Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - meyergru

#1
CG-NAT does not handle IPv6, which is the problem at hand if it can be fixed by using IPv4 only or by instructing the browser to disregard IPv6 in the first place.

Movistar in Spain is known to have issues with IPv6, there are lots of reports on this (also from this year, BTW).
#2
The provider test is crap, for me, it shows "OPALTELECOM-AS TalkTalk Communications Limited, GB", while I am in Germany.

If you still use the parameter in Firefox, the test should probably fail, because that setting essentially disables IPv6.

There were several changes in 26.1.6 for IPv6. If you only did an 26.1.6 -> 26.1.6_2 upgrade, everything should work.

What do you mean by "the DNS server is the upstream router"? Do you use a router-behind-router setup, do you mean the ISP router or your OpnSense? If so, its IPv4 or IPv6 address? Please be more specific.

#3
Read the change notes for the update(s) you did. I think there were changes for IPv6. Probably, you need a reboot, depending on what your update path was.
#4
The name of the parameter should give you a hint about what is probably wrong with your setup: DNS resolution for IPv6 names or IPv6 reachability.

You should investigate what exactly goes wrong (and then, why).

For example:

1. When you resolve a name like "www.google.com", you will get both an IPv6 and an IPv4 address - that is, if DNS resolution does not fail in the first place, in case your client tries to resolve via IPv6 first. If that fails, which is the IPv6 address of your DNS server? Does it answer?

2. Can you reach the resolved IPv6 via ping? Probably not.

3. Does your client get a routeable IPv6?

4. Has it got an IPv6 gateway? Can it be reached?

5. Can you reach your upstream gateway? Or any IPv6, like "2600::", via ping?

You catch my drift. "websites are slow" means "cannot be reached via IPv6, which is the preferred way" in your case. There is about 0% chance that TLS is impacted. OpnSense does not even interfere with that, unless you use a proxy.

When IPv6 did work before, you should be able to fix it. If your ISP does not offer it, turn it off globally.
#5
Quote from: francescofff on Today at 12:00:47 PMThanks for the quick response.

Point 10. The CPU is sufficient because with Linux Mint on USB I reach 500 Mbps. Now, I don't know if OPNsense adds anything that makes performance more demanding.

Obviously, you did not read the full point and the link about RSS and others.

Quote from: francescofff on Today at 12:00:47 PMPoint 22. I first tried it in a virtual machine with Proxmox. Then I installed OPNsense bare metal. I gained absolutely no speed.

Perhaps there's a difference between FreeBS and Linux that means the hardware isn't managed, I don't know?

There is a lot more in the linked article about OpnSense under PVE, like not using passthru, suggested tuneables and more.

What I meant by that is:

1. You did not state how you measure throughput (i.e. single-threaded vs. multi threaded). So, your testinmg methodology cannot be verified.
2. You tried the most advanced setup (i.e. under PVE) first, without using guidance about how that is to be done (hint: no, it does not work optimally from the get-go).
3. You probably did not apply some needed tuneables for using more than one of your CPU cores.
#6
Start with this, points 10 and 13, if you use some kind of IPS and point 22.
#7
Die DG scheint - zumindest an manchen Anschlüssen - erst nach einigen Minuten eine IPv6 zu vergeben. Warte mal 15 Minuten ab.
#8
When you read my explanation again closely, you will find that your problem is completely unrelated to the automatic discovery, thus any more complaining about that won't help you a bit.

What really helps to clean up the mess once is also given in my post.

The final solution to this is to use the newly created "delete lease" button in the Kea leases window, which should take care of cleaning out the old lease correctly.
#9
FWIW: Ich habe eine (von drei) Installation bei DG, bei der nach einem Neustart die IPv6 erst nach ca. 10 Minuten vergeben wird.

Keine Ahnung, wieso.
#10
26.1, 26,4 Series / Re: IPv6 weirdness
April 19, 2026, 09:14:41 AM
Take a look at the Tutorial section - there is a HowTo for IPv6.
#11
General Discussion / Re: Updates no longer working
April 18, 2026, 08:53:00 AM
The business license that comes with Deciso boxes is valid for one year only, so it probably has expired.
#12
I assume you want to set up a bridge with LAN and LAN2. Follow the Offizials docs, them it will work.
#13
26.1, 26,4 Series / Re: PPPOE Frequent Disconnection
April 14, 2026, 12:34:14 PM
Miscconfiguration: why do you use two logical interfaces for pppoe?
#14
26.1, 26,4 Series / Re: DNS Confusion
April 13, 2026, 10:05:18 AM
If that does not work, I can only imagine two reasons:

1. You have your local unbound be responsible for home.arpa as a whole, such that sub-zone are not delegated any more.

2. Somehow the firewall rules or something blocks your OpnSense from accessing 192.168.178.3 on port 53. Being able to resolve from a client on your LAN is not the same as doing the same from OpnSense itself, especially when a VPN in involved en route. Try an nslookup from your OpnSense instance and then track down where that goes.
#15
General Discussion / Re: os-gdrive-backup setup
April 12, 2026, 09:52:28 AM
Note that Google Driver will not work anymore for new users: https://forum.opnsense.org/index.php?topic=48393