Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - LOTRouter

#1
I also lost WEB GUI access on upgrade, or at least it was intermittently inaccesable for long periods of time.  This fixed it for me:

https://forum.opnsense.org/index.php?topic=52409.0
#2
I had the same problem where my GUI would randomly freeze for a minute at a time, then work for a bit, then freeze again.  Once I added this tunable my 26.7 OPNsense became stable again.
#3
Quote from: OPNenthu on July 17, 2026, 08:22:12 PMNothing applied could mean that you already have the latest ucode, such as from a BIOS update.

Makes sense.  I just tried it on an N5105 I have running as well, and I do see the microcode update:

[1] CPU microcode: updated from 0x1d to 0x24000026
#4
I followed the steps and also do not see the microcode load.  Under SYSTEM > FIRMWARE > PLUGINS I see "os-cpu-microcode-intel-devel (misconfigured)" with the Repository as "unknown-repository" so I believe I have it correctly loaded, but it doesn't appear to ever update the microcode:

---<<BOOT>>---
Copyright (c) 1992-2025 The FreeBSD Project.
Copyright (c) 1979, 1980, 1983, 1986, 1988, 1989, 1991, 1992, 1993, 1994
The Regents of the University of California. All rights reserved.
FreeBSD is a registered trademark of The FreeBSD Foundation.
FreeBSD 15.1-RELEASE-p1 stable/26.7-n283674-12334a596709 SMP amd64
FreeBSD clang version 19.1.7 (https://github.com/llvm/llvm-project.git llvmorg-19.1.7-0-gcd708029e0b2)
[1] VT(vga): resolution 640x480
[1] CPU: Intel(R) N100 (806.40-MHz K8-class CPU)
[1]   Origin="GenuineIntel"  Id=0xb06e0  Family=0x6  Model=0xbe  Stepping=0
[1]   Features=0xbfebfbff<FPU,VME,DE,PSE,TSC,MSR,PAE,MCE,CX8,APIC,SEP,MTRR,PGE,MCA,CMOV,PAT,PSE36,CLFLUSH,DTS,ACPI,MMX,FXSR,SSE,SSE2,SS,HTT,TM,PBE>
[1]   Features2=0x7ffafbbf<SSE3,PCLMULQDQ,DTES64,MON,DS_CPL,VMX,EST,TM2,SSSE3,SDBG,FMA,CX16,xTPR,PDCM,PCID,SSE4.1,SSE4.2,x2APIC,MOVBE,POPCNT,TSCDLT,AESNI,XSAVE,OSXSAVE,AVX,F16C,RDRAND>
[1]   AMD Features=0x2c100800<SYSCALL,NX,Page1GB,RDTSCP,LM>
[1]   AMD Features2=0x121<LAHF,ABM,Prefetch>
[1]   Structured Extended Features=0x239ca7eb<FSGSBASE,TSCADJ,BMI1,AVX2,FDPEXC,SMEP,BMI2,ERMS,INVPCID,NFPUSG,PQE,RDSEED,ADX,SMAP,CLFLUSHOPT,CLWB,PROCTRACE,SHA>
[1]   Structured Extended Features2=0x98c007bc<UMIP,PKU,OSPKE,WAITPKG,GFNI,VAES,VPCLMULQDQ,RDPID,MOVDIRI,MOVDIR64B>
[1]   Structured Extended Features3=0xfc184410<FSRM,MD_CLEAR,IBT,IBPB,STIBP,L1DFL,ARCH_CAP,CORE_CAP,SSBD>
[1]   Structured Extended Features4=0x810
[1]   XSAVE Features=0xf<XSAVEOPT,XSAVEC,XINUSE,XSAVES>
[1]   IA32_ARCH_CAPS=0x180fd6b<RDCL_NO,IBRS_ALL,SKIP_L1DFL_VME,MDS_NO,TAA_NO>
[1]   VT-x: PAT,HLT,MTF,PAUSE,EPT,UG,VPID,VID,PostIntr
[1]   TSC: P-state invariant, performance statistics
[1] real memory  = 34358689792 (32767 MB)
[1] avail memory = 33219031040 (31680 MB)
[1] Event timer "LAPIC" quality 600
[1] ACPI APIC Table: <ALASKA A M I >
[1] WARNING: L3 data cache covers more APIC IDs than a package (7 > 3)
[1] FreeBSD/SMP: Multiprocessor System Detected: 4 CPUs
[1] FreeBSD/SMP: 1 package(s) x 4 core(s)
[1] random: registering fast source Intel Secure Key Seed
[1] random: fast provider: "Intel Secure Key Seed"
[1] random: unblocking device.
[1] ioapic0 <Version 2.0> irqs 0-119
[1] Launching APs: 1 2 3
[1] random: entropy device external interface
[1] wlan: mac acl policy registered
[1] kbd0 at kbdmux0
[1] WARNING: Device "spkr" is Giant locked and may be deleted before FreeBSD 16.0.
[1] efirtc0: <EFI Realtime Clock>
[1] efirtc0: registered as a time-of-day clock, resolution 1.000000s
[1] smbios0: <System Management BIOS> at iomem 0x75cc3000-0x75cc3017
[1] smbios0: Entry point: v3 (64-bit), Version: 3.5
[1] aesni0: <AES-CBC,AES-CCM,AES-GCM,AES-ICM,AES-XTS,SHA1,SHA256>
[1] acpi0: <ALASKA A M I >
[1] acpi0: Power Button (fixed)
[1] hpet0: <High Precision Event Timer> iomem 0xfed00000-0xfed003ff on acpi0
[1] Timecounter "HPET" frequency 19200000 Hz quality 950
[1] Event timer "HPET" frequency 19200000 Hz quality 550
[1] Event timer "HPET1" frequency 19200000 Hz quality 440
[1] Event timer "HPET2" frequency 19200000 Hz quality 440
[1] Event timer "HPET3" frequency 19200000 Hz quality 440
[1] Event timer "HPET4" frequency 19200000 Hz quality 440
[1] atrtc1: <AT realtime clock> on acpi0
[1] atrtc1: Warning: Couldn't map I/O.
[1] atrtc1: registered as a time-of-day clock, resolution 1.000000s
[1] Event timer "RTC" frequency 32768 Hz quality 0
[1] attimer0: <AT timer> port 0x40-0x43,0x50-0x53 irq 0 on acpi0
[1] Timecounter "i8254" frequency 1193182 Hz quality 0
[1] Event timer "i8254" frequency 1193182 Hz quality 100
[1] Timecounter "ACPI-fast" frequency 3579545 Hz quality 900
[1] acpi_timer0: <24-bit timer at 3.579545MHz> port 0x1808-0x180b on acpi0
[1] pcib0: <ACPI Host-PCI bridge> port 0xcf8-0xcff on acpi0
[1] pci0: <ACPI PCI bus> on pcib0
[1] vgapci0: <VGA-compatible display> port 0x3000-0x303f mem 0x6000000000-0x6000ffffff,0x4000000000-0x400fffffff at device 2.0 on pci0
[1] vgapci0: Boot video device
[1] xhci0: <XHCI (generic) USB 3.0 controller> mem 0x6001110000-0x600111ffff at device 13.0 on pci0
[1] xhci0: 32 bytes context size, 64-bit DMA
[1] xhci0: xECP capabilities <PROTO,PROTO,VEND(c0),LEGACY,VEND(c6),VEND(c7),VEND(c2),DEBUG,VEND(c3),VEND(d1),VEND(ce),VEND(c8),VEND(c9),VEND(ca),VEND(cc),VEND(cd),VEND(d2),VEND(cf),VEND(d3)>
[1] usbus0 on xhci0
[1] usbus0: 5.0Gbps Super Speed USB v3.0
[1] xhci1: <XHCI (generic) USB 3.0 controller> mem 0x6001100000-0x600110ffff at device 20.0 on pci0
[1] xhci1: 32 bytes context size, 64-bit DMA
[1] xhci1: xECP capabilities <PROTO,PROTO,VEND(c0),LEGACY,VEND(c6),VEND(c7),VEND(c2),DEBUG,VEND(c3),VEND(c4),VEND(ce),VEND(c8),VEND(c9),VEND(ca),VEND(cb),VEND(cc),VEND(cd)>
[1] usbus1 on xhci1
[1] usbus1: 5.0Gbps Super Speed USB v3.0
[1] pci0: <memory, RAM> at device 20.2 (no driver attached)
[1] pci0: <simple comms> at device 22.0 (no driver attached)
[1] pcib1: <ACPI PCI-PCI bridge> at device 28.0 on pci0
[1] pci1: <ACPI PCI bus> on pcib1
[1] igc0: <Intel(R) Ethernet Controller I226-V> mem 0x80e00000-0x80efffff,0x80f00000-0x80f03fff at device 0.0 on pci1
[1] igc0: EEPROM V2.13-0 eTrack 0x80000284
[1] igc0: Using 1024 TX descriptors and 1024 RX descriptors
[1] igc0: Using 4 RX queues 4 TX queues
[1] igc0: Using MSI-X interrupts with 5 vectors
[1] igc0: Ethernet address: 00:d0:b4:01:57:0c
[1] igc0: netmap queues/slots: TX 4/1024, RX 4/1024
[1] pcib2: <ACPI PCI-PCI bridge> at device 28.1 on pci0
[1] pci2: <ACPI PCI bus> on pcib2
[1] igc1: <Intel(R) Ethernet Controller I226-V> mem 0x80b00000-0x80bfffff,0x80c00000-0x80c03fff at device 0.0 on pci2
[1] igc1: EEPROM V2.13-0 eTrack 0x80000284
[1] igc1: Using 1024 TX descriptors and 1024 RX descriptors
[1] igc1: Using 4 RX queues 4 TX queues
[1] igc1: Using MSI-X interrupts with 5 vectors
[1] igc1: Ethernet address: 00:d0:b4:01:57:0d
[1] igc1: netmap queues/slots: TX 4/1024, RX 4/1024
[1] pcib3: <ACPI PCI-PCI bridge> at device 28.2 on pci0
[1] pci3: <ACPI PCI bus> on pcib3
[1] igc2: <Intel(R) Ethernet Controller I226-V> mem 0x80800000-0x808fffff,0x80900000-0x80903fff at device 0.0 on pci3
[1] igc2: EEPROM V2.13-0 eTrack 0x80000284
[1] igc2: Using 1024 TX descriptors and 1024 RX descriptors
[1] igc2: Using 4 RX queues 4 TX queues
[1] igc2: Using MSI-X interrupts with 5 vectors
[1] igc2: Ethernet address: 00:d0:b4:01:57:0e
[1] igc2: netmap queues/slots: TX 4/1024, RX 4/1024
[1] pcib4: <ACPI PCI-PCI bridge> at device 28.6 on pci0
[1] pci4: <ACPI PCI bus> on pcib4
[1] igc3: <Intel(R) Ethernet Controller I226-V> mem 0x80500000-0x805fffff,0x80600000-0x80603fff at device 0.0 on pci4
[1] igc3: EEPROM V2.13-0 eTrack 0x80000284
[1] igc3: Using 1024 TX descriptors and 1024 RX descriptors
[1] igc3: Using 4 RX queues 4 TX queues
[1] igc3: Using MSI-X interrupts with 5 vectors
[1] igc3: Ethernet address: 00:d0:b4:01:57:0f
[1] igc3: netmap queues/slots: TX 4/1024, RX 4/1024
[1] pcib5: <ACPI PCI-PCI bridge> at device 29.0 on pci0
[1] pci5: <ACPI PCI bus> on pcib5
[1] nvme0: <Generic NVMe Device> mem 0x81000000-0x81003fff at device 0.0 on pci5
[1] isab0: <PCI-ISA bridge> at device 31.0 on pci0
[1] isa0: <ISA bus> on isab0
[1] hdac0: <Intel Alder Lake-N HDA Controller> mem 0x6001120000-0x6001123fff,0x6001000000-0x60010fffff at device 31.3 on pci0
[1] pci0: <serial bus> at device 31.5 (no driver attached)
[1] acpi_button0: <Sleep Button> on acpi0
[1] cpu0: <ACPI CPU> on acpi0
[1] acpi_button1: <Power Button> on acpi0
[1] acpi_tz0: <Thermal Zone> on acpi0
[1] uart: ns8250: UART FCR is broken (0x1)
[1] uart0: <16550 or compatible> port 0x3f8-0x3ff irq 4 flags 0x10 on acpi0
[1] uart0: console (115200,n,8,1)
[1] uart: ns8250: UART FCR is broken (0x1)
[1] uart1: <16550 or compatible> port 0x2f8-0x2ff irq 3 on acpi0
[1] acpi_syscontainer0: <System Container> on acpi0
[1] acpi_syscontainer1: <System Container> on acpi0
[1] atrtc0: <AT realtime clock> at port 0x70 irq 8 on isa0
[1] atrtc0: Warning: Couldn't map I/O.
[1] atrtc0: registered as a time-of-day clock, resolution 1.000000s
[1] atrtc0: Can't map interrupt.
[1] hwpstate_intel0: <Intel Speed Shift> on cpu0
[1] cpufreq0: <CPU frequency control> on cpu0
[1] hwpstate_intel1: <Intel Speed Shift> on cpu1
[1] cpufreq1: <CPU frequency control> on cpu1
[1] hwpstate_intel2: <Intel Speed Shift> on cpu2
[1] cpufreq2: <CPU frequency control> on cpu2
[1] hwpstate_intel3: <Intel Speed Shift> on cpu3
[1] cpufreq3: <CPU frequency control> on cpu3
[1] Timecounter "TSC" frequency 806401148 Hz quality 1000
[1] Timecounters tick every 1.000 msec
[1] ugen1.1: <Intel XHCI root HUB> at usbus1
[1] ugen0.1: <Intel XHCI root HUB> at usbus0
[1] uhub0 on usbus1
[1] uhub0: <Intel XHCI root HUB, class 9/0, rev 3.00/1.00, addr 1> on usbus1
[1] ZFS filesystem version: 5
[1] ZFS storage pool version: features support (5000)
[1] uhub1 on usbus0
[1] uhub1: <Intel XHCI root HUB, class 9/0, rev 3.00/1.00, addr 1> on usbus0
[1] nda0 at nvme0 bus 0 scbus0 target 0 lun 1
nda0: <Samsung SSD 970 EVO Plus 500GB 2B2QEXM7 S58SNJ0N613187J>
nda0: Serial Number S58SNJ0N613187J
[1] nda0: nvme version 1.3
nda0: 476940MB (976773168 512 byte sectors)
[1] Trying to mount root from zfs:zroot/ROOT/24.1 []...
[1] uhub1: 3 ports with 3 removable, self powered
[2] uhub0: 16 ports with 16 removable, self powered
[2] pid 30 (zpool) is attempting to use unsafe AIO requests - not logging anymore
#5
If four hours isn't long engough for you, you can increase the timout in SYSTEM: SETTINGS: ADMINISTRATION: Session Timeout
#6
I upgraded 5 systems from 24.7.4_1 to 24.7.5.  The first three with Crowdsec installed.  All three with Crowdsec returned to the Lobby without rebooting.  On all three, I then initiated a reboot, two of which rebooted fine, the third hung up hard and had to be power cycled to recover it.

For the next two, I uninstalled the Crowdsec plugin, then initiated the upgrade.  On both of these systems, the upgrade went exactly as expected.  One of them did return to the Lobby briefly before rebooting, but both did reboot on their own withour issue.  I then re-installed the Crowdsec plugin withour issue.

This is certainly a Crowdsec issue.

I have five more system to upgrade, but I'll wait for a hotfix to test on them.
#7
Upgrade to 24.7 went smoothly.  However, I did notice a cosmetic issue with the CPU Widget.  I have a Core i5-1135G7 CPU with 4 Cores, 8 threads.  The Widget is reporting it as 8 Cores, 4 threads.
#8
Some devices (modems, etc.) have a feature in that they stop responding if they have not received an ARP request for a couple of minutes. The cache of BSD based routers (such as OPNSense) is longer than that.

Try adding net.link.ether.inet.max_age=120 to tunables, which forces the router to re-arp every two minutes and often solves this issue.

#9
I've been seeing this as well.  I thought it coorisponded with my CRON job that runs, "Update and reload firewall aliases" every night at 1:07am, but maybe it has nothing to do with that?
#10
24.1, 24.4 Legacy Series / Re: DNSCrypt-Proxy won't start
February 09, 2024, 04:46:41 PM
Quote from: almodovaris on February 08, 2024, 11:47:21 PM
Why use DNScrypt? Unbound does DoT (yup, it works with dns.opendns.com also).

I prefer DoH.  It's just a personal preference.
#12
Why are you creating an out rule?  Stateful firewalls like OPNsense work best with all rules as in rules.
#13
Personally, I'd rather that OPNsense respond exactly as it is described.  I'd hate to try troubleshooting why performance to my NAS on the same LAN/subnet was poor, only to discover that all traffic had to be routed through my firewall, when it obviously shouldn't be.  I don't see creating a rule to allow it to route within the same subnet as a viable solution to allow my NAS to beat the crap out of my router.  At least now you know the root issue is with your NAS and you can allow it if you choose, but I wouldn't.
#14
I've seen Unbound go stupid like this many times, and the bigger your total block list entries, the more chance of it happening.  If you are using other systems for DNS, you might try removing all blocklists in Unbound and then try starting it again.
#15
24.1, 24.4 Legacy Series / Re: DNSCrypt-Proxy won't start
February 08, 2024, 08:57:52 PM
Thanks for the follow up.  It looks like a fairly easy fix:

https://github.com/DNSCrypt/dnscrypt-proxy/discussions/1979