Recent posts

#1
Zenarmor (Sensei) / How to block Firefox VPN
Last post by kkeller - Today at 12:51:07 AM
So Firefox rolled out early this year an integrated free VPN in their browser that bypasses the Zenarmor policies. I have every Proxy in the policy blocked and it still is working. Is there going to be a policy update to block the Firefox VPN?
#2
26.7 Series / Re: nfSensei ( fork pfsense )
Last post by Lucid1010 - Today at 12:19:57 AM
where is code?
#3
26.7 Series / Re: VLAN devices are on LAN IP...
Last post by tonys - August 07, 2026, 11:38:00 PM
Quote from: dseven on August 07, 2026, 09:13:34 AMHave you reboot (opnsense) since eliminating the bridge? There may be some artifact from it lurking somewhere.

Otherwise try this tcpdump to see "what's happening on the wire":

tcpdump -nnvvei igc0 '(ether host aa:bb:cc:dd:ee:ff and port 67) or (vlan and ether host aa:bb:cc:dd:ee:ff and port 67)'

Substitute the MAC address of a Guest or IoT device (in two places), and make it (re)connect.

Feedback:
- OPNSense router has been rebooted MANY times since removing the bridge

- This wireless device is supposed to be on the IoT VLAN (192.168.40.x). It used to be under v21 and earlier, but now it keeps reconnecting to the LAN. The Roku screen shows it's on the IoT network WITH theTHE IoT password (very different from the LAN password) but it keeps getting a LAN IP. The Unifi wireless AP also shows it on the IoT network which it must be because I gave it the IoT password. Yet it got a LAN IP. ??

tcpdump -nnvvei igc0 '(ether host d4:be:dc:20:de:dd and port 67) or (vlan and ether host d4:be:dc:20:de:dd and port 67)'
tcpdump: listening on igc0, link-type EN10MB (Ethernet), snapshot length 262144 bytes
16:24:11.301381 d4:be:dc:20:de:dd > ff:ff:ff:ff:ff:ff, ethertype IPv4 (0x0800), length 590: (tos 0x0, ttl 64, id 0, offset 0, flags [none], proto UDP (17), length 576)
    0.0.0.0.68 > 255.255.255.255.67: [udp sum ok] BOOTP/DHCP, Request from d4:be:dc:20:de:dd, length 548, xid 0x70cd0629, Flags [none] (0x0000)
     Client-Ethernet-Address d4:be:dc:20:de:dd
     Vendor-rfc1048 Extensions
       Magic Cookie 0x63825363
       DHCP-Message (53), length 1: Request
       Requested-IP (50), length 4: 192.168.1.127
       Parameter-Request (55), length 5:
         Subnet-Mask (1), Default-Gateway (3), Domain-Name-Server (6), Domain-Name (15)
         Hostname (12)
       Hostname (12), length 9: "RokuUltra"
16:24:11.301551 64:62:66:22:4c:ab > d4:be:dc:20:de:dd, ethertype IPv4 (0x0800), length 342: (tos 0x10, ttl 128, id 0, offset 0, flags [none], proto UDP (17), length 328)
    192.168.1.1.67 > 192.168.1.127.68: [udp sum ok] BOOTP/DHCP, Reply, length 300, xid 0x70cd0629, Flags [none] (0x0000)
     Your-IP 192.168.1.127
     Client-Ethernet-Address d4:be:dc:20:de:dd
     Vendor-rfc1048 Extensions
       Magic Cookie 0x63825363
       DHCP-Message (53), length 1: ACK
       Server-ID (54), length 4: 192.168.1.1
       Lease-Time (51), length 4: 5452
       Subnet-Mask (1), length 4: 255.255.255.0
       Default-Gateway (3), length 4: 192.168.1.1
       Domain-Name-Server (6), length 4: 192.168.1.1
       Domain-Name (15), length 8: "home.lan"
#4
German - Deutsch / Re: Hilfe zu VPN Client in OPN...
Last post by diabolo511 - August 07, 2026, 11:20:18 PM
Okay für mich war das eigentlich relativ logisch zwecks DNS.
Ich möchte nur, das die VPN Clients den Mullvad DNS nutzen, der Rest geht seinen regulären Weg.

Es sei dazu auch gesagt das ich echt kein Profi bin und auch noch einiges zu lernen hab.

Der Client ist so eingestellt, das der Mullvad DNS über den VPN genutzt werden soll.
Das mit der Gateway Regel muss ich mir selber noch mal anschauen, konnte die Woche über nicht daran arbeiten.
#5
26.7 Series / legacy ipsec settings on 26.7....
Last post by tentpig - August 07, 2026, 11:00:03 PM
Just converted from pfSense to Opnsense. Running 26.7.1_1.

have a client with some legacy ipsec gear I need to connect to. They are set up with AES 256 SHA1 DH2.

I cannot see how to configure this in the GUI.

Can someone provide guidance? Googling yields instructions which don't correspond to anything I see on the screen, so I assume they're for an older version of the software.
#6
General Discussion / Re: Only subnet with OPNSense ...
Last post by daboxx - August 07, 2026, 10:50:12 PM
Thank you sir!    I changed NAT to hybrid and added the LAN alias and now other subnets can get out.   

I thought all addresses on the LAN would get out, but you were correct adjusting NAT fixed it.

Thanks again! 
#7
26.7 Series / Re: Internal DNS only works fo...
Last post by Patrick M. Hausen - August 07, 2026, 10:42:47 PM
Don't run a NAS dual homed.
#8
General Discussion / Re: Only subnet with OPNSense ...
Last post by viragomann - August 07, 2026, 10:26:09 PM
If the switch doesn't nat outgoing traffic to the gateway, you have to add source NAT rules to WAN for the local networks behind it.

OPNsense creates such rules automatically, but only for subnets defined on its interfaces.
#9
German - Deutsch / Re: Hilfe zu VPN Client in OPN...
Last post by viragomann - August 07, 2026, 09:43:54 PM
Quote from: diabolo511 on August 07, 2026, 09:03:03 PMEin ping auf die reine IP Adresse geht raus, auf die Domain aber nicht.
Den Grund dafür hast du doch eh schon erkannt. Du kannst keine Hostnamen auflösen, kein DNS.

Quote from: diabolo511 on August 07, 2026, 09:03:03 PMIch habe einen Alias über den ich einzelne Clients über den VPN schicken möchte.
Also nochmal: Je nachdem, welche Regel du sonst noch hast, schickt diese Gateway-Regel möglicherweise auch DNS Requests auf das Gateway.
Hier hast du nichts dazu erklärt.

Ich nehme aber an, dass dein Client so konfiguriert ist, dass er OPNsense als DNS verwendet. D.h. die LAN IP der Firewall.
Nun, wenn du diesen Request auf den VPN Server schickst, wird das Paket dort verworfen, weil da die Ziel-IP unbekannt ist.

Quote from: diabolo511 on August 07, 2026, 09:03:03 PMJa, man kann einen DNS Server in Wireguard in die config eintragen.
Das kenne ich nicht. Wenn dann würde so etwas dem VPN Client, also OPNsense, diesen DNS-Server zuweisen, wenn die Verbindung hergestellt wird.
Das würde aber nur funktionieren, wenn du den lokalen DNS im Forwarder-Modus betreibst. Und ggf. braucht das auch noch eine Route, kommt auf die Ziel-IP an.

Das obige ist vielleicht gar nicht das, was du möchtest. Ob du alle DNS-Anfragen auf Mullvad schicken möchtest, oder nur die im der Clients im Alias, hast du nicht verraten.
Wie auch immer, eine einfache Methode, die Request auf den gewünschten Server und auch über die VPN zu schicken, ist sie einfach mit einer NAT-Regel weiterzuleiten. Allerdings kannst du dann keine lokalen Namen mehr auflösen. Ist das gewünscht, muss du das interne DNS entsprechend konfigurieren. Was verwendest du da?

Quote from: diabolo511 on August 07, 2026, 09:03:03 PMWelchen Fehler hat der Mann begangen? Wär cool wenn man sowas auflösen kann.
Die WAN-Regel, die sicherstellen soll, dass kein Traffic anderswo hingeht als auf den Mullvad Server hat er für eingehenden Traffic erstellt. Die hätte Direction out haben sollen. Erwähnt hat er es.

Überdies bin ich mir gar nicht sicher, ob dies Regel überhaupt funktionieren würde, ob diese die IP Adressen im Alias überhaupt sieht.
#10
26.7 Series / Re: Internal DNS only works fo...
Last post by tangofan - August 07, 2026, 09:28:04 PM
Quote from: rheilke on August 07, 2026, 07:35:53 PMOnce again, the great thing about standards is that there are so many of them. :/

But wait, there is more! I had a similar problem in my network that non-fqdn requests from my Windows 11 client to my TrueNAS server didn't work properly. The culprit here was that apparently Windows 11 uses mDNS by default. And the TrueNAS server had two network interfaces and returned two IPv4 adresses, but Windows picked the wrong one. I had to disable the mDNS server on TrueNAS to get this to work.