Recent posts

#1
Tutorials and FAQs / Re: [HOWTO]: Mullvad Selective...
Last post by colourcode - Today at 02:03:10 PM
Quote from: Mai tran on May 01, 2026, 02:56:11 PMIm not sure where else to post this but

Hey all does anyknow know of a guide that demonstrates how to have a wireguard road wiarrior (external -> home) route out over a von providers network via wiregaurd?

I have various vlans route over mullvad  vpn provider successfully with selective routing as instructed above. I also have a seperate wiregaurd instance that connects my devices back to my home. The problem is traffic is exposed to to my isp but i want it to route out through my mullvad vpn instance. Help or guide requested.

If I understand you correctly. You want to connect to home-wireguard-instance over WAN and then go out by the mullvad tunnel.
Should be enough to include the home-wireguard-interface in your selective route firewall rule. Then add the IPs of home-instance-peers to the selective route alias.
#2
26.1, 26,4 Series / Re: 26.1.7_2: issue with ACME ...
Last post by fraenki - Today at 01:42:23 PM
If you want to dive even deeper: try to query the TrueNAS API endpoint "system.ready" using `curl` and your API key. The API documentation is available here:
https://www.truenas.com/docs/api/scale_websocket_api.html
It should make the root cause more obvious, but crafting the `curl` command might be a challenge.
#3
26.1, 26,4 Series / Re: 26.1.7_2: issue with ACME ...
Last post by Rene78 - Today at 01:35:34 PM
Hmmm... okay.. wasn't aware that TrueNAS API needed any configuration, but I'll dive into that one next. Thanks! I'll report back when I find something.
#4
26.1, 26,4 Series / Re: Stuck Library?
Last post by franco - Today at 12:12:45 PM
Did the forum search for you:

# pkg remove php82-pecl-mongodb


Cheers,
Franco
#5
General Discussion / Troubleshooting guidance
Last post by mrThirsty - Today at 11:56:30 AM
Hi All,

I could use some guidance with troubleshooting a problem I am having currently with OpnSense. Randomly during the day, my entire network seems to freeze up for about 30 seconds to a couple of minutes. I am not sure if its just LAN or WAN but all devices both wired and wireless can't seem to do anything during this, I am leaning toward it being a WAN-related issue as on the odd occasion when the freeze up has been long enough, I am still able to log into the Admin portal on my router. It started about after about 6 months of OpnSense running as my network.

My network looks like the following:

Virgin Media Fibre modem/router (modem only mode) -> OpnSense (Protectli Vault FW4C (Intel J3710) with 2 2.5GB NIC) -> 1GB switch and Ubiquiti Amplify-HD wireless router (Bridge Mode)

I have determined the issue is my OpnSense router as I have removed it from my network and then ran each of the ISP modem and Amplify-HD as the router for a day each and during those two days I did not have any of the freezes. I have also taken the extreme move of completely wiping my router and just having it run as it comes out of the box, just as a DHCP server, no ZenArmour or OpenVPN etc. and I still get the freezing. No matter what configuration I run my network in, as soon as OpnSense is the router, the freezing happens.

My OpnSense is a pretty basic setup, it runs Dnsmasq for DHCP, ZenArmour, and then an OpenVPN connection with some routing rules to push specific network client's traffic over that connection.

I am at a loss at what to look at to try determine what is causing this freezing when OpnSense is the active router on my network, when looking at the logs I am not really sure what I am looking at so probably wouldn't spot the issue if it was staring at me. I do appreciate that this could also be a hardware issue as well.

I could use some guidance on what to look for or potentially even a fix to try as I don't want to get rid of OpnSense as I love the control it gives me, especially along with ZenArmour, about what my kids can access when and filtering out the dodgy stuff as best as possible, but I am getting to the point that the Wife Acceptance Factor is getting very low, so I need to resolve it otherwise I will be gaining an expensive paper weight in the protectli.

Appreciate any help, pointers, etc.
#6
26.1, 26,4 Series / Stuck Library?
Last post by Aimdev99 - Today at 11:20:29 AM
How can i fix this safely?
Thanks

06-May-2026 09:09:28 UTC] PHP Warning:  PHP Startup: Unable to load dynamic library 'mongodb.so' (tried: /usr/local/lib/php/20230831/mongodb.so (Cannot open "/usr/local/lib/php/20230831/mongodb.so"), /usr/local/lib/php/20230831/mongodb.so.so (Cannot open "/usr/local/lib/php/20230831/mongodb.so.so")) in Unknown on line 0
[

pkg-static: No packages available to install matching 'php82' have been found in the repositories
>>> Summary of actions performed:

php82 dependency failed to be fixed

>>> There are still missing dependencies.
>>> Try fixing them manually.
#7
Quote from: meyergru on Today at 10:48:22 AMDas wundert mich wirklich. Mit Request Prefix Only und einem passenden Präfix und einer Interface ID kann man die GUA so festlegen, wie man will.

Mit einem festen Präfix am Businessanschluss müsste das sogar eine feste IP geben.
Ja, so habe ich es jetzt auch und somit am Business-Anschluss effektiv eine feste IP.

Aus Anwendersicht ist eben nur etwas unverständliche das:
  • die ohne die Angabe der optionalen Präfix- und Schnittstellen-ID EUI-64-Adresse sich ändert, da die zugrundeliegende MAC quasi zufällig wechseln kann.
  • auch mit gesetztem Haken bei "Request Prefix Only" und ohne Angabe der optionalen Präfix- und Schnittstellen-ID eine GUA bezogen wird - allerdings offenbar nur bei Geschäftskundenanschlüssen der Telekom; nicht bei privaten Anschlüssen.
  • in der Konstellation die GUA nur dann selbst festgelegt werden kann, wenn neben der Interface-ID auch die optionale Präfix-ID angegeben wird.

[Edit]: Bei der hier beschriebenen OpnSense 3 wird auch an einem Privatkundenanschluss der Telekom trotz Haken bei "Request Prefix Only" eine GUA bezogen. Teilweise dauert es nur ein wenig bis die Adresse angezeigt wird.


Quote from: Patrick M. Hausen on Today at 11:08:25 AMWas schreib ich da beispielsweise rein?
Ich hatte hier ein Beispiel dazu gemacht.
Aktuell habe ich bei Präfix "0" eingetragen, und bei Schnittstellen-ID die feste IPv4-Adresse (ohne Punkte und mit Nullen aufgefüllt).
#8
German - Deutsch / Re: Öffentlicher IPv6-Suffix ä...
Last post by meyergru - Today at 11:17:33 AM
Was Du willst. Im Zweifel 1. Es geht doch nur darum, eine feste EUI-64 zu haben. Da die Notation ein Integer ist, kannst Du das höchste Bit nicht setzen.

Ich nehme für die Interface ID oft eine zufällige Zahl, damit die nach Privacy Extensions aussieht.
#9
26.1, 26,4 Series / Re: 26.1.7_2: issue with ACME ...
Last post by fraenki - Today at 11:11:34 AM
Quote2026-05-05T21:12:22acme.sh [Tue May 5 21:12:22 CEST 2026] Verify API key.
2026-05-05T21:12:22acme.sh [Tue May 5 21:12:22 CEST 2026] Please check environment variables DEPLOY_TRUENAS_APIKEY, DEPLOY_TRUENAS_HOSTNAME and DEPLOY_TRUENAS_PROTOCOL.

If you're seeing this message, it means that os-acme-client is working perfectly fine.

This error message is raised by acme.sh when a communication error with your TrueNAS occured:
https://github.com/acmesh-official/acme.sh/blob/7735cdf3abe84bce8c1e37e7fa46c71e38606262/deploy/truenas_ws.sh#L219
This code checks the "system.ready" TrueNAS API endpoint and seems to receive an error or invalid result.

I can't give you any advice for setting up TrueNAS. Maybe you need to configure something to make the TrueNAS websocket API work.
#10
Quote from: meyergru on Today at 10:48:22 AMMit Request Prefix Only und einem passenden Präfix und einer Interface ID kann man die GUA so festlegen, wie man will.

Was schreib ich da beispielsweise rein?