Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - Lucid1010

#1
26.7 Series / Re: chrony port open?
September 17, 2026, 01:54:26 AM
Quote from: Patrick M. Hausen on September 16, 2026, 03:11:23 PM127.0.0.1 is the loopback interface. It is not reachable from anywhere but the firewall itself.

Yes. I'd just like to disable the local port as well.
#2
26.7 Series / chrony port open?
September 16, 2026, 03:03:06 PM


You cannot view this attachment.

$ sockstat -4 -l | grep chrony
chronyd chronyd    69981   5 udp4  127.0.0.1:323         *:*

Is it a bug that port 323 is open even though I didn't set 'Allowed Networks'?

When 'Allowed Networks' is configured, it opens as `*:323`, but when it's not set, the port opens as `127.0.0.1:323`.

$ cat /usr/local/etc/chrony.conf

port 323
driftfile /var/db/chrony/drift
pidfile /var/run/chrony/chronyd.pid
makestep 1 3

ntsdumpdir /var/lib/chrony
ntstrustedcerts /usr/local/etc/ssl/cert.pem
nosystemcert


server time.cloudflare.com iburst nts

It would be great to have an option to set the port to 0 or disable it completely.
#3
/usr/local/opnsense/scripts/wireguard/wg-service-control.php: The command </usr/bin/wg syncconf 'wg0' '/usr/local/etc/wireguard/wg0.conf'> returned exit code 1 and the output was "Name could not be resolved at this time: `my-domain.com:51820'.
Trying again in 1.00 seconds...
Name could not be resolved at this time: `my-domain.com:51820'.
Trying again in 1.20 seconds...
Name could not be resolved at this time: `my-domain.com:51820'.
Trying again in 1.44 seconds...
Name could not be resolved at this time: `my-domain.com:51820'.
Trying again in 1.73 seconds...
Name could not be resolved at this time: `my-domain.com:51820'.
Trying again in 2.07 seconds...
Name could not be resolved at this time: `my-domain.com:51820'.
Trying again in 2.49 seconds...
Name could not be resolved at this time: `my-domain.com:51820'.
Trying again in 2.99 seconds...
Name could not be resolved at this time: `my-domain.com:51820'.
Trying again in 3.58 seconds...
Name could not be resolved at this time: `my-domain.com:51820'.
Trying again in 4.30 seconds...
Name could not be resolved at this time: `my-domain.com:51820'.
Trying again in 5.16 seconds...
Name could not be resolved at this time: `my-domain.com:51820'.
Trying again in 6.19 seconds...
Name could not be resolved at this time: `my-domain.com:51820'.
Trying again in 7.43 seconds...
Name could not be resolved at this time: `my-domain.com:51820'.
Trying again in 8.92 seconds...
Name could not be resolved at this time: `my-domain.com:51820'.
Trying again in 10.70 seconds...
Name could not be resolved at this time: `my-domain.com:51820'.
Trying again in 12.84 seconds...
Name could not be resolved at this time: `my-domain.com:51820' Configuration parsing error"

After upgrading to 26.7.4, I encountered the WireGuard log error shown above.
I'm using AdGuard Home, and I suspect this issue occurs because the AdGuard Home service fails to start on reboot.
#4
https://freebsdfoundation.org/blog/freebsd-ai-assisted-vulnerability-discovery-project-launch/

https://www.reddit.com/r/technology/comments/1vkjpxh/linus_torvalds_says_ai_has_made_huge_linux_kernel/


Even if not for vibe coding, it would still be useful for security vulnerability scanning of OPNsense core and plugins, performance tuning, and WebUI development.
#5
General Discussion / Re: Rclone backup support
September 13, 2026, 01:23:00 PM
https://rclone.org/downloads/

Since rclone uses a FreeBSD binary, you can run backups directly using a shell script.
I currently back up to Dropbox and S3 via rclone.
#6
26.7 Series / Problem where fallback DNS is being used
September 10, 2026, 08:16:15 PM
You cannot view this attachment.

$ cat /etc/resolv.conf
# This file was automatically generated by system_resolvconf_generate()
# If you want to append configuration here use /etc/resolv.conf.local
domain xxxxxxxxxxxxxxxx
nameserver 192.168.1.1
nameserver 1.1.1.1
nameserver 1.0.0.1
search xxxxxxxxxxxxxxx


$ drill google.com
;; ->>HEADER<<- opcode: QUERY, rcode: NOERROR, id: 41425
;; flags: qr rd ra ; QUERY: 1, ANSWER: 6, AUTHORITY: 0, ADDITIONAL: 0
;; QUESTION SECTION:
;; google.com.  IN      A

;; ANSWER SECTION:
google.com.     114     IN      A      xxxxxxx
xxx
;; AUTHORITY SECTION:

;; ADDITIONAL SECTION:

;; Query time: 0 msec
;; SERVER: 192.168.1.1

# --

$ drill google.com
;; ->>HEADER<<- opcode: QUERY, rcode: NOERROR, id: 13948
;; flags: qr rd ra ; QUERY: 1, ANSWER: 6, AUTHORITY: 0, ADDITIONAL: 0
;; QUESTION SECTION:
;; google.com.  IN      A

;; ANSWER SECTION:
google.com.     281     IN      A       xxx
xxxx
;; AUTHORITY SECTION:

;; ADDITIONAL SECTION:

;; Query time: 4 msec
;; SERVER: 1.1.1.1

I am currently using AdGuard Home as my main DNS server.
AdGuard Home responds immediately and works without issue.
However, whenever a DNS query is made, my device alternates between AdGuard Home (192.168.1.1) and Cloudflare DNS(1.1.1.1).

Is it possible to set it up so AdGuard Home is used as the sole primary DNS, 
and Cloudflare DNS is only used as a fallback when AdGuard Home is delayed or unresponsive?
#7
👍
#8
This looks like a bug.
#9
Q: What value should I enter for the monitor IP in the System Gateway settings?

I am using Mullvad, and according to their documentation, I should enter their DNS address (10.64.0.1).

However, since I have set up multiple selective routings (3 or more), I can only use 10.64.0.1 as the monitor IP for a single gateway due to a duplicate IP error.
#11
useful
#13
General Discussion / Re: nfSensei ( fork pfsense )
August 08, 2026, 12:19:57 AM
where is code?
#14
General Discussion / Re: apc ups commlost
July 21, 2026, 10:20:36 PM
apcupsd and NUT work together without any issues. I use apcupsd alongside NUT because it provides features such as automatic shutdown of the OPNsense host and configurable battery thresholds.

Since the NUT configuration in OPNsense doesn't work properly, I'm using apcupsd alongside it.

nut.conf, upsd.conf, ups.conf ...etc configure not working


Quote from: Patrick M. Hausen on July 21, 2026, 03:51:49 PM
Quote from: lmoore on July 21, 2026, 03:47:17 PMNUT includes the driver APCUPSD-Driver and it may tempt some users to use it.

From the thread I got the impression they were trying to install and run the standalone apcupsd alongside NUT which probably won't work.
There is an os-apcupsd plugin. Don't run that if you intend to run NUT and vice versa.
#15
Quote from: tuto2 on July 17, 2026, 11:50:59 AM# opnsense-update -zkr 26.7-igc

Will the official patch be included in the next update?