Quote from: gpb on August 02, 2026, 04:01:20 PMIn Firewall - Settings - Advanced, do you have "Disable Anti-lockout" checked?
Unchecked
This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.
Show posts MenuQuote from: gpb on August 02, 2026, 04:01:20 PMIn Firewall - Settings - Advanced, do you have "Disable Anti-lockout" checked?
Quote from: viragomann on January 28, 2026, 02:18:13 PMThe guide suggests to do policy-routing for all LAN traffic in step 4. This means any traffic would be sent out to the current upstream gateway (gateway group). Hence you would not be able to reach any internal destination, even not OPNsense itself.
The suggested rule in step 5 would allow DNS only to OPNsense befor this.
If DNS resolution on your internal devices works anyway without it, you either didn't state the gateway in step 4 or your internal devices are not configured to use OPNsense for DNS resolution.
Quote from: OPNenthu on December 07, 2025, 09:25:44 AMThe release notes for 25.7.8 have an important note:
https://forum.opnsense.org/index.php?topic=49869.0QuoteThe Unbound blocklists feature formerly known as a business feature is
now a community feature. Since this required merging both the existing
community one with the business one you need to make sure to reapply the
blocklist settings after the reboot since it will not generate a new and
possibly incompatible format. Make sure to check your automatically
migrated settings while at it.
Maybe this is it?
Quote from: Patrick M. Hausen on December 06, 2025, 11:57:37 AMIn general it doesn't. I run it at multiple offices and an entire data centre with that setting and no problems at all.
Something about your configuration must be unusual. Still pondering what that might be. Did you change the interfaces setting for Unbound, possibly? Something in private networks?
Quote from: Patrick M. Hausen on December 05, 2025, 01:57:42 PMThen probably enable:
Services > Unbound DNS > Advanced > Log SERVFAIL
Quote from: Patrick M. Hausen on December 05, 2025, 01:57:42 PMThen probably enable:
Services > Unbound DNS > Advanced > Log SERVFAIL

Quote from: Patrick M. Hausen on December 04, 2025, 05:13:37 PMLook at the Unbound log files for the cause of the SERVFAIL - how often do I need to repeat this?
Quote from: Patrick M. Hausen on December 04, 2025, 04:45:17 PMAs I wrote: investigate the cause of the SERVFAIL by looking at the log files.
Quote from: Patrick M. Hausen on December 04, 2025, 04:41:04 PMProbably local resolution fails entirely. You need to investigate the logfiles to find the cause of that SERVFAIL.
Your browsers continue to work because modern browsers implement their own methods of name resolution.



Quote from: viragomann on December 10, 2024, 06:54:23 PM
It would also be possible if both have the same though, but then they need different LAN IPs and you can only connect a single WAN of OPNsense to them, means you need also a switch between the devices.