Recent posts

#1
Portuguese - Português / Re: Failover dual-WAN automáti...
Last post by jovangdg34 - September 15, 2026, 11:29:39 PM
Eu começaria verificando o DNS e as regras de saída, já que os pings por IP funcionam, mas os domínios não resolvem. Também vale confirmar se o DNS está sendo encaminhado pela WAN ativa e se não há alguma regra de firewall ou NAT impedindo essa comunicação.
#2
Hardware and Performance / Re: 10G but reaching only 5-5....
Last post by pfry - September 15, 2026, 11:09:35 PM
Quote from: power13 on September 15, 2026, 09:58:03 PM[...]Could it depend on the SFP+ module I chose?[...]

So long as the interface clocks are sync'd there should not be a silent condition that would affect speed (and async clocking seems unlikely, particularly at 10Gb). You could fall down a component testing rabbit hole... which might be enlightening, but would certainly be expensive.

The "1.9W" spec (for the UACC-CM-RJ45-MG) looks decent. I wonder what chippie they use (guessing RealTek). I don't think "ifconfig -v" would give anything more than the product ID.

Speaking of "silent", how does netstat look? Anything untoward?
#3
German - Deutsch / Re: OPNSense Anfänger braucht ...
Last post by viragomann - September 15, 2026, 10:13:58 PM
Quote from: Chr1sly on September 15, 2026, 07:05:02 PMIch habe eine Router-Kaskade aus zwei Fritzboxen. dazwischen ist die OPNSense Firewall
Hi, was ist der Sinn?

Für die Zugriffe auf deine Services würde ich empfehlen, das Caddy Plugin direkt auf OPNsense als Reverse Proxy zu nutzen.
Das ist einfach einzurichten und holt sich auch die SSL Zertifikate von LE automatisch.

Ansonsten, zu de Regeln:
In OPNsense braucht es Firwall Regeln (Firewall> Rules), die ein bestimmtes Protokoll von einer gwissen Quell IPs und Poerts auf bestimmte Ziel IPs und Ports erlauben. All diese Parameter müssen also angegeben werden. Wenn es um Zugriffe aus dem Internet geht, sind Quell IP und Port normalerweise "any".

Um eingehenden Traffic an deinen bestehenden Reverse Proxy weiter zu leiten, braucht es eine NAT Regel (Firewall > NAT > Destination NAT).
Hier ist die Quelle wieder "any", das Ziel ist jenes, das der Client anspricht. Also bspw. WAN address (auf diese hast du den Traffic in der FB weitergeleitet), Zielport 443. Das Redirect Target ist die IP des Reverse Proxy und Port 443.

In NAT Regeln hast du die Möglichkeit, den Traffic auch gleich zu erlauben oder eine Regel automatisch setzen zu lassen. Das erspart das zusätzliche Einrichten einer FW Regel.
#4
Hardware and Performance / Re: 10G but reaching only 5-5....
Last post by power13 - September 15, 2026, 09:58:03 PM
I tested with iperf with the router, but through the router too. No difference, same results.

Tried with the --affinity switch on client side, the one core had about 30% load, seems not to be a bottleneck.
Cannot use --affinity on the server side, as its not my iperf server :-). But server side is from Init7, they have a very good reputation and also provide 25GBit/s internet.

Tested with "sysctl net.inet.tcp.sendbuf_max=16777216", unfortunately same result.

I have a bridge configured between two 1G LAN interfaces. 10G interfaces are not part of the bridge. Disabled the bridge and the two 1G LAN interfaces too. Did not make any difference.

I cannot get more than 5.63-6.0 Gbits/sec.

Could it depend on the SFP+ module I chose?
What else may it be?
#5
General Discussion / Re: Rclone backup support
Last post by franco - September 15, 2026, 09:51:33 PM
Regardless of push or pull... a backup method needs another machine for integrity.


Cheers,
Franco
#6
General Discussion / Re: Rclone backup support
Last post by viragomann - September 15, 2026, 09:41:13 PM
Yeah, but this requires an addional machine, which does the backup. Don"t know if this is an option here.

I simply backup the config via SSH from another server.
#7
German - Deutsch / The best girls are near you
Last post by diehardbattery - September 15, 2026, 08:12:17 PM
#8
26.7 Series / DDNS Question (maybe a feature...
Last post by hdholm - September 15, 2026, 07:47:45 PM
So my WAN dynamic IP (both IPv4 and 6) don't change very often, but they do change.  And occasionally I'll find that the IP my DDNS provider has is wrong, while the WAN interface and the DDNS service agree that is something different even though the DDNS service is green and nothing in the logs looks "interesting".  The question is, how would you go about diagnosing this?  Deleting the configuration and rebuilding it seems to be overkill, but there also doesn't seem to be a way to force the DDNS service to reach out to the DDNS provider when it thinks the IP is already correct.  So maybe this is a request for a "force an update even if you think it's unneeded" switch.  But I'm open to better ways to diagnose the issue.
#9
26.7 Series / Re: 26.7.4 Update - Scrolling ...
Last post by franco - September 15, 2026, 07:37:18 PM
This is new on 26.7.4?  If so try to revert this one:

# opnsense-patch https://github.com/opnsense/core/commit/050f3c8277

There haven't been a lot of changes that would affect this particular behaviour.


Cheers,
Franco
#10
German - Deutsch / OPNSense Anfänger braucht Star...
Last post by Chr1sly - September 15, 2026, 07:05:02 PM
Hi Leute,

also ich habe ein wenig Erfahrung in der Konfiguration von Firewalls, (Cisco, Fortinet, Zywall), aber die OPNSense ist mir noch ziemlich rätselhaft.
Ich weiss nicht wo und wie ich Regeln generieren soll... 😨

Ich habe eine Router-Kaskade aus zwei Fritzboxen. dazwischen ist die OPNSense Firewall, was bedeutet, dass die FB hinter der Firewall auf Port1 ihren WAN-Port hat. Ein Server hinter der Firewall hostet über Proxmox diverse virtuelle Server u.a. auch einen NextCloud Server für meine eigene Cloud. Dazu habe ich (ebenfalls unter Proxmox) einen Nginx-Proxyserver der die Anfragen an die Cloud übernimmt und an die NextCloud weiterleitet. Ausserdem versorgt er die Cloud mit dem Let'sEncrypt Zertifikat.

Wie konfiguriere ich nun eine Regel, wonach HTTP und HTTPS Anfragen für die IP des Proxys erlaubt sind?

Schon mal Danke für Eure Hilfe!
Chrisly