Recent posts

#1
Quote from: runo10 on September 17, 2026, 11:03:59 AMI didnt check for issue one but I have issue 2. When I enable suricata, a few minutes later all network gone. And later a few minutes it start to work again but it gones again a minutes later. This repeats continuesly.
I have crowdsec and suricata. But it worked before may be latest updates break something.

Also when I check suricata alerts from gui there is no alerts?

I find a side solution, If someone needs. I use divert mode with no problem. Probably problem related to netmap.
#2
26.7 Series / LAN unresponsive after firmwar...
Last post by Neil Mistry - Today at 03:12:35 AM
I set up OPNSense on a  Lenovo ThinkCentre M720q Tiny (Intel Core i5-8400T, with 8gb ram) back in May with a GLOTRENDS LE8245(A3) amazon .  Was working great until a week ago when I updated to OPNsense 26.7.4_1-amd64, FreeBSD 15.1-RELEASE-p3, OpenSSL 3.5.8. 

When I first upgraded within a hour I had to reboot as all LAN devices lost wifi.  A week later in this is happening frequently.  I can still reach the OPNSense box through wan (tailscale), but all lan devices lose wifi.  I reboot and works for some time. 

In the logs, I do not see any errors under 'System > Log Files > General', except the weekly '2026-08-25T02:31:09Erroropnsense/usr/local/etc/rc.linkup: Interface lan tracking nonexistent interface wan'.

I installed the plug-in 'os-realtek-re', issue still persists.  My connection is PPPOe with a vlan that my ISP requires, modem is a simple media converter box (optical to RJ45).  How do I diagnose and fix this?  Worked with no issues over 4 months before upgrading.
#3
26.7 Series / PPPoE unstable on I226-V (igc)...
Last post by (MARLOO) - Today at 02:58:56 AM
After upgrading from 26.7.3_11 to 26.7.4_1, my PPPoE WAN on an Intel I226-V interface (driver igc) became unstable. The PPPoE session occasionally comes up and ping works, but the PPP daemon continuously logs LCP down events and reconnection attempts, leading to an unstable connection.

The root issue is physical link flapping on igc1 and igc3 (link state changed to DOWN/UP), not a PPPoE-only problem. PPPoE failures are a consequence of the unstable underlying link.

All four I226-V ports are already running NVM V2.32-0 (eTrack 0x80000425), confirmed via dmesg | grep igc.

------------Environment---------------------

OPNsense version:
FreeBSD 15.1-RELEASE-p3 stable/26.7-n283949-083dc7025377 SMP amd64 (26.7.4_1)

NIC: Intel Ethernet Controller I226-V (device 0x125c, rev 0x04)

Driver: igc (module pci/igc, interface igc3)

Physical interface: igc3 (MTU 1492, status: active, 1000baseT full-duplex)

PPPoE: pppoe0

------------------------------Hardware---------------------------------

Motherboard: Techvision TVI7309X

CPU: Intel Celeron N5105 @ 2.00 GHz (max 2.9 GHz)

Symptoms

PPPoE session comes up and obtains a public IP.

Ping to public IPs (e.g. 1.1.1.1) works while the session is up.

System logs show continuous PPPoE/LCP failures:


[opt12_link0] PPPoE connection timeout after 9 seconds
[opt12_link0] Link: DOWN event
[opt12_link0] LCP: Down event
[opt12_link0] Link: reconnection attempt N in X seconds
[opt12_link0] PPPoE: Connecting to ''

This loop repeats every ~9 seconds (PPPoE timeout after 9 seconds, then immediate reconnect). At the time of writing, the PPP daemon has performed over 130 reconnection attempts in less than an hour, with no sign of stabilization.

On 26.7.3_11, with the same hardware, cabling, and NVM V2.32 firmware, the connection is stable and no such LCP timeout loop occurs.

------------------------Questions-----------------------------------------------------

Is this a known regression in 26.7.4_1 related to the igc driver or PPPoE handling?

Are there any recommended workarounds (different MTU, driver options, sysctl tweaks) before downgrading back to 26.7.3_11?
#4
German - Deutsch / Re: Kein SMTP outbound
Last post by RR - Today at 02:23:20 AM
Quote from: meyergru on September 19, 2026, 07:04:47 PMNur kurz gelesen, klingt nach Standardproblemen:

1. Ist das Kabel-Modem wirklich ein Modem oder ein Router mit 192.168.0.x als Transfernetz dahinter? Hint: Reply-To und "Wann ist ein WAN ein WAN"?
2. Erfolgt der Zugriff auf den Port von hinter der OpnSense aus und auf die externe IP via DNS? Ist das die vermeintliche oder die richtige WAN-IP? Ist NAT Reflection an?

Je nach Antwort auf diese Fragen ist Bobs Frage eventuell sehr naheliegend. Ich empfehle ggf: https://forum.opnsense.org/index.php?topic=42985.0

Die Sense läuft als Exposed Host mit externer IP. NAT Reflection ist aus. Deinen Post habe ich mir durchgelesen und einiges daraus mitgenommen. Ich habe den Fehler mittlerweile selbst beheben können. War eine falsche Einstellung im Mailserver. Danke für eure konstruktive Hilfe.

#5
26.1, 26,4 Series / Re: File truncated, kernel/bas...
Last post by newsense - Today at 02:04:41 AM
Which mirror are you on? Try changing it

To update the kernel and base packages do this:


opnsense-update -bkr 26.1.11
#6
26.7 Series / Re: Firewall Aliases – Functio...
Last post by Seimus - Today at 12:44:45 AM
The counter increases only for non Port based aliases.

Regards,
S.
#7
26.7 Series / Re: Firewall Aliases – Functio...
Last post by pfry - Today at 12:39:12 AM
It only counts pass matches... most of the time. I don't think I ever characterized it fully, and I've forgotten the details. How are the aliases you are testing applied?
#8
Hardware and Performance / Re: 10G but reaching only 5-5....
Last post by Seimus - Today at 12:38:45 AM
As already mentioned by others,
DO NOT test iperf using the FW as a client or a server, test THRU it but not TO it.

As well post output of command on FW as root.
netstat -Q
If Dispatch policy & IP is not hybrid you have it set wrongly. In that case set a tunable
net.isr.dispatch with value
hybrid
Restart your FW and check the command again.

You should see something like this

# netstat -Q
Configuration:
Setting                        Current        Limit
Thread count                        8            8
Default queue limit              2048        10240
Dispatch policy                hybrid          n/a
Threads bound to CPUs          enabled          n/a

Protocols:
Name  Proto QLimit Policy Dispatch Flags
ip        1  1000    cpu  hybrid  C--
igmp      2  2048 source  default  ---
rtsock    3  2048 source  default  ---
arp        4  2048 source  default  ---
ether      5  2048    cpu  direct  C--
ip6        6  1000    cpu  hybrid  C--
ip_direct    9  2048    cpu  hybrid  C--
ip6_direct    10  2048    cpu  hybrid  C--

Regards,
S.
#9
Hi everyone,
I'm trying to setup my Mullvad VPN connection on my OPNsense. I have IPv4 connection working great, but I'm trying to setup the IPv6 peer with no luck. Also important note here, I do not have native IPv6 from my ISP, I am utilizing Hurricane Electric's IPv6 tunnel broker, which is also working great on my LAN network. But for some reason the wireguard instance won't even attempt to try to handshake on IPv6.


Things I've tried
1. I can successfully ping the Mullvad Peer IP from the firewall console
2. Packet capture on my IPv6 WAN interface going to Hurricane Electric, absolutely no traffic even attempting on port 51820
3. Looking at the wireguard status, there is no sent bytes, like it's not even attempting to handshake.
4. Changed MTU settings on the gif interface and the wireguard instance.
5. I spun up OPNsense on a virtual machine behind my primary OPNsense and assigned it an IPv6 address from the primary LAN's subnet pool, so that way this from the perspective of this second firewall it's a native IPv6 connection from my ISP and not a tunnel. I put the exact same wireguard configuration in that one and it peered up instantly and works.

So my suspicion is either this just simply isn't supported, or there's a bug in OPNsense where the wireguard service isn't utilizing a gif interface as it's WAN connection.


My Configuration:
root@OPNsense:~ # wg show wg2
interface: wg2
  public key: (hidden)
  private key: (hidden)
  listening port: 51820

peer: (hidden)
  endpoint: [2a02:6ea0:d80b:3::b75f]:51820
  allowed ips: ::/0
  persistent keepalive: every 20 seconds



root@OPNsense:~ # cat /usr/local/etc/wireguard/wg2.conf
####################################################
# Interface settings, not used by `wg`             #
# Only used for reference and detection of changes #
# in the configuration                             #
####################################################
# Address =  fc00:bbbb:bbbb:bb01::9:5ecc/128
# DNS =
# MTU = 1420
# disableroutes = 1
# gateway =
# debug = 0

[Interface]
PrivateKey = (redacted)
ListenPort = 51820

[Peer]
# friendly_name = Mullvad_us-sea-wg-001-IPv6
PublicKey = (redacted)
Endpoint = 2a02:6ea0:d80b:3::b75f:51820
AllowedIPs = ::0/0
PersistentKeepalive = 20
#10
26.7 Series / Firewall Aliases – Function of...
Last post by wiring8228 - September 19, 2026, 11:46:34 PM
What does the 'Statistics' option, which has the description 'Maintain a set of counters for each table entry', actually do? Which counters is it referencing?

I can't see any change in Diagnostics > Aliases when I activate this option for an alias.
The following is the only documentation I could find about it: https://docs.opnsense.org/manual/diagnostics_firewall.html#aliases