Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - dirtyfreebooter

#1
Zenarmor (Sensei) / Re: How to block Firefox VPN
August 14, 2026, 07:48:42 PM
Quote from: Seimus on August 14, 2026, 07:22:35 PM
Quote from: dirtyfreebooter on August 12, 2026, 12:11:29 AMi tried this and couldn't get the custom application to hit. i assume i am setting things up wrong.

i tried adjusting the custom app like 10x different ways. when i go back to the live sessions after updating custom app / policy, i still just see the entry allowed (green shield)

Custom apps in ZA are broken. And for some time now.

I already did open a ticket (21.10. 2025) for it, but it's in a backlog.

Regards,
S.

this makes sense, but i tried also making some other custom apps, and none of those worked either. like real simple ones, by IP address or just a port, so try and see if any custom app was working. seems like you said, custom apps just doesn't work and they apparently have no tests around that.
#2
Zenarmor (Sensei) / Re: How to block Firefox VPN
August 12, 2026, 12:11:29 AM
i tried this and couldn't get the custom application to hit. i assume i am setting things up wrong.

i tried adjusting the custom app like 10x different ways. when i go back to the live sessions after updating custom app / policy, i still just see the entry allowed (green shield)
#3
yea i was able to get almost 2.5 gbps on n150 protectli, which cpubenchmark.net shows 9100 has better single and multi-threaded performance
#4
i had the same random cloudflare rate limits: https://forum.opnsense.org/index.php?topic=52181.0

i also reported this a few months ago. nothing was done or even acknowledged
#5
26.1, 26,4 Series / Re: vnstat dashboard widget
July 19, 2026, 12:01:30 AM
interface names to use the OPNsense names vs the FreeBSD interface names: https://github.com/opnsense/plugins/pull/5566
#6
pkg -d update
Updating OPNsense repository catalogue...
DBG(1)[18410]> PkgRepo: verifying update for OPNsense
DBG(1)[18410]> Pkgrepo, begin update of '/var/db/pkg/repos/OPNsense/db'
DBG(1)[18410]> (fetch) Request to fetch https://us-east.opnsense-update.deciso.com/4409c341-bd35-4332-9b15-39ffd854a63b/FreeBSD:14:amd64/26.4/latest/meta.conf
DBG(1)[18410]> (fetch) Fetch: fetcher used: https
DBG(1)[18410]> (fetch) Request to fetch https://us-east.opnsense-update.deciso.com/4409c341-bd35-4332-9b15-39ffd854a63b/FreeBSD:14:amd64/26.4/latest/data.pkg
DBG(1)[18410]> (fetch) Fetch: fetcher used: https
OPNsense repository is up to date.
Updating SunnyValley repository catalogue...
DBG(1)[18410]> PkgRepo: verifying update for SunnyValley
DBG(1)[18410]> Pkgrepo, begin update of '/var/db/pkg/repos/SunnyValley/db'
DBG(1)[18410]> (fetch) Request to fetch https://updates.zenarmor.net/opnsense/FreeBSD:14:amd64/26.4/769b66af-4dce-43d9-81a0-cdac469aef9d/meta.conf
DBG(1)[18410]> (fetch) Fetch: fetcher used: https
pkg: An error occurred while fetching package: Unknown error
DBG(1)[18410]> (fetch) Request to fetch https://updates.zenarmor.net/opnsense/FreeBSD:14:amd64/26.4/769b66af-4dce-43d9-81a0-cdac469aef9d/meta.txz
DBG(1)[18410]> (fetch) Fetch: fetcher used: https
DBG(1)[18410]> (fetch) Request to fetch https://updates.zenarmor.net/opnsense/FreeBSD:14:amd64/26.4/769b66af-4dce-43d9-81a0-cdac469aef9d/data.pkg
DBG(1)[18410]> (fetch) Fetch: fetcher used: https
pkg: An error occurred while fetching package: Unknown error
DBG(1)[18410]> (fetch) Request to fetch https://updates.zenarmor.net/opnsense/FreeBSD:14:amd64/26.4/769b66af-4dce-43d9-81a0-cdac469aef9d/data.tzst
DBG(1)[18410]> (fetch) Fetch: fetcher used: https
Fetching data.tzst:   0%
DBG(1)[18410]> (fetch) Request to fetch https://updates.zenarmor.net/opnsense/FreeBSD:14:amd64/26.4/769b66af-4dce-43d9-81a0-cdac469aef9d/packagesite.pkg
DBG(1)[18410]> (fetch) Fetch: fetcher used: https
Fetching packagesite.pkg:   0%
SunnyValley repository is up to date.
All repositories are up to date.

if i try and curl that URL i get error code: 1015
curl --verbose --location https://updates.zenarmor.net/opnsense/FreeBSD:14:amd64/26.4/769b66af-4dce-43d9-81a0-cdac469aef9d/meta.conf
*   Trying [2606:4700:20::681a:dad]:443...
* Immediate connect fail for 2606:4700:20::681a:dad: No route to host
* connect to 2606:4700:20::681a:dad port 443 from :: port 0 failed: No error: 0
*   Trying [2606:4700:20::ac43:4ad1]:443...
* Immediate connect fail for 2606:4700:20::ac43:4ad1: No route to host
* connect to 2606:4700:20::ac43:4ad1 port 443 from :: port 0 failed: No error: 0
*   Trying [2606:4700:20::681a:cad]:443...
* Immediate connect fail for 2606:4700:20::681a:cad: No route to host
* connect to 2606:4700:20::681a:cad port 443 from :: port 0 failed: No error: 0
* Host updates.zenarmor.net:443 was resolved.
* IPv6: 2606:4700:20::681a:dad, 2606:4700:20::ac43:4ad1, 2606:4700:20::681a:cad
* IPv4: 104.26.13.173, 172.67.74.209, 104.26.12.173
*   Trying 104.26.13.173:443...
* ALPN: curl offers h2,http/1.1
* TLSv1.3 (OUT), TLS handshake, Client hello (1):
* SSL Trust Anchors:
*   CApath: /etc/ssl/certs
* TLSv1.3 (IN), TLS handshake, Server hello (2):
* TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8):
* TLSv1.3 (IN), TLS handshake, Certificate (11):
* TLSv1.3 (IN), TLS handshake, CERT verify (15):
* TLSv1.3 (IN), TLS handshake, Finished (20):
* TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1):
* TLSv1.3 (OUT), TLS handshake, Finished (20):
* SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519 / id-ecPublicKey
* ALPN: server accepted h2
* Server certificate:
*   subject: CN=zenarmor.net
*   start date: Jun  2 00:12:03 2026 GMT
*   expire date: Aug 31 01:11:53 2026 GMT
*   issuer: C=US; O=Google Trust Services; CN=WE1
*   Certificate level 0: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA256
*   Certificate level 1: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA384
*   Certificate level 2: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384
*   subjectAltName: "updates.zenarmor.net" matches cert's "*.zenarmor.net"
* OpenSSL verify result: 0
* SSL certificate verified via OpenSSL.
* Established connection to updates.zenarmor.net (104.26.13.173 port 443) from 71.33.134.33 port 37694
* using HTTP/2
* [HTTP/2] [1] OPENED stream for https://updates.zenarmor.net/opnsense/FreeBSD:14:amd64/26.4/769b66af-4dce-43d9-81a0-cdac469aef9d/meta.conf
* [HTTP/2] [1] [:method: GET]
* [HTTP/2] [1] [:scheme: https]
* [HTTP/2] [1] [:authority: updates.zenarmor.net]
* [HTTP/2] [1] [:path: /opnsense/FreeBSD:14:amd64/26.4/769b66af-4dce-43d9-81a0-cdac469aef9d/meta.conf]
* [HTTP/2] [1] [user-agent: curl/8.20.0]
* [HTTP/2] [1] [accept: */*]
> GET /opnsense/FreeBSD:14:amd64/26.4/769b66af-4dce-43d9-81a0-cdac469aef9d/meta.conf HTTP/2
> Host: updates.zenarmor.net
> User-Agent: curl/8.20.0
> Accept: */*
>
* Request completely sent off
* TLSv1.3 (IN), TLS handshake, Newsession Ticket (4):
* TLSv1.3 (IN), TLS handshake, Newsession Ticket (4):
< HTTP/2 429
< date: Tue, 07 Jul 2026 20:36:16 GMT
< content-type: text/plain; charset=UTF-8
< content-length: 17
< retry-after: 162
< cache-control: private, max-age=0, no-store, no-cache, must-revalidate, post-check=0, pre-check=0
< expires: Thu, 01 Jan 1970 00:00:01 GMT
< referrer-policy: same-origin
< x-frame-options: SAMEORIGIN
< report-to: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=ZmUN3cyrFXqk%2B1qHTk7Ldc8NjauZHxDaMxXTuxWL1gtrmKFKgDn9h0LH0Cdn%2BgIGmb%2BExZJRJ8gDW0V%2FVR5OPO6bF7%2BPmNehWHiNDZMQybw9ot93lAsoaVlUjcu6LsuJ6ITjWZeS"}]}
< nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
< server: cloudflare
< cf-ray: a179a3f369b2e675-DEN
<
error code: 1015
* Connection #0 to host updates.zenarmor.net:443 left intact

HTTP/2 429  so it looks like i am hitting some sort of cloudflare rate limiting... from my quantum fiber home internet...
#7
26.1, 26,4 Series / Re: vnstat dashboard widget
July 07, 2026, 06:15:03 PM
Quote from: gpfountz on July 07, 2026, 05:39:05 PMThanks for this widget.  I like it!!

I would like to recommend an option to reverse the sort order.  So when the widget placed as a small window, the newest hours/days/months are visible at the top of the widget window.

yes, i could add sort order option. thanks for the feedback
#8
26.1, 26,4 Series / Re: vnstat dashboard widget
July 06, 2026, 09:42:38 PM
Quote from: caplam on July 03, 2026, 01:29:18 PM- when you select which interfaces to monitor you have the choice within the different names of the interfaces and when it's displayed on the dashboard you have the name of the underlying device. i would prefer to have the interface name.

yea, that makes sense, i'll put up a PR to use the OPNsense interface name instead of the underlying FreeBSD device name.

Quote from: caplam on July 03, 2026, 01:29:18 PM- perhaps a layout with where you can select 2 or more interfaces to display could be a plus. But i guess it there will troubles to display that correctly. Or maybe spawn that to a widget per interface.

i'll probably skip this due to the complexity and trying to keep things simple
#9
26.1, 26,4 Series / Re: vnstat dashboard widget
July 02, 2026, 10:44:25 PM
this finally landed in 26.1.11
#10
***GOT REQUEST TO CHECK FOR UPDATES***
Currently running OPNsense 26.4.1 (amd64) at Sat Jun 20 16:47:18 MDT 2026
Strict TLS 1.3 and CRL checking is enabled.
Fetching subscription information, please wait... done
Fetching changelog information, please wait... done
Updating OPNsense repository catalogue...
Fetching meta.conf: . done
Fetching data.pkg: .......... done
Processing entries: .......... done
OPNsense repository update completed. 938 packages processed.
Updating SunnyValley repository catalogue...
pkg: An error occurred while fetching package: Unknown error
pkg: An error occurred while fetching package: Unknown error
Fetching data.tzst: .... done
Processing entries: .. done
SunnyValley repository update completed. 15 packages processed.
All repositories are up to date.
Checking for upgrades (2 candidates): .. done
Processing candidates (2 candidates): . done
Checking integrity... done (0 conflicting)
Your packages are up to date.
***DONE***

like i am not sure i ever remember a single zenarmor update without some sort of issue.
#11
when RSS is enabled,
net.inet.rss.enabled = 1
the kernel will override dispatch and always make it hybrid (so you can leave that tunable out if you are enabling RSS), you can verify my claim with netstat -Q
net.isr.dispatch = hybrid
---

i tested a protectli VP2440 with N150 with i226 with Zenarmor and i was able to get 2.5 gbps

using the x710 10g interface without Zenarmor, i was able to get 9.46 gbps

so i would think that N100 could easily do 2 Gbps without IDS/IPS.

the tunables i used were (including installing the Intel Microcode Plugin):
dev.hwpstate_intel.0.epp = 10
dev.hwpstate_intel.1.epp = 10
dev.hwpstate_intel.2.epp = 10
dev.hwpstate_intel.3.epp = 10
dev.igc.0.fc = 0
dev.igc.1.fc = 0
hw.acpi.cpu.cx_lowest = C2
hw.ibrs_disable = 1
net.inet.tcp.soreceive_stream = 1
net.isr.bindthreads = 1
net.isr.maxthreads = -1
vm.pmap.pcid_enabled = 0
vm.pmap.pti = 0

note that i think the intel microcode plugin + vm.pmap.pcid_enabled = 0 is pretty much the gold standard with the N100/N150/N305 cpus, as they have a bug in the freebsd kernel otherwise...

i did update my i226 firmwares to v2.32 tho i dont think that mattered.
#12
over the weekend, saw these in dmesg
[2148079] ax0: unable to obtain hardware mutexes
[2148079] ax1: unable to obtain hardware mutexes
[2148080] ax0: unable to obtain hardware mutexes
[2148080] ax1: unable to obtain hardware mutexes
[2148081] ax0: unable to obtain hardware mutexes
[2148081] ax1: unable to obtain hardware mutexes
[2148082] ax0: unable to obtain hardware mutexes
[2148082] ax1: unable to obtain hardware mutexes
[2148083] ax0: unable to obtain hardware mutexes
[2148083] ax1: unable to obtain hardware mutexes

but things still seem to be fine and moving along :)
#13
Running OPNsense Business 26.4_14-amd64

Acme cert expired today. The logs say:
AcmeClient: issue/renewal not required for certificate: <domain>
but the cert is expired, if i manually click on issue/renew button, it renews fine.
#14
Hardware and Performance / Re: DEC3920 Quick Review
April 28, 2026, 06:05:35 PM
just wanted to post a follow up. after my last changes (those few tunables), i have had very stable experience. i updated to 26.4 and migrated my rules, but i have had 100% uptime on OS and WAN since i updated and rebooted for the update.

haven't had a change to redo some of my cable management since i replaced the unifi cloud gateway fiber, but i like the pop of red :) lol