Recent posts

#1
26.1, 26,4 Series / Re: samplicate pegging cpu
Last post by ubu - Today at 02:51:12 AM
{
    "@attributes": {
        "version": "1.0.1",
        "persisted_at": "1773874029.39",
        "description": "NetFlow configuration"
    },
    "capture": {
        "interfaces": "wan",
        "egress_only": "wan",
        "version": "v9",
        "targets": "127.0.0.1:2055,127.0.0.1:2056"
    },
    "collect": {
        "enable": "0"
    },
    "activeTimeout": "1800",
    "inactiveTimeout": "15"
}
#2
26.7 Series / Re: Can settings from ver OPNs...
Last post by seamus - Today at 02:30:21 AM
Quote from: lmoore on September 14, 2026, 11:00:00 AMFWIW, I would have installed 25.1 on the Backup firewall and using the Web GUI on Backup firewall, restored the configuration file created on the Primary, also using the Web GUI.

I did seriously consider that - and AFAIK, I've not surrendered any options yet - so I might still...  However, my thinking is currently running in the direction of taking a "bigger step" toward becoming "current". I am hoping that my network is simple enough that I don't take that big step in front of an oncoming bus :)  If you'd care to provide some background on your suggestion, I'd really like to hear that. FWIW, following is how I'm currently thinking on the path forward:

And as I said in my OP, my primary motivation for this effort is a hardware upgrade. I've still not decided what that hardware will be, but the low-end "Deciso" models are high on my list. I still need to evaluate the "throughput" of my current 10 yr-old SuperMicro hardware is... I think I can do this with 'iperf3'. But if that evaluation turns out as I think it will, I'll be "in the market" for at least one new server. And if I decide on a Deciso model, it will come with a current version of OPNsense pre-installed. So if this pans out as I expect, it would seem that an upgrade to the current version of OPNsense is inevitable.
#3
General Discussion / Anyone else hosting a small sc...
Last post by drewhartman - September 14, 2026, 08:48:28 PM
Hi everyone,

I've been running a small Roblox scripting site from my home network for the past few months, routing it through my OPNsense box with some basic traffic rules. It's a pretty low-traffic project (maybe a few hundred hits a day), but I wanted to make sure it doesn't interfere with my normal home bandwidth.

My setup is: OPNsense with a /24 from my ISP, the site runs on a small VPS but I port-forward for local dev testing. The website handles all the actual serving, my OPNsense side is just doing NAT and light QoS.

Curious if anyone else here has a similar setup - running a small web project through their home gateway and how you handle the traffic separation? I've got a simple firewall rule that tags the VPS IP and keeps it on a lower-priority queue, which seems to be working fine so far.

Would appreciate any tips on best practices for this kind of mixed traffic scenario. Happy to share my config rules if useful.

Thanks!
#4
General Discussion / Re: Rclone backup support
Last post by Patrick M. Hausen - September 14, 2026, 08:42:13 PM
Quote from: skittle6674 on September 14, 2026, 07:51:32 PMJust exactly this really. I just want to automate as much as possible, and currently use the Google drive option.

Git, Nextcloud and SFTP are not enough alternatives? 😉
#5
General Discussion / Re: [SOLVED] P2P gaming betwee...
Last post by Bob.Dig - September 14, 2026, 08:13:22 PM
Quote from: nero355 on September 14, 2026, 06:13:50 PMpoint me to a nice explanation
Here you go. Ok, it isn't that good but contains some info which is relevant here too. 

Although I doubt that it makes gaming better than static port does. It would only make a difference if your gaming clients would use the same UDP source ports. But why should they in the first place, these days that would be stupid.
I think Endpoint-independent Port Restricted Cone NAT is more for very big networks, maybe ISPs and their CG-NAT stuff etc.
#6
General Discussion / Re: Rclone backup support
Last post by skittle6674 - September 14, 2026, 07:51:32 PM
Quote from: Patrick M. Hausen on September 13, 2026, 01:27:47 PMWhat exactly are you intending to backup? There isn't much besides the config.xml, really.
Just exactly this really. I just want to automate as much as possible, and currently use the Google drive option.

Quote from: Lucid1010 on September 13, 2026, 01:23:00 PMhttps://rclone.org/downloads/

Since rclone uses a FreeBSD binary, you can run backups directly using a shell script.
I currently back up to Dropbox and S3 via rclone.
That's a good idea, I'll look into this option.
#7
26.7 Series / Re: Firmware upgrade from 26.1...
Last post by KHatfull - September 14, 2026, 07:41:52 PM
Last night (or should I say this morning, 3:00a is morning right?) I went from 26.7.1_1 to 26.7.3_11.  No issues.

  • os-intel-microcode not installed
  • removed theme plugins
  • grabbed a config export
  • ZFS snapshot
  • Ran the upgrade, one boot, all good
  • Copied the bootloader files to the secondary ZFS mirror disk
  • Rebooted, all good.

Process took less than 10 minutes.  All services just fine.

This is how I remember OPNsense upgrades going :)
#8
26.7 Series / Re: AQC107 aq0 + Suricata IPS/...
Last post by chr - September 14, 2026, 06:43:27 PM
Small update:

After disabling Services > Intrusion Detection / Suricata, aq0 no longer shows NETMAP in ifconfig options.

Before disabling IPS on WAN:
  aq0 options included NETMAP

After disabling IPS on WAN:
  options=4802028<VLAN_MTU,JUMBO_MTU,WOL_MAGIC,HWSTATS,MEXTPG>

It has now been stable for several hours with no new aq0 / atlantic / FLB / link reset messages in dmesg.

So this still looks like Suricata IPS/Netmap on the WAN interface triggering the aq/atlantic reinitialization loop after 26.7.3_11. Not sure if this is specific to AQC107 or a broader Netmap/driver interaction.
#9
General Discussion / Re: [SOLVED] P2P gaming betwee...
Last post by nero355 - September 14, 2026, 06:13:50 PM
Quote from: fornax on August 25, 2026, 10:50:15 PMwith OPNSense 26.7.2 this is now resolved via Endpoint-independent NAT.

That's it, no UPnP necessary.
NICE! :)

But could someone point me to a nice explanation about what 'Endpoint-independent NAT' does exactly ?!
#10
German - Deutsch / Re: DNS Setup mit Unbound, DNS...
Last post by Patrick M. Hausen - September 14, 2026, 06:07:26 PM
Dazu kommt doch, dass wir uns in dieser Runde hier gerade innerhalb von Deutschland unterhalten, jedenfalls meistens. Hier ist immer noch ein Rechtsstaat und es gilt die DSGVO. Von welchen ISPs reden wir denn bitte schön?

Was glaubst du wie die Kacke am Dampfen ist, wenn Telekom oder Vodafone dabei erwischt werden, wie sie shady Zeug mit dem Verkehr ihrer ISP-Kunden machen ...

Haben die nicht mal Malware-Filter eingebaut, ohne zu fragen, und das gab einen ziemlichen Shitstorm? Jedenfalls ist "Security on net" bei der Telekom heute erhältlich und optional. Kann ja jedes halten wie sie möchten.