Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - tusc

#1
@pmhausen, how would I go about submitting a panic to help troubleshoot what might be causing this? Thanks.
#2
You need to add the following to /boot/loader.conf.local :

sfxge_load="YES"

With that said, I've had issues with my Solarflare card. I have an SFN7122F that doesn't seem to work under Opnsense. Anytime I load the driver in loader.conf and reboot, the system panics after networking starts. The same card works fine under Linux. Seems to be an issue with the sfxge driver under FreeBSD 13.


#3
General Discussion / Uptick in users
March 31, 2021, 06:59:39 AM
This forum has seen an uptick in users since the pfsense exodus and might see some more. Ubiquiti breach worse than they said: https://krebsonsecurity.com/2021/03/whistleblower-ubiquiti-breach-catastrophic/
#4
Cool, I managed to get the kernel module to work, was able to maintain 900Mbit/sec through the tunnel with iperf3 running on the firewall. I have to believe load will be lower if I just route through it.
#5
It looks like removing wireguard-go from the command line removes os-wireguard (which includes the UI interface for wireguard). Any way to remove this dependency?

[root@OPNsense ~]# pkg delete wireguard-go
Checking integrity... done (0 conflicting)
Deinstallation has been requested for the following 2 packages (of 0 packages in the universe):

Installed packages to be REMOVED:
os-wireguard: 1.5
wireguard-go: 0.0.20210323,1

Number of packages to be removed: 2

The operation will free 3 MiB.

Proceed with deinstalling packages? [y/N]
#6
Now that 21.1.4 has released, how do you transition to the kernel wireguard module? Do you have to uninstall wireguard-go first? Thanks.
#7
Any idea when 21.1.4 will ship? :) No worries if you can't say.
#8
@randomwalk,

as MrB stated there's an API available. In fact, a user wrote a solution to automatically create and manage wireguard keys for PIA. This could be the basis for a similar solution for MullVad: https://github.com/FingerlessGlov3s/OPNsensePIAWireguard

#9
The Realtek NIC is more dependent on CPU performance. Have you tried disabling specter and meltdown mitigations? Also, make sure to enable powerd and set to "max" or "hiadaptive". These two make the biggest impact in throughput performance.

https://www.reddit.com/r/OPNsenseFirewall/comments/mascfl/another_pfsense_refugee_slow_wan_throughput_where/
#10
I've been on Metronet for almost 2 years now with no issues but with a static IP. You might call in and ask for their free 1 year static trial option. They sometimes will even reset the trial period for you.
#11
If you're looking for something that's relatively cheap ( ~ $150 on ebay), upgradable, can handle 1Gb link (it has a 3.1GHz CPU) and low power (idles at 10 watts), then check out the HP 290. There's a big thread below on the many use cases. Unfortunately it's not rack mountable but it is a small form factor. It has one 80mm fan but very quiet.

https://forums.serverbuilds.net/t/official-hp-290-p0043w-owners-thread/2829
#13
I'm hitting close to that with a Celeron G4900 on a 1Gb symmetrical link on PIA. I started a thread on this: https://www.reddit.com/r/OPNsenseFirewall/comments/m8qhys/wireguardgo_is_good_enough/
#14
@N0_Klu3, I've set it up where Adguard listens on port 53 and point the upstream DNS to the Unbound DNS server on OPNSense. You just need to change the port Unbound is listening on (e.g. 7553) and update Adguard upstream section accordingly.

This way local IP addresses have name resolution since the DHCP server on OPNsense registers all addresses and returned by Unbound. Hope this helps.

#15
Virtual private networks / Wireguard in FreeBSD 13
March 15, 2021, 11:38:05 PM
https://lists.zx2c4.com/pipermail/wireguard/2021-March/006494.html

Status of wiredguard in FreeBSD 13 and an unflattering opinion by Jason Donenfeld on a certain network company that contracted wireguard in FreeBSD 12. This might explain why some people have complained of kernel panics in PFsense 2.5.