Recent posts

#1
26.7 Series / Re: Confused by 26.7 upgrade
Last post by defaultuserfoo - Today at 05:05:58 AM
Quote from: franco on September 08, 2026, 08:56:50 AM> Apparently the rules didn't continue to work.

You're convoluting your experience with the technical facts in this particular case. It's futile to go into an argument like that.


Cheers,
Franco

I'm not convoluting anything.  IIUC, someone created this thread when he found that he can not enable or disable firewall rules after an upgrade anymore, and was advised to install a plug-in to fix that.  I haven't made this experience, but I made the experience that the firewall rules didn't work after the migration and had all to be redone.  After the painful experience, I was told that it would take many years to come before the migration would be necessary.  In spite of that, now apparently everyone who wants to be able to enable or disable firewall rules needs to do some kind of migration, even if it is only to install the plug-in.

Don't continue to pretend that it is an easy and harmless migration that wouldn't even require a big fat warning.  It is not.

This is not about technical details but about the user experience and about improving it.  From the technical details being clear to the developers, it doesn't follow that users are sufficiently informed even when they read the release notes.  Apparently, this very argument is futile here.  I wonder why that is.
#2
26.7 Series / Re: Some SSL certificate help ...
Last post by fornax - Today at 12:41:16 AM
At what point are you getting that message? Can you describe the exact steps you're following to generate the CSR and upload the certificate?

Edit: It sounds like you're choosing an option that tells OPNSense to sign a certificate itself (like "Sign a Certificate Signing Request"), which would explain why it thinks it needs a CA key. Instead, you need to edit the line that was created when you generated the CSR. There's a field there for Certificate data where you can paste the cert.
#3
26.7 Series / Re: Unbound stopps suddenly
Last post by notspam - September 08, 2026, 11:36:36 PM
Perhaps a new approach for dns filter lists in unbound:

Here is the breakdown of how AVM optimized the native DNS filter lists introduced in FRITZ!OS 8.40 / 8.50 to minimize RAM and CPU impact.
------------------------------
## 1. RAM Optimization (Memory Efficiency)

* Highly Compressed Data Structures: AVM does not store the imported text files as raw strings. Instead, during the import process, the FRITZ!Box parses and compiles the domains into highly efficient data structures (likely optimized Tries or compressed Bloom Filters). This reduces the memory footprint to a fraction of the raw file size.
* Low Footprint for Millions of Domains: Real-world testing by the community shows that importing heavy lists like HaGeZi Multi PRO combined with TIF (Malware)—totaling around 2.3 million blocked domains—only increases the RAM usage of an older FRITZ!Box 7590 (which only has 512 MB RAM) by a moderate 5% to 10%. There remains plenty of headroom on all supported models.
* No External Storage Required: Unlike early community speculations, you do not need to connect a USB drive or utilize the internal NAS storage to handle large blocklists. The RAM management handles everything internally.

## 2. CPU and Performance Optimization

* Algorithmic Complexity (O(1) / O(log n)): Thanks to the specialized search trees mentioned above, lookup times are mathematically decoupled from the list's size. Whether a list contains 10,000 or 2.5 million entries, the time it takes to check a domain remains nearly identical. The router never performs a slow sequential string search.
* The "Paradoxical" CPU Relief: User reports from the FRITZ! Labor beta phase revealed that the overall CPU load often decreases during normal web browsing when the filter is active.
* Why this happens: When tracking, advertising, or malware domains are instantly blocked at the DNS stage, the FRITZ!Box never has to establish those TCP/UDP connections, route the packets, or handle Network Address Translation (NAT) for them. Less junk traffic means less work for the CPU.
* Integration with Packet Acceleration: The DNS filtering engine is deeply integrated into FRITZ!OS and operates in tandem with AVM's hardware-level routing accelerators. This ensures that filtering does not bottleneck your overall internet throughput.

In short, AVM has successfully implemented this feature directly into the core of their lightweight Linux-based firmware, making it significantly more resource-efficient than running a heavy Docker container or Pi-hole on an external device.

#4
Zenarmor (Sensei) / Re: Cancelling my subscription...
Last post by abenaou - September 08, 2026, 10:17:09 PM
I agree with most of what was said in this thread, the other thing I feel very limiting is the number of policies, having just 5 policies can become a serious limitation for the home licence subscribers.

I wish other database back ends were considered, obviously the developers have their own reasons, but I feel between elastic and sqlite the choices are restrictive as both could wear out the disk while having an external mariadb handling the database aspect would make things more flexible.

Anyway, this is unrelated to the first post but thought giving some feedback can help improve the product.
#5
26.7 Series / Re: Firewall can't access serv...
Last post by viragomann - September 08, 2026, 10:10:17 PM
Quote from: creatronics on September 08, 2026, 08:16:26 PMA NAT rule redirects all traffic to WAN 80 and 443 to ´the loopback address.
So port forwarding is in play here. But this rule might be defined on the WAN or LAN interface and hence only affect traffic entering there.

I guess, there is mo possibility to forward traffic coming from the firewall itself (localhost). Don't know. But maybe it works if you enable NAT reflection in the rule.

Otherwise, is there a real need to have HAproxy listening on loopback?
I have it just on WAN and acess it from inside networks as well.
#6
Hardware and Performance / Re: Power loss recovery on Pro...
Last post by pfry - September 08, 2026, 09:29:09 PM
Quote from: Nullman on September 08, 2026, 02:05:29 PM[...]Modern motherboards show no signs of life if the battery goes below 2.5V.[...]

I haven't had a problem with mine (a few Asrock, Asus, Gigabyte, and Supermicro boards). I've noticed that most eat batteries when powered off (5 year life at best), and one Asrock Rack board eats them in no time (perhaps a year). It boots fine, though - the only obvious symptom is the time (it has few meaningful configuration options).

I wish the bloody things used flash for configuration (active as opposed to backup, and some of mine are old enough to lack even that). A (convenient, supported) bigger battery option would be nice, too (e.g. 2 AA). Oh, context: I like to use systems for 10+ years these days. Advances in compute just aren't as exciting as they were 25+ years ago.
#7
General Discussion / Re: Trying to block an alias g...
Last post by tangofan - September 08, 2026, 09:06:27 PM
Quote from: The Crazy Squirrel on September 07, 2026, 11:14:26 PMI don't know why, but now it's working.  I didn't change anything from my original post.
Was it time?  Was it a cache?  I have no idea.

What might have happened is that the state for internet access was still active in the firewall state table. You can clear individual states under Firewall -> Diagnostics -> States and under the "Actions" tab you can also reset the whole state table.
#8
Zenarmor (Sensei) / Re: Very high SSD writes with ...
Last post by bodenlos - September 08, 2026, 08:57:50 PM
Thanks for sharing your findings. I can add some further real-world data points that seem to support the same pattern:

I am seeing the same behaviour on three additional production systems with essentially the same system design. The absolute write volumes differ somewhat, but the result is consistent: when the Zenarmor engine is running, SSD host writes increase by approximately 4–5x compared with the baseline without Zenarmor.

Based on the measured write rates and the respective SSD endurance ratings (TBW), the specified endurances would be reached after approximately 2–4 years of operation, depending on the SSD and system.

For comparison, on my own system with the 320 TBW rating of my Kingston NV3, that corresponds to roughly 9.1 years at the baseline write rate, compared with only 2.3 years with Zenarmor enabled. (TBH: are endurance projections, not predictions of actual SSD failure.)
What makes this particularly concerning is that these are Proxmox hosts running several other servers and services, which already generate a substantial amount of disk I/O. Nevertheless, the additional write load associated with Zenarmor exceeds the combined baseline workload by several times. Essentially for the purpose of persisting reporting and connection metadata!

At this point, the consistency across multiple systems makes me strongly suspect a fundamental design or implementation issue in how much data Zenarmor writes and how those writes are performed. Whether the main contributor is the record volume, SQLite WAL/checkpointing, cleanup operations, write amplification, or a combination of these still needs to be investigated. But the resulting sustained write load seems difficult to justify for a reporting feature, particularly on appliances with limited SSD endurance.

I would therefore really like to see Zenarmor investigate the root cause and provide a technical explanation and mitigation for the local reporting backend. Ideally, there should also be an option to disable persistent reporting entirely while keeping the filtering/security engine active, for users who do not need historical reporting data.
#9
26.7 Series / Re: Some SSL certificate help ...
Last post by Ed V. - September 08, 2026, 08:26:03 PM
@fornax

That's exactly what I'm trying to do.

Replace the existing (now expired) SSL certificate with a new /renewed certificate from a Publicly Available CA.

The CA's I've attempted are:

CACert (my usual CA)
SSL.com (a fairly well-known CA)
DigiCert (the "granddaddy" CA, only surpassed by Verisign)
LetsEncrypt (ACME based CA)

In each case, I imported /uploaded the Root CA and Intermediate CA bundles before generating the CSR and uploading the signed certificate.

In all attempts, I get the:

"missing CA key"

error message.

#10
26.7 Series / Firewall can't access servers ...
Last post by creatronics - September 08, 2026, 08:16:26 PM
Hi,
first: thanks to all of you for providing a great forum for OPNsense.
We have an installation with HA setup and HA-proxy up and running. The only ting I just can't get to work, is to get the firewall to access it's own ha proxy and the server bhind it.

ha runs on a loopback ip 127.1.2.3 to make it independend of the WAN and LAN interfaces, which might change on failover.
A NAT rule redirects all traffic to WAN 80 and 443 to ´the loopback address.

everything is working perfectly except one thing: when I try to do a configuration backup on the master to our internal nextcloud server: nothing. Make it the slave and it accesses the Nextcloud via the master and it's working.
No matter what I tried, I just can't get it to work.

doing a curl -vvv on the nextcloud server gives something like this:

connect to 111.222.333.444 port 443 from 111.222.333.444 port 59859 failed: Connection refused

The OS is trying to create a connection from the WAN IP to the WAN IP (which is a pppoe device btw.)

And no matter what, there are no log entries for NAT or firewall rules. HA-proxy is seeing nothing, too.

Any idea which checkbox is missing?

Thank you all,

Michael