Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - Taunt9930

#1
Quote from: Patrick M. Hausen on August 09, 2026, 10:00:35 PMThey have a false positive reporting form in your TIP.

Yep, submitted. Just wondered if there was anything worth doing in the meantime. Hopefully it'll be reviewed swiftly.
#2
AHH, brilliant - thanks both - I missed that. Didn't think to search for 43.131.0.0. (Yes, I'm on plus).

What's the best way to whitelist/bypass for that single address? I notice you can add domain whitelist in qfeeds, but not sure you can add an IP?
#3
Quote from: vk2him on August 09, 2026, 12:14:10 AMI searched the qfeeds block file and 43.131.7.8 isn't contained there.

virustotal.com also shows zero reported security issues wirh that ip

Vendors Analysis:
No security vendors flagged this URL as malicious
Final URL:
http://43.131.7.8/
Domain:
43.131.7.8

Look at your logs to see why it's being blocked for you?

All of that is in my original post.

It is being blocked by the qfeeds rule - as indicated by the firewall log, and as indicated by being in the qfeeds event list - despite, as I said above, not being on the IOC list, or the qfeeds alias list on the device itself.

Disabling the qfeeds rule resolves the problem.
#4
Hi All,

I am not sure if this is a Q-feeds issue, OPNSense Firewall Issue, or a me issue.

After working for some time, I noticed the other day that my Aqara presence sensors can no longer be controlled by the Aqara app. Upon looking at the OPNSense firewall live log, it appears that connections from those devices into the firewall/out to the internet is suddenly being blocked by my Qfeeds rule blocking connections to the qfeeds created malware-ip feed.

EDIT: The event is also shown in the Qfeeds events pane.

When I search for the IP on the TIP, nothing comes up - no IOC's.

This (happily) appears to be the only connection being blocked by this rule - connection to this IP from the two Aqara Device IP's.

EDIT: If I go to firewall > Diagnostics > aliases and select the qfeeds malware alias in the dropdown, and search for the IP, it does not appear to be in the list. Why is it being blocked? What can I do to work out why this is suddenly being blocked. If I disable the qfeeds rule, all is well.

The IP in question is 43.131.7.8

Thanks - I appreciate any help anyone can give!
#5
Quote from: Lukas L. on July 24, 2026, 06:09:33 PMThere seems to be some cloudflare wrong-doings. Either i'm told I've been limited or
Error 1000 Ray ID: a20430019928d268 • 2026-07-24 16:09:08 UTC
DNS points to prohibited IP

Error 1015 Ray ID: a204460fdb0cd268 • 2026-07-24 16:24:11 UTC
You are being rate limited

Yes, there was an issue yesterday that was quickly resolved after I submitted a ticket. All OK now for the Cloudflare issue.
#6
That's a shame, I thought that would probably be the case - except for a very select few people, the same constraints/complaints about the Home tier remain for most. 
#7
Should we be being offered an update to 2.6.x? Version 2.5.1 from May 22 is showing as up to date for me.
#8
Yeah, I have noticed massive battery drain on my mobile when connected via WiFi at home recently caused by the email client, and also unable to send emails. When I have checked Tip, exchange2019.ionos.co.uk is also on the list which is Ionos UK Exchange Server for all their customer emails.
#9
Hi all, I have been following this thread for a while with the thought evolution and also the changes in 26.1 related to interface tracking. My IPv6 experience is not very good, and I am certain it is a misconfiguration on my part and I have lost my way somewhere.

Is there a latest and greatest summary of optimum setup steps that include the most recent changes to interface tracking that I can follow? I use DNSMasq for my DHCP if that matters. I have both windows and android devices on my main Vlan I wish this to be enabled on and get delegated a /48 prefix on Zen UK.

Thanks.

Thanks.
#10
Is there any more detail on the premium DNS? E.g. how to see if it is active and best ways to use it etc? Thanks. Keep up the great work!
#11
26.1, 26,4 Series / Re: 26.1.1 MTU Issues on PPPoE
February 13, 2026, 05:55:11 PM
Quote from: Enverex on February 11, 2026, 01:04:56 PMI'm seeing the same issue. I found this thread before upgrading so I blanked all the MTU boxes prior to upgrading, but putting 1508 back into the PPPoE adapter post upgrade also results in breaking a lot of the internet as other people here mentioned. I've had to go back to blank/default for now which isn't ideal.

Has anyone who has seen this issue tried 26.1.2 yet? I am stumped.

EDIT: Setting WAN MTU to Blank on 25.7.11_9, and upgrading to 26.1.2 and then setting it back to 1508 works. It now works as before, and gives expected results of 1440 and 1460 here http://pmtud.enslaves.us/
#12
26.1, 26,4 Series / Re: 26.1.1 MTU Issues on PPPoE
February 11, 2026, 04:18:47 PM
Quote from: Enverex on February 11, 2026, 01:04:56 PMI'm seeing the same issue. I found this thread before upgrading so I blanked all the MTU boxes prior to upgrading, but putting 1508 back into the PPPoE adapter post upgrade also results in breaking a lot of the internet as other people here mentioned. I've had to go back to blank/default for now which isn't ideal.


AHH, that saves me trying that then. Clearly something has changed in the implementation but it only affects a subset of previously working setups.

#13
26.1, 26,4 Series / Re: 26.1.1 MTU Issues on PPPoE
February 11, 2026, 10:24:00 AM
Quote from: Boxer on February 10, 2026, 10:30:34 PMI would roll back to 25.7.11_9, delete your wan mtu and leave it blank, reboot. Then update to 26.1 and re-enter your wan mtu 1508. Maybe there's some shenanigans during the update

That's not a bad idea. It's possible I've already tried that, but I'll re-visit later when the house is empty.
#14
26.1, 26,4 Series / Re: 26.1.1 MTU Issues on PPPoE
February 10, 2026, 10:28:03 PM
Quote from: meyergru on February 10, 2026, 10:13:08 PMThis does not look like an MTU issue if you can use those ping sizes - it look just fine.

Did you also use traffic shaping? Maybe the old ISP had lower speeds and you shape it to fit? Happened before...


Just saw that you disabled all shaping...

No idea what could be wrong.

It's a weird one, isn't it!?

When I've got more time I'll try a 3rd update from the working 25.7 snapshot.
#15
26.1, 26,4 Series / Re: 26.1.1 MTU Issues on PPPoE
February 10, 2026, 10:10:23 PM
Quote from: Boxer on February 10, 2026, 10:00:16 PMI'm on BT PPPOE (Openreach) and just set the wan mtu to 1508 without any issues on websites. Are you on Zen Openreach or Zen City Fibre?


Openreach. As said, been running that config with no issues since around 23.7.5 and as per Meyergru (with physical interface explicitly stated) before that.

Upgrade to 26.1 breaks something. I've done it twice now, same result.