Recent posts

#1
26.1 Series / No internet with WAN using Sta...
Last post by Yeff - Today at 11:15:04 PM
OPNsense "lab" router only connects to internet with OPNsense WAN on DHCP, won't connect when set to static.
IT kook here.
26.1 baremetal in my "learning lab" connected to internet via main router.
Main router port set to only 100.100.100.1/24.
OPNsense router will only connect to the internet when WAN on the OPNsense router is set to DHCP and not when set to say. 100.100.100.100.
If an OPNsense firewall rule is causing this, is there a way to see which rule is doing this?


Any suggestions why?


When I move the cable to a mac with static ip on the 100.100.100.1/24 subnet, it connects.

#2
General Discussion / Re: Support AmneziaWG
Last post by Patrick M. Hausen - Today at 10:35:20 PM
And why don't you just use Wireguard, if you control the firewall?

As far as I understand AmneziaWG is intentionally circumventing/bypassing corporate firewall and compliance policies. As such I would strongly recommend against including it in OPNsense.

If you control OPNsense just run WG.
#3
26.1 Series / Re: [Help] Multi-WAN Reply-to ...
Last post by ftani - Today at 10:33:10 PM
Sorry for being a little bit off topic here, but in the original post it was said "Internal AmneziaWG service hosted in the LAN.", can you share some details about how did you implemented it? I'm very interested in having AmneziaWG running on my network.
#4
General Discussion / Re: Can we expect support for ...
Last post by ftani - Today at 10:28:38 PM
But this would be a very interesting tool have in the box.
#5
General Discussion / Re: Support AmneziaWG
Last post by ftani - Today at 10:25:25 PM
This possibility is very exciting indeed. A WireGuard VPN protocol with features to protect it against DPI is something I can see myself having running around the clock on my Firewall.
#6
General Discussion / Re: AmneziaWG on OPNsense and ...
Last post by ftani - Today at 10:13:58 PM
It is simply perfect that you are working on AmneziaWG on OPNsense, currently I'm using this VPN protocol through desktop apps and since I have to connect a few devices at a time, it is only logical to seek to install it in the Firewall. :)

I'm looking very forward to your news about it.
#7
26.1 Series / Re: MiniUPNPD
Last post by doubletakex - Today at 09:14:46 PM
I'm on 26.1.2_5 and I seem to be having the same issue. I did not manually install the patch.
#8
26.1 Series / Re: move anti-lockout rules to...
Last post by grb - Today at 08:40:13 PM
Right, thanks for screenshot, that will help a lot.
I was trying to replicate those 3 rules, in Destination NAT. Having in mind that, they exists for a reason.
I understand that I could block myself If I will forward 443 or 80 then I could block myself.
You cannot view this attachment.
This is what I'm struggling with to recreate.
#9
26.1 Series / Re: Enable SSH at Console
Last post by Nephiria - Today at 08:08:56 PM
Have you tried restoring a backup? As far as I know, they are created by default after every change, and you can also do this from the console.
#10
26.1 Series / Some Widget not working on Das...
Last post by Nephiria - Today at 07:46:44 PM
Hi All,

i have some Widget on Dashboard that is not working.
Anyone have a Solution for that?

Look here:

https://ibb.co/LdFFMj5p

https://ibb.co/rRjZBBTc

My Hardware Specs:

---<<BOOT>>---
Copyright (c) 1992-2023 The FreeBSD Project.
Copyright (c) 1979, 1980, 1983, 1986, 1988, 1989, 1991, 1992, 1993, 1994
        The Regents of the University of California. All rights reserved.
FreeBSD is a registered trademark of The FreeBSD Foundation.
FreeBSD 14.3-RELEASE-p8 stable/26.1-n271977-c961e158e272 SMP amd64
FreeBSD clang version 19.1.7 (https://github.com/llvm/llvm-project.git llvmorg-19.1.7-0-gcd708029e0b2)
[1] VT(vga): resolution 640x480
[1] CPU microcode: updated from 0x1d to 0x24000026
[1] CPU: Intel(R) Celeron(R) N5105 @ 2.00GHz (1996.80-MHz K8-class CPU)
[1]   Origin="GenuineIntel"  Id=0x906c0  Family=0x6  Model=0x9c  Stepping=0
[1]   Features=0xbfebfbff<FPU,VME,DE,PSE,TSC,MSR,PAE,MCE,CX8,APIC,SEP,MTRR,PGE,MCA,CMOV,PAT,PSE36,CLFLUSH,DTS,ACPI,MMX,FXSR,SSE,SSE2,SS,HTT,TM,PBE>
[1]   Features2=0x4ff8ebbf<SSE3,PCLMULQDQ,DTES64,MON,DS_CPL,VMX,EST,TM2,SSSE3,SDBG,CX16,xTPR,PDCM,SSE4.1,SSE4.2,x2APIC,MOVBE,POPCNT,TSCDLT,AESNI,XSAVE,OSXSAVE,RDRAND>
[1]   AMD Features=0x28100800<SYSCALL,NX,RDTSCP,LM>
[1]   AMD Features2=0x101<LAHF,Prefetch>
[1]   Structured Extended Features=0x2394a2c3<FSGSBASE,TSCADJ,FDPEXC,SMEP,ERMS,NFPUSG,PQE,RDSEED,SMAP,CLFLUSHOPT,CLWB,PROCTRACE,SHA>
[1]   Structured Extended Features2=0x18400124<UMIP,WAITPKG,GFNI,RDPID,MOVDIRI,MOVDIR64B>
[1]   Structured Extended Features3=0xfc000400<MD_CLEAR,IBPB,STIBP,L1DFL,ARCH_CAP,CORE_CAP,SSBD>
[1]   XSAVE Features=0xf<XSAVEOPT,XSAVEC,XINUSE,XSAVES>
[1]   IA32_ARCH_CAPS=0x14020c6b<RDCL_NO,IBRS_ALL,SKIP_L1DFL_VME,MDS_NO>
[1]   VT-x: PAT,HLT,MTF,PAUSE,EPT,UG,VPID,VID,PostIntr
[1]   TSC: P-state invariant, performance statistics
[1] real memory  = 17179869184 (16384 MB)
[1] avail memory = 16403177472 (15643 MB)
[1] Event timer "LAPIC" quality 600
[1] ACPI APIC Table: <ALASKA A M I >
[1] WARNING: L1 data cache covers fewer APIC IDs than a core (0 < 1)
[1] FreeBSD/SMP: Multiprocessor System Detected: 4 CPUs
[1] FreeBSD/SMP: 1 package(s) x 4 core(s)
[1] random: registering fast source Intel Secure Key RNG
[1] random: fast provider: "Intel Secure Key RNG"
[1] random: unblocking device.
[1] ioapic0 <Version 2.0> irqs 0-119
[1] Launching APs: 2 1 3
[1] random: entropy device external interface
[1] wlan: mac acl policy registered
[1] kbd1 at kbdmux0
[1] WARNING: Device "spkr" is Giant locked and may be deleted before FreeBSD 15.0.
[1] efirtc0: <EFI Realtime Clock>
[1] efirtc0: registered as a time-of-day clock, resolution 1.000000s
[1] smbios0: <System Management BIOS> at iomem 0x78d7a000-0x78d7a017
[1] smbios0: Entry point: v3 (64-bit), Version: 3.3
[1] aesni0: <AES-CBC,AES-CCM,AES-GCM,AES-ICM,AES-XTS,SHA1,SHA256>
[1] acpi0: <ALASKA A M I >
[1] acpi0: Power Button (fixed)
[1] cpu0: <ACPI CPU> on acpi0
[1] hpet0: <High Precision Event Timer> iomem 0xfed00000-0xfed003ff on acpi0
[1] Timecounter "HPET" frequency 19200000 Hz quality 950
[1] Event timer "HPET" frequency 19200000 Hz quality 550
[1] Event timer "HPET1" frequency 19200000 Hz quality 440
[1] Event timer "HPET2" frequency 19200000 Hz quality 440
[1] Event timer "HPET3" frequency 19200000 Hz quality 440
[1] Event timer "HPET4" frequency 19200000 Hz quality 440
[1] atrtc1: <AT realtime clock> on acpi0
[1] atrtc1: Warning: Couldn't map I/O.
[1] atrtc1: registered as a time-of-day clock, resolution 1.000000s
[1] Event timer "RTC" frequency 32768 Hz quality 0
[1] attimer0: <AT timer> port 0x40-0x43,0x50-0x53 irq 0 on acpi0
[1] Timecounter "i8254" frequency 1193182 Hz quality 0
[1] Event timer "i8254" frequency 1193182 Hz quality 100
[1] Timecounter "ACPI-fast" frequency 3579545 Hz quality 900
[1] acpi_timer0: <24-bit timer at 3.579545MHz> port 0x1808-0x180b on acpi0
[1] pcib0: <ACPI Host-PCI bridge> port 0xcf8-0xcff on acpi0
[1] pci0: <ACPI PCI bus> on pcib0
[1] vgapci0: <VGA-compatible display> port 0x3000-0x303f mem 0x6000000000-0x6000ffffff,0x4000000000-0x400fffffff at device 2.0 on pci0
[1] vgapci0: Boot video device
[1] xhci0: <XHCI (generic) USB 3.0 controller> mem 0x6001100000-0x600110ffff at device 20.0 on pci0
[1] xhci0: 32 bytes context size, 64-bit DMA
[1] usbus0 on xhci0
[1] usbus0: 5.0Gbps Super Speed USB v3.0
[1] pci0: <memory, RAM> at device 20.2 (no driver attached)
[1] pci0: <simple comms> at device 22.0 (no driver attached)
[1] ahci0: <AHCI SATA controller> port 0x3090-0x3097,0x3080-0x3083,0x3060-0x307f mem 0x80800000-0x80801fff,0x80803000-0x808030ff,0x80802000-0x808027ff at device 23.0 on pci0
[1] ahci0: AHCI v1.31 with 2 6Gbps ports, Port Multiplier not supported
[1] ahcich0: <AHCI channel> at channel 0 on ahci0
[1] ahcich1: <AHCI channel> at channel 1 on ahci0
[1] pcib1: <ACPI PCI-PCI bridge> at device 28.0 on pci0
[1] pci1: <ACPI PCI bus> on pcib1
[1] igc0: <Intel(R) Ethernet Controller I226-V> mem 0x80600000-0x806fffff,0x80700000-0x80703fff at device 0.0 on pci1
[1] igc0: EEPROM V2.14-0 eTrack 0x80000290
[1] igc0: Using 2048 TX descriptors and 2048 RX descriptors
[1] igc0: Using 4 RX queues 4 TX queues
[1] igc0: Using MSI-X interrupts with 5 vectors
[1] igc0: Ethernet address: 60:be:b4:0d:88:c6
[1] igc0: netmap queues/slots: TX 4/2048, RX 4/2048
[1] pcib2: <ACPI PCI-PCI bridge> at device 28.3 on pci0
[1] pci2: <ACPI PCI bus> on pcib2
[1] igc1: <Intel(R) Ethernet Controller I226-V> mem 0x80400000-0x804fffff,0x80500000-0x80503fff at device 0.0 on pci2
[1] igc1: EEPROM V2.14-0 eTrack 0x80000290
[1] igc1: Using 1024 TX descriptors and 1024 RX descriptors
[1] igc1: Using 4 RX queues 4 TX queues
[1] igc1: Using MSI-X interrupts with 5 vectors
[1] igc1: Ethernet address: 60:be:b4:0d:88:c7
[1] igc1: netmap queues/slots: TX 4/1024, RX 4/1024
[1] pcib3: <ACPI PCI-PCI bridge> at device 28.4 on pci0
[1] pci3: <ACPI PCI bus> on pcib3
[1] igc2: <Intel(R) Ethernet Controller I226-V> mem 0x80200000-0x802fffff,0x80300000-0x80303fff at device 0.0 on pci3
[1] igc2: EEPROM V2.14-0 eTrack 0x80000290
[1] igc2: Using 1024 TX descriptors and 1024 RX descriptors
[1] igc2: Using 4 RX queues 4 TX queues
[1] igc2: Using MSI-X interrupts with 5 vectors
[1] igc2: Ethernet address: 60:be:b4:0d:88:c8
[1] igc2: netmap queues/slots: TX 4/1024, RX 4/1024
[1] pcib4: <ACPI PCI-PCI bridge> at device 28.5 on pci0
[1] pci4: <ACPI PCI bus> on pcib4
[1] igc3: <Intel(R) Ethernet Controller I226-V> mem 0x80000000-0x800fffff,0x80100000-0x80103fff at device 0.0 on pci4
[1] igc3: EEPROM V2.14-0 eTrack 0x80000290
[1] igc3: Using 1024 TX descriptors and 1024 RX descriptors
[1] igc3: Using 4 RX queues 4 TX queues
[1] igc3: Using MSI-X interrupts with 5 vectors
[1] igc3: Ethernet address: 60:be:b4:0d:88:c9
[1] igc3: netmap queues/slots: TX 4/1024, RX 4/1024
[1] pcib5: <ACPI PCI-PCI bridge> at device 28.6 on pci0
[1] pci5: <ACPI PCI bus> on pcib5
[1] igc4: <Intel(R) Ethernet Controller I226-V> mem 0x7fe00000-0x7fefffff,0x7ff00000-0x7ff03fff at device 0.0 on pci5
[1] igc4: EEPROM V2.14-0 eTrack 0x80000290
[1] igc4: Using 1024 TX descriptors and 1024 RX descriptors
[1] igc4: Using 4 RX queues 4 TX queues
[1] igc4: Using MSI-X interrupts with 5 vectors
[1] igc4: Ethernet address: 60:be:b4:0d:88:ca
[1] igc4: netmap queues/slots: TX 4/1024, RX 4/1024
[1] pcib6: <ACPI PCI-PCI bridge> at device 28.7 on pci0
[1] pci6: <ACPI PCI bus> on pcib6
[1] igc5: <Intel(R) Ethernet Controller I226-V> mem 0x7fc00000-0x7fcfffff,0x7fd00000-0x7fd03fff at device 0.0 on pci6
[1] igc5: EEPROM V2.14-0 eTrack 0x80000290
[1] igc5: Using 1024 TX descriptors and 1024 RX descriptors
[1] igc5: Using 4 RX queues 4 TX queues
[1] igc5: Using MSI-X interrupts with 5 vectors
[1] igc5: Ethernet address: 60:be:b4:0d:88:cb
[1] igc5: netmap queues/slots: TX 4/1024, RX 4/1024
[1] isab0: <PCI-ISA bridge> at device 31.0 on pci0
[1] isa0: <ISA bus> on isab0
[1] hdac0: <Intel Jasper Lake HDA Controller> mem 0x6001120000-0x6001123fff,0x6001000000-0x60010fffff at device 31.3 on pci0
[1] pci0: <serial bus> at device 31.5 (no driver attached)
[1] acpi_button0: <Sleep Button> on acpi0
[1] acpi_button1: <Power Button> on acpi0
[1] acpi_tz0: <Thermal Zone> on acpi0
[1] atkbdc0: <Keyboard controller (i8042)> port 0x60,0x64 irq 1 on acpi0
[1] atkbd0: <AT Keyboard> irq 1 on atkbdc0
[1] kbd0 at atkbd0
[1] atkbd0: [GIANT-LOCKED]
[1] ns8250: UART FCR is broken
[1] ns8250: UART FCR is broken
[1] uart0: <16550 or compatible> port 0x3f8-0x3ff irq 4 flags 0x10 on acpi0
[1] ns8250: UART FCR is broken
[1] uart0: console (115200,n,8,1)
[1] ns8250: UART FCR is broken
[1] ns8250: UART FCR is broken
[1] uart1: <16550 or compatible> port 0x2f8-0x2ff irq 3 on acpi0
[1] acpi_syscontainer0: <System Container> on acpi0
[1] acpi_syscontainer1: <System Container> on acpi0
[1] atrtc0: <AT realtime clock> at port 0x70 irq 8 on isa0
[1] atrtc0: Warning: Couldn't map I/O.
[1] atrtc0: registered as a time-of-day clock, resolution 1.000000s
[1] atrtc0: Can't map interrupt.
[1] hwpstate_intel0: <Intel Speed Shift> on cpu0
[1] cpufreq0: <CPU frequency control> on cpu0
[1] hwpstate_intel1: <Intel Speed Shift> on cpu1
[1] cpufreq1: <CPU frequency control> on cpu1
[1] hwpstate_intel2: <Intel Speed Shift> on cpu2
[1] cpufreq2: <CPU frequency control> on cpu2
[1] hwpstate_intel3: <Intel Speed Shift> on cpu3
[1] cpufreq3: <CPU frequency control> on cpu3
[1] Timecounter "TSC" frequency 1996803693 Hz quality 1000
[1] Timecounters tick every 1.000 msec
[2] ZFS filesystem version: 5
[2] ZFS storage pool version: features support (5000)
[2] hdacc0: <Intel Jasper Lake HDA CODEC> at cad 2 on hdac0
[2] hdaa0: <Intel Jasper Lake Audio Function Group> at nid 1 on hdacc0
[2] pcm0: <Intel Jasper Lake (HDMI/DP 8ch)> at nid 4 on hdaa0
[2] ada0 at ahcich0 bus 0 scbus0 target 0 lun 0
ada0: <FORESEE 128GB SSD V4.30.2> ACS-3 ATA SATA 3.x device
ada0: Serial Number NEH437Q011880
ada0: 600.000MB/s transfers (SATA 3.x, UDMA6, PIO 512bytes)
ada0: Command Queueing enabled
ada0: 122104MB (250069680 512 byte sectors)
[2] Trying to mount root from zfs:zroot/ROOT/default []...
[2] ugen0.1: <Intel XHCI root HUB> at usbus0
[2] uhub0 on usbus0
[2] uhub0: <Intel XHCI root HUB, class 9/0, rev 3.00/1.00, addr 1> on usbus0
[3] uhub0: 14 ports with 14 removable, self powered
[3] Mounting filesystems...
[3] no pools available to import
[3] Setting hostuuid: 42bc2e5c-b51b-43ee-9591-352745e081b5.
[3] Setting hostid: 0x96ca5550.
[3] Configuring vt: keymap.
[3] >>> Invoking import script 'importer'
[3] Configuring crash dump device: /dev/ada0p3
[3] swapon: adding /dev/ada0p3 as swap device
[3] .ELF ldconfig path: /lib /usr/lib /usr/lib/compat /usr/local/lib /usr/local/lib/compat/pkg /usr/local/lib/compat/pkg /usr/local/lib/ipsec /usr/local/lib/perl5/5.42/mach/CORE
[3] 32-bit compatibility ldconfig path:
[3] done.
[4] >>> Invoking early script 'upgrade'
[4] >>> Invoking early script 'configd'
[4] Starting configd.
[5] >>> Invoking early script 'templates'
[5] Generating configuration: templates...done
[10] >>> Invoking early script 'backup'
[10] >>> Invoking backup script 'captiveportal'
[10] >>> Invoking backup script 'netflow'
[10] >>> Invoking backup script 'rrd'
[12] >>> Invoking early script 'carp'
[12] CARP event system: OK
[12] Launching the init system...done.
[12] Initializing..........done.
[13] igc0: link state changed to UP
[13] igc1: link state changed to UP
[13] igc2: link state changed to UP
[14] Starting device manager...
[14] acpi_wmi0: <ACPI-WMI mapping> on acpi0
[14] acpi_wmi0: cannot find EC device
[14] acpi_wmi0: Embedded MOF found
[14] ACPI: \134_SB.WFDE.WQCC: 1 arguments were passed to a non-method ACPI object (Buffer) (20221020/nsarguments-361)
[14] acpi_wmi1: <ACPI-WMI mapping> on acpi0
[14] acpi_wmi1: cannot find EC device
[14] acpi_wmi1: Embedded MOF found
[14] ACPI: \134_SB.WFTE.WQCC: 1 arguments were passed to a non-method ACPI object (Buffer) (20221020/nsarguments-361)
[16] done.
[16] Configuring login behaviour...done.
[17] Configuring loopback interface...
[17] lo0: link state changed to UP
[17] done.
[17] Configuring kernel modules...
[17] qat_ocf0: <QAT engine>
[17] done.
[17] Setting up extended sysctls...done.
[17] Setting timezone: Europe/Zurich
[17] Writing firmware settings: FreeBSD OPNsense
[17] Writing trust files...done.
[17] Scanning /usr/share/certs/untrusted for certificates...
Scanning /usr/share/certs/trusted for certificates...
Scanning /usr/local/share/certs for certificates...
[17] certctl: Modified 192 trust store links.
[17] Writing trust bundles...done.
[18] Setting hostname: opensense01.freenet.dom
[18] Generating /etc/resolv.conf...done.
[18] Generating /etc/hosts...done.
[18] Configuring system logging...done.
[18] Configuring firewall.......done.
[19] Configuring hardware interfaces...done.
[19] Configuring loopback interface...done.
[19] Configuring LAGG interfaces...done.
[19] Configuring VLAN interfaces...done.
[19] Configuring ISCSI interface...
[19] igc2: link state changed to DOWN
[19] done.
[19] Configuring LAN interface...
[19] igc1: link state changed to DOWN
[19] done.
[19] Configuring WAN interface...
[19] igc0: link state changed to DOWN
[19] done.
[20] Generating /etc/resolv.conf...done.
[20] Generating /etc/hosts...done.
[20] Configuring firewall.......done.
[20] Configuring OpenSSH...done.
[20] Starting web GUI...done.
[20] Setting up routes...done.
[21] Starting Unbound DNS...done.
[22] Configuring firewall.....
[22] igc0: link state changed to UP
[22] igc2: link state changed to UP
[22] ..
[22] igc1: link state changed to UP
[23] done.
[23] Setting up gateway monitor...done.
[23] Syncing OpenVPN settings...done.
[23] Configuring WireGuard VPN...
[23] wg0: link state changed to UP
[23] done.
[23] Starting DHCP relays...done.
[23] Starting NTP service...done.
[23] Starting Unbound DNS...
[24] done.
[24] >>> Invoking start script 'newwanip'
[24] >>> Invoking start script 'freebsd'
[24] setup igc2
[24] setup igc1
[24] error : interface opt5 not found
[24] error : interface opt3 not found
[24] error : interface opt1 not found
[25] Starting acme_http_challenge.
[25] Starting hostwatch.
[25] Starting redis.
[25] Starting clamav_clamd.
[38] Starting haproxy.
[38] Starting rspamd.
[38] 2026-02-20 12:10:09 #38576(main) <8060fd>; main; main: rspamd 3.14.0 is loading configuration, build id: release
[38] Starting clamav_freshclam.
[39] Updating aliases
[39] Certificates generated /usr/local/etc/postfix/cert_opn.pem
[39] Certificates generated /usr/local/etc/postfix/ca_opn.pem
[39] postfix: Postfix is using backwards-compatible default settings
[39] postfix: See https://www.postfix.org/COMPATIBILITY_README.html for details
[39] postfix: To disable backwards compatibility use "postconf compatibility_level=3.6" and "postfix reload"
[39] /usr/local/sbin/postconf: warning: /usr/local/etc/postfix/main.cf: support for parameter "smtpd_tls_dh1024_param_file" will be removed; instead, do not specify (leave at default)
[39] /usr/local/sbin/postconf: warning: /usr/local/etc/postfix/main.cf: support for parameter "smtpd_use_tls" will be removed; instead, specify "smtpd_tls_security_level"
[39] postfix/postfix-script: starting the Postfix mail system
[39] >>> Invoking start script 'syslog'
[39] >>> Invoking start script 'haproxy'
[39] >>> Invoking start script 'carp'
[39] >>> Invoking start script 'cron'
[39] Starting Cron: OK
[40] >>> Invoking start script 'openvpn'
[40] >>> Invoking start script 'sysctl'
[41] Service `sysctl' has been restarted.
[41] >>> Invoking start script 'beep'
[42] Root file system: zroot/ROOT/default
[42] Fri Feb 20 12:10:13 CET 2026
[42]
*** XXX:  OPNsense 26.1.2_5 (amd64) ***

Thats my Firewall that i have buy for some Years.
https://www.amazon.de/dp/B0B4P354QG

I hope now i have all Informationen submited.

Thanks all.