Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - Warbreaker

#1
26.7 Series / Re: os-upnp plugin not working?
July 26, 2026, 02:48:34 PM
Quote from: nero355 on July 23, 2026, 04:02:12 PM
Quote from: Warbreaker on July 22, 2026, 07:43:52 PMIMHO you found a bug, because why would you need both of them when uPnP does more than a Source NAT Rule with Strict-port Enabled does : It completely opens the port like a Port Forward a.k.a. Destination NAT Rule would :)

I'm sort of new to OPNSense, I started using OPNSense somewhere around 26.1.x, in my new installation back then I migrated to the new rules set because of a message I read that legacy would go away, so maybe the bug I found was with the new rules set?
Are you talking about Firewall Rules or NAT Rules ?!

IMHO the migration from Firewall Rules (Legacy) to Firewall Rules [New] that was more or less the thing to do before upgrading from 26.1.x to 26.7.x to avoid issues and should not have any affect to this whole story.

However the migration from Outbound NAT Rules to Source NAT Rules that's now a thing during the 26.7.x Release and should IMHO be done before the upgrade to 27.1.x in January 2027 could indeed have some kind of bug related to Strict-port since it was added a bit later after the whole new Source NAT section was added to 26.1.x :)

Sorry I missed your question, let me list in order the things I did in 26.1:
  • I migrated from legacy to the new firewall rules set when I installed 26.1
  • When I installed uPnP I converted the NAT mode from automatic to hybrid
  • I did not do anything related to firewall or NAT when I migrated to 26.7, no conversion (it was already converted), but my destination NAT firewall rules seem to work, I have a DNS and time server redirect that are still working from 26.1, but they were created after I migrated to the new firewall rules set
  • Once I moved to 26.7 a bit later I added the source NAT rule so uPnP would work again so now everything is working, only the "?" source IP bug on the uPnP when listing the current mappings
#2
26.7 Series / Re: OPNsense 26.7.r2_3 Disk Widget
July 24, 2026, 11:45:03 AM
It may be a numbers approximation issue, change the size of your browser for a second, then maximize it back, it then fixes the widget (done with Brave in my case)
#3
26.7 Series / Re: os-upnp plugin not working?
July 22, 2026, 07:43:52 PM
Quote from: nero355 on July 22, 2026, 06:44:07 PMIMHO you found a bug, because why would you need both of them when uPnP does more than a Source NAT Rule with Strict-port Enabled does : It completely opens the port like a Port Forward a.k.a. Destination NAT Rule would :)

I'm sort of new to OPNSense, I started using OPNSense somewhere around 26.1.x, in my new installation back then I migrated to the new rules set because of a message I read that legacy would go away, so maybe the bug I found was with the new rules set? either way I can't recall having to do anything other than the Source NAT change from Automatic to Hybrid.
#4
26.7 Series / Re: os-upnp plugin not working?
July 22, 2026, 10:12:52 AM
Quote from: bamf on July 21, 2026, 10:52:31 PM
Quote from: Warbreaker on July 20, 2026, 08:00:36 PMI finally got it working.

I added this "Source NAT" rule:
https://www.pasteboard.co/lTHlqpZ_SWPY.png

Is this rule required now for getting UPnP IGD & PCP back to work? Why? I am facing the same issue. Active mappings with IP address ?.

It seems that way now, I didn't need it on 26.1 but the reason of why it was working is unknown to me, but now you do need it with 26.7
#5
26.7 Series / Re: os-upnp plugin not working?
July 20, 2026, 08:00:36 PM
I finally got it working.

I added this "Source NAT" rule:
https://www.pasteboard.co/lTHlqpZ_SWPY.png

And I guess combined with this UPnP rule it should only bind non privileged ports, it should be good:
https://www.pasteboard.co/rmGUkErct6gE.png

Note: I can't make images work on this forum for some reason.
#6
26.7 Series / Re: os-upnp plugin not working?
July 20, 2026, 05:39:41 PM
Quote from: Chris123NT on July 20, 2026, 04:20:12 PMand you set Static port right?

What is this last bit exactly? Maybe is something silly I haven't done or did before but need to redo for 26.7
#7
I can confirm that, for my CWWK mini PC N150 only 6 degrees down but maybe is because the N150 is quite heat efficient already.
Seen from average 62 down to 56, whatever it is, I am happy with it, extends the life of mini PCs, those are  difficult to select for me :)
#8
26.7 Series / Re: os-upnp plugin not working?
July 20, 2026, 10:26:50 AM
Quote from: Chris123NT on July 20, 2026, 01:31:11 AMI migrated that from the old Outbound NAT section on 26.1 before upgrading and things seem to be operating correctly, despite the visual glitch in the UPNP service page.

In the past when I installed OPNSense back in 26.1 I migrated to the new firewall rules.

I had my source NAT configured as Hybrid in 26.1 and it was working for 26.1, in 26.7 it is in Hybrid mode too, besides the visual glitch, was there something I needed to do?

My understanding is that I had already made the modifications required, but maybe I missed something?

My test subject is my son's Destiny 2 and that stopped working for 26.7, I mean you can NAT but you cannot map ports properly, they show as mapped but no IP address and Destiny complains about it so it is not working as it was in 26.1
#9
26.7 Series / Re: os-upnp plugin not working?
July 19, 2026, 12:41:58 PM
Quote from: poeBaer on July 18, 2026, 11:38:46 PMConfirming issues immediately after an upgrade to 26.7 as well

It seems to be partially working though, as some entries/mappings are being made. And now the "IP address" column is just showing "?" for all entries, instead of the local IP as in previous versions. Not sure if that could help point the finger at the actual issue

This is exactly what's happening to me, the IP address column is just ? and while it attempts to add entries to the firewall, uPnP is failing to do so.

I already had migrated my old firewall rules in 26.1 to the new rules set and all of my other rules are working as expected, the firewall seems fine, including my port 53 and 123 interception for the firewall own services.

So for now I just disabled the service until it is confirmed is fixed, but glad it wasn't just a me issue ;-)
#10
26.7 Series / Re: os-upnp plugin not working?
July 16, 2026, 04:16:09 PM
I will probably do that at some point, but thought on reporting it as well, either something is broken or the stronger rules on 26.7 is making the old plugin not work at all, for security reasons of course I have only one ACL on my UPnP plugin to just allow non privileged ports to be bound.

It would be interesting to know why it isn't working anymore.
#11
26.7 Series / os-upnp plugin not working?
July 16, 2026, 03:12:47 PM
I moved to 26.7, my old firewall rules in 26.1 was already moved to the new rules set format so I imagine that's good on 26.7
But when I look at UPnP mappings I see this:
IP address Port External port Protocol Remote IP Remote port Added via / description
? 22419 22419 UDP any any UPnP IGD / DemonwarePortMapping

No IP address and it seems to not be working (My son is my tester with Destiny 2 complaining about strict NAT), it was working on 26.1
#12
The plugin has been updated for 26.7, thanks for the effort ;-)
#13
Quote from: franco on July 15, 2026, 06:22:31 PM-f deletes the configuration. I really wouldn't recommend it.

I forgot to edit it, I didn't use the -f at the end, re-installed the plugins and they got their configuration back, running like before without AdGuard for the moment until that's fixed for 26.7

Thanks all for the help, even if it didn't directly solved the issue it let me to ask AI the right questions :)
#14
Solved the problem with this:

fetch https://raw.githubusercontent.com/opnsense/update/master/src/bootstrap/opnsense-bootstrap.sh.in
sh ./opnsense-bootstrap.sh.in -r 26.7
#15
How do I do this clean pkg?