Quote from: nero355 on September 29, 2026, 03:17:58 PMI have got a question that really bugs me :
Why would you do this =>Quote from: merrins63 on September 28, 2026, 01:38:52 PMI also have an Intel i226 2.5 GbE trunk, with corresponding VLAN interfaces bridged to the X550/LAGG VLAN interfaces.Aren't you effectively Bridging 2x 2,5 Gbps with 2 x 10 Gbps ?!
What is the purpose of such a setup ??
The issue I'm trying to solve with this design is mainly about making the best use of the different network speeds available in my home.
I have a traditional 1 GbE wired network, which is perfectly adequate for many of my wired IoT devices. However, my wireless access points and newer switches are capable of 2.5 GbE.
I need my wired and wireless IoT devices to remain on the same VLANs and subnets, while allowing the 2.5 GbE side of the network to make use of the faster interfaces rather than forcing everything through the existing 1 GbE switching infrastructure.
I'm also planning to upgrade my Internet connection to 2000/200 in the next few months, and I already have several multi-gigabit devices that will be able to take advantage of that bandwidth.
Previously, I used the more traditional approach of a single 24-port Gigabit Ethernet switch. However, with affordable 2.5 GbE switches now readily available, I wanted to take advantage of the Cat6A cabling already installed throughout my house.
The important point is that this design isn't intended for redundancy. The objective is to utilise the available 1 GbE and 2.5 GbE links efficiently while keeping devices within their existing VLANs.
Using bridged VLAN interfaces on OPNsense allows me to achieve that design.
Hopefully that explains the reasoning behind my setup a little better.
Quote from: Patrick M. Hausen on September 29, 2026, 01:20:12 PMThese definitions match the interface configuration. I am out of ideas ... er ... one moment ...
Did you check this option?
If you did not that would perfectly explain your observed symptoms.
ISC creates the necessary firewall rules for DHCP to work by default, if I remember correctly. For Kea that's optional, because some users complained that OPNsense should not create any rules automatically giving full control to the admin.
Quote from: Patrick M. Hausen on September 29, 2026, 01:20:12 PMThese definitions match the interface configuration. I am out of ideas ... er ... one moment ...
Did you check this option?
If you did not that would perfectly explain your observed symptoms.
ISC creates the necessary firewall rules for DHCP to work by default, if I remember correctly. For Kea that's optional, because some users complained that OPNsense should not create any rules automatically giving full control to the admin.
QuoteSome of those things can run alternative software like :
- UBPorts Ubuntu Touch
- Jolla SailFish
- PostmarketOS
Maybe IPv6 works a lot better in one of those ?! :)
Quote from: nero355 on September 29, 2026, 07:08:11 PMPost your network setup and all the Firewall Rules for the LAN Interface.
Is the Mini PC a Single NIC model or Dual/Quad NIC ?
And in general : The more info you provide, the less guessing we all have to do! ;)
VLAN ID VLAN Name Member Ports Tagged Ports Untagged Ports
1 Default 1-8 1-8
5 Redacted 2-3 2-3
10 Redacted 2-3 2-3
15 Redacted 2-3 2-3
20 Redacted 2-3 2-3
25 Redacted 2-3 2-3
30 Redacted 2-3 2-3
50 Redacted 2-3 2-3
80 Redacted 2-3 2-3
101 Redacted 2-3 2-3
110 Redacted 2-3 2-3
111 Redacted 2-3 2-3 Quote from: astronaut on September 29, 2026, 05:49:25 PMMy Android device is a Fairphone 6.Some of those things can run alternative software like :
[environment]
HTTP_PROXY=http://10.19.241.33:3128
HTTPS_PROXY=http://10.19.241.33:3128
http_proxy=http://10.19.241.33:3128
https_proxy=http://10.19.241.33:3128
FTP_PROXY=http://10.19.241.33:3128
ftp_proxy=http://10.19.241.33:3128
NO_PROXY=10.0.0.0/8,172.16.0.0/12,192.168.0.0/16,.unseredomain.de
no_proxy=10.0.0.0/8,172.16.0.0/12,192.168.0.0/16,.unseredomain.de
__timestamp__ 2026-09-29T15:48:11
ack 3901492930
action [block]
anchorname
datalen 39
dir [in]
dst 34.54.185.247
dsthostname
dstport 443
ecn
id 13033
interface vtnet0
ipflags DF
ipversion 4
label Default deny / state violation rule
length 91
offset 0
protoname tcp
protonum 6
reason match
rid 02f4bab031b57d1e30553ce08e0ec131
rulenr 13
seq 3881579953:3881579992
src 192.168.1.225
srchostname
srcport 40708
status 2
subrulenr
tcpflags PA
tcpopts
tos 0x0
ttl 64
urp 63
@13 block drop in log inet all label "02f4bab031b57d1e30553ce08e0ec131"
15
:
59
:
25 2026
evaluations
:
11538
packets
:
1700
bytes
:
171359
states
:
0
nodes
:
0
limit
:
0
nat/rdr
:
0
route
:
0
inserted
:
uid 0 pid 0
state_creations
:
0
time
:
tue sep 29