Recent posts

#1
Zenarmor (Sensei) / tweaks that fixed my zenarmor ...
Last post by abenaou - Today at 08:38:34 PM
Hi all,

I just want to share with you some tunables that fixed repetitive crashes when using zenarmor in native mode, there is a warning that say you should be using the emulated mode, but that wasn't enough of an explanation for me, queuese would run out after a few hours and force an interface restart, after a lot of AI fu I was finally given the correct value, these won't work from the web interface as those are applied once the firewall has started which is already late, this works with i350-t4 cards :

cat /boot/loader.conf.local
dev.igb.0.iflib.override_ntxds="4096"
dev.igb.1.iflib.override_ntxds="4096"
dev.igb.2.iflib.override_ntxds="4096"
dev.igb.3.iflib.override_ntxds="4096"
dev.igb.0.iflib.override_nrxds="4096"
dev.igb.1.iflib.override_nrxds="4096"
dev.igb.2.iflib.override_nrxds="4096"
dev.igb.3.iflib.override_nrxds="4096"

dmes confirms the application of the new values :

[31] tun0: changing name to 'zen0'
[33] igb1: link state changed to UP
[34] igb0: link state changed to UP
[34] igb2: link state changed to UP
[35] igb3: link state changed to UP
[42] 137.783848 [ 805] iflib_netmap_config       txr 6 rxr 6 txd 4096 rxd 4096 rbufsz 2048
[42] 137.783906 [ 805] iflib_netmap_config       txr 6 rxr 6 txd 4096 rxd 4096 rbufsz 2048
[42] igb1: link state changed to DOWN
[42] igb0: link state changed to DOWN
[43] 138.429571 [ 805] iflib_netmap_config       txr 6 rxr 6 txd 4096 rxd 4096 rbufsz 2048
[43] 138.540666 [ 805] iflib_netmap_config       txr 6 rxr 6 txd 4096 rxd 4096 rbufsz 2048
[47] igb0: link state changed to UP
[47] igb1: link state changed to UP

as soon as I applied this, my issues were gone.
#2
26.7 Series / Re: Upgrade 26.7.1 to 26.7.1_1...
Last post by trdeal - Today at 08:29:28 PM
I have a backup firewall which was running 27.6 (and not been internet connected until tonight since the upgrade to 26.7) with the original firewall rules when I update it to 27.6.4_1 this evening the process completed successfully and all the rules with the aliases worked correctly, absolutely no issues.
However I still restored the backup from this morning to both firewalls would be running the same config.
#3
26.7 Series / Re: Firewall rules [new] missi...
Last post by Patrick M. Hausen - Today at 07:58:49 PM
When the new system was still new (in 26.1) it was named accordingly. Now (26.7) it's the default and named "Rules". The old UI is now named "Rules legacy" if you have the plugin installed.

Isn't all of this obvious? Do you expect the rules UI to be named "new" for eternity? Someone starting with OPNsense now will never know there once was a different one.
#4
German - Deutsch / Re: KI oder AI
Last post by k0ns0l3 - Today at 07:23:40 PM
Ich würde lieber in einer Welt ohne KI leben ;)) am liebste bediene ,Eingehenden Traffic und Ausgehenden Traffic.

lg
#5
Quote from: nero355 on Today at 06:08:33 PMIf it's Aquantia or RealTek and even Broadcom or Mellanox

That type of NIC is in the Desico appliances, like the DEC7xx or DEC8xx. It's from AMD and usually baked into the SoC.
#6
Quote from: ThomasE on September 14, 2026, 02:14:35 PMNIC: AMD 10GbE — pciconf: ax1@pci0:8:0:5 vendor=0x1022 device=0x1458
Driver: amd-xgbe, version 1.0.3, firmware 16.118.33
What is the actual chip being used for this "AMD" NIC ?!

If it's Aquantia or RealTek and even Broadcom or Mellanox then you have got a great chance it's driver related and you need to talk to FreeBSD developers/maintainers about it :)
#7
Hardware and Performance / Re: amd-xgbe ("ax"): interface...
Last post by TimS - Today at 06:04:46 PM
Quote from: BrandyWine on Today at 01:05:34 AMIs the cpu being fully offloaded to the NIC now?

You can try disabling this feature for individual NIC functions using sysctl.
Or use ifconfig ax1 -tso4 -tso6

So 1st try that.

To me it just sounds like a driver issue.

@BrandyWine thanks for the input.

TSO is already disabled on this interface.
The ifconfig ax1 output in the original post only shows:

Is the cpu being fully offloaded to the NIC now?

so neither TSO4 nor TSO6 is currently enabled. Checksum offloading and LRO are disabled as well.

That is also why I'm leaning more towards a driver/counter issue at this point. The interesting part is that inbound traffic is clearly present on ax1 in packet captures and is routed normally, while if_ibytes and the driver's RX byte counters essentially stay at zero.
TX accounting works.

The remaining thing I'd like to test is disabling HWSTATS, e.g.:

ifconfig ax1 -hwstats
to see whether FreeBSD then falls back to software accounting and the RX counter starts increasing.

Do you happen to know whether -hwstats is properly supported by amd-xgbe / iflib, and whether toggling it on a live interface causes any interface reinitialization or traffic interruption?
Because I suppose it does.

Thx!

Tim :)
#8
26.7 Series / Re: Firewall rules [new] missi...
Last post by nero355 - Today at 06:02:43 PM
Quote from: SVMartin80 on Today at 05:17:11 PMAnyone who could help this beginner?
It's at the bottom at the right and it's an icon with a small arrow in it I believe ?!

Also make sure the theme you are using isn't bugged and not showing it for whatever reason !!
Or your browser...
#9
26.7 Series / Re: Feature Request - Ability ...
Last post by nero355 - Today at 06:00:19 PM
Not going to happen : https://forum.opnsense.org/index.php?topic=52134.msg268594#msg268594 :)

As long as you boot in UEFI mode it's basically two simple commands that do the trick without any risk of writing to the wrong partition...

I did my first ever Bootloader upgrade this week and after reading a couple of topics here it was pretty easy!
#10
German - Deutsch / Re: OPNSense Anfänger braucht ...
Last post by Chr1sly - Today at 06:00:17 PM
Quote from: viragomann on September 15, 2026, 10:13:58 PMFür die Zugriffe auf deine Services würde ich empfehlen, das Caddy Plugin direkt auf OPNsense als Reverse Proxy zu nutzen. Das ist einfach einzurichten und holt sich auch die SSL Zertifikate von LE automatisch.

Danke für den Hinweis. Ich wusste nicht, dass es so ein Plugin gibt, ist halt meine erste OPNSense... 
NAT Regeln also... ich schätze, ich muss mir die FW nochmal etwas länger vornehmen und vielleicht auch mal im Admin Handbuch stöbern.
Ich finde das Benutzerinterface zwar logisch, aber auch recht zerklüftet... Da waren die Zywalls schon irgendwie einfacher zu administrieren.
Scheint, dass die Lernkurve doch etwas steiler ist als zunächst gedacht.

Jedenfalls Danke nochmal für den Hinweis... ich fuchse mich da mal ein.