OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • Profile of dave »
  • Show Posts »
  • Messages
  • Profile Info
    • Summary
    • Show Stats
    • Show Posts...
      • Messages
      • Topics
      • Attachments

Show Posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

  • Messages
  • Topics
  • Attachments

Messages - dave

Pages: [1] 2 3 ... 5
1
General Discussion / WAN IP in loopback
« on: November 03, 2024, 11:30:32 pm »
Sorry if this is a stupid question, but i've noticed my WAN's external IP addr is included as a route in the loopback address... is that to be expected?

2
General Discussion / Re: v.high wired memory
« on: May 09, 2023, 04:40:06 pm »
Disabling IOMMU in the BIOS has brought it way down


3
General Discussion / v.high wired memory
« on: May 09, 2023, 03:02:04 pm »
This expected memory usage with ZenArmor running? (APU2c4)

I can't really remember what is was prior to the issue with 1.13, but I don't remember it being this high.




4
Zenarmor (Sensei) / Re: V1.13 after upgrade does not block web sites
« on: May 07, 2023, 03:22:17 pm »
I'm seeing very high RAM usage to (+/-80% of 4GB) with high usage related to what appears to be ZenArmor services

I tried reinstalling ZenArmor and then opnsense factory reset, but none of it helped

Saw a msg saying services were waiting to start or failing

Looks like there's something wrong with it, for me at least (us)

5
Zenarmor (Sensei) / Re: V1.13 after upgrade does not block web sites
« on: May 06, 2023, 04:29:40 pm »
can confirm there appears to be an issue here with the essentially security policies

if any of the following are enabled, all filtering across app, web, and security stops working :

bad ip
non-existent domains
hacking sites
potentially dangerous
undecided not safe

tested using mobile browser with no addons enabled and an ad block test site

just went through the essential sec policies enabling and disabling one after another

6
Intrusion Detection and Prevention / CrowdSec bouncer
« on: May 01, 2023, 04:47:54 pm »
I've noticed having the Crowdsec IDS enabled results is a lot of CPU usage.

If I just enabled just the IPS bouncer, will the blocklist aliases still update?

I've also got ZenArmor running.

7
General Discussion / PPPoE; IPoE; low power multi-threaded devices
« on: March 19, 2023, 01:31:07 pm »
Been looking for a fibre provider who doesn't use PPPoE.

Toob (UK) said they use IPoE.

From what I've read this is not an encapsulated protocol, using DHCP options for auth.

Just wanted to checked if IPoE's an issue with BSD based routers, like the single threaded PPPoE daemon is?

Are there other issues that could impact performance or limit functionality?

8
General Discussion / 23.1 upnp
« on: February 01, 2023, 01:26:29 pm »
do you still have to set up hybrid NAT rules for UPNP to work properly?

9
22.7 Legacy Series / Re: unbound dns stops sporadically
« on: November 10, 2022, 01:50:34 pm »
Using the blocklist does it for me

Disabled everything except Threatfox IOC... no problems

10
Hardware and Performance / APU's and IOMMU
« on: October 27, 2022, 02:14:19 pm »
APU's have IOMMU support in the CoreBoot BIOS.

I know it's a virtualisation thing, but wondering if it's something you'd want enabled anyway for other purposes?

11
Intrusion Detection and Prevention / Re: Netmap api 14
« on: June 02, 2022, 02:43:28 pm »
What NIC's does your router use?

12
23.7 Legacy Series / Re: [Tutorial/Call for Testing] Enabling Receive Side Scaling on OPNsense
« on: March 19, 2022, 05:16:24 pm »
Code: [Select]
The current Suricata/Netmap implementation limits this re-injection to one thread only.
Work is underway to address this issue since the new Netmap API (V14+) is now capable of increasing this thread count.
Until then, no benefit is gained from RSS when using IPS.

Any news on this?  This plus RSS on lower power multi-cored devices sounds interesting.

13
Hardware and Performance / Re: [APU2] Connection issues, random lags, drops
« on: March 03, 2022, 08:05:34 pm »
Cloudflare DNS is an anycast network.

https://www.cloudflare.com/en-gb/learning/cdn/glossary/anycast-network/

Just a guess, but some of those reponses, for whatever reason, could be coming from the other side of the world.

14
General Discussion / Syncthing incoming SPAT
« on: February 27, 2022, 02:19:48 pm »
ignore
:D

15
Virtual private networks / Re: Zerotier Lan Routing help!
« on: December 12, 2021, 10:57:11 pm »
I'm strugglgin with this to.

I can ping in to my LAN from a ZT node via OPNsense, just not the other way around.

Pages: [1] 2 3 ... 5
OPNsense is an OSS project © Deciso B.V. 2015 - 2024 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2