Recent posts

#1
German - Deutsch / Re: Extrem Schlechte Download-...
Last post by drosophila - Today at 07:08:33 PM
Diesen Effekt bekommt man, wenn die Single-Thread Performance des Zielrechners zu schlecht ist. Das sollte natürlich in Deinem Fall nicht so sein, und eigentlich auch nicht an der Sensebox haken, zumindest, wenn die nicht der Zielrechner ist. Testen könnte man mal mit einem normalen PC am WAN der Sensebox, um diese auszuschließen. Vielleicht ist irgendwas im Traffic Shaping vergurkt?
#2
German - Deutsch / Re: DNS Setup mit Unbound, DNS...
Last post by emmitt - Today at 06:55:30 PM
Quote from: Patrick M. Hausen on December 12, 2025, 10:22:53 AMIch verwende Kea und Unbound mit AGH und das funktioniert prima. Ich registriere allerdings keine dynamischen Leases im DNS - das hatte ich auch mit ISC nicht getan. Statische Leases funktionieren prima.

Hallo Patrick,

wärst Du bereit, Dein Setup zu teilen bzw. näher zu erläutern?

Ich habe zwar mit Dnsmasq, AGH und Unbound geliebäugelt, entnehme aber den Beiträgen, dass diese Variante nicht optimal ist!?

Ich möchte gerne ebenfalls Adguard Home behalten, weiterhin DNS over TLS einsetzen und benötige auch eine Namensauflösung sowie eine statische IP-Vergabe anhand von Mac-Adressen. Da ist dann wohl KEA DHCP ind Verbindung mit Unbound und AGH besser geeignet.

Ich habe aber zu wenig Wissen, um die Migration zu KEA SICHER umzusetzen...
#3
German - Deutsch / Extrem Schlechte Download-Perf...
Last post by nein365 - Today at 06:30:57 PM
Hallo zusammen,

ich habe ein merkwürdiges Performanceproblem an einem Telekom-GPON-Anschluss mit einer originalen OPNsense/Deciso-Appliance DEC7xx. Bin auf 26.7.2

Gebucht sind 600 Mbit/s im Download. Diese Bandbreite erreiche ich mit dem Ookla Speedtest auch nahezu vollständig.

Normale Downloads über einen einzelnen TCP-Flow sind dagegen deutlich zu langsam. Mit curl/wget erreiche ich nur ca. 30–50 Mbit/s. Auch einzelne iperf3-Verbindungen bleiben deutlich hinter der verfügbaren Bandbreite zurück.

Besonders interessant ist dabei: Ich betreibe selbst einen Ookla-Speedtest-Server im gleichen Netz wie meinen HTTP-/iperf-Testserver. Mit Ookla erreiche ich ca. 600 Mbit/s, während ein einzelner TCP-Download in dasselbe Netz massiv langsamer ist.

Ich habe deshalb einen Ookla-Test mit tcpdump mitgeschnitten. Dabei sieht man, dass Ookla sehr viele parallele TCP-Verbindungen verwendet. Auch die einzelnen Ookla-TCP-Flows sind vergleichsweise langsam und erreichen in dem Capture überwiegend nur ca. 15–35 Mbit/s. Die ca. 600 Mbit/s Gesamtdurchsatz entstehen erst durch die vielen kleinen parallelen Verbindungen.

Zusammengefasst:
  • Gebuchte Bandbreite: 600 Mbit/s
  • Ookla Speedtest: ca. 600 Mbit/s
  • Single TCP mit curl/wget: teilweise nur ca. 30–50 Mbit/s
  • Einzelne TCP-Flows im Ookla-PCAP: überwiegend ca. 15–35 Mbit/s
  • Viele parallele Ookla-Flows zusammen: ca. 600 Mbit/s

Setup:
  • Original OPNsense/Deciso Appliance DEC7xx
  • Telekom GPON
  • PPPoE mit MTU 1492
  • GPON-SFP direkt in der OPNsense
  • GPON-SFP-Link läuft mit 1000Base-SGMII
  • Beide SFP-Ports (ax0 und ax1) getestet

Bereits getestet:
  • Zwei unterschiedliche GPON-ONT-SFPs:
  •   - Zyxel PMG3000-D20B
  •   - FS.com GPON-SFP-ONT-MAC-I
  • Beide Module zeigen exakt dasselbe Performanceproblem
  • Wechsel von ax0 auf ax1: keine Veränderung
  • IPv4 und IPv6: beide betroffen
  • PPPoE-MTU geprüft und korrekt
  • TCP Window Scaling per PCAP geprüft und funktioniert korrekt
  • Praktisch keine TCP-Retransmissions bzw. kein relevanter Packet Loss
  • ECN testweise deaktiviert: keine Veränderung
  • Hardware-TSO testweise aktiviert: keine Veränderung
  • curl direkt auf der OPNsense selbst ist ebenfalls langsam. LAN, NAT und Client können damit als Ursache ausgeschlossen werden.
  • Parallele iperf3-Streams wurden ebenfalls getestet
  • Die verwendeten Testserver liefern über andere Internetanschlüsse normale Performance

Aktuell sieht es für mich danach aus, dass der Anschluss grundsätzlich die vollen 600 Mbit/s übertragen kann, einzelne TCP-Verbindungen aber aus irgendeinem Grund stark ausgebremst werden. :(

Als nächsten Gegencheck habe ich ein Telekom Glasfaser Modem 2 bestellt. Damit möchte ich den GPON-SFP umgehen und die OPNsense über normales Ethernet mit dem ONT verbinden.

Hat jemand ein ähnliches Verhalten mit OPNsense/FreeBSD und einem Telekom-PPPoE-Anschluss beobachtet?

Insbesondere würde mich interessieren, ob jemand schon einmal das Problem hatte, dass einzelne TCP-Verbindungen deutlich zu langsam sind, während mit vielen parallelen Verbindungen die volle Anschlussbandbreite erreicht wird.

Es ist nicht zu verstehen und ich bin gerade wirklich überfragt. Irgendwas ist da krumm.
#4
26.7 Series / Re: Unbound stopps suddenly
Last post by Patrick M. Hausen - Today at 06:19:11 PM
If you like to use DNSBL I recommend delegating that to a servicd that is designed specifically with large lists in mind. Like AdGuard Home which can run directly on OPNsense and comes with a much nicer UI to manage excepted devices, manual allowlists, statistics etc.
#5
26.7 Series / Re: Unbound stopps suddenly
Last post by xavx - Today at 06:02:28 PM
What I've done for both unbound and suricata is to create 2 small bash scripts to monitor their status. If they get killed, they are restarted automatically.
root@fwall:~ # cat dnscheck.sh
#!/usr/local/bin/bash

LOGFILE="/root/log/unbound_monitor.log"
TIMESTAMP=$(date "+%Y-%m-%d %H:%M:%S")

if ! pgrep -x "unbound" > /dev/null; then
    echo "$TIMESTAMP: Unbound process not found, restarting..." >> $LOGFILE
    /usr/local/sbin/configctl unbound restart
    echo "$TIMESTAMP: Unbound restart command executed" >> $LOGFILE
fi

root@fwall:~ # cat /etc/cron.d/dnscheck
*/5      *       *       *       *    root   /root/dnscheck.sh > /dev/null

A major issue with DNSBL on opnsense is the lack of memory usage optimization when the blocklists get updated.
First issue is the blocklist update process loads all the blocklists in RAM then format them for Unbound, instead of streaming them.
Second issue is at DNSBL swap time, Unbound effectively has 2x all the blocklists loaded for a brief moment before releasing the old blocklist.
Both situations can lead to the highest memory consumer being killed by FreeBSD (expected behavior).
#6
General Discussion / Re: Why I am retiring from con...
Last post by Greg_E - Today at 05:24:02 PM
There was some discussion on the Lawrence Systems forums about pf and the amount of code the submit back to BSD. A couple mentioned that OPN also contributes code back, but that there were politics that got in the way.

Sad that they are still being petty.
#7
26.1, 26,4 Series / Migration from ISC DHCP to Dns...
Last post by emmitt - Today at 05:20:00 PM
I'm currently in the process of switching from ISC to dnsmasq. I'm wondering what the ideal configuration is and if there's a quick guide for this?


Here's what I have set up right now:
I have Adguard-Home installed (port 53, which currently forwards requests directly to Unbound (port 53530). There, I'm using DNSSEC and DNS over TLS.

Going forward:
I want to keep AGH—but do I still need Unbound?

Additionally, I want dnsmasq to assign static IP addresses to my devices based on their MAC addresses so I can access them using a domain name. I don't have that set up right now.

Translated with DeepL.com (free version)
#8
General Discussion / Re: The joys of Google AI
Last post by Greg_E - Today at 05:12:25 PM
In order to run the Vulkan version of LoacalAI, I needed to run this in a container (docker), but there is a bunch of messing around to feed the GPU through to the container, same with persistent storage. No problem sharing the display with the container, that's the only way I've tested it so far (going to 127.0.0.1:8080)

I'm running mine on an HP T740 with the internal gpu. Speeds are pretty slow, but it's working. With 32GB of ram, I'm able to load a few different 8GB models (not at the same time). It's working, I may trade RAM from another T740 and increase this up to 64GB even though it might slow things down moving to another bigger model. Just kind of playing right now while I decide what to do, and how much money to spend. Wishing I had bought a used AMD V620 when they were still available at around $300usd. Would need to mess around with PCIe extension, power supply, and cooling for the card, but might have been worth it.
#9
German - Deutsch / Re: SSD Killer gesucht
Last post by Patrick M. Hausen - Today at 05:07:38 PM
Nein, ist es nicht.

Reporting > Netflow > Capture local

Macht jede SSD kaputt außer bei den allerkleinsten Heimnetzen mit wenig Traffic.
#10
Hardware and Performance / Re: Inseego MiFi Pro M4 as WAN...
Last post by Greg_E - Today at 05:04:46 PM
Coming back around to this because I had a problem that I'm now trying to understand.

OPNsense works fine when the ethernet connection is plugged it, doing an update right now.

But if I connect the USB to keep the battery charged, the entire firewall stops all traffic. The local console is working, but DHCP server on management port doesn't work. Even if I set the IP manually on a connected computer, there is no connection and can't ping anything. I have the USB connection turned off (charge only) in the menu of the mifi device, but apparently that's not good enough. I've used the mifi in the car and it works fine while charging, so not a limitation there.

I'll have to find a charge only cable, or find a spot for a USB power supply in my rack.

Any other ideas where I should look?