The xxxxx are, of course, just placeholders.
The OPNsense is connected as usual to a Vodafone cable connection without a Fritzbox. The external DNS is Vodafone, without a VPN or similar. This configuration is a test environment that had always worked up until version 26.1.8.
Unbound is used for internal DNS. The error first occurred after the update to 26.1.9. Among other things, OPNsense updates are tested in this test environment before they go into production. In production, there are OPNsense devices that establish 50 IPsec tunnels. If each tunnel generates 5 Phase 2 entries, we'll have to buy a 100-inch monitor.
I now suspect that after the update to 26.1.9, the DNS service starts up more slowly than StrongSwan, preventing the IPsec endpoints from being resolved.
Markus
The OPNsense is connected as usual to a Vodafone cable connection without a Fritzbox. The external DNS is Vodafone, without a VPN or similar. This configuration is a test environment that had always worked up until version 26.1.8.
Unbound is used for internal DNS. The error first occurred after the update to 26.1.9. Among other things, OPNsense updates are tested in this test environment before they go into production. In production, there are OPNsense devices that establish 50 IPsec tunnels. If each tunnel generates 5 Phase 2 entries, we'll have to buy a 100-inch monitor.
I now suspect that after the update to 26.1.9, the DNS service starts up more slowly than StrongSwan, preventing the IPsec endpoints from being resolved.
Markus
"