Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - hushcoden

#1
Not sure if I'm misunderstanding the first post, but nothing changes in my setup when I tweak the MTU in the point-to-point section; the only way I can get an MTU of 1500 is by entering 1508 on the WAN interface instead.
#2
So, I tested twice, first time with MTU = 1500 and second test with MTU = 1508 and in both cases it seems not working as if I type from my Windows laptop ping 1.1.1.1 -f -l 1465 I get 100% packet loss, how come?

The only change I made was in WAN interface -> point-to-point configuration - > Advanced -> Show advanced options -> Link Parameters -> MTU = 150x (and I rebooted the firewall).
#3
I've got my new FTTP connection (PPPoE with no VLAN) and in the WAN interface I can see "Calculated PPP MTU: 1492" and I hope I can bring that value up to 1500.

Reading the first post, I should also set the MTU on my ONT, but I have no access to its GUI, so hopefully it won't be a problem.

The only thing I can do is clicking on the WAN interface -> point-to-point configuration - > Advanced -> Show advanced options -> MTU = 1508

Is that it?

Tia.
#4
26.1 Series / Re: Planning to install v26.1.4
March 14, 2026, 12:08:52 PM
Thanks, and will I have to tweak/change any of the firewall rules at all (including NAT, port-forward/outbound)?
#5
26.1 Series / Planning to install v26.1.4
March 12, 2026, 05:11:26 PM
For sanity check, can I fresh install the latest version and then import the settings via backup file considering I'm running v25.7.11_9 ?

Anything to be aware of?

Tia.
#6
Me again, today I switched to FTTP, but I cannot browse the Internet, and ISP confirmed I don't need any VLAN/Tag.

The interesting thing is as soon as I run the VPN on my laptop, I can browse, whys is that?

I suspect it might be a DNS issue because if SSH to the OPNsense, I can ping any sites with their IP addresses but not by name.

Does it have anything to do with the fact that I now have a static IP?

Can someone help me to understand what the problem may be?

Tia/

Update: after rebooting the ONT and 4 times the OPNsense appliance, it works now.
#7
25.7, 25.10 Series / Re: Need help to configure my FTTP
February 22, 2026, 01:34:45 PM
Thank you, good to know that I just need to change the username and password, and that's it.
#8
25.7, 25.10 Series / Need help to configure my FTTP
February 22, 2026, 01:15:14 PM
I'm currently using an FTTC connection with PPPoE, and in the next few days, I will be switching to FTTP (still PPPoE). I know where to enter the username and password - Interfaces -> Devices -> Point-to-Point - but for the life of me, I can't find where to enter the static IP address the ISP has provided me (along with the subnet mask of 255.255.255.255).

Tia.

P.S. - I'm running OPNsense v25.7.11_9.
#9
Quote from: cs1 on January 08, 2026, 02:47:13 PMIf you want to send any local DNS request to a local Unbound through wireguard to an upstream DNS, the easiest way is to use the documentation for wireguard selective routing (https://docs.opnsense.org/manual/how-tos/wireguard-selective-routing.html) and modify it to only tunnel DNS traffic from any firewall IP to the upstream DNS IPs.
Are you referring to the section "Dealing with DNS Leaks"? If so, which of the 5 points/solutions would you recommend?

Tia.
#10
Quote from: CaptainFrank on October 04, 2025, 02:24:26 PMAm I right in thinking that I need to set the OPNSense WAN interface to use VLAN101, and DHCP for it's IP config?  because (assuming I`m doing it right!), it doesn't seem to work.
VLAN tag must be set in the Draytek modem (as per the guide you linked), and the WAN in OPNsense must be set as DHCP, that's it!
#11
And like OPNenthu, I never changed the default settings... anyways, it's now fixed, but frankly I don't know if it's because of the few times I did reboot the appliance or the crowdsec plugin which I had to remove and to reinstall or something else, thanks.
#12
Not sure, do you see something wrong?

root@hush:/var/etc # cat ntpd.conf

#
# Autogenerated configuration file
#

tinker panic 0
# Orphan mode stratum
tos orphan 12
# Max number of associations
tos maxclock 10


# Upstream Servers
pool 0.opnsense.pool.ntp.org maxpoll 9
pool 1.opnsense.pool.ntp.org maxpoll 9
pool 2.opnsense.pool.ntp.org maxpoll 9
pool 3.opnsense.pool.ntp.org maxpoll 9


statsdir /var/log/ntp
logconfig =syncall +clockall
driftfile /var/db/ntpd.drift
restrict source  kod limited nomodify noquery notrap
restrict default  kod limited nomodify noquery notrap nopeer
restrict -6 default  kod limited nomodify noquery notrap nopeer
restrict 127.0.0.1  kod limited nomodify notrap nopeer
restrict ::1  kod limited nomodify notrap nopeer
#13
25.1, 25.4 Legacy Series / NTP service not starting
April 13, 2025, 10:38:24 AM
I've just updated to 25.1.5_4 and after the reboot the NTP service doesn't start, anybody's seeing a similar behaviour?

I've attached some errors from the log, if it can help.

Tia.
#14
and one more question: could you explain what the Virtual IPs are for ?

Tia.
#15
Thanks both, turns out I had three faulty cables :-) and when tried the forth one (and the newest one), it now negotiates at 1000 Mb/s