Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - abenaou

#1
Zenarmor (Sensei) / Re: Zenarmor on the DEC850
September 23, 2026, 11:07:03 PM
If you plan to run Zenarmor in native netmap mode you have to widen the queues to avoid starvation and interfaces crashes down the road, look at my post where I implemented a solution that fixed my native netmap mode that caused incessant interfaces restarts, this fixed my igb interfaces issues and might work for igc providing the nic is compatible.
#2
While the decision is yours, I respect that.
But it is expected to have a basic understanding of how Zenarmor works to really make an informed decision and ditch it.
Some settings are not suitable for some hardware and will break stuff, the provided documentation is far from ideal but solutions do exist and it takes some trial and errors to reach the "sweet spot", you can read my post and/or other members posts to find solutions to issues that people encountered before.
At the end of the day time is expensive and some of us have better uses for their time but if you decide to resume the troubleshooting, help is available here.
#3
Have you tried a dmesg when the video freezes up? the freeze can happen for various reasons, one of them being the zenarmor engine mode used, it can also be an under powered cpu, or not enough ram, there are tons of possibilities and without a capture of those metrics at the time of the issue the best you would end up with are guesses.
#4
Hi all,

I just want to share with you some tunables that fixed repetitive crashes when using zenarmor in native mode, there is a warning that say you should be using the emulated mode, but that wasn't enough of an explanation for me, queuese would run out after a few hours and force an interface restart, after a lot of AI fu I was finally given the correct value, these won't work from the web interface as those are applied once the firewall has started which is already late, this works with i350-t4 cards :

cat /boot/loader.conf.local
dev.igb.0.iflib.override_ntxds="4096"
dev.igb.1.iflib.override_ntxds="4096"
dev.igb.2.iflib.override_ntxds="4096"
dev.igb.3.iflib.override_ntxds="4096"
dev.igb.0.iflib.override_nrxds="4096"
dev.igb.1.iflib.override_nrxds="4096"
dev.igb.2.iflib.override_nrxds="4096"
dev.igb.3.iflib.override_nrxds="4096"

dmesg confirms the application of the new values :

[31] tun0: changing name to 'zen0'
[33] igb1: link state changed to UP
[34] igb0: link state changed to UP
[34] igb2: link state changed to UP
[35] igb3: link state changed to UP
[42] 137.783848 [ 805] iflib_netmap_config       txr 6 rxr 6 txd 4096 rxd 4096 rbufsz 2048
[42] 137.783906 [ 805] iflib_netmap_config       txr 6 rxr 6 txd 4096 rxd 4096 rbufsz 2048
[42] igb1: link state changed to DOWN
[42] igb0: link state changed to DOWN
[43] 138.429571 [ 805] iflib_netmap_config       txr 6 rxr 6 txd 4096 rxd 4096 rbufsz 2048
[43] 138.540666 [ 805] iflib_netmap_config       txr 6 rxr 6 txd 4096 rxd 4096 rbufsz 2048
[47] igb0: link state changed to UP
[47] igb1: link state changed to UP

as soon as I applied this, my issues were gone.
#5
Quote from: Patrick M. Hausen on September 09, 2026, 08:42:04 AMOut of curiosity: can't you use an off device Elastic installation? E.g I run Elastic as an "app" on TrueNAS for my FreeBSD jail based Nextcloud to use.
I did use an elasticsearch container running docker/portainer but I just feel it is an overkill for a home lab or even an SMB, sqlite being transactional nothing would stop mysql from replacing it and having far more benefits, as I said before I don't know if there are architectural limitations or roadblocks for the devs, but from my perspective I think it is far better to have a mysql/mariadb back end for performance and redundancy, homelabbers like me would choose mysql/mariadb for its "simplicity" and bigger players could use elasticsearch for their bigger databases.

I used to run a master/slave mariadb cluster years ago, and it was one of the ways to minimize the load on my production server, I can't see that happening with SQLite that lives in the same nvme as opnsense (I know I can always use a mount), or using elasticsearch for that purpose, it just gives me less possibilities overall.
#6
I agree with most of what was said in this thread, the other thing I feel very limiting is the number of policies, having just 5 policies can become a serious limitation for the home licence subscribers.

I wish other database back ends were considered, obviously the developers have their own reasons, but I feel between elastic and sqlite the choices are restrictive as both could wear out the disk while having an external mariadb handling the database aspect would make things more flexible.

Anyway, this is unrelated to the first post but thought giving some feedback can help improve the product.
#7
Quote from: Patrick M. Hausen on December 07, 2025, 09:38:51 PMIf the DHCP server in LAN98 sends a default gateway that is the cause for your static route. Don't use DHCP or any dynamic configuration for anything but WAN.
This was indeed the solution to the problem, thank you so much.
#8
Quote from: Patrick M. Hausen on December 07, 2025, 12:54:23 AMInterfaces > LAN - is there a gateway set?
Here is what my LAN interface looks like (didn't set anything there) as well as the second lan98 interface that connects through dhcp:

Screenshot attached
#9
As a workaround I emplemented a cron to delete that route, I really don't know where to look for anymore :

* * * * * /sbin/route delete -host 10.99.200.180
#10
Quote from: Patrick M. Hausen on December 06, 2025, 04:43:15 PMInterface configuration for LAN - did you set a gateway there? Don't.

If you need static routes pointing to that other firewall, add it as a gateway in System > Gateways and add the static routes as necessary.
Thanks, I checked, there are no routes configured in both of my LAN interfaces :
system -> routing -> configuration = empty

This is what makes it confusing, is that I don't have any static routes on both firewalls, just the gateways whith different priorities (1 for IPv6 / 2 IPv4 / 256 for the LAN98 interface)
#11
Quote from: Patrick M. Hausen on December 05, 2025, 08:54:18 PMUGHS - that route is static. It's configured somewhere. Do you have configured a gateway on vlan0.6? Remove that.
Thanks for your answer.
Where should I look? I checked :
System -> Routes -> configuration
And there is no such a route, in fact the page is empty.
I even downloaded the configuration file and did and nothing came up:
grep -rni 10.99.200.180 myroute-20251206083945.xml
Where should I check?

Thanks
#12
Here is more details about the route :

Proto   Destination   Gateway   Flags   MTU   Netif   Netif (name)
ipv4   10.99.200.0/24   link#14   U   1500   Vlan0.2   LAN
ipv4   10.99.200.1   Link#10   UHS   16384   lo0   loopback
ipv4   10.99.200.180   10.99.200.1   UGHS   1500   Vlan0.6   LAN98

The unwanted route is 10.99.200.180 being sent to 10.98.200.1 which is another firewall, the traffic ends up being blocked and rejected, making the server 10.99.200.180 isolated from the internet.

Do you have any ideas?

Thanks
#13
Hi all,

I have 2 opnsense firewalls, both running 25.7.8 and to each their vlan.
They're both interconnected by their LAN interfaces, in case WAN1 fails the traffic goes through the gateway of WAN2.
No the issue I have is that a route shows up on its own, I didn't create it, and when I delete it keeps coming back bringing my server down :
The faulty route is 10.99.200.180 being sent to 10.98.200.1 which goes through WAN2, I didn't add it and even when I delete it, it keeps coming back.
Can you please help?

Thanks
#14
This has been solved in the latest release :
OPNsense 25.7.1_1-amd64

Thanks for the devs and the forum participants.
#15
Quote from: Monviech (Cedrik) on July 31, 2025, 09:08:31 PMhttps://forum.opnsense.org/index.php?topic=48256.0
Thanks for replying back, I guess I am just going to wait for it be fixed in the upcoming version, I want to keep a consistent build.