Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Topics - buedi

#1
I posted here (https://forum.opnsense.org/index.php?topic=50771.0) earlier while being on 25.7 , but I figured I can upgrade to 26.1, maybe things will change.
And they did... it got worse.

I upgraded from 25.7 to 26.1 and now sqlite3 is constantly writing on the SSD and I cannot figure out why it is doing this. It does not look like more space is consumed (I did not notice a change in the last 3 hours), but the constant writing is worrying.

A top -S -m io -o total shows:
  PID USERNAME     VCSW  IVCSW   READ  WRITE  FAULT  TOTAL PERCENT COMMAND
83231 root         481      0      2   2396      0   2398  97.44% sqlite3
35108 hostd         22      0      0     63      0     63   2.56% hostwatch
73985 root           0      0      0      0      0      0   0.00% php-cgi
70657 root           0      0      0      0      0      0   0.00% openvpn
59009 root           0      0      0      0      0      0   0.00% cron

So it is clearly sqlite3 writing all the time. But I have no idea which OPNsense function / service this could be.

I have read, that Neighbor Discovery can cause load, so I disabled that. No change.
Then I disabled the Wazuh Agent I installed recently. No Change
I also disabled Netflow. No change.
Captiva Portal seems to use sqlite3 too, but this is turned off for me.
I also disabled Surricata to see if it changes anything... no change.

Since I upgraded to 26.1 this is happening and the upgrade was like 5 or 6 hours ago. I suspect, even if this was some internal Database migration, it should be finished a long time ago.

How can I track down what sqlite3 is doing here?

Any help is appreciated very much by me and my SSD ;-)
#2
Hi everyone,

I am still at 25.7 and since a few weeks I encounter system instabilities and increased Disk I/O. Both might not be related, but Disk I/O is something I want to look into first, because it is also visible from the outside.

My OPNsense box has a Disk activity LED. Usually this one flashes up once every 5-10 seconds I would say. Recently it is more like every 0,5 seconds, sometimes even constantly on for a few seconds. When I set up my OPNsense around a year ago, I paid attention to minimize logging as much as possible, but either things might have changed due to new functionality / updates, or my system is having issues which is causing more logging.

I lack the knowledge in BSD how to find out which processes or parts of OPNsense are causing the Disk I/O and I would appreciate if someone could point me in the right direction.

I am not saying that OPNsense is causing the crashes I encounter, but maybe it is logging some faults that lead to the crash after a while. Also, if possible, I want to find the root cause of the Disk I/O to bring it down again for less heat and wear of the SSD.

Any help is appreciated very much.

Thank you very much in advance :-)
#3
Hello everyone,
I searched the forum and some other bits of the internet and it seems like this setup usually is a no-brainer. But for some odd reason, I cannot get it up and running and I am a bit lost on how to debug this.
I got myself a /64 prefix from tunnelbroker.net and try to configure it on my OPNsense. Although on my end all lights show up green / up, I cannot even ping the remote end of the tunnel.
What I did is what is in the documentation here: https://docs.opnsense.org/manual/how-tos/ipv6_tunnelbroker.html.
I ended up having a gif Interface in the interface overview which shows up and the correct IPv6 addresses.
Also in the gateways, I made sure the tunnel is the default IPv6 gateway.

ifconfig shows me that the interface is there with the correct prefix length:
```
gif0: flags=1008051<UP,POINTOPOINT,RUNNING,MULTICAST,LOWER_UP> metric 0 mtu 1280
        description: IPv6Tunnel (opt7)
        options=80000<LINKSTATE>
        tunnel inet 1xx.x.x.9 --> 216.66.80.30
        inet6 fe80::aab8:e0ff:fe03:fec5%gif0 prefixlen 64 scopeid 0xf
        inet6 2001:470:xxxx:xxx::2 prefixlen 64
        groups: gif
        nd6 options=21<PERFORMNUD,AUTO_LINKLOCAL>
```
netstat -rn6 shows me that the IPv6 tunnel is indeed the default gateway:
```
Routing tables

Internet6:
Destination                       Gateway                       Flags         Netif Expire
default                           2001:470:xxxx:xxx::1          UGS            gif0
```

But I cannot ping the other end of the tunnel. All "local" IPv6 addresses work. Even when configuring SLAAC, my clients get valid IPv6 addresses and up until the LAN interface on the OPNsense I can ping all hosts. It just seems like nothing wants to go through the tunnel.
But if I look at the live view and filter the destination IP I am trying to ping, it shows no blocked traffic... quite contrary, it shows that the packet was sent through the tunnel interface.

And this is where I am lost now... I have the impression that all interfaces are configured correctly and that the route for IPv6 traffic into the tunnel is honored. Tunnelbrocker.net is a free service and I want to make sure I have checked everything on my side before trying to open a ticket and ask them for help. Is there anything else I can do to debug if I have a problem on my end?

#4
Hi everyone,

I am pretty sure there is something I am doing wrong and you can point me in the right direction.
I run OPNsense 24.7.5_3-amd64 and utilizing ISC DHCPv4 to handle my LAN IP Pool.
It is set to hand out IPs in the range of 10.0.0.100 to 10.0.0.150. Within that range, I configured a static mapping to one of my devices MAC address, so it always will get the 10.0.0.149 address.

For whatever reason, every new system or VM I join to the network gets the 10.0.0.149 address. It feels like instead of picking one of the other 49 free addresses, it gives out the Static one on purpose and not by accident. But I can not wrap my head around why this is.

Attached is a Screenshot of the current situation. The Host "BOEXLE" is the one with the correct MAC and the static reservation. I spun up a Container on another system and it gets the .149. Yesterday I spun up a KVM VM on one of my other hosts and it got the .149 too. I do not understand why this is. I thought reserving a IP within the pool for a specific MAC should prevent from handing out this IP to another system.

#5
I am doing my research now for a few days to get the right hardware for a new OPNsense system that should replace my DD-WRT system. I am especially looking for devices capable of 2.5GbE with 2-4 NICs. In that process I have read a log about Realtek NICs and Intel NICs and the issues people have with the i225/i226 NICs.

The problem is, that no matter what devices I search for in that segment (small, fanless, 2-4 NICs, 2.5GbE), there does not seem to be a way around the i226-V NICs. Even on devices that are meant to be used with OPNsense like the Thomas Krenn LESv4, they all use the i226-V NICs.

I also read that some people can get rid of the issues by tweaking the APM features (turning them off), but that defeats the purpose of a low power, low noise Firewall for me (which sits right here on my desk).

Even when reading all the recent posts about which hardware to chose, in the end it seems always to be a device with an i226-V. Like no other thing exists... and I can not find something else with current technology and low energy consumption either.

I was even on the fence to get a Odroid H4+, because of its  super low power consumption but still good performance... well, i226-V again :-) Current CWWK systems? i226-V. Most of the Aliexpress no-name stuff? i226-V or i225 if they are a bit older.