Recent posts

#1
26.7 Series / Fresh 26.7 install → 26.7.3_11...
Last post by Jeremy_S - Today at 03:04:53 AM

Fresh install from the 26.7 amd64 ISO (Intel mini PC, igc NICs, UFS on NVMe).
Updating to 26.7.3_11 downloads all 67 packages, then aborts at the integrity check:

Checking integrity...Assertion failed: (!STREQ(uid, p->uid)), function pkg_conflicts_check_local_path, file pkg_jobs_conflicts.c, line 317.
Child process pid=4252 terminated abnormally: Abort trap

Plan is 67 straight upgrades — no removals, no new installs, no replacements. Nothing gets installed; system remains on 26.7.

Reproduces:
- with no config restored (clean install) and with config restored
- via GUI, pkg upgrade, and opnsense-update -bkp
- on two mirrors (default pkg.opnsense.org + [MIRROR NAME])

Health audit is clean: kernel/base 26.7 correct, no plugins, no locks, no missing/altered files, only expected version mismatches vs 26.7.3_11. Only the OPNsense repo is enabled. pkg is 2.3.1_1. Connectivity audit passes over IPv4 (no IPv6 route here, "prefer IPv4" is set).

Full update log and health audit below.

Is there a supported way through this — step through the intermediate hotfixes, or is opnsense-bootstrap the recommended path?

Thanks!

Update log:

***GOT REQUEST TO UPDATE***
Currently running OPNsense 26.7 (amd64) at Thu Sep 10 19:42:07 CDT 2026
Updating OPNsense repository catalogue...
OPNsense repository is up to date.
All repositories are up to date.
Updating OPNsense repository catalogue...
OPNsense repository is up to date.
All repositories are up to date.
Checking for upgrades (166 candidates): .......... done
Processing candidates (166 candidates): ..... done
The following 67 package(s) will be affected (of 0 checked):

Installed packages to be UPGRADED:
boost-libs: 1.89.0_2 -> 1.91.0 [OPNsense]
ca_root_nss: 3.124 -> 3.127 [OPNsense]
cyrus-sasl: 2.1.28_5 -> 2.1.28_6 [OPNsense]
dpinger: 3.4 -> 3.6 [OPNsense]
expat: 2.8.2 -> 2.8.3 [OPNsense]
glib: 2.86.4,2 -> 2.88.3,2 [OPNsense]
hostapd: 2.11_3 -> 2.12_2 [OPNsense]
jansson: 2.15.1 -> 2.15.1_1 [OPNsense]
json-c: 0.18 -> 0.19_1 [OPNsense]
kea: 3.0.3 -> 3.0.4 [OPNsense]
krb5: 1.22.2_2 -> 1.22.2_3 [OPNsense]
libffi: 3.6.0 -> 3.8.0 [OPNsense]
libnghttp2: 1.69.0 -> 1.70.0 [OPNsense]
libpsl: 0.21.5_2 -> 0.23.3 [OPNsense]
log4cplus: 2.1.2 -> 2.2.0.1 [OPNsense]
monit: 5.35.2 -> 6.0.0 [OPNsense]
mpd5: 5.9_19 -> 5.9_20 [OPNsense]
nss: 3.124 -> 3.127 [OPNsense]
openldap26-client: 2.6.13 -> 2.6.14 [OPNsense]
openssh-portable: 10.3.p1,1 -> 10.5.p1_1,1 [OPNsense]
openssl35: 3.5.7 -> 3.5.8 [OPNsense]
openvpn: 2.7.5 -> 2.7.7 [OPNsense]
opnsense: 26.7 -> 26.7.3_11 [OPNsense]
opnsense-update: 26.7 -> 26.7.3 [OPNsense]
perl5: 5.42.2 -> 5.42.3 [OPNsense]
php85: 8.5.8 -> 8.5.9 [OPNsense]
php85-ctype: 8.5.8 -> 8.5.9 [OPNsense]
php85-curl: 8.5.8 -> 8.5.9 [OPNsense]
php85-dom: 8.5.8 -> 8.5.9 [OPNsense]
php85-filter: 8.5.8 -> 8.5.9 [OPNsense]
php85-gettext: 8.5.8 -> 8.5.9 [OPNsense]
php85-ldap: 8.5.8 -> 8.5.9 [OPNsense]
php85-mbstring: 8.5.8 -> 8.5.9 [OPNsense]
php85-pcntl: 8.5.8 -> 8.5.9 [OPNsense]
php85-pdo: 8.5.8 -> 8.5.9 [OPNsense]
php85-pecl-mcrypt: 1.0.7 -> 1.0.9 [OPNsense]
php85-phalcon: 5.16.0 -> 5.20.3 [OPNsense]
php85-session: 8.5.8 -> 8.5.9 [OPNsense]
php85-simplexml: 8.5.8 -> 8.5.9 [OPNsense]
php85-sockets: 8.5.8 -> 8.5.9 [OPNsense]
php85-sqlite3: 8.5.8 -> 8.5.9 [OPNsense]
php85-xml: 8.5.8 -> 8.5.9 [OPNsense]
php85-zlib: 8.5.8 -> 8.5.9 [OPNsense]
py313-anyio: 4.13.0 -> 4.14.2 [OPNsense]
py313-certifi: 2026.5.20 -> 2026.7.22 [OPNsense]
py313-cffi: 2.0.0 -> 2.1.1 [OPNsense]
py313-charset-normalizer: 3.4.7 -> 3.5.1 [OPNsense]
py313-cryptography: 48.0.0_1,1 -> 49.0.0,1 [OPNsense]
py313-duckdb: 1.5.4 -> 1.5.5 [OPNsense]
py313-hpack: 4.1.0 -> 4.2.0 [OPNsense]
py313-numexpr: 2.14.1_2 -> 2.14.2 [OPNsense]
py313-pyasn1: 0.6.0 -> 0.6.4 [OPNsense]
py313-pyopenssl: 26.2.0,1 -> 26.3.0,1 [OPNsense]
py313-pytz: 2026.2,1 -> 2026.3,1 [OPNsense]
py313-pyyaml: 6.0.3 -> 6.0.3_1 [OPNsense]
py313-service-identity: 24.2.0 -> 26.1.0 [OPNsense]
py313-sqlite3: 3.13.14_10 -> 3.13.15_10 [OPNsense]
py313-trio: 0.33.0 -> 0.34.0 [OPNsense]
py313-tzdata: 2026.2 -> 2026.3 [OPNsense]
py313-ujson: 5.12.1 -> 5.13.0 [OPNsense]
python313: 3.13.14 -> 3.13.15 [OPNsense]
rrdtool: 1.9.0_1 -> 1.11.0 [OPNsense]
sqlite3: 3.53.3,1 -> 3.53.4,1 [OPNsense]
syslog-ng: 4.12.0 -> 4.12.0_3 [OPNsense]
unbound: 1.25.1_1 -> 1.26.0 [OPNsense]
wpa_supplicant: 2.11_7 -> 2.12_1 [OPNsense]
zip: 3.0_5 -> 3.0_6 [OPNsense]

Number of packages to be upgraded: 67

The process will require 11 MiB more space.
142 MiB to be downloaded.
[1/67] Fetching php85-xml-8.5.9.pkg: .. done
[... all 67 packages fetched successfully ...]
[67/67] Fetching expat-2.8.3.pkg: ... done
Checking integrity...Assertion failed: (!STREQ(uid, p->uid)), function pkg_conflicts_check_local_path, file pkg_jobs_conflicts.c, line 317.
Child process pid=4252 terminated abnormally: Abort trap
Flushing temporary package files... done
Starting web GUI...done.
Partial update failure detected: report this error log to OPNsense.
No further actions will be taken. Please restart the update now.
***DONE***

Health audit:

***GOT REQUEST TO AUDIT HEALTH***
Currently running OPNsense 26.7 (amd64) at Thu Sep 10 12:20:41 CDT 2026
>>> Root file system: /dev/gpt/rootfs
>>> Check installed kernel version
Version 26.7 is correct.
>>> Check for missing or altered kernel files
No problems detected.
>>> Check installed base version
Version 26.7 is correct.
>>> Check for missing or altered base files
No problems detected.
>>> Check installed repositories
OPNsense (Priority: 11)
>>> Check installed plugins
No plugins found.
>>> Check locked packages
No locks found.
>>> Check for missing package dependencies
Checking all packages: .......... done
>>> Check for missing or altered package files
Checking all packages: .......... done
>>> Check for core packages consistency
Core package "opnsense" at 26.7 has 68 dependencies to check.
ca_root_nss-3.124 version mismatch, expected 3.127
dpinger-3.4 version mismatch, expected 3.6
hostapd-2.11_3 version mismatch, expected 2.12_2
kea-3.0.3 version mismatch, expected 3.0.4
monit-5.35.2 version mismatch, expected 6.0.0
mpd5-5.9_19 version mismatch, expected 5.9_20
openssh-portable-10.3.p1,1 version mismatch, expected 10.5.p1_1,1
openvpn-2.7.5 version mismatch, expected 2.7.7
opnsense-26.7 version mismatch, expected 26.7.3_11
opnsense-update-26.7 version mismatch, expected 26.7.3
php85-ctype-8.5.8 version mismatch, expected 8.5.9
php85-curl-8.5.8 version mismatch, expected 8.5.9
php85-dom-8.5.8 version mismatch, expected 8.5.9
php85-filter-8.5.8 version mismatch, expected 8.5.9
php85-gettext-8.5.8 version mismatch, expected 8.5.9
php85-ldap-8.5.8 version mismatch, expected 8.5.9
php85-pcntl-8.5.8 version mismatch, expected 8.5.9
php85-pdo-8.5.8 version mismatch, expected 8.5.9
php85-phalcon-5.16.0 version mismatch, expected 5.20.3
php85-session-8.5.8 version mismatch, expected 8.5.9
php85-simplexml-8.5.8 version mismatch, expected 8.5.9
php85-sockets-8.5.8 version mismatch, expected 8.5.9
php85-sqlite3-8.5.8 version mismatch, expected 8.5.9
php85-xml-8.5.8 version mismatch, expected 8.5.9
php85-zlib-8.5.8 version mismatch, expected 8.5.9
py313-duckdb-1.5.4 version mismatch, expected 1.5.5
py313-sqlite3-3.13.14_10 version mismatch, expected 3.13.15_10
py313-ujson-5.12.1 version mismatch, expected 5.13.0
rrdtool-1.9.0_1 version mismatch, expected 1.11.0
syslog-ng-4.12.0 version mismatch, expected 4.12.0_3
unbound-1.25.1_1 version mismatch, expected 1.26.0
wpa_supplicant-2.11_7 version mismatch, expected 2.12_1
zip-3.0_5 version mismatch, expected 3.0_6
***DONE***

#2
26.7 Series / Can settings from ver OPNsense...
Last post by seamus - Today at 12:47:12 AM
I installed OPNsense on my server in Jan 2018 - best I can recall. I upgraded fairly regularly until I got to ver 21.7.8. I stopped there because I was concerned about migrating to the "new" version, and because I began traveling extensively. My OPNsense firewall (OPNsense + SuperMicro Intel 4 core 1.8 GHz Atom CPU) has run 24x7 for many years now with virtually no maintenance or administration! The only time I even log into the FW is when I need to check the DHCP logs. My ISP is Google fiber - also very reliable. My family used the Internet continuously while I was on travel, and never had an incident. All this is background to say that I'm very pleased with this setup!

However, after 8+ years I have some concerns re my hardware. Late last year, I attempted installation of a newer version of OPNsense on a slightly newer server that has seen very little use - I planned to use it as a "cold backup" system. Unfortunately, my installation attempt was unsuccessful. 

I am now *seriously* considering the future. I definitely want to stick with OPNsense, but feel that I must upgrade my hardware. 8+ years ago I was "active", and enjoyed tinkering in such projects. Today, I'm looking for a solution that doesn't involve "starting over", and is less challenging for my aging brain  :P  All of that said, I have a few questions:

1. At one time (and perhaps still today) OPNsense allowed one to make a "configuration backup" to an XML file. I still have several of these backup files - several from 2022, the latest from June 2025. Can I apply these "backup configuration" files to a new version of OPNsense?

2. As I said earlier, I am motivated to upgrade my hardware. It's my understanding that if I bought a hardware server, OPNsense would come pre-installed. I wonder if I could send my "backup configuration" files to Decisio (?), and have them "pre-configure" my server?

3. As I read the specifications, it seems the DEC677 would meet my needs. My Google Fiber service is rated at 2 Gbps, and there are 3-4 fairly active users. We have a "streaming service" for movies, a "cellular extender box" and several (too many) computers laying about. Could someone "take a stab" at confirming the DEC677 would be sufficient?

That's all I can think of at present. Thanks in advance for your help!

Best Rgds,
~S
#3
Virtual private networks / Re: Twingate Connector
Last post by Glitch01 - September 10, 2026, 11:16:08 PM
After some investigating, turns out my Crowdsec rule was blocking the outbound connection to the remote Twingate relay connector. Even though I could authenticate to the service, the block rule would deny the connection to remote relay through one or more of it's intermediary host servers even though I allowed the require outbound ports. I believe the intermediary servers establishes the initial handshake before a direct P2P connection is later established for the session.
#4
Hardware and Performance / Re: Power loss recovery on Pro...
Last post by cottec - September 10, 2026, 10:35:47 PM
Quote from: OPNenthu on September 08, 2026, 07:58:10 PMBTW, you probably saw my note above about setting the date manually in FreeBSD the first time you boot after a battery change / CMOS reset.  Coreboot doesn't let you set the system time unfortunately so until you do it in the OS you'll have problems getting NTP to sync.  FYI.
I waited for a new battery to arrive but it's still dead, will send it to them tomorrow.
#5
26.7 Series / Re: Problem where fallback DNS...
Last post by bamf - September 10, 2026, 10:17:13 PM
If you only need a fallback in case AdGuardHome is unavailable, better set up a second instance on another machine. You can use adguardhome-sync to synchronize your settings.

However, this will get you unreliable statistics as your clients will randomly pick one of your instances. I have solved that with keepalived. Set up a virtual IP for keepalived on both machines and use that IP address as your DNS server. If the main instance goes down, the virtual ip will move to the second machine and that instance will answer the queries.
#6
Development and Code Review / Re: netflector available as pl...
Last post by RamSense - September 10, 2026, 09:28:22 PM
@UnicronHD Thanks for looking into it.
I'm happy to help test the next build/fix when it's ready.
#7
26.7 Series / Re: Problem where fallback DNS...
Last post by meyergru - September 10, 2026, 09:12:42 PM
"drill" without any options explicitly randomizes the nameserver list. For the test you want, you must use "drill -z".

But that probably does not solve your actual issue. When OPNsense itself resolves a name using the servers from resolv.conf, they are normally tried in order, so you already have a kind of fallback there. The same is not guaranteed for DHCP clients to which you hand out a list of DNS servers.

The clients decide for themselves how to deal with a list of DNS servers, and that behavior differs between operating systems. Therefore, handing out AdGuard as DNS1 and Cloudflare as DNS2 does not reliably mean "use AdGuard unless it is unavailable".

If you want a real fallback for your clients, hand out only the address of a local resolver and implement the fallback there. For example, OPNsense's Dnsmasq has the option "Query DNS servers sequentially", which queries upstream DNS servers in the configured order.

Unbound with multiple forwarders would not provide strict primary/fallback ordering, as Unbound selects forwarders based on its own server-selection and RTT logic.
#8
26.7 Series / Had to reinstall and
Last post by Karla - September 10, 2026, 08:50:43 PM
then I had to delete all partitions with Gparted to proceed with installation.
#9
Development and Code Review / Re: netflector available as pl...
Last post by UnicronHD - September 10, 2026, 08:23:58 PM
@RamSense I have identified the problem with the ICMP unreachable responses. It has to do with the fact that WG tunnel has no broadcast and no multicast domains. I'm working on the solution.
#10
26.7 Series / Problem where fallback DNS is ...
Last post by Lucid1010 - September 10, 2026, 08:16:15 PM
You cannot view this attachment.

$ cat /etc/resolv.conf
# This file was automatically generated by system_resolvconf_generate()
# If you want to append configuration here use /etc/resolv.conf.local
domain xxxxxxxxxxxxxxxx
nameserver 192.168.1.1
nameserver 1.1.1.1
nameserver 1.0.0.1
search xxxxxxxxxxxxxxx


$ drill google.com
;; ->>HEADER<<- opcode: QUERY, rcode: NOERROR, id: 41425
;; flags: qr rd ra ; QUERY: 1, ANSWER: 6, AUTHORITY: 0, ADDITIONAL: 0
;; QUESTION SECTION:
;; google.com.  IN      A

;; ANSWER SECTION:
google.com.     114     IN      A      xxxxxxx
xxx
;; AUTHORITY SECTION:

;; ADDITIONAL SECTION:

;; Query time: 0 msec
;; SERVER: 192.168.1.1

# --

$ drill google.com
;; ->>HEADER<<- opcode: QUERY, rcode: NOERROR, id: 13948
;; flags: qr rd ra ; QUERY: 1, ANSWER: 6, AUTHORITY: 0, ADDITIONAL: 0
;; QUESTION SECTION:
;; google.com.  IN      A

;; ANSWER SECTION:
google.com.     281     IN      A       xxx
xxxx
;; AUTHORITY SECTION:

;; ADDITIONAL SECTION:

;; Query time: 4 msec
;; SERVER: 1.1.1.1

I am currently using AdGuard Home as my main DNS server.
AdGuard Home responds immediately and works without issue.
However, whenever a DNS query is made, my device alternates between AdGuard Home (192.168.1.1) and Cloudflare DNS(1.1.1.1).

Is it possible to set it up so AdGuard Home is used as the sole primary DNS, 
and Cloudflare DNS is only used as a fallback when AdGuard Home is delayed or unresponsive?