Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - GrantSquirt8415

#1
25.1, 25.4 Production Series / Re: 25.1RC1
January 23, 2025, 03:30:43 AM
Quote from: franco on January 22, 2025, 09:12:44 PMSet release type to "community", check for updates and update. Voila: 25.1.r1 (25.1.r1).

The underlying truth is that both 25.1.r_6 and 25.1.r1 are almost entirely the same anyway.

If you used the 25.1-BETA image to install your release default is only "development".

If you used the 25.1-RC1 image to install your release default is already "community".


Cheers,
Franco

Thank you!

I had this same issue.

Attempted to update the system twice with Type = "Development" selected and got the following:
***GOT REQUEST TO UPGRADE***
Currently running OPNsense 25.1.r_6 (amd64) at Thu Jan 23 02:13:22 UTC 2025
Fetching packages-25.1.r1-amd64.tar: ......................................................................... done
Extracting packages-25.1.r1-amd64.tar... done
Please reboot.
>>> Invoking upgrade script 'sanity.sh'
Passed all upgrade tests.
>>> Invoking upgrade script 'unbound-duckdb.py'
Unbound DNS database exported successfully.
>>> Invoking upgrade script 'cleanup.sh'
***DONE***

PS: I rebooted twice. Once after each attempt thinking this could have been like the CrowdSec issue a few point releases back which would hang and prevent a reboot.

Switched Type to "Community" and then re-ran the check for update and got the following:
***GOT REQUEST TO UPDATE***
Currently running OPNsense 25.1.r_6 (amd64) at Thu Jan 23 02:25:14 UTC 2025
Updating OPNsense repository catalogue...
OPNsense repository is up to date.
All repositories are up to date.
Updating OPNsense repository catalogue...
OPNsense repository is up to date.
All repositories are up to date.
Checking for upgrades (103 candidates): .......... done
Processing candidates (103 candidates): . done
Checking integrity... done (0 conflicting)
Your packages are up to date.
Checking integrity... done (0 conflicting)
Nothing to do.
Checking all packages: .......... done
Nothing to do.
Updating OPNsense repository catalogue...
OPNsense repository is up to date.
All repositories are up to date.
The following packages will be fetched:

New packages to be FETCHED:
    opnsense: 25.1.r1 (5 MiB: 50.00% of the 9 MiB to download)
    opnsense-devel: 25.1.r_6 (5 MiB: 50.00% of the 9 MiB to download)

Number of packages to be fetched: 2

The process will require 9 MiB more space.
9 MiB to be downloaded.
Fetching opnsense-25.1.r1.pkg: .......... done
Fetching opnsense-devel-25.1.r_6.pkg: .......... done
Updating OPNsense repository catalogue...
OPNsense repository is up to date.
All repositories are up to date.
Checking integrity... done (1 conflicting)
  - opnsense-25.1.r1 conflicts with opnsense-devel-25.1.r_6 on /boot/lua/brand-opnsense.lua
Checking integrity... done (0 conflicting)
The following 2 package(s) will be affected (of 0 checked):

Installed packages to be REMOVED:
    opnsense-devel: 25.1.r_6

New packages to be INSTALLED:
    opnsense: 25.1.r1

Number of packages to be removed: 1
Number of packages to be installed: 1
[1/2] Deinstalling opnsense-devel-25.1.r_6...
Stopping configd...done
Resetting root shell
Updating /etc/shells
Unhooking from /etc/rc
Unhooking from /etc/rc.shutdown
[1/2] Deleting files for opnsense-devel-25.1.r_6: .......... done
[2/2] Installing opnsense-25.1.r1...
[2/2] Extracting opnsense-25.1.r1: .......... done
Updating /etc/shells
Registering root shell
Hooking into /etc/rc
Hooking into /etc/rc.shutdown
Starting configd.
>>> Invoking update script 'refresh.sh'
Writing firmware settings: FreeBSD OPNsense
Writing trust files...done.
Scanning /usr/share/certs/untrusted for certificates...
Scanning /usr/share/certs/trusted for certificates...
Scanning /usr/local/share/certs for certificates...
certctl: No changes to trust store were made.
Writing trust bundles...done.
Configuring login behaviour...done.
Configuring cron...done.
Configuring system logging...done.
=====
Message from opnsense-25.1.r1:

--
TBA
Nothing to do.
Starting web GUI...done.
***DONE***
#2
Just to add a little, my concern is that this error is popping up about every 15-95 seconds, which in internet time isn't that long, but not sure if this could either purposely or accidentally become a DOS issue (below are the last 20 log entries)

Date                   Severity  Process        Line    
2024-12-30T22:28:45   Error   opnsense-devel   /usr/local/etc/rc.newwanipv6: The command '/sbin/route add -host -'inet6' 'fe80::aedf:9fff:fe61:ecd8' 'fe80::aedf:9fff:fe61:ecd8%igb3'' returned exit code '1', the output was 'add host fe80::aedf:9fff:fe61:ecd8: gateway fe80::aedf:9fff:fe61:ecd8%igb3 fib 0: route already in table'   
2024-12-30T22:27:45   Error   opnsense-devel   /usr/local/etc/rc.newwanipv6: The command '/sbin/route add -host -'inet6' 'fe80::aedf:9fff:fe61:ecd8' 'fe80::aedf:9fff:fe61:ecd8%igb3'' returned exit code '1', the output was 'add host fe80::aedf:9fff:fe61:ecd8: gateway fe80::aedf:9fff:fe61:ecd8%igb3 fib 0: route already in table'   
2024-12-30T22:26:45   Error   opnsense-devel   /usr/local/etc/rc.newwanipv6: The command '/sbin/route add -host -'inet6' 'fe80::aedf:9fff:fe61:ecd8' 'fe80::aedf:9fff:fe61:ecd8%igb3'' returned exit code '1', the output was 'add host fe80::aedf:9fff:fe61:ecd8: gateway fe80::aedf:9fff:fe61:ecd8%igb3 fib 0: route already in table'   
2024-12-30T22:25:45   Error   opnsense-devel   /usr/local/etc/rc.newwanipv6: The command '/sbin/route add -host -'inet6' 'fe80::aedf:9fff:fe61:ecd8' 'fe80::aedf:9fff:fe61:ecd8%igb3'' returned exit code '1', the output was 'add host fe80::aedf:9fff:fe61:ecd8: gateway fe80::aedf:9fff:fe61:ecd8%igb3 fib 0: route already in table'   
2024-12-30T22:24:45   Error   opnsense-devel   /usr/local/etc/rc.newwanipv6: The command '/sbin/route add -host -'inet6' 'fe80::aedf:9fff:fe61:ecd8' 'fe80::aedf:9fff:fe61:ecd8%igb3'' returned exit code '1', the output was 'add host fe80::aedf:9fff:fe61:ecd8: gateway fe80::aedf:9fff:fe61:ecd8%igb3 fib 0: route already in table'   
2024-12-30T22:23:45   Error   opnsense-devel   /usr/local/etc/rc.newwanipv6: The command '/sbin/route add -host -'inet6' 'fe80::aedf:9fff:fe61:ecd8' 'fe80::aedf:9fff:fe61:ecd8%igb3'' returned exit code '1', the output was 'add host fe80::aedf:9fff:fe61:ecd8: gateway fe80::aedf:9fff:fe61:ecd8%igb3 fib 0: route already in table'   
2024-12-30T22:22:45   Error   opnsense-devel   /usr/local/etc/rc.newwanipv6: The command '/sbin/route add -host -'inet6' 'fe80::aedf:9fff:fe61:ecd8' 'fe80::aedf:9fff:fe61:ecd8%igb3'' returned exit code '1', the output was 'add host fe80::aedf:9fff:fe61:ecd8: gateway fe80::aedf:9fff:fe61:ecd8%igb3 fib 0: route already in table'   
2024-12-30T22:21:45   Error   opnsense-devel   /usr/local/etc/rc.newwanipv6: The command '/sbin/route add -host -'inet6' 'fe80::aedf:9fff:fe61:ecd8' 'fe80::aedf:9fff:fe61:ecd8%igb3'' returned exit code '1', the output was 'add host fe80::aedf:9fff:fe61:ecd8: gateway fe80::aedf:9fff:fe61:ecd8%igb3 fib 0: route already in table'   
2024-12-30T22:20:45   Error   opnsense-devel   /usr/local/etc/rc.newwanipv6: The command '/sbin/route add -host -'inet6' 'fe80::aedf:9fff:fe61:ecd8' 'fe80::aedf:9fff:fe61:ecd8%igb3'' returned exit code '1', the output was 'add host fe80::aedf:9fff:fe61:ecd8: gateway fe80::aedf:9fff:fe61:ecd8%igb3 fib 0: route already in table'   
2024-12-30T22:19:45   Error   opnsense-devel   /usr/local/etc/rc.newwanipv6: The command '/sbin/route add -host -'inet6' 'fe80::aedf:9fff:fe61:ecd8' 'fe80::aedf:9fff:fe61:ecd8%igb3'' returned exit code '1', the output was 'add host fe80::aedf:9fff:fe61:ecd8: gateway fe80::aedf:9fff:fe61:ecd8%igb3 fib 0: route already in table'   
2024-12-30T22:18:45   Error   opnsense-devel   /usr/local/etc/rc.newwanipv6: The command '/sbin/route add -host -'inet6' 'fe80::aedf:9fff:fe61:ecd8' 'fe80::aedf:9fff:fe61:ecd8%igb3'' returned exit code '1', the output was 'add host fe80::aedf:9fff:fe61:ecd8: gateway fe80::aedf:9fff:fe61:ecd8%igb3 fib 0: route already in table'   
2024-12-30T22:17:45   Error   opnsense-devel   /usr/local/etc/rc.newwanipv6: The command '/sbin/route add -host -'inet6' 'fe80::aedf:9fff:fe61:ecd8' 'fe80::aedf:9fff:fe61:ecd8%igb3'' returned exit code '1', the output was 'add host fe80::aedf:9fff:fe61:ecd8: gateway fe80::aedf:9fff:fe61:ecd8%igb3 fib 0: route already in table'   
2024-12-30T22:16:45   Error   opnsense-devel   /usr/local/etc/rc.newwanipv6: The command '/sbin/route add -host -'inet6' 'fe80::aedf:9fff:fe61:ecd8' 'fe80::aedf:9fff:fe61:ecd8%igb3'' returned exit code '1', the output was 'add host fe80::aedf:9fff:fe61:ecd8: gateway fe80::aedf:9fff:fe61:ecd8%igb3 fib 0: route already in table'   
2024-12-30T22:15:45   Error   opnsense-devel   /usr/local/etc/rc.newwanipv6: The command '/sbin/route add -host -'inet6' 'fe80::aedf:9fff:fe61:ecd8' 'fe80::aedf:9fff:fe61:ecd8%igb3'' returned exit code '1', the output was 'add host fe80::aedf:9fff:fe61:ecd8: gateway fe80::aedf:9fff:fe61:ecd8%igb3 fib 0: route already in table'   
2024-12-30T22:14:45   Error   opnsense-devel   /usr/local/etc/rc.newwanipv6: The command '/sbin/route add -host -'inet6' 'fe80::aedf:9fff:fe61:ecd8' 'fe80::aedf:9fff:fe61:ecd8%igb3'' returned exit code '1', the output was 'add host fe80::aedf:9fff:fe61:ecd8: gateway fe80::aedf:9fff:fe61:ecd8%igb3 fib 0: route already in table'   
2024-12-30T22:13:45   Error   opnsense-devel   /usr/local/etc/rc.newwanipv6: The command '/sbin/route add -host -'inet6' 'fe80::aedf:9fff:fe61:ecd8' 'fe80::aedf:9fff:fe61:ecd8%igb3'' returned exit code '1', the output was 'add host fe80::aedf:9fff:fe61:ecd8: gateway fe80::aedf:9fff:fe61:ecd8%igb3 fib 0: route already in table'   
2024-12-30T22:12:45   Error   opnsense-devel   /usr/local/etc/rc.newwanipv6: The command '/sbin/route add -host -'inet6' 'fe80::aedf:9fff:fe61:ecd8' 'fe80::aedf:9fff:fe61:ecd8%igb3'' returned exit code '1', the output was 'add host fe80::aedf:9fff:fe61:ecd8: gateway fe80::aedf:9fff:fe61:ecd8%igb3 fib 0: route already in table'   
2024-12-30T22:12:07   Error   opnsense-devel   /usr/local/etc/rc.newwanipv6: The command '/sbin/route add -host -'inet6' 'fe80::aedf:9fff:fe61:ecd8' 'fe80::aedf:9fff:fe61:ecd8%igb3'' returned exit code '1', the output was 'add host fe80::aedf:9fff:fe61:ecd8: gateway fe80::aedf:9fff:fe61:ecd8%igb3 fib 0: route already in table'   
2024-12-30T22:12:04   Notice   dhcp6c   dhcp6c_script: RENEW on igb3 executing   
2024-12-30T22:11:45   Error   opnsense-devel   /usr/local/etc/rc.newwanipv6: The command '/sbin/route add -host -'inet6' 'fe80::aedf:9fff:fe61:ecd8' 'fe80::aedf:9fff:fe61:ecd8%igb3'' returned exit code '1', the output was 'add host fe80::aedf:9fff:fe61:ecd8: gateway fe80::aedf:9fff:fe61:ecd8%igb3 fib 0: route already in table'   
#3
Hello,

Running OPNsense 25.1.b_20-amd64 for a few days after a clean install (no configuration brought over from previous setup)
Functionally, everything seems to be running well. No client errors and the system seems to boot more quickly than on the 24.7 image.
I am getting this odd error message, which does not seem to impact the functionality of the firewall, but wanted to share to see if this is anything that may require additional review:

TimeSeverityProcessMessage
2024-12-30T16:19:32Erroropnsense-devel/usr/local/etc/rc.newwanipv6: The command '/sbin/route add -host -'inet6' 'fe80::aedf:9fff:fe61:ecd8' 'fe80::aedf:9fff:fe61:ecd8%igb3'' returned exit code '1', the output was 'add host fe80::aedf:9fff:fe61:ecd8: gateway fe80::aedf:9fff:fe61:ecd8%igb3 fib 0: route already in table'

If this is of any concern, please let me know and I can provide additional information.

Thank you
#5
I've been having issues with Android devices connecting over IPv6 since the "FreeBSD security advisory" patch and the back and forth with reverting it.
You may want to see this thread, it may be relevant: https://forum.opnsense.org/index.php?topic=42556.0
#6
Ran into the same issue, Crowdsec held up the update and was unable to end just that process.
Rebooted and resumed the update after disabling Crowdsec and now all seems to be running correctly.
If you have not yet updated, try disabling Crowdsec before you update.
#7
Hello all,
Upgraded from 23.7.12 to 23.7.12_5 and then immediately to 24.1_1.
Running 4 physical interfaces with separate networks on each, 2 wan, 2 lan with DCHP service.
Switched from ISC to Kea DHCPv4
Transitioned to the Kea DHCPv4 service was simple but seems to be an all or nothing issue.
Attempting to get Kea listening on interface 1 would not work with ISC DHCPv4 listening on interface 2 (seems the ISC DHCPv4 server locks the port on all interfaces).
Once I had both subnets defined (you can do them separately for clarity) and disabled the ISC DHCPv4 instances Kea was able to start as per the logs and as per GUI.
I would be happy to test the Kea implementation further.
Thanks
#8
Completed the upgrade from 23.1.11 to 23.1.11_1 with no issues. The upgrade from 23.1.11_1 to 23.7 seemed to proceed with no issues, but after the update was complete internal machines had no internet access. I could no longer access the firewall with the FQDN but could access it directly via IP address. For some reason unbound was not started. Going into the configuration the check box to enable it was not checked and some of the other required settings were missing. Enabled unbound and restarted the service and only other minor issue was a complaint about a logging database missing (I had OPNSense create what it wanted). Has been running fine since.
Setup includes two wan interfaces and two lan interface with a firewall rule for gateway fail over.