Recent posts

#1
26.7 Series / Unbound sendmsg failed message...
Last post by cinergi - Today at 02:12:45 AM
Hello,

I've noticed that I get the following messages repeating every minute (or even more often) in the Unbound log for a specific client:

2026-07-27T18:11:57-04:00 Notice unbound[87634:1] notice: remote address is <IPv6 address of client> port 54860
2026-07-27T18:11:57-04:00 Notice unbound[87634:1] notice: sendmsg failed: Invalid argument

That client doesn't have any connectivity issues, and works normally.  None of my other ~35 clients have this behavior.  Any ideas what is causing this, and what it means?  When that client is offline, the log is silent.

Thanks all!
#2
General Discussion / Can't get firewall to pass som...
Last post by thinkentropy - Today at 02:07:36 AM
I had the bright idea of moving my Opnsense from bare metal to virtualized in Proxmox. Everything seems to be working except the firewall seems to be blocking some subnet traffic that I think should be passing. I've been struggling with this for days so if I can't figure this out I will go back to bare metal. Any help would be so greatly appreciated!! Here is my current setup--

I have Opnsense (192.168.1.1) running in a VM in Proxmox (192.168.1.101). They're both sharing a physical network interface over a virtual bridge within Proxmox. I setup this network and called it "LAN," 192.168.1.0/24.

I created a 2nd virtual bridge within Proxmox for another physical network interface on my machine. In Opnsense, I assigned this network as 192.168.3.0/24 and called it "VLANs". I created a Truenas VM in Proxmox and assigned it to use the 2nd virtual bridge I setup. In Opnsense, I assigned IP 192.168.3.248 to this Truenas VM.

In my firewall rules, I have added "pass" rules to allow all traffic into the "VLANs" interface, and "pass" rules to allow all traffic into the "LAN" interface. I can successfully ping computers to and from both subnets. Pinging 192.168.3.248 from 192.168.1.222 works.



The problem is when I try and access the Truenas webgui. The firewall live view shows "Default Deny" blocking the TCP request on port 80 going into the VLANs interface.



Shouldn't the rules I created allow this TCP traffic to pass?
#3
26.7 Series / Re: Unbound stopps suddenly
Last post by fab - Today at 01:03:42 AM
Hello!

I'm having a similar problem. unbound suddenly stops and doesn't restart with the following log message:

<6>[86420] pid 4171 (unbound), jid 0, uid 59: exited on signal 11 (no core dump - denied by kern.coredump)
It has already happened a few times after the 26.7 upgrade. I also can start it manually after that has happened.

Is there at least some way, I can make it restart automatically again after exiting?

Best wishes,
-fab-
#4
General Discussion / Re: Periodic NIC issues (?) wi...
Last post by fornax - Today at 12:39:28 AM
Quote from: BrandyWine on July 28, 2026, 07:53:03 AM@fornax, it has been seen in past that auto-negotiate for 2.5gbps was an issue between certain devices that can do 2.5Gbps. If the WAN shows problem again, try:

sudo ifconfig igc1 down
sudo ifconfig igc1 media 1000baseTX
sudo ifconfig igc1 up

Yeah, I actually had both interfaces hardcoded to 1000 Full before the rebuild, thanks for the reminder.

I also flashed the BIOS from coreboot to AMI, which was a suggestion Protectli threw out there when I contacted them previously.
#5
Virtual private networks / Self signed Certificate renewa...
Last post by zuma48 - July 28, 2026, 11:35:07 PM
Hi, new to this VPN server OPNsense 23.1.11
I know it's an old version; it is just used for VPN.
The server Cert is due to expire.
I created a new self-signed certificate Authority
Confirming steps;
1. Do I need to revoke the current one for the new one to take over, or is it fine with the new dates? If so how? In the certificate section?
2 Do I need to issue new certificates for the users since they were issued under the current expiring Server cert, or just make sure they do not have expiring certs?
3 Anything else required? And do I need to reboot it for any changes or adds? I see there are 149 certificates under the current cert...

Thank you in advance for any help!
#6
26.7 Series / Re: Asking for Sanity Check be...
Last post by tangofan - July 28, 2026, 11:21:35 PM
Quote from: Patrick M. Hausen on July 28, 2026, 11:12:49 PMIt won't cause any downtime. You do not strictly need to reboot the system, you know?
Not strictly perhaps, but then I might as well test the change right away and make sure the system comes back up. Otherwise, if the system fails to boot at a later time - say after the next OPNsense update/upgrade - I'm dealing with multiple potential root causes. So I'd rather keep it simple and straightforward.
#7
General Discussion / Re: Please Make a Donation to ...
Last post by tangofan - July 28, 2026, 11:14:15 PM
Thanks to everyone working on OPNsense or otherwise helping with the project. Just donated 50 USD to the project.
#8
26.7 Series / Re: Asking for Sanity Check be...
Last post by Patrick M. Hausen - July 28, 2026, 11:12:49 PM
It won't cause any downtime. You do not strictly need to reboot the system, you know?
#9
26.7 Series / Re: Asking for Sanity Check be...
Last post by tangofan - July 28, 2026, 11:09:34 PM
Quote from: Patrick M. Hausen on July 28, 2026, 09:21:42 PMCorrectamundo on both accounts.
Patrick, thanks a bunch for the quick response and the confirmation. I'll implement this at the next "family-approved maintenance window" for the router.

Quote from: Patrick M. Hausen on July 28, 2026, 09:21:42 PM
Quote from: tangofan on July 28, 2026, 09:14:16 PMupdate the BIOS bootloader

You only need this if you want to be prepared in case you ever transfer your drive with the complete installation on it to an older system that still uses legacy boot instead of UEFI. If that is not a scenario you deem worth considering, you can ignore the legacy boot partition entirely.
Updating the BIOS bootloader sounds like something that doesn't have any downside and is easy to do, so I might as well do it, though I likely will never need it.
#10
26.7 Series / Re: Services widget
Last post by AhnHEL - July 28, 2026, 10:12:28 PM
I have an Ultrwide monitor so my columns might be slightly larger than yours but my Kea DHCP Widget already lists the Devices and IPs side by side.

Quote from: nero355 on July 28, 2026, 05:30:17 PMThe wasted space needs to removed on this one :

And then it's fine IMHO :)