Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - nero355

#1
Posting a bit more info about it or some personal first impression stories never hurts anyone ;)
#2
General Discussion / Re: Strange WiFi issue
October 04, 2026, 10:12:11 PM
Quote from: suur13 on October 04, 2026, 08:44:30 PMOne reaches its configuration page by 192.168.1.xxx:58050
I can reach this page from my desktop, laptop or iPhone, when later is connected to random AP in my house. Only when it is connected to Opnsense box Wifi (WLAN which is bridged to lan together with other Ethernet connections opt1, opt2....) I can not reach this page. It blocks me and says external connection not allowed. But obviously I have 192.168.1.y IP on my iPhone.
That sounds more like playing around with these options is needed : https://bubblesoftapps.com/bubbleupnpserver2/docs/config_network_and_security.html

Can you simply ping/traceroute the IP Address when connected via OPNsense WLAN ?
#3
General Discussion / Re: Strange WiFi issue
October 03, 2026, 08:36:21 PM
Quote from: suur13 on October 03, 2026, 02:50:39 PMIf I connect iPhone to Wifi via Opnsense box own WLAN interface I can not reach BubbleUPnP.
Is Multicast DNS allowed on the WiFi Bridge ?!

Perhaps disable IGMP Snooping tuneable or something like that ?


/Just some thoughts...
#4
Quote from: Schwermzilla on October 03, 2026, 12:30:33 AMYou got it! memes be praised, it was DNS.

Following your thoughts, I was able to connect with a static ip on my laptop, received a DNS error trying to access any website. So I just deleted both DNS setups and reservations, and rebuilt/re-enabled everything in DNSmasq and it worked! So I clearly fumbled something in the DNS settings on my first... many attempts.

I will figure out how to mark this as Resolved!

Thanks again!

LOL! NICE! ^_^
#5
26.7 Series / Re: Postfix sender rewriting
October 03, 2026, 08:30:18 PM
Quote from: lmoore on October 03, 2026, 02:42:59 AMIt doesn't appear that mail is installed in OPNsense by default, at least not on mine. There is nothing in /etc/mail and no sendmail program.
Makes sense I guess and the documentation seems to confirm it : https://docs.opnsense.org/manual/how-tos/mailgateway.html#postfix

Quote
Quote from: nero355 on October 02, 2026, 11:09:49 PMBut how about adding .conf files
I have done this with Unbound - after reading the documentation. Your mileage may vary for other services, depending on how OPNsense configures them. However, it's best they are managed using an applicable plug-in.

[Edit] Of course, such custom settings wont be included in a back-up.

OPNsense Web GUI for Unbound lets me know there is a configuration which could possibly overwrite settings in the Web GUI.

NICE! :)

I think that kind of configutations made me think that the same rules apply to other software, but that does not seem to be the case.

Quote from: putt1ck on October 03, 2026, 12:32:15 PMNow I'm nervous we've been wasting effort - we have several deployed systems where we've customised the rspamd plugin configuration to enable DKIM,as per this post:

https://forum.opnsense.org/index.php?topic=20280.msg270642#msg270642

- is there a risk that configuration work will be lost on the next service/firewall restart?
It seems to be supported according to : https://docs.opnsense.org/manual/how-tos/mailgateway.html#rspamd

But to be honest my personal preference would always be this :
Quote from: putt1ck on October 03, 2026, 06:49:57 AMWhile we're comfortable making Postfix work via conf it would seem that shouldn't be using a plugin on the firewall and we should have a separate VM to act as the relay for mail.
:)
#6
26.7 Series / Re: Postfix sender rewriting
October 02, 2026, 11:09:49 PM
Quote from: Patrick M. Hausen on October 02, 2026, 10:54:51 PM
Quote from: nero355 on October 02, 2026, 09:40:30 PMEditing .conf files directly shouldn't be a big deal when using OPNsense AFAIK ?!
It definitely would. Your config file changes will be overwritten at every reboot.

Unless the plugin in question provides e.g. a specific directory for custom configuration.
But in general *all configuration* is regenerated from scratch from the config.xml at every reboot.
Hmm... OK. Good to know!

But how about adding .conf files to /etc/postfix/ or /usr/local/etc/postfix or where the main .conf is located anyway ?!

Postfix is the default MTA and not a plug-in : Right ?
#7
Quote from: Schwermzilla on October 02, 2026, 10:39:39 PMThank you very much nero355!
I feel like you are very close to setting this up properly so it would be a shame not to help! :)

QuoteThis is all helpful to my understanding and context on all of this.
COOL!

QuoteSince google drive doesn't play nice, maybe Microsoft works better? https://1drv.ms/f/c/676bc1fb105ced33/IgDdJIPRu_JdQJgC0L6t-j1OAQcqN-Abuw1LuiE72ZLj9BA
A little bit better...

QuoteIt seems like the best way to solve for this and allow for future updates is to have things more granularly setup in the advanced settings.
In my previous post, lmoore also recommended this.

Unfortunately, after implementing this on the switch, I am still unable to access either vlan from my laptop when testing.
That sucks! :(

As far as I can see you have set it up correctly and I have no idea why it's not working...

- OPNsense stuff seems OK.
- Switch stuff now seems OK too.
But... I don't know this Switch software-wise so maybe there is more to it ?!

QuoteMy immediate concern is the lack of traffic I can see from the OPNsense router.
Do you have any insight into how/why I see 0 activity from OPNsesne on port5?
Dunno...

Your Firewall Rules seem to be fine so that can't be it, can it ?!

To make sure it's not some stupid DNSmasq issue or the Firewall blocking communication to it you could assign the Laptop a Static IP Address and test that way : Ping the Gateway and see what happens...

To test if the Switch configuration is correct should be simple : Replace the OPNsense machine with another PC/Laptop and start pinging while both have Static IP Addresses configured.


Good luck! :)
#8
26.7 Series / Re: Postfix sender rewriting
October 02, 2026, 09:40:30 PM
I would start reading official documentation for this kind of stuff : https://www.postfix.org/ADDRESS_REWRITING_README.html

Editing .conf files directly shouldn't be a big deal when using OPNsense AFAIK ?!
/EDIT : I was wrong! See below !!

Also this : https://unix.stackexchange.com/a/726317
Seems to match what I know about Sendmail from a long time ago and seems to apply to Postfix too ?! :)
#9
Quote from: Schwermzilla on October 02, 2026, 07:12:48 PMAre you able to review the photos shared on google drive? https://drive.google.com/drive/folders/1YmCybrYoM4dVkMVTz_UjtMY8Dn6Zi6km
Verification of those things are visible there
NOFI, but viewing the screenshots that way is horrible and seems to be optimized for their own Google Chrome browser, because LibreWolf (basically Firefox + uBlock Origin + Some Privacy stuff added) acts really weird when viewing them and I never had such issues anywhere else...

Quotebut to reverify for my own sanity:

The only things in use that are connected in Access mode are the default LAN, which not setup as a vlan, so no tags from OPNsense igc1 to the switch port 4, which is set for access and connects my computer to OPNsense through the switch.
Probably using VLAN 1 for both sides and that's just perfectly fine! :)

QuoteThe only things connected in Trunk/tagged mode are the vlans 11 & 22 from OPNsense on igc2 to the switch port 5, which is set for Trunk/uplink.
The vlan assignments are visible on the shared screenshot above, showing the interface assignments in OPNsense.
That's correct too! :)

QuoteDo I need to have igc2, assigned as a "hardware" interface as well? Or does assigning the parent for the vlans as igc2 enable that device?
In all honesty : It's something that confuses me a bit too and conflicts with what I know from other systems and devices.

According to most people and from what I have seen here on the forum there is no need to Enable "the Main Interface" but in my case I have Enabled both the Interface that carries the WAN VLAN and the Interface that carries the LAN VLANs.

Reason : On for example a CISCO Router you need to Enable the Main Interface, leave it's IP configuration empty and just configure the sub-interface(s) and the VLAN configuration for them.

Quote from: caplam on October 02, 2026, 04:12:10 PMport 4 needs to be set to access mode with PVID 1
port 5 needs to be set to trunk with vlan tag 11&22
but for this to work port5 can't have PVID 1.
I fixed things by creating a dummy vlan 99 (or whatever you want but not used ) and setting PVID 99 to port5.
Can't you simply leave it empty ?!

I mean a dummy VLAN is fine, but a real Managed Switch allows you to simply assign the TAGGED VLANs and be done with it :)

Quoteand of course the port for the orbi needs pvid 1 and tagged vlan11 and vlan22 (if you have wifi cams)
Exactly! :)

Quote from: Schwermzilla on October 02, 2026, 07:48:50 PMI think I have it correct on OPNsense, igc1=port4 in access mode for lan (192.168.1.x subnet using PVID1?) While igc2 exclusively is handling the two vlans 11 & 22.
Good! :)

QuoteHowever, in matching the vlan settings on the switch, the pathway from igc2 to Port5 also cannot have any association Pvid/vlan 1? 
This might be the issue, Netgear's unmodifiable "default" uses vlan tag 1, would that cause conflict between PVID of OPNsense sending untagged traffic for PVID1 on Port4 vs Netgear expecting it tagged on Port5?
It's not a conflict : You can do whatever you need to do, but just make sure there is no network loop created by accident !! ;)

QuoteThe Netgear switch Basic 802.1Q VLAN mode (which I have been using) seems to be always expecting tagged vlan 1 traffic in addition to the added vlans.
Then, if I am following the logic correctly, the solution could be to move my untagged LAN to a different subnet location, say 192.168.99.x. Then create a new vlan 1, on subnet 192.168.1.x and run with it as my "main" network, running all three vlans (1,11,22) on port 5, with the matching vlans setup on the switch?
You don't need an actual network : Just create the VLAN on the Switch and configure the Ports correctly and you are DONE!

Your VLAN 1 can stay as it is right now ;)

QuoteTo make the options more confusing, the switch does have an Advanced 802.1Q VLAN support options, with port-by-port tag/untag/exclude options for each VLAN.
I initially felt like it was too overpowered for a simple test, but I may be able to the switch it to expect the mix of tagged and untagged traffic across the various ports. I will test this later tonight and update this post with the results.
Funny : I always first Enable any kind of Advanced/Expert Mode and from that moment on I only use the device that way! :P
#10
Quote from: BoerBart on October 02, 2026, 05:03:40 PMI don't know whether the configuration I had adds to your "weird stuff/things" people do, or that it should be a valid configuration, but for now, it works.
Definitely weird : You need to Bridge that Modem/Router from your ISP and use it as a pure Modem that way on the WAN of your OPNsense :)

What you have know is the same 192.168.1.0/24 subnet at two places and that can't work properly because your OPNsense did not know where the traffic should go : WAN or LAN ?!
#11
Quote from: Schwermzilla on October 02, 2026, 01:01:56 AMYeah, hope that is not what is causing the problem.
Well... if you want to transport Multiple VLANs to another Switch or Accesspoint then you need to use TAGGED VLANs and not ACCESS Mode :)

Just to be sure :

Are you aware of the following =>

OPNsense Interface (whole NIC basically) => Switch Port in ACCESS Mode
OPNsense VLAN Interface (VLAN Interface assigned to a NIC that's not used for anything else) => Switch Port in TAGGED Mode

Switch Port in ACCESS Mode => End user devices like PCs/TVs/Consoles/etc.
Switch Port in TAGGED Mode => Port of another Switch or Accesspoint that understands TAGGED VLAN traffic.

ACCESS MODE = Only 1 VLAN allowed.
TAGGED MODE = Multiple VLANs allowed.

Does your current setup look like this ??
#12
Quote from: Schwermzilla on October 01, 2026, 10:35:24 PMLast relevant connection on the switch, port 1 goes to my wireless AP (Netgear Orbi Pro 6, SXR80) setup in AP mode, which works on local network access when tested.

On the Orbi, it has been setup in Trunk mode since being in AP, I have two id's broadcasting there, one for 192.168.1.x (local) and the other for 192.168.11.x. (guest).
I have tried running port 1 on the switch in trunk/uplink mode as well, but then I lose connection to the orbi in either Trunk or Access vlan 11 only (pictured).

The only way it works is when it is set to access only local vlan 1 : Then devices on the local wifi work fine, devices on the guest wifi connect to the Orbi but have an IP configuration error and aren't assigned DHCP leases, as expected.
So the problem is your WiFi Orbi Unit and not OPNsense then ?!

Do those things even understand VLANs on their Switch/LAN side ??
AFAIK they do not : Only on the WAN Port.

Also currently your Netgear Switch shows Port 3 as Access Port and those do not transport VLANs ofcourse...
#13
This issue is caused by your Repositories configuration from what I have seen in other topics...

Sometimes it's because you got the FreeBSD Repositories Enabled and sometimes it's a Third Party Repository messing up things.

Look for 'pkg errors' with the Forum Search ;)
#14
Quote from: Xaver on October 01, 2026, 02:57:32 PMOPNsense:

  • Outbound NAT set to Hybrid
  • Static Port enabled in the Outbound NAT rule for the Grandstream's fixed IP address
  • Normalization disabled for the Grandstream's IP address on both the LAN and PPPoE interfaces, so that the QoS Layer 3 packet markings are not removed
Don't you need to do some Port Forwards for VoIP too ?!

The last time I was messing around with VoIP was around 15 years ago, so I don't remember all the rules exactly :)
#15
26.7 Series / Re: Opnsense 26.7.5 hangs at boot
October 01, 2026, 02:06:43 PM
Quote from: QuisaZaderak on October 01, 2026, 08:54:25 AMSMART is status OK (from within BMC/UEFI).
Please simply boot a Linux or *BSD Live ISO from your favorite USB Stick and use 'smartctl -a /dev/<whatever>' to see the full S.M.A.R.T. output and post it here so we can double check for you before you reinstall :)