Recent posts

#1
General Discussion / Re: Going from no VLAN to VLAN...
Last post by prutz0r - September 26, 2026, 07:42:53 PM
Quote from: nero355 on September 26, 2026, 02:38:14 PMBut I was thinking...

Any chance that there is some kind of alternative firmware available for these things ?!
Slapping OpenWRT on them for example would solve the whole issue pretty easily! :)
Great idea. But then I searched for the model numbers and openwrt and no result unfortunately.
#2
26.7 Series / System unusable after starting...
Last post by mekano - September 26, 2026, 04:40:37 PM
Every time i start zenarmor engine, my system is unusable because de CPU goes to 100% usage. Zenarmor is configure to don't start at boot so when this happens i reboot the computer to make it accessible again. I have a protectli VP2420 with 16 gig of ram. Everything was working fine before that.

I don't know why this is happening. Anyone in the same situation ?
#3
German - Deutsch / IPSEC- Connections: Doppelte P...
Last post by Z80ACPU - September 26, 2026, 03:12:41 PM
Hallo Allerseits,
ich habe zwischen zwei Standorten ein IPSEC VPN laufen. (Opnsense 26.7.4_1)

Das VPN läuft und soweit ich sehen kann, ist eigentlich alles okay.
Aber:
Ich sehe im "Status Overview" meine Phase 1, jedoch wird in der zugehörigen Phase 2 das Child doppelt angezeigt.
Ich kann mir darauf keinen Reim machen und frage hier besser noch mal nach.

1) In der Phase 1 habe ich beidseitig ein DPD Delay von 10 Sekunden eingetragen
2) In der Phase 2 habe ich auf beiden Seiten (Start Action ="Trap+Start"); (Close Action ="Trap"); (DPD Action ="Trap") eingetragen.

Tja...
Wieso wird zwei Mal das Child in der Phase 2 angezeigt?
Habe ich ein Problem und sehe es nicht?

Vielen Dank für Eure Gedanken!

Beste Grüße
Wolfgang

#4
Virtual private networks / Re: Please make an updated ste...
Last post by ohlalayeah - September 26, 2026, 03:05:53 PM
I am not missing anything. It's the updated tutorial is missing.

Quote from: nero355 on September 26, 2026, 02:54:03 PMWhat is missing or not compatible for you exactly ?

To name a few :
Port Forward = Destination NAT now.
Outbound NAT = Becoming Source NAT now.
Firewall Rules (called Legacy now) that got migrated to Firewall Rules [new] are simply Firewall Rules now.

In the end it's all the same, but just a bit different, however if you are missing something then the developers need to know that ;)
#5
Virtual private networks / Re: Please make an updated ste...
Last post by nero355 - September 26, 2026, 02:54:03 PM
What is missing or not compatible for you exactly ?

To name a few :
Port Forward = Destination NAT now.
Outbound NAT = Becoming Source NAT now.
Firewall Rules (called Legacy now) that got migrated to Firewall Rules [new] are simply Firewall Rules now.

In the end it's all the same, but just a bit different, however if you are missing something then the developers need to know that ;)
#6
Hardware and Performance / Re: 10G but reaching only 5-5....
Last post by nero355 - September 26, 2026, 02:47:54 PM
Quote from: ou1 on September 26, 2026, 10:04:57 AMYes, unfortunately at 1650 EUR (current price) and 45W typical power usage, this puts it out of reach for me as a home user.
My whole network was something like € 1300 (Router/Switches/Accesspoints/Cables/etc.) years ago so paying more than that for just one appliance is a bit too much indeed :)

QuoteMy M920q setup was under 400EUR including the X710 card and typically uses <20W.
Not really comparable, an ancient mini PC with a hole cut into it and a fan over the hole, but it's silent and it gets the job done.
That was this : https://forum.opnsense.org/index.php?topic=50846.msg268263#msg268263
Right ?

Looks good to me! :)

QuoteMaybe they didn't anticipate 10G internet to be so readily available when they designed the DEC750.
Whatever the reason was : I am a big fan of simply using OPNsense-like software on some DIY-ish hardware setup anyway :)

At least from a Home User point of view...
#7
Virtual private networks / Please make an updated step-by...
Last post by ohlalayeah - September 26, 2026, 02:39:32 PM
OPNsense has been updated to version 26.7.4 and the interface has been changed. Old tutorials on Youtube or documents are all outdated. Please make an updated one based on the version OPNsense 26.7.4. Thank you.
#8
General Discussion / Re: Going from no VLAN to VLAN...
Last post by nero355 - September 26, 2026, 02:38:14 PM
Quote from: prutz0r on September 26, 2026, 11:01:03 AM
QuoteNow to answer your question about VLANs partially :
- When your OPNsense Interface is just the Default LAN for example you need to transport it as UNTAGGED to a Switch or Accesspoint.
That would be the situation without VLANs that I have right now I think?
Yup!

Quote
Quote- When your OPNsense Interface has VLANs assigned to it you need to transport them as TAGGED to a Switch or Accesspoint.
My default LAN will be VLAN 10 so that would mean connection from router to switch is tagged?
Yup!

Quote
Quote- VLANs from Switches to Accesspoints go TAGGED too unless you are doing something special for whatever reason.

Simple common example of "Something special" :
Some equipment needs to have it's Management Network transported as UNTAGGED instead of TAGGED.
Since your MESH units probably don't know what to do with VLANs on the "Switch side" you will need to do something like this, because both the regular traffic and management traffic will go via the same connection/network :)
This system is completely unaware of VLANs, it's not like Ubiquity where you apply a VLAN to an SSID so I would think the traffic is untagged anyway to the MR interface that connects the access points to the rest of the network and the internet? And then apply a fixed PVID to the relevant switch port?
Sounds like a plan! :)

But I was thinking...

Any chance that there is some kind of alternative firmware available for these things ?!
Slapping OpenWRT on them for example would solve the whole issue pretty easily! :)
#9
Zenarmor (Sensei) / Important Notice: Retirement o...
Last post by beki - September 26, 2026, 02:27:45 PM
Dear Zenarmor Community,

To ensure the highest level of network security, performance, and system stability, legacy CTI cloud endpoints serving Zenarmor versions prior to 2.1 will be permanently turned off on October 31, 2026. Systems running pre-2.1 builds will no longer fetch live web categorizations, malware feeds, or real-time domain lookups.

Clarification on Version Support

Please note that versions prior to 2.1 are already out of official support. For instance, on platforms like OPNsense, Zenarmor officially supports only the last two major releases. While CTI cloud lookup services have continued to work on these older builds up until now, those legacy CTI endpoints will be permanently decommissioned at the end of October.

Why You Should Always Run the Latest Version
Running the latest version of Zenarmor isn't just about maintaining connectivity—it is a very important way to protect your network properly. Upgrading to the latest release ensures you benefit from:

  • Enhanced Security: Access to our newest machine-learning classification models and immediate protection against emerging zero-day exploits.
  • Superior Performance: Ongoing engine optimizations that reduce CPU and memory footprints.
  • New Features & Bug Fixes: Immediate access to new dashboard tools, advanced policy controls, and system stability updates.


Impact on Legacy Versions (< 2.1) After October 31, 2026

If your firewall or gateway is still running a pre-2.1 engine after October 31, 2026:

  • CTI Cloud Disconnection: Your engine will no longer be able to query Zenarmor cloud threat servers.
  • Incomplete Threat Protection: Real-time domain lookups, dynamic malware blocklists, and advanced web categorizations will stop functioning.

Required Action: Upgrade to the latest Zenarmor version

We strongly encourage all users running older builds to update to the latest Zenarmor release well ahead of the deadline.

If you have questions, run into dependency issues during the upgrade, or need technical assistance,  open a ticket through the application or reach out directly to our support team at support@zenarmor.com.

Thank you for your cooperation as we work to keep your networks secure!

Zenarmor Team
#10
26.7 Series / Re: Pppoe Interfaces Linkage
Last post by meyergru - September 26, 2026, 01:20:46 PM
...because the documentation knows better than you if your ISP needs a VLAN and if your modem supplies it in that case?

There are two cases:

1. your ISP does not need a VLAN - then your use the NIC device without one.
2. your ISP needs a VLAN - then you can do one of two things:
   a. if your modem supports it, you can set the VLAN in the modem and your NIC device without VLAN.
   b. if your modem does not support it or you do not want to lose modem access via the untagged VLAN, you can use the NIC device with VLAN.


I prefer 2b if needed for the reason given.