Recent posts

#1
Du kannst dir das nicht unbedingt aussuchen. Hast du Apple-Geräte? Dann hast du mDNS.
#2
26.7 Series / Re: how to recover using an ol...
Last post by lmoore - Today at 04:55:24 AM
Quote from: defaultuserfoo on October 10, 2026, 10:41:05 PMIt means that all the rules need to be redone because migrating them doesn't work

It seems you are in the minority of users experiencing the impossibility of migrating firewall and NAT rules.

Perhaps you could invest time working through your issue and find a way to restore your old configuration file and get it working in a way where information already provided has not worked.

Considering the pain this has caused you, and in the interest that another user may some day befall your predicament, you could document the process you used and post it to the list, so they may also benefit from your experience.
#3
General Discussion / 1x NIC + 1x TP‑Link TL‑SG105E ...
Last post by z0rk - Today at 12:29:27 AM
Hi,

Another router on a stick setup question.

I am using Xfinity as my ISP.
I am using OPNsense 26.7

TL-SG108E configuration.

1️⃣ VLAN 10 (WAN/Modem Port)
VLAN ID: 10
Ports:Port 1 → Untagged
Port 5 → Tagged
Ports 2–4 → Not Member

2️⃣ VLAN 20 (LAN‑A, 192.x)
VLAN ID: 20
Ports:Port 2 → Untagged
Port 5 → Tagged
Ports 1, 3, 4 → Not Member

3️⃣ VLAN 30 (LAN‑B, 172.x)
VLAN ID: 30
Ports:Port 3 → Untagged
Port 5 → Tagged
Ports 1, 2, 4 → Not Member

4️⃣ VLAN 40 (LAN‑C, 10.x)
VLAN ID: 40
Ports:Port 4 → Untagged
Port 5 → Tagged
Ports 1–3 → Not Member

5️⃣ PVIDs (Port VLAN IDs)
(see attached)

The modem connects to port 1.
Port 5 connects to PC.

I can ping all subnets. I can access the GUI and SSH. WAN doesn't get an IP address assigned.
WAN is set up to use DHCP for both v4 and v6. All other settings are default.
Initially I left the MAC address blank.
Then I tried setting it to use the MAC address of the physical link, the address of the switch, and a randomly created MAC. I tried these with and without promiscuous mode enabled.
Rebooted the modem/OPNsense in between each setting change as well just for good measure.

No luck at all.

Maybe some wizard can shed some light on this.

Thanks!

---
Edit:
I've tried using the MAC address of my current OPNsense box, set VLAN priority to 6 and 7 respectively, but I am still having the same issue.

tcpdump -ni re0_vlan10 port 67 or port 68
tcpdump: verbose output suppressed, use -v[v]... for full protocol decode
listening on re0_vlan10, link-type EN10MB (Ethernet), snapshot length 262144 bytes
16:29:15.088863 IP 0.0.0.0.68 > 255.255.255.255.67: BOOTP/DHCP, Request from 98:b7:85:1f:be:ad, length 300
16:29:26.118714 IP 0.0.0.0.68 > 255.255.255.255.67: BOOTP/DHCP, Request from 98:b7:85:1f:be:ad, length 300
16:29:48.321257 IP 0.0.0.0.68 > 255.255.255.255.67: BOOTP/DHCP, Request from 98:b7:85:1f:be:ad, length 300
16:29:50.349083 IP 0.0.0.0.68 > 255.255.255.255.67: BOOTP/DHCP, Request from 98:b7:85:1f:be:ad, length 300
16:29:55.381867 IP 0.0.0.0.68 > 255.255.255.255.67: BOOTP/DHCP, Request from 98:b7:85:1f:be:ad, length 300
16:30:09.383068 IP 0.0.0.0.68 > 255.255.255.255.67: BOOTP/DHCP, Request from 98:b7:85:1f:be:ad, length 300
16:30:29.402982 IP 0.0.0.0.68 > 255.255.255.255.67: BOOTP/DHCP, Request from 98:b7:85:1f:be:ad, length 300
16:30:36.421088 IP 0.0.0.0.68 > 255.255.255.255.67: BOOTP/DHCP, Request from 98:b7:85:1f:be:ad, length 300
16:30:48.423105 IP 0.0.0.0.68 > 255.255.255.255.67: BOOTP/DHCP, Request from 98:b7:85:1f:be:ad, length 300
16:31:04.452439 IP 0.0.0.0.68 > 255.255.255.255.67: BOOTP/DHCP, Request from 98:b7:85:1f:be:ad, length 300
16:31:05.516106 IP 0.0.0.0.68 > 255.255.255.255.67: BOOTP/DHCP, Request from 98:b7:85:1f:be:ad, length 300
16:31:07.580611 IP 0.0.0.0.68 > 255.255.255.255.67: BOOTP/DHCP, Request from 98:b7:85:1f:be:ad, length 300
16:31:12.586850 IP 0.0.0.0.68 > 255.255.255.255.67: BOOTP/DHCP, Request from 98:b7:85:1f:be:ad, length 300
16:31:22.670109 IP 0.0.0.0.68 > 255.255.255.255.67: BOOTP/DHCP, Request from 98:b7:85:1f:be:ad, length 300
16:31:33.703175 IP 0.0.0.0.68 > 255.255.255.255.67: BOOTP/DHCP, Request from 98:b7:85:1f:be:ad, length 300
16:31:48.722855 IP 0.0.0.0.68 > 255.255.255.255.67: BOOTP/DHCP, Request from 98:b7:85:1f:be:ad, length 300
16:32:11.326441 IP 0.0.0.0.68 > 255.255.255.255.67: BOOTP/DHCP, Request from 98:b7:85:1f:be:ad, length 300
16:32:16.327227 IP 0.0.0.0.68 > 255.255.255.255.67: BOOTP/DHCP, Request from 98:b7:85:1f:be:ad, length 300
16:32:25.352865 IP 0.0.0.0.68 > 255.255.255.255.67: BOOTP/DHCP, Request from 98:b7:85:1f:be:ad, length 300
^C
19 packets captured
141 packets received by filter
0 packets dropped by kernel
#4
26.7 Series / Re: how to recover using an ol...
Last post by nero355 - October 10, 2026, 11:58:47 PM
Quote from: defaultuserfoo on October 10, 2026, 10:41:05 PMNo. It's not working.

Instead it was made to appear something easy to do.  But it is isn't.

This reminds of the fatal blow Debian struck their users with their stupid brokenarch.  I had been using Debian for about 15 years and then the devs decided to comepletely mess it up, and it was forseeable that the problems would continue to exist in the next release.  So I switched away from Debian.

This is the same crap.  If I knew a good alternative to OPNsense I would switch.
As someone who is using both Debian and OPNsense I totally disagree with you :)

QuoteWe've already had a discussion about the release notes.  The devs refuse to make good release notes.
NOFI but IMHO it's you and not the software...

Maybe try something OpenWRT based or simply buy stuff like TP-Link Omada or Ubiquiti UniFi or HPE Aruba ?!



Good luck! :)
#5
26.7 Series / Re: how to recover using an ol...
Last post by defaultuserfoo - October 10, 2026, 11:22:15 PM
Quote from: defaultuserfoo on October 10, 2026, 10:43:25 PM
Quote from: defaultuserfoo on October 10, 2026, 07:02:17 PM
Quote from: lmoore on October 10, 2026, 04:29:11 AM
Quote from: defaultuserfoo on October 10, 2026, 02:23:16 AMI had only one plugin installed, so I don't expect that any plugin conflicts would need resolving

Referring to page 6, after you powered on the restored system, did you check the 'Status' page and was the 'Resolve plugin conflicts' button there!?

I don't know ...  I'll pay attention to that when I start over.


I've installed the plugin that will be needed and there is no button to resolve plugin conflicts.  I'll check again after importing the old configuration.


There were no conflicts after importing the configuration.  But the plugin (os-maltrail) shows as orphaned.
#6
26.7 Series / Re: how to recover using an ol...
Last post by defaultuserfoo - October 10, 2026, 11:19:20 PM
Quote from: (MARLOO) on October 10, 2026, 04:57:54 AMThan you can setup your manual backup,sftp backup with cron job,screenshoot of your plugin and many other things you like.

Oh, are you suggesting to log in on the console and set up a cron job to use the ftp client to make a copy of /conf/config.xml?

Is there a better way?  I could as well use scp maybe.  Unfortunately, rsync is not installed.  Or is there a way through the web interface?
#7
26.7 Series / Re: how to recover using an ol...
Last post by defaultuserfoo - October 10, 2026, 10:43:25 PM
Quote from: defaultuserfoo on October 10, 2026, 07:02:17 PM
Quote from: lmoore on October 10, 2026, 04:29:11 AM
Quote from: defaultuserfoo on October 10, 2026, 02:23:16 AMI had only one plugin installed, so I don't expect that any plugin conflicts would need resolving

Referring to page 6, after you powered on the restored system, did you check the 'Status' page and was the 'Resolve plugin conflicts' button there!?

I don't know ...  I'll pay attention to that when I start over.


I've installed the plugin that will be needed and there is no button to resolve plugin conflicts.  I'll check again after importing the old configuration.
#8
26.7 Series / Re: how to recover using an ol...
Last post by defaultuserfoo - October 10, 2026, 10:41:05 PM
Quote from: (MARLOO) on October 10, 2026, 08:03:52 PM
Quote from: defaultuserfoo on October 10, 2026, 07:09:55 PMOh so I have to use 25.7 and no 26.  I don't want to migrate the rules.  That won't work.  The router needs to be working again since a couple days ago.  I'll try to get it set up with 25.7 and deploy it.

Then I'll have to use the spare machine and set that up and see if the rules can be migrated somehow and either switch the machines or the disks, or migrate the currently broken one.  Having a spare really pays out big time.



Do whatever you want, but why do you not want to migrate the rules?

Migrating the rules does not mean changing them. It means validating your existing rules so they work with the new rules system in 26.7.

No it doesn't.  It means that all the rules need to be redone because migrating them doesn't work.  After importing the rules you get a mess of rules that don't work anymore because of the way things work with the new rules has changed and the old ones are not compatible.

I've done it at home a couple months ago and was left with a ruined firewall which I had to redo.  I was told here that I shouldn't have migrated the rules and that it would be many years before a migration would be required.

I've tried it yesterday when I suddenly found I can't edit the rules anymore after upgrading.  Exporting the old rules and importing them created yet again a total mess with a mixture of immutable rules and non-working rules and maybe some rules weren't imported. The import gets stuck with a popup window having a checkbox and checkmark in it and if you keep clicking on that you get unclear error messages and are left with no idea as to what you're supposed to do now.  You can keep importing the rules over and over but that is futile.

There is no migration.  It does 100% not work.

QuoteThat way, you can also keep receiving updates.

Only when I redo the whole firewall, and I don't want to do that again.

QuoteOPNsense is not obsolete. It is a well-maintained and well-documented system. Major changes are announced in the release notes and discussed in the forum, so it is important to follow those before upgrading an old configuration.

No.  It's not working.  I already said here that this so-called migration was handled badly because there must be a big fat warning in the release notes that your firewall will be broken and that you better wait the however many years before ever trying this so-called migration.  Instead it was made to appear something easy to do.  But it is isn't.

This reminds of the fatal blow Debian struck their users with their stupid brokenarch.  I had been using Debian for about 15 years and then the devs decided to comepletely mess it up, and it was forseeable that the problems would continue to exist in the next release.  So I switched away from Debian.

This is the same crap.  If I knew a good alternative to OPNsense I would switch.

We've already had a discussion about the release notes.  The devs refuse to make good release notes.

QuoteThe developers put a lot of work into maintaining the ecosystem and keeping it up to date. Reading the release notes and planning migrations is part of running a firewall, especially after a major architecture change.

Good luck with the recovery. At least now you know why the release notes exist.



The relase notes suck.  Look up the discussion about it we had.

It's not about the release notes anyway.  The problem is that there is no way to update the OPNsense instances anymore because doing that will break the firewall rules and the firewall needs to be completely redone.  That makes OPNsense obsolete.

Maybe I'll find an alternative.  If I have to start over from scratch I can as well switch to something else.
#9
German - Deutsch / Re: [Gelöst] Unbound-DNS Erw...
Last post by k0ns0l3 - October 10, 2026, 10:24:56 PM
ich bleibe vorerst bei 5353 , mit mDNS ich habe nicht vor danke für Hinweis ;))

lg k0ns0l3
#10
General Discussion / Re: netgate freebsd performanc...
Last post by Greelan - October 10, 2026, 10:17:26 PM
All of that said, there is no doubt a lesson in repeated CVEs happening due to similar reasons (input sanitization). I assume the tests have been hardened on that front.

As a matter of interest, does the development team use AI for vulnerability spotting?