Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - dMopp

#1
25.1, 25.4 Production Series / Re: acme broken?
March 27, 2025, 10:46:26 PM
Setting 30s was enough and Problem fixed (+ a reboot due to that hanging loop).. thanks  :)
#2
25.1, 25.4 Production Series / acme broken?
March 27, 2025, 07:16:57 PM
I cant add any new certificate NOR recerify them. Iam using ionos and i see no issues regarding DNS record adding... But i see errors like:

[Thu Mar 27 19:15:51 CET 2025] Not valid yet, let's wait for 10 seconds then check the next one.
2025-03-27 19:15:51.000 OPNsense.quolke.net
[Thu Mar 27 19:15:51 CET 2025] Please refer to https://curl.haxx.se/libcurl/c/libcurl-errors.html for error code: 6
2025-03-27 19:15:51.000 OPNsense.quolke.net
[Thu Mar 27 19:15:51 CET 2025] No DOH
2025-03-27 19:15:51.000 OPNsense.quolke.net

And its repeating for all my certis. There where working before and as mentioned, i can see the DNS records without any issue (and usually, in the past, in 10-30 secods as ionos is fast AF  .. :D)
#3
25.1, 25.4 Production Series / Shaper rules kinda buggy ?
February 27, 2025, 10:21:41 PM
Iam really trying to improve my shaper knowlege.. But iam hitting a limit ehre and there.

Long story short:

I have a normalization rule, adding CS3 to all packages coming/going to a specific device and a rule, looking for traffic containing CS3 traffic. But for some reason, the rule is matching ALL traffic from all VLANs  :|
#4
A bit dirty but:
- change unbound zone mode to transparent
- add specific subdomains to unbound
- enable dnsmasq with another port then 53
- forward domain to dnsmasq
- add wildcard to dnsmasq

That's what coming in my mind right now
#5
Or Tailscale, which in the end opens p2p Wireguard tunnel, skipping the jump host :)
#6
Thanks, I know that thread but what I don't understand is, how the config actually looks like in his case. If iam guessing right:
WFQ Pipe and Codel Queues ?
#7
I followed the docs and yes, bufferbloat is (and was the whole time) fine. But still there is the open question, if I can COMBINE codel with WFQ? Sounds like not, but if I could, I would use the new feature to sort packets into the right pipe/queue
#8
Does not work :/ IPTV is multicast here btw
#9
You don't get me right.

I have Bufferfloat queues / pipes already in place. But I wanna use Bandwith priorisation based on source / target / protocol (whatever) in place, too. So my IPTV is working WHILE steam is downloading big blobs. (Weight 1 as default and weight 20 or so for iptv) the traffic matching will be done by the new firewall feature
#10
First: Thank you ! Finally this helps a LOT :)

But i have a question: Is there a (official) way to tackle Bufferbloat AND using Shaping together? I would like to Prio my IPTV but without loosing the pimped bufferbloat  :|
#11
Here the same, was on devr6, too before
#12
Also rolled back kernel. No Sideeffect currently. Also unbound is running.
#13
Does a kernel downgrade any side-effects?
#14
I will test my issue as well. Maybe related, maybe not. Will report then :)
#15
I started just for my issue. Resolving works as well. At least on opnsense. Clients even can't reach the firewall over ipv6. I might find some time later on to trigger the issue again, for the weekend I will my workaround in place