Recent posts

#1
26.7 Series / Re: Confused by 26.7 upgrade
Last post by defaultuserfoo - Today at 02:09:09 AM
Quote from: franco on September 09, 2026, 09:27:40 AM> IIUC, someone created this thread when he found that he can not
  enable or disable firewall rules after an upgrade anymore, and was
  advised to install a plug-in to fix that.

Which is correct, but that's in the release notes. You don't need the
plugin to use and/or migrate the rules, but you need the plugin to
administrate them.

It's kinda in the release notes: 'Kinda' because it's very well
hidden.  I think it would be something that should be pointed out in
the 'Migration notes, known issues and limitations' section.

If someone doesn't read that section it's his fault.  I wouldn't blame
anyone for not reading the long list of items most or all of which
don't tell users anything.

Quote> but I made the experience that the firewall rules didn't work after
  the migration and had all to be redone

Which is entirely different.  It may be because of FreeBSD 15.1 or
something else.  It looks like we don't know?

Different from what?

It's not because of FreeBSD.  It's because things work differently
with the new rules so that the old ones can not easily be converted
into new ones.  I guess that there may be configurations for which the
migration works: That's only when no conversion is needed.  That
doesn't mean it would work for everyone, and it means that a big fat
warning is needed.

I'm basically using a configuration that goes as described in this post:
https://forum.opnsense.org/index.php?topic=28447.msg138309#msg138309

If you want to use IPv6 and don't have a static prefix, what other
solution is there?  It's working great, and it doesn't migrate.

Quote> Don't continue to pretend that it is an easy and harmless migration
  that wouldn't even require a big fat warning.  It is not.

I never pretended it was easy and harmless for you.  This is the core
of the issue.  It is your experience.  Not everyone else's.

I'm sure I'm not the only one to find out that the migration wasn't
easy and harmless.  Even if I'm the only one to experience that it
wasn't, it does warrant a big fat warning because there can always be
other users for which it won't be harmless and easy.

The core issue is that the migration was made to appear as being
harmless and easy and that the GUI suggested that we better do it
soon, and that we were not informed that we might have to redo our
firewalls and that we don't need to do the conversion anytime soon.

You right now still deny that it is not harmless and easy by
claiming that I'd be the only one for whom it wasn't.  Even if I am
the only one, it proves that your assumption that it is harmless and
easy is wrong.

Quote> I wonder why that is.

Because you don't know what the problem is, but feel entitled to raise
your concern in advance?  If I know your exact problem I can probably
help or point to the right bits of documentation.

I'm not raising my concern in advance.

I did the migration because it was made to appear easy and harmless a
while after there was the entry for the new rules in the GUI,
suggesting that I better migrate my rules as long as it is
possible. Living in the past seldwhen is a good idea, meaning that
things like software keep moving on, and when you don't keep up you
can get so far behind that you eventually find that updating isn't
possible anymore. I've had that happen and it's a situation I really
don't want to be in again.

I'm raising my concern only after I know what the problem is.  The
problem is that the migration can easily go wrong, and my concern is
that there needs to be a big fat warning about it instead of making it
appear easy and harmless.

I don't know exactly in detail what causes the problem, just see
above.  I don't expect you/the developers to fix the cause(s) so that
the problem doesn't exist anymore.  The big fat warning would suffice,
so everyone who planning to do the migration can make backups and set
aside time to try it out and do whatever they deem necessary
beforehand.

The user's approach needs to be 'the migration may go wrong and is
not necessary' instead of 'the migration is harmless and easy and
should be done as soon as possible'.

Quote> However, if you use the Community Edition, I believe you also bear
  some responsibility for regularly reading forum posts; otherwise,
  you might find yourself facing a problem eight months down the line
  that has already been thoroughly discussed and addressed. This
  applies equally to experienced forum members and OPNsense newcomers.

I did that until you drove me away.

Besides, users would have to not only read every post just in case
they might have a problem some months later but also remember it all.
I think that is demanded way too much.

It's like saying that every user of whatever software needs to read
everything about it in case he encounters a problem.

It doesn't work that way.  When I'm encountering a problem, I try to
solve it myself.  Asking questions anywhere is a last resort when
everything else fails.  The internet has mutated from a rather
friendly and helpful domain into the most hostile environment I
know. I don't want to ask questions because it almost always only
stirrs up useless and stupid discussions in which people try to insult
me, call me a troll and censor me.

Even if I wanted to read everything just to keep up to date, every day
would have to be at least a week long.

What if someone uses the business edition?

Quote> Sometimes perhaps, but I'm surprised at the trivial questions that
  are being raised seeing the code that was touched and people not
  realising how many technical issues they would never notice because
  a) they don't have the setup or b) changes are handled in a way that
  few regressions arise to begin with.

And yet you expect these people to read every forum post to be
informed and to remember all the technical issues, regressions and
setups they never encounter or have.

Maybe if the 'Migration notes, known issues and limitations' section were
more exensive and there were only a link to the (rather irrelevant)
long list of items, then people wouldn't have so many trivial
questions.

Quote> A great example is the Intel microcode plugin that if I had read the
  forum properly would have known I should have removed it before
  upgrading to 26.7.

> It's a very complex issue involving the microcode updates and the
  operating system that has been going on for years now -- and both
  are not under our immediate influence.  And here, also, it was
  clearly in the release notes:

https://github.com/opnsense/changelog/blob/b0be678d6235cb8da05446df7ea233c38cdcd0a7/community/26.7/26.7#L101

I guess you mean this:


"The CPU microcode early loading has been known to be flaky on some
setups.  A fix is in the FreeBSD 15.1 boot loader code, but can only
be reached by reinstall or manually updating the boot code of your
system after the upgrade succeeded.  If you want to be on the safe
side during the upgrade itself please remove the plugin before
proceeding."


I still don't know which plug-in this is referring to and how I would
update the boot code.

I can only guess that 'boot code' means the boot manager.  What
exactly am I supposed to do after reading this when I'm about to
update?  Why isn't the boot manager being updated automatically during
the update?

What I might do is figure out how one updates the boot manager of
FreeBSD.  But then, it would be pretty pointless because OPNSense
might be different from FreeBSD, so that might not work.  I wouldn't
take that chance.

I'm finding this also unclear.  It says I should manually update the
'boot code' (boot manager?) *after* updating.  That doesn't make sense
because if this goes wrong, booting wouldn't be possible.  So
obviously, I would need to update the 'boot code' before updating.

So maybe I better remove a plug-in first.  But which one?

Trivial questions?  Maybe, maybe not.  It's certainly not trivial when
I update and the router doesn't boot anymore.

The update shouldn't even start before that issue is somehow resolved
first.  Or perhaps I'm understanding this wrong and nothing can go
wrong when I update because the information is entirely unclear?

Why are the release notes not starting with the important section?
#2
26.7 Series / Traffic through VIP is roughly...
Last post by dispo2 - Today at 12:03:35 AM
I have two opnsense (26.7.3_8) running on different tin as a HA pair (active / standby)

I have a 500/50 Mbit internet connection and I have noticed (via speedtest.net) that my test results when using the real IP address as gateway are full 500Mbit but when I use the VIP as gateway the test speed max'es out at roughly half that.

I am trying to understand why as I did not think running a VIP / running traffic through a VIP added any major layer of additional processing.

tl;dr

These are proxmox hosted VM's with all of the recommendations (that I can find) enabled, cpu=host, hardware offloads disabled, hw.ibrs_disable=1, vm.pmap.pti=0, 8Gb RAM.

Hardware is quadcore Intel(R) Celeron(R) J6412 @ 2.00GHz and quadcore Intel(R) Pentium(R) N6415 @ 1.20GHz
Network is 4xIntel i226-V 2.5GbE, interfaces are configured as virtIO

LAN and WAN interfaces are their own NIC, not bridges

I have a virtual IP configured on the LAN via CARP, this is used for the gateway address in DHCP for seemless failover for LAN devices.
I have a virtual IP configured on the WAN for outbound NAT

These were originally 2 vCPU running the default v86-64-v2-aes profile with the default cpuunits. I have changed these to 3 vCPU type host with cpuunits=2048. This has helped a bit but has not significantly increased throughput through the VIP.

Using the real IP as the gateway address for a LAN device gets full internet speed so the hardware is obviously capable of it.
I cannot understand why, when using the VIP as gateway address, I get roughly half that.

When running the speed tests with the real ip of the active opnsense as gateway I can see traffic on the active firewall (as expected) and no traffic on the standby firewall (as expected).
Changing the gateway to the standby firewall reverses which firewall shows traffic (as expected).
Changing the gateway to the VIP shows the traffic via the active (CARP master) firewall (as expected).

In the above changes the only difference is the target gateway IP on the LAN side, all required NAT (at the WAN) is the same, all required firewall rule matching is the same, all hardware abilities and settings are the same.

So I cannot understand why the VIP is a bottleneck. Increasing cpu helps which implies an additional overhead for the VIP path but never solves it.

Any suggestions / ideas / tuneables I have missed ?
#3
Tutorials and FAQs / Re: How I updated my I226-V NV...
Last post by Lucid1010 - September 09, 2026, 10:30:22 PM
👍
#4
26.7 Series / Re: Some SSL certificate help ...
Last post by Patrick M. Hausen - September 09, 2026, 08:35:42 PM
System > Trust > Certificates

Click on the "+", select "Create Certificate Signing Request", continue with all your data. After you signed the CSR with your CA in the same menu click on the "edit" icon for the CSR - the little pencil. Paste the signed certificate date into the empty box at the top labelled "Certificate data". Save. Done.
#5
26.7 Series / Re: Some SSL certificate help ...
Last post by fornax - September 09, 2026, 08:32:26 PM
When you perform the step on the Certificates page to generate the CSR, it creates a line on that page. Once you have the cert from the CA, you click the Edit button on that same line. There'll be an empty box in the edit page for you to paste in the cert.
#6
German - Deutsch / Re: Umstieg auf Kea DHCP
Last post by Patrick M. Hausen - September 09, 2026, 08:31:10 PM
Hier die Leases mit meinem IOT VLAN ausgeklappt.
#7
German - Deutsch / Re: Umstieg auf Kea DHCP
Last post by Patrick M. Hausen - September 09, 2026, 08:29:35 PM
Aber Auto collect will man doch sowieso. Dann wird in jedem VLAN die Interface-Adresse der OPNsense an die Clients verteilt. Goldrichtig.

Und hinterher hast du alle Subnets/VLANs übersichtlich in einer Liste, und einen Reiter weiter alle Reservierungen über alle Subnets in einer Liste zum auf- und zuklappen. Leases dito. Das Interface ist einfach viel besser, siehe Screenshots.
#8
German - Deutsch / Re: Umstieg auf Kea DHCP
Last post by spooner.arthur - September 09, 2026, 08:22:03 PM
Mmh, OK, finde ich nicht so schön und übersichtlich beim ISC.

Also unter Kea DHCP v4 unter Settings und Interfaces anklicken / auswählen, wo man einen DHCP benötigt z.B. 5 Stück und dann unter
Subnets pro VLan je einen neuen Subnet Eintrag anlegen, richtig?

Aber wo geb ich den DNS und das Gateway mit, das habe ich gerade durch Zufall gefunden, da muss man den "Auto collect option data" Haken entfernen.
Mmh, OK.

Oder ist der "Dnsmasq DNS & DHCP" Server die bessere Alternative zum ISC DHCP?
#9
26.7 Series / Re: Upgrade advice to OPNsense...
Last post by tangofan - September 09, 2026, 07:33:17 PM
I upgraded 5 weeks ago to 26.7.1_1 with Zenarmor, Crowdsec, QFeeds and Tailscale installed and I didn't have any problem with the upgrade, but I paid attention to the things below:

- There were some issues with the newer FreeBSD version in 27.1, which manifested when running the os-cpu-microcode-intel plugin. At the time the recommendation was to uninstall this plugin before upgrading, update the OPNsense bootloader and only afterwards reinstall the plugin. I suggest that you search the forum for this, since there were plenty of posts on this subject.

- If you have not yet migrated the firewall and NAT rules to the new UI, you will need to install a new plugin in 26.7 to be able to edit them. That plugin (os-firewall-legacy IIRC) is already available in later versions of 26.1, at which time I installed it. I waited with the migration until after the upgrade to 26.7, but it's probably better to execute that migration before the upgrade. I found the migration to be very easy, just follow the instruction in the migration tool and remember to go through all the tabs of that tool.

As always, read the release notes and download your config before the upgrade and (if you run ZFS, which I hope everyone does) create a snapshot.
#10
Zenarmor (Sensei) / Re: Cancelling my subscription...
Last post by tangofan - September 09, 2026, 07:08:49 PM
My OPNsense box is a little over two years old and I had Zenarmor running for two years with a home subscription, using a local elasticsearch DB. The lifetime writes of my SSD are about 5.7 TiB, which is very mild compared to the rated typical lifespan of an SSD. So I suspect those who have a wear problem with their SSD have some additional features or logs turned on or turned to a higher logging level.

What made me discontinue my Zenarmor home subscription and ultimately uninstall Zenarmor were performance problems like the one I described here. I don't know, if those particular problems could have been solved by multicore support (single I don't know how granular the workload for a particular connection can be shared between different threads), but not having it or getting it means that I definitely would have to get a system with a CPU that has higher single-core performance than an Intel J6412. And that just didn't seem to be worth it.

So I would agree with the assessment that Zenarmor has a growing problem with positioning themselves. I understand that they don't want their free edition or their home edition subscription to cannibalize their commercial subscriptions (particularly in the SMB sector, where you might not need enterprise-level sizing). My assumption is that the main purpose of the free and home tiers is to have a showcase to home-labbers, in the hope that some of them would carry a positive experience into their workplace and thus increase Zenarmor's commercial subscription base. However as the home-labber experience turns less positive, that "carryover" effect is much less likely to happen. Thus I am surprised that they don't offer multithreading (with a limited thread count) in the free and home editions.