Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - passeri

#1
Hardware and Performance / Re: Wireless
February 09, 2026, 05:41:34 AM
Do you mean an AP to attach to an interface on an existing Opnsense box?

At face value you are asking to run Opnsense on an ARM A53. How would you propose to do that with proven software?
#2
26.1 Series / Re: upgrade from 25.7.11_9 and ISC
February 03, 2026, 11:02:03 PM
There are no special considerations I have seen mentioned, use of ISC or Kea or DNSmasq being essentially independent from the upgrade. ISC changes to being a plugin but still transitions as expected, or so I read because I had switched to Kea prior. Use snapshots and upgrade stuff in the order that pleases you. If you are not already using ZFS then consider seriously a reinstallation to employ it, before other work.
#3
Quote from: waxhead on February 03, 2026, 07:07:00 PMI don't use everything in the menu, ... for example stuff like ... services->ISC DHCP ...
It would be great if it was possible to click a button to hide
Without detracting from your general point with which I agree, if you are on 26.1 and not using ISC DHCP then go to -->firmware-->plugins and bin it. The menu vanishes.
#4
26.1 Series / Re: 26.1 - Success
February 03, 2026, 10:14:21 AM
Migrated the main firewall and rules successfully, today. The new rules view is a structural improvement for me, making it easer to perceive and potentially change these configurations.
#5
26.1 Series / Re: 26.1 - Success
February 02, 2026, 10:53:14 PM
I have upgraded a test bed and an internal router, including successful migration of rules (yes Franco, we all charge in). I will probably do the critical edge firewall today. Being able to snapshot the working 25.7 and then the base 26.1 before rule migration provides nice security, or encourages diving in.
#6
25.7, 25.10 Series / Re: [SOLVED] hostwatch at 100% CPU
January 21, 2026, 05:25:27 AM
Just to mention, on one test box and two operational boxes, all bare metal Intel and AMD, hostwatch trots along quietly with no untoward CPU spikes or log writes. Three principal subnets (no vlans), all IPv4, around 25 devices.
#7
25.7, 25.10 Series / Re: clarification of snapshots
January 18, 2026, 03:24:56 AM
Quote from: tessus on January 18, 2026, 02:07:17 AMSo how can I rollback or switch to a point where the new firmware was not installed, if the operations are persisted
This is, in terms of my explanation, a configuration change. It is not part of the snapshot, so you can still roll back to the prior configuration.
#8
25.7, 25.10 Series / Re: clarification of snapshots
January 18, 2026, 01:36:36 AM
This appears to be the question:
Quote from: tessus on January 17, 2026, 05:38:16 AMMy problem of understanding is why and when will a snapshot in OPNsense start to persist data? When I make it active for the first time? If so, this means I cannot use (rollback to) a snapshot more than once. e.g. how do I rollback to Sept. 2025 when the "default" snapshot was created?
Somehow there is a disconnect I cannot reconcile.
and this is a lay answer from my use of snapshots: essentially, you do not roll back to a date but to a version.

If I take a snapshot then I am preserving a (presumably) stable version. All normal operations of the router will continue to be reflected in that snapshot version as well as in the active. That is, it continues to update for operations ... but not for configuration.

Any configuration changes will be reflected in the Active version but not in the Snapshot version. If you like the changes and they are stable, you can make that the master simply by continuing to use it while optionally deleting the Snapshot. If you do not like the changes then revert to the Snapshot in which case your configuration changes will vanish yet the router will be operationally up to date. If your changes crash the router then you can recover safely to your snapshot on boot.

Snapshots reflect a configuration point, not a time point.

I will be interested to see whether my understanding is confirmed.
#9
Given the base is working software, not a development from scratch, I can understand that the release pattern does not follow a conventional cycle such as one might read in Wikipedia. I interpret development as a form of beta which is yet changing for reasons other than bugs. Community I accept as an advanced stable release which may yet have bugs which are fixed under _NN releases. Business is a supported stable release which might be called long term except that its term is not long.

Opnsense is not the only operation to follow a pattern like this, nor the only forum in which it is argued. I think that the conventional namings from alpha through gold, including the word beta, confuse the issue by their prior connotations.

We have a stable base product. On that there is a development offshoot. When that is feature-complete (for this phase) and stable it becomes Community, field testing more advanced features ahead of the low-risk business edition.

The clear implication is that there are three levels of risk for the consumers who must themselves share the risk management as discussed, firstly by selecting in which level they will join and secondly by their own testing and timing of upgrades on one or more of their own systems. Personally I use select Community then upgrade (always with snapshots) through "Does it work for a few hours?" on a reserve box to "Does it work for a few days?" on an internal production box to "Here we go" on the edge router.
#10
General Discussion / Re: Wireless Access Points
January 16, 2026, 01:48:41 AM
Mikrotik offers WiFi6 devices such as the wAP and cAP but not mesh as plug and play. On the other hand, they give you absolute control of every other aspect of operation including nigh-endless vLans or virtual radios. Do you have ethernet between the levels?
#11
General Discussion / Re: Wrong username or password
January 12, 2026, 03:17:41 AM
Given you commented on the date and time, are you using the TOTP feature?
#12
Quote from: manki_09 on January 11, 2026, 11:01:56 PMI currently have shaping turned off. I tried shaping as a troubleshooting step to limit the speed to 1gb but nothing changed.

The intel x550 NICs will not auto negotiate to 2.5gbps. Which is programmed into the firmware. Manual selection is required. This is why I have a 2.5gb usb nic order so I can test if the NIC is at fault.
I see. You mean like this comment which I found on the Intel site here?
Quote from: Intel engineerThe autonegotiation for 2.5 and 5Gb speeds for the X550 was changed in 2020.

Default autonegotiation excludes the 2.5 and 5Gb speeds.

If 2.5 or 5Gb is chosen in the dropdown, it will change autonegotiation to only advertise that speed. So it is not forcing to 2.5Gb or 5Gb when those options are chosen, it changes the advertised speed.

That may be an issue if the switch is configured as forced to 2.5Gb instead of autonegotiate.

If that still does not help, please make sure the ethernet updated to the latest NVM and drivers.

This comment and the prior discussion on the Intel site imply to me that the problem may lie with NIC configuration rather than with Opnsense config. Your proposed test may be informative ("may" because I lack complete confidence in USB-Ethernet adapters even though I sometimes use them in testing).
#13
You are shaping the WAN-side speed? What was the preceding position, when using auto-negotiation?
#14
@xXHelperXx, I think you misunderstood the meaning of "here". The problem with using an image service is it is more likely to disappear, leaving this thread largely incomprehensible to anyone who might have a similar problem in the future. Is there any particular reason you are unable to post images here, within your replies, rather than as links?

Regarding your further comment, are you filtering on the interfaces or on the bridge? https://docs.opnsense.org/manual/how-tos/lan_bridge.html (see Step Six, System Settings Tunables)
#15
Quote from: xXHelperXx on January 05, 2026, 11:53:06 PMNot really sure why it still block and why especially on LAN and not on VPN.
Different rules, most likely. LAN and Wireguard are not the same subnets.

If you publish your rules here, I will look at them to see whether I can help. Using imgur is not publishing here.