Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - nero355

#1
Quote from: Patrick M. Hausen on February 03, 2026, 05:09:35 PMand I care for it with all my heart.
Just not soo much to get a burnout...

Quote from: Greg_E on February 03, 2026, 05:55:20 PMYou should add in mindlessly paste from AI.
Just don't use those "Machine Learning Chatbots" at all !!! :(



The other day a guy Copy->Pasted something from one while I was asking something about HIS project... d0h!
#2
Quote from: opnsense-user123 on February 03, 2026, 06:10:42 PMI have three LANs so I thought I'd try one or two before changing the final one that has many more hosts on it.
That was unsuccessful because, even though in ISC DHCPv4 config I unchecked the box for those two LANs, ISC seemed to still be bound to port 67 on those LANs.

So I had to do all three at once and make sure ISC was really stopped.
That is as expected.

QuoteThen I noticed in the Kea error logs that the "Control Agent" is deprecated. So though I at first checked the box to turn it on in that page, I later went back and turned it off.
Only needed for HA setups! ;)

QuoteEarly going, but so far so good. Hoping for a smooth update to v26.
+1 :)
#3
Quote from: jim1985 on February 03, 2026, 12:05:50 PMFrom what I understand, it is PPPoE that can be the problem & it requires a pretty decent single core clock speed as the PPPoE implementation in FreeBSD is not multithreaded yet.
It is multi-threaded just not multi-core capable as in 'Use the processing power of more than 1 CPU Core' ;)

So it will never go further than 4 x 25% of each Core at best in case of my N5150 for example !!



Anyways...



Just get a nice N100 "NUC" with Intel NICs and be happy! :)
#4
Quote from: waxhead on February 03, 2026, 07:07:00 PMa favorites menu
Was thinking about requesting something like that too for a time now :)

I would then add the stuff I like to check often like DHCP Leases/ARP Cache and ofcourse everything related to my network that I am actually using at the moment.

You could also have a Group in the Favorites section where each group would be all settings related to one specific Network/VLAN/Subnet or the WAN for example.

#SooManyIdeas!!!
#5
Quote from: OPNenthu on February 01, 2026, 09:13:15 PMI haven't tried the professional Netgear switches and I do expect better of them, but I had a terrible experience with a cheaper Netgear smart switch and had to return it.

It was leaking RAs across the VLANs.
Do you happen to remember the exact model and revision ?


/EDIT :
Quote from: OPNenthu on February 02, 2026, 08:30:37 PMGS308EP with firmware 1.0.1.4

I was still very green at the time but I don't think this was user error.  There was no working combination to prevent the RA spillage.
Quote from: OPNenthu on February 02, 2026, 08:49:05 PMHa!  Looks like they fixed it some months after:

https://kb.netgear.com/000066737/GS308EP-Firmware-Version-2-0-0-5

:-)
Thank you! :)
#6
Quote from: coffeecup25 on February 01, 2026, 10:46:44 PMSorry you had so many problems with it.
I am actually saying I did not ;)

QuoteThe import / export feature with KEA is amazing. It's the best part of it IMO.
Totally agree!
#7
Quote from: nelox on February 02, 2026, 02:08:27 AMCisco/CCNA best practices do not say to "skip VLAN 0-5."
It was either 0-4 or 0-5 when I took my CCNA somewhere in 2013/2014 so maybe things have changed by now... dunno... :)
#8
Quote from: darkencraft on February 01, 2026, 04:44:10 PM
Quote- Did you setup new Firewall Rules similar to those that the LAN network has by Default ?
No. I did not add any additional firewall rules.

I intentionally kept the firewall rules in their out-of-box state so that any custom rules would not introduce variables or interfere when asking for community support.
I am not sure if the rules that the default LAN Interface has after a fresh install are also applied when you create the new "Bridged LAN Interface" so to speak since it basically is a NEW Interface like any other newly created interface...

You need to have the firewall rules that allow IPv4 and IPv6 communication to other networks + internet access and ofcourse :
Quote
Quote- DHCP settings are also adjusted ?
for LAN ipv4 config type was static ipv4 with dhcp server for LAN interface. not sure if this answers the question, or are you referring to something else?
DHCPv4 at least for that new "Bridged LAN Interface" in order to get IPv4 addresses.

But you told us already that regular wired LAN Clients have a fully working connection on the "Bridged LAN Interface" so I am guessing you have applied these settings already ?!
#9
** BUMP **

I am really curious if this is the case or not :

I really liked the ISC DHCP option and hope the KEA DHCP option does the same :)
#10
Quote from: allenlook on February 01, 2026, 06:15:26 PMI thought the check mark was odd as well, and that it indicated the CSV had been parsed successfully, but I was looking for a "Go" or arrow or "Submit" button, but after a few seconds I clicked on the check mark and Bob was suddenly my uncle.
+1 when moving from ISC DHCP to KEA DHCP and Importing/Exporting the Static DHCP Mappings but it did not took me a hour to figure it out :)
#11
Quote from: Patrick M. Hausen on February 01, 2026, 06:12:42 PMUnplug and replug LAN or reboot the switch it's connected to - UI access gone.
Hmm... never tested that...

The same goes for OpenSSH Server ?!

Luckily the device has a regular Power On/Off button as a last resort so a clean "reboot" can be performed...
#12
See : https://forum.opnsense.org/index.php?topic=50567.msg258716#msg258716

TL;DR : It's work in progress and there will be a lot of improvements to avoid misunderstandings :)
#13
Quote from: meyergru on February 01, 2026, 05:44:05 PMBecause it does not work for interfaces that are created on-the-fly or change their IPs if the BIND is not done to the anonymous socket 0.0.0.0, which denotes "all" interfaces, including such that do not exist (yet).

Just try to use a VPN interface: It will seem to work, but on the next reboot, the service fails because it cannot bind to a non-existing interface.

So, the usual way is to bind services to "all" interfaces and block access using firewall rules.
But if I understand you correctly then there is no issue in binding it on the Default LAN Interface since you are probably never ever going to change anything there anyway ?!

And if you need access from a VPN or another network you can use firewall rules for those :)
#14
Quote from: RamSense on February 01, 2026, 02:55:20 PMIn OPNSense I had, and still have, System -> Settings :  Listen Interfaces ALL (recommended).

Looks like I have to change this to LAN and Wireguard only(?) although it is not recommended?
I still don't understand why this is not recommended ?!

IMHO it's totally logical to bind things like the webGUI and SSH to just the Management VLAN network a.k.a. the default LAN Interface in the case of OPNsense :)
#15
25.7, 25.10 Series / Re: Seting up Vlan
February 01, 2026, 04:59:57 PM
Quote from: JustSecure on February 01, 2026, 04:05:25 PMEven found a old IPcam, which when booted screams something in chinese. think its hacked, now it got time to check it.
LOL! ^_^

Good luck & Have FUN !!! ;)