Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - tangofan

#1
Thanks to both of you for your suggestions. However I decided to uninstall ZenArmor about 3 weeks ago. My OPNsense box is a J6412 with 16GB of RAM and 2.5G NICs. The throughput between two VLANs was 1.1 Gb/s with ZenArmor enabled on those VLANs and ca. 2.4 Gb/s without it (measured with iperf). The stalling video was then the last straw and I decided to give up on ZenArmor.
#2
Quote from: Patrick M. Hausen on September 18, 2026, 11:36:36 PM
Quote from: tangofan on September 18, 2026, 09:44:58 PMPerhaps it would be a good idea, if at the time of uninstallation of a plugin, there was an option to erase the configuration block of that plugin

- System > Configuration > Defaults > Components
- Select "Services: ISC DHCPV4 [legacy] [dhcpd]"
- Click on "Reset"
- Repeat for DHCPV6

HTH,
Patrick

I was totally unaware that this feature even existed. OPNsense regularly surprises me on the positive side.

Many thanks, Patrick.
#3
Quote from: Remington on September 17, 2026, 10:32:57 PMFor me the issue seems to be an old DHCP/DHCPv6 configuration in config.yml which is not necessary anymore as I moved from ISC DHCP to DNSMASQ. I have created a backup of config.xml. Removed the <dhcp> and <dhcpv6> bock and restored the firewall from this config. This fixed the issue.
At the risk of derailing this thread ever so slightly: I used ISC before and switched to KEA not too long ago and - after looking at my config file for the first time ever - I also noticed a <dhcp> block. (Never had ipv6 active.)

Perhaps it would be a good idea, if at the time of uninstallation of a plugin, there was an option to erase the configuration block of that plugin, e.g. by having an additional popup querying, whether to erase that data. Obviously that would require additional entries in the metadata of each plugin as to where to find the configuration block(s). So if that additional metadata weren't present, that option to erase the config data wouldn't be available.
#4
26.7 Series / Re: Firewall rules [new] missing
September 17, 2026, 09:17:37 PM
Quote from: SVMartin80 on September 17, 2026, 09:09:58 PMThanks both for the replies!

Patrick, if I understand correctly the version I'm currently running by default only shows the new rules and during an upgrade the rules already have been migrated automatically?

It totally makes sense to me that the new Rules page is now called 'Rules' and the legacy version is available through a plugin for users who prefer this.

However, what doesn't make sense to me is that I still see 'Migration assistant'; will that be removed soon in an update?
No, there is no automatic migration of the old rules. The new rules UI will show those old rules IIRC, but you can't edit them there. So you will need to go through the migration steps for your rules manually. IIRC the migration assistant "disappears", once everything is migrated.
#5
Quote from: stulpinger on September 17, 2026, 04:32:56 PMmein OPNsense ist auf 26.7.4_1
nur noch Rules im Menü 😎
Der "Rules [legacy]" Menüeintrag erscheint nur, wenn du das os-firewall-legacy Plugin installiert hast. Die Migration der alten Regeln ist aber auch ohne dieses Plugin möglich.
#6
General Discussion / Re: Block Local Network Connections?
September 16, 2026, 10:35:13 PM
Quote from: lmoore on September 16, 2026, 01:29:21 AMI don't have a Smart TV for privacy reasons. However, any device used to stream content from the Internet can send telemetry.

Reading this article, NTP is also utilised for gathering information.

I've included a Destination NAT rule to redirect NTP connections to OPNsense.

I found that I also needed an SNAT rule for NTP, so my Synology NAS would accept the response from the OPNsense NTP server. Other clients might require the same.
#7
Quote from: turipriv on September 13, 2026, 11:15:04 AMMy unit works like a charm; all services loaded and no issues whatsoever; hardware and running features as per signature.

For the sake of completeness, the microcode plugin is currently running in late load mode.

If you ever want to run the microcode plugin in early load mode, my understanding is that you need to upgrade the bootloader first, which essentially involves copying some files from one OPNsense directory to another. While I also run the microcode plugin with default settings (late mode IIRC), I did go through those steps, since I figured that it doesn't hurt to get my bootloader current.

My upgrade was similarly smooth (perhaps due to uninstalling the microcode plugin first) and I applaud the team for their ability to manage the ever shifting sands of their foundations (FreeBSD, etc.) and still provide a smooth experience with minimal manual steps (provided one reads the release notes, of course).
#8
I would doubt that Deciso will "preconfigure" a new device, unless it's done under a consulting agreement and I assume you're not willing to pay for that. But I might be wrong...

You have two problems:
1. You're about 10 major releases behind (assuming the 6 month release cycle has been going on since 2021) and
2. you also want to switch to a different hardware.

#2 means they even with a config file from the current version you may have to do some manual editing, because the network interfaces might have different names on your new hardware. That's the smaller problem by far.

#1 is the real problem: I seriously doubt that you can jump 10 releases ahead and expect everything to work, since nobody will ever test for that. It might work for a very simple setup, but I wouldn't bet on it. So you either upgrade manually through each release, carefully reading all the release notes for any breaking changes and/ or necessary manual steps, or alternatively just get a new device and start configuring it from scratch. For a simple setup, this might be the easier path.

Whatever you decide to do, in the future you should keep your router software more current. I don't see OPNsense (or any router/firewall software for that matter) as something you can leave unattended for months on end, let alone 5 years.
#9
I upgraded 5 weeks ago to 26.7.1_1 with Zenarmor, Crowdsec, QFeeds and Tailscale installed and I didn't have any problem with the upgrade, but I paid attention to the things below:

- There were some issues with the newer FreeBSD version in 27.1, which manifested when running the os-cpu-microcode-intel plugin. At the time the recommendation was to uninstall this plugin before upgrading, update the OPNsense bootloader and only afterwards reinstall the plugin. I suggest that you search the forum for this, since there were plenty of posts on this subject.

- If you have not yet migrated the firewall and NAT rules to the new UI, you will need to install a new plugin in 26.7 to be able to edit them. That plugin (os-firewall-legacy IIRC) is already available in later versions of 26.1, at which time I installed it. I waited with the migration until after the upgrade to 26.7, but it's probably better to execute that migration before the upgrade. I found the migration to be very easy, just follow the instruction in the migration tool and remember to go through all the tabs of that tool.

As always, read the release notes and download your config before the upgrade and (if you run ZFS, which I hope everyone does) create a snapshot.
#10
My OPNsense box is a little over two years old and I had Zenarmor running for two years with a home subscription, using a local elasticsearch DB. The lifetime writes of my SSD are about 5.7 TiB, which is very mild compared to the rated typical lifespan of an SSD. So I suspect those who have a wear problem with their SSD have some additional features or logs turned on or turned to a higher logging level.

What made me discontinue my Zenarmor home subscription and ultimately uninstall Zenarmor were performance problems like the one I described here. I don't know, if those particular problems could have been solved by multicore support (single I don't know how granular the workload for a particular connection can be shared between different threads), but not having it or getting it means that I definitely would have to get a system with a CPU that has higher single-core performance than an Intel J6412. And that just didn't seem to be worth it.

So I would agree with the assessment that Zenarmor has a growing problem with positioning themselves. I understand that they don't want their free edition or their home edition subscription to cannibalize their commercial subscriptions (particularly in the SMB sector, where you might not need enterprise-level sizing). My assumption is that the main purpose of the free and home tiers is to have a showcase to home-labbers, in the hope that some of them would carry a positive experience into their workplace and thus increase Zenarmor's commercial subscription base. However as the home-labber experience turns less positive, that "carryover" effect is much less likely to happen. Thus I am surprised that they don't offer multithreading (with a limited thread count) in the free and home editions.
#11
Quote from: The Crazy Squirrel on September 07, 2026, 11:14:26 PMI don't know why, but now it's working.  I didn't change anything from my original post.
Was it time?  Was it a cache?  I have no idea.

What might have happened is that the state for internet access was still active in the firewall state table. You can clear individual states under Firewall -> Diagnostics -> States and under the "Actions" tab you can also reset the whole state table.
#12
General Discussion / Re: Block Local Network Connections?
September 07, 2026, 08:31:29 AM
Quote from: pfry on September 07, 2026, 07:50:12 AMThanks, Steve.

Sure, just run all connections through the firewall. I do this. In general you just need enough compute power in your firewall (varies by application) and appropriate connectivity (e.g. lots of ports on the firewall and/or virtual ports via one or more managed Ethernet switches).

Just to clarify: That would mean running every device directly into a port on the firewall, would it not? Because if you connect them via a switch, that traffic would never hit the firewall, since the switch would just pass it directly via the applicable port to the target device.

Of course now that I think of it, if you had a managed(!) switch, then you could put each device into a separate VLAN that you also created in OPNsense. Then there would be no intra-VLAN traffic and the switch would forward all traffic to OPNsense. Pretty extreme, but workable. Perhaps someone has a better idea?
#13
Quote from: OPNenthu on August 14, 2026, 01:23:26 AMI'm going to call this a win.  Been following the issue for some days now and the pf rate limiter is reliably capping the queries from the Roku group to just around 300/min, which corresponds perfectly to the 50 / 10s rate that I set in the rules.

That "50 per 10s" you set, is this per individual device (e.g. per source ip) or is this across all matches for that rule (so the matches for Roku1 would also count towards the rate limiting of Roku2 and vice versa)?
#14
26.7 Series / Re: Hagezi Blocklist Not Available?
August 13, 2026, 11:52:37 PM
Quote from: OPNenthu on August 13, 2026, 11:00:31 PM
Quote from: Patrick M. Hausen on August 13, 2026, 10:34:26 PMThe repo on github is back online. IMHO that won't be the solution:

https://github.com/AdguardTeam/AdGuardHome/issues/8561

All, pay attention to Patrick's note here ^ about "dnsbunker.org" being blocked by DOH lists.  It is also blocked by this one, if not others:

https://dbl.ipfire.org/lists/doh/domains.txt

So you might need to add an override.  I don't know if the firewall itself is affected by DNSBL policy (maybe depending on your setup), so may or may not be an issue for you.

This is a kind of ironic situation.  Hopefully hagezi can settle on a host that is NOT also a DNS provider.

One way one might also circumvent this problem is to set the option "Do not use the local DNS service as a nameserver for this system" under System->Settings->General. Then OPNsense should go upstream for all its DNS requests, instead of using the local Unbound DNS and its blocklists.
#15
26.7 Series / Re: Hagezi Blocklist Not Available?
August 13, 2026, 10:53:40 PM
Quote from: Patrick M. Hausen on August 13, 2026, 10:34:26 PMThe repo on github is back online. IMHO that won't be the solution:

https://github.com/AdguardTeam/AdGuardHome/issues/8561

Indeed, it won't be. Hagezi himself recommends a different mirror for his repo and the new patch points to that one, IIRC. But until that patch ships in a release and folks have updated to it, at least their old blocklist entry will work again (at least until the next github suspension).

On a side note, I am very surprised that github doesn't have a mechanism to prevent certain repos that are frequently subject to reporting spam from being blocked without human review. But perhaps I'm expecting too much...