Hello community,
I need a some help to find a solution the following issue:
My opnsense WAN-Interface crashes today, so that no connection could be established from inside or outside.
Its the firs time after years, I had this issue.
Its a new opnsense installation (30 days old) with an imported config from another working opnsense.
It runs without problems up to today.
Infos:
- config: internet => modem (fritzbox 7490) => opnsense (apu4d) => multiple
- I see the unbound LOG process uses 60% from the 4GB physical ram.
- the last 5000 mails (there are not imported, all are from the last 30 days) shows the same messages like:
*
Code Select
subject cron root@opnsense (sbin/pfctl -t 'virusprot' -T expire 3600) > /dev/nullsee:
Code Select
root:$ mail
:5
Message 5:
From root@OPNsense.internal Mon Oct 6 22:45:00 2025
From: Cron Daemon <root@OPNsense.internal>
To: root
Subject: Cron <root@OPNsense> (/sbin/pfctl -t 'virusprot' -T expire '3600') > /dev/null
X-Cron-Env: <SHELL=/bin/sh>
X-Cron-Env: <PATH=/etc:/bin:/sbin:/usr/bin:/usr/sbin:/usr/local/bin:/usr/local/sbin>
X-Cron-Env: <REQUESTS_CA_BUNDLE=/usr/local/etc/ssl/cert.pem>
X-Cron-Env: <LOGNAME=root>
X-Cron-Env: <USER=root>
Date: Mon, 06 Oct 2025 22:45:00 +0000
0/0 addresses expired.
& 5200
5200: Invalid message number
& 5150
Message 5150:
From root@OPNsense.intern Fri Nov 7 15:00:00 2025
From: Cron Daemon <root@OPNsense.intern>
To: root
Subject: Cron <root@OPNsense> (/sbin/pfctl -t 'sshlockout' -T expire '3600') > /dev/null
X-Cron-Env: <SHELL=/bin/sh>
X-Cron-Env: <PATH=/etc:/bin:/sbin:/usr/bin:/usr/sbin:/usr/local/bin:/usr/local/sbin>
X-Cron-Env: <REQUESTS_CA_BUNDLE=/usr/local/etc/ssl/cert.pem>
X-Cron-Env: <LOGNAME=root>
X-Cron-Env: <USER=root>
Date: Fri, 07 Nov 2025 15:00:00 +0100
0/0 addresses expired.
& 5170
5170: Invalid message number
& 5160
Message 5160:
From root@OPNsense.intern Fri Nov 7 16:15:00 2025
From: Cron Daemon <root@OPNsense.intern>
To: root
Subject: Cron <root@OPNsense> (/sbin/pfctl -t 'sshlockout' -T expire '3600') > /dev/null
X-Cron-Env: <SHELL=/bin/sh>
X-Cron-Env: <PATH=/etc:/bin:/sbin:/usr/bin:/usr/sbin:/usr/local/bin:/usr/local/sbin>
X-Cron-Env: <REQUESTS_CA_BUNDLE=/usr/local/etc/ssl/cert.pem>
X-Cron-Env: <LOGNAME=root>
X-Cron-Env: <USER=root>
Date: Fri, 07 Nov 2025 16:15:00 +0100
0/0 addresses expired.
& 590
Message 590:
From root@OPNsense.intern Fri Oct 10 01:00:00 2025
From: Cron Daemon <root@OPNsense.intern>
To: root
Subject: Cron <root@OPNsense> (/sbin/pfctl -t 'virusprot' -T expire '3600') > /dev/null
X-Cron-Env: <SHELL=/bin/sh>
X-Cron-Env: <PATH=/etc:/bin:/sbin:/usr/bin:/usr/sbin:/usr/local/bin:/usr/local/sbin>
X-Cron-Env: <REQUESTS_CA_BUNDLE=/usr/local/etc/ssl/cert.pem>
X-Cron-Env: <LOGNAME=root>
X-Cron-Env: <USER=root>
Date: Fri, 10 Oct 2025 01:00:00 +0200
0/0 addresses expired.
&
Furthermore I see, that my established onvpn connection from my phone are failed with TLS errors after I change the connection at 07:51 am from WLAN to mobile at my phone for one hour.
It seems to be, that all established connections are working after the unknown big fail. But if one of these connections gets a disconnect, they cant be established anymore.
But I cant find some hints in the logs on which time this happened...
All connections working succesfully after I physically reconnect the patch cable between modem and opnsense.
I dont know where I can find and inspect specific details at the logs.
Ive checkt all logs at /var/log/* but doesnt found some interesting points .. the two ones above.
Does anyone know, whats happend?
Edit-1: change WANs to VLANs
"