Recent posts

#1
26.7 Series / Re: Renewed server certificate...
Last post by userfw - Today at 02:15:35 PM
I'm getting the same error trying to renew the GUI self-signed cert.
The release notes for 26.7 mentioned the upgrade of openssl to 3.5 and possible issues, maybe related to this and the other thread about exporting OpenVPN profiles?
#2
Também estou testando uma configuração parecida com fibra como principal e 5G como backup. O failover para o 5G funciona quando desligo a fibra, mas quando a fibra volta nem sempre o tráfego retorna imediatamente para ela. Alguém já passou por isso? Tem alguma configuração específica no gateway group para o retorno ao Tier 1 funcionar de forma mais consistente?
#3
Quote from: vk2him on Today at 12:14:10 AMI searched the qfeeds block file and 43.131.7.8 isn't contained there.

virustotal.com also shows zero reported security issues wirh that ip

Vendors Analysis:
No security vendors flagged this URL as malicious
Final URL:
http://43.131.7.8/
Domain:
43.131.7.8

Look at your logs to see why it's being blocked for you?

All of that is in my original post.

It is being blocked by the qfeeds rule - as indicated by the firewall log, and as indicated by being in the qfeeds event list - despite, as I said above, not being on the IOC list, or the qfeeds alias list on the device itself.

Disabling the qfeeds rule resolves the problem.
#4
26.7 Series / Re: Call for testers - new CPU...
Last post by PencilHCV - Today at 09:41:01 AM
Hi all!
this by:
1.-uninstall CPU-Microcode
2.-Upgrade to 26.7.1
3.-Update Boot Loader
4.-Install CPU- Microcode
Do we always have to do this when updating to ver. 26.7.1 or will there be a new version of OPNsense that will work without all the above steps?
Best regards!
//Hugo
#5
26.7 Series / Re: Internal DNS only works fo...
Last post by chrisgtl - Today at 08:41:39 AM
Not sure why this isn't working for you. I can resolve without using FQDN.

❯ ping ap
PING ap.internal (10.10.2.4) 56(84) bytes of data.
64 bytes from ap (10.10.2.4): icmp_seq=1 ttl=63 time=0.562 ms
64 bytes from ap (10.10.2.4): icmp_seq=2 ttl=63 time=0.443 ms
#6
General Discussion / Re: nfSensei ( fork pfsense )
Last post by patient0 - Today at 07:37:13 AM
Quote from: RES217AIII on August 08, 2026, 10:25:57 PMAt what network size and data throughput does this become relevant?
VPP is a very fast and efficient packet processor and would allow to reach 10Gbit throughput on small, fanless devices.
E.g. the DEC740 can't do 10Gbit with OPNsense (it does 5-6 Gbit) and if the NICs were supported (which they are not) I could saturate my line.

Having said that: VPP seems best suited for routing, since it only supports ACLs (but they seem to be able to do firewall-ish rules).

Two articles about VPP on FreeBSD from Pim van Pelt (who used to run the SIxXS tunnel service with Jeroen Massar) for the interested:

https://ipng.ch/s/articles/2024/02/10/vpp-on-freebsd-part-1/
https://ipng.ch/s/articles/2024/02/10/vpp-on-freebsd-part-2/

He does work and develop for/with VPP (on Debian) and has got a lot of interesting articles about it, in a routing context.
#7
General Discussion / Re: Sonicwall TZ300 compatibil...
Last post by patient0 - Today at 07:21:33 AM
Searching the internet for "Sonicwall TZ300 cpu specs" returns https://www.reddit.com/r/sonicwall/comments/m6aemk/ram_and_cpu_specs_of_tz_models/.

It lists a few Sonicwall models, the TZ300 is one of them but there seem to be multiple generation.

QuoteTZ 300 1GB Ram 1.6GHz (2x 800MHz Mips64 Octeon Processor)

If correct, Mips64 would be a show stopper in any case.

Addition: In an TZ300 unboxing video (https://www.youtube.com/watch?v=ath1kafIRVM) at 9:25 it shows in the GUI 2x 800Hz Mips64 Octeon Processor under Dashboard / Multi-Core Monitor. You can verify it yourself if the SonicOS is still on your device.
#8
Hardware and Performance / Re: AX88179B USB NIC: 57 -> 97...
Last post by web - Today at 05:44:32 AM
thanks! yeah thats what made me go looking, the numbers just didnt add up for a superspeed link. hope it helps someone else with one of these!!
#9
General Discussion / Re: Allow Public Internet IPv4...
Last post by passeri - Today at 03:48:20 AM
Interestingly, the sentence starting "However" in the second paragraph said all that was necessary as an opening and probably sufficient question.

Given it looks like a question to or by AI, I decided to give just the critical sentence (with contextual "In OPNsense") to a local model (Qwen3.6 35B A3B in this case). After thinking strenuously for 1.2s (a minute elapsed) it came up with a lengthy explanation and correct answer, together with validation tests and informative notes for beginners.

That is not how I do OPNsense myself, but it seems that simple clear questions work either way.
#10
26.7 Series / Re: Internal DNS only works fo...
Last post by rheilke - Today at 01:24:49 AM
tangofan: thanks for the note about mDNS and TrueNAS. I'll check what QNap does.

Haven't seen XKCD in ages...