Recent posts

#1
26.7 Series / Re: Opnsense 26.7.5 hangs at b...
Last post by nero355 - Today at 02:06:43 PM
Quote from: QuisaZaderak on Today at 08:54:25 AMSMART is status OK (from within BMC/UEFI).
Please simply boot a Linux or *BSD Live ISO from your favorite USB Stick and use 'smartctl -a /dev/<whatever>' to see the full S.M.A.R.T. output and post it here so we can double check for you before you reinstall :)
#2
26.7 Series / Sudden shutdown of all interfa...
Last post by uhillebrand - Today at 12:31:31 PM
Hi all, we had a severe outage at a customer's site a few days ago (OPNsense stopped responding on all interfaces). After going through the logs I am baffled how this could happen. Maybe someone can help finding the cause for this.

The firewall in question is running 26.7.1_1 on a Protectli VP2440.

There is a multi WAN-Setup:
- igc0 has a PPPoE connection to the primary ISP
- igc1 has an ethernet connection to the backup ISP

On the LAN side there is a lagg0 with 2 10G Interfaces (ixl0, ixl1); all internal traffic is routed via a number of VLANs on this bond.

This is how the problem developed:

1) At first, dpinger alerted that both ISPs had packet loss:

<165>1 2026-09-29T17:18:18+02:00 hwk-gw01.c.cibex.net dpinger 10740 - [meta sequenceId="1"] ALERT: WAN1_PPPOE (Addr: 8.8.8.8 Alarm: none -> loss RTT: 17.9 ms RTTd: 0.1 ms Loss: 12.0 %)
<165>1 2026-09-29T17:18:18+02:00 hwk-gw01.c.cibex.net dpinger 10740 - [meta sequenceId="2"] ALERT: WAN2GW (Addr: 1.1.1.1 Alarm: none -> loss RTT: 22.2 ms RTTd: 0.4 ms Loss: 12.0 %)
<165>1 2026-09-29T17:18:30+02:00 hwk-gw01.c.cibex.net dpinger 10740 - [meta sequenceId="3"] ALERT: WAN1_PPPOE (Addr: 8.8.8.8 Alarm: loss -> down RTT: 17.9 ms RTTd: 0.2 ms Loss: 33.0 %)
<165>1 2026-09-29T17:18:30+02:00 hwk-gw01.c.cibex.net dpinger 10740 - [meta sequenceId="4"] ALERT: WAN2GW (Addr: 1.1.1.1 Alarm: loss -> down RTT: 22.1 ms RTTd: 0.4 ms Loss: 33.0 %)


2) In system.log error messages regarding PPPoE started to show:

<29>1 2026-09-29T17:18:34+02:00 hwk-gw01.c.cibex.net ppp 35846 - [meta sequenceId="17"] [opt15_link0] LCP: no reply to 1 echo request(s)
[...]
<29>1 2026-09-29T17:19:04+02:00 hwk-gw01.c.cibex.net ppp 35846 - [meta sequenceId="20"] [opt15_link0] LCP: no reply to 4 echo request(s)
<29>1 2026-09-29T17:19:14+02:00 hwk-gw01.c.cibex.net ppp 35846 - [meta sequenceId="21"] [opt15_link0] LCP: no reply to 5 echo request(s)
<29>1 2026-09-29T17:19:14+02:00 hwk-gw01.c.cibex.net ppp 35846 - [meta sequenceId="22"] [opt15_link0] LCP: peer not respond ing to echo requests
<29>1 2026-09-29T17:19:14+02:00 hwk-gw01.c.cibex.net ppp 35846 - [meta sequenceId="23"] [opt15_link0] LCP: state change Opened --> Stopping


3) And now starts the part that is baffling me: a few seconds later, system.log reported that the LAN interface was detatched, and shut down both interfaces:

<13>1 2026-09-29T17:19:29+02:00 hwk-gw01.c.cibex.net opnsense 80063 - [meta sequenceId="57"] /usr/local/etc/rc.linkup: DEVD: Ethernet detached event for opt2(lagg0)
<13>1 2026-09-29T17:19:30+02:00 hwk-gw01.c.cibex.net kernel - - [meta sequenceId="58"] [3363137] ixl1: Interface stopped DISTRIBUTING, possible flapping
<13>1 2026-09-29T17:19:30+02:00 hwk-gw01.c.cibex.net kernel - - [meta sequenceId="59"] [3363137] ixl0: Interface stopped DISTRIBUTING, possible flapping
<13>1 2026-09-29T17:19:30+02:00 hwk-gw01.c.cibex.net kernel - - [meta sequenceId="60"] <6>[3363137] lagg0: link state changed to DOWN


-


Some time later the firewall was physically reset, and started working without problems again.

What kind of problem can cause a shutdown of *all* available interfaces in the matter of less than a minute? I checked CPU temp, RAM usage, state table, nothing out of the ordinary there. If anyone has an explanation or could tell me how to further debug this issue any input would be very welcome.

Thanks
Urban
#3
Virtual private networks / Re: IPv6 Wireguard VPN over gi...
Last post by franco - Today at 12:19:30 PM
Where are these WG IPv6 addresses using /128 coming from lately?  IMO this trend sucks as it moves your gateway out of the subnet because you don't have a subnet anymore and there are historical limitations at play here, also see https://github.com/opnsense/core/issues/10578


Cheers,
Franco
#4
26.7 Series / Re: OPNsense 26.7.4 - VLAN tra...
Last post by merrins63 - Today at 11:12:10 AM
Yes it is, that mode was enabled by default.
I had the same setting as your picture.

Turning it off then on again made no difference

regards
#5
26.7 Series / Re: OPNsense 26.7.4 - VLAN tra...
Last post by Patrick M. Hausen - Today at 11:10:56 AM
What kind of feedback do you expect? You have not yet answered my question. Is "Firewall rules" active in your setup?
#6
26.7 Series / Re: OPNsense 26.7.4 - VLAN tra...
Last post by merrins63 - Today at 11:04:43 AM
Quote from: Patrick M. Hausen on September 29, 2026, 01:20:12 PMThese definitions match the interface configuration. I am out of ideas ... er ... one moment ...

Did you check this option?



If you did not that would perfectly explain your observed symptoms.

Quote from: Patrick M. Hausen on September 29, 2026, 01:20:12 PMThese definitions match the interface configuration. I am out of ideas ... er ... one moment ...

Did you check this option?



If you did not that would perfectly explain your observed symptoms.

ISC creates the necessary firewall rules for DHCP to work by default, if I remember correctly. For Kea that's optional, because some users complained that OPNsense should not create any rules automatically giving full control to the admin.


ISC creates the necessary firewall rules for DHCP to work by default, if I remember correctly. For Kea that's optional, because some users complained that OPNsense should not create any rules automatically giving full control to the admin.


Hi @Patrick,

Do you have any further feedback on this? Since I've already exhausted everything possible on the Kea DHCP side, I wanted to ask: could this potentially be a bug?

If so, is there anything else I can do to help get this reviewed before the next release to confirm whether it's an issue?

Cheers
#7
26.7 Series / Re: Programmatic way to create...
Last post by franco - Today at 10:30:07 AM
There's MVC/API for both VLAN and interface assignment.  On master there's also an API extension for interface settings coming to 26.7.x soon.


Cheers,
Franco
#8
26.7 Series / Re: OPNsense 26.7 blocks LAN t...
Last post by ricksense - Today at 10:13:17 AM
Quote from: Patrick M. Hausen on September 30, 2026, 09:42:02 PMWhat exactly was your fix, please?

Of course!

Here is an explanation of what I did to configure the firewall rules successfully. Frankly, it barely makes sense even to me, since I simply reapplied the exact configuration I had in the previous version. After setting and applying the LAN pass rule again, I used the following commands in the shell: pfctl -F state and pfctl -e

After that, even though my PC could access the OPNsense dashboard, it still couldn't reach the internet. I enabled gateway monitoring (monitoring IP: 8.8.8.8), and checking 'Use System Nameservers' in the Unbound settings (enabling DoT got the job done as well).
#9
26.7 Series / Programmatic way to create vla...
Last post by paulrosham - Today at 09:09:18 AM
Is there any way that I can create some vlan devices and assign them to a new interface. If there is no MVC api, is there some other method?
thanks
Paul
#10
26.7 Series / Re: Opnsense 26.7.5 hangs at b...
Last post by QuisaZaderak - Today at 08:54:25 AM
SMART is status OK (from within BMC/UEFI).
I have password protected config backup with me.
Already downloading usb install image.

Where is a good reinstalltion guide documented?
And what kind of configurations are perhaps not backed up by the GUI backup feature?