Recent posts

#1
German - Deutsch / Re: 'Migration Assistant ' der...
Last post by drosophila - September 21, 2026, 11:57:06 PM
Du könntest mal schauen, was im exportierten .csv ankommt. Möglicherweise braucht wirklich nur der letzte Punkt "alte Regeln löschen" ausgeführt zu werden, vielleicht sogar nur, um der GUI zu sagen, daß das erledigt ist.
#2
Development and Code Review / Re: netflector available as pl...
Last post by UnicronHD - September 21, 2026, 11:54:28 PM
Quote from: RamSense on September 21, 2026, 07:30:43 AMGreat, The plugin 0.1.6 with netflector 0.16.0 is installed and working perfectly here.

Thanks again for all the work and support!

Happy to help, thanks for the idea and all the testing.
#3
26.7 Series / Re: Firewall rules [new] missi...
Last post by drosophila - September 21, 2026, 11:47:59 PM
Maybe whatever piece of how-to you got these information from should be updated to include that [new] only appears between 26.1 and 27.x, and that the steps work wothout installing the plugin (as they seem to do, as I gather from your report). There seem to be a bunch of "appliance users" around who will eventually stumble across this issue during the coming ages. ;)
#4
26.7 Series / Re: Need to set "far gateway" ...
Last post by drosophila - September 21, 2026, 11:37:28 PM
No idea what causes this to break now; I kept "Far gateway" checked and it hasn't failed ever since. Maybe the code that makes it work in my case is the path that actually sets the address if both "fargw" is set and ipprotocol is ipv6 (in line 780)? It unconditionally deletes it in line 774 but the syntax explicitly used in 782 differs from what I expect will appear in 794?
#5
26.7 Series / Re: Ddclient - no global IP ad...
Last post by drosophila - September 21, 2026, 11:07:10 PM
As stupid as it sounds: wait until it fixes itself. I had the same issue during the last weeks with dynv6.com: first, the addresses kept resolving to the old one, then after a few days the entire hostname resolution failed. Luckily, the IPv4 fallback had come back from a similar failure a month ago, so I postponed the troubleshooting, and just today, the hostname came back online. My experience is that these dynamic DNS providers tend to have such issues every couple years, and unless you have some sort of priority access, you can only wait them out.

The only thing you could try on your end is to change the way your ddns client figures out its address, so, change the interface to monitor between "WAN" and the interface name (idk if you actually can enter this there), and also the "Check IP method". Maybe the provider you chose for that is down.
#6
26.1, 26,4 Series / Re: Zenarmor 2.6.2: worker0 ha...
Last post by nero355 - September 21, 2026, 10:30:43 PM
Quote from: rvansoest79 on September 21, 2026, 08:40:45 PMduring that time the kernel logs netmap_transmit igc1 full and traffic through the interface stalls

- Intel Celeron N5100 (4 cores), 7.8 GB RAM, Intel I226-V (igc), XGS-PON ~900/900 Mbit

20:12:46–20:13:04  kernel: netmap_transmit igc1 full ...   (2 lines/s, ~19 s)

20:13:04–20:13:19  kernel: generic_netmap_unregister/dtor/attach ... "Emulated adapter for igc1" deactivated → created → activated

- Earlier I also had bursts of UDPConnectionFlow::connect ... UDP flow connect failed: Address already in use / EastpectInstance::onAcceptUDP New UDP flow connect failed (98% in minute :09–:12) from one server VM; excluding that host removed those errors, but the worker hangs remain.
All of that sounds to me like you need to take a look at this topic : https://forum.opnsense.org/index.php?topic=48695.0

But I could be horribly wrong because I don't use ZenArmor so please read the complete topic and then decide what to do !! ;)
#7
German - Deutsch / Re: IPS auf OPNsense, Divert-t...
Last post by Bob.Dig - September 21, 2026, 10:17:43 PM
Danke erst Mal.
Quote from: Monviech (Cedrik) on September 21, 2026, 09:02:48 PMam besten nur auf dem WAN interface anmachen, im Netmap mode
Das möchte ich eher nicht machen, sondern das Ganze auf einem WireGuard-Interface betreiben. Mal sehen, ob das dann ohne netmap geht/gehen muss.
Bei mir hat divert in einem kurzen Test halt die Verbindung zum eigentlichen Ziel gekappt, ganz ohne Treffer. Mir ist auch noch nicht klar, warum das nur für 'ne große Kiste gut sein soll, denn ich möchte ja gerade bei 'ner kleinen Kiste performance sparen / selektiver sein. Aber gut, divert lass ich dann weg.
#8
26.7 Series / Re: [26.7.4_1]Intermittent con...
Last post by dragao-azul - September 21, 2026, 09:45:44 PM
Not sure if it counts as "solved", but setting up as virtio doesn't cause the issue anymore! The intel drivers might have brought something finicky, but for virtualisation this works! Thanks again!
#9
German - Deutsch / Re: IPS auf OPNsense, Divert-t...
Last post by viragomann - September 21, 2026, 09:17:56 PM
Quote from: Bob.Dig on September 21, 2026, 08:07:18 PMVielleicht ist das ja was für Dich:
https://www.youtube.com/watch?v=PDNMLmULm_M
Danke.
Diese wäre meine zweite Option nach der OPNWAF auf OPNsense.
Mein Problem mit Bunker Web ist allerdings, dass das alles in einer Public Cloud laufen muss, wobei die WAF-Instanz physisch getrennt von allen anderen zu laufen hat (Kunden-Vorgabe). D.h. ich müsste dafür eine eigene VM installieren.

Quote from: Bob.Dig on September 21, 2026, 08:07:18 PMNur was eben divert soll, ist für mich maximal unklar geblieben.
"Divert to" war hier im Forum aber schon einige male Thema. Vermutlich wurde da auch erklärt, was es genau tut.

Quote from: Monviech (Cedrik) on September 21, 2026, 09:02:48 PMDie Opnsense hat auch eine WAF die direkt von uns gepflegt wird, halt in der Business edition.

https://docs.opnsense.org/vendor/deciso/opnwaf.html
Ja, danke, werde ich mir als erstes ansehen.
Dafür brauche ich aber erst die Lizenz. Aktuell läuft da zum Test natürlich eine CE.
Hab mir aber heute schon eine 6.1 als Template vorbereitet, damit ich sofort auf BE upgraden kann.
#10
German - Deutsch / Re: IPS auf OPNsense, Divert-t...
Last post by Monviech (Cedrik) - September 21, 2026, 09:02:48 PM
Die Opnsense hat auch eine WAF die direkt von uns gepflegt wird, halt in der Business edition.

https://docs.opnsense.org/vendor/deciso/opnwaf.html

Zum Thema IDS/IPS, am besten nur auf dem WAN interface anmachen, im Netmap mode (hat am wenigsten Probleme wenn man eine normalen intel nic und kein pppoe hat), und aus dem ET Pro oder ET Telemetry ruleset das anmachen was man braucht (am besten unter so 20-30k Regeln bleiben). Meiner Meinung nach sind alle anderen Regeln als die nicht so das wahre.

Und das wars auch schon, so richte ich es bei Kunden ein wenn sie Anfragen damit sie es auf der Anforderungscheckliste abhaken können.

Ob es was bringt kann man nur durch Messen des Ergebnisses herausfinden.

Divert-to wird hier erklärt:
https://docs.opnsense.org/manual/firewall.html#divert-to

Für einfache IDS konfigurationen ist netmap besser geeignet meiner Meinung nach, Divert to wird interessant wenn du ne risige Firewall hast und nur bestimmte flows inspekten willst um performance zu sparen / selektiver zu sein.