Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - tonys

#1
26.7 Series / Re: VLAN devices are on LAN IPs
August 12, 2026, 11:27:00 PM
I'll continue testing without the external VPN and if anything changes, I'll post here.
#2
26.7 Series / Re: VLAN devices are on LAN IPs
August 08, 2026, 09:51:39 PM
Quote from: meyergru on August 08, 2026, 09:00:10 AM
Quote from: tonys on August 08, 2026, 04:19:52 AMHopefully this settles your debate over combining tagged and untagged traffic, LOL.

See you again when this goes horribly wrong and you do not even remember what you did to make that possible. We never said it was not feasible, but depending on what you do, there can be lots of problems. This may be influenced by your NIC hardware on OpnSense, and is especially true for Unifi switches, which have all kinds of problems with VLANs. If you want a taste of it, look here.

The current switch software releases of some switch models have a problem separating untagged and tagged LANs during switch startup. Depending on the startup order of your machines, they can get IPv4 from any of your VLANs (since all of them are presented untagged). With 802.1x enabled, you may see all IPv6 prefixes at once on untagged ports.

But, as Patrick often says: You do you, LOL. The advice given in here is free - and you are also free to take it or leave it.


I'm not using a Unifi nor other switch and have no requirement for one in the foreseeable future. My AP is the Unifi Pro 7 wireless (UFO style) on one Protecli port and my entire network is wireless with the sole exception of an internet-facing OpenVPN Access Server which is on its own dedicated Protecli port.
#3
26.7 Series / Re: VLAN devices are on LAN IPs
August 08, 2026, 04:19:52 AM
I found the problem. The Unifi OS configuration had its Default, Guest, and IoT networks set up correctly with the proper tags (20 for Guest, 40 for IoT) but the tags weren't showing up in the network table list. Google Gemini led me to this issue and showed me how to correct it - basically, MANUALLY add the two tags to their respective networks. Why they didn't copy over when I defined those networks remains a mystery (maybe a bug?) but once I manually added the tags, all devices disconnected from the native (LAN) network and reconnected on their proper networks.

Attached is a Unifi OS screenshot after adding these tags. The bottom table is where I originally set up the networks with their tags. The top table was generated by UnifiOS but was missing the VLAN tags so I added the tags manually. FYI, the VLAN definition for the LAN is currently disabled in OPNSense. It seems to be unnecessary to tag the LAN so I'm able to combine untagged LAN with the two VLANs on one port going to the Unifi AP. Hopefully this settles your debate over combining tagged and untagged traffic, LOL.

Thanks for all your help gentlemen. Now it's time to move on to the next problem (LAN stalls requiring using an external VPN to stop LAN blocks to Quad9 encrypted DNS  from Apple's Private Relay traffic).
#4
26.7 Series / Re: VLAN devices are on LAN IPs
August 07, 2026, 11:38:00 PM
Quote from: dseven on August 07, 2026, 09:13:34 AMHave you reboot (opnsense) since eliminating the bridge? There may be some artifact from it lurking somewhere.

Otherwise try this tcpdump to see "what's happening on the wire":

tcpdump -nnvvei igc0 '(ether host aa:bb:cc:dd:ee:ff and port 67) or (vlan and ether host aa:bb:cc:dd:ee:ff and port 67)'

Substitute the MAC address of a Guest or IoT device (in two places), and make it (re)connect.

Feedback:
- OPNSense router has been rebooted MANY times since removing the bridge

- This wireless device is supposed to be on the IoT VLAN (192.168.40.x). It used to be under v21 and earlier, but now it keeps reconnecting to the LAN. The Roku screen shows it's on the IoT network WITH theTHE IoT password (very different from the LAN password) but it keeps getting a LAN IP. The Unifi wireless AP also shows it on the IoT network which it must be because I gave it the IoT password. Yet it got a LAN IP. ??

tcpdump -nnvvei igc0 '(ether host d4:be:dc:20:de:dd and port 67) or (vlan and ether host d4:be:dc:20:de:dd and port 67)'
tcpdump: listening on igc0, link-type EN10MB (Ethernet), snapshot length 262144 bytes
16:24:11.301381 d4:be:dc:20:de:dd > ff:ff:ff:ff:ff:ff, ethertype IPv4 (0x0800), length 590: (tos 0x0, ttl 64, id 0, offset 0, flags [none], proto UDP (17), length 576)
    0.0.0.0.68 > 255.255.255.255.67: [udp sum ok] BOOTP/DHCP, Request from d4:be:dc:20:de:dd, length 548, xid 0x70cd0629, Flags [none] (0x0000)
     Client-Ethernet-Address d4:be:dc:20:de:dd
     Vendor-rfc1048 Extensions
       Magic Cookie 0x63825363
       DHCP-Message (53), length 1: Request
       Requested-IP (50), length 4: 192.168.1.127
       Parameter-Request (55), length 5:
         Subnet-Mask (1), Default-Gateway (3), Domain-Name-Server (6), Domain-Name (15)
         Hostname (12)
       Hostname (12), length 9: "RokuUltra"
16:24:11.301551 64:62:66:22:4c:ab > d4:be:dc:20:de:dd, ethertype IPv4 (0x0800), length 342: (tos 0x10, ttl 128, id 0, offset 0, flags [none], proto UDP (17), length 328)
    192.168.1.1.67 > 192.168.1.127.68: [udp sum ok] BOOTP/DHCP, Reply, length 300, xid 0x70cd0629, Flags [none] (0x0000)
     Your-IP 192.168.1.127
     Client-Ethernet-Address d4:be:dc:20:de:dd
     Vendor-rfc1048 Extensions
       Magic Cookie 0x63825363
       DHCP-Message (53), length 1: ACK
       Server-ID (54), length 4: 192.168.1.1
       Lease-Time (51), length 4: 5452
       Subnet-Mask (1), length 4: 255.255.255.0
       Default-Gateway (3), length 4: 192.168.1.1
       Domain-Name-Server (6), length 4: 192.168.1.1
       Domain-Name (15), length 8: "home.lan"
#5
26.7 Series / Re: VLAN devices are on LAN IPs
August 06, 2026, 10:31:38 PM
Quote from: dseven on August 06, 2026, 09:50:21 AMAt the start, you had a bridge. Is that bridge now completely gone? Updated ifconfig output might be helpful.

Otherwise I'd tend to suspect that your WiFi is misconfigured...

@viragomann... here is the updated config and yes, the bridge is completely gone and igc3 is disconnected. Sorry about the confusion.

Notes:

- VLAN02 and VLAN03 are unresponsive from anywhere other than OPNSense itself. I can ping 192.168.20.1 and 192.168.40.1 but only when I'm logged directly into the OPNSense shell via SSH. I don't know what layer these pings are operating from.

- The VLAN networks are enabled in UnifiOS and labeled correctly as Guest and IoT with the appropriate tags (20 and 40 respectively). I highly doubt there is a misconfiguration in Unifi OS as it's the same as it always has been and worked just fine under all OPNSense releases up to and including 21.x. The devices listed in Unifi OS are shown on the correct networks (LAN, Guest, and IoT) but they all have LAN IPs. All of my problems started after upgrading to 26.7.x.

- OPNSense's ARP table clearly shows the issue - both VLANs are shown with IP's of 192.168.20.1 and 192.168.40.1 but none of the devices can reach them. Instead, OPNSense incorrectly dumps them into LAN IPs.

igc0: flags=1008843<UP,BROADCAST,RUNNING,SIMPLEX,MULTICAST,LOWER_UP> metric 0 mtu 1500
    description: LAN (lan)
    inet 192.168.1.1 netmask 0xffffff00 broadcast 192.168.1.255
    media: Ethernet autoselect (2500Base-T <full-duplex>)
    status: active

igc1: flags=1008843<UP,BROADCAST,RUNNING,SIMPLEX,MULTICAST,LOWER_UP> metric 0 mtu 1500
    description: WAN (wan)
    inet xxx.xxx.xxx.xxx netmask 0xfffff800 broadcast 255.255.255.255
    inet6 x cac%igc1 prefixlen 64 scopeid 0x2
    media: Ethernet autoselect (1000baseT <full-duplex>)
    status: active

igc2: flags=1008843<UP,BROADCAST,RUNNING,SIMPLEX,MULTICAST,LOWER_UP> metric 0 mtu 1500
    description: DMZ (opt1)
    inet 192.168.30.1 netmask 0xffffff00 broadcast 192.168.30.255
    media: Ethernet autoselect (1000baseT <full-duplex>)
    status: active

igc3: flags=8802<BROADCAST,SIMPLEX,MULTICAST> metric 0 mtu 1500
    media: Ethernet autoselect
    status: no carrier

lo0: flags=1008049<UP,LOOPBACK,RUNNING,MULTICAST,LOWER_UP> metric 0 mtu 16384
    inet 127.0.0.1 netmask 0xff000000
    groups: lo

enc0: flags=0 metric 0 mtu 1536
    options=0
    groups: enc

vlan00: flags=1008843<UP,BROADCAST,RUNNING,SIMPLEX,MULTICAST,LOWER_UP> metric 0 mtu 1500
    groups: vlan
    vlan: 10 vlanproto: 802.1q vlanpcp: 0 parent interface: igc0
    media: Ethernet autoselect (2500Base-T <full-duplex>)
    status: active

vlan01: flags=1008843<UP,BROADCAST,RUNNING,SIMPLEX,MULTICAST,LOWER_UP> metric 0 mtu 1500
    description: Guest (opt2)
    inet 192.168.20.1 netmask 0xffffff00 broadcast 192.168.20.255
    groups: vlan
    vlan: 20 vlanproto: 802.1q vlanpcp: 0 parent interface: igc0
    media: Ethernet autoselect (2500Base-T <full-duplex>)
    status: active

vlan02: flags=1008843<UP,BROADCAST,RUNNING,SIMPLEX,MULTICAST,LOWER_UP> metric 0 mtu 1500
    description: IoT (opt3)
    inet 192.168.40.1 netmask 0xffffff00 broadcast 192.168.40.255
    groups: vlan
    vlan: 40 vlanproto: 802.1q vlanpcp: 0 parent interface: igc0
    media: Ethernet autoselect (2500Base-T <full-duplex>)
    status: active
#6
26.7 Series / Re: VLAN devices are on LAN IPs
August 06, 2026, 02:03:39 AM
I went back to my original configuration as posted in the beginning of this thread (listed from the SSH login to OPNSense):

*** OPNsense.home.lan: OPNsense 26.7.1_1 (amd64) ***

 DMZ (igc2)      -> v4: 192.168.30.1/24
 Guest (vlan01)  -> v4: 192.168.20.1/24
 IoT (vlan02)    -> v4: 192.168.40.1/24
 LAN (igc0)      -> v4: 192.168.1.1/24
 WAN (igc1)      -> v4/DHCP4: x.x.x.x

From one of my LAN devices (192.168.1.63), I attempted pings to the Guest (192.168.20.1) and IoT (192.168.40.1) vlans and there is no connectivity as expected. This means there are no leaks that could lead to bleeding FROM the LAN TO the Guest or IoT networks. Unfortunately, I still have no devices connecting on either vlan - all devices are getting LAN IPs. I don't see how to check for bleeding from the Guest or IOT vlans to the LAN since I can't get any device onto either vlan.

This is bad - the Guest and IoT devices have complete access to my LAN. How do I check for leakage if I can't get any devices to connected to either VLAN?
#7
26.7 Series / Re: VLAN devices are on LAN IPs
August 03, 2026, 05:20:49 AM
OK, so for better or for worse, I removed the LAN bridge completely. The new configuration is as follows (igc3 is now unconnected):

igc0: flags=1008843<UP,BROADCAST,RUNNING,SIMPLEX,MULTICAST,LOWER_UP> metric 0 mtu 1500
   description: LAN (lan)
igc1: flags=1008843<UP,BROADCAST,RUNNING,SIMPLEX,MULTICAST,LOWER_UP> metric 0 mtu 1500
   description: WAN (wan)
igc2: flags=1008843<UP,BROADCAST,RUNNING,SIMPLEX,MULTICAST,LOWER_UP> metric 0 mtu 1500
   description: DMZ (opt1)
igc3: flags=8843<UP,BROADCAST,RUNNING,SIMPLEX,MULTICAST> metric 0 mtu 1500
vlan00: flags=1008843<UP,BROADCAST,RUNNING,SIMPLEX,MULTICAST,LOWER_UP> metric 0 mtu 1500
   groups: vlan
   vlan: 1 vlanproto: 802.1q vlanpcp: 0 parent interface: igc0
   status: active
vlan01: flags=1008843<UP,BROADCAST,RUNNING,SIMPLEX,MULTICAST,LOWER_UP> metric 0 mtu 1500
   groups: vlan
   vlan: 20 vlanproto: 802.1q vlanpcp: 0 parent interface: igc0
   status: active
vlan02: flags=1008843<UP,BROADCAST,RUNNING,SIMPLEX,MULTICAST,LOWER_UP> metric 0 mtu 1500
   groups: vlan
   vlan: 40 vlanproto: 802.1q vlanpcp: 0 parent interface: igc0
   status: active

While this seems to be correct, I can't figure out how to add the VLAN address ranges back in (i.e., I want vlan01 to be 192.168.20.x and vlan02 to be 192.168.40.x). Note that I also added vlan00 for the LAN address block of 192.168.1.x. Unfortunately, nothing has changed at all. All devices remain stuck on the LAN IPs. I used to be able to add interfaces opt2 and opt3 for the VLANs but I can't do this now. What am I doing wrong?

Another interesting thing is that the Unifi AP is seeing the proper tag names from the Guest and IoT VLANs even though they're all LAN IPs. I find this very confusing - how does the Unifi AP see the proper VLAN names but OPNSense doesn't assign the proper IPs? See the attached screen shot.


#8
26.7 Series / Re: VLAN devices are on LAN IPs
August 02, 2026, 09:45:45 PM
Quote from: dseven on August 02, 2026, 10:32:17 AMWhat is the purpose of the bridge? What are the member ports?

What are the parent interfaces for the VLAN interfaces?

Mixing bridges and VLAN tagging can be tricky...
Quote from: dseven on August 02, 2026, 10:32:17 AMWhat is the purpose of the bridge? What are the member ports?

What are the parent interfaces for the VLAN interfaces?

Mixing bridges and VLAN tagging can be tricky...

The purpose of the bridge is to give LAN access to future hard-wired clients. Interface assignments are shown in the original post. The untagged LAN + both tagged VLANs are on igc0 (port 1 of the Protecli) and go ONLY to the Unifi AP. This worked fine up to and including OPNSense 21.x but I now understand that 26.7 doesn't seem to like mixing untagged and tagged frames on one port. I'm trying to setup a VLAN for the LAN so all three will be VLANs on igc0. I'm not sure if this is compatible with the bridge setup though.

Planned reconfiguration:

VLANs on igc0: vlan00 (LAN) + vlan01 (Guest) + vlan02 (IoT)

Must I remove the LAN bridge to make this work?


Quote from: Patrick M. Hausen on August 02, 2026, 09:14:19 PMCan you post the output of "ifconfig -a", please? Redact external IP addresses. Private ones are not a security concern, but if you like, change them, too. I am after a full view of VLAN parent devices and bridge memberships.

Kind regards,
Patrick

Hi Patrick, here you go:

igc0: flags=1008943<UP,BROADCAST,RUNNING,PROMISC,SIMPLEX,MULTICAST,LOWER_UP> metric 0 mtu 1500
   options=4802028<VLAN_MTU,JUMBO_MTU,WOL_MAGIC,HWSTATS,MEXTPG>
   ether 64:62:66:22:4c:ab
   media: Ethernet autoselect (2500Base-T <full-duplex>)
   status: active
   nd6 options=29<PERFORMNUD,IFDISABLED,AUTO_LINKLOCAL>
igc1: flags=1008843<UP,BROADCAST,RUNNING,SIMPLEX,MULTICAST,LOWER_UP> metric 0 mtu 1500
   description: WAN (wan)
   options=4802028<VLAN_MTU,JUMBO_MTU,WOL_MAGIC,HWSTATS,MEXTPG>
   ether 64:62:66:22:4c:ac
   inet xx.xx.xx.xx netmask 0xfffff800 broadcast 255.255.255.255
   inet6 x
   media: Ethernet autoselect (1000baseT <full-duplex>)
   status: active
   nd6 options=23<PERFORMNUD,ACCEPT_RTADV,AUTO_LINKLOCAL>
igc2: flags=1008843<UP,BROADCAST,RUNNING,SIMPLEX,MULTICAST,LOWER_UP> metric 0 mtu 1500
   description: DMZ (opt1)
   options=4802028<VLAN_MTU,JUMBO_MTU,WOL_MAGIC,HWSTATS,MEXTPG>
   ether 00:e0:4c:68:1c:12
   hwaddr 64:62:66:22:4c:ad
   inet 192.168.30.1 netmask 0xffffff00 broadcast 192.168.30.255
   media: Ethernet autoselect (1000baseT <full-duplex>)
   status: active
   nd6 options=29<PERFORMNUD,IFDISABLED,AUTO_LINKLOCAL>
igc3: flags=8943<UP,BROADCAST,RUNNING,PROMISC,SIMPLEX,MULTICAST> metric 0 mtu 1500
   description: OPT4 (opt4)
   options=4802028<VLAN_MTU,JUMBO_MTU,WOL_MAGIC,HWSTATS,MEXTPG>
   ether 64:62:66:22:4c:ae
   media: Ethernet autoselect
   status: no carrier
   nd6 options=29<PERFORMNUD,IFDISABLED,AUTO_LINKLOCAL>
lo0: flags=1008049<UP,LOOPBACK,RUNNING,MULTICAST,LOWER_UP> metric 0 mtu 16384
   options=680003<RXCSUM,TXCSUM,LINKSTATE,RXCSUM_IPV6,TXCSUM_IPV6>
   inet 127.0.0.1 netmask 0xff000000
   inet6 ::1 prefixlen 128
   inet6 fe80::1%lo0 prefixlen 64 scopeid 0x5
   groups: lo
   nd6 options=21<PERFORMNUD,AUTO_LINKLOCAL>
enc0: flags=0 metric 0 mtu 1536
   options=0
   groups: enc
   nd6 options=29<PERFORMNUD,IFDISABLED,AUTO_LINKLOCAL>
pfsync0: flags=0 metric 0 mtu 1500
   options=0
   maxupd: 128 defer: off version: 1500
   syncok: 1
   groups: pfsync
pflog0: flags=1000141<UP,RUNNING,PROMISC,LOWER_UP> metric 0 mtu 33152
   options=0
   groups: pflog
vlan01: flags=1008843<UP,BROADCAST,RUNNING,SIMPLEX,MULTICAST,LOWER_UP> metric 0 mtu 1500
   description: Guest (opt2)
   options=4000000<MEXTPG>
   ether 64:62:66:22:4c:ab
   inet 192.168.20.1 netmask 0xffffff00 broadcast 192.168.20.255
   groups: vlan
   vlan: 20 vlanproto: 802.1q vlanpcp: 0 parent interface: igc0
   media: Ethernet autoselect (2500Base-T <full-duplex>)
   status: active
   nd6 options=29<PERFORMNUD,IFDISABLED,AUTO_LINKLOCAL>
vlan02: flags=1008843<UP,BROADCAST,RUNNING,SIMPLEX,MULTICAST,LOWER_UP> metric 0 mtu 1500
   description: IoT (opt3)
   options=4000000<MEXTPG>
   ether 64:62:66:22:4c:ab
   inet 192.168.40.1 netmask 0xffffff00 broadcast 192.168.40.255
   groups: vlan
   vlan: 40 vlanproto: 802.1q vlanpcp: 0 parent interface: igc0
   media: Ethernet autoselect (2500Base-T <full-duplex>)
   status: active
   nd6 options=29<PERFORMNUD,IFDISABLED,AUTO_LINKLOCAL>
bridge0: flags=1008843<UP,BROADCAST,RUNNING,SIMPLEX,MULTICAST,LOWER_UP> metric 0 mtu 1500
   description: LAN (lan)
   options=10<VLAN_HWTAGGING>
   ether 58:9c:fc:10:4f:48
   inet 192.168.1.1 netmask 0xffffff00 broadcast 192.168.1.255
   id 00:00:00:00:00:00 priority 32768 hellotime 2 fwddelay 15
   maxage 20 holdcnt 6 proto rstp maxaddr 2000 timeout 1200
   root id 00:00:00:00:00:00 priority 32768 ifcost 0 port 0
   bridge flags=0<>
   member: igc0 flags=143<LEARNING,DISCOVER,AUTOEDGE,AUTOPTP>
           port 1 priority 128 path cost 55 vlan protocol 802.1q
   member: igc3 flags=143<LEARNING,DISCOVER,AUTOEDGE,AUTOPTP>
           port 4 priority 128 path cost 2000000 vlan protocol 802.1q
   groups: bridge
   nd6 options=29<PERFORMNUD,IFDISABLED,AUTO_LINKLOCAL>
vlan00: flags=1008843<UP,BROADCAST,RUNNING,SIMPLEX,MULTICAST,LOWER_UP> metric 0 mtu 1500
   options=4000000<MEXTPG>
   ether 64:62:66:22:4c:ab
   groups: vlan
   vlan: 10 vlanproto: 802.1q vlanpcp: 0 parent interface: igc0
   media: Ethernet autoselect (2500Base-T <full-duplex>)
   status: active
   nd6 options=29<PERFORMNUD,IFDISABLED,AUTO_LINKLOCAL>
#9
26.7 Series / Re: VLAN devices are on LAN IPs
August 02, 2026, 09:10:08 PM
Quote from: viragomann on August 02, 2026, 09:38:58 AMThe devices might get their IPs from the DHCP on OPNsense. That they get IPs assigned from the wrong subnet indicates, that they are able to communicate with the DHCP on the other subnet.
If you think, your OPNsense configuration is correct, check the subnet separation outside.
How did you do this? Which device is connected to port 1?

The configuration listed above worked fine under OPNSense 21.x. I am now aware that 26.7 doesn't like mixing an untagged LAN with tagged VLANs on the same interface port (igc0 is on Protectli's port 1). I had also bridged the LAN to igc3 on port 4 under 21.x after getting locked out of the wireless LAN during setup of the wireless AP. It's nice having a free external ethernet port available in case the wireless network goes down again but it's certainly not mandatory.
#10
26.7 Series / VLAN devices are on LAN IPs
August 02, 2026, 05:42:04 AM
Since upgrading to 26.7.x.x, all my VLAN devices (192.168.20.x, 192.168.40.x) now have LAN IP addresses. Here's my configuration (ssh'd into the Protectli VP2420 box):

*** OPNsense.home.lan: OPNsense 26.7.1_1 (amd64) ***

 DMZ (igc2)      -> v4: 192.168.30.1/24  (Protectli hardware port 3, DMZ addresses are correct)
 Guest (vlan01)  -> v4: 192.168.20.1/24 
 IoT (vlan02)    -> v4: 192.168.40.1/24
 LAN (bridge0)   -> v4: 192.168.1.1/24.  (Protectli hardware port 1, routes to WiFi)
 OPT4 (igc3)     -> (Bridged to LAN for external devices)
 WAN (igc1)      -> v4/DHCP4.            (Protectli hardware port 2)

------------------------------------------------------------------------------------

Interfaces: Assignments

wan  WAN hardware  igc1 
lan  LAN bridge    bridge0 (LAN->OPT4 Bridge) 
opt1 DMZ hardware  igc2 
opt2 Guest vlan    vlan01 Guest_VLAN (Parent: igc0, Tag: 20) 
opt3 IoT   vlan    vlan02   IoT_VLAN (Parent: igc0, Tag: 40) 
opt4 OPT4 hardware igc3 
opt5 OPT5 hardware igc0

BACK PANEL OF VP2420
  ___________________________________

 |                                   |
 |  [Port 4]  [Port 3]  [Port 2]  [Port 1] <-- (Physical Labels)
 |   igc3       igc2      igc1      igc0   <-- (OPNsense OS Names)

 |___________________________________|

Prior to the upgrade, all guest devices were assigned IP addresses in the 192.168.20.x space and all IoT devices were assigned IP addresses in the 192.168.40.x space. Now the ARP table shows all devices that are part of vlan01 (Guest) and vlan02 (IoT) having LAN IPs in 192.168.1.x space. I've tried rebooting several times but no luck. How do I get my VLAN IPs back? I don't want guests and IOT devices on my LAN.

#11
Quick update: I discovered that turning on a third-party VPN (ProtonVPN) on both the Mac and iPhone seems to work around this problem. I think that turning on ProtonVPN turns off Apple's Private Relay which would validate the problem area.
#12
I'm having issues with my iPhones reporting "Privacy Warning" and/or "internet not connected" errors since upgrading to 26.7. I applied the 26.7.1 patch today but the problems persist. Google AI is reporting that Apple's Private Relay is being temporarily blocked or getting slow access via Unbound DNS which causes iOS to timeout and issue these errors. I've tried a lot of different tests suggested by Google AI but I can't solve this issue. I don't know why DNS requests to Quad9 are getting stalled when they come through any device running Private Relay. This didn't happen under OPNSense 21.x.

I've also noticed slow updates on the OPNSense web page when going through the various settings. OPNSense is accessed from my Mac via Private Relay under Safari as well so this further indicates the problem is between Private Relay and Unbound DNS. It sometimes takes more than a full minute to update the OPNSense GUI whenever I switch to a different settings page if the new page hasn't been cached already.

I'm currently using both AdGuard and Stevens Blacklist lists with the Normal relaxed/balanced blocking level setting.
#13
@patient0... Ding ding ding, you nailed it! There *were* 0 evaluations or matches being made according to Inspect in the WAN rules. There's no Inspect button in the port forwarding rules but I did find *old* PASS rules prior to the new block rules. The old rules weren't showing up earlier for some reason but when I erased all the categories, they showed up. Oops! I deleted the old port forward rules and left only the new ones and now I'm getting hundreds of matches per minute showing up in the WAN rules.

Thank all of you for resolving this mess. The Inspect Results attached show what's hitting me in a 5-minute time period. Fail2ban is now almost dead quiet running on the OpenVPN Access server which was my long-term goal :-)

Tony
#14
Quote from: EricPerl on March 28, 2025, 07:13:30 PMI would remove that "Internet -> WAN (Firewall)" rule on the spot.
It ALLOWS any Internet host that is NOT in your alias to access any port on your public WAN IP!

An allow rule is not blocking anything in any case!!!
An Allow rule with a source (not inverted) only allows hosts matching the criteria.
An allow rule with an inverted (!) source allows all EXCEPT hosts matching the criteria.

More on the rest later.

Removed.
#15
While waiting for a reply last night, I experimented with the settings shown below. These settings are still NOT blocking the tony_bogons alias list.

I also added a screen shot showing the tens of thousands of bogon IPs slipping through to my OpenVPN Access server and being trapped by fail2ban. Many of these are already in the tony_bogons list.