Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - Rockyuk

#1
Hi all,

I've been experiencing an issue with my OPNsense firewall where the system becomes unresponsive approximately every 2–3 weeks. The most recent incident occurred on April 5th, with the system locking up around 01:00 and remaining unresponsive until I manually rebooted it just after 06:00.

System Info:

OPNsense Version: 25.1.1 (amd64) with Zenarmor    1.18.6 - Feb 10, 2025

FreeBSD 14.2-RELEASE-p2

CPU: Intel Core i5-3450

Memory: 16 GB

Storage: 256 GB SSD (SMART tests passed)

ZFS file system

What I've Done So Far:

Log Collection & Review:

Collected /var/log/system/system_20250405.log, dmesg.today, and other logs before/during the outage.

No clear errors or kernel panics noted in dmesg or /var/log/system.

Performed dmesg | grep -iE "memory|panic|fault|fail|segfault|ECC" — no suspicious output.

Disk Health:

Ran SMART self-tests on the SSD — all tests passed with no bad sectors or errors.

SSD life left is at 81%, and write cycles are well within tolerance.

Unbound Service:

Investigated Unbound as a possible cause, including verifying its runtime state, config consistency, and control interface. No errors or conflicts were observed.

Suricata and Zenarmor:

Checked Suricata logs — no evidence of high resource usage or crash during the outage.

Zenarmor logs were not found in the default directory; may not be configured for log persistence.

System Performance:

Resource usage (CPU, memory, swap) appears healthy before and after reboot.

No abnormal spikes or saturation were seen in interface statistics via Flow Interface Totals.

Despite all this, the root cause remains elusive. I would greatly appreciate it if anyone with a similar experience or insight into possible culprits (e.g., hardware compatibility, driver issues, kernel bugs, plugin conflicts) could share their thoughts or recommendations.

Thanks in advance!

Rockyuk
#2
25.1, 25.4 Series / Re: IDS Alerts
March 28, 2025, 09:13:05 AM
Update OPNsense 25.1.4_1-amd64 Resolved it.

Thanks

Rockyuk
#3
25.1, 25.4 Series / IDS Alerts
March 28, 2025, 09:00:53 AM
Hi Everyone,
Maybe it's just me, but after the recent update, under ID, then Administrator, when I click on alerts, it gets stuck on processing a request. It was working fine before the update.

Versions
OPNsense 25.1.4-amd64
FreeBSD 14.2-RELEASE-p2
OpenSSL 3.0.16

Thanks

Rockyuk
#4
Ok, after digging a little deeper I did a packet capture on the Apps on my Android phone RTP & STUN are being blocked and some DNS queries on port 53.

#5
Nope, I don't think I did, so I am assuming there is not much else I can do in terms of rolling back?
#6
I can ping and connect to the devices fine the only issue is they will not play live video anymore. Just randomly stopped after the update.
#7
24.7, 24.10 Legacy Series / Video Doorbells/IOT Devices
September 16, 2024, 03:33:09 PM
Hello Everyone,
Has anyone updated to 24.7.4_1? Since I have updated I cannot see any live video views (doorbell and indoor CCTV) via my WIFI MESH, before the updates it was working perfectly. I'm not sure what could have changed that via the update is anyone else having similar issues?

Thanks

Rockyuk
#8
Well that's embarrassing lol, Thank you
#9
Hello Everyone,
I am a newbie from pfsense and finally managed to get Opnsense up and running. However I am getting a few issues, if I enable IPS it blocks all external traffic for updates, plugins etc. Has anyone else experienced this and how did you fix it, please? I forgot to mention it also blocks signature updates as well.

Thanks

Rockyuk
#10
Hello Everyone,
I have been struggling to set up Zenarmor on Opnsense v24.7.2, I worked out that if I enable IPS on this very it stops all internal firewall downloads. If I disable it the system comes back to life but I am getting the following error



As you can see from the image below everything is disabled I even tried to disable it manually via the console and still got the same error



Any help would be much appreciated

Thanks

Rockyuk
#11
General Discussion / pfSense to Opnsense
August 23, 2024, 01:38:53 PM
Hello Everyone,
I have finally made the move from pfSense to Opnsense but I am getting stuck on a few things. I am not used to the Opnsense interface and getting a little frustrated finding what I am looking for. The first thing is the firewall alerts if I want to see what is blocked and if I need to whitelist things I cannot find the logs or section for this.

I am also running a web server, and my WordPress sites are timing out, they also use a Redis cache server to speed up load times but my WordPress sites are loading slow. So, I assume something is being blocked as on my pfsense they were blazing fast and now I can't even login to the admin area.

If I can find the alert logs I can start diagnosing what's being blocked and start whitelisting things and getting things back to normal. Regarding IPS logs do I need to enable something for the alerts to work as I have never used Suricata before. I used to use snort, default firewall rules and pfBlocker-NG. I knew where to configure rules and whitelists but on Opnsense I cannot seem to find what I am looking for so any help would be much appreciated.

Thanks

Rockyuk
#12
General Discussion / Fresh Install
April 05, 2022, 11:10:32 AM
Hello Everyone,
I have just completed a fresh install of the latest version of Opnsense, I finally managed to get my WAN connection working which updates and checks for updates fine etc. I am not getting any LAN traffic and it is driving me crazy! During the initial setup have I accidentally missed something?

Is the not an automatic NAT or is this something you need to setup after a fresh install?

Thanks

Rockyuk