Recent posts

#1
Tutorials and FAQs / Re: ndp-proxy-go: Proxy ISP pr...
Last post by meyergru - Today at 10:48:03 AM
N.P., Cedrik, this just made it to https://forum.opnsense.org/index.php?topic=42985.0, point 29.
#2
25.7, 25.10 Series / unbound logger file increase i...
Last post by aperezva - Today at 10:41:20 AM
Every 24 hours ican see this behaviour in my firewall:


---- Muestra Sun Nov 30 10:00:42 CET 2025 ----
last pid: 72722;  load averages:  0.10,  0.10,  0.08  up 2+00:28:34    10:00:42
90 threads:    1 running, 88 sleeping, 1 zombie
CPU:  0.6% user,  0.0% nice,  0.4% system,  0.0% interrupt, 99.0% idle
Mem: 227M Active, 670M Inact, 2912M Wired, 56K Buf, 27G Free
ARC: 2105M Total, 1288M MFU, 660M MRU, 836K Anon, 23M Header, 130M Other
     1802M Compressed, 4146M Uncompressed, 2.30:1 Ratio
Swap: 8192M Total, 8192M Free

  PID USERNAME    PRI NICE   SIZE    RES STATE    C   TIME    WCPU COMMAND
80838 root         21    0   323M   235M kqread   5  13:02   0.20% /usr/local/bin/python3 /usr/local/opnsense/scripts/unbound/logger.py (python3.11){python3.11}

---- Muestra Sun Nov 30 10:00:50 CET 2025 ----
last pid: 30905;  load averages:  0.08,  0.10,  0.08  up 2+00:28:42    10:00:50
93 threads:    1 running, 92 sleeping
CPU:  0.6% user,  0.0% nice,  0.4% system,  0.0% interrupt, 99.0% idle
Mem: 235M Active, 670M Inact, 2912M Wired, 56K Buf, 27G Free
ARC: 2105M Total, 1289M MFU, 659M MRU, 1271K Anon, 23M Header, 130M Other
     1802M Compressed, 4146M Uncompressed, 2.30:1 Ratio
Swap: 8192M Total, 8192M Free

  PID USERNAME    PRI NICE   SIZE    RES STATE    C   TIME    WCPU COMMAND
  442 root         23    0    59M    34M accept   7   0:02   0.88% /usr/local/bin/php-cgi

---- Muestra Sun Nov 30 10:01:39 CET 2025 ----
last pid:  1475;  load averages:  1.33,  0.40,  0.19  up 2+00:29:31    10:01:39
91 threads:    1 running, 89 sleeping, 1 zombie
CPU:  0.6% user,  0.0% nice,  0.4% system,  0.0% interrupt, 99.0% idle
Mem: 236M Active, 2070M Inact, 4468M Wired, 56K Buf, 24G Free
ARC: 2190M Total, 1257M MFU, 776M MRU, 1576K Anon, 23M Header, 130M Other
     1799M Compressed, 4140M Uncompressed, 2.30:1 Ratio
Swap: 8192M Total, 8192M Free

  PID USERNAME    PRI NICE   SIZE    RES STATE    C   TIME    WCPU COMMAND
80838 root         63    0  1914M  1644M kqread   6  13:09  21.97% /usr/local/bin/python3 /usr/local/opnsense/scripts/unbound/logger.py (python3.11){python3.11}

---- Muestra Sun Nov 30 10:01:42 CET 2025 ----
last pid:  5519;  load averages:  1.33,  0.40,  0.19  up 2+00:29:34    10:01:42
90 threads:    1 running, 88 sleeping, 1 zombie
CPU:  0.6% user,  0.0% nice,  0.4% system,  0.0% interrupt, 99.0% idle
Mem: 236M Active, 2070M Inact, 4468M Wired, 56K Buf, 24G Free
ARC: 2190M Total, 1257M MFU, 776M MRU, 1576K Anon, 23M Header, 130M Other
     1799M Compressed, 4140M Uncompressed, 2.30:1 Ratio
Swap: 8192M Total, 8192M Free

  PID USERNAME    PRI NICE   SIZE    RES STATE    C   TIME    WCPU COMMAND
80838 root         39    0  1914M  1644M kqread   6  13:09  15.19% /usr/local/bin/python3 /usr/local/opnsense/scripts/unbound/logger.py (python3.11){python3.11}

---- Muestra Sun Nov 30 10:01:51 CET 2025 ----
last pid:  8403;  load averages:  1.21,  0.40,  0.19  up 2+00:29:43    10:01:51
90 threads:    1 running, 88 sleeping, 1 zombie
CPU:  0.6% user,  0.0% nice,  0.4% system,  0.0% interrupt, 99.0% idle
Mem: 233M Active, 2074M Inact, 4468M Wired, 56K Buf, 24G Free
ARC: 2186M Total, 1253M MFU, 776M MRU, 1576K Anon, 23M Header, 130M Other
     1797M Compressed, 4138M Uncompressed, 2.30:1 Ratio
Swap: 8192M Total, 8192M Free

  PID USERNAME    PRI NICE   SIZE    RES STATE    C   TIME    WCPU COMMAND
80838 root         39    0  1914M  1644M kqread   6  13:10   5.66% /usr/local/bin/python3 /usr/local/opnsense/scripts/unbound/logger.py (python3.11){python3.11}

Sizing in logger.py increase from 323 Mb to 1914Mb, is this normal?

Any recomandation?.

It´s increasing my memory usage too
#3
25.7, 25.10 Series / Unable to watch Yortube
Last post by nicholaswkc - Today at 10:28:24 AM
Dear all, I open browser to watch youtube but unfortunately I cannot stremam any videos or login. Any things wrong?

#4
German - Deutsch / Re: Log Files der Firewall feh...
Last post by Schnuffel2008 - Today at 09:45:16 AM
Hi,
nee ich habe es mit mehreren Browsern versucht. Chrome, Firefox und Edge. Wie gesagt vor kurzem haben alle funktioniert. Und wie gesagt, ich kann auch ausschließen, dass es an meinem Skin flexcolor liegt. Mit dem ging es noch vor kurzem und ich habe es auch mit dem original OPNsense Skin versucht. Das Problem bleibt.
Ich vermute auch eher, dass ich etwas verstellt habe.
Müsste jetzt im Notfall wieder zu einer älteren Sicherung zurück und versuchen, ob es damit wieder geht. Ich denke, seit der Sicherung habe ich aber noch anderes geändert, was ich nicht mehr zusammen bekomme.
Da haben wir wieder das übliche User-Problem, dass man immer genau die Sicherung
vergessen hat, die man hinterher benötigt.😄
Da fällt mir ein, ich könnte natürlich eine aktuelle Sicherung machen und diese mit einer älteren vergleichen.
#5
25.1, 25.4 Series / Some routes were not successf...
Last post by techexplore - Today at 09:32:52 AM
I am trying to setup OpenVpn with OpnSense 25.1.

I am able to connect but with no data transfer of any kind (from wireshark, I could only see ARP requests).

The OpenVpn GUI reports the following logs:

Sun Nov 30 09:21:54 2025 Note: --cipher is not set. OpenVPN versions before 2.5 defaulted to BF-CBC as fallback when cipher negotiation failed in this case. If you need this fallback please add '--data-ciphers-fallback BF-CBC' to your configuration and/or add BF-CBC to --data-ciphers.
Sun Nov 30 09:21:54 2025 OpenVPN 2.6.16 [git:v2.6.16/647b115111079fcf] Windows [SSL (OpenSSL)] [LZO] [LZ4] [PKCS11] [AEAD] [DCO] built on Nov 17 2025
Sun Nov 30 09:21:54 2025 Windows version 10.0 (Windows 10 or greater), amd64 executable
Sun Nov 30 09:21:54 2025 library versions: OpenSSL 3.6.0 1 Oct 2025, LZO 2.10
Sun Nov 30 09:21:54 2025 DCO version: 1.3.3
Sun Nov 30 09:21:56 2025 WARNING: No server certificate verification method has been enabled.  See http://openvpn.net/howto.html#mitm for more info.
Sun Nov 30 09:21:56 2025 TCP/UDP: Preserving recently used remote address: [AF_INET]10.110.100.74:1194
Sun Nov 30 09:21:56 2025 ovpn-dco device [OpenVPN Connect DCO Adapter] opened
Sun Nov 30 09:21:56 2025 TCPv4_CLIENT link local (bound): [AF_INET][undef]:0
Sun Nov 30 09:21:56 2025 TCPv4_CLIENT link remote: [AF_INET]10.110.100.74:1194
Sun Nov 30 09:21:56 2025 WARNING: this configuration may cache passwords in memory -- use the auth-nocache option to prevent this
Sun Nov 30 09:21:56 2025 [xxxx-vpn] Peer Connection Initiated with [AF_INET]10.110.100.74:1194
Sun Nov 30 09:21:57 2025 IPv4 MTU set to 1500 on interface 10 using service
Sun Nov 30 09:21:57 2025 Warning: route gateway is not reachable on any active network adapters: 10.254.3.1
Sun Nov 30 09:21:57 2025 Warning: route gateway is not reachable on any active network adapters: 10.254.3.1
Sun Nov 30 09:21:57 2025 Warning: route gateway is not reachable on any active network adapters: 10.254.3.1
Sun Nov 30 09:21:57 2025 Warning: route gateway is not reachable on any active network adapters: 10.254.3.1
Sun Nov 30 09:21:57 2025 Warning: route gateway is not reachable on any active network adapters: 10.254.3.1
Sun Nov 30 09:21:57 2025 Initialization Sequence Completed
Sun Nov 30 09:21:57 2025 ERROR: Some routes were not successfully added. The connection may not function correctly


My VPN net is 10.254.3.0/24 and LAN on OpnSense is 10.254.0.0/24.

I do have an all allow firewall rule on the OpenVpn interface under Firewall/Rules.

No ping or data transfer, and when using OpenVpn Connect it keeps reconnecting every 40 second.
#6
German - Deutsch / Re: Log Files der Firewall feh...
Last post by chemlud - Today at 09:14:18 AM
Hi, hier 25.7.8 und alle logs normal mit Firefox (latest)...

Anderer Browser (Palemoon) kann seit Jahren keine Logs der OPNsense darstellen. Browser gewechselt?
#7
25.7, 25.10 Series / Re: The new configuration clea...
Last post by OPNenthu - Today at 09:13:14 AM
You know what, I only just realized after closer reading of Ad's commit message that this is how it works.  It identifies config models by the version. https://github.com/opnsense/core/commit/c485a33ab7c9d366baf3665dfcbbda65052b04ad

My bad...
#8
25.7, 25.10 Series / The new configuration cleanup ...
Last post by OPNenthu - Today at 08:53:11 AM
I tried the new configuration cleanup tool under System->Configuration->Defaults->Components.  It worked beautifully to remove the stale configs of several plugins that I'd uninstalled.  It even helpfully highlighted which ones were not installed to guide the selection for cleanup :)  Nice touch.

The only minor inconsistency is that the XML element start/end tags sometimes get removed and sometimes don't.  I had limited configs to play with, but it might be the case that when there is no plugin version in the start tag then those get left intact, but the versioned ones get removed.

I'm not sure if this is expected or warrants a bug, but in either case the end result is that the configs are removed and the plugin would revert to its defaults when re-installed (so not really an issue).

Adding a couple diff snippets here to illustrate.

1. The 'bind' plugin did not have a version listed.  The element start tag was <bind> and the end tag was </bind>.  Everything between the tags was removed:

6186,6234c6088,6089
<       <record version="1.0.1">
<         <records/>
<       </record>
<       <acl version="1.0.0">
<         <acls/>
<       </acl>
<       <general version="1.0.12">
<         <enabled>0</enabled>
<         <disablev6>0</disablev6>
<         <enablerpz>1</enablerpz>
<         <listenv4>0.0.0.0</listenv4>
<         <listenv6>::</listenv6>
<         <querysource/>
<         <querysourcev6/>
<         <transfersource/>
<         <transfersourcev6/>
<         <port>53530</port>
<         <forwarders/>
<         <filteraaaav4>0</filteraaaav4>
<         <filteraaaav6>0</filteraaaav6>
<         <filteraaaaacl/>
<         <logsize>5</logsize>
<         <general_log_level>info</general_log_level>
<         <maxcachesize>80</maxcachesize>
<         <recursion/>
<         <allowtransfer/>
<         <allowquery/>
<         <dnssecvalidation>no</dnssecvalidation>
<         <hidehostname>0</hidehostname>
<         <hideversion>0</hideversion>
<         <disableprefetch>0</disableprefetch>
<         <enableratelimiting>0</enableratelimiting>
<         <ratelimitcount/>
<         <ratelimitexcept>0.0.0.0,::</ratelimitexcept>
<         <rndcalgo>hmac-sha256</rndcalgo>
<         <rndcsecret>VxtIzJevSQXqnr7h2qerrcwjnZlMWSGGFBndKeNIDfw=</rndcsecret>
<       </general>
<       <domain version="1.1.1">
<         <domains/>
<       </domain>
<       <dnsbl version="1.0.5">
<         <enabled>0</enabled>
<         <type/>
<         <whitelists/>
<         <forcesafegoogle>0</forcesafegoogle>
<         <forcesafeduckduckgo>0</forcesafeduckduckgo>
<         <forcesafeyoutube>0</forcesafeyoutube>
<         <forcestrictbing>0</forcestrictbing>
<       </dnsbl>
---

2. The 'stunnel' plugin had a version in the <start> tag and in that case everything including the tags was removed:

6236,6243d6090
<     <Stunnel version="1.0.4" persisted_at="1756512408.00">
<       <general>
<         <enabled>0</enabled>
<         <chroot>0</chroot>
<         <enable_ident_server>0</enable_ident_server>
<       </general>
<       <services/>
<     </Stunnel>

Thanks again for your work on this tool!
#9
Quote from: Greg_E on Today at 06:39:18 AMbut the x710 should habe 2.5 and 5g support if I need to run a copper module.
It may be OT but: would you be able to ELI5 how to determine if a chipset is supporting 2.5 and 5Gbit? On and off I look for an answer now for a year or two (more of an indication of limitation on my side).

I only have SFP+ adapters, no NBaseT; NBaseT only by using copper transceiver. Some Mikrotik switches support it 2.5/5Gbit, some cards support it others not. I read quite a few datasheets of SFP+ conroller but can't find an explanation.

Does the MAC has to support these speeds, or the PHY? Or modes like MII, RMII, XGMII etc.?

And since there are copper versions of the X710 (X710-TM4 & X710-AT2) which do support 2.5 and 5Gbit, is that a sure indication that SFP+ models also support these speeds?

The XL710/X710 datasheet (I'm not through yet) : https://cdrdv2-public.intel.com/332464/332464_710_Series_Datasheet_v_4_1.pdf
#10
German - Deutsch / Log Files der Firewall fehlen
Last post by Schnuffel2008 - Today at 07:14:24 AM
Hi,
ich benötige einmal kurz Hilfe.
Leider werden mir keine Einträge unter den Ligs für die Firewall angezeigt.
Wenn ich Liveview Aufrufe, dann wird mir nur  der Waiting+cursor angezeigt. Und auch bei Overview ist alles leer.
Zuletzt als ich flexcolor fertig gestellt habe, hatte ich diese Seiten immer geprüft, um zu schauen, dass mein theme sie richtig darstellt. Da war alles okay. Seitdem habe ich allerdings einiges in den Einstellungen verändert eben um zu schauen, ob der Skin funktioniert. Und ich habe das Update auf 25.7.8 durchgeführt. Jetzt eriß ich nicht was die Ursache für das Problem ist. Ich habe neu gestartet, habe neben meinem Theme auch den Original Skin getestet, aber das Problem bleibt. Jemand eine Idee wo ich etwas abgeschaltet haben könnte?