Recent posts

#1
26.7 Series / Re: Connections suddenly block...
Last post by BoerBart - Today at 05:03:40 PM
Quote from: nero355 on September 30, 2026, 10:18:35 PMWait...

The Modem is Bridged... right ?!

No - The modem is the main entry for my ISP. So, ISP --> Modem -->.... The Archer AX50 was bridged, but I've removed it and replaced it with the switch I had laying around.

I might have found the issue, though. It might be the issue, or I'm simply masking it now.

The ISP modem has IP 192.168.1.1, the OPNsense LAN interface has IP 192.168.1.214. I had the LAN interface IP of OPNsense (192.168.1.214) configured as gateway for my smartphone and PC. It has been like that from pretty much the beginning, never had any issues. No clue why it now 'suddenly' shows up. I've tested it with a fresh OPNsense 26.1 VM too, and the same exact issue showed up (packets/connections being dropped). After changing the gateway from 192.168.1.214 to the IP of the ISP modem (192.168.1.1), the issue is gone(?). Obviously the packets don't go through OPNsense anymore, hence it works fine now.

I don't know whether the configuration I had adds to your "weird stuff/things" people do, or that it should be a valid configuration, but for now, it works.
#2
26.7 Series / Re: Fresh Install OPNsense 26....
Last post by caplam - Today at 04:12:10 PM
it reminds me of the first time i enabled vlans on my switches.
if i understand correctly
igc1 (LAN) is linked to port4 of the switch
igc2 (VLAN11+VLAN22) is linked to port 5 of the switch.

port 4 needs to be set to access mode with PVID 1
port 5 needs to be set to trunk with vlan tag 11&22
but for this to work port5 can't have PVID 1.
I fixed things by creating a dummy vlan 99 (or whatever you want but not used ) and setting PVID 99 to port5.
and of course the port for the orbi needs pvid 1 and tagged vlan11 and vlan22 (if you have wifi cams)
#3
Post screenshots of your complete Kea and DNSmasq configuration.
#4
26.1, 26,4 Series / dnsmasq does not give any leas...
Last post by JL - Today at 03:14:24 PM
I don't understand how this possible and cannot find anything extraordinary hinting at a reason why.

dnsmasq : disabled : configured dhcp + dns

kea dhcp: enabled : configure dhcp, uses unbound for DNS (so no host resolved), this gives leased and DNS lookups work except for LAN, as expected

switching to dnsmasq, disable kea, disable unbound, enable dnsmasq
no leases are handed out by dnsmasq

so, same firewall configuration, no leases
in 'live view' i do see bogon network detection + a drop, these are multiple drops for dnsmasq while a single drop for kea
dnsmasq = no lease, kea = lease

please, your thoughts and recommendations
#5
26.7 Series / Re: Upgrade Candidate Discrepa...
Last post by pholt - Today at 02:19:27 PM
Are the lingering update candidates is just some kind of random artifact? I'm curious because, the number is different on each identically configured machine.
#6
26.7 Series / Postfix sender rewriting
Last post by putt1ck - Today at 02:11:57 PM
We have a scenario where an internal service sends with a domain that needs rewriting to one that the firewall relay can successfully deliver i.e.

mailbox1@internaldomain.net needs rewriting to mailbox1@correctdomain.com

Our initial research suggested that the Postfix plugin could achieve this with "Sender Canonical Rewriting" but found little documentation on how to correctly complete the fields. Posts elsewhere on this forum suggested we should format the original sender (entered into "Rewrite From") like this:

/mailbox1@internaldomain.net/i

and then the replacement address (entered into "Rewrite To") simply as:

mailbox1@correctdomain.com

However configured like this the sender address is not rewritten and the mail gets relayed with the original "From:" address and the headers do not contain the replacement address anywhere.

Is there any additional documentation on how to achieve the rewrite correctly?

NB the only entry in the logs referencing "canonical" is this: warning: regexp map /usr/local/etc/postfix/sendercanonical, line 1: ignoring unrecognized request but it is from a week ago, not repeated on subsequent service restarts nor when mail flows

All suggestions welcome!

Regards

Chris
#7
26.7 Series / Re: Fresh Install OPNsense 26....
Last post by nero355 - Today at 01:40:54 PM
Quote from: Schwermzilla on Today at 01:01:56 AMYeah, hope that is not what is causing the problem.
Well... if you want to transport Multiple VLANs to another Switch or Accesspoint then you need to use TAGGED VLANs and not ACCESS Mode :)

Just to be sure :

Are you aware of the following =>

OPNsense Interface (whole NIC basically) => Switch Port in ACCESS Mode
OPNsense VLAN Interface (VLAN Interface assigned to a NIC that's not used for anything else) => Switch Port in TAGGED Mode

Switch Port in ACCESS Mode => End user devices like PCs/TVs/Consoles/etc.
Switch Port in TAGGED Mode => Port of another Switch or Accesspoint that understands TAGGED VLAN traffic.

ACCESS MODE = Only 1 VLAN allowed.
TAGGED MODE = Multiple VLANs allowed.

Does your current setup look like this ??
#8
26.7 Series / Re: Programmatic way to create...
Last post by Patrick M. Hausen - Today at 12:59:47 PM
A small wrapper around the API with CURL should not be hard to do?
#9
26.7 Series / Re: pkg: 2.3.1_1 -> 2.8.4_1 Pa...
Last post by Patrick M. Hausen - Today at 12:59:01 PM
Please post the output here as text in a code block. Thank you. I am not clicking on that link.
#10
26.7 Series / Re: Programmatic way to create...
Last post by bimbar - Today at 12:57:15 PM
A cli would be so nice.