Recent posts

#1
Spanish - Español / Ayuda con la apertura de puert...
Last post by Distroyer - Today at 02:04:04 AM
Hola,

Tengo OPNsense instalado en un equipo dedicado desde hace algún tiempo y todo mi tráfico y servicios pasan a través de él. Soy bastante nuevo en temas de redes, así que básicamente he configurado lo necesario usando los valores por defecto y siguiendo algunas guías en línea para tareas específicas, pero nada especialmente avanzado.

Recientemente quise jugar con unos amigos y aprovechar la infraestructura que ya tengo para alojar un servidor. El problema es que mi OPNsense está detrás del router de mi proveedor de Internet, por lo que actualmente tengo una configuración de doble NAT.

Cuando instalé OPNsense no realicé ninguna configuración especial. Simplemente conecté la interfaz WAN de OPNsense a uno de los puertos Ethernet del router del ISP y comencé a utilizarlo. Todos mis experimentos y servicios están dentro de la red gestionada por OPNsense y, hasta ahora, no había necesitado nada más. Sin embargo, en cuanto he necesitado que un servicio sea accesible desde Internet, han empezado los problemas.

Concretamente, necesito ayuda para configurar un la redirección de un puerto. Lo que quiero es redirigir el puerto 50505 (UDP) hacia una IP específica dentro de mi red OPNsense (por ejemplo, una IP del rango 192.168.1.x).

Entiendo que también debo configurar el reenvío de puertos en el router de mi ISP y no tengo ningún problema con ello. De hecho, hice una prueba ejecutando el mismo servicio directamente detrás del router del ISP, sin pasar por OPNsense, y funcionó correctamente.

Sin embargo, por alguna razón, ninguna de las guías que he encontrado ni las indicaciones proporcionadas por herramientas de IA (Google Search y Microsoft Copilot) me han funcionado. Lo que explican parece tener sentido, pero en la práctica no he conseguido que nada funcione en mi entorno. Por eso estoy aquí, buscando ayuda específica para mi caso.

Esta es la infraestructura completa que tengo actualmente para llegar desde Internet hasta el servicio:

Internet → Router del ISP → WAN de OPNsense* → LAN de OPNsense → Servidor (IP local) con un servicio escuchando en el puerto UDP 50505

*Actualmente estoy en proceso de implementar High Availability (HA) en mi infraestructura OPNsense. En este momento tengo dos direcciones IP configuradas detrás del router del ISP, ambas estáticas: una dirección física y una dirección virtual. La configuración HA todavía no está terminada porque aún no tengo listo el segundo dispositivo. Además, ya tengo reservada una tercera IP para completar la implementación cuando llegue el momento.

No sé si esta configuración incompleta de HA podría estar provocando el problema o si no tiene relación alguna. Es parte del motivo por el cual lo menciono.

La configuración actual que tengo para atravesar el doble NAT es la siguiente:

Router del ISP → Redirección del puerto 50505 UDP hacia la IP virtual utilizada por HA en la WAN de OPNsense → Redirección del puerto 50505 UDP hacia el servidor con IP estática que ejecuta el servicio en el puerto 50505 UDP

Voy a adjuntar una captura de pantalla de la configuración actual para que puedan ver exactamente cómo lo tengo configurado.

Si necesitáis más información o contexto sobre algún aspecto concreto, no dudéis en decírmelo y os proporcionaré todos los detalles que hagan falta.

Muchas gracias de antemano.
#2
26.7 Series / Port Forwarding HELP for 26.7....
Last post by Distroyer - Today at 01:58:15 AM
Hello,

I have been running OPNsense on a dedicated machine for some time, and all my devices and services are behind it. I'm still quite new to networking, so I have mostly configured the default settings and followed a few online guides for specific tasks, but nothing particularly advanced.

Recently, I wanted to play a game with some friends and host a server using my existing infrastructure. The problem is that my OPNsense firewall is behind my ISP's router, which means I have a double NAT setup.

I did not perform any special configuration when I installed OPNsense. I simply connected the OPNsense WAN interface to one of the ISP router's Ethernet ports, and that was it. All my experiments and services run within the OPNsense network, and until now I never needed anything different. However, as soon as I needed external access to something inside my network, I started running into problems.

Specifically, I need help configuring port forwarding. I need to forward port 50505 (UDP) to a specific IP address within my OPNsense network (something like 192.168.1.x).

I understand that I also need to configure port forwarding on the ISP router, and I have no problem doing that. In fact, I tested the same service directly behind the ISP router without OPNsense, and it worked correctly.

However, for some reason, none of the guides I found online, nor the instructions provided by AI tools (Google Search and Microsoft Copilot), have worked in my case. Their explanations seem logical, but no matter what I try, I cannot get it working. That is why I am here looking for a solution specific to my setup.

This is my network infrastructure from the Internet to the service, to provide a complete overview:

Internet → ISP Router → OPNsense WAN* → OPNsense LAN → Server (local IP) running a service on UDP port 50505

* I am currently in the process of implementing High Availability (HA) for my OPNsense setup. Right now, I have two IP addresses assigned by the ISP router, both static: one physical IP and one virtual IP. The HA configuration is not complete yet because I do not have the second device ready. A third IP address has also been reserved for the future setup.

I am not sure whether this unfinished HA configuration could be causing the problem or not, which is one of the reasons I am asking for help.

My current port-forwarding configuration for the double NAT setup is the following:

ISP Router → Forward UDP 50505 to → Virtual IP used by the OPNsense WAN HA configuration → Forward UDP 50505 to → Server with a static IP running the service on UDP 50505

I will attach an screenshot of the relevant configurations that may help explain my setup and show what has already been configured (my layout is in Spanish :P).

If you need any additional information or context, please let me know and I will be happy to provide it.

Thank you.
#3
26.7 Series / Re: Good News: Less Memory-Saf...
Last post by pfry - Today at 12:36:27 AM
Quote from: (MARLOO) on October 06, 2026, 03:00:20 PM[...]Just note that CHERI's hardware-enforced memory safety requires CHERI-capable hardware — mainly Arm Morello or CHERI-RISC-V — not existing x86‑64 systems.[...]

Or ARM or RV. I didn't see ARM's plans offhand, but you're not getting this feature on any commercial hardware for a few years. Their FreeBSD push is interesting.

Also, sounds like another case of "what's old is new again": x86 selectors. Fancier, of course. I don't recall if ARM was among the RISC vendors crapping on strict memory ordering and protection back in the day; the UNIX vendors certainly did. But hey - maybe it'll amount to something.
#4
Tutorials and FAQs / Re: Use Tailscale+mullvad as t...
Last post by firewall - Today at 12:00:34 AM
It has been almost a year so I will address at a high level for posterity. I can only speak to the routing of traffic originating on the router as I have no experience with Tailscale. Also this is just how I accomplish this and there could be other ways. Some steps may be redundant.

- Create static routes for WG peer addresses to use ordinary (ISP/WAN) gateway (i.e. System > Routes, add Mullvad server IP + ISP/WAN GW)
- Create interface(s) for WG instance(s): IP configuration types "None", MTU 1420 (research & experiment here), select "Dynamic gateway policy" at bottom
- Create gateway(s) for WG instance(s): IP address same as used in WG instance config*, check Upstream, Far, Failover, Fallback, select unique Monitor IP per GW**
- Back out, assess overview of system Gateways, insert GW priorities for all of them with lower number holding higher significance***
- Enable default GW switching at System > General
- Its OK to make a monitor IP for ISP/WAN GW using assigned GW IP for both addresses. It will participate in GW failover but its very low (high number) priority will prevent selection unless WG fails.
- About your Tailscale I expect you can use FW rules to force traffic from that ip/network over WG GW


(* often tunnel's last octet -1, e.g. VPN provider's assigned (internal) IP=10.10.10.10, GW config=10.10.10.9)
(** must be routable, immune to/participative in persistent ICMP, and something you'll never use otherwise. e.g. 4.2.2.1)
(*** e.g. WG Gateway=100, ISP/WAN GW=200)
#5
26.1, 26,4 Series / Firewall rule migration assist...
Last post by Patrick M. Hausen - October 06, 2026, 09:55:12 PM
Hi all,

I just upgraded a production HA system from 26.1.latest to 26.7.5. I used the migration assistant on the primary node to migrate the firewall rules including deletion of the legacy rules.

I then synced the configuration from primary to backup.

Expectedly all the "Rules [new]" rules were present but so were the legacy rules on the backup. Is this intentional? I manually deleted them and the upgrade continued successfully without any unexpected events.

Just wondering ... I was expecting the "Rules [new]" to be synced (which happened) as well as the "Rules", i.e. the fact that there are none. This did not happen.

Kind regards,
Patrick
#6
26.7 Series / Re: PPPoE over an unassigned V...
Last post by fanski - October 06, 2026, 09:48:30 PM
Hi Franco,

Quote from: franco on October 06, 2026, 11:15:17 AMHmm, I'm assuming your WAN sits on top of igb0?
so yes the ONT is connected to igb0.

Quote from: franco on October 06, 2026, 11:48:51 AMcan you try to set "VLAN Hardware Filtering" on Interfaces: Settings to "Leave default" and reboot.
did that and unfortunately it didn't solve the issue. still the same behavior. I also tested it with 26.7.1 and at first everything was working except the internet traffic because of state violations, but after playing with the 3 different options and 3 or 4 reboots it worked without a problem and also after some reboots.

Quote from: franco on October 06, 2026, 11:15:17 AMCan you try to add igb0 to a new interface and simply enable it without doing any other settings? Then try a reboot and see if the problem persists.
I think I already tried this before once or twice as it was a suggested workaround, but I tried again and also with the VLAN Hardware Filtering disabled or leave default but this also had no positive effect.

I attached the logs with the VLAN Hardware Filtering default option, and the ones with the dummy interface.

Regards,

Fanski
#7
Virtual private networks / Re: Wireguard site to site wit...
Last post by ala_nathaniel - October 06, 2026, 08:50:52 PM
I would be interested to see if you solve this. I have wanted to do the same. This is what I got to work:

WAN 1 = General Internet
WAN 2 = VPN Internet

WAN 1 Gateway got a weight of 200
WAN 2 Gateway got a weight of 100

Gateway Switching and such all configured. This allows Wireguard to use WAN 2 normally, and if WAN 2 goes down, it would then use WAN 1.

Created Gateway Group with WAN 1 Primary and WAN 2 Secondary.
Created a Firewall Rule on the LAN network using inverted destination so if it was not going to the internal or VPN networks, it would use the Gateway Group instead of the defaults.

Not sure this would work for you as it sounds like you might be hosting other services that require NAT. I also have not done this method on the latest version of OPNsense, so I do not know if this still works with the new rule and NAT structures.
#8
Virtual private networks / Re: Hub-Spoke Wireguard VPN wo...
Last post by ala_nathaniel - October 06, 2026, 08:08:36 PM
An update to this. We are still trying to figure this out. In the mean time, the following has changed.

We moved a location, which resulted in a rebuild of a firewall. When we did the rebuild, most everything worked. While we were still unable to ping from the console (still able to ping from Web GUI) we were able to use DNS and LDAP. This prompted us to believe that it really might be something related to ZeroTier still lingering in the System. However, once we patched and rebooted the firewalls during our maintenance cycle, it stopped working. All the same symptoms.

We are now on 26.4 on all the firewalls. We did migrate the rules to the new format and there was no change.

We added a Outbound NAT rule that looked like this

Interface     Source          Source Port     Destination     Destination Port     NAT Address           Static Port
WG_STS        This Firewall   *               10.1.0.0/24     *                    Interface Address     No

This did not help as well.

We can ping and traceroute to external IPs just fine (1.1.1.1, 8.8.8.8, 4.2.2.1) and when we have live view open, it does not show that it is blocking the traffic, and we do see it pass, which is why we think it is something routing and WireGuard directly, not something to do with the rules.

There is one difference I did not put in the original post, which is that the HUB firewall has static routing, and the Site firewalls all use WG to push the routes. We did have one site on static routes as well, and saw the same issue.

We are still working on this, but it is kinda a low priority as other functions still work.

#9
German - Deutsch / Re: [Hardware] Temperaturen
Last post by HBerger - October 06, 2026, 05:07:57 PM
QuoteAlso wenn die CPU Temp 55° ist bei einem aktiv gekühlten Server, würde ich von Stromverschwendung der Lüfter sprechen und die fan curve anpassen
Ja das sind die CPU Temps von den internen (CPU) Sensoren.
Da das teil aber nicht aktiv gekühlt ist, ist das auch ca. die Temperatur von allem, also auch der SSD.
Und ich hab keine Ahnung ob die Wärme von der CPU selber oder von der SSD (wobei die eher nicht, die hat keine Verbindung zum passiven Kühlkörper, zeigt auch um die 5x° im smart an) oder von den SPannungswandlern kommt.

#10
26.7 Series / ATTENTION: frr plugin is going...
Last post by Monviech (Cedrik) - October 06, 2026, 05:06:18 PM
I cleaned a lot of stuff up in the frr plugin.

I tested it all in my own test environment, but if somebody who also uses BGP/OSPF/OSPFv3 peering and has some basic development knowledge (aka how to build an opnsense plugin from master, deploy it, and report issues) it would be nice to get some feedback before pushing this out.

Please, test it if you can, its a lot of changes but less so feature wise, mostly corrections.

https://github.com/opnsense/plugins/blob/master/net/frr/pkg-descr

Check out the 2.0 changelog and the migration notes (there are a few migrations happening automatically).

Thank you for any help (and if not brace for impact on community at some point regardless :D)