.11, I'm having trouble installing base-26.1.11-amd64.txz. I suspect this isn't just happening to me, but to everyone else as well.

***GOT REQUEST TO UPDATE***
Currently running OPNsense 26.1.10 (amd64) at Mon Jul  6 06:45:04 CEST 2026
Updating OPNsense repository catalogue...
OPNsense repository is up to date.
All repositories are up to date.
Updating OPNsense repository catalogue...
OPNsense repository is up to date.
All repositories are up to date.
Checking for upgrades (11 candidates): .......... done
Processing candidates (11 candidates): .......... done
The following 11 package(s) will be affected (of 0 checked):

Installed packages to be UPGRADED:
bind-tools: 9.20.23 -> 9.20.24 [OPNsense]
curl: 8.20.0 -> 8.21.0 [OPNsense]
expat: 2.8.1 -> 2.8.2 [OPNsense]
ldns: 1.9.0 -> 1.9.2 [OPNsense]
lighttpd: 1.4.82 -> 1.4.84 [OPNsense]
opnsense: 26.1.10 -> 26.1.11_6 [OPNsense]
opnsense-update: 26.1.10 -> 26.1.11 [OPNsense]
os-isc-dhcp: 1.0_5 -> 1.0_6 [OPNsense]
php83-phalcon: 5.14.2 -> 5.16.0 [OPNsense]
py313-duckdb: 1.5.3 -> 1.5.4 [OPNsense]
syslog-ng: 4.11.0_2 -> 4.12.0 [OPNsense]

Number of packages to be upgraded: 11

28 MiB to be downloaded.
[1/11] Fetching lighttpd-1.4.84.pkg: .......... done
[2/11] Fetching opnsense-update-26.1.11.pkg: .. done
[3/11] Fetching ldns-1.9.2.pkg: ......... done
[4/11] Fetching os-isc-dhcp-1.0_6.pkg: ... done
[5/11] Fetching bind-tools-9.20.24.pkg: .......... done
[6/11] Fetching syslog-ng-4.12.0.pkg: .......... done
[7/11] Fetching curl-8.21.0.pkg: .......... done
[8/11] Fetching php83-phalcon-5.16.0.pkg: .......... done
[9/11] Fetching opnsense-26.1.11_6.pkg: .......... done
[10/11] Fetching py313-duckdb-1.5.4.pkg: .......... done
[11/11] Fetching expat-2.8.2.pkg: ......... done
Checking integrity... done (0 conflicting)
[1/11] Upgrading bind-tools from 9.20.23 to 9.20.24...
[1/11] Extracting bind-tools-9.20.24: .......... done
[2/11] Upgrading curl from 8.20.0 to 8.21.0...
[2/11] Extracting curl-8.21.0: .......... done
[3/11] Upgrading expat from 2.8.1 to 2.8.2...
[3/11] Extracting expat-2.8.2: .......... done
[4/11] Upgrading ldns from 1.9.0 to 1.9.2...
[4/11] Extracting ldns-1.9.2: .......... done
[5/11] Upgrading lighttpd from 1.4.82 to 1.4.84...
===> Creating groups
Using existing group 'www'
===> Creating users
Using existing user 'www'
[5/11] Extracting lighttpd-1.4.84: .......... done
[6/11] Upgrading opnsense-update from 26.1.10 to 26.1.11...
[6/11] Extracting opnsense-update-26.1.11: .......... done
[7/11] Upgrading os-isc-dhcp from 1.0_5 to 1.0_6...
[7/11] Extracting os-isc-dhcp-1.0_6: .......... done
Stopping configd...done
Starting configd.
Reloading plugin configuration
Flushing all caches...done.
Configuring system logging...done.
Reloading template OPNsense/Syslog: OK
[8/11] Upgrading php83-phalcon from 5.14.2 to 5.16.0...
[8/11] Extracting php83-phalcon-5.16.0: ........ done
[9/11] Upgrading py313-duckdb from 1.5.3 to 1.5.4...
[9/11] Extracting py313-duckdb-1.5.4: .......... done
[10/11] Upgrading syslog-ng from 4.11.0_2 to 4.12.0...
[10/11] Extracting syslog-ng-4.12.0: .......... done
[11/11] Upgrading opnsense from 26.1.10 to 26.1.11_6...
[11/11] Extracting opnsense-26.1.11_6: .......... done
Stopping configd...done
Resetting root shell
Updating /etc/shells
Unhooking from /etc/rc
Unhooking from /etc/rc.shutdown
Updating /etc/shells
Registering root shell
Hooking into /etc/rc
Hooking into /etc/rc.shutdown
Starting configd.
>>> Invoking update script 'refresh.sh'
Migrated OPNsense\Firewall\Filter from 1.0.4 to 1.0.5
Flushing all caches...done.
Writing firmware settings: OPNsense
Writing trust files...done.
Scanning /usr/share/certs/untrusted for certificates...
Scanning /usr/share/certs/trusted for certificates...
Scanning /usr/local/share/certs for certificates...
certctl: No changes to trust store were made.
Writing trust bundles...done.
Configuring login behaviour...done.
Configuring cron...done.
Configuring system logging...done.
You may need to manually remove /usr/local/etc/syslog-ng.conf if it is no longer needed.
=====
Message from opnsense-26.1.11_6:

--
One step ahead, one step behind it, now you gotta run to get even
Checking integrity... done (0 conflicting)
Nothing to do.
Checking all packages: .......... done
The following package files will be deleted:
/var/cache/pkg/lighttpd-1.4.84~7501b26875.pkg
/var/cache/pkg/syslog-ng-4.12.0~7e3f25272b.pkg
/var/cache/pkg/expat-2.8.2.pkg
/var/cache/pkg/opnsense-26.1.11_6~d52b7b0fde.pkg
/var/cache/pkg/py313-duckdb-1.5.4.pkg
/var/cache/pkg/opnsense-26.1.11_6.pkg
/var/cache/pkg/php83-phalcon-5.16.0.pkg
/var/cache/pkg/opnsense-update-26.1.11~3ef18a4908.pkg
/var/cache/pkg/bind-tools-9.20.24~06a130e148.pkg
/var/cache/pkg/ldns-1.9.2.pkg
/var/cache/pkg/os-isc-dhcp-1.0_6~5b8d9139ed.pkg
/var/cache/pkg/curl-8.21.0.pkg
/var/cache/pkg/bind-tools-9.20.24.pkg
/var/cache/pkg/curl-8.21.0~0e3f9b6e02.pkg
/var/cache/pkg/ldns-1.9.2~cc8eba3ed0.pkg
/var/cache/pkg/py313-duckdb-1.5.4~8d0acd924a.pkg
/var/cache/pkg/syslog-ng-4.12.0.pkg
/var/cache/pkg/expat-2.8.2~52f92df3bb.pkg
/var/cache/pkg/lighttpd-1.4.84.pkg
/var/cache/pkg/php83-phalcon-5.16.0~32c71b5484.pkg
/var/cache/pkg/opnsense-update-26.1.11.pkg
/var/cache/pkg/os-isc-dhcp-1.0_6.pkg
The cleanup will free 28 MiB
Deleting files: .......... done
Nothing to do.
Flushing temporary package files... done
Starting web GUI...done.
Fetching base-26.1.11-amd64.txz: ........ done
Fetching kernel-26.1.11-amd64.txz: .... done
!!!!!!!!!!!! ATTENTION !!!!!!!!!!!!!!!
! A critical upgrade is in progress. !
! Please do not turn off the system. !
!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
Installing kernel-26.1.11-amd64.txz... done
Installing base-26.1.11-amd64.txz..../usr/bin/ld.lld: Truncated tar archive detected while reading data: Unknown error: -1
tar: Error exit delayed from previous errors.
 failed, tar error 0
***DONE***

Also, since then, I've encountered some strange errors during the health check.

***GOT REQUEST TO AUDIT HEALTH***
Currently running OPNsense 26.1.11_6 (amd64) at Mon Jul  6 11:44:16 CEST 2026
>>> Root file system: zroot/ROOT/default
>>> Check installed kernel version
Version 26.1.11 is correct.
>>> Check for missing or altered kernel files
No problems detected.
>>> Check installed base version
Version 26.1.10 is incorrect, expected: 26.1.11
>>> Check for missing or altered base files
Error 2 occurred.
usr/bin/lldb:
sha256digest (0x9afbd73a548f72d1271c9c3625905d2843009fd594127adb5bbadf8bbecc6f4b, 0xec7d750bc27bbc44d7c670e6e085a4ae9dd593b1d71fe10c80e411ab635a305e)
usr/lib/libkvm.a:
sha256digest (0xd92e445f6712763c8c09a7a92e12f4033826d8f4d4b3de58c516bcacd5abbbc4, 0x7e2c4733982a857f007c1fc6e6edcda2196f2d493a6c4191f676d55743e6dd2a)
usr/lib/i18n/libHZ.so.5:
sha256digest (0x5438ec95a816ace6968d179e89280448489ed64de79978cf8153e525799230df, 0x80dcf8a50ce8e9f2a06af39d4dbcc8889c7bf6d1e234321cba97ac60679a75a9)
usr/lib/i18n/libUTF7.so.5:
size (9120, 9200)
sha256digest (0x2fff784e753c3b35984124294956d77a61b0a60c7343773e8a82401398ed68dc, 0x40a307fc50cbdf5bc8aa9aaa903c068874dce71ca8141efd0dbee6df12fce7e2)
usr/lib/i18n/libVIQR.so.5:
size (14440, 14088)
sha256digest (0x71b02f481bcac9221a1082e562957ca34dcbf75eacc853d2a2601d3e856f831a, 0xc3dd2674be339843356409a30866e2243e62dcb57dc154f98474c79491d97603)
usr/lib/i18n/libZW.so.5:
size (8256, 8272)
sha256digest (0x2a3590049f76309f0d06ea6b65423bb312283f27c54ecf04771132ff0e5cbe36, 0x76a25a305fb5c629c8832668c3a51b68bd80b1397bb46672030e588d914ceaca)
usr/lib/i18n/libISO2022.so.5:
sha256digest (0xca46587941ce8e9916118caaaade3acab93ca2d7b7a0d3d2b9ca0090d38e48d9, 0x79a325b016e42bc6f675a114ca89f8413fedd039a5c587e986256883b74e7629)
usr/lib/libalias_smedia.a:
size (7216, 7240)
sha256digest (0xbc79e04cd58a0f7d03455d7e2040a45da9ff95ffd6309fc68cf851e285cc00d2, 0x3494fc89280aff4d33c400ae712c34796e191214394d1d6dab58463d9a92b9d5)
usr/lib/libprocstat.a:
sha256digest (0x8677af05554104767cae4d5a0c1a770228892dcb5540ec98164f09f1ff27e621, 0x01c87ecf49b2dedf26279d5300c188d768de03bbbd360794ff613df32ac81b36)
usr/lib/libzpool.a:
size (27097712, 27098832)
sha256digest (0x3e6b58d15035dfdf27eeeef563c02fb435676f9badf23438cfe7738213380b1f, 0xe1e734b3f81ee0bf075aec05e427cad6955e3568b2e456ad1855c5141d90d499)
usr/lib/libnvpair.a:
size (149740, 149812)
sha256digest (0xbac00f093f2c5f00ecd2b7bed760e8c09bd8189979916ab626eb7004c18eea03, 0x6eb660ad78c2abf838f624b44499f5f7603e2fc5163119bf96b6b1d9bec1c0dc)
usr/lib/libprocstat.so.1:
sha256digest (0x8fa046a88d736af9f455b618df9174be289fb83396fc3f6988894a34d414dac9, 0x75e21d106b4c3ffaecd0d79b5689cd5bc0f20731af67a1756c265d6fc3091b61)
usr/include/vm/vm_object.h:
size (14025, 14006)
sha256digest (0xa5403bcab1c3eac25f2e607904533c02c74df685d84abae5f062bf23ace59819, 0x25e8407175213e3d52332c68f81c8b56758bd3dd9e5c7df2c8d69b49cb3d3053)
usr/include/sys/proc.h:
size (55340, 55496)
sha256digest (0xd537232d194203dc1b21b1ba5f2f57f1b64b0aa4bd40c823ff7e4f52d75e0b16, 0xd734301495ef1056fd891c74d97d2de98471e4ba8c8b564c98ff73ba40fc5d83)
usr/include/sys/imgact.h:
size (5280, 5492)
sha256digest (0x1f74b7709f06052648b3d5780a1061f14c28b0385e19d262531b3d35dec674af, 0xe0ea64c2e02726d475752ddf70b421d2815d7395673637d2ccfe69cdc9bb4638)
usr/include/sys/ptrace.h:
size (9934, 10418)
sha256digest (0xa71fd4ca527a14ff66ef6b5464cb422b14e44d15ac5347226c2d82da9ca87820, 0xd9c29dd066bd0f52f6b3f086197b02c042cd5e03b64d4983c54a91c8a0785693)
bin/freebsd-version:
sha256digest (0x5663276f4b94371fba908eb4148bd6469d9f18b3c5916f749a0629e79823bac4, 0x3cedb1e37b0fdec57135aa0fbccdd967db67d087425426d010e5df0ab989edf1)
>>> Check installed repositories
OPNsense (Priority: 11)
>>> Check installed plugins
os-acme-client 4.16_1
os-isc-dhcp 1.0_6
os-theme-rebellion 1.9.4
>>> Check locked packages
No locks found.
>>> Check for missing package dependencies
Checking all packages: .......... done
>>> Check for missing or altered package files
Checking all packages: .........
python313-3.13.14: checksum mismatch for /usr/local/lib/python3.13/__pycache__/typing.cpython-313.pyc
Checking all packages.... done
>>> Check for core packages consistency
Core package "opnsense" at 26.1.11_6 has 68 dependencies to check.
Checking packages: ..................................................................... done
***DONE***


Maybe I'm getting a little too paranoid, but in this era of AI supply chain attacks and widespread discoveries of vulnerabilities in FreeBSD, I probably can't be too careful.


Best regards,
Hover
#4
Ich habe mit dem aktuellen updaten von Version 26.1.10 zu 26.1.11 das Problem base-26.1.11-amd64.txz zu installieren ich vermute das betrifft nicht nur mich sondern auch alle anderen.


***GOT REQUEST TO UPDATE***
Currently running OPNsense 26.1.10 (amd64) at Mon Jul  6 06:45:04 CEST 2026
Updating OPNsense repository catalogue...
OPNsense repository is up to date.
All repositories are up to date.
Updating OPNsense repository catalogue...
OPNsense repository is up to date.
All repositories are up to date.
Checking for upgrades (11 candidates): .......... done
Processing candidates (11 candidates): .......... done
The following 11 package(s) will be affected (of 0 checked):

Installed packages to be UPGRADED:
bind-tools: 9.20.23 -> 9.20.24 [OPNsense]
curl: 8.20.0 -> 8.21.0 [OPNsense]
expat: 2.8.1 -> 2.8.2 [OPNsense]
ldns: 1.9.0 -> 1.9.2 [OPNsense]
lighttpd: 1.4.82 -> 1.4.84 [OPNsense]
opnsense: 26.1.10 -> 26.1.11_6 [OPNsense]
opnsense-update: 26.1.10 -> 26.1.11 [OPNsense]
os-isc-dhcp: 1.0_5 -> 1.0_6 [OPNsense]
php83-phalcon: 5.14.2 -> 5.16.0 [OPNsense]
py313-duckdb: 1.5.3 -> 1.5.4 [OPNsense]
syslog-ng: 4.11.0_2 -> 4.12.0 [OPNsense]

Number of packages to be upgraded: 11

28 MiB to be downloaded.
[1/11] Fetching lighttpd-1.4.84.pkg: .......... done
[2/11] Fetching opnsense-update-26.1.11.pkg: .. done
[3/11] Fetching ldns-1.9.2.pkg: ......... done
[4/11] Fetching os-isc-dhcp-1.0_6.pkg: ... done
[5/11] Fetching bind-tools-9.20.24.pkg: .......... done
[6/11] Fetching syslog-ng-4.12.0.pkg: .......... done
[7/11] Fetching curl-8.21.0.pkg: .......... done
[8/11] Fetching php83-phalcon-5.16.0.pkg: .......... done
[9/11] Fetching opnsense-26.1.11_6.pkg: .......... done
[10/11] Fetching py313-duckdb-1.5.4.pkg: .......... done
[11/11] Fetching expat-2.8.2.pkg: ......... done
Checking integrity... done (0 conflicting)
[1/11] Upgrading bind-tools from 9.20.23 to 9.20.24...
[1/11] Extracting bind-tools-9.20.24: .......... done
[2/11] Upgrading curl from 8.20.0 to 8.21.0...
[2/11] Extracting curl-8.21.0: .......... done
[3/11] Upgrading expat from 2.8.1 to 2.8.2...
[3/11] Extracting expat-2.8.2: .......... done
[4/11] Upgrading ldns from 1.9.0 to 1.9.2...
[4/11] Extracting ldns-1.9.2: .......... done
[5/11] Upgrading lighttpd from 1.4.82 to 1.4.84...
===> Creating groups
Using existing group 'www'
===> Creating users
Using existing user 'www'
[5/11] Extracting lighttpd-1.4.84: .......... done
[6/11] Upgrading opnsense-update from 26.1.10 to 26.1.11...
[6/11] Extracting opnsense-update-26.1.11: .......... done
[7/11] Upgrading os-isc-dhcp from 1.0_5 to 1.0_6...
[7/11] Extracting os-isc-dhcp-1.0_6: .......... done
Stopping configd...done
Starting configd.
Reloading plugin configuration
Flushing all caches...done.
Configuring system logging...done.
Reloading template OPNsense/Syslog: OK
[8/11] Upgrading php83-phalcon from 5.14.2 to 5.16.0...
[8/11] Extracting php83-phalcon-5.16.0: ........ done
[9/11] Upgrading py313-duckdb from 1.5.3 to 1.5.4...
[9/11] Extracting py313-duckdb-1.5.4: .......... done
[10/11] Upgrading syslog-ng from 4.11.0_2 to 4.12.0...
[10/11] Extracting syslog-ng-4.12.0: .......... done
[11/11] Upgrading opnsense from 26.1.10 to 26.1.11_6...
[11/11] Extracting opnsense-26.1.11_6: .......... done
Stopping configd...done
Resetting root shell
Updating /etc/shells
Unhooking from /etc/rc
Unhooking from /etc/rc.shutdown
Updating /etc/shells
Registering root shell
Hooking into /etc/rc
Hooking into /etc/rc.shutdown
Starting configd.
>>> Invoking update script 'refresh.sh'
Migrated OPNsense\Firewall\Filter from 1.0.4 to 1.0.5
Flushing all caches...done.
Writing firmware settings: OPNsense
Writing trust files...done.
Scanning /usr/share/certs/untrusted for certificates...
Scanning /usr/share/certs/trusted for certificates...
Scanning /usr/local/share/certs for certificates...
certctl: No changes to trust store were made.
Writing trust bundles...done.
Configuring login behaviour...done.
Configuring cron...done.
Configuring system logging...done.
You may need to manually remove /usr/local/etc/syslog-ng.conf if it is no longer needed.
=====
Message from opnsense-26.1.11_6:

--
One step ahead, one step behind it, now you gotta run to get even
Checking integrity... done (0 conflicting)
Nothing to do.
Checking all packages: .......... done
The following package files will be deleted:
/var/cache/pkg/lighttpd-1.4.84~7501b26875.pkg
/var/cache/pkg/syslog-ng-4.12.0~7e3f25272b.pkg
/var/cache/pkg/expat-2.8.2.pkg
/var/cache/pkg/opnsense-26.1.11_6~d52b7b0fde.pkg
/var/cache/pkg/py313-duckdb-1.5.4.pkg
/var/cache/pkg/opnsense-26.1.11_6.pkg
/var/cache/pkg/php83-phalcon-5.16.0.pkg
/var/cache/pkg/opnsense-update-26.1.11~3ef18a4908.pkg
/var/cache/pkg/bind-tools-9.20.24~06a130e148.pkg
/var/cache/pkg/ldns-1.9.2.pkg
/var/cache/pkg/os-isc-dhcp-1.0_6~5b8d9139ed.pkg
/var/cache/pkg/curl-8.21.0.pkg
/var/cache/pkg/bind-tools-9.20.24.pkg
/var/cache/pkg/curl-8.21.0~0e3f9b6e02.pkg
/var/cache/pkg/ldns-1.9.2~cc8eba3ed0.pkg
/var/cache/pkg/py313-duckdb-1.5.4~8d0acd924a.pkg
/var/cache/pkg/syslog-ng-4.12.0.pkg
/var/cache/pkg/expat-2.8.2~52f92df3bb.pkg
/var/cache/pkg/lighttpd-1.4.84.pkg
/var/cache/pkg/php83-phalcon-5.16.0~32c71b5484.pkg
/var/cache/pkg/opnsense-update-26.1.11.pkg
/var/cache/pkg/os-isc-dhcp-1.0_6.pkg
The cleanup will free 28 MiB
Deleting files: .......... done
Nothing to do.
Flushing temporary package files... done
Starting web GUI...done.
Fetching base-26.1.11-amd64.txz: ........ done
Fetching kernel-26.1.11-amd64.txz: .... done
!!!!!!!!!!!! ATTENTION !!!!!!!!!!!!!!!
! A critical upgrade is in progress. !
! Please do not turn off the system. !
!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
Installing kernel-26.1.11-amd64.txz... done
Installing base-26.1.11-amd64.txz..../usr/bin/ld.lld: Truncated tar archive detected while reading data: Unknown error: -1
tar: Error exit delayed from previous errors.
 failed, tar error 0
***DONE***

Weiter habe ich seitdem einige seltsame Fehler bei der Intigritätsprüfung (Health Check)

***GOT REQUEST TO AUDIT HEALTH***
Currently running OPNsense 26.1.11_6 (amd64) at Mon Jul  6 11:44:16 CEST 2026
>>> Root file system: zroot/ROOT/default
>>> Check installed kernel version
Version 26.1.11 is correct.
>>> Check for missing or altered kernel files
No problems detected.
>>> Check installed base version
Version 26.1.10 is incorrect, expected: 26.1.11
>>> Check for missing or altered base files
Error 2 occurred.
usr/bin/lldb:
sha256digest (0x9afbd73a548f72d1271c9c3625905d2843009fd594127adb5bbadf8bbecc6f4b, 0xec7d750bc27bbc44d7c670e6e085a4ae9dd593b1d71fe10c80e411ab635a305e)
usr/lib/libkvm.a:
sha256digest (0xd92e445f6712763c8c09a7a92e12f4033826d8f4d4b3de58c516bcacd5abbbc4, 0x7e2c4733982a857f007c1fc6e6edcda2196f2d493a6c4191f676d55743e6dd2a)
usr/lib/i18n/libHZ.so.5:
sha256digest (0x5438ec95a816ace6968d179e89280448489ed64de79978cf8153e525799230df, 0x80dcf8a50ce8e9f2a06af39d4dbcc8889c7bf6d1e234321cba97ac60679a75a9)
usr/lib/i18n/libUTF7.so.5:
size (9120, 9200)
sha256digest (0x2fff784e753c3b35984124294956d77a61b0a60c7343773e8a82401398ed68dc, 0x40a307fc50cbdf5bc8aa9aaa903c068874dce71ca8141efd0dbee6df12fce7e2)
usr/lib/i18n/libVIQR.so.5:
size (14440, 14088)
sha256digest (0x71b02f481bcac9221a1082e562957ca34dcbf75eacc853d2a2601d3e856f831a, 0xc3dd2674be339843356409a30866e2243e62dcb57dc154f98474c79491d97603)
usr/lib/i18n/libZW.so.5:
size (8256, 8272)
sha256digest (0x2a3590049f76309f0d06ea6b65423bb312283f27c54ecf04771132ff0e5cbe36, 0x76a25a305fb5c629c8832668c3a51b68bd80b1397bb46672030e588d914ceaca)
usr/lib/i18n/libISO2022.so.5:
sha256digest (0xca46587941ce8e9916118caaaade3acab93ca2d7b7a0d3d2b9ca0090d38e48d9, 0x79a325b016e42bc6f675a114ca89f8413fedd039a5c587e986256883b74e7629)
usr/lib/libalias_smedia.a:
size (7216, 7240)
sha256digest (0xbc79e04cd58a0f7d03455d7e2040a45da9ff95ffd6309fc68cf851e285cc00d2, 0x3494fc89280aff4d33c400ae712c34796e191214394d1d6dab58463d9a92b9d5)
usr/lib/libprocstat.a:
sha256digest (0x8677af05554104767cae4d5a0c1a770228892dcb5540ec98164f09f1ff27e621, 0x01c87ecf49b2dedf26279d5300c188d768de03bbbd360794ff613df32ac81b36)
usr/lib/libzpool.a:
size (27097712, 27098832)
sha256digest (0x3e6b58d15035dfdf27eeeef563c02fb435676f9badf23438cfe7738213380b1f, 0xe1e734b3f81ee0bf075aec05e427cad6955e3568b2e456ad1855c5141d90d499)
usr/lib/libnvpair.a:
size (149740, 149812)
sha256digest (0xbac00f093f2c5f00ecd2b7bed760e8c09bd8189979916ab626eb7004c18eea03, 0x6eb660ad78c2abf838f624b44499f5f7603e2fc5163119bf96b6b1d9bec1c0dc)
usr/lib/libprocstat.so.1:
sha256digest (0x8fa046a88d736af9f455b618df9174be289fb83396fc3f6988894a34d414dac9, 0x75e21d106b4c3ffaecd0d79b5689cd5bc0f20731af67a1756c265d6fc3091b61)
usr/include/vm/vm_object.h:
size (14025, 14006)
sha256digest (0xa5403bcab1c3eac25f2e607904533c02c74df685d84abae5f062bf23ace59819, 0x25e8407175213e3d52332c68f81c8b56758bd3dd9e5c7df2c8d69b49cb3d3053)
usr/include/sys/proc.h:
size (55340, 55496)
sha256digest (0xd537232d194203dc1b21b1ba5f2f57f1b64b0aa4bd40c823ff7e4f52d75e0b16, 0xd734301495ef1056fd891c74d97d2de98471e4ba8c8b564c98ff73ba40fc5d83)
usr/include/sys/imgact.h:
size (5280, 5492)
sha256digest (0x1f74b7709f06052648b3d5780a1061f14c28b0385e19d262531b3d35dec674af, 0xe0ea64c2e02726d475752ddf70b421d2815d7395673637d2ccfe69cdc9bb4638)
usr/include/sys/ptrace.h:
size (9934, 10418)
sha256digest (0xa71fd4ca527a14ff66ef6b5464cb422b14e44d15ac5347226c2d82da9ca87820, 0xd9c29dd066bd0f52f6b3f086197b02c042cd5e03b64d4983c54a91c8a0785693)
bin/freebsd-version:
sha256digest (0x5663276f4b94371fba908eb4148bd6469d9f18b3c5916f749a0629e79823bac4, 0x3cedb1e37b0fdec57135aa0fbccdd967db67d087425426d010e5df0ab989edf1)
>>> Check installed repositories
OPNsense (Priority: 11)
>>> Check installed plugins
os-acme-client 4.16_1
os-isc-dhcp 1.0_6
os-theme-rebellion 1.9.4
>>> Check locked packages
No locks found.
>>> Check for missing package dependencies
Checking all packages: .......... done
>>> Check for missing or altered package files
Checking all packages: .........
python313-3.13.14: checksum mismatch for /usr/local/lib/python3.13/__pycache__/typing.cpython-313.pyc
Checking all packages.... done
>>> Check for core packages consistency
Core package "opnsense" at 26.1.11_6 has 68 dependencies to check.
Checking packages: ..................................................................... done
***DONE***


Vielleicht werde ich jetzt zu paranoid aber in Zeiten der AI supply chain attacks und massenhaften Funde von vulnerabilities für FreeBSD kann an vielleicht nicht vorsichtig genug sein.

Ich poste auch mal im Englischen Forum.

Best regards,
Hover
#5
German - Deutsch / Re: Wireguard über PPPoE mit Vlan
December 21, 2022, 12:56:24 PM
Hallo pmhausen,

danke Dir, die Oberfläche von dem Vigor 130 sieht etwas anders aus aber vermute mal die Einstellungen werden ähnlich sein.

Frohe Weihnachten und einen guten Rutsch!
Hovy
#6
German - Deutsch / Re: Wireguard über PPPoE mit Vlan
December 21, 2022, 01:28:52 AM
QuoteAllerdings lasse ich immer den Vigor das VLAN Tag setzen.

Ahh, ich denke genau daran wird es liegen, dadurch ändert sich ja einiges an den Firewall-Regeln und soweit ich weiß ist das Wireguard-Go Plugin nur Userspace, das führt natürlich zu weiteren Einschränkungen.


Ich bin seit über 20 Jahren nicht mehr bei der Telekom und die Modems die ich bisher hatte, hatten alle immer direkt PPPoE unterstützt.

Könntest du mir vllt einen Screenshot machen wie du es konfiguriert hast in deinem Vigor 130? Nur um sicher zu gehen? Ich kann da leider gerade nur remote auf die Infrastruktur zugreifen und müsste dann vllt jemanden anweisen das so einzustellen.

LG
Hovy
#7
German - Deutsch / Re: Wireguard über PPPoE mit Vlan
December 19, 2022, 03:03:48 AM
Klar, gerne.

Ich bin im wesentlichen diesem Tutorial gefolgt: https://www.thomas-krenn.com/de/wiki/OPNsense_WireGuard_VPN_f%C3%BCr_Road_Warrior_einrichten#

Ich habe bei mir zuhause selbst ein ähnliches Setup aber bei einem anderen Provider. In dem Fall um den es hier geht wird ein DrayTek Vigor 130 Modem zur Einwahl bei der Deutschen Telekom verwendet. Dafür musste ich leider ein VLAN für das WAN Interface anlegen das die VLAN ID 7 hat. Dadurch sind die Regel für WAN hier auf das VLAN Interface "DrayTekTKom" angewendet worden.

Netzplan
https://ibb.co/vh3LT6j

VLAN Interface für Telekom Einwahl
https://ibb.co/X32C1V8

WG Local Config
https://ibb.co/TRDbSnZ

WG Endpoint Config
https://ibb.co/6RDbqBY

Firewallregeln VLAN
https://ibb.co/cyLgBGs

Firewall Regeln WG Interface [mehr aus Verzweifelung weil ich keine Lösung finde]
https://ibb.co/NFBMqrx

Firewall Regeln WG (Group) [mehr aus Verzweifelung weil ich keine Lösung finde]
https://ibb.co/t3bSYk5

Firewall Regeln WAN [Als Test als ich keine Lösung fand]
https://ibb.co/98KGK6J

Das seltsame ist das ich noch nicht mal einen Handshake laut Wiregurad log kriege aber z.B. die ICMP Regel im WAN VLAN einwandfrei funktioniert wenn ich sie aktiviere. Ich wundere mich etwas da ich ein ziemlich ähnliches Setup hier zuhause habe und auch schon anderorts aufgesetzt habe. Aber noch nie auf einer Telekom Leitung, diese hat sogar eine statische IP und einen TLD subdomain der auf diese zeigt.

Auch die Client configs sind an sich jetzt nicht besonders.
[Interface]
Address = 10.1.0.4/32
PrivateKey = [cut]

[Peer]
PublicKey = [cut]
AllowedIPs = 10.1.0.0/24, 192.168.59.0/24, 192.168.9.0/24
Endpoint = gw.domain.de:51820


In dem Thread hier ging es ja darum das es scheinbar ein Problem mit den CRC Checks oder den MTUs gibt bei Wireguard und einem ähnlichen Setup. Frage ist halt ob das hier ein Bug ist oder ich Tomaten auf den Augen habe.  Initial hatte ich es intuitiv genau so wie in dem oben geschriebenen Tutorial gemacht. Nur eben mit dem VLAN Interface von für das WAN. Kann es sein das es ein generelles Problem mit T-Kom Setup mit Vigor 130 Modem und Wireguard gibt?

Hovy

Edit: Mit OpenVPN habe ich es noch nicht probiert ich war jetzt erstmal irritiert warum es mit Wiregurad nicht geklappt hat.




#8
German - Deutsch / Re: Wireguard über PPPoE mit Vlan
December 17, 2022, 12:08:52 AM
Mittlerweile habe ich noch ein WG Interface für das von dem wireguard-go plugin angelegem Interface angelegt und hier einen Zugriff zu allen Netzen erlaubt (inkl. sich selbst) aber ich kann gar nicht erst eine Verbindung aufbauen.
#9
German - Deutsch / Re: Wireguard über PPPoE mit Vlan
December 16, 2022, 11:33:51 PM
Hallo MenschAergereDichNicht!

Kurze Frage hast Du es noch hinbekommen? Ich habe scheinbar das gleiche oder ein ähnliches Problem.

Ich habe ein Wireguard Setup für die kleine Firma von einem Bekannten eingerichtet, ich habe es genauso gemacht wie hier in der Anleitung: https://www.thomas-krenn.com/de/wiki/OPNsense_WireGuard_VPN_f%C3%BCr_Road_Warrior_einrichten

Allerdings erfuhr ich dann vor Ort, dass eine Telekom DSL Leitung mit einem DrayTek Vigor 130 zum Einsatz kommt. Hier kann man sich nur per PPPoE einwählen, wenn man für das WAN Interface ein VLAN mit dem Tag 7 anlegt. Das war mir vorher so nicht bewusst und hat mir mein remote Administrations-Konzept etwas zerrissen. Ich bekomme es auf absolut nicht hin eine Wiregurad Verbindung zur OPNsense aufzubauen. Erst dachte ich es liegt an meinen Firewall-Regeln (die müssten ja analog zur Anleitung sein nur eben für das angelegte VLAN statt dem WAN Interfacce) aber daran scheint es nicht zu liegen. Mit den MTUs hatte ich jetzt wegen deinem Posting auch noch mal probiert, derzeit habe ich auf dem pppoe-vlan 1492 und für WG 1432. Ebenso mit dem Hardware CRC offloading, das ich auch deaktiviert habe.

Aber wirkt alles nicht und ich sehe das Problem jetzt nicht so ganz.

LG
Hovy
#10
Thanks for the explanation, I  thought that this is the problem. However, this is the first time I have received this message since I started using OPNsense. Wouldn't it make sense to exclude the paths from the package or find another workaround?

I think this can be understood as a bug.

Hovy
#11
***GOT REQUEST TO AUDIT HEALTH***
Currently running OPNsense 22.7.7_1 (amd64/LibreSSL) at Thu Nov 10 18:48:17 CET 2022
>>> Check installed kernel version
Version 22.7.7 is correct.
>>> Check for missing or altered kernel files
No problems detected.
>>> Check installed base version
Version 22.7.7 is correct.
>>> Check for missing or altered base files
No problems detected.
>>> Check installed repositories
OPNsense
>>> Check installed plugins
os-acme-client 3.14
os-dyndns 1.27_3
os-theme-rebellion 1.8.8
os-wireguard-devel 1.13
>>> Check locked packages
No locks found.
>>> Check for missing package dependencies
Checking all packages: .......... done
>>> Check for missing or altered package files
Checking all packages: ........
python39-3.9.15: checksum mismatch for /usr/local/lib/python3.9/__pycache__/io.cpython-39.pyc
python39-3.9.15: checksum mismatch for /usr/local/lib/python3.9/__pycache__/os.cpython-39.pyc
python39-3.9.15: checksum mismatch for /usr/local/lib/python3.9/__pycache__/posixpath.cpython-39.pyc
python39-3.9.15: checksum mismatch for /usr/local/lib/python3.9/__pycache__/re.cpython-39.pyc
python39-3.9.15: checksum mismatch for /usr/local/lib/python3.9/__pycache__/site.cpython-39.pyc
python39-3.9.15: checksum mismatch for /usr/local/lib/python3.9/__pycache__/stat.cpython-39.pyc
python39-3.9.15: checksum mismatch for /usr/local/lib/python3.9/__pycache__/threading.cpython-39.pyc
python39-3.9.15: checksum mismatch for /usr/local/lib/python3.9/__pycache__/token.cpython-39.pyc
python39-3.9.15: checksum mismatch for /usr/local/lib/python3.9/__pycache__/tokenize.cpython-39.pyc
python39-3.9.15: checksum mismatch for /usr/local/lib/python3.9/__pycache__/traceback.cpython-39.pyc
python39-3.9.15: checksum mismatch for /usr/local/lib/python3.9/__pycache__/types.cpython-39.pyc
python39-3.9.15: checksum mismatch for /usr/local/lib/python3.9/__pycache__/typing.cpython-39.pyc
python39-3.9.15: checksum mismatch for /usr/local/lib/python3.9/__pycache__/uu.cpython-39.pyc
python39-3.9.15: checksum mismatch for /usr/local/lib/python3.9/__pycache__/warnings.cpython-39.pyc
python39-3.9.15: checksum mismatch for /usr/local/lib/python3.9/__pycache__/weakref.cpython-39.pyc
Checking all packages..... done
>>> Check for core packages consistency
Core package "opnsense" has 63 dependencies to check.
Checking packages: ................................................................. done
***DONE***
#12
19.7 Legacy Series / Re: OPNsense SSH hardening
October 03, 2019, 10:51:06 PM
Maybe a good issue to report...
#13
19.7 Legacy Series / OPNsense SSH hardening
October 03, 2019, 06:34:12 PM
Hello Folks,

just had a look on the SSH service default configuration and was wondering why it supports so may outdated key, kex and mac algorithms.

Why not hardening it?


$ ssh-audit opnsense
[...]
# algorithm recommendations (for OpenSSH 8.0)
(rec) -diffie-hellman-group14-sha1          -- kex algorithm to remove
(rec) -diffie-hellman-group-exchange-sha256 -- kex algorithm to remove
(rec) -ecdh-sha2-nistp256                   -- kex algorithm to remove
(rec) -ecdh-sha2-nistp384                   -- kex algorithm to remove
(rec) -ecdh-sha2-nistp521                   -- kex algorithm to remove
(rec) -ecdsa-sha2-nistp256                  -- key algorithm to remove
(rec) -hmac-sha1                            -- mac algorithm to remove
(rec) -hmac-sha2-256                        -- mac algorithm to remove
(rec) -hmac-sha2-512                        -- mac algorithm to remove
(rec) -umac-64@openssh.com                  -- mac algorithm to remove
(rec) -umac-128@openssh.com                 -- mac algorithm to remove
(rec) -hmac-sha1-etm@openssh.com            -- mac algorithm to remove
(rec) -umac-64-etm@openssh.com              -- mac algorithm to remove


The argument is probably backwards compatibility, but I thought OPNsens is the firewall for the paranoid ones ;)

Maybe not like here, but in general

Best Regards,
Hover
#14
Quote from: mimugmail on August 06, 2019, 12:55:14 PM
Quote from: l0rdraiden on August 06, 2019, 10:52:07 AM
In 19.7 still this isn't fixed... :-[

Did someone open a bug report via github?
I have around 20 OPNsense Firewalls on most common versions of ESX, HV, KVM, also Hardware. Never had such an issue.

I have the same issue here but with a PCE APU2 Board, everything vanilla expect the new coreboot 4.10.0.1 Bios.

I'm running OPNsense 19.7.4_1-amd64. But this issue only happens on the WebGUI if I use opnsense-update via ssh everything works fine!

Best Regards
#15
Hey OPNsense forum,

Im pretty new her and new to OPNsense and pf as packet filter. I running a PC-Engines APU2 board for my OPNsense setup.
It divides my home office LAN from my private LAN like this:

https://pastebin.com/RYJbjsP0

       
I configured the OPNsense box to do NAT for my private and for Office LAN. I also installed WireGuard on OPNsense so the box can act as an VPN Endpoint.

What I want to do is to setup a second gateway on the OPNsense (10.0.2.254) on the LAN interface and an gateway (10.0.0.254) on the OpenWRT box so the clients can decide if they want to tunnel all their traffic via WireGurad by using the 0.254 gateway or direct internet connection on the 0.1 gateway.

Under Linux this is easy; add an eth0:x device give it a different IP address. The rest can be handled using ip / iprout2 to manage that the the second gateway uses 10.0.2.254 as gateway and this gateway should tunnel everything through 10.0.1.1 to the internet.

I tried to set up things but ended up in somehow breaking (web interface wasn't starting anymore, could not ping 10.0.2.1 anymore)  the configuration of the LAN interface on the OPNsense box, by adding a VLAN to the igb0 interface and giving that VLAN interface a different mac address.

I'm not sure how to achieve what I want on the OPNsense (Hardnend BSD) using the web interface or if there is a problem with my NIC drivers (Intel i210AT)  I have to admit.

I'm running the 19.7 version of OPNsense, because I want to run a WireGuard instance

Can some here help me on fixing my problem.

Best regards,
Hover