Recent posts

#1
Zenarmor (Sensei) / Re: Latest Zenarmor update bre...
Last post by Irishfluter - Today at 03:05:43 PM
Quote from: sy on Today at 07:00:18 AMHi,

Can you share the some of the domains which is blocked as malware and IPs of them?


Best regards

There are over 8000 entries over the past 72 hours.  Can you please tell me how to generate this information in a form that's useful to you?

Thanks.
#2
25.7, 25.10 Series / Re: DEC2752 - How to check har...
Last post by pfry - Today at 02:56:40 PM
Quote from: Seimus on Today at 12:56:46 PM[...]Stress-ng[...]

Does stress-ng generate enough load? I use good old mprime, but I boot Linux to run it (more CPU/sensor info). Even it will not load all CPUs effectively (e.g. low-turbo non-SMT Skylakes, and earlier version did not detect AVX support in Ryzens).
#3
General Discussion / Re: Kea Not Populating Hostnam...
Last post by stanps - Today at 02:51:50 PM
Unchecking "Auto collection option data" in the Kea config for the subnet, worked for me.
#4
25.7, 25.10 Series / 25.7.11_1 os-cpu-microcode-amd
Last post by MoonbeamFrame - Today at 02:44:51 PM
I updated a firewall from 25.7.10 yesterday only to find the firewall would no longer boot.

Rebuilding from scratch to 25.7.11_1 and then re-installing plugins led to the same result.

Rebuilding and iterating through the plugins led to os-cpu-microcode-amd being the cause.

The hardware is a Minisforum Ryzen 9 9955HX MS-A2.
#5
25.7, 25.10 Series / Re: Hostwatch - high disk writ...
Last post by pfry - Today at 02:44:14 PM
Quote from: franco on Today at 07:48:43 AMWe're recording the last MAC address for any IPv4 and IPv6 we see. If the MAC changes that's considered a "movement". In some environments this happens very rapidly and thus the service constantly registers the changes.

OK, thanks. This is just for virtual interface setup/teardown? Interesting. The behavior sounds... less than ideal. Not something I (and apparently others) would expect.
(The overall issue reminds me to always control information rate, unless a spew is intended.)
#6
25.7, 25.10 Series / Re: Hostwatch - high disk writ...
Last post by franco - Today at 02:31:13 PM
These typical UFS issues mainly are from unclean shutdowns regardless of where the corruption occurs.

If you have a process that is writing while the power goes off there will be an error for it. And if the process is writing all the time the chances are pretty high it's going to catch that one.


Cheers,
Franco
#7
25.7, 25.10 Series / Interfaces: Neighbors: Automat...
Last post by Rene78 - Today at 02:18:18 PM
Hi all,

Just upgraded to 25.7.11_1 from 25.7.10. Everything works as normal. Fiddling around with the new feature Interfaces: Neighbors: Automatic Discovery. Noticed that it works, but only with All interfaces selected. Any other subselection of interfaces, including Select All, prevents the service from starting.

See below for examples. When looking at the log (when using All) shows that the adds capture for the various interface devices. I have bridges configured (multiple eth-devices into different LANs (IOT and NET for example) and have pppoe0 as WAN (VLAN6 on physical interface - KPN FttH).

One error always shows up, and does not seem related. Is there when it works, and when the service does not start. No other logs are available in the GUI that show the reason for the service failing. Using promiscuous mode does not make a difference, nor does verbose logging for figuring out what is going wrong. All my interface types can be captured apparently...   

Successful when All:
2026-01-17T13:10:02.890816Z INFO hostwatch: Added capture for device: pppoe0 (WAN_INET (wan))
2026-01-17T14:10:02Noticehostwatch 2026-01-17T13:10:02.890344Z INFO hostwatch: Added capture for device: bridge1 (LAN_IOT (opt12))
2026-01-17T14:10:02Noticehostwatch 2026-01-17T13:10:02.889866Z INFO hostwatch: Added capture for device: bridge0 (LAN_INET (lan))
2026-01-17T14:10:02Noticehostwatch 2026-01-17T13:10:02.889356Z INFO hostwatch: Added capture for device: wg0 (ViperWG (opt13))
2026-01-17T14:10:02Noticehostwatch 2026-01-17T13:10:02.888815Z INFO hostwatch: Added capture for device: vlan03 (LAN_IPTV (opt10))
2026-01-17T14:10:02Noticehostwatch 2026-01-17T13:10:02.888242Z INFO hostwatch: Added capture for device: vlan02 (WAN_IPTV (opt8))
2026-01-17T14:10:02Noticehostwatch 2026-01-17T13:10:02.887692Z INFO hostwatch: Added capture for device: vlan01 (No description)
2026-01-17T14:10:02Noticehostwatch 2026-01-17T13:10:02.887166Z INFO hostwatch: Added capture for device: igb7 (ETH8 (opt9))
2026-01-17T14:10:02Noticehostwatch 2026-01-17T13:10:02.886684Z INFO hostwatch: Added capture for device: igb6 (ETH7 (opt11))
2026-01-17T14:10:02Noticehostwatch 2026-01-17T13:10:02.886156Z INFO hostwatch: Added capture for device: igb5 (ETH6 (opt6))

Error always visible (regardless if the service does or does not start):
2026-01-17T13:10:02.914762Z WARN hostwatch: Failed to initialize capture for device: pfsync0

Edit: Found some logs in the general log in settings.

At failure to start:
2026-01-17T14:15:15Noticekernel <6>[1488] pid 81926 (hostwatch), jid 0, uid 0: exited on signal 6 (no core dump - bad address)
2026-01-17T14:15:15Noticeroot /usr/local/etc/rc.d/hostwatch: WARNING: failed to start hostwatch
2026-01-17T14:14:54Noticekernel <6>[1467] pid 29596 (hostwatch), jid 0, uid 0: exited on signal 6 (no core dump - bad address)
2026-01-17T14:14:54Noticeroot /usr/local/etc/rc.d/hostwatch: WARNING: failed to start hostwatch

At successful start: no logs related to the service in General. Only the change in config XML file (enabled check).

#8
General Discussion / Re: Wireless Access Points
Last post by vimage22 - Today at 02:16:13 PM
I have been very happy with Zyxel NWA130BE (WiFi 7). I actually get 2.5gbs performance over WiFi.
#9
25.7, 25.10 Series / Re: Dnsmasq stops occasionaly
Last post by ligand - Today at 02:15:31 PM
addn-hosts=/var/etc/dnsmasq-hosts
#addn-hosts=/var/etc/dnsmasq-leases
  PID  RSS COMMAND
63604 5000 /usr/local/sbin/dnsmasq -x /var/run/dnsmasq.pid -C /usr/local/etc/dnsmasq.conf
Fri Jan 16 14:03:01 EST 2026
  PID   RSS COMMAND
63604 19156 /usr/local/sbin/dnsmasq -x /var/run/dnsmasq.pid -C /usr/local/etc/dnsmasq.conf
Fri Jan 16 15:03:01 EST 2026
  PID   RSS COMMAND
63604 39708 /usr/local/sbin/dnsmasq -x /var/run/dnsmasq.pid -C /usr/local/etc/dnsmasq.conf
Fri Jan 16 16:03:01 EST 2026
  PID   RSS COMMAND
63604 66068 /usr/local/sbin/dnsmasq -x /var/run/dnsmasq.pid -C /usr/local/etc/dnsmasq.conf
Fri Jan 16 17:03:01 EST 2026
  PID   RSS COMMAND
63604 90212 /usr/local/sbin/dnsmasq -x /var/run/dnsmasq.pid -C /usr/local/etc/dnsmasq.conf
Fri Jan 16 18:03:01 EST 2026
  PID    RSS COMMAND
63604 109960 /usr/local/sbin/dnsmasq -x /var/run/dnsmasq.pid -C /usr/local/etc/dnsmasq.conf
Fri Jan 16 19:03:01 EST 2026
  PID    RSS COMMAND
#10
German - Deutsch / Re: Hardware Suche N150 mit In...
Last post by carepack - Today at 02:08:13 PM
Hi nochmal,

jetzt wollte ich das Thema nochmal von der anderen Seite angehen. Aktuell hat der MiniPC zwei Anschlüsse mit Realtek Netzwerkchip und läuft sauber. Telekom Anschluss mit PppoE, WireGuard, zenarmor. Auch die Performance passt gut.

@meyergru und @patrick, ihr habt da sicherlich mehr Erfahrungswerte als ich. Ist ein Betrieb mit Realtek soweit ok oder muss ich befürchten, dass bei jedem Update oder so die Chance mit Realtek höher ist, dass etwas nicht klappt? Also sind mit Realtek Chipsätzen mehr Probleme zu erwarten oder kann man die Realteks bedenkenlos einsetzen, weil der Problematik mittlerweile beigekommen ist und der Treiber soweit stabil ist?

Erneut vielen Dank für eueren Input.

Grüße