Recent posts

#1
26.7 Series / Re: 26.7.2 firewall logging bu...
Last post by hharry - Today at 03:29:12 AM
i had the same issue, and the patch also worked.

@franco, will the patch be included in next release ?
#2
26.7 Series / Re: Incorrect firewall rule re...
Last post by opnwall - Today at 03:27:25 AM
Resolved after the update; citations are working correctly.
#3
26.7 Series / Re: Incorrect firewall rule re...
Last post by hharry - Today at 03:25:28 AM
Did you migrate your legacy firewall rules, to the new firewall rules ?

I migrated some time ago, and the icon/link to firewall rules in  interfaces > overview page is working without any issues for me...
#4
26.7 Series / Incorrect firewall rule refere...
Last post by opnwall - Today at 03:11:53 AM
Due to the firewall rules utilizing a new page, the previously referenced page link is no longer valid; consequently, clicking the firewall rule button results in a "Page not found" error.
#5
26.7 Series / hostapd 2.12 (26.7.2) — AP bro...
Last post by cercle - Today at 03:02:50 AM
Titre : hostapd 2.12 (26.7.2) — AP broadcasts open/unprotected after upgrade (WPA security not applied)

Environment

OPNsense version: 26.7.2 (upgraded from 26.7.1_1)
Hardware: PC Engines APU6
Wi-Fi card: wle200nx
hostapd version before: 2.11 (working correctly)
hostapd version after upgrade: 2.12 (issue observed)

Description

After upgrading from 26.7.1_1 to 26.7.2, the Wi-Fi access point configured via hostapd on this system started broadcasting without any WPA/WPA2 protection — the SSID became open and unencrypted, despite the security configuration (WPA2-PSK) remaining unchanged in the GUI (Interfaces → Wireless).

Steps to reproduce

Configure a Wi-Fi interface as AP mode with WPA2-PSK security on 26.7.1_1.
Upgrade to 26.7.2 (bumps hostapd/wpa_supplicant from 2.11 to 2.12).
Observe that the AP is broadcasting open, with no encryption enforced.

Expected behavior

WPA2 security configured in the GUI should be preserved and enforced after the package upgrade.

Actual behavior

AP is open/unprotected, exposing the network to any nearby device without authentication.

Workaround

Reverted hostapd and wpa_supplicant to 2.11 via:

opnsense-revert -r 26.7.1 hostapd wpa_supplicant
pkg lock -y hostapd wpa_supplicant

This restored correct WPA2 enforcement.

Impact

This is a security-relevant regression — administrators upgrading to 26.7.2 with a Wi-Fi AP configured may be unknowingly exposing an open network.
#6
26.7 Series / Re: Services widget looks grea...
Last post by hharry - Today at 01:59:21 AM
also having the new and same issue...long items, like gateways and VPNs, run into the next column...

#7
26.7 Series / Re: Services widget looks grea...
Last post by muchacha_grande - Today at 01:12:35 AM
Awesome. It can't be better... wow!!
#8
26.7 Series / Re: Services widget looks grea...
Last post by Seimus - Today at 12:49:16 AM
Yea I see the same, the new widget looks great to the overall theme, but it was problem with longer names.

I would however not remove them from the service widget. As you can easily restart those using the service widget itself.
Its very handy.

Regards,
S.
#9
26.7 Series / Re: VLAN devices are on LAN IP...
Last post by tonys - August 12, 2026, 11:27:00 PM
I'll continue testing without the external VPN and if anything changes, I'll post here.
#10
German - Deutsch / Re: Wie halte ich meinen Backu...
Last post by viragomann - August 12, 2026, 11:14:04 PM
Quote from: thogru on August 12, 2026, 07:55:50 PMDann blieben noch die Netze für LAN, DMZ und WLAN nach und es bleibt das Problem mit dem fehlenden Interface für das pfSync-Netz.
Ein gesondertes Interface für Sync ist empfohlen, aber nicht zwingend nötig.

Auch ist HA keine zwingende Voraussetzung, um die Konfiguration von einer Instanz auf eine weitere zu synchronisieren, aber es vereinfacht das ein Umschalten ungemein. Genau dafür ist es gemacht. Die Möglichkeit, die Konfig zu syncen komplettiert die Sache nur.
Wenn beide aktiv laufen, bleiben sogar die meisten Verbindungen erhalten, sofern sie synchronisiert werden.

Quote from: thogru on August 12, 2026, 07:55:50 PMKann ein "üblicher" managed Switch den ganzen Verkehr von LAN, DMZ und WLAN so auseinander dröseln, dass die Daten nur an bestimmten Ports (und ohne VLAN-IDs für LAN und DMZ) des Switches herauskommen? Oder benötige ich für meine Anforderungen einen speziellen Switch?
VLAN-fähig muss der Switch sein, dann kann er das. Der Ausdruck "managed" könnte so manches Andere bedeuten, wenngleich meist das gemeint ist.

Quote from: thogru on August 12, 2026, 07:55:50 PMst es überhaupt "sicher" alle Netzwerk in einem Switch zusammenzuführen, um diese anschließend auf dezidierte Ports am Switch zu leiten?
Wenn er korrekt konfiguriert ist, ja.

Quote from: thogru on August 12, 2026, 07:55:50 PMWürde so etwas mit IPv4 und IPv6 funktionieren?
Ja, die IP-Version ist dem VLAN grundsätzlich egal und umgekehrt. Die VLAN-Segmentierung passiert am Layer 2, IP in 3.

Quote from: thogru on August 12, 2026, 07:55:50 PMKann ein Switch aus einer 192.168.148.0/24 VLAN 40 eine 192.168.131.0/24  VLAN 10 machen?
Warum sollte er das tun? Ich denke, ich verstehe die Frage nicht.

Quote from: thogru on August 12, 2026, 07:55:50 PMOder gehen quasi alle IP-Adressen gemeinsam auf ein Interface aus?
Es geht hier mehr um virtuelle Netzwerksegmente.
Ein Switch Port, der so konfiguriert ist, dass er an das VLAN 10 angebunden ist, ohne dass angeschlossene Geräte etwas vom VLAN merken (untagged, PVID), lässt nur Pakete vom VLAN 10  raus bzw. eingehende gehen nur ins VLAN 10.
Der Port, den du bspw. mit der OPNsense verbindest muss so konfiguriert sein, dass alle VLANs drüber gehen (Trunk). Allerdings gibt es da kein "Übersprechen", wenn ordentlich konfiguriert. In OPNsense hättest du für jedes VLAN ein Interface eingerichtet, und nur auf dieses laufen die Pakete.

Quote from: thogru on August 12, 2026, 07:55:50 PMAktuell nutze ich IPv6 nicht. Muss ich bei der Anschaffung des Switches die eventuelle Nutzung von IPv6 bei der Auswahl des Switches berücksichtigen?
Nein. Bzw. nur, wenn er Layer 3 machen soll.

Quote from: thogru on August 12, 2026, 07:55:50 PMKönnt Ihr mir überhaupt empfehlen, an dieser Stellen weiterzudenken in Anbetracht meiner hier gestellten Fragen?
Es hätte was Gutes: Du würdest was lernen. :-)
Anfängliche Probleme musst du einkalkulieren. Ob sich der Aufwand für deinen Zweck lohnt, musst du entscheiden.

Grüße