Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - vimage22

#1
# Check list:
Remove the trailing dot when adding a reservation (fix with script?)
(The trailing dot has significance in the context of kea)
It will crash unbound on a restart if not removed.

Restart unbound after adding reservation (trigger with script?)
After restart, LAN hostname resolution from reservation / v4, v6 (WORKS)

Track WAN IPv6 Prefix (under active development)
Make sure to temporarily turn off 'Track WAN...' if changing to a different DHCP server.
Update kea, unbound, radvd if WAN IPv6 Prefix changes (working on script)

Are options applied to reservations?
For example, IPv4 DNS server(s) shows as blank under the reservation list.
It also shows as blank in '/conf/config.xml'

Per documentation:
https://docs.opnsense.org/manual/dhcp.html
If a client is assigned a reservation, within the pool, but goes offline
Why can this IP be assigned to a different client?
IPv4 - It should be assigned based on the unique MAC address, and therefore NOT assigned to a different client?
IPv6 - Same, except by DUID?
By definition, reservation is matched vie MAC or DUID?

# Auto collect option data
Automatically update option data for relevant attributes as routers, dns servers and ntp servers when applying settings from the gui.

Auto collect option data (IPv4) (nice feature)
Automatic = (view by un-checking Auto...)
Routers (gateway)
DNS servers
NTP servers

Not Automatic =
Static routes
Classless static routes
Domain name (auto based on System settings?)
Domain search
Time servers
Next server
TFTP server
TFTP bootfile name

#2
General Discussion / Re: Wireless Access Points
January 17, 2026, 02:16:13 PM
I have been very happy with Zyxel NWA130BE (WiFi 7). I actually get 2.5gbs performance over WiFi.
#3
OK, great, I will try that.
#4
25.7, 25.10 Series / Re: Where is the post button?
January 16, 2026, 03:00:48 PM
Are you looking for "New Topic"?
#5
Yes, it looks like it reappears for all of the sections below. I realize this might be "by design" to make it obvious that the items in a section can be changed with an action. My logic for allowing it to be sticky is if I know I will not need a command in a particular section, it saves a bit on screen area to see more information from the other columns. All other column choices appear to be sticky and the column widths remembered, which is great.
System: Access: Users
System: Access: Groups
System: Access: Privileges
System: Gateways: Configuration
System: Routes: Status (Action)
System: Diagnostics: Services (also missing the word "Command" under drop down)
Interfaces: Devices: Bridge
Interfaces: Overview
Firewall: Aliases
Firewall: Automation: Filter
Firewall: Automation: Source NAT
Firewall: Categories
Firewall: Groups
Firewall: Diagnostics: Aliases (also missing the word "Command" under drop down)
Firewall: Diagnostics: States
#6
Quote from: franco on January 09, 2026, 01:07:26 PMLAN has Track6 mode by default which launches DHCPv6 and Radvd.

This was not obvious to me when I did a fresh install and tried to change from ISC to kea or dsnmasq. After reading this entire thread, it now makes even more sense. I am on kea and IPv6 works perfectly.
#7
25.7, 25.10 Series / kea FileNotFoundError
January 06, 2026, 08:00:16 PM
I added a reservation using the '+' command under Services: Kea DHCP: Leases DHCPv6.
I then went to check the kea log and found this, without a time stamp.

FileNotFoundError: [Errno 2] No such file or directory: '/var/db/kea/kea-leases6.csv'
^^^^^^^^^^^
if lstpos is None or (os.path.isfile(fn) and os.fstat(fhandle.fileno()).st_ino != os.stat(fn).st_ino):
File "/usr/local/opnsense/scripts/kea/kea_prefix_watcher.py", line 51, in yield_log_records
for record in yield_log_records(inputargs.filename):
File "/usr/local/opnsense/scripts/kea/kea_prefix_watcher.py", line 109, in <module>
Traceback (most recent call last):

Has anyone else experienced this?

Edit: '/var/db/kea/kea-leases6.csv' does exist and seems to be correct.
Not sure if this matters, but before I saved the reservation, I removed the trailing dot from the hostname.

#8
I recently switched from ISC to kea and I am very impressed. My environment is relatively simple, but IPv6 is working (lan, wan, nat port rules, etc.). Plus I like kea=dhcp, unbound=dns just from an organizational point of view. Not familiar with ("Ubiquiti") DHCP option requirements, but I would be curious if you wanted to share.
#9
BTW, just wanted to re-mention this.
#10
Excellent, thank you. I will google 'menu override files'. It is not security related, I just find myself clicking on the wrong service.

I modified 2 files. They will not survive updates, but I'm good with that.
comment lines 127-133
/usr/local/opnsense/mvc/app/models/OPNsense/Core/Menu/Menu.xml
comment lines 3-13
/usr/local/opnsense/mvc/app/models/OPNsense/Dnsmasq/Menu/Menu.xml
execute
/usr/local/etc/rc.configure_plugins

Thanks again.
#11
Happy New Year
For example, can I remove the entire entry for dnsmasq?
I tried looking here:
System: Access: Privileges
But this area does not seem to cover the entire service.
And this is just to remove it from displaying, not the underlying software.
Thanks.
#12
I also had a trouble with DNS after doing a fresh install a couple of week ago. When looking at
"Firewall: Log Files: Live View" and "Firewall: Diagnostics: States:"
I noticed it was complaining about this setting:
Interfaces: [WAN] > Block private networks
I executed "Firewall: Diagnostics: States: Actions: Reset state table".
Everything works great now, but resetting this table has become a very important step when setting up or making changes to the Firewall settings.
#13
I have been testing with DNSSEC off, but DoT is still on. I am starting to agree with DEC740airp414user on this, even though information found seems to lead in another direction.
In particular, this option appears to affect performance:
"Harden DNSSEC Data"
#14
General Discussion / Re: ECS and DNSSEC Setup
December 28, 2025, 02:32:48 PM
Harden DNSSEC Data
If this is on, it appears to have a negative impact on performance.

Enable DNSSEC Support
If this is on, it was very difficult to see if it had an impact.

Both are off now. DoT is still on.
#15
25.7, 25.10 Series / Reporting: Columns not remembered.
December 28, 2025, 01:25:11 PM
Under Reporting: Unbound DNS, I uncheck the "Command" column, as well as a few others. when I leave, and then return to that page, the "Command" column reappears. The others stay hidden. Is this an issue?