Recent posts

#1
26.7 Series / OPNsense 26.7.5 update
Last post by (MARLOO) - Today at 02:24:17 PM
Hi everyone,

I upgraded my OPNsense installation to version 26.7.5.

After the upgrade, I applied the new password-security feature by changing my administrator password. This regenerated the password hash using the new Argon2id method instead of the previous bcrypt hash.

Regarding Unbound, I confirmed that it is running correctly on the configured LAN and VLAN interfaces. DNS resolution continued to work normally after the upgrade, with no additional configuration changes required.

Regarding NAT, I checked the new Source NAT section under:

Firewall → NAT → Source NAT

My existing NAT configuration continued to work normally after the upgrade, so no migration or rule changes were required.

Other changes include:

- improved interface dependency handling and boot-order diagnostics;
- improved HA service restart handling;
- Kea DHCP ping-check settings for subnets;
- improved gateway group ACL handling;
- stricter packet-capture archive handling;
- improved backup verification after upload;
- updates to opnsense-patch and opnsense-prefetch;
- OpenSSL updated to 3.5.9;
- package manager updated to 2.8.4;
- updates to ddclient, the firewall legacy plugin, Net-SNMP, Puppet Agent and several themes.

So far, everything is working normally for me after the update.

Thanks to the OPNsense developers for the work on this update!
#2
26.7 Series / Re: OPNsense 26.7.4 - VLAN tra...
Last post by Patrick M. Hausen - Today at 01:28:02 PM
Sometimes it's just how your apartment or office is built, the location of the "Internet socket", and so on. E.g. years ago in the office of my wife there was a single network connection to a small cabinet on which the laser printer was placed and it was decided that the new FreeNAS was to be put next to the printer. So I bridged the two ports of the NAS to connect NAS and printer to the network via that single line - why not? Instead of messing with an extra switch, needing yet another power outlet etc.

The OP might tell us their reasons :-)
#3
Tutorials and FAQs / How do you setup bitwarden on ...
Last post by kbthomelab88 - Today at 01:27:05 PM
How do you setup bitwarden on nginx plugin? I have set it up since the update suddenly it's stop working and i'm trying resolve the problem to get it back to working and has the setting change? if you could let me know if happen to you and got it working please let me know.

Many thanks
#4
26.7 Series / Re: OPNsense 26.7.4 - VLAN tra...
Last post by RES217AIII - Today at 12:50:26 PM
To reiterate: My focus is on understanding the situation. There have already been several discussions on the forum regarding the use of OPNsense as a bridge.
And as I have learned, there are circumstances that make bridging necessary—though it remains only the second-best option.
Even though FreeBSD's bridge mode can work well, I do not understand why one would want to use it.
If you are building a network and planning network segmentation for valid reasons, the setup looks like this:

ISP – OPNsense Router – VLAN Trunk – Switch Segmentation – Clients in different network segments.

You could certainly make it more complex by separating the routing and firewall functions, but what advantage would that offer in the context of the described setup and requirements?
#5
Zenarmor (Sensei) / Re: Zenarmor Cloud Agent servi...
Last post by sy - Today at 12:47:13 PM
Hi all,

Thank you for your patience. A fix for this issue will be included in version 2.7.1.


Best regards

#6
26.1, 26,4 Series / Re: Dynamic DNS ddclient confi...
Last post by franco - Today at 12:31:29 PM
Feels a bit unnecessary but ok.  I'll make a note in https://github.com/opnsense/core/issues/9948


Cheers,
Franco
#8
26.1, 26,4 Series / Re: Dynamic DNS ddclient confi...
Last post by Greelan - Today at 12:21:04 PM
Quote from: franco on Today at 08:45:55 AMbut a breaking change
The main breaking change is the change of the default config location from /usr/local/etc/ to /usr/local/etc/ddclient/.
#9
26.7 Series / Re: Invalid link to Outbound N...
Last post by franco - Today at 11:54:35 AM
Thanks, nice spot. The firewall advanced settings page is going away in 27.1 so we need to be a bit careful with a change that alters the page.  Maybe only a fix on stable/26.7.


Cheers,
Franco
#10
26.7 Series / Invalid link to Outbound NAT i...
Last post by bamf - Today at 11:49:57 AM
[ ] Disable all packet filtering.
Warning: This will convert into a routing-only platform!
Warning: This will also turn off NAT!
If you only want to disable NAT, and not firewall rules, visit the Outbound NAT page.

I think this should point to the new d_nat page.