Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - sopex

#1
Was it working before? 26.1.9? Or we don't know?
#2
You probably should use Traffic Shaper:
https://docs.opnsense.org/manual/shaping.html#introduction

The settings you are changing don't necessarily do what you would expect:
https://docs.opnsense.org/manual/firewall.html#settings (Choose priority)

#3
Have you gone to your WAN interface settings on OPNsense and disabled "Block private networks" and "Block bogon networks"? I would start there.

You can also try deleting and re-adding the WAN interface.
#4
You can always just buy a license if you plan to use it longish term. No? At around 4 months, you break even.

But I believe it as the automatic table mentions $0.05/hour + Azure infrastructure costs
#5
26.1, 26,4 Series / Re: CVE-2026-45257
June 16, 2026, 06:06:24 PM
Quote from: franco on June 16, 2026, 05:18:39 PMNo, these are not our CVEs.

I meant something along the lines of
"This business release is based on the OPNsense 26.1.9 community version with additional security and reliability improvements." because this person probably got a bit overwhelmed with all the improvements on the new version.

We are in a CVE apocalypse ofcourse no need to micromanage each security fix :)
#6
26.1, 26,4 Series / Re: CVE-2026-45257
June 16, 2026, 05:00:25 PM
Quote from: viragomann on June 16, 2026, 03:51:03 PMMay we expect a fix for the business edition as well?

The most recent release from today is based on 26.1.9 and there is no fix regarding this CVE mentioned on the page. So I guess, it might be still vulnerable.

Or should we go the manual path by setting the tunable?


It's fixed. Maybe there is a need for better visibility but business edition always gets security fixes.

This is the relevant mention:
o src: arbitrary file overwrite via the KTLS receive path[15]
#7
Quote from: wincent on June 16, 2026, 03:11:39 AMWe don't have much budget. I remember this 4600 cost around $15,000, and now the new 3790 costs around almost $20,000.
I plan to replace it with a spare HP DL388, but there's a problem. The HP server takes too long to boot up, and the self-test takes several minutes, which is quite a headache.

There is also a middle ground between spending $20,000 and wasting time and electricity with a DL388 just to run a firewall.

Official opnsense hardware :)

https://shop.opnsense.com/product/dec3940-opnsense-rack-security-appliance/
#8
26.1, 26,4 Series / Re: CVE-2026-45257
June 15, 2026, 03:07:24 PM
I also install nano, much better experience :) Editor wars 2.0
#9
26.1, 26,4 Series / Re: FreeBSD 15.1 available
June 14, 2026, 03:31:59 PM
And on July 29th its coming to OPNsense. If all goes well :)
#10
26.1, 26,4 Series / Re: ASN in alias.
June 13, 2026, 12:28:52 PM
Quote from: Nullman on June 13, 2026, 12:10:41 PMThat was not my question. I want to know if they are updated automatically, or i have to intervene?

If you add a cron job they are updated automatically every X amount of time.
Otherwise, they don't.

My bad, I just assumed the end goal was to do it automatically.
#11
26.1, 26,4 Series / Re: ASN in alias.
June 13, 2026, 12:04:13 PM
Go to cron jobs and add an "Update and reload firewall aliases" job every day or whenever you see fit.
#12
Quote from: cookiemonster on June 12, 2026, 11:39:59 PMIMHO running any system without swap is not a very good idea. If the system needs it for any reason, it is best for it to have it than not.

It's not a perfect science. In my limited experimentation, the chances of swap getting used and the whole system becoming sluggish are much higher than a 16GB+ system being starved of memory.
#13
Yes, let the defaults be. You don't need swap.
#14
Quote from: somanet on June 12, 2026, 09:55:39 AMHave set the range and lease time but its not picking the new leases its still using old configurations

You need to tell the local clients to renew their lease manually.

For Windows:
ipconfig /release
ipconfig /renew

But you need to do some research and use AI. Its great for these kinds of things.
#15
XXXX/ui/dnsmasq/settings#dhcpranges

Edit or create a new range, its one of the settings here