Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - knowHoff

#1
thank you for the info and time taken to teach / spread knowledge.
highly appreciated!

Cheers
#2
I thought that checksumming and snapshotting is only available on multiple disk systems / RAIDZx.
Thanks for pointing that out!
Just starting the installation now utilizing  ZFS.

Cheers
#3
thanks for that hint.
are there benefits on single disk system when using zfs over ufs?
#4
I have done SMART tests and the harddrive / ssd passed successfully.
I've also fsck'd the drive using GhostBSD live medium. fsck found errors. I did let fsck correct the found errors automatically but it didn't help.

It is also worth mentioning that this is / was a clean install, just two weeks old, since my upgrade from 26.1 to 26.7 failed the webUI way so I was forced to do a clean install to jump up to 26.7.

Right now, the ssd is being wiped and getting a clean install.

Thanks again for your help!

Cheers
#5
I've been reading through BSD forum and found this

So I just tried to switch the Bios setting from legacy to UEFI.
The system is booting now, but is not able to finish the booting process.

It stops here:

You cannot view this attachment.

Is it possible that there is a fault in the upgrade process that just overwrites legacy boot with UEFI boot?

Cheers
#6

Thank you for taking the time to look at my problem.

This is the output of gpart show, please take a look at the picture.

You cannot view this attachment.

It seems that the partition table is still valid.

Do you know how to restore the bootloader on  BSD?
#7
Good evening,

after doing the upgrade today from
26.7.1 to 26.7.2,
my system fails while trying to boot.
The only output I see is the one shown here

You cannot view this attachment.

I am able to access a boot prompt.
The only answer I get after typing "boot" is from gptboot, which is not applicable on a CSM / legacy boot system.

You cannot view this attachment.

Is there any possibility to recover the installation
or do I have to clean install?

Cheers
#8
I assume I had the same issue, at least the health check log looked the same like health check log

Interestingly I have two almost exact same systems.

The other system updated fine from the webGUI.

Thank you for taking care of us!

Cheers
#9
had the exact error messages

Version 26.7 is incorrect, expected: 26.1.11

curl + install + reboot = no boot

the machine did not come back again, had to cold reset.

After cold reset, again:

Version 26.7 is incorrect, expected: 26.1.11

did not have the time to narrow down the fault,

so did a fresh install with successful config restore.
#10
Quote from: nero355 on April 23, 2026, 03:00:53 PMif that is what you are worried about ;)

that is exactly what is holding me back.
Thanks for pointing that out!
Back then, the github-migration tool was taking care of that.

Cheers
#11
Thanks a lot Patrick, good to know!
I've checked the rules and found them there.

I just hope, that this change will last.
Quote from: Patrick M. Hausen on April 22, 2026, 06:10:58 PMThe old one going to be removed, eventually.


off topic:
After being an early adopter of KEA DHCP,  being afraid of continues use of ISC back then,
I regret the move nowadays, since I did not find a comparable migration tool to come back to ISC.
Someday I'll take the time to either learn howto use dnsmasq or switch back to ISC manually.

Cheers
#12
Dear people,

after migrating "Rules" to "Rules[new]" within OPNsense 26.1.5
I was looking for those very helpful basic rules like

.sshlockout
.allow access to DHCP server
.Default deny / state violation rule
etc.

only to find them within "Rules" (old rules) in LAN, WAN, etc.

I saw here, that these rules should have been ported to "Rules [new]".

The official documentation does not mention automatically generated within Rules [new],
only within Rules (4.)

Therefore I'm worried, that as soon as Rules are removed, this will also remove the Basic, important rulesets all along within LAN and WAN.

What has to be done now?
Am I missing something?

Cheers
#13
24.1, 24.4 Legacy Series / Re: 24.1 Bug report
February 02, 2024, 01:17:18 PM
 ;D obviously!

it worked, thanks a lot!

Cheers
#14
24.1, 24.4 Legacy Series / Re: 24.1 Bug report
February 01, 2024, 06:10:50 PM
Thanks franco!

squid error is gone!

pkg remove wireguard throws:

root@OPNsense:~ # pkg remove wireguard
No packages matched for pattern 'wireguard'

Checking integrity... done (0 conflicting)
1 packages requested for removal: 0 locked, 1 missing


wireguard-kmod still there.

I'm afk for today and check back tomorrow noon CET.

Cheers
#15
24.1, 24.4 Legacy Series / Re: 24.1 Bug report
February 01, 2024, 05:37:00 PM
thanks franco!

I'v logged in as root, ran

root@OPNsense:/usr/local/etc/rc.syshook.d/update # ./10-refresh


getting:

Writing firmware settings: FreeBSD OPNsense
Writing trust files...done.
Scanning /usr/share/certs/blacklisted for certificates...
Scanning /usr/share/certs/trusted for certificates...
Scanning /usr/local/share/certs for certificates...
Writing trust bundles...done.
Configuring login behaviour...done.
Configuring system logging...done.


rebooted the firewall and ran health report, still getting the squid error:

***GOT REQUEST TO AUDIT HEALTH***
Currently running OPNsense 24.1_1 at Thu Feb  1 17:12:28 CET 2024
>>> Root file system: /dev/gpt/rootfs
>>> Check installed kernel version
Version 24.1 is correct.
>>> Check for missing or altered kernel files
No problems detected.
>>> Check installed base version
Version 24.1 is correct.
>>> Check for missing or altered base files
No problems detected.
>>> Check installed repositories
OPNsense
>>> Check installed plugins
os-apcupsd 1.1
os-chrony 1.5_1
os-ddclient 1.20_1
os-realtek-re 1.0
os-theme-rebellion 1.8.9
os-wol 2.4_2
>>> Check locked packages
No locks found.
>>> Check for missing package dependencies
Checking all packages: .......... done
>>> Check for missing or altered package files
Checking all packages: .........
squid-langpack-7.0.0.20230225: missing file /usr/local/share/squid-langpack/af/ERR_ACCESS_DENIED
Checking all packages.... done
>>> Check for core packages consistency
Core package "opnsense" has 68 dependencies to check.
Checking packages: ..................................................................... done
***DONE***


I've checked the dir content of "/usr/local/share/squid-langpack/af"
and get this, "ERR_ACCESS_DENIED" is not there:

root@OPNsense:/usr/local/share/squid-langpack/af # ls -la
total 180
drwxr-xr-x   2 root  wheel  3584 Feb  1 13:57 .
drwxr-xr-x  48 root  wheel  1024 Nov 17 17:39 ..
-rw-r--r--   1 root  wheel  1320 Feb 25  2023 ERR_ACL_TIME_QUOTA_EXCEEDED
-rw-r--r--   1 root  wheel  1639 Feb 25  2023 ERR_AGENT_CONFIGURE
-rw-r--r--   1 root  wheel  1598 Feb 25  2023 ERR_AGENT_WPAD
-rw-r--r--   1 root  wheel  1156 Feb 25  2023 ERR_CACHE_ACCESS_DENIED
-rw-r--r--   1 root  wheel  1314 Feb 25  2023 ERR_CACHE_MGR_ACCESS_DENIED
-rw-r--r--   1 root  wheel  1477 Feb 25  2023 ERR_CANNOT_FORWARD
-rw-r--r--   1 root  wheel  1399 Feb 25  2023 ERR_CONFLICT_HOST
-rw-r--r--   1 root  wheel  1175 Feb 25  2023 ERR_CONNECT_FAIL
-rw-r--r--   1 root  wheel  1030 Feb 25  2023 ERR_DIR_LISTING
-rw-r--r--   1 root  wheel  1267 Feb 25  2023 ERR_DNS_FAIL
-rw-r--r--   1 root  wheel  1209 Feb 25  2023 ERR_ESI
-rw-r--r--   1 root  wheel  1179 Feb 25  2023 ERR_FORWARDING_DENIED
-rw-r--r--   1 root  wheel  1063 Feb 25  2023 ERR_FTP_DISABLED
-rw-r--r--   1 root  wheel  1148 Feb 25  2023 ERR_FTP_FAILURE
-rw-r--r--   1 root  wheel  1157 Feb 25  2023 ERR_FTP_FORBIDDEN
-rw-r--r--   1 root  wheel  1306 Feb 25  2023 ERR_FTP_NOT_FOUND
-rw-r--r--   1 root  wheel   716 Feb 25  2023 ERR_FTP_PUT_CREATED
-rw-r--r--   1 root  wheel  1261 Feb 25  2023 ERR_FTP_PUT_ERROR
-rw-r--r--   1 root  wheel   720 Feb 25  2023 ERR_FTP_PUT_MODIFIED
-rw-r--r--   1 root  wheel  1137 Feb 25  2023 ERR_FTP_UNAVAILABLE
-rw-r--r--   1 root  wheel  1278 Feb 25  2023 ERR_GATEWAY_FAILURE
-rw-r--r--   1 root  wheel  1268 Feb 25  2023 ERR_ICAP_FAILURE
-rw-r--r--   1 root  wheel  1852 Feb 25  2023 ERR_INVALID_REQ
-rw-r--r--   1 root  wheel  1275 Feb 25  2023 ERR_INVALID_RESP
-rw-r--r--   1 root  wheel  1394 Feb 25  2023 ERR_INVALID_URL
-rw-r--r--   1 root  wheel  1125 Feb 25  2023 ERR_LIFETIME_EXP
-rw-r--r--   1 root  wheel  1090 Feb 25  2023 ERR_NO_RELAY
-rw-r--r--   1 root  wheel  1296 Feb 25  2023 ERR_ONLY_IF_CACHED_MISS
-rw-r--r--   1 root  wheel  1083 Feb 25  2023 ERR_PRECONDITION_FAILED
-rw-r--r--   1 root  wheel  1122 Feb 25  2023 ERR_PROTOCOL_UNKNOWN
-rw-r--r--   1 root  wheel  1179 Feb 25  2023 ERR_READ_ERROR
-rw-r--r--   1 root  wheel  1238 Feb 25  2023 ERR_READ_TIMEOUT
-rw-r--r--   1 root  wheel  1432 Feb 25  2023 ERR_SECURE_CONNECT_FAIL
-rw-r--r--   1 root  wheel  1056 Feb 25  2023 ERR_SHUTTING_DOWN
-rw-r--r--   1 root  wheel  1176 Feb 25  2023 ERR_SOCKET_FAILURE
-rw-r--r--   1 root  wheel  1355 Feb 25  2023 ERR_TOO_BIG
-rw-r--r--   1 root  wheel  1077 Feb 25  2023 ERR_UNSUP_HTTPVERSION
-rw-r--r--   1 root  wheel  1106 Feb 25  2023 ERR_UNSUP_REQ
-rw-r--r--   1 root  wheel  1084 Feb 25  2023 ERR_URN_RESOLVE
-rw-r--r--   1 root  wheel  1181 Feb 25  2023 ERR_WRITE_ERROR
-rw-r--r--   1 root  wheel  1074 Feb 25  2023 ERR_ZERO_SIZE_OBJECT
-rw-r--r--   1 root  wheel  7409 Feb 25  2023 error-details.txt


I've compared this to the other opnsense.
Here I don't have "squid-langpack" dir within /usr/local/share/

My idea was to copy "ERR_ACCESS_DENIED" from there.

wireguard-kmod is still available.
Initially (in 2019) wireguard was installed through plugin section as a plugin.
I did not install wireguard-kmod manually or "locked" it.