Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Topics - hushcoden

#1
General Discussion / Checking the zpool status
July 26, 2026, 02:41:01 PM
I ran the command /sbin/zpool status
and this is the output
pool: zroot
 state: ONLINE
status: Some supported and requested features are not enabled on the pool.
        The pool can still be used, but some features are unavailable.
action: Enable all features using 'zpool upgrade'. Once this is done,
        the pool may no longer be accessible by software that does not support
        the features. See zpool-features(7) for details.
  scan: resilvered 529M in 00:00:02 with 0 errors on Mon Feb 26 19:03:35 2024
config:

        NAME        STATE     READ WRITE CKSUM
        zroot       ONLINE       0     0     0
          mirror-0  ONLINE       0     0     0
            ada1p4  ONLINE       0     0     0
            ada0p4  ONLINE       0     0     0

errors: No known data errors
Do I need to worry for those features not available at all?

Tia.
#2
My installation is about 3.5 years old, and I read somewhere that before upgrading from v26.1 to v26.7, I should update the disk bootloader. Is that correct?

I ran the following command: ./loaders-update show-me

and this is the output: loaders-update v1.3.2

One or more efi partition(s) have been found.

Examining ada1p1...
mount -t msdosfs /dev/ada1p1 /mnt
Would run: cp /boot/loader.efi /mnt/efi/freebsd/loader.efi
Would run: cp /boot/loader.efi /mnt/efi/boot/bootx64.efi
umount /mnt

Examining ada0p1...
Efi partition ada0p1 is already mounted in /boot/efi.
Would run: cp /boot/loader.efi /boot/efi/efi/freebsd/loader.efi
Would run: cp /boot/loader.efi /boot/efi/efi/boot/bootx64.efi

One or more freebsd-boot partition(s) have been found.
The root file system is zfs.

Examining ada1...
Would run: gpart bootcode -b /boot/pmbr -p /boot/gptzfsboot -i 2 ada1

Examining ada0...
Would run: gpart bootcode -b /boot/pmbr -p /boot/gptzfsboot -i 2 ada0

-------------------------------
Your current boot method is BIOS.
Updatable EFI loader: 4
Updatable BIOS loader: 2
-------------------------------

Could some kind soul guide me on the next steps?

Tia.
#3
I'm reading a post about migrating to the new OPNsense rules, and I noticed that the downloaded CSV contains multiple rows but only a single column. I was expecting each rule to occupy a row with multiple columns (one for each field). Is this expected, or is there something wrong with the export? I tried a few times, but the export looks always the same...

Tia.
#4
My son's PS5 is connected to one of the OPNsense firewall ports (LAN3), and I want to prioritise (or reserve) upload bandwidth for it in OPNsense. Basically, when he is gaming and I'm uploading large files, his latency jumps from about 20 ms to 150 ms. How can I stop that from happening?

I already read this article, is that the approach I should follow? Ideally, I'd want to assign to the PS5 5 Mb/s of bandwidth in upload when he is playing, but then when the PS5 is switched off, I'd want to be able to use the whole bandwidth for my devices.

Tia.
#5
I've just updated to the latest AdGuard Home (v0.107.74), and unfortunately the small button to check for updates at the bottom of the main page next to the version number has disappeared, and as a result, I'm no longer able to check for updates.

Also, if I log out and log back in (or just refresh the home page), I get a red error message saying: "Update check failed. Please check your Internet connection." But I do have Internet connection and I'm still able to update the DNS blocklists.

I've already cleared cookies and browser cache (Brave and Firefox) and rebooted OPNsense, but with no success.

Has anyone experienced something similar?

I'm running OPNsense v26.1.6 and latest mimugmail plugin v1.16.

Tia.
#6
I'm playing around with DNSCrypt (+ Unbound) and there are a couple of things I need clarification on:

1. In Unbound -> Query Forwarding there are two options that I cannot understand, i.e. 'Forward TCP upstream' & 'Forward first' - can someone please confirm whether I have to check them?

2. If I disable DNSCrypt to check any possible DNS leaks, I actually still have Internet access, and on dnsleaktest.com I can see it finds one DNS server, which is my ISP's. How do I troubleshoot this?

Tia.
#7
General Discussion / Help needed to create an alias
April 04, 2026, 03:08:33 PM
I'd want to create an alias using the block list https://rules.emergingthreats.net/fwrules/emerging-Block-IPs.txt and from my understanding - reading here - I should select the type 'networks', but unfortunately I get the error that the entry is not a network, can someone advise, please?

Tia.
#8
26.1, 26,4 Series / Planning to install v26.1.4
March 12, 2026, 05:11:26 PM
For sanity check, can I fresh install the latest version and then import the settings via backup file considering I'm running v25.7.11_9 ?

Anything to be aware of?

Tia.
#9
I'm currently using an FTTC connection with PPPoE, and in the next few days, I will be switching to FTTP (still PPPoE). I know where to enter the username and password - Interfaces -> Devices -> Point-to-Point - but for the life of me, I can't find where to enter the static IP address the ISP has provided me (along with the subnet mask of 255.255.255.255).

Tia.

P.S. - I'm running OPNsense v25.7.11_9.
#10
25.1, 25.4 Legacy Series / NTP service not starting
April 13, 2025, 10:38:24 AM
I've just updated to 25.1.5_4 and after the reboot the NTP service doesn't start, anybody's seeing a similar behaviour?

I've attached some errors from the log, if it can help.

Tia.
#11
I've followed the instructions by doktornotor here and that seems to work.

The issue I have (and I don't know what the root cause is) is that the modem GUI interface I created negotiates at 100 Mb/s rather than 1000 Mb/s: why on earth this is happening?

Tia.
#12
I read the official article of how to import an existing configuration, and it seems quite straight forward.

I also came across with this post where the OP stated the importer doesn't work as expected and he used a workaround - has anybody used the  importer and in case can confirm whether or not it works as in the guide?

Tia.
#13
I've set up two wireguard instances, one for ProtonVPN and one for Mullvad (and they both work), what I don't understand why on the dashoboard under gatewaus I can't see the Mullvad entry, any suggestions?

Tia.
#14
General Discussion / Using RAM for logs
January 12, 2025, 06:54:25 PM
I have upgraded my device to 16GB of RAM, and considering my OPNsense uses around 1.5GB (give or take), I was thinking to enable both /var/log RAM disk & /tmp RAM disk options (so I can avoid some writes to the SSD) - apart from the fact I will lose the logs on reboot, any drawback I have to be aware of?

Tia.
#15
General Discussion / Limiting the access to the gui
December 12, 2024, 05:05:56 PM
I'd want to allow only two devices within the LAN to access the OPNsense gui (and ssh too), can someone explain to me how do I do that?

Tia.
#16
I've configured Unbound with DoT and Quad9 servers (9.9.9.9 & 149.112.112.112), and looking at the firewall live view on the WAN interface, I see continual calls to those servers on port 53 (and not 853) where the source is my WAN IP address, the destination is the Quad9 server and the label is "let out anything from firewall host itself (force gw)"

Similarly, if I filter port 853, i see the same type of output, i.e. source is my WAN IP address, the destination is the Quad9 server and the label is "let out anything from firewall host itself (force gw)"

I'd want to know if that's normal beavhiour or there is something wrong in my configuration.

Tia.
#17
24.7, 24.10 Legacy Series / Question about Kea DHCP
November 24, 2024, 08:49:54 PM
I've decided to test the (new) Kea DHCP service and I've added 10 hosts an in the 'Reservations' section, so far so good.

What I don't understand is that if I click on 'Leases DHCPv4' menu, I see all those hosts with a Lifetime of 86400 (which is the default value for hosts with no reservation), and they actually expire within 24 hrs, hence I'm confused, why is that?

Tia.
#18
While configuring a WG interface, I'd like to understand whther or not we should enable the feature Dynamic gateway policy.

Tia.
#19
Hardware and Performance / About performance
October 24, 2024, 02:55:39 PM
While reading the document https://docs.opnsense.org/troubleshooting/performance.html I decided to enable RSS (my appliance has got 4x i225 ports and a Celeron J4125, 4 cores) and after reboot I've noticed that the value of net.inet.rss.bits is set to 3: just courious to understand why consdering that before enabling RSS the value was correctly set to 2...  ::)

Also, I read in the guide that if RSS is enabled with the 'enabled' sysctl, the packet dispatching policy will move from 'direct' to 'hybrid'. But not for me as even after rebooting, the dispatching policy is still 'direct', and should I set a tuneable to change that to 'hybrid'? Or would it be better to change that to 'deferred' considering my connection is PPPoE?

Tia.
#20
Virtual private networks / How to configure DNS in WG?
October 24, 2024, 01:00:37 PM
Still a lot to learn, so please educate me: by reading the official document WireGuard Selective Routing to External VPN Endpoint it seems there is no need to create a firewall rule for the DNS, and the only mention is at the very end of the document but just relating to DNS leaks (so I read it as optional):

1) why is there no need for firewall DNS rule?

2) as for the very last paragraph/note, I was expecting also the need to specify the destination port range i.e. DNS/DNS, but why is it not the case?

On a separate note, in the instance WG configuration there is a DNS servers setting, but it's not mentioned on any documentation, so what is that for?