Recent posts

#1
26.7 Series / Re: ACME cron renewal fails bu...
Last post by JeGr - Today at 08:46:19 PM
Seconded here. Was hitting a monitoring alert because 2 certs that are in use with Caddy were over there set up renewal timeframe. As I'm already using the new "tlsserver" profile that only has ~45days certs manually refreshing multiple certificates is tedious. It's only the cron that fails though, manually refreshing is fine, but somehow the --cron stuff isn't running correctly.
#2
26.7 Series / Re: OPNsense 26.7 blocks LAN t...
Last post by ricksense - Today at 07:34:35 PM
Quote from: nero355 on Today at 06:24:33 PMWhat happens when you Enable all the Anti-Lock Out Rules for webGUI and SSH access ?

Or are they already Enabled ?!

Yes, already enabled. Anyway, I fixed the problem(s) eventually, but I had to struggle a lot.
Very strange behavior compared to the old version.
Thanks
#3
26.7 Series / Re: Connections suddenly block...
Last post by BoerBart - Today at 07:30:50 PM
Quote from: nero355 on Today at 06:00:54 PMWhy have both a Modem and the TP-Link in Bridge Mode there ?!

The TP-link is running in bridge mode to have WiFi on the first floor. There's an UTP cable running from the first floor to the second, where all the other components are, hence it's all hooked up to the TP-Link router.

Quote from: nero355 on Today at 06:00:54 PMTo be sure :
Are you sure there is not a VM or LXC on any of these two connected to your LAN and running a DHCP Server without you knowing ?

I'm not a 100% sure, so i'll go and check. For my understanding, how would that cause random connections being dropped on the LAN interface?

Quote from: nero355 on Today at 06:00:54 PMWatch out with this Switch : If connected like this a wrong configuration can expose the Switch's webGUI to the Internet !!

Thanks for the info - I'll have a look at that later. It's one of the reasons I still have the modem, I'm very much it's not much, but it's something.

I'll go over the rules again to see if there's anything off. Though, as it's the main deny rule which is no. 13 in my case, it wouldn't matter what comes afterwards, as the rules are processed first match, correct?

OpenWRT isn't supported on the Archer AX50 sadly enough, i've looked into that a little ago. Of course, buying new hardware is always a good option, though I find it frustrating it 'suddenly' started acting up. Next to that, it seems to be somewhat specific. My PC and phone have issues, but when I check the Live view, no connections are dropped coming off the 2 Proxmox nodes.

I've got another TP-link switch laying around here, I'll take the Archer AX50 out, and replace it with the switch, see if that changes anything. I've also patched OPNsense to the latest firmware version (26.7.5), without luck.
#4
26.7 Series / Re: os-upnp plugin not working...
Last post by bamf - Today at 06:43:56 PM
Quote from: nero355 on Today at 06:05:55 PMSo far it seems you can't combine both so I am not sure if Endpoint-Independent NAT will solve that issue too...

It does resolve this issue in a more secure way than Static Port. EIM-NAT is a fairly recent addition to OPNsense, and I migrated my rules for online gaming away from static port as soon as it became available. You might still need static ports for specific scenarios like SIP, but for gaming clients, EIM-NAT is definitely the more secure route now.

There's a good explanation of the details in the Netgate documentation here: https://docs.netgate.com/pfsense/en/latest/nat/outbound.html#endpoint-independent-port-restricted-cone-nat
#5
26.7 Series / Re: OPNsense 26.7 blocks LAN t...
Last post by nero355 - Today at 06:24:33 PM
What happens when you Enable all the Anti-Lock Out Rules for webGUI and SSH access ?

Or are they already Enabled ?!
#6
26.7 Series / Re: OPNsense 26.7.5 update
Last post by Monviech (Cedrik) - Today at 06:22:15 PM
Its not really a beta test component as this page has been around for years, it was a firewall automation plugin page since 2021 or so.
#7
26.7 Series / Re: OPNsense 26.7.5 update
Last post by nero355 - Today at 06:21:08 PM
I am bit surprised by the "Move to plug-in" note for Outbound NAT now already, but I guess they want more "Beta Testers" for the new Source NAT webGUI to make sure it's 100% ready when 27.1 is released ??
#8
26.7 Series / Re: Android IPv6 issues: In my...
Last post by nero355 - Today at 06:16:32 PM
Quote from: astronaut on September 29, 2026, 10:11:14 PMI do make use of more or less well designed apps on my smartphone, and I assume that the majority of apps is not available on these OSs.

Or is my assumption wrong?
It depends if you like using Waydroid or not and in case of Jolla SailFish their Licensed version of the OS has integrated Android Emulation for Android apps :)

But if you are one of those people that depends on stuff like Banking apps on their Android phone then I guess you are stuck with it...

Considering that this kind of nonsense is going on now : https://keepandroidopen.org/
I hope a lot of people will simply dump the whole thing and a whole new fresh wave of native apps will get developed for a lot of things instead of messing around with Waydroid or any kind of Android Emulation :)
#9
26.7 Series / Re: os-upnp plugin not working...
Last post by nero355 - Today at 06:05:55 PM
Quote from: bamf on Today at 05:26:42 PM
Quote from: nero355 on Today at 05:19:26 PMSee Post #1 => https://forum.opnsense.org/index.php?topic=52419.msg270603#msg270603 ;)

Why? What's the benefit of Static Port over Endpoint-Independent NAT?
I can't tell you that yet, but to solve Strict NAT issues and moving to Moderate NAT that is the way to go :)

So far it seems you can't combine both so I am not sure if Endpoint-Independent NAT will solve that issue too...
#10
26.7 Series / Re: Connections suddenly block...
Last post by nero355 - Today at 06:00:54 PM
Quote from: BoerBart on September 29, 2026, 08:33:36 PMNetwork setup
Modem of provider --> TP-Link archer AX50 (bridge mode) --> TP-Link TL-SG108E switch --> single NIC Mini PC.
Why have both a Modem and the TP-Link in Bridge Mode there ?!

QuoteSwitch port layout
Port 2 is Single NIC Mini PC #1
Port 2 is Single NIC Mini PC #2
To be sure :
Are you sure there is not a VM or LXC on any of these two connected to your LAN and running a DHCP Server without you knowing ?

QuoteSwitch VLAN (802.1Q) configuration
VLAN ID     VLAN Name     Member Ports     Tagged Ports     Untagged Ports
1     Default     1-8    1-8
Watch out with this Switch : If connected like this a wrong configuration can expose the Switch's webGUI to the Internet !!

QuoteAll firewall rules that are either directly on the LAN interface, or the rule itself contains multiple interfaces, including LAN, are exported to a csv file that can be downloaded here:
https://filebin.net/aer3hx75u8wj72il
It seems you only have the two Default Any to Any Rules for IPv4 and IPv6 active for the LAN Interface so I guess that's OK.

I do see some things that might benefit from double checking the rules vs. a default setup or at least testing them with improved values.
For example the rules where no Interface is mentioned.


Running everything via a Single NIC and using Proxmox to manage all the VM/LXC traffic could be the issue here, but I could be wrong...

If I am honest I would stop using OPNsense this way and replace the Archer with a nice Quad Port NIC Intel Mini PC with Intel NICs and run OPNsense directly on it without any Virtualisation in between :)
Another option is checking if you can run OpenWRT on the Archer and have something similar to OPNsense that way without buying anything new!