Recent posts

#1
26.7 Series / Re: os-upnp plugin not working...
Last post by nero355 - Today at 04:31:03 PM
Quote from: AlpAne on October 07, 2026, 09:57:30 PMSo I should disable Static-port and enable Endpoint Independent?
Yes, because you can only use one of them in the same NAT Rule from what I have understood so far :)
#2
Zenarmor (Sensei) / Re: Cannot use external elasti...
Last post by Greg_E - Today at 03:25:52 PM
This doesn't help you, but your post gave me an idea to check my local DB, and through a bunch of breaks, I finally got mine working again. I was on Elastic 5 and after breaking and then upgrading to Elastic 8 mine is now working again.

So thanks for the idea, wish I could help with your problem.
#3
Zenarmor (Sensei) / Re: ZA no longer filtering net...
Last post by Greg_E - Today at 03:24:17 PM
After reading another post, I went to the local elastic database to see if cleaning it would help.

I tried a reset reporting database which partly worked, but in the end showed a red error 200. I then tried to Perform Index Check, this also failed with error 200.

The Settings Database Health Check reports OK

And now on the live connections I get a database server not running error 200

I then went to change the database type to SQLight and noticed that I had an option to install elastic 8, so I installed it and now things are working again.

Apparently when ZA is upgrading, it won't upgrade the Elastic database and if you get old enough, it isn't going to work or it gets corrupted.
#4
26.7 Series / Re: No link with Intel E810 on...
Last post by franco - Today at 02:48:18 PM
Hi Patrick,

Unfortunately the upgrade will want to get the 26.7 kernel. You could try manually booting the 26.7.6 kernel from 26.1.11 which should be fine:

# opnsense-update -fkr 26.7.6 -a FreeBSD:15:amd64/26.7
(reboot)

If it works we can consider bumping the upgrade path from 26.1.11 to 26.7.6. Usually this takes some more time to verify things are still working as expected with the major upgrade also because we have a package manager update in between now.


Cheers,
Franco
#5
Zenarmor (Sensei) / Cannot use external elastic se...
Last post by Styx13 - Today at 02:38:50 PM
I hadn't looked at my Zenarmor dashboard for a while, and I recently noticed that it didn't have any connection in the report/live session, no threat, nothing, just the Traffic Graph (Throughput) volume/packets on the dashboard.

I checked my Elasticsearch (v8) and noticed the zenarmor indices didn't have any new data in them in a while.

I then proceeded with deleting the indices (tried to delete them from the Zenarmor settings > Reporting & Data > Reporting Database, but that didn't do anything), so I deleted them directly from Elastic search.

Then I noticed that Zenarmor re-creates new indices, but it does not put any document in them, they stay empty.

Finally, I opened the "Change reporting database" pane and noticed the little tooltip next to Use a "Remote Elasticsearch Database" that says: "To use this reporting database, you need to purchase a premium subscription."

You cannot view this attachment.

So I guess that is the reason why I do not see anything in live session and reports? Zenarmor just refuses to send data to my Elasticsearch because I have the free edition?
#6
Announcements / OPNsense 26.7.6 released
Last post by franco - Today at 02:30:27 PM
Oh, hi!

This update finally brings interface settings to MVC/API!  It also brings
a number of fixes and improvements from FreeBSD stable/15 including a fix
for previous Hyper-V boot issues and hopefully also fixes ice driver DDP
issues with newer firmware versions.

For the interface settings MVC/API there a few things to keep in mind:

o You can find them on the assignments page integrated into the existing grid.
o Commonly required DHCP advanced options not in basic mode have been made available.
o Advanced/file based modes for DHCP are gone and will reset on save.
o Saving settings queues them for reconfiguration and storage.
o A reboot without apply will discard the previously saved changes.
o Apply works similar to the old interfaces.php page but uses a rewritten backend sequence.
o The old interfaces.php page is still available retaining the old style settings.
o The old interfaces.php page will likely move to a plugin for 27.1.

We are looking for your feedback on this historic milestone!

Here are the full patch notes:

o system: use correct type for IP when killing active states in "lockout_handler" (reported by Omar Habra of Apex Security Research)
o system: reject a null gateway in getGatewayAction()
o system: add "latency_avg" as sanity check for running dpinger
o system: missing chown in backup call for proper non-root web GUI access
o system: do not allow system scope users to be renamed
o reporting: unbound: add DNSSEC status column in details grid
o interfaces: add interface configuration settings in new assignments page
o interfaces: prevent interface_configure() from reloading non-interface hooks when in batch mode
o interfaces: improve queue build sequence in interfaces_dependencies()
o interfaces: remove stale VIP address after update (contributed by ExpRam)
o interfaces: be more conservative with -no_dad
o interfaces: add a new 'updateip' hook
o firewall: aliases: reject reversed port ranges
o firewall: destination NAT: fix destination for no-rdr rules (reported by fa1k3)
o firewall: destination NAT: add safety guards for calculated port ranges
o ipsec: add "replay_window" option to children
o monit: log from the first line and reconfigure through the base class (contributed by IvanTheGeek)
o openvpn: default keepalive to "10 60" in server mode and improve validation
o bootgrid: upgrade Tabulator to version 6.5.3
o mvc: disable Nginx reverse proxy buffering on configd streams
o mvc: dispatch failed message during reconfiguredAction()
o mvc: PortField: keep the first well-known service in the option list (contributed by fa1k3)
o mvc: PortField: always return a string for normalizedPort()
o mvc: UidField: allow an arbitrarily specified UID for system scope users upon creation
o ui: do not add the spinner again when it fails
o plugins: add error returns to plugins_configure()
o plugins: os-ndp-proxy-go 1.5[1]
o src: sysvsem: heap out-of-bounds access in semop(2)[2]
o src: ktls: remote DoS via receive-side kernel TLS[3]
o src: udp: IPv6 UDP sendto(2) bypasses jail loopback restriction[4]
o src: vfs: multiple jail filesystem root escapes[5]
o src: openssl: out-of-bounds read in OpenSSL DTLS retransmission[6]
o src: kqueue: memory safety bugs in kqueue copy-on-fork implementation[7]
o src: syslogd: fix leaking child processes when logging to a pipe[8]
o src: iflib: do not hold the ifnet lock across registration
o src: ixgbe: correct Wake-on-LAN configuration
o src: dummynet: do not overflow the points[ED_MAX_SAMPLES_NO] array
o src: pf: mark non-port packets to require IP checksumming
o src: pf: set the correct type for rule timeouts
o src: loopback: improve checksum offloading
o src: vlan: use the exclusive lock everywhere
o src: routing: initialize V_rt_numfibs earlier during boot
o src: raw ip: clear sin_port on bind(2)
o src: nd6: fix regeneration of temp addresses in detached state
o src: hyperv: fix single page invalidation path
o src: route/fib_algo: fix nexthop index collision across families
o src: ice: do not leave device non-functional if Tx scheduler config fails
o src: netipsec: fix V_spd_size updates
o src: bnxt: assorted updates from stable/15
o src: ixl: assorted updates from stable/15
o src: linxkpi: assorted updates from stable/15
o src: net80211: assorted updates from stable/15
o src: pci: assorted updates from stable/15
o ports: ca_root_nss / nss 3.130[9]
o ports: expat   2.8.5[10]
o ports: pcre2 10.49[11]
o ports: phalcon 5.22.1[12]
o ports: php 8.5.11[13]
o ports: py-duckdb 1.5.6[14]


Stay safe and open source,
Your OPNsense team

--
[1] https://github.com/opnsense/plugins/blob/stable/26.7/net/ndp-proxy-go/pkg-descr
[2] https://www.freebsd.org/security/advisories/FreeBSD-SA-26:64.sysvsem.asc
[3] https://www.freebsd.org/security/advisories/FreeBSD-SA-26:67.ktls.asc
[4] https://www.freebsd.org/security/advisories/FreeBSD-SA-26:69.udp.asc
[5] https://www.freebsd.org/security/advisories/FreeBSD-SA-26:66.jail.asc
[6] https://www.freebsd.org/security/advisories/FreeBSD-SA-26:68.openssl.asc
[7] https://www.freebsd.org/security/advisories/FreeBSD-SA-26:65.kqueue.asc
[8] https://www.freebsd.org/security/advisories/FreeBSD-EN-26:23.syslogd.asc
[9] https://firefox-source-docs.mozilla.org/security/nss/releases/nss_3_130.html
[10] https://github.com/libexpat/libexpat/blob/R_2_8_5/expat/Changes
[11] https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.49
[12] https://github.com/phalcon/cphalcon/releases/tag/v5.22/1
[13] https://www.php.net/ChangeLog-8.php#8.5.11
[14] https://github.com/duckdb/duckdb/releases/tag/v1.5.6
#7
Yeah, different architecture makes sense.  Thanks for the pointer.  It is much appreciated.

The 26.7.6 tag was just pushed.


Cheers,
Franco
#8
General Discussion / Re: Beta Testers and Feedback ...
Last post by franco - Today at 01:18:38 PM
Once the login screen goes MVC we can talk about this popular request. At the moment we still want to refrain from glueing more of the legacy code to get to a good result:

> Entering the OTP directly on the login screen is extremely inconvenient.

It's the other main concern we voiced many times already.

26.7.6 ships interface settings as MVC/API.  It's very likely authentication revamp will be done in 2027.


Cheers,
Franco
#9
26.7 Series / Re: Port forwarding settings u...
Last post by Bob.Dig - Today at 11:05:18 AM
Quote from: kaneelschep on Today at 10:50:06 AMAnd I see there are quite some people asking about this.
I think you are the only one. Portforwarding always has to do be done in NAT. There you decide, if you don't want to use a corresponding firewall rules by selecting "pass".
#10
26.7 Series / Re: Port forwarding settings u...
Last post by kaneelschep - Today at 10:50:06 AM
I have been reading a bit more on this. And I see there are quite some people asking about this. Yet I didnt really find an answer that explains me why the port forwarding is now handled in 2 separate locations. It seems confusing to me as it used to be in one location.
Also I cant find if this is by design or something just went wrong here during migrations/updates.
I am going to experiment a bit with making new rules and seeing how they end up in the destination nat.

Thanks!