Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - rfox

#1
Just updated from 26.7.1 to 26.7.2 then 26.7.2_2 - and now I'm getting a fingerprint error when checking for updates using default mirror - Anyone else ??

Quick update - after trying again 5 minutes later - it works again.  Issue seems sporadic
#2
Just updated my production 26.1.11 instance to 26.7 with ZenArmor - and everything looks great!  Congrats on the new release . . .

Quick question, I don't use the ZA Cloud Agent - which shows up RED on my dashboard - is there a way to get rid of that eyesore ?  The dashboard widget doesn't seem to allow hiding of individual services on the GUI ?  Maybe a future feature, offer the ability to toggle what services show on the dashboard . . .

Thx and once again, great release!



#3
Quote from: franco on July 09, 2026, 01:00:37 PMI'm assuming this since the file could have been created before ntp corrected the time. A forced update may fix it?


Cheers,
Franco

Congrats on 26.7 release!!  I have since updated to 26.7 from my production 26.1.11 instance - all looks good, including Zenarmor - Unfortunately, this issue still exists in 26.7 after upgrade - and reboot

Should I report this in 26.7 forum ?

#4
Quote from: Patrick M. Hausen on July 15, 2026, 03:51:18 PMYou mean like in the official release announcement?

Quoteo Since this is a major OS upgrade and OpenSSL changes from 3.0 to 3.5 third party repositories may interfere with your upgrade experience.  Removing offending repositories and plugins may help; or wait for affirmation from the respective repository owners.

EDIT: and here's the matching announcement from Sunny Valley.

Thanks for that - but it's a bit hidden in the forum specific to ZA - My suggestion is a reference in the main 26.7 Release announcement - to avoid such misunderstandings upfront . . . as ZA is quite popular and not everyone ready the ZA Forum specifically . . .
#5
Quote from: Patrick M. Hausen on July 15, 2026, 03:39:56 PMIt isn't, but ZA is a third party product, OPNsense cannot take responsibility for. Sunnyvalley's job.

Congrats on the 26.7 release!  I also got caught by updating a test machine with ZenArmor Sensei - and it also failed to start ZA after the update
Agree that ZA is considered third party - but seeing as many rely on this extra plugin, maybe there should be a warning for 26.7 release that "those who are using ZA should wait until Sunnyvally releases a compatible version for 26.7 - as an Upgrade will break this feature" 

Just a suggestion!
#6
Good guess Franco - but don't think so - machine is only 1 year old and system time seems fine - this is only the "update" timestamp for Dyn DNS

#7

Not sure if this is a bug, but the dashboard widget for Dynamic DNS is showing an incorrect timestamp of 01/01/1970 - although it appears to be updating the DNS entry ?!?





#8
Quote from: nero355 on February 15, 2026, 03:49:57 PM
Quote from: rfox on February 15, 2026, 12:12:07 PMNow how do I mark this post a "Solved" ?!?
Edit the Title in your Topic Start Post/Comment :)

Thx - DONE!
#9
Well that was quick - after experimenting around I think I solved it myself - as FYI for those curious, I had Zenarmor configured to use "native netmap" - since forever - after changing to "emulated netmap" it works again . . .

File this under "Good to know" category!  Now how do I mark this post a "Solved" ?!?

Happy Sunday to all . . .
#10
Greetings - just noticed on my 26.1.2 updated virtual instance - seeing flatlines on all internal interfaces in the Reporting > Traffic menu
When I show WAN traffic, it works ?!?  Prior to upgrading from 25.7 and changing to new rules, this was working ??

Netflow cache not showing data (see attached pic)- I tried repairing then resetting the netflow data - no change

YES - I'm running Zenarmor - and when I turn it off - the data seems to flow again (as opposed to last time this happened it didn't help) ?!?

Similar issue as reported in this post:
https://forum.opnsense.org/index.php?topic=45608.msg228098

Any hints what can be done short of uninstalling Zenarmor?

I'm tempted to perform a fresh install and import my config file and take my chances . . . This instance has been updated since I think 23.1 version ?!?

Thx in advance -
#11
Quote from: franco on February 06, 2026, 12:02:33 PMLatest ports update for crowdsec will hit 26.1.2. We had to freeze ports for the release procedure of 26.1 to avoid last minute surprises and 26.1.1 was "rushed" out for OpenSSL/Python which should have been in 26.1 but would have "exploded" the 26.1 release timeline. ;)


Cheers,
Franco

As usual, your prompt response is appreciated and on point!  Thx Franco and have a great weekend in advance . . .
#12
Just wondering about Crowdstrike updates - do we have to wait until the plugin maintainer updates the plugin or is there another way?

BTW - Updated to rules(New) and all is well ;-)

#13
Quote from: franco on February 03, 2026, 05:17:39 PMFeel free to wait a bit. 26.1.1 brings a lot of immediate feedback improvement and a few fixes. It will get even better in later 26.1.x IMO.


Cheers,
Franco

Now I upgraded to 26.1.1 - looking fine . . . Before I migrate the rules, just one last question - Besides the presentation (GUI) changes on the new Rules interface - are there any other benefits (performance, logic, etc) to migrate from old rules ??

Thx and keep up the great work!
#14
Just wanted to report another successful upgrade from GUI to 26.1_4 from 25.7.11_9 on a home lab Proxmox VM instance . . . I decided to keep ISC DHCP for now, but not sure about converting to new ruleset GUI (Tried in a test instance with simple install and all worked well)

My rules are not very complex, although I have multiple VLANs and setup Firehole many moons ago as floating rules - so worried about breakage.

Should I wait a bit or take the plunge with new rules ??  Fun thing, with snapshots and VM backups - can always revert ;-)

Great update!  Many Thanks . . . and congrats!
#15
Quote from: franco on January 30, 2026, 02:15:47 PMWith Zenarmor in your list I would recommend waiting for 26.1.1 next week just to be sure. You can keep ISC-DHCP for the foreseeable future. I'm certainly guilty of it too.  ;)

If you want to migrate to Dnsmasq you can do it in 26.1.x or 26.7.x. ISC-DHCP won't be gone in 2027 if things continue as normal but it's likely going to drop to community plugin status by then.


Cheers,
Franco

Thanks Franco for the prompt response!  Filed under "good to know" ;-)  Have a great weekend in advance!