Recent posts

#1
Tutorials and FAQs / Re: OPNsense aarch64 firmware ...
Last post by Maurice - September 30, 2026, 10:33:05 PM
OPNsense 26.7.5 aarch64 packages and sets released.
#2
26.7 Series / Re: os-upnp plugin not working...
Last post by nero355 - September 30, 2026, 10:22:07 PM
Quote from: bamf on September 30, 2026, 06:43:56 PM
Quote from: nero355 on September 30, 2026, 06:05:55 PMSo far it seems you can't combine both so I am not sure if Endpoint-Independent NAT will solve that issue too...

It does resolve this issue in a more secure way than Static Port.
Can you give me some "real world" examples ?

I have read some stuff about it already like :
QuoteThere's a good explanation of the details in the Netgate documentation here: https://docs.netgate.com/pfsense/en/latest/nat/outbound.html#endpoint-independent-port-restricted-cone-nat
But I am not yet sure what to do with it to be honest...
#3
26.7 Series / Re: Connections suddenly block...
Last post by nero355 - September 30, 2026, 10:18:35 PM
Quote from: BoerBart on September 30, 2026, 07:30:50 PMThe TP-link is running in bridge mode to have WiFi on the first floor.
But that would mean each WiFi device has a WAN IP Address ?!

I am pretty sure your ISP does not like that...

QuoteI'm not a 100% sure, so i'll go and check.

For my understanding, how would that cause random connections being dropped on the LAN interface?
I was thinking maybe you pick up the wrong DHCP Settings on your Client from time to time... Who knows... I have seen a lot of weird stuff throughout the years ;)

QuoteThanks for the info - I'll have a look at that later.
It's one of the reasons I still have the modem, I'm very much it's not much, but it's something.
Wait...

The Modem is Bridged... right ?!

QuoteI'll go over the rules again to see if there's anything off.
Though, as it's the main deny rule which is no. 13 in my case, it wouldn't matter what comes afterwards, as the rules are processed first match, correct?
From the top down indeed and as they all seem to be so called 'Quick Rules' then it's basically the first rule that gets hit is the way to go IIRC :)

QuoteOpenWRT isn't supported on the Archer AX50 sadly enough, i've looked into that a little ago.
Too bad! :(

QuoteOf course, buying new hardware is always a good option, though I find it frustrating it 'suddenly' started acting up.
Next to that, it seems to be somewhat specific.
Sometimes there is a simple reason such as simply a configuration that was wrong in the first place and after "Change X" to the software the issue rises to the surface so to speak...

QuoteMy PC and phone have issues, but when I check the Live view, no connections are dropped coming off the 2 Proxmox nodes.
It could be something local to them but you will have to figure that out on your own.

One of the things I was thinking about is A-Symmetric Routing but I am not sure how that would apply here, however as stated before : I have seen weirder things before... A LOT of weird things...

QuoteI've got another TP-link switch laying around here, I'll take the Archer AX50 out, and replace it with the switch, see if that changes anything.
Good idea anyway!

Quote**Added later**
In the meantime, I've swapped out the TP-Link router for a TP-Link switch, no change to the issue.

I've stopped all (unnecessary) VMs and LXC containers in Proxmox, no change to the issue.
I've moved the Opnsense VM to the other node, also no change to the issue.
Bummer... :(
#4
26.7 Series / Re: OPNsense 26.7 blocks LAN t...
Last post by Patrick M. Hausen - September 30, 2026, 09:42:02 PM
What exactly was your fix, please?
#5
26.7 Series / Re: ACME cron renewal fails bu...
Last post by JeGr - September 30, 2026, 08:46:19 PM
Seconded here. Was hitting a monitoring alert because 2 certs that are in use with Caddy were over there set up renewal timeframe. As I'm already using the new "tlsserver" profile that only has ~45days certs manually refreshing multiple certificates is tedious. It's only the cron that fails though, manually refreshing is fine, but somehow the --cron stuff isn't running correctly.
#6
26.7 Series / Re: OPNsense 26.7 blocks LAN t...
Last post by ricksense - September 30, 2026, 07:34:35 PM
Quote from: nero355 on September 30, 2026, 06:24:33 PMWhat happens when you Enable all the Anti-Lock Out Rules for webGUI and SSH access ?

Or are they already Enabled ?!

Yes, already enabled. Anyway, I fixed the problem(s) eventually, but I had to struggle a lot.
Very strange behavior compared to the old version.
Thanks
#7
26.7 Series / Re: Connections suddenly block...
Last post by BoerBart - September 30, 2026, 07:30:50 PM
Quote from: nero355 on September 30, 2026, 06:00:54 PMWhy have both a Modem and the TP-Link in Bridge Mode there ?!

The TP-link is running in bridge mode to have WiFi on the first floor. There's an UTP cable running from the first floor to the second, where all the other components are, hence it's all hooked up to the TP-Link router.

Quote from: nero355 on September 30, 2026, 06:00:54 PMTo be sure :
Are you sure there is not a VM or LXC on any of these two connected to your LAN and running a DHCP Server without you knowing ?

I'm not a 100% sure, so i'll go and check. For my understanding, how would that cause random connections being dropped on the LAN interface?

Quote from: nero355 on September 30, 2026, 06:00:54 PMWatch out with this Switch : If connected like this a wrong configuration can expose the Switch's webGUI to the Internet !!

Thanks for the info - I'll have a look at that later. It's one of the reasons I still have the modem, I'm very much it's not much, but it's something.

I'll go over the rules again to see if there's anything off. Though, as it's the main deny rule which is no. 13 in my case, it wouldn't matter what comes afterwards, as the rules are processed first match, correct?

OpenWRT isn't supported on the Archer AX50 sadly enough, i've looked into that a little ago. Of course, buying new hardware is always a good option, though I find it frustrating it 'suddenly' started acting up. Next to that, it seems to be somewhat specific. My PC and phone have issues, but when I check the Live view, no connections are dropped coming off the 2 Proxmox nodes.

I've got another TP-link switch laying around here, I'll take the Archer AX50 out, and replace it with the switch, see if that changes anything. I've also patched OPNsense to the latest firmware version (26.7.5), without luck.

**Added later**
In the meantime, I've swapped out the TP-Link router for a TP-Link switch, no change to the issue. I've stopped all (unnecessary) VMs and LXC containers in Proxmox, no change to the issue. I've moved the Opnsense VM to the other node, also no change to the issue.
#8
26.7 Series / Re: os-upnp plugin not working...
Last post by bamf - September 30, 2026, 06:43:56 PM
Quote from: nero355 on September 30, 2026, 06:05:55 PMSo far it seems you can't combine both so I am not sure if Endpoint-Independent NAT will solve that issue too...

It does resolve this issue in a more secure way than Static Port. EIM-NAT is a fairly recent addition to OPNsense, and I migrated my rules for online gaming away from static port as soon as it became available. You might still need static ports for specific scenarios like SIP, but for gaming clients, EIM-NAT is definitely the more secure route now.

There's a good explanation of the details in the Netgate documentation here: https://docs.netgate.com/pfsense/en/latest/nat/outbound.html#endpoint-independent-port-restricted-cone-nat
#9
26.7 Series / Re: OPNsense 26.7 blocks LAN t...
Last post by nero355 - September 30, 2026, 06:24:33 PM
What happens when you Enable all the Anti-Lock Out Rules for webGUI and SSH access ?

Or are they already Enabled ?!
#10
26.7 Series / Re: OPNsense 26.7.5 update
Last post by Monviech (Cedrik) - September 30, 2026, 06:22:15 PM
Its not really a beta test component as this page has been around for years, it was a firewall automation plugin page since 2021 or so.