Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - Plethodon

#1
26.7 Series / Re: Confused by 26.7 upgrade
September 06, 2026, 01:41:32 AM
Quote from: franco on September 04, 2026, 07:09:26 AMSome people are not aware, but it bears repeating:

In the context of the BSD licenses, the "as is" provision means that the software is provided without warranties, and the authors generally disclaim liability for issues, failures, or damages resulting from its use, including operational errors.

We try our best to describe the changes. The code is open so it also documents the changes in a straightforward (but still very technical) way. If you want more you may want to consider participating in this process: the documentation is open and the changelogs are open too.


Cheers,
Franco

Seems I unintentionally stirred up a lot of feelings about the upgrade.

First, it's safe to say that I failed to read the upgrade notes prior to upgrading. That's on me. And, in an odd way, it's a testament to the previous upgrades, which were so smooth that I never felt compelled to read the notes. That was my mistake.

Second, I can't speak to whether the release notes would have adequately prepared me for the big change, since I didn't read them. It sounds like some people were fine with the communication and some were not. In the future, I'll examine the release notes closely.

Thanks to the devs for all their work.
#2
26.7 Series / Re: Confused by 26.7 upgrade
September 01, 2026, 01:57:23 AM
Quote from: Patrick M. Hausen on August 31, 2026, 12:36:24 AMThe rule UI was replaced, entirely. You need to migrate your rules to the new system. Use the migration assistant. Detailed instructions are on the migration assistant UI page. Just do as is documented there.

You might need to install the legacy rule plugin to finally delete all the legacy rules.

This was announced months ago for 26.1 - you could have gone through the migration in 26.1 already to be prepared for 26.7.

Patrick, thank you for this clarity. Clearly I'm not attending to changes closely enough. Is there a recommended site to follow (like RSS) or something similar so I can keep up to date?
#3
26.7 Series / Confused by 26.7 upgrade
August 31, 2026, 12:29:18 AM
After I upgraded to 26.7 everything worked, so I thought I was done.  But when I went to enable some rules that I generally keep disabled, the rules weren't even there. Then I noticed that the interface didn't even let me select a rule (no checkboxes on the left side). I'm starting to think that I missed something big about this upgrade.

Then I noticed a Migration assistant under Firewall. Can anyone direct me to what I should do about this situation? I've read some posts about the Migration assistant, but I'm not clear whether that even applies to my situation. Thanks.
#4
When I create a new template in Firewall > Log Files > Live View, for example to view logs from a particular interface, I often find that when I switch to the new template I get no records.  But if I manually enter the same criteria I get plenty of records.

Also, when I recently created a template that had an interface criteria and an address criteria, when I select that template the presented criteria shows something like "iface is lan" and "address is lan" (rather than something like "iface is lan" and "address is 192.168.1.1).  Uh, that's not even possible. And I get no records. Any idea what's up? Thanks.
#5
General Discussion / Re: Log templates often not working
November 09, 2025, 09:38:48 PM
Looks like I should have posted this in the 25.7 forum. I'll move it there.
#6
General Discussion / Re: Log templates often not working
November 08, 2025, 07:11:38 PM
I should have mentioned that this is for Firewall Logs in Liveview.
#7
General Discussion / Log templates often not working
November 08, 2025, 07:09:33 PM
When I create a new template, for example to view logs from a particular interface, I often find that if I switch to the new template that I get no records.  But if I manually enter the same criteria I get plenty of records.

Also, when I recently created a template that had an interface criterion and an address criterion, when I select that template the presented criteria shows something like "iface is lan" and "address is lan".  Uh, that's not even possible. And I get no records. Any idea what's up?
#8
Success!  Yeah, clearly you have to have different instances on different ports, and in retrospect that makes perfect sense.  Thanks for your help.

So, do you know if I set up another ProtonVPN tunnel I can just change the port, or am I constrained by the port Proton indicates?
#9
meyergru, that's a reasonable guess. They only thing in common with the two instances and peers is the port, 51820. But I don't see why the use of that standard port would affect the ability to add a static route on interface wg2. I guess it's possible that the error regarding adding a static route on interface wg2 is a red herring, but I don't see any other errors.

I would love to test different things, but I don't even know where to start testing.
#10
Hello,

Some time ago I successfully set up the WireGuard Road Warrior Setup (https://docs.opnsense.org/manual/how-tos/wireguard-client.html).
Now recently I configured a wireguard connection to ProtonVPN from my gateway using
this:
WireGuard ProtonVPN Road Warrior Setup (https://docs.opnsense.org/manual/how-tos/wireguard-client-proton.html)
and this:
WireGuard Selective Routing to External VPN Endpoint (https://docs.opnsense.org/manual/how-tos/wireguard-selective-routing.html)

Initially I could not get the ProtonVPN connection to work, but learned that when I disable the Road Warrior instance the ProtonVPN connection works.

With the Road Warrior instance on, and I turned on the ProtonVPN instance, I get this error:
/usr/local/opnsense/scripts/wireguard/wg-service-control.php: The command '/sbin/route -q -n add '-4' '10.2.0.1' -iface 'wg2'' returned exit code '1', the output was ''

My conclusion is basically that wireguard's attempt at adding a new route to interface wg2 failed.  I have no idea how to fix this. 

Does anyone understand why there is a conflict between the Road Warrior setup and the ProtonVPN setup?

Thanks
#11
This was not an OPNsense issue. The ISP had to release the DHCP lease.
#12
Thank you.

I figured as much, so it's good to have confirmation.
#13
I used to manage pfSense firewalls at my former job, but decided to try OPNsense for my home gateway. I received a Protectli with OPNsense 24.7 installed. I did some minor configuration to establish a couple of wifi networks and familiarize myself with the interface. I like it, but I cannot get the traffic to route from LAN to WAN. Should I expect that it would just work out of the box if WAN gets an IP from my ISP?

I know this seems very basic, but I cannot figure out how to get traffic to exit the WAN. Any help would be greatly appreciated.