Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - teb

#1
25.7, 25.10 Series / Re: Memory protection faults
December 17, 2025, 02:48:12 AM
Thanks guys!  It's definitely RAM.. now I just have to find some that won't take 3 weeks to get to me, or cost me a kidney.
#2
25.7, 25.10 Series / Memory protection faults
December 16, 2025, 02:27:36 AM
I have been getting a lot of memory protection faults in the last couple weeks.  This is on an official OpnSense DEC2750.  I am thinking the RAM has gone south, so I was going to order replacement.  It looks like it is DDR4, but in what configuration?  2x4GB? 

I got this a while ago, so I can't imagine there is a warranty on it that is still valid.

Is there something else I should look at? 

Thanks,
Travis

system_20251213.log:<13>1 2025-12-13T22:39:54-05:00 mira.domain.org kernel - - [meta sequenceId="228"] <118>[4] savecore 245 - - reboot after panic: general protection fault
system_20251214.log:<13>1 2025-12-14T02:41:49-05:00 mira.domain.org kernel - - [meta sequenceId="190"] <118>[4] savecore 230 - - reboot after panic: general protection fault
system_20251214.log:<13>1 2025-12-14T15:27:22-05:00 mira.domain.org kernel - - [meta sequenceId="190"] <118>[4] savecore 237 - - reboot after panic: general protection fault
system_20251214.log:<13>1 2025-12-14T18:40:23-05:00 mira.domain.org kernel - - [meta sequenceId="189"] <118>[4] savecore 245 - - reboot after panic: page fault
system_20251214.log:<13>1 2025-12-14T22:32:22-05:00 mira.domain.org kernel - - [meta sequenceId="189"] <118>[4] savecore 230 - - reboot after panic: general protection fault
system_20251214.log:<13>1 2025-12-14T23:29:41-05:00 mira.domain.org kernel - - [meta sequenceId="19"] [3391] panic: general protection fault
system_20251214.log:<13>1 2025-12-14T23:29:41-05:00 mira.domain.org kernel - - [meta sequenceId="24"] [3391] vpanic() at vpanic+0x161/frame 0xfffffe00cdb97ae0
system_20251214.log:<13>1 2025-12-14T23:29:41-05:00 mira.domain.org kernel - - [meta sequenceId="25"] [3391] panic() at panic+0x43/frame 0xfffffe00cdb97b40
system_20251214.log:<13>1 2025-12-14T23:29:41-05:00 mira.domain.org kernel - - [meta sequenceId="36"] [3391] KDB: enter: panic
system_20251214.log:<13>1 2025-12-14T23:29:41-05:00 mira.domain.org kernel - - [meta sequenceId="224"] <118>[4] savecore 225 - - reboot after panic: general protection fault
system_20251215.log:<13>1 2025-12-15T01:00:54-05:00 mira.domain.org kernel - - [meta sequenceId="26"] [5421] panic: general protection fault
system_20251215.log:<13>1 2025-12-15T01:00:54-05:00 mira.domain.org kernel - - [meta sequenceId="31"] [5421] vpanic() at vpanic+0x161/frame 0xfffffe00cbdeeaa0
system_20251215.log:<13>1 2025-12-15T01:00:54-05:00 mira.domain.org kernel - - [meta sequenceId="32"] [5421] panic() at panic+0x43/frame 0xfffffe00cbdeeb00
system_20251215.log:<13>1 2025-12-15T01:00:54-05:00 mira.domain.org kernel - - [meta sequenceId="46"] [5421] KDB: enter: panic
system_20251215.log:<13>1 2025-12-15T01:00:54-05:00 mira.domain.org kernel - - [meta sequenceId="235"] <118>[4] savecore 225 - - reboot after panic: general protection fault
system_20251215.log:<13>1 2025-12-15T01:42:09-05:00 mira.domain.org kernel - - [meta sequenceId="190"] <118>[4] savecore 225 - - reboot after panic: general protection fault
system_20251215.log:<13>1 2025-12-15T08:09:38-05:00 mira.domain.org kernel - - [meta sequenceId="19"] [23193] panic: general protection fault
system_20251215.log:<13>1 2025-12-15T08:09:38-05:00 mira.domain.org kernel - - [meta sequenceId="24"] [23193] vpanic() at vpanic+0x161/frame 0xfffffe00ce2e6b70
system_20251215.log:<13>1 2025-12-15T08:09:38-05:00 mira.domain.org kernel - - [meta sequenceId="25"] [23193] panic() at panic+0x43/frame 0xfffffe00ce2e6bd0
system_20251215.log:<13>1 2025-12-15T08:09:38-05:00 mira.domain.org kernel - - [meta sequenceId="36"] [23193] KDB: enter: panic
system_20251215.log:<13>1 2025-12-15T08:09:38-05:00 mira.domain.org kernel - - [meta sequenceId="224"] <118>[4] savecore 230 - - reboot after panic: general protection fault
system_20251215.log:<13>1 2025-12-15T12:27:42-05:00 mira.domain.org kernel - - [meta sequenceId="189"] <118>[4] savecore 230 - - reboot after panic: general protection fault
system_20251215.log:<13>1 2025-12-15T14:43:39-05:00 mira.domain.org kernel - - [meta sequenceId="190"] <118>[4] savecore 227 - - reboot after panic: general protection fault
system_20251215.log:<13>1 2025-12-15T19:42:24-05:00 mira.domain.org kernel - - [meta sequenceId="19"] [17876] panic: general protection fault
system_20251215.log:<13>1 2025-12-15T19:42:24-05:00 mira.domain.org kernel - - [meta sequenceId="24"] [17876] vpanic() at vpanic+0x161/frame 0xfffffe00ca10f420
system_20251215.log:<13>1 2025-12-15T19:42:24-05:00 mira.domain.org kernel - - [meta sequenceId="25"] [17876] panic() at panic+0x43/frame 0xfffffe00ca10f480
system_20251215.log:<13>1 2025-12-15T19:42:24-05:00 mira.domain.org kernel - - [meta sequenceId="43"] [17876] KDB: enter: panic
system_20251215.log:<13>1 2025-12-15T19:42:24-05:00 mira.domain.org kernel - - [meta sequenceId="231"] <118>[4] savecore 243 - - reboot after panic: general protection fault


#3
25.1, 25.4 Series / Tayga setup issues
May 26, 2025, 02:40:15 AM
I followed the instructions here: https://github.com/opnsense/docs/blob/master/source/manual/how-tos/tayga.rst, and configured Tayga, the normalizer, the inbound allow all for the tayga interface, and outbound NAT firewall rules. 


I have a /60 from my ISP, let's say it's 1111:2222:3333:2010::/60
My setup is as such:

IPV4 Address: 192.168.240.1
IPv4 NAT64 Interface Address: 192.168.239.255
IPv6 Address: ---
IPv6 NAT64 Interface Address: 1111:2222:3333:2010::6464
IPv6 Prefix: 1111:2222:3333:201f::/96
IPv4 Pool: 192.168.240.0/20
Custom Routing: False

If I traceroute to 1111:2222:3333:201f:1.1.1.1, I get the following:

traceroute6 to 1111:2222:3333:201f::1.1.1.1 (1111:2222:3333:201f::101:101) from 1111:2222:333:2010::6464, 64 hops max, 28 byte packets
 1  1111:2222:3333:201f::c0a8:f001  0.148 ms  0.083 ms  0.033 ms
 2  1111:2222:3333:201f::c0a8:efff  0.066 ms  0.209 ms  0.135 ms
 3  * * *
 4  * * *
 5  * * *

So it looks like it's doing all the right things to generate the right IPs, but it's not sending things out.  I have been racking my brain for 2 days on this.  I even followed this video: https://youtu.be/WZSdpY_VgyY?si=9A_WJJJp1J-IdZnW, and followed to a tee (minus the ipv6 address he uses), and I got the same result. 

Any help would be greatly appreciated.  TIA!

-Travis

#4
Hey all,

  I spent the weekend to get my IPSec road warrior up and running successfully.  I was at first running dual stack, and IPv6 wasn't working, but IPv4 was.  It turns out I had the wrong subnet.  Rookie mistake.  Once I got the right subnet up and running though, I didn't have any network connectivity, except ICMP and UDP traffic.. or so I thought.  I had the DNS in my IPSec IPv4 pool to my adguard instance hosted on my opnsense box, so 192.168.1.1.  I could see traffic getting to the DNS server, but for some reason, my end user device was not getting the answers.  I stumbled across this: https://forum.opnsense.org/index.php?topic=30967.0.  That told me I need to set up a static route for the IPSec subnet so that the DNS servers could figure out where to send the packets.  I realize I could use a public DNS, and it would work, but then I wouldn't get any of my adguard features, which is part of the reason I wanted to do this in the first place. 

  I was also hoping that the documentation could get updated, since it has the user configure the DNS to the router, so the guide won't work as is.
 
  I hope someone finds this useful.

Thanks!

 
#5
24.7, 24.10 Legacy Series / Re: Unbound not starting
December 06, 2024, 12:36:36 AM
Well, I moved /usr/local/etc/unbound to /usr/local/etc/unbound.bak and /usr/local/etc/unbound.opnsense.d to /usr/local/etc/unbound.opnsense.d.bak, reinstalled unbound and now it's working. 
#6
24.7, 24.10 Legacy Series / [SOLVED] Unbound not starting
December 06, 2024, 12:12:27 AM
I upgraded to 24.7.10_2-amd64 last night, and now Unbound will not start.  I can start it by hand using the 'service' command from the shell, but if I use the GUI or pluginctl, it doesn't start.  The logs are pretty sparse and just show:

Unable to open pipe. This is likely because Unbound isn't running.


I do not have anything else listening on this port (53530) and have 200GB free on my disk.

Is there a way to get more detailed logs, or does anyone have any suggestions on how  I should try to resolve this?

Thanks!
#7
I think I am in the same boat.  I have tailscale set up with subnet routing on both sides (I am paying for 2 subnets).  I have 2 subnets I want to connect: 192.168.10.0/24 and 192.168.77.0/24.  I can ping any 192.168.77.x IP from my router (192.168.10.1), but I cannot ping anything on 192.168.77.1 from my laptop (192.168.10.24).  I have set up a gateway and route according to the screenshots, but nothing.