Recent posts

#1
26.7 Series / Re: Post 26.7.4 Wireless Issue
Last post by franco - Today at 12:02:16 AM
If you disable the interface and hit apply wpa_supplicant should be stopped, or is that not the case? And if it's stopped the card will still keep advertising?

Again, the re-configuration logic should not have changed on stable.

Looking at the apply in the wireless we could also stop wpa_supplicant/hostapd and restart them on their attached interfaces. The refactoring is a bit crude in this area.


Cheers,
Franco
#2
General Discussion / Re: OPNsense insists that DHCP...
Last post by Patrick M. Hausen - September 18, 2026, 11:36:36 PM
Quote from: tangofan on September 18, 2026, 09:44:58 PMPerhaps it would be a good idea, if at the time of uninstallation of a plugin, there was an option to erase the configuration block of that plugin

- System > Configuration > Defaults > Components
- Select "Services: ISC DHCPV4 [legacy] [dhcpd]"
- Click on "Reset"

HTH,
Patrick
#3
General Discussion / Re: OPNsense insists that DHCP...
Last post by tangofan - September 18, 2026, 09:44:58 PM
Quote from: Remington on September 17, 2026, 10:32:57 PMFor me the issue seems to be an old DHCP/DHCPv6 configuration in config.yml which is not necessary anymore as I moved from ISC DHCP to DNSMASQ. I have created a backup of config.xml. Removed the <dhcp> and <dhcpv6> bock and restored the firewall from this config. This fixed the issue.
At the risk of derailing this thread ever so slightly: I used ISC before and switched to KEA not too long ago and - after looking at my config file for the first time ever - I also noticed a <dhcp> block. (Never had ipv6 active.)

Perhaps it would be a good idea, if at the time of uninstallation of a plugin, there was an option to erase the configuration block of that plugin, e.g. by having an additional popup querying, whether to erase that data. Obviously that would require additional entries in the metadata of each plugin as to where to find the configuration block(s). So if that additional metadata weren't present, that option to erase the config data wouldn't be available.
#4
Tutorials and FAQs / Re: [HOWTO] Reach your ONT, ca...
Last post by meyergru - September 18, 2026, 09:06:26 PM
The point is that in the route section of the web UI, you can define a route to an existing gateway or to a predefined "Null4" or "Null6" gateway.

The way the route is created seems to be bound by using these specific entries and they use the B (blackhole) flag, you can see this results in "USB" flags for the route.

Since you cannot set the "Reject" flag for a self-defined gateway either, I do not see any way to to this via the web UI. So your are left with either a feature request on Github or by creating a specific pf entry by other means than the web UI.
#5
26.7 Series / Re: API reauest toggleRule fai...
Last post by Webfeger - September 18, 2026, 09:00:58 PM
Sometimes you can't see the forest for the trees. It only just occurred to me that an error had crept into the URL.. the script is working without the getRule param..
#7
Zenarmor (Sensei) / Re: tweaks that fixed my zenar...
Last post by Seimus - September 18, 2026, 08:21:15 PM
Yea they should definitely revisit the docs.

But all round its like you said.
The benefit of emulated is that you can run it on HW that does not have a native support of Netmap in the first place.

Regards,
S.
#8
26.7 Series / 26.7 → 26.7.4_1 update fails: ...
Last post by alanconner - September 18, 2026, 08:13:09 PM
Hello,

My OPNsense 26.7 amd64 firewall cannot update to 26.7.4_1.

The update fails repeatedly, including after one reboot:

Checking integrity...Assertion failed: (!STREQ(uid, p->uid)),
function pkg_conflicts_check_local_path,
file pkg_jobs_conflicts.c, line 317.
Child process pid=3086 terminated abnormally: Abort trap
Flushing temporary package files... done
Starting web GUI...done.
Partial update failure detected: report this error log to OPNsense.
No further actions will be taken. Please restart the update now.

Health audit results:

- Root filesystem: /dev/gpt/rootfs
- Installed kernel/base version: 26.7
- Missing or altered kernel files: none
- Missing or altered base files: none
- Repositories: OPNsense only
- Installed plugins: none
- Locked packages: none
- Missing package dependencies: none

The audit did report one missing package file:

perl5-5.42.2: missing file
/usr/local/lib/perl5/5.42/mach/auto/Opcode/Opcode.so

The core package consistency check expects opnsense 26.7.4_1,
but the installed version is 26.7.

What is the supported recovery method for this
pkg_conflicts_check_local_path assertion on OPNsense 26.7?

Thank you.

***GOT REQUEST TO UPDATE***
Currently running OPNsense 26.7 (amd64) at Fri Sep 18 10:06:52 AKDT 2026
Updating OPNsense repository catalogue...
OPNsense repository is up to date.
All repositories are up to date.
Updating OPNsense repository catalogue...
OPNsense repository is up to date.
All repositories are up to date.
Checking for upgrades (166 candidates): .......... done
Processing candidates (166 candidates): ..... done
The following 82 package(s) will be affected (of 0 checked):

New packages to be INSTALLED:
   py313-typing-extensions: 4.16.0 [OPNsense]

Installed packages to be UPGRADED:
   boost-libs: 1.89.0_2 -> 1.91.0 [OPNsense]
   ca_root_nss: 3.124 -> 3.129 [OPNsense]
   curl: 8.21.0 -> 8.22.0 [OPNsense]
   cyrus-sasl: 2.1.28_5 -> 2.1.28_6 [OPNsense]
   dhcp6c: 20260122 -> 20260122_1 [OPNsense]
   dpinger: 3.4 -> 3.6 [OPNsense]
   expat: 2.8.2 -> 2.8.4 [OPNsense]
   filterlog: 0.8 -> 0.9 [OPNsense]
   glib: 2.86.4,2 -> 2.88.3,2 [OPNsense]
   hostapd: 2.11_3 -> 2.12_2 [OPNsense]
   jansson: 2.15.1 -> 2.15.1_1 [OPNsense]
   json-c: 0.18 -> 0.19_1 [OPNsense]
   kea: 3.0.3 -> 3.0.4 [OPNsense]
   krb5: 1.22.2_2 -> 1.22.2_3 [OPNsense]
   libffi: 3.6.0 -> 3.8.0 [OPNsense]
   libnghttp2: 1.69.0 -> 1.70.0 [OPNsense]
   libpsl: 0.21.5_2 -> 0.23.3 [OPNsense]
   libuuid: 2.42.2 -> 2.42.3 [OPNsense]
   libxml2: 2.15.3 -> 2.15.4 [OPNsense]
   log4cplus: 2.1.2 -> 2.2.0.1 [OPNsense]
   monit: 5.35.2 -> 6.0.0 [OPNsense]
   mpd5: 5.9_19 -> 5.9_20 [OPNsense]
   nss: 3.124 -> 3.129 [OPNsense]
   ntp: 4.2.8p18_5 -> 4.2.8p18_6 [OPNsense]
   openldap26-client: 2.6.13 -> 2.6.15 [OPNsense]
   openssh-portable: 10.3.p1,1 -> 10.5.p1_1,1 [OPNsense]
   openssl35: 3.5.7 -> 3.5.8 [OPNsense]
   openvpn: 2.7.5 -> 2.7.7 [OPNsense]
   opnsense: 26.7 -> 26.7.4_1 [OPNsense]
   opnsense-update: 26.7 -> 26.7.4 [OPNsense]
   pcre2: 10.47_1 -> 10.48 [OPNsense]
   perl5: 5.42.2 -> 5.42.3 [OPNsense]
   php85: 8.5.8 -> 8.5.10 [OPNsense]
   php85-ctype: 8.5.8 -> 8.5.10 [OPNsense]
   php85-curl: 8.5.8 -> 8.5.10 [OPNsense]
   php85-dom: 8.5.8 -> 8.5.10 [OPNsense]
   php85-filter: 8.5.8 -> 8.5.10 [OPNsense]
   php85-gettext: 8.5.8 -> 8.5.10 [OPNsense]
   php85-ldap: 8.5.8 -> 8.5.10 [OPNsense]
   php85-mbstring: 8.5.8 -> 8.5.10 [OPNsense]
   php85-pcntl: 8.5.8 -> 8.5.10 [OPNsense]
   php85-pdo: 8.5.8 -> 8.5.10 [OPNsense]
   php85-pecl-mcrypt: 1.0.7 -> 1.0.9 [OPNsense]
   php85-phalcon: 5.16.0 -> 5.20.3 [OPNsense]
   php85-phpseclib: 3.0.55 -> 3.0.57 [OPNsense]
   php85-session: 8.5.8 -> 8.5.10 [OPNsense]
   php85-simplexml: 8.5.8 -> 8.5.10 [OPNsense]
   php85-sockets: 8.5.8 -> 8.5.10 [OPNsense]
   php85-sqlite3: 8.5.8 -> 8.5.10 [OPNsense]
   php85-xml: 8.5.8 -> 8.5.10 [OPNsense]
   php85-zlib: 8.5.8 -> 8.5.10 [OPNsense]
   py313-anyio: 4.13.0 -> 4.15.1 [OPNsense]
   py313-certifi: 2026.5.20 -> 2026.7.22 [OPNsense]
   py313-cffi: 2.0.0 -> 2.1.1 [OPNsense]
   py313-charset-normalizer: 3.4.7 -> 3.5.1 [OPNsense]
   py313-cryptography: 48.0.0_1,1 -> 50.0.1,1 [OPNsense]
   py313-duckdb: 1.5.4 -> 1.5.5 [OPNsense]
   py313-h2: 4.3.0 -> 4.4.1 [OPNsense]
   py313-hpack: 4.1.0 -> 4.2.0 [OPNsense]
   py313-idna: 3.18 -> 3.19 [OPNsense]
   py313-numexpr: 2.14.1_2 -> 2.14.2 [OPNsense]
   py313-packaging: 26.2 -> 26.3 [OPNsense]
   py313-pandas: 2.3.3_3,1 -> 2.3.3_4,1 [OPNsense]
   py313-pyasn1: 0.6.0 -> 0.6.4 [OPNsense]
   py313-pyopenssl: 26.2.0,1 -> 26.4.0,1 [OPNsense]
   py313-pytz: 2026.2,1 -> 2026.3,1 [OPNsense]
   py313-pyyaml: 6.0.3 -> 6.0.3_1 [OPNsense]
   py313-service-identity: 24.2.0 -> 26.1.0 [OPNsense]
   py313-sqlite3: 3.13.14_10 -> 3.13.15_10 [OPNsense]
   py313-trio: 0.33.0 -> 0.34.0 [OPNsense]
   py313-tzdata: 2026.2 -> 2026.4 [OPNsense]
   py313-ujson: 5.12.1 -> 6.0.0 [OPNsense]
   python313: 3.13.14 -> 3.13.15 [OPNsense]
   rrdtool: 1.9.0_1 -> 1.11.0 [OPNsense]
   sqlite3: 3.53.3,1 -> 3.53.4,1 [OPNsense]
   strongswan: 6.0.7 -> 6.1.0 [OPNsense]
   suricata: 8.0.6 -> 8.0.7 [OPNsense]
   syslog-ng: 4.12.0 -> 4.12.0_5 [OPNsense]
   unbound: 1.25.1_1 -> 1.26.1 [OPNsense]
   wpa_supplicant: 2.11_7 -> 2.12_1 [OPNsense]
   zip: 3.0_5 -> 3.0_6 [OPNsense]

Number of packages to be installed: 1
Number of packages to be upgraded: 81

The process will require 13 MiB more space.
172 MiB to be downloaded.
[1/82] Fetching php85-xml-8.5.10.pkg: .. done
[2/82] Fetching unbound-1.26.1.pkg: .......... done
[3/82] Fetching wpa_supplicant-2.12_1.pkg: ......... done
[4/82] Fetching py313-idna-3.19.pkg: ..... done
[5/82] Fetching filterlog-0.9.pkg: . done
[6/82] Fetching dpinger-3.6.pkg: .. done
[7/82] Fetching opnsense-update-26.7.4.pkg: . done
[8/82] Fetching hostapd-2.12_2.pkg: ...... done
[9/82] Fetching py313-pyopenssl-26.4.0,1.pkg: ...... done
[10/82] Fetching php85-curl-8.5.10.pkg: ..... done
[11/82] Fetching py313-service-identity-26.1.0.pkg: . done
[12/82] Fetching boost-libs-1.91.0.pkg: .......... done
[13/82] Fetching monit-6.0.0.pkg: .......... done
[14/82] Fetching py313-cffi-2.1.1.pkg: ......... done
[15/82] Fetching php85-dom-8.5.10.pkg: ......... done
[16/82] Fetching php85-filter-8.5.10.pkg: . done
[17/82] Fetching nss-3.129.pkg: .......... done
[18/82] Fetching py313-h2-4.4.1.pkg: ... done
[19/82] Fetching py313-packaging-26.3.pkg: ......... done
[20/82] Fetching json-c-0.19_1.pkg: .. done
[21/82] Fetching php85-simplexml-8.5.10.pkg: ... done
[22/82] Fetching php85-pdo-8.5.10.pkg: . done
[23/82] Fetching python313-3.13.15.pkg: .......... done
[24/82] Fetching py313-pyyaml-6.0.3_1.pkg: .... done
[25/82] Fetching php85-pecl-mcrypt-1.0.9.pkg: ... done
[26/82] Fetching openvpn-2.7.7.pkg: ...... done
[27/82] Fetching py313-pyasn1-0.6.4.pkg: ........ done
[28/82] Fetching krb5-1.22.2_3.pkg: .......... done
[29/82] Fetching libnghttp2-1.70.0.pkg: ..... done
[30/82] Fetching libxml2-2.15.4.pkg: .......... done
[31/82] Fetching py313-pandas-2.3.3_4,1.pkg: .......... done
[32/82] Fetching php85-session-8.5.10.pkg: ...... done
[33/82] Fetching rrdtool-1.11.0.pkg: .......... done
[34/82] Fetching dhcp6c-20260122_1.pkg: . done
[35/82] Fetching py313-pytz-2026.3,1.pkg: ... done
[36/82] Fetching ntp-4.2.8p18_6.pkg: .......... done
[37/82] Fetching syslog-ng-4.12.0_5.pkg: .......... done
[38/82] Fetching php85-8.5.10.pkg: .......... done
[39/82] Fetching php85-phalcon-5.20.3.pkg: .......... done
[40/82] Fetching py313-certifi-2026.7.22.pkg: .... done
[41/82] Fetching php85-sqlite3-8.5.10.pkg: . done
[42/82] Fetching libpsl-0.23.3.pkg: .. done
[43/82] Fetching php85-gettext-8.5.10.pkg: . done
[44/82] Fetching ca_root_nss-3.129.pkg: ..... done
[45/82] Fetching php85-ldap-8.5.10.pkg: .. done
[46/82] Fetching py313-charset-normalizer-3.5.1.pkg: ..... done
[47/82] Fetching kea-3.0.4.pkg: .......... done
[48/82] Fetching py313-cryptography-50.0.1,1.pkg: .......... done
[49/82] Fetching php85-pcntl-8.5.10.pkg: . done
[50/82] Fetching openssl35-3.5.8.pkg: .......... done
[51/82] Fetching php85-phpseclib-3.0.57.pkg: ....... done
[52/82] Fetching php85-zlib-8.5.10.pkg: . done
[53/82] Fetching log4cplus-2.2.0.1.pkg: .... done
[54/82] Fetching pcre2-10.48.pkg: .......... done
[55/82] Fetching curl-8.22.0.pkg: .......... done
[56/82] Fetching py313-trio-0.34.0.pkg: .......... done
[57/82] Fetching libuuid-2.42.3.pkg: ..... done
[58/82] Fetching jansson-2.15.1_1.pkg: ... done
[59/82] Fetching py313-sqlite3-3.13.15_10.pkg: . done
[60/82] Fetching php85-sockets-8.5.10.pkg: ... done
[61/82] Fetching cyrus-sasl-2.1.28_6.pkg: .... done
[62/82] Fetching openssh-portable-10.5.p1_1,1.pkg: .......... done
[63/82] Fetching py313-anyio-4.15.1.pkg: ...... done
[64/82] Fetching py313-hpack-4.2.0.pkg: .... done
[65/82] Fetching suricata-8.0.7.pkg: .......... done
[66/82] Fetching zip-3.0_6.pkg: ....... done
[67/82] Fetching mpd5-5.9_20.pkg: ....... done
[68/82] Fetching sqlite3-3.53.4,1.pkg: .......... done
[69/82] Fetching py313-numexpr-2.14.2.pkg: ........ done
[70/82] Fetching php85-mbstring-8.5.10.pkg: .......... done
[71/82] Fetching openldap26-client-2.6.15.pkg: ........ done
[72/82] Fetching py313-tzdata-2026.4.pkg: ..... done
[73/82] Fetching glib-2.88.3,2.pkg: .......... done
[74/82] Fetching py313-ujson-6.0.0.pkg: .. done
[75/82] Fetching perl5-5.42.3.pkg: .......... done
[76/82] Fetching opnsense-26.7.4_1.pkg: .......... done
[77/82] Fetching libffi-3.8.0.pkg: . done
[78/82] Fetching strongswan-6.1.0.pkg: .......... done
[79/82] Fetching php85-ctype-8.5.10.pkg: . done
[80/82] Fetching py313-duckdb-1.5.5.pkg: .......... done
[81/82] Fetching expat-2.8.4.pkg: .. done
[82/82] Fetching py313-typing-extensions-4.16.0.pkg: ....... done
Checking integrity...Assertion failed: (!STREQ(uid, p->uid)), function pkg_conflicts_check_local_path, file pkg_jobs_conflicts.c, line 317.
Child process pid=86949 terminated abnormally: Abort trap
Flushing temporary package files... done
Starting web GUI...done.
Partial update failure detected: report this error log to OPNsense.
No further actions will be taken. Please restart the update now.
***DONE***
#9
Development and Code Review / Re: netflector available as pl...
Last post by RamSense - September 18, 2026, 07:32:53 PM
@UnicronHD thanks for the follow-up. I checked your remaining details.

The iPhone WireGuard interface is configured as 10.10.10.2/32. OPNsense has wg0 = 10.10.10.1/24, with 10.10.10.2/32 as the peer AllowedIP.

The ~350-byte packets are actually 348-byte SOOD packets. Their exact destination is the iPhone's own tunnel address:

10.10.10.2:<ephemeral> -> 10.10.10.2:9003

The payload starts with SOOD, message type Q, and includes the iPhone endpoint data (iOS 26.7, raat_version 1.1.48, tcp_port 9200).

During the dedicated capture I saw no ICMP packets toward 10.10.10.2.

Roon Server runs on Linux, Debian 12 (bookworm), x86_64.

Roon was in the foreground during the endpoint test.

One thing that may be relevant is the /32 on the iPhone together with the destination above: the phone's SOOD packet is sourced from 10.10.10.2 and is also addressed to 10.10.10.2:9003, and it does not appear on the LAN capture.

This may also be an interesting difference compared with udp-proxy-2020. Its VPN handling learns the client from UDP/9003 traffic seen on the tunnel interface and forwards that traffic onto the other configured interfaces; its debug examples show WG client traffic being reinjected toward the LAN.

So perhaps the relevant question here is whether UDP/9003 sourced from a configured WG peer should also be treated as discovery input for the opposite interface even when its destination is the peer's own tunnel address (?)

Happy to run any further captures or test another build.
#10
26.7 Series / API reauest toggleRule failed
Last post by Webfeger - September 18, 2026, 07:28:59 PM
Hi there,

i try to toggle fw rules by pusing api request in powershell. I already tried to check out different sites but i can't find the reason, why this request failed:

# api key
$key = 'hidden'
# api secret
$secret = 'hidden too' 
# url
$url = 'https://192.168.1.1:4444
# ------------------

# create basic auth info
$authinfo = [Convert]::ToBase64String([Text.Encoding]::ASCII.GetBytes(("{0}:{1}" -f $key,$secret))) 
Invoke-RestMethod -Uri "$url/api/firewall/filter/toggleRule/getRule/d4649c5b-8e6c-4768-88fd-6f39a28e0a05/0" -Method Post -Headers @{Authorization = "Basic $authinfo"} 

Output:
result
------
failed


Any ideas?
I already checked out that the UUID is correct by using backup xml