Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - Boxer

#1
Quote from: opnsense1 on July 19, 2026, 09:46:17 AM
Quote from: Boxer on July 19, 2026, 08:08:11 AMhttps://docs.opnsense.org/manual/dnsmasq.html#configuration-examples

Are `lan.internal` and 'guest.internal' standard variable names for lan traffic or is that something I have to setup separately or if I've never done anything with those names can I just ignore that part? I just want DNS resolution in Unbound and DHCP in Dnsmasq, that isn't necessary for that right?

You need to set up the query forwarding yes. So 'lan.internal' or just 'internal' works. Ignore the guest network if that's not something you need
#2
Glad it's working :)
#3
Leave the Domain box empty
#4
If you're using Cloudflare Malware blocking DNS then it's 1.1.1.2.
1.1.1.1 CN is cloudflare-dns.com
#5
Incorrect CN maybe? Show your Unbound DoT settings for Cloudflare
#7
General Discussion / Re: Trouble understanding VLANs
April 13, 2026, 11:26:10 PM
Post #5 https://community.tp-link.com/en/home/forum/topic/214828
Apparently it's a built-in mechanism that cannot be turned off
#8
General Discussion / Re: Trouble understanding VLANs
April 13, 2026, 10:03:56 PM
First, let me apologise. The Tapo AP's ping those servers (reddit, netflix etc) to check the connection is still up. So sorry about questioning that. I still think that's absurd if they're in AP Mode. But it is a ping only, there's no data telemetry. You can block those pings on opnsense but the AP will show a constant red light as if network is down, even when it's up.
#9
General Discussion / Re: Trouble understanding VLANs
April 12, 2026, 11:18:00 PM
The telemetry you talk about isn't originating from the AP itself but from the clients connected to that AP (laptop, phone, pc etc.), as already pointed out. If you want to limit such telemetry then you can use Unbound DNSBLs or Adguard Home plugin on the main OPNsense machine (things may break and you'll need to unbreak them if you're aggressive in your blocking). You have a lot of plans with regards to your network but I think it's best to start with the easy stuff. Understand what an AP does. It's just a bridge to your opnsense. Make sure it's in AP Mode and not Router Mode. Unbound/Adguard for telemetry blocking. These are things you can do right now before you get your managed switch. :)
#10
If it still doesn't work keep lowering your mss value until it does
#11
Interfaces>wan
#12
Try clamping your mss to 1492
#13
I had similar issues with Microsoft and it's the DNSmasq RA MTU that needs to be manually set. If you use radvd instead, the issue goes away. But setting the dnsmasq RA MTU to a workable value also fixes it. As does clamping the WAN MSS value
#14
In Reporting, Unbound shows a blocklist size from two days ago (it's updated daily). The logs show that the DNSBLs were updated but then Unbound auto restored the database after the last two updates. Maybe corruption or size issues? I don't know
#15
Yes I see the same thing. According to the Unbound logs the blocklist are updating but then a few hours later I see this in the log -

<Database auto restore from /var/cache/unbound.duckdb for cleanup reasons in 0.44 seconds>