Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - Patrick M. Hausen

#61
Quote from: fragrance744 on June 23, 2026, 07:34:55 AMI'd rather have TrueNAS run the script itself and set a firewall rule to allow the connection

I'll ask again: why not use SSH with public key authentication to execute the midclt command on TrueNAS from OPNsense?
#62
Is ACPI enabled for your VM?
#63
Production is not working because FreeBSD is not supported in Hyper-V. Only Microsoft can change that. Standard seems to have the issues you describe - again IMHO only MS can change that.

You could shutdown the VM at night, take a snapshot, boot up again.

Or schedule configuration backups to Nextcloud, git, SFTP, ... your choice really. And not rely on VM snapshots for backup.

Also there is a perfectly capable snapshot mechanism within OPNsense if you install with ZFS. So if I was to insist running an unsupported guest OS in my hypervisor I would at least not plan with any of the advanced hypervisor mechanisms like snapshots to be working but use different means.

HTH,
Patrick
#65
Isn't there an option to "quiesce" the guest file system or not when creating the snapshot. Can you try not to stop I/O during snapshot creation?
#66
Quote from: chemlud on June 20, 2026, 10:50:41 PM...I see stuff with WG tunnels (non-connecting, stopping randomly, not starting services on reboot) which shows no pattern or is not related to any changes at the endpoints. There is something weird going on.

Are you using DNS names for peer configuration, possibly?

I manage (mostly IPsec) VPNs for more than 30 years, now. It's a good rule of thumb to never do that. Only use IP addresses for your peers - unless you don't need an explicit peer setting, of course, like with "road warriors" dialing in. VPN connections should not depend on DNS.
#67
Quote from: Mark_the_Red on June 20, 2026, 05:09:07 AMIf ONLY the switch can assign the device to a VLAN, then I guess I have my answer.  I just thought since the unifi access point is making OPNsense do this, there would be a way in OPNsense to say this IP address or MAC address should always be on the VLAN subnet at this IP address.

The AP is a switch in that regard. And the AP "assigns" the VLANs via different SSIDs, not OPNsense. And yes, only a managed VLAN capable switch can do that for wired devices.
#68
Quote from: NDregger on June 19, 2026, 09:10:45 PMIch weiß noch aus meinen Anfängen mit OPNsense das es nicht die tollste Idee ist ein WLAN Modul in einer OPNsense betreiben zu wollen

Richtig.

Quote from: NDregger on June 19, 2026, 09:10:45 PMaber vielleicht hat sich ja hier mittlerweile richtig was getan und wir könnten dem Kreuz Kosten ersparen?

Falsch.

Kauft einen kleinen AP wie einen Mikrotik hAP ax S oder eine Fritzbox im LAN-Client-Modus.

Sorry, aber es gilt nach wie vor: WLAN infrastructure mode on FreeBSD - don't. Der Mikrotik AP liefert noch einen 5-Port Switch mit. Alles fein.
#69
You need to assign the switch port the device is connected to to the particular VLAN for this device. The end devices are oblivious of VLANs, this is all managed by the network infrastructure.
#70
@viragomann Reading how Greg phrased the question, I think it's safe to assume that he wants OPNsense to authenticate to an 802.1x secured network as a client. Requirements like this exist in enterprise or uni campus space ;-)

Kind regards,
Patrick
#71
Please show your custom rule details.
#72
Quote from: fastboot on June 17, 2026, 09:59:24 AMHowever, there is fairly strong evidence that newer microcode exists for CPUID 06-9a-04:
[...]

OK. That's all I was asking. :-)
#73
Are you sure there is a microcode update applicable to your CPU? Is there any way to check this with e.g. Intel docs?
#74
Blockliste(n) aktiv?
#75
General Discussion / Re: ARC RAM usage
June 16, 2026, 03:03:26 PM
Quote from: Isabella Borgward on June 16, 2026, 03:01:00 PMWill ARC memory usage cause problems for PF states being created?

No. The number of pfstates has got a kernel internal hard limit. You can increase it at

Firewall > Settings > Advanced > Firewall Maximum States