Recent posts

#1
Incidentally, mine is now again failing to enumerate the USB serial console on the admin PC (currently a Linux box).

You cannot view this attachment.

In 'dmesg' there's some USB related error:

[  158.544011] usb 1-1: new full-speed USB device number 12 using xhci_hcd
[  158.748063] usb 1-1: device descriptor read/64, error -71
[  159.032069] usb 1-1: device descriptor read/64, error -71
[  159.313023] usb 1-1: new full-speed USB device number 13 using xhci_hcd
[  159.517076] usb 1-1: device descriptor read/64, error -71
[  159.800081] usb 1-1: device descriptor read/64, error -71
[  159.905782] usb usb1-port1: attempt power cycle
[  160.354040] usb 1-1: new full-speed USB device number 14 using xhci_hcd
[  160.380898] usb 1-1: Device not responding to setup address.
[  160.616897] usb 1-1: Device not responding to setup address.
[  160.822041] usb 1-1: device not accepting address 14, error -71
[  160.822140] usb 1-1: WARN: invalid context state for evaluate context command.
[  161.001048] usb 1-1: new full-speed USB device number 15 using xhci_hcd
[  161.027898] usb 1-1: Device not responding to setup address.
[  161.264898] usb 1-1: Device not responding to setup address.
[  161.470051] usb 1-1: device not accepting address 15, error -71
[  161.470150] usb 1-1: WARN: invalid context state for evaluate context command.
[  161.473864] usb usb1-port1: unable to enumerate USB device

On the OPNsense side, 'dmesg' shows that the console is up.  The 'FCR is broken' part was always there, so ignoring that.

[1] uart: ns8250: UART FCR is broken (0x1)
[1] uart0: <16550 or compatible> port 0x3f8-0x3ff irq 4 flags 0x10 on acpi0
[1] uart0: console (115200,n,8,1)

Anything else I can check in OPNsense?  The serial console is already enabled and set as primary in admin settings.  Haven't changed anything there.

I hope it's just the battery again and ordered a couple to try.
#2
FYI,

I finally got the nerve to try again, and this time the upgrade to 26.1 went smoothly.  I'll go to the next version in a week or so, and also have to migrate DHCP at some point down the road.

Thanks for the help...
#3
26.7 Series / Re: Fresh Install OPNsense 26....
Last post by Schwermzilla - Today at 01:01:56 AM
So the problem is your WiFi Orbi Unit and not OPNsense then ?!

It may be a part of the current config problem, to test that, I have just plugged my laptop into port 1 and 8 to test vlan 11 and 22 and it also doesn't connect to the internet on either port in access mode for their respective vlans.
So, I am primarily trying to diagnose the managed switch and it's connection to OPNsense, so far, when I change any connection on the switch that connects to OPNsense to Trunk, I lose communication on that port (showing 0 bytes received over 30 mintues).
Not expanded above, but I have previously attempted to have the lan port assigned the non-vlan 192.168.1.x in addition to the tagged vlans of 11 and 22 (with lan/igc1 as parent), but I assumed it was sending the LAN as untagged traffic, and read elsewhere that the switch was expecting three vlans. When I was testing this I kept losing access to the OPNsense over the network when switching to Trunk mode on the switch, so I set one port, igc1, to be untagged LAN access and am attempting to diagnose the pathway of just vlans 11 and 22 from igc2 on the router, to port 5 on the switch in Trunk/Uplink mode, and then handing over vlan exclusive Access to 11 or to port 8 as exclusive access to 22, neither have worked. Essentially ignoring the AP for now.

The current connection of ports 2,3,4,6,7 are running on untagged Lan so I can continue to interface with network devices and troubleshoot the vlan path, do you think that is causing problems?

Do those things even understand VLANs on their Switch/LAN side ??
AFAIK they do not : Only on the WAN Port.


Those things being the wireless AP? and the NVR?
AP, yes I have its incoming port from the switch set to Trunk, and have the wireless network setup expecting tag 11 for the guest network wifi.
NVR, no, which is why I have it's port setup as Access - 22, expecting the netgear to provide untagged access exclusively to vlan 22. 

Also currently your Netgear Switch shows Port 3 as Access Port and those do not transport VLANs ofcourse...
Yeah, hope that is not what is causing the problem. as expanded above, other devices are runninng on LAN without tags. Hoping this would isolate the switch's Port 5 trunk port to the OPNSense igc2 connection, assigned just the two vlans and testing with the AP and a laptop for connection on either port 1 for vlan 11 or port 8 for vlan 22
#4
26.7 Series / Re: Fresh Install OPNsense 26....
Last post by nero355 - Today at 12:14:12 AM
Quote from: Schwermzilla on October 01, 2026, 10:35:24 PMLast relevant connection on the switch, port 1 goes to my wireless AP (Netgear Orbi Pro 6, SXR80) setup in AP mode, which works on local network access when tested.

On the Orbi, it has been setup in Trunk mode since being in AP, I have two id's broadcasting there, one for 192.168.1.x (local) and the other for 192.168.11.x. (guest).
I have tried running port 1 on the switch in trunk/uplink mode as well, but then I lose connection to the orbi in either Trunk or Access vlan 11 only (pictured).

The only way it works is when it is set to access only local vlan 1 : Then devices on the local wifi work fine, devices on the guest wifi connect to the Orbi but have an IP configuration error and aren't assigned DHCP leases, as expected.
So the problem is your WiFi Orbi Unit and not OPNsense then ?!

Do those things even understand VLANs on their Switch/LAN side ??
AFAIK they do not : Only on the WAN Port.

Also currently your Netgear Switch shows Port 3 as Access Port and those do not transport VLANs ofcourse...
#5
26.7 Series / Re: Sudden shutdown of all int...
Last post by (MARLOO) - Today at 12:00:12 AM
Hi Urban,

What you're seeing looks very much like a driver/hardware issue on the 10G interfaces (ixl) that drags down the whole LAN side and, as a side effect, breaks WAN monitoring and PPPoE.

Key points from your logs:

ixl0/ixl1: Interface stopped DISTRIBUTING, possible flapping

lagg0: link state changed to DOWN

DEVD: Ethernet detached event for opt2(lagg0)

Those "possible flapping" messages are typical of the ixl driver when it detects abnormal conditions (errors, watchdog, DMA issues, etc.) and stops the interfaces. When lagg0 goes down, all VLANs on top of it disappear, dpinger loses its route, and PPPoE stops getting LCP echoes – so it looks like "everything died", even if the WAN PHYs are still up

----------------------------------------Things I'd check-----------------------------------------------------------------------------------------------------

Full system.log around the incident for ixl0/ixl1 errors: watchdog, TX/RX hang, DMA, no buffers.

ifconfig ixl0, ifconfig ixl1, ifconfig lagg0 and netstat -i for growing error counters.

Lagg type vs switch config (LACP/failover, active/passive, speed/duplex). If you don't need aggregation, try failover or a single 10G temporarily.

OPNsense forum for 26.7.x + ixl/lagg + "interface down" / "flapping"; in some cases, rolling back version fixed similar issues.

Basic hardware checks: different SFP+/DAC ports, cables, and (if available) disable PCIe power saving in BIOS..

If you can share a larger log excerpt (anonymized) and your lagg/VLAN config, it's easier to narrow down whether this is driver, switch negotiation, or hardware


-------------------------------------------------------------------------------------------------------------------------------------------------------------
These kinds of issues often show up only in specific hardware/driver/topology combinations (Protectli + Intel 10G + LACP + certain switches), so they may not be obvious in general testing and only surface in production setups like yours.

That doesn't mean you must run the absolute latest release everywhere. A pragmatic approach that many use:

Keep your current version on staging and monitor for similar symptoms.

If you see any 10G/ixl/lagg‑related fixes in later release notes, consider testing those on staging before deciding whether to move production.

For critical sites, maintain a known‑good version and only move after checking forums/issues for regressions on your hardware.
-------------------------------------------------------------------------------------------------------------------------------------------------------------

Check interface status and errors

ifconfig ixl0
ifconfig ixl1
ifconfig lagg0

Look for:

status: (active / no carrier)
****************************************************
Counters like input errors, output errors, collisions, dropped.

Then:

netstat -i

Check if ixl0/ixl1 show increasing error counters compared to other interfaces
****************************************************************
grep -i "ixl" /var/log/system.log | less
dmesg | grep -i "ixl"

Search for patterns like:

watchdog timeout

TX hang / RX hang

DMA error

no buffers

descriptor errors
****************************************

ifconfig lagg0

*****************************************
During normal operation

top -P
systat -if 1
*****************************************
maybe this will help your troubleshooting
#6
General Discussion / Re: PowerShell script to assis...
Last post by badbroccoli - October 01, 2026, 11:52:02 PM
Quote from: steamy24 on July 26, 2025, 11:20:16 AMHello,

there is an error running the script:

Line |
  68 |      throw "File $OPNSenseBackupXML not in expected format"
     |      ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
     | File [...].xml not in expected format

I only have a dhcpd-section, but not a dhcpdv6-section in my XML.....

This has been resolved in the latest commit of this script. Apologies for the delay - I didn't have post reply notifications enabled.
#7
General Discussion / Re: Telekom SIP Trunk becomes ...
Last post by lmoore - October 01, 2026, 11:11:15 PM
Quote from: Xaver on October 01, 2026, 02:57:32 PMAny suggestions on what I could check next would be greatly appreciated.

Is this a new installation or has it worked in the past?

I'm unable to resolve any SRV records for tel.telekom.de, but this may be because I am elsewhere in the world.

Searching the net it appears the SIP server to use is tel.t-online.de and SRV records can be resolved for this address.

Perhaps this page will help: https://www.telekom.de/hilfe/internet-telefonie/telefonie/voice-over-ip-sip-client

Another tidbit I came across is you need to be querying the DNS servers offered by Telekom to ensure it works: https://support.yeastar.com/hc/en-us/articles/360014536894-Recommended-SIP-Configuration-for-Deutsche-Telekom

Which DNS servers are used by the ATA?

If you find you can receive a call as soon as the ATA has registered, but you can't receive an incoming call after a couple of minutes, or until the next registration, you could drop the Keep-Alive interval to 25 seconds. If you use TCP for the SIP connection the state timeout should be the default of 86400 seconds when it is established.

I recently moved some numbers to another ITSP and I'm using TLS and SRTP. I've set the registration interval for this service to 5 minutes.

Have you created specific firewall rules for your VoIP service?

You mentioned you disabled 'Normalization', are you referring to OPNsense?

Does the QoS from Telekom use DSCP and do you know what values these should be?

Quote from: nero355 on October 01, 2026, 08:24:17 PMDon't you need to do some Port Forwards for VoIP

I haven't encountered a situation where port-forwarding has been required for VoIP. Providing the connection that your registration is going through is kept alive, incoming calls should reach the ATA.
#8
General Discussion / Re: Telekom SIP Trunk becomes ...
Last post by muchacha_grande - October 01, 2026, 10:49:56 PM
@Xaver, if you are using an updated OPNSense version, you can migrate Outbound NAT to Source NAT. Once migrated there is a new option in the Source NAT rule called "endpoint independent". You can try enabling that. Is the "full cone nat"

It seems to me that this option is not present in the old Outbound NAT rule menu but if it is, you don't need to migrate to the new system.
#9
26.7 Series / Fresh Install OPNsense 26.7, u...
Last post by Schwermzilla - October 01, 2026, 10:35:24 PM
Hello OPNsense forum, I apologize if this is a novice problem, but it has stumped me for days at this point and I have been searching here and at netgear's forum and not found anyone sharing the same problem, I have seen some related posts which I have tried to replicate the solutions of, to no success.

Scenario: I have OPNsense 26.7.4_1 running on a 5 port miniPC (Intel N150, 128gb ssd & 8GB ram), the pc has 3 2.5Gb ports and 2 10Gb SFP ports. Currently, I am just using the 2.5Gb ports, as I want to verify vlans work before I add more complexity. To keep things simple, I am working on a reduced complexity as things weren't working in a previous, more complex state either. So, I recently did a fresh install and full update because I was at wits end.
I am only able to upload one photo here because of image size, full folder is available here: https://drive.google.com/drive/folders/1YmCybrYoM4dVkMVTz_UjtMY8Dn6Zi6km

Currently: LAN and WAN access work great, stable internet, DHCP leases working, Static IP config for the managed switch, wireless AP, and NAS.
Port 1 is WAN (igc0/Wide_Network in photos).
Port 2 is the LAN (igc1/Local_Network in photos).

Problem: I am trying to setup Port 3/igc2 as a truncated vlan port with only two tagged vlans on it;
tag 11 is the Guest_Network, tag 22 is the Surveillance_Network. I have setup the vlans, enabled them as interfaces, added static ipv4 addresses, allowed firewall access and allocated DHCP address pools (verifiable in the photos).
I have split out the Local_Network and vlans on separate ports, as I have seen others have issues with mixing tagged and untagged traffic on the same port with netgear/Opnsense.
The photo (netgear_ports) shares the mapping on the Netgear managed switch; ports 4/5 are connected to OPNSense, port 4 is paired with igc1 (Local), port 5 with igc2 (vlan Trunk).  Port 8 will go to an NVR which has POE ports for the cameras (haven't turned this on yet). Last relevant connection on the switch, port 1 goes to my wireless AP (Netgear Orbi Pro 6, SRX80) setup in AP mode, which works on local network access when tested. On the Orbi, it has been setup in Trunk mode since being in AP, I have two id's broadcasting there, one for 192.168.1.x (local) and the other for 192.168.11.x. (guest). I have tried running port 1 on the switch in trunk/uplink mode as well, but then I lose connection to the orbi in either Trunk or Access vlan 11 only (pictured). The only way it works is when it is set to access only local vlan 1; Then devices on the local wifi work fine, devices on the guest wifi connect to the Orbi but have an IP configuration error and aren't assigned DHCP leases, as expected.

My understanding of the problem, when in Trunk/Uplink mode, the Netgear switch is not seeing the incoming tagged traffic on igc2/port 5. Running in diagnostic mode shows zero "bytes received" on that port, the screenshot was captured after 30 mins or so. I am not confident OPNsense is sending anything, but I don't see any issues with my configuration from the OPNsense side.

Any help would be wonderful, I had spoken with my friend who is an SRE, and he gave me a bit of sanity check that I didn't have anything obviously setup wrong, but who knows, so I come to you all in hopes of finding a solution. THANK YOU!
#10
26.7 Series / Re: Upgrade Candidate Discrepa...
Last post by franco - October 01, 2026, 09:23:07 PM
Well this looks as expected.


Cheers,
Franco