Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - JohnSchnee

#1
26.7 Series / 26.7 Issues on Hyper-V
July 27, 2026, 12:01:34 PM
Hi there,

I found some additional information regarding the Hyper-V Issues.

I've tried to install OPNSense on Hyper-V on a EPYC 3151 based plattform.

The boot failes with kernel panic, unless I go and enable Safe-Mode in the Boot Option.

This however, hurts performance alot and I can see Core 0 fully saturated on the Hyper-V Host.

What is strange, when I click in the VM-Window of Hyper-V to see the Display of the VM, it may crash both the VM and the Host. (DPC_Watchdog Bugcheck)

If i don't touch the Hyper-V Window, OPNSense boots and the Web-Interface comes online (in safemode).

I've tested with some plattforms and I can confirm working 26.7 appliances on Hyper-V with:

- AMD Ryzen 3 2200G & 3200G
- AMD Ryzen 5 5600G & Ryzen 9 5950X
- Intel Celeron J4105
- Intel Core i7-7700

and not working with

- EPYC 3151 SoC (safemode only)
- Ryzen 9 3800X (reported by monviech)

What wonders me - what does safemode to the OPNSense overall functionalities?

Does it affect any security critical functions or would it be safe to run an OPNSense in SafeMode, when there is no other option?

I tried to research in this topic, but was unable to find anything about Safe-Mode.

If I find the time, I'll try a physical installation on the EPYC Platform, to see if the error persists without Hyper-V as Hypervisor.

Maybe this information helps to encircle the problem.

Best regards
#2
26.7 Series / Re: Services widget
July 27, 2026, 11:32:02 AM
Hi there,

after seeing the new widget for some day, I now just removed it because I'm just getting angry seeing this (anger issues..)

I really appreciate the work from the folks making this project possible.

But what I don't understand, why there is no chance for the user to choose from both versions.

There was obviously a working code for the old widget - and nearly all widgets have that little Pen-Symbol - why not add the pen and let users choose?

This would simply end all discussions, and allthough I know this a bit (but I think not too much) extra work.

Style "Classic" for the old one and "Compact" for the new one.

I also don't really understand where this goes? Should I expect all UI Elements to be cut down to the basic, even without headline?

For me, OPN-Sense had the most beautiful/functional Mix of the Interface for a long time.

Now I'm desperate, because if this "compacting" goes further, I know my experience is new anger with every update.

Most people have huge screens, and I really don't see functional benefit in compacting things, and IMO, it looks less modern, more like a bare HTML.

I would even make a 200€ donation to bring this widget back or implement the "Style-Pen-Function"!

Best regards
#3
Hi,

I don't know if anyone else is experiencing this, but suddenly without changes some elements of the UI are broken.

The Firewall Widget

Now only shows "IPv6 ICMP Requirements.." and seems to be frozen. Restarting the Web-Gui does not fix it.

I can see Firewall Hits on other Rules that have logging enabled.

Disk-Usage Widget

Sometimes has a wrong sizing, reloading the page does fix this for a short time.

Interface Widget

In the smallest widget size, the link speeds are not shown - however it now sometimes shows the link speed regardless of the size.

I've also tested different themes to ensure this is not a rebellion-only issue.

Not a priority-topic but I thought, worth to report.

Best regards!
#4
Hi,

I don't want to argue, but from what I experienced with the Docks and the USB Ethernet, I would not say a 100% that its not the driver.

As I mentioned, the docks needed a full powercycle to revocer the LAN-Port. It went away with new drivers. I never had this kind of issue with PCIe Cards.

It may be worth to name your specific card vendor, to sort out that this specific vendor has some quality issues at a PCB Level.

Best example for this is with the Broadcom 5720 Card - look at the Parts Count of both PCBs, one is as double as expensive with the same Chipset as the other.

If the cheapo card had problems, then it would be likely due to omitting components and not the BCM-Chip beeing just a bad Chip.
#5
Quote from: meyergru on July 16, 2026, 01:18:21 PMWhen you read the thread you will find that it is an incompatibility of Realtek 8126 / 8127 devices with X570 chipsets that cannot be healed by drivers, since the device is not even detected. It is a hardware incompatibility.

I read *you* assuming it is an Hardware issue, but from the problems you describe, its a 100% not general hardware compability issue.

On your own article on Computerbase you self write "Daraus ergab sich der Verdacht, dass die über den X570-Chipsatz angebundenen PCIe-4.0-Slots instabil arbeiten."

So you were now talking about unstable PCIe Lanes on your Board, so tell me, is it a card issue, a board issue or even a specific Problem with your board?

I just don't understand single users detecting something, and assume this problem affects the whole Chipset, while only a single Board was used for testing.

It's just not representative, to test one board with one/two cards, and then warn about the card when it's a chipset Issue, or even just one bad PCB...

Best example is my friend with a RTL8127 on a Gigabyte X570 Board without any issues for 3 months now. (Yuanley Card from Amazon)

Another factor: With PCIe 4.0 bad routing of the PCIe traces on the card or on the mainboad or even bad EMI can cause training issues.

But as I said I have various evidence that a missing card at boot time can but not always be caused by bad drivers.

My personal and not verified theory is, that the OS failes to communicate power states, leaving the IC in a soft-bricked state.

So yes, I read the thread and I appreciate the time you put in it, but no, I'm not convinced it's a general X570 or hardware issue.

Quote from: nero355 on July 16, 2026, 02:35:34 PMYou are talking about Windows but the most issues you will see on this Forum are on the OPNsense/FreeBSD side so I guess most people don't use them for their Clients or don't use Windows at all ;)

In this thread it was about Windows.. And drivers are somehow important regardless of the OS.

All I wanted to point out that include the network drivers in the private patch cycles or troubleshooting, can be worth, but it will not fix every problem.

Best regards!
#6
Hi,

are you sure this was changed in the last update?

I'm using rebellion for a long time, and thats like its normal design, which I really appreciate.

I'm working at night alot, and all the colours are somehow darker than in other themes.
#7
Hi,

Input:
sysctl hw.vmbus.tlb_hcall

Output:
hw.vmbus.tlb_hcall: 1

If you need anything more, let me know.

Regards
#8
Hi there,

I know this Thread is very old, but I just want to add that it is very worth to periodically check the Realtek Website and download the newest driver.

For Windows 11, the driver architecture changed from NDIS to NETCX, and I had no issues with the new NETCX Drivers so far.

Realtek is known for various issues with older drivers, but indeed some problems got fixed with the newer ones:

- 2.5G USB NIC only did 1.2G in iPerf because of outdated drivers from Windows (Installed 2016 Drivers in 2023...)
- Issues with NICs in Dockingstations (e.g. Dell WD 19, all Docks based on USB GBE Adapter) that disappeared after Standby and needed Powercycles
- Dropouts with PCIe NICS, when doing iSCSI and High IO Load

Thats why in our environment, we push the newest Realtek Drivers with Intune every 3 months.

But yeah overall, Realtek NICs are not great, but also not terrible.

In my opinion, their biggest issue is interrupt handling, when doing iPerf, watch Core 0 in the Task-Manager getting overwhelmed while the others idle.

There is not really a good core scaling by the driver like Intel and Broadcom based Cards. Features like VMQ, RDMA etc. are non-existent.

For Desktop and SMB Workloads with modern CPUs this works out but for serious workloads and protocols like iSCSI, I would never use Realtek.
#9
Hi Cedrik,

I've tested it with both mine and your settings and the VM didn't crash.

I booted and logged in with "Installer" - so I expect the crash should have occured before this point?

Curiously I wasn't able to enable Secure-Boot for this VM, but I know I had a long fight to get this working, so I better don't touch my current config. :D

I'm using Unbound cascaded with the AdGuard-Plugin as DNS, where AD-Guard is my Upstream and Unbound the "internal" DNS.

I've added a Screenshot where you can see the Kernel Version as evidence of a successfull boot with 12 vCores

Best regards
#10
Quote from: Melroy vd Berg on July 16, 2026, 02:23:33 AMI think I will just reinstall from scratch now. How can I plugin the installer USB at the same time as the second USB (with my backup config), while the DEC3800 only has 1 USB port on the front here. 

Could a simple USB-HUB solve your problem? This would limit the Install-Speed a little (with 2.0 Hub) but as temporary solution, I think that should work out.
#11
Hi there,

thank you so much for the quick answers and the feedback.

My Hyper-V Config is:

- Based on Windows 11 25H2, latest Jul Update installed
- VM-Config Version is 12.0
- Gen-2 VM with TPM, Secure-Boot & Shielded VM enabled
- 12 vCPUs and 16 GB RAM configured

Physical Hardware: Ryzen 5 5600G, A520 Chipset, 64 GB RAM, BCM5720-2P Ethernet + Onboard RTL 8116 Ethernet

No Hyper-V based Snapshots, only PCIe based NICs (if that can make a difference).

I've also added a Screenshot of the "Integration Services TAB".

The theme I'm using is Rebellion, and I'm afraid to say, it's more about the layout of the new Widget and how it blends in with the other UI Elements.

Maybe it would be a compromise, if both (old and new) have their existence and the new one is the "Compact" Version.

But yeah, life and maybe a firewall isn't a "Wish-Concert", so I could survive with the new one.

Just my honest feedback.

Regards

#12
26.7 Series / Feedback on new Widgets since 26.7
July 16, 2026, 04:37:08 AM
Hi there,

today I was updating from 26.1.11 to 26.7.

As always the update went smooth, thanks for the great work guys. (Even on Hyper-V, I don't had kernel Panics)

However, the new Service Widget looks not great and does not blend in well with the other GUI Elements. (Black writing on green background)

Thats of course only my personal opinion. Maybe others find the new design more helpful, the advantage might be that a failed service is more visible.

Is there any possiblity to let users choose from the two designs. I was just super satisfied with the old one.

I've added you a screenshot of an old test-build with my typical Web-Interface-Design and a small Picture how it looks with the new design.

Keep the good work up and best regards!