Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - wirefall

#1
Quote from: dirtyfreebooter on September 30, 2025, 04:10:32 PMyea i guess i was hoping to be able to use N-series intel boxes, like N100/N150 or N-305/N-350 with Zenarmor + Wireguard at 1-2 Gbps. Wireguard is very good at going across cores, but Zenarmor will peg 1 cpu so you can't have both, Zenarmor + Wireguard, even though there is CPU leftover.

the whole businesses trying to use the home subscription is absolute bullsh*t. meanwhile, you get tons of free testing from home users. The whole SASE stuff, i don't care about any of that as a home user. i want to use low powered device without sacrificing my internet connection.

i picked up a UniFi Fiber gateway and $99/year Cybersecure subscription. This has come a long way in 1 year with regard to content filtering. Its still in pre-release software, but its very close to Zenarmor in terms of content filtering, etc. Using suricata, content filter, is all multi-threaded, no limits, so this is getting interesting at least.

i prefer OPNsense as a router. zenarmor is nice, even with its upgrade warts. As a home user, i just want some decent content filtering, be able to use my full fiber home connection, and do it on the lowest possible power device. zenarmor makes this easy in some ways and extremely difficult in others.


+ 1
#2
Thank you very much for this important improvement :-) This is indeed a main argument to keep my home plan, as I can now achieve the needed granularity without fiddling with compromises as a result of only 3 policies.

Please consider to include also multicore support in home plan, thanks in advance :-)
#3
Quote from: almodovaris on May 26, 2025, 12:25:55 PMI use cheap miniPCs as firewalls. They can do 1 Gbps Zenarmor without problems. So, for me multicore Zenarmor is not needed.

Hm, n = 1. Do you think your solitary case is representative for all the rest?
#4
I understand a company needs to make money. I am therefor happy to pay for my home subscription. If multicore support won't be in the free version, ok for me. Not nice, as multicore is plain standard nowadays as you other guys correctly stated, but ok.

It won't be ok however not to include multicore in home subscription. The upper plans are too pricey for my home purposes. I really think to quit home subscription, as I do not agree with that policy.

Think twice, if I were you, I would offer multicore for free, or include in home subscriptions whatever, to get more customers. Otherwise I guess you would lose them...
#5
Zenarmor (Sensei) / Re: 1.18 Wireguard is disconnected
November 03, 2024, 12:06:26 PM
Good to hear you could solve it. Meaning also, 1.18.1 should work properly with WG.
#6
Zenarmor (Sensei) / Re: 1.18 Wireguard is disconnected
November 02, 2024, 09:28:13 PM
I don't use Suricata, so this could confirm your findings.
#7
Zenarmor (Sensei) / Re: 1.18 Wireguard is disconnected
November 02, 2024, 08:35:54 PM
Interesting, I haven't noticed this zenarmor overlay WG thing so far. You've got the answer about this in your other thread, this is a zenarmor WG thing for future release.

Question is, if this thing could interfere somehow with your standard WG interface. However, I could find this overlay the same way as in your setup, but WG is still working as expected here (just checked again). Regarding WG itself I pretty much followed the setup in the OPNsense documentation.
#8
Zenarmor (Sensei) / Re: 1.18 Wireguard is disconnected
November 02, 2024, 04:39:53 PM
Hmm, here is all ok so far, about one day uptime with the new version.

But that was the same with the initial update 1.18. Have you rebooted after 1.18.1?
#9
Zenarmor (Sensei) / Re: 1.18 Wireguard is disconnected
November 01, 2024, 07:10:09 PM
1.18.1 just has been released to fix the WG issue.

Looks good so far.
#10
Zenarmor (Sensei) / Re: 1.18 Wireguard is disconnected
October 29, 2024, 07:59:57 PM
Quote from: wirefall on October 27, 2024, 07:55:08 PM
I haven't changed anything in Zenarmor, WG interfaces have always been in. WG works again after 2 restarts, for over 2 days now reliable. However there was definitely something wrong with WG right after update, all connections to quite some peers outside were broken.

As I haven't changed any setting (only restarting), this keeps to be strange...

UPDATE: After another 2 days WG is broken again! Unpleasant surprise. Nothing has been changed, so this is rather unreliable. Another reboot seems to fix it, but for how long??

Please fix this soon, as I really need WG remote access. As I paid for a Zenarmor plan I count on the Zenarmor features even on the road. I am not willing to disable WG interfaces in Zenarmor, as there is quite a reason why I have them there. Thanks for your efforts in advance!
#11
Zenarmor (Sensei) / Re: 1.18 Wireguard is disconnected
October 27, 2024, 07:55:08 PM
I haven't changed anything in Zenarmor, WG interfaces have always been in. WG works again after 2 restarts, for over 2 days now reliable. However there was definitely something wrong with WG right after update, all connections to quite some peers outside were broken.

As I haven't changed any setting (only restarting), this keeps to be strange...
#12
Exactly the same here, logs show the same. Restart helps.
#13
Zenarmor (Sensei) / Re: 1.18 Wireguard is disconnected
October 27, 2024, 11:23:30 AM
I think I had this problem, too. Right after 24.7.7 update WG stops to work. I always saw a 124kb received from WG/OPNsense (e.g. on my iPhone), then it stops.

However, after some restarts this problem is just gone. WG works as expected and I haven't touched anything. Strange.

See here: https://forum.opnsense.org/index.php?topic=43653.0
So maybe it is not related to Zenarmor?
#14
That is exactly the solution I have got from support some days ago and can confirm all works perfectly after reset and re-install via webgui.
#15
Fehlende bzw. falsche Zeitsynchronisation kann schon allerhand "Schweinereien" machen, bestimmte Geräte reagieren da schon mal sehr empfindlich. Z.B. bei TP-Link Omada, Lancom soll auch ein "Kandidat" sein. Hatte ich tatsächlich mit dem auch hier verwendeten DrayTek Vigor 167, da war das so weit auseinander, dass Nichts mehr lief mit OPNsense. Bin ich auch erst nach laaaaaanger Fehlersuche drauf gekommen. Hat also schon seinen guten Grund, weshalb die Zeitsynchronisation in den Einstellungen vorgesehen ist  :)

Zeit synchronisiert und schon flutschte alles wie es soll. Seitdem ist das einer der Dinge, die ich bei fehlender Funktion des Netzwerkes standardmäßig prüfe. Umgekehrt ist der hier gezeigte Weg (wie vergleichbar auch bei anderen Geräten) gewissermaßen Pflicht, im Sinne dass man sich auf die vorgenommenen Einstellungen bei allen Netzwerkgeräten verlassen kann.

Die NTP (bzw. NTS) Abfragen kann man dann ja gut im Live View sehen.

Dann noch vielleicht Chrony dazu und NTP redirect to Unbound  :)