Recent posts

#1
26.7 Series / Re: Port Forwarding HELP for 2...
Last post by nero355 - Today at 09:12:23 PM
Quote from: Monviech (Cedrik) on Today at 06:45:54 PMThe earth is our single point of failure, when earth 2 please?

(This is only intended as a joke xD)
There are shows where they travel between different versions of Earth ^_^


But seriously :

Can anyone tell me why I see people Port Forwarding to WAN and then Redirect to a specific IP Address ?!

I would expect to simply Port Forward directly to the LAN-side IP Address and not WAN ?
The other one I have seen was in this topic : https://forum.opnsense.org/index.php?topic=53086.0

Disclaimer : I have left my "Host Servers at home" time behind me so I have no reason/option to test this and I am really curious :)
#2
26.7 Series / Re: DNSmasq DNS & DHCP: Device...
Last post by nero355 - Today at 08:59:55 PM
Quote from: ohlalayeah on Today at 05:14:52 AMDevices which are supposed to be assigned static IP addresses ranged from 192.168.1.3 to 192.168.1.5x.
DHCP range has been set from 192.168.1.3 to 192.168.1.245.
Well... at least that part is good :)

QuoteSome devices could obtain the static IPs from the Hosts list, some obtained the dynamic IPs such as TP-link network switch and an IPcam. dunno why.
Could be because of the fact that you can not do a DHCP IP Release on those last two devices ?!

And just to be sure : You did click APPLY after making all the Static DHCP IP Address Mappings ?
I forgot a couple days ago while changing some stuff... It was really awkward! :)



By the way :
I would always configure all important devices on the network with a Static IP Address in their own Operating System or some kind of webGUI and consider the Static DHCP IP Address Mapping as the backup option in case the device somehow loses it's configuration !!

So stuff like :
- Routers
- Switches
- Accesspoints
- Any kind of Servers like NAS devices or DNS Filtering instances either VM/Container based (Proxmox!) or Bare metal ones.
#3
26.7 Series / Re: os-upnp plugin not working...
Last post by nero355 - Today at 08:28:59 PM
Quote from: AlpAne on Today at 08:12:44 PMStill same problem, when second PC tries to connect it gets network error in Call of Duty, as soon as the first PC closes Call of Duty the second PC can connect and vice versa.
Then you need 'Endpoint-Independent NAT' instead of Static-port :)
#4
26.7 Series / Re: os-upnp plugin not working...
Last post by AlpAne - Today at 08:12:44 PM
Quote from: nero355 on October 06, 2026, 03:00:44 PM
Quote from: AlpAne on October 05, 2026, 04:40:23 PMThe only thing I'm unsecure about is Translate Source IP: Single host or Network, the field for Interface address is empty.
I see what you were talking about now : It should be 'WAN address' and then you are good to go! :)

I have now done the change: "It should be 'WAN address' and then you are good to go! :)It should be 'WAN address' and then you are good to go! :)" to my best knowledge.

Still same problem, when second PC tries to connect it gets network error in Call of Duty, as soon as the first PC closes Call of Duty the second PC can connect and vice versa.

Attached new screenshots.
#5
26.7 Series / Re: Port Forwarding HELP for 2...
Last post by Monviech (Cedrik) - Today at 06:45:54 PM
The earth is our single point of failure, when earth 2 please?

(This is only intended as a joke xD)
#6
26.7 Series / Re: Port Forwarding HELP for 2...
Last post by viragomann - Today at 06:27:05 PM
Quote from: Distroyer on Today at 01:58:15 AMMy current port-forwarding configuration for the double NAT setup is the following:

ISP Router → Forward UDP 50505 to → Virtual IP used by the OPNsense WAN HA configuration → Forward UDP 50505 to → Server with a static IP running the service on UDP 50505
If you forward the traffic to the virtual IP on the ISP router, you also have to specify the virtual IP as destination in the NAT rule on OPNsense. It looks like, you left the default WAN address there, however.

Quote from: Distroyer on Today at 01:58:15 AM* I am currently in the process of implementing High Availability (HA) for my OPNsense setup.
Remember that your ISP router will still be the single point of failure. So a HA setup only has a limited benefit.
#7
Hardware and Performance / Powershell moduule to test net...
Last post by stanps - Today at 05:44:56 PM
Hey everyone.  I searched the forum and didn't see it mentioned.

Has anyone seen, heard of, or used the Invoke-NetStress powershell module, found at https://github.com/AlphaMvge/Invoke-NetStress?

I am not affiliated or related in any way to this module, I just saw an article mentioning it (https://powershellisfun.com/2026/10/02/test-your-network-equipment-using-powershell-and-the-invoke-netstress-module/), and DEFINITELY want to try it.  And I was wondering if anyone here might have tried it already.

TIA,
Stan
#8
Without knowing more it kinda sounds like this we recently found.

It happens on mixed vti and policy based setups and is hard to replicate

https://github.com/opnsense/src/commit/e666a996d5325b10cafe21b67a97c4538deae139
#9
Hi everyone, I recently deployed OPNsense on my home network with Suricata enabled on the LAN interface, and I have run into an issue with unexpected connection resets. A user on my local subnet has been running deltaexeutor on a client machine, but the client repeatedly fails to establish a stable handshake with external endpoints and times out during startup requests.

Looking through the live firewall logs, I see outbound sessions destined getting prematurely terminated or intermittently rejected by rule matching. What would be the best practice in OPNsense to verify whether this is an IDS false positive or an aggressive state timeout, without having to create an overly broad bypass rule for that entire machine?
#10
I have a multihomed office, a remote office and a bunch of remote workers. Between the main office and remote office I have 2 IPsec VTI tunnels and using BGP for failover routing. Works as expected. For the remote user I use another ipsec instance (connection) on the main link and EAP authentication. What happens is that one user a time works normally. As soon as a 2nd user logs in, the outgoing / return packets don´t go thru the tunnel. They show up unencrypted on the WAN interface. The connection pool is a /24 network. Running OpnSense 26.1.11_10.
Any clues ?