I've just upgraded my instance to 25.1.5_4 and now works.
Thanks, well done!
Thanks, well done!
This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.
Show posts MenuQuote from: franco on April 11, 2025, 09:30:59 AMIf you have a captive portal and reflection enabled there is an issue that is going to be hotfixed in 25.1.5_4.Yes, captive portal is enabled on one of vlans and 1:1 along with port reflection are enabled as well.
Data Channel Offload doesn't support DATA_V1 packets. Upgrade your server to 2.4.5 or newer.
Quote from: dseven on February 25, 2025, 09:12:12 PMThat document is just all kinds of wrong. How stuff like that gets into the official OPNsense docs is beyond my comprehension. smh...Yes, I changed my config completely:
If you want to be able to use IPv6 from your LAN, you will need at least one firewall rule to allow it - similar to the "Default allow LAN to any rule", but for IPv6.
Quote from: dseven on February 25, 2025, 03:22:36 PMWhat does "I can connect to WAN ip6 services" mean? Are you saying that LAN hosts can reach the internet via IPv6, but can't get DNS from, or ping, your OPNsense firewall's LAN IP address? What do your firewall rules for LAN look like?I meant, in LAN:
root@OPNsense:/ # du -mah | sort -rh | head -n 10
37G .
28G ./var
25G ./var/log
16G ./var/log/squid
9.5G ./var/log/squid/access.log
8.0G ./usr
7.8G ./var/log/c-icap/access.log
7.8G ./var/log/c-icap
7.4G ./usr/local
7.0G ./var/log/squid/store.log
Quote from: franco on July 25, 2024, 07:54:37 PMThus I need to migrate to "instances"?
Not going to be in legacy client/server, sorry.
Quote from: franco on July 25, 2024, 07:29:06 PMYes, that restored UDP server...
disable-dco
2024-07-25T19:06:21 Warning openvpn_server9 dco_set_ifmode: failed to set ifmode=00008002: Invalid argument (errno=22)
2024-07-25T19:06:21 Warning openvpn_server9 Failed to create interface ovpns9 (SIOCSIFNAME): File exists (errno=17)
QuoteBut any tests I do via browsers (Safari, Chrome), fail miserably. For example, https://test-ipv6.com/, says there's no ipv6 address discovered.
% dig google.com AAAA
; <<>> DiG 9.10.6 <<>> google.com AAAA
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 4210
;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 1
;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 1232
;; QUESTION SECTION:
;google.com. IN AAAA
;; ANSWER SECTION:
google.com. 40 IN AAAA 2a00:1450:401b:804::200e
;; Query time: 2 msec
;; SERVER: X001:XXX:XXXX:4::1#53(X001:XXX:XXXX:4::1)
;; WHEN: Thu Feb 29 12:00:35 CET 2024
;; MSG SIZE rcvd: 67