Recent posts

#1
26.7 Series / Re: New Source NAT page
Last post by Monviech (Cedrik) - Today at 09:44:23 PM
Can you share what you have configured in /conf/config.xml (your config backup) for these Source NAT rules?

Also what is your NAT mode?
#2
26.7 Series / New Source NAT page
Last post by Ted - Today at 09:31:03 PM
Greetings,
I have an OPNsense box running 26.7.2_2-amd64. The WAN interface has a static /29 subnet. Some IPs are used for specific servers. In previous versions of OPNsense, I used Outbound NAT to direct internal servers to a specific external address.

When I upgraded to 26.7, I decided to migrate the Outbound NAT rules using the steps outlined under the Migration assistant. I downloaded the Outbound rules, looked over the CSV file, and then uploaded the CSV file. I tested from an external network, and everything appeared to be working. I went to look at the new Source NAT page, and the page claimed to be "showing 1 to 4 of 4 entries", which sounded right. However, no entries were actually displayed.

I decided that it should not cause a problem if I manually added the rules. (If it did, I could always delete them). Again, I tested the servers from an external network, and everything appeared to be working. I went back to look at the new Source NAT page, and the page claimed to be "showing 1 to 8 of 8 entries", which sounded like I had managed to double up on my rules. However, this time, 4 entries were displayed (most likely the ones I added manually).

This doesn't seem to be causing a functional problem, and I'm inclined to leave it alone lest I break something. Do I really have eight rules? If necessary I can SSH in and edit a config file. Is the wrong count displayed? In that case I can learn to ignore it.

Grateful for any suggestions on this.
Thanks,
Ted
#3
26.7 Series / Re: SSH to opnsense fails afte...
Last post by dseven - Today at 09:28:30 PM
Are you sure you're actually ssh'ing to the opnsense box? Maybe you have destination NAT for port 22 or something???
#4
General Discussion / CRON troubleshoot
Last post by kweefc - Today at 09:11:12 PM
hi i want to ask about this cron for geoip database auto update doesn't run. its bugged?
#5
26.7 Series / Re: SSH to opnsense fails afte...
Last post by revr3nd - Today at 08:58:09 PM
Quote from: dseven on Today at 07:50:38 PMRegardless of key type, if password authentication is enabled, there should be a password prompt if the publickey method fails, so there's something else not right here.

OP, when this worked prior to the upgrade, were you prompted for a password, or did you get straight in with the key?

Check System -> Log Files -> Audit for clues (maybe change level to "Informational")

Only items in the audit logs are just starting and stopping of the process. Does not appear to generate any logs of connection attempts


2026-08-19T10:37:57-07:00InformationalsshdServer listening on 127.0.0.1 port 22.
2026-08-19T10:37:57-07:00InformationalsshdServer listening on fe80::1%lo0 port 22.
2026-08-19T10:37:57-07:00InformationalsshdServer listening on fe80::227c:14ff:fef4:381d%vlan0.10 port 22.
2026-08-19T10:37:57-07:00InformationalsshdServer listening on 192.168.11.1 port 22.
2026-08-19T10:37:57-07:00InformationalsshdServer listening on fe80::227c:14ff:fef4:381d%vlan0.11 port 22.
2026-08-19T10:37:57-07:00InformationalsshdServer listening on fd00:0:0:11::1 port 22.
2026-08-19T10:37:56-07:00InformationalsshdReceived signal 15; terminating.




Regarding rollback of the process itself, I will need to go on site to console into the device. This will take some time :/
#6
Tutorials and FAQs / Re: new to OpenSense and like ...
Last post by comet424 - Today at 08:33:03 PM
i setup the CA  i trying to setup OpenVPN for PIA_Toronto   it wont show up as a certificate.

i was watching a video to set it up  by importing the cert  but i did that  it should have said self signed

and when setting up i should have that cert show up but its not..
or is it best to ask in IRC chat.. i didnt think anyone still used it since i been on IRC since 1989

here the photos i stuck with
#7
Tutorials and FAQs / Re: new to OpenSense and like ...
Last post by comet424 - Today at 08:20:56 PM
ah kk

anyway you know why then CA isnt self assigned after being imported
#8
26.7 Series / Re: Interfaces: Virtual IPs: S...
Last post by Patrick M. Hausen - Today at 08:19:26 PM
Gemini is stating BS. You cannot deprive a bridge device from operating on layer 3. It never will, because a bridge is layer 2.
#9
Im sure you can get the setup working eventually.

Please don't post so much, it's a forum and not a chat.

We also have an IRC chat here:
https://libera.chat/
Channel: #opnsense

Just have to be a bit patient, most of the time somebody replies and helps.
#10
Tutorials and FAQs / Re: new to OpenSense and like ...
Last post by comet424 - Today at 08:11:14 PM
for the rules when you expand them all it is stuck in a iframe style window

is there no way to set it to be a regular display..  to scroll or are you you limited to just in a set window size.. i tried blowing up and reducing screen size of the browser.. but the rules still stays in a predefined frame that has to be seperately scrolled.. if you cant turn that off thats ok i just asking