Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - slackadelic

#1
Being virtualized, did you turn off all the hardware checksum offloading in OPNsense?
#2
Quote from: slackadelic on November 26, 2024, 04:49:29 PM
This is an Intel nick that's been running great for quite a few years.  Didn't have this particular issue back in the summer and folks are correct, about the last update is when I started noticing the issue.
I'm continuing to look at logs when it happens to see if I can sort out what is going on, but so far nothing stands out.

After some more observations and testing, this issue that is discussed does not seem to apply to my Intel setup.  I'm pretty sure my ISP did something; not sure what but will keep an eye out if the issue persists.

So far, I'm stable. 
#3
This is an Intel nick that's been running great for quite a few years.  Didn't have this particular issue back in the summer and folks are correct, about the last update is when I started noticing the issue.
I'm continuing to look at logs when it happens to see if I can sort out what is going on, but so far nothing stands out.

#4
Ok maybe I'm not losing my mind.

I've seen the same errors, but can't remember when it started.  I tought at first it was my ISP dropping.

What I noticed is no more arp, no route... just out of the blue.   I have to down the interface and bring it back up, and it's fine.

Reboot of the firewall fixes it as well, and a power cycle of the ONT fixes it.  I don't think your card is going bad... I think something odd is definitely going on.
#5
Quote from: JetSerge on February 21, 2024, 05:34:44 PM
Disabling Allow PCP/NAT-PMP Port Mapping setting doesn't help. I can still see duplicate entries and the client reads them incorrectly.

Confirmed.  I thought at first it was working, but nah, back to a bunch of duplicate entries.
#6
General Discussion / Re: Unbound DNS not working anymore
February 19, 2024, 10:46:38 PM
Reporting -> Settings

Under "Unbound DNS reporting"

"Reset DNS Data"

I had to do something similar.
#7
Quote from: AhnHEL on February 19, 2024, 05:32:02 AM
I'm seeing this too.  Do you happen to have NAT-PMP checked as well in your UPnP settings?

I did have that turned on.   I've disabled it for now, not sure it would matter, but here's hoping!
#8
24.1, 24.4 Legacy Series / Re: KEA DHCP DNS search suffix
February 17, 2024, 09:17:42 AM
Quote from: Patrick M. Hausen on February 16, 2024, 01:28:22 PM
It is not the job of the recursive DNS server to append search domains. The resolver library on the client does that.

Oh I know, however it appears KEA doesn't quite use the default system one as ISC did.  Most likely just some missing options right now.  Not a showstopper, just a minor annoyance. :)
#9
24.1, 24.4 Legacy Series / Re: KEA DHCP DNS search suffix
February 16, 2024, 07:54:30 AM
Quote from: mimugmail on February 15, 2024, 10:59:10 AM
System : Settings : General

I set this on my install, but still having issues pinging just by host name internally, unless I'm missing something else.
#10
After reading this I check and I'm seeing the same growing list happening.  Not sure it's causing any issues, but it's concerning for sure.
#11
23.7 Legacy Series / Re: Local Tag
October 05, 2023, 05:26:41 PM
I have a rule that contains IPs, Aliases, etc. for internal machines that I do not want to have specific internet access when a VPN tunnel goes down.

I tag those as "BLOCKINET" and then in my WAN OUTBOUND Rules I have a match set for BLOCKINET and anything with that tag set and matches, I set it to 'block' so they cannot route out the WAN interface if the VPN tunnel goes down.
#12
Quote from: Maurice on September 02, 2023, 11:47:27 AM
Quote from: FarmView on August 31, 2023, 05:29:46 AM
release then renew WAN

Is that because your modem assigns a private address if it has no upstream connection? Cable modems typically do that (192.168.100.1 is their standardized IPv4 address).

That's exactly what the "Reject Leases From" feature is for (in the WAN interface's DHCP client configuration).

Cheers
Maurice

This is exactly what my modem does, so I set it to reject those leases.  Works like a charm until the cable modem is back up and functioning.
#13
You're welcome!
#14
Most likely what is happening is when you enable wireguard your Local endpoint config in OPNsense is overwriting the default routes.

You can try going into the Local endpoint config and select "Disable Routes"

That should stop it from adding it's own routes into the table.
#15
General Discussion / Re: voip
August 23, 2023, 02:31:41 PM
Your question is extremely broad and vague at the same time.

What benefits are you looking for?

If you took on this project, you should be able to give us a bit more detail of what YOU'RE looking for in a firewall and your plans for the implementation.