Quote from: Erhesar on November 26, 2025, 11:28:47 PMВ interfaces: overview он присутсвует, но помечен как down
root@OPNsense:~ # ls -la /usr/local/etc/rc.syshook.d/early/
total 28
drwxr-xr-x 2 root wheel 8 Mar 4 05:50 .
drwxr-xr-x 12 root wheel 12 Dec 28 10:48 ..
-rwxr-xr-x 1 root wheel 137 Feb 11 17:58 05-upgrade
-rwxr-xr-x 1 root wheel 63 Feb 11 17:58 10-configd
-rwxr-xr-x 1 root wheel 95 Feb 11 17:58 15-templates
-rwxr-xr-x 1 root wheel 93 Feb 11 17:58 20-backup
-rw-r--r-- 1 root wheel 74 Jan 21 13:09 50-tun2socks
-rwxr-xr-x 1 root wheel 631 Feb 11 17:58 90-carproot@OPNsense:~ # chmod +x /usr/local/etc/rc.syshook.d/early/50-tun2socksQuote from: OPNenthu on March 03, 2026, 09:23:27 PM[...]I want to try this myself but the ping command you gave doesn't work in OPNsense.[...]
Microsoft Windows [Version 10.0.19045.4529]
(c) Microsoft Corporation. All rights reserved.
C:\Users\User>ping google.com -f -l 1472
Pinging google.com [142.251.116.102] with 1472 bytes of data:
Reply from 142.251.116.102: bytes=1472 time=19ms TTL=104
Reply from 142.251.116.102: bytes=1472 time=14ms TTL=104
Reply from 142.251.116.102: bytes=1472 time=19ms TTL=104
Reply from 142.251.116.102: bytes=1472 time=19ms TTL=104
Ping statistics for 142.251.116.102:
Packets: Sent = 4, Received = 4, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
Minimum = 14ms, Maximum = 19ms, Average = 17ms
C:\Users\User>
Quote from: Sisko on March 03, 2026, 10:08:58 AM[,,,]I also recently replaced my ISP's cable modem /w a Netgear CM2000 which meets and exceeds the specs of the ISP's modem.[...]
Quote from: falken on March 03, 2026, 09:28:24 PMI can't find anything official on how it should handle "blank" subnets, but the method right now is it will parse any lists that are blank in addition to any other policy it did match on. I agree if nothing else, it should be a feature request.
QuoteAs far as forcing the route though the GUA to get there, you would have needed to add a firewall rule to allow that behavior, otherwise it wouldn't route. DNS is also not a security feature. They can also just type the IP in directly, add it their local hosts file, or many other various methods
Quote from: senseOPN on March 03, 2026, 09:27:56 PMBUT, in my Interfaces below the old rules, I still see "Floating rules" and those are clearly MY floating rules, not automatically created!I can't tell from your screenshot what those Floating rules are but I think they would all be yours. System-generated and automatic rules go into their own categories.
They seem to be the same as from the new rules, at least I can see one new rule that I added in the new rules section after the upgrade.
But they have no Delete button.
Quote from: senseOPN on March 03, 2026, 09:27:56 PMThis seems to be a fundamental change to before, where changing such things would never change the priority (rule-number)!
And, I cannot have "late" rules anymore for more than one Interface! Now, such a rule get's moved to the front.