Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - cottec

#1
Quote from: OPNenthu on September 08, 2026, 07:58:10 PMBTW, you probably saw my note above about setting the date manually in FreeBSD the first time you boot after a battery change / CMOS reset.  Coreboot doesn't let you set the system time unfortunately so until you do it in the OS you'll have problems getting NTP to sync.  FYI.
I waited for a new battery to arrive but it's still dead, will send it to them tomorrow.
#2
Quote from: OPNenthu on September 07, 2026, 10:28:49 PMHi @cottec,

Not sure what's going on with yours specifically but the COM issue sounds familiar.  I have a newer production run of the V1410 now and these issues haven't come back.  I would reach out to Protectli support.

You might be able to get COM port responding again with a CMOS reset: https://kb.protectli.com/kb/cmos-reset/.  I remember this working for me.

Replace the battery first if you can, and make sure you are on the latest firmware.


as my emmc is dead and I'm barely within warranty I might still send it to them

did you try updating the NIC's firmware with the newer build?


Quote from: Nullman on September 08, 2026, 02:05:29 PM
Quote from: cottec on September 07, 2026, 11:17:39 AMCan a dead battery cause the whole system not to boot anymore?!

Yes. Not only on Protectli devices. Modern motherboards show no signs of life if the battery goes below 2.5V. You would think 2.5V is not that bad, but that 2.5V becomes 0.9V when under load. So yes. Replace your battery.
yeah will do that for sure, but I wasn't expecting such issues tbh. Seems to be a coreboot thing not to boot up at all with the battery empty

Still dont understand why that battery's dead after 2 years...
#3
Super weird behaviour on my side as well.

This morning one single client didnt get an IP Adress.
The Protectli 1410 OPsense leased an IP but the client connected to the Wifi AP using a local 169.254 adress

Tried to reboot the Protecli in OPsene WebGUI.

It never booted again...

COM not working either.



Took out the Bios Battery 0.2Volts


Can a dead battery cause the whole system not to boot anymore?!
#4
Quote from: cottec on May 08, 2026, 09:54:09 PMIch endlich mal wieder, sorry, bin derzeit im Umzugsstress und hatte die Probleme hinten angestellt...


Jetzt ist mir allerdings etwas aufgefallen, das seit dem Update gar nicht mehr geht:
Meine Kaffeemaschine kann Bezüge auf die Plattform visualizer.coffee hochladen bzw konnte.
Das geht seit dem Update wohl nicht mehr.
Die Software der Maschine hat ein kleines Plugin zum hochladen.
Wenn ich die Bezugsdaten per Browser direkt auf die Webseite von visualizer hochlade, dann geht das auch. Es scheint also ein Problem in der Art und Weise zu liegen, wie das Plugin kommuniziert.


Wenn ich statt opnsense Wifi einen Hotspot per Handy auf dem Android Tablet der Kaffeemaschine benutze funktioniert alles wunderbar, die Konfig auf dem Tablet scheint also okay.

Ich hab mal testweise Adguard abgeschaltet, ansonsten benutze ich ja nichts...
Hab mal den Traffic mitgeschnitten (siehe Anhang)

Da geht ja irgendwas schief... ist das ein MTU/MSS Problem?

kleines Update:
das eingesetze Tablet kann zwar IPv6 aber irgendwas läuft bei dem Upload Skript der App falsch.
IPv6 auf dem Interface deaktiviert und das Tablet läuft wunderbar...
Ich hab mal den Entwickler angeschrieben, ob er das fixen mag.
Falls nicht kann ich immer noch ein weiteres VLAN nur für die Kaffeemaschine ohne V6 erzeugen.

Klingt irgendwie total Verrückt, dass man sich bei Kaffeemaschinen um IPv6 Gedanken machen muss :D
#5
Hatte meine OPNsense jetzt 2 Monate offline während des Umzugs...
Habe da natürlich auch mein DSL und VoIP mit umgezogen.

Bin das Thema Firwall dann am Wochenende endlich mal angegangen und eigentlich lief alles sofort.
Dann einmal alles fröhlich auf die neueste Version geupdatet, endlich Firewall Regeln und NAT migriert und eigentlich läuft alles, bis auf das verfluchte VoIP.

Nach drölf Milliarden Stunden Troubleshooting mit der KI immer noch nicht weiter gekommen.

Bis ich mal auf die Idee gekommen bin das SIP Passwort in der Fritz Oberfläche neu einzutippen (ich hab das nie angefasst seit es lief!)

Ja und siehe da, die vielen Stunden hätte ich mir sparen können... o2 hat im Rahmen des Umzugs das SIP Passwort geupdated, nicht aber das des pppoe.

So kommt man natürlich gar nicht auf die Idee, dass auf einmal das Passwort anders ist, weil ja eben alles andere auch lief...



Also, nur als grundsätzlicher Hinweis, falls jemandem mal das gleiche passiert:
o2 ändert beim Umzug das SIP Passwort
#6
So, der Umzug ist dann endlich auch mal durch...

Gerade läuft erst mal alles notdürftig auf einer Fritzbox, aber nervt wenn man besser gewohnt ist :)

Quote from: fastboot on June 19, 2026, 04:50:10 PMDie eigentliche Frage des OP war für mich eher, wie er möglichst einfach von seiner alten Installation auf die neue Protectli migrieren kann.

Tatsächlich ist die Installation nicht sooo alt, ich habe nur noch nicht von die zwei Legacy Geschichten mit dem IPv6 und DHCP migriert, der Rest sollte okay sein...
#7
Quote from: trixter on June 16, 2026, 01:39:21 PMWenn Du irgendwas davor hängen hast (Router vom Provider)
nein nein, die opnsense übernimmmt die einwahl über ein gebrücktes Draytec Vigor 167

hast du nen Tipp wie ich möglichst simpel migriere für eine Basis-Funktion?
#8
Quote from: trixter on June 12, 2026, 09:04:49 AMDann zieh doch erst mal in Ruhe um, bevor Du noch eine Baustelle aufmachst..
Ja gut, ich könnte ja mit Snapshots immer wieder auf andere Stände zurückspringen. Muss halt lernen wie ich die Sachen migriere und bestenfalls kommt dann nix mehr :D
Ich muss vielleicht auch mal simpler anfangen und nur v4 checken, ob das auch schon Probleme hat.
Für mein Verständnis müsste doch da reichen, wenn ich unter Generel use V4 only oder wie das heißt aktiviere, oder?!
#9
Quote from: trixter on June 05, 2026, 09:18:56 AMlass mich raten, deine Netzwerkkarten kommen auch noch von Realtek?

Grundsätzlich gibt es zu wenige Infos von Dir, was du da gebaut hast.
Außerdem würde ich jede Legacy Einstellung hinterfragen, denn sonst fällst du beim nächsten Update auf die Nase, wenn aus legacy deprecated wird.
Ich habs mir mal in die Signatur geschrieben ;)

Sind Intel I226-V NICs


Ja ich bin da bei dir, ich werde die Migration dann auch bei Zeiten machen, ich weiß nur jetzt schon, dass mich das vermutlich wieder mehrere Stunden und viele graue Haare kostet, das ist mitten im Umzug immer schwierig unterzubringen :)
#10
Quote from: trixter on June 03, 2026, 10:55:04 AMbevor ich anfange zu meckern?
Sorry, wo hab ich denn gemeckert?

In den Release Notes lese ich das hier:
To accommodate the change away from ISC-DCHP defaults the "Track interface" IPv6 mode now has a sibling called "Identity Association" which does the same except it is not automatically starting ISC-DHCPv6 and Radvd router advertisements to allow better interoperability with Kea and Dnsmasq setups.
Dann bleibt doch die Frage, was schlecht am automatischen von ISC-DHCPv6 und RA wenn ich noch nicht auf Kea oder Dnsmasg migriert habe?

Nur weil es mit dem Update Legacy wurde sollte man doch meinen, dass es weiterhin funktioniert?
#11
Quote from: trixter on May 28, 2026, 08:08:14 PMVielleicht das Interface selbst mal aus dem Legacy-Mode holen?
Ist das denn so falsch?
Ich scheine ja per DHCP auf dem WAN Adressen zu kriegen...
Hätte eh keine Ahnung wie ich sonst v6 einrichte um ehrlich zu sein...
#12
Quote from: meyergru on May 23, 2026, 12:18:27 PMWindows hat da etliche Parameter
Sorry, wir sprechen hier von einem Android Tablet..

Und ich bin mir ziemlich sicher, dass das Problem eher durch das Update auf die 26.1 gekommen ist.
Vermutlich dann auch eher ne IPv6 Thematik...
#13
Quote from: meyergru on May 23, 2026, 11:18:14 AMist die MTU nicht die Ursache.
Scheint so... Hast du noch ne Idee wo ich forschen könnte?
Normalizing?
NIC Firmware update?
Ist eine Intel I226-V in version 2.13 meine ich
You cannot view this attachment.
#14
okay hab ich jetzt eingestellt mit WAN MTU 1400 und die anderen Interfaces MSS 1400


jetzt kriege ich bei mehr als 1344 ein "message too long"
ist das richtig so?
You cannot view this attachment.


hilft das hier?
und by the way: was sollte man eigentlich schwärzen und was nicht? :D
You cannot view this attachment.
#15
Quote from: nero355 on May 16, 2026, 03:58:48 PMDid you contact Protectli first and tried to get the update from them directly ?
If so : What did they say ?


https://kb.protectli.com/kb/how-to-update-intel-nic-nvm-firmware-on-protectli-vaults/
QuoteConclusion and Related Notes
You may be wondering how to perform similar firmware updates on other Intel NICs (specifically the Intel i226-V).

The challenge with the i226-V is that Intel does not publicly distribute the .bin NVM firmware images required by the Intel NVM Update Utility. The .bin files are required in order to update i226-V firmware, but they typically must be obtained directly from Intel, such as through Intel RDC or Intel DevZone, or provided under the appropriate terms.

We (Protectli) cannot directly redistribute those .bin files.

Stock firmware on Vault platforms that include the i226-V NIC is typically around NVM 2.17. We have successfully validated updates to NVM 2.27+.

We are currently investigating the proper and compliant way to provide updated firmware images (or tools) to customers.

In the meantime, this OPNsense community forum post contains useful real-world context and discussion that should get you in the right direction, but use at your own risk.