This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.
Show posts Menu
Quote from: PeterZaitsev on January 04, 2021, 12:13:37 AM
Unbound crashes for me too. Have not tried downgrading at this point.
One surprising thing was to see it does not restart itself - I would imagine for key system services there would be some auto restart process. Is there not such a thing in opnsense or is it disabled for unbound ?
opnsense-revert -r 20.7.6 unboundQuote from: FullyBorked on August 07, 2020, 07:31:57 PM
This isn't comprehensive by any means, but outlines what I am experiencing. I've not found any workarounds for these issues. I consider 1 and 2 more serious than the others. I'll try and keep this up to date as issues are resolved or more are encountered.
1. WAN throughput is very slow IPS on or off doesn't matter, I'm only getting about 15% of my actual WAN bandwidth. A reboot fixes the issue temporarily but at some point it will drop back to being slow. >:(
Edit: Messing with my power settings https://forum.opnsense.org/index.php?topic=18450.0 seemed to "fix" this somehow. Very confused, maybe it was stuck in a low power mode? No idea but my speed is fine now, maybe try cycling your power settings.
2. GEO IP Alias simply doesn't work, the zip file is being downloaded from maxmind.com but the alias won't populate, so any rules containing the alias fail to correctly function.
3. Dashboard traffic graphs don't show data with IPS enabled. I'm on an Intel NIC, some have suggested it's driver related. Worked ok in 20.1.9 though maybe there is a bug in the latest driver? No workaround has resolved the issue as of yet.
4.Syslog-NG service doesn't start on it's own after reboot. Starting it manually does seem to work, but is inconvenient after reboot.This appears to be fixed with 20.7.1.
4. Restarting suricata service sometimes stops the ntpd service for some reason. It can be manually started.
5. Bogons alias is inexplicably empty at times. Firewall > Diagnostics > pftables > bogons > "update bogons" does populate the list.
6. Seeing log spam just like https://forum.opnsense.org/index.php?topic=18480.msg84175#msg84175 constantly in the log. Not sure if this is cause of issue #1 or not.
kernel: pflog0: promiscuous mode enabled
kernel: pflog0: promiscuous mode disabled
Quote from: mimugmail on August 17, 2020, 07:24:23 AM
Known error when Sensei or IPS is running in same interface. Needs some time to fix.




Quote from: mimugmail on August 11, 2020, 09:25:36 AM
Nothing, it will upgrade from 7.3 to 7.4 and disable requirement for ebgp policies
11 root 155 ki31 0 64K CPU0 0 835.0H 92.19% [idle{idle: cpu0}]
88347 root 25 0 1919M 325M select 1 135:00 8.89% /usr/local/bin/suricata -D --netmap --pidfile /var/run/suricata.pid -c /usr/local/etc/suricata/suricata.yaml{W#01-igb1}
27807 root 25 0 39M 32M select 1 73:28 6.49% /usr/local/bin/python2.7 /usr/local/opnsense/scripts/netflow/flowd_aggregate.py
18 root -16 - 0 16K - 3 107:38 2.10% [rand_harvestq]