Recent posts

#1
26.7 Series / Re: [26.7.4_1]Intermittent con...
Last post by dragao-azul - Today at 08:24:21 PM
Sorry for the multiple updates: Had problems pretty much immediately.

I've tried `sysctl kern.timecounter.hardware=ACPI-fast` and got the issue within 5 minutes of this change. In fact, multiple times, same frequency as before, so I'll revert...

Differences I can think of apart from the config above is the direct WAN connection instead of the intermediate router - but this was working before.
#2
26.7 Series / Unbound at Reboot does not cre...
Last post by IsaacFL - Today at 08:16:54 PM
If I reboot opnsense and I dig opnsense.mydomain.com aaaa, I get no answer.  If I restart unbound manually after boot, then I get expected answer.

This causes me to be unable to access the opnsense web interface from my ipv6 only clients if I reboot the router.





#3
26.7 Series / Re: [26.7.4_1]Intermittent con...
Last post by dragao-azul - Today at 06:32:25 PM
Just to leave an update: It took me longer than I wanted to get back to this. No issues experienced since my last update with WAN in DHCP, I just now went back to PPPoE. These are the only changes I did as well as a couple of reboots of both the VM and the proxmox host (which I had tried before):

--- /conf/backup/config-1790233266.5738.xml    2026-09-24 08:01:06.576665000 +0100
+++ /conf/backup/config-1790612178.7565.xml    2026-09-28 17:16:18.760095000 +0100
@@ -322,6 +322,14 @@
       <type>none</type>
       <virtual>1</virtual>
     </lo0>
+    <wan>
+      <if>vtnet4</if>
+      <descr>WANETH</descr>
+      <enable>1</enable>
+      <lock>1</lock>
+      <spoofmac/>
+      <mtu>1508</mtu>
+    </wan>
     <opt1>
       <if>bridge0</if>
       <descr>LAN</descr>
@@ -391,34 +399,46 @@
       <type>group</type>
     </local_intf>
     <opt8>
-      <if>vtnet4</if>
+      <if>pppoe0</if>
       <descr>WAN</descr>
       <enable>1</enable>
       <lock>1</lock>
       <spoofmac/>
       <blockpriv>1</blockpriv>
       <blockbogons>1</blockbogons>
-      <mtu>1500</mtu>
-      <ipaddr>dhcp</ipaddr>
-      <dhcphostname/>
-      <alias-address/>
-      <alias-subnet>32</alias-subnet>
-      <dhcprejectfrom/>
-      <adv_dhcp_pt_timeout/>
-      <adv_dhcp_pt_retry/>
-      <adv_dhcp_pt_select_timeout/>
-      <adv_dhcp_pt_reboot/>
-      <adv_dhcp_pt_backoff_cutoff/>
-      <adv_dhcp_pt_initial_interval/>
-      <adv_dhcp_pt_values>SavedCfg</adv_dhcp_pt_values>
-      <adv_dhcp_send_options/>
-      <adv_dhcp_request_options/>
-      <adv_dhcp_required_options/>
-      <adv_dhcp_option_modifiers/>
-      <adv_dhcp_config_advanced/>
-      <adv_dhcp_config_file_override/>
-      <adv_dhcp_config_file_override_path/>
-      <ipaddrv6>slaac</ipaddrv6>
+      <mtu>1508</mtu>
+      <ipaddr>pppoe</ipaddr>
+      <ipaddrv6>dhcp6</ipaddrv6>
+      <dhcp6-ia-pd-len>8</dhcp6-ia-pd-len>
+      <dhcp6-ia-pd-send-hint>1</dhcp6-ia-pd-send-hint>
+      <dhcp6prefixonly>1</dhcp6prefixonly>
+      <adv_dhcp6_interface_statement_send_options/>
+      <adv_dhcp6_interface_statement_request_options/>
+      <adv_dhcp6_interface_statement_information_only_enable/>
+      <adv_dhcp6_interface_statement_script/>
+      <adv_dhcp6_id_assoc_statement_address_enable/>
+      <adv_dhcp6_id_assoc_statement_address/>
+      <adv_dhcp6_id_assoc_statement_address_id/>
+      <adv_dhcp6_id_assoc_statement_address_pltime/>
+      <adv_dhcp6_id_assoc_statement_address_vltime/>
+      <adv_dhcp6_id_assoc_statement_prefix_enable/>
+      <adv_dhcp6_id_assoc_statement_prefix/>
+      <adv_dhcp6_id_assoc_statement_prefix_id/>
+      <adv_dhcp6_id_assoc_statement_prefix_pltime/>
+      <adv_dhcp6_id_assoc_statement_prefix_vltime/>
+      <adv_dhcp6_prefix_interface_statement_sla_len/>
+      <adv_dhcp6_authentication_statement_authname/>
+      <adv_dhcp6_authentication_statement_protocol/>
+      <adv_dhcp6_authentication_statement_algorithm/>
+      <adv_dhcp6_authentication_statement_rdm/>
+      <adv_dhcp6_key_info_statement_keyname/>
+      <adv_dhcp6_key_info_statement_realm/>
+      <adv_dhcp6_key_info_statement_keyid/>
+      <adv_dhcp6_key_info_statement_secret/>
+      <adv_dhcp6_key_info_statement_expire/>
+      <adv_dhcp6_config_advanced/>
+      <adv_dhcp6_config_file_override/>
+      <adv_dhcp6_config_file_override_path/>
     </opt8>
     <opt9>
       <if>vlan02</if>
@@ -481,8 +501,8 @@
   </ntpd>
   <revision>
     <username>[___myusername___]</username>
-    <description>/interfaces.php made changes</description>
-    <time>1790233266.57</time>
+    <description>/api/core/backup/revert_backup/config-1790202624.039.xml made changes</description>
+    <time>1790612178.76</time>
   </revision>
   <OPNsense>
     <wireguard>

If it breaks I'll continue debugging with the suggestion above, I'm unsure if the PPPoE/DHCP change (and lack of issues) gives any interesting data point. If it doesn't break further I'll also leave an update.

Thanks!
#4
26.7 Series / Re: DS-LITE OPTION 64 - GIF ...
Last post by franco - Today at 02:20:50 PM
The dhcp6c log will list your AFTR hostname, but the whole GIF tunnel setup is still manual.


Cheers,
Franco
#5
26.7 Series / DS-LITE OPTION 64 - GIF TUNN...
Last post by ijobs - Today at 02:08:49 PM

Hi everyone,

I'll soon be getting my fiber-optic connection from Netcologne, which provides DS-Lite/CGNAT.


I can't find a clear answer in the forum as to whether the current version of DHCPv6 in OPNsense now detects the AFTR server and establishes a GIF tunnel for IPv4.

I look forward to hearing from users with this setup and learning how they created a working configuration.


Thanks in advance.
#6
Zenarmor (Sensei) / Re: Zenarmor Cloud Agent servi...
Last post by sy - Today at 02:02:58 PM
Hi,

Our team is currently investigating the issue and will provide an update shortly.
#7
26.1, 26,4 Series / Re: Dynamic DNS ddclient confi...
Last post by Greelan - Today at 01:57:43 PM
The real issue is how the ddclient version that OPNsense bundles parses and filters per-provider options. That has been fixed in ddclient 4.0. Stripping the commas and backslashes "works" because ddclient then interprets the options as global and doesn't filter them, but if you had multiple providers configured this would potentially interfere with others.

The real solution is for 4.0 to be shipped with OPNsense (it is already in ports), with some changes in the plugin to accommodate it.
#8
26.7 Series / OPNsense 26.7.4 - VLAN traffic...
Last post by merrins63 - Today at 01:38:52 PM
Hi all,

I'm troubleshooting a VLAN issue that appeared after upgrading to OPNsense 26.7.4 / FreeBSD 15.1.

My setup is roughly:
Cisco 2960X
    |
Po3 LACP / 802.1Q
    |
Intel X550 ix0 + ix1
    |
  lagg0
    |
 VLAN interfaces
    |
 OPNsense bridges
    |
Kea DHCP

I also have an Intel i226 2.5 GbE trunk, with corresponding VLAN interfaces bridged to the X550/LAGG VLAN interfaces.

This affects all VLANs traversing the Cisco 2960X /   Intel X550 LAGG path. VLAN 15 is simply the VLAN I am using for troubleshooting.

Clients on the Cisco side fail DHCP and remain on 169.254.x.x.

Cisco switch looks healthy: Po3 is UP, both LACP members are bundled, VLAN 15 is forwarding, and the test client MAC is correctly learned on its VLAN 15 access port.

The interesting part is simultaneous packet captures of the same DHCP transaction:

bridge1:      DHCP REQUEST ✓   ACK ✓
vlan0.1.15:   DHCP REQUEST ✓   ACK ✓
lagg0:        DHCP not visible
ix0 / ix1:    DHCP not visible

Kea therefore appears to receive the request and generate an ACK, but the client never receives/configures the lease.

I found FreeBSD bug 276936, describing packet-forwarding problems involving ixgbe, VLAN interfaces and bridges. The topology isn't identical, but it looks potentially relevant.

Has anyone experienced similar issues with OPNsense 26.7, Intel X550, LAGG/LACP, VLANs and bridges, or have suggestions for further diagnostics?

Any help or feedback would be greatly appreciated, as I am stuck until I can fix this, as my network relies on the VLAN Bridges to connect my home network

Thanks in advance
#9
German - Deutsch / DS-LITE OPTION 64 - GIF TUNNEL...
Last post by ijobs - Today at 01:29:18 PM
Hallo Leute,

ich bekomme bald meinen Glasfaser Anschluss von Netcologne.

Finde im Forum keine klare Antwort, ob die aktuelle Version von dhcpv6 mittlerweile den AFTR Server erkennt und einen GIF Tunnel für ipv4 aufbaut.

Freue mich auf Antwort von Usern mit diesem Setup und wie eine funktionierende Konfiguration angekegt wurde.

Danke schon mal.
#10
German - Deutsch / Re: PPPoE-Interface-Bug
Last post by Monviech (Cedrik) - Today at 11:25:32 AM
Am einfachsten ist es auch hier die Point to Point session vor der OPNsense zu terminieren, wenn HA benötigt wird.

Vor allem rauchen dann auch keine Sessions ab wenn es schwenkt, da pfsync states auf echten interfaces liegen.

Das läuft bei mir seit Jahren stabil.

Point to point is halt grundsätzlich eher point to point und nicht point to multipoint... das bedeuted HA ist immer etwas feindlich in so Szenarios.