Recent posts

#1
German - Deutsch / Re: [Gelöst] Unbound-DNS Erw...
Last post by k0ns0l3 - Today at 11:30:50 AM
Ja , Apple Geräte sind vorhanden genau aber wenn ich umstelle 53053 lauft unbound nicht kein Ahnung warum.

Lg k0ns0l3
#2
26.7 Series / Re: PPPoE over an unassigned V...
Last post by fanski - Today at 10:20:32 AM
Hi Franco,

so I tried with 5, 10 and 15 seconds but no success.
I changed this (log message was just for me to be sure where this happens and if it works :) ):

/* wait for functional parent (only the first) */
    $max = 10;
    $i = 0;
    while ($i < $max) {

        sleep(15);
        log_msg("sleeping", LOG_WARNING);
        if (does_interface_exist($ports[0], 'up')) {
            break;
        }
        $i++;
    }

I'm just curious, do you think this could be hardware related? I use an old firewall for my setup. It was for free so for my home config it was good enough.I thought maybe the old hardware is not working properly with the new firmware/something in the modern architecture is causing this issue with my old hardware.

Regards,

Fanski
#3
General Discussion / Re: netgate freebsd performanc...
Last post by franco - Today at 10:01:47 AM
@greelan

Just briefly:

1. GitHub security advisories submissions are open since September 2025. This channel seems to be liked by researchers and yes there is a lot of AI generated content. How do we know? As soon as AI tools learn about a new type of vulnerability pattern 2 to 5 researchers are going to tell you about it independently.

2. GitHub makes CVE assignment as easy as pushing a button "Request CVE". We are guilty of using it.

3. 1. and 2. easily explain the surge of CVEs.

4. CVSS scoring fits an application running on a native Windows integration relatively well. Network-connected security tools where every single page is an access level down to the confiugration database and OS the scoring breaks down because a web GUI is a "remote access" by definition. The privilege system we inherited through shared history is also causing researchers to believe "limited" rights are not "full" admin rights even if you are on a firewall administration page. These things are unfixable and lead to higher scores. We've had a number of arguments about how scores are too high, but CVSS at face value is what it is. If pfSense says they don't have high scores that's quite strange, because everything translates 1:1 to their project. This is a fact of CVSS scoring and our shared project scope.

5. We have a LINCE certification since a number of years now.  Although it's on the back burner now we've also worked on reports via  https://scan.coverity.com/projects/opnsense-core -- but we don't use any AI tools to scan the code base.

6. As an example: https://github.com/opnsense/core/commit/10dd8619aea42 is a direct consequence of unguarded advanced input inherited from pfSense. I highly doubt they fixed it before we published it.

7. As another example: https://github.com/opnsense/core/commit/016f66cb4620 is an inherited bug fixed by them without issuing an advisory or CVE here https://github.com/pfsense/pfsense/commit/f0b0a03bbdca93 (as far as I know)

8. Communication with pfSsense is not possible due to constant bickering and belittlement mentality: https://www.reddit.com/r/PFSENSE/comments/1ottyh3/security_leadership_opnsenses_marketing_hype_vs/ -- It has been since the start. We could have shared reports and helped each other but that's not what the other side wants.

9. We've worked on privilege separation for almost 12 years now. Non-root web GUI option is available since

community/25.7/25.7:o system: allow experimental feature to run web GUI privilege separated as "wwwonly" user

and will likely be the factory default in 27.1:

https://github.com/opnsense/core/commit/63c8df03

10. We've removed mwexec() which was a source of many unguarded shell escapes throughout the inherited code base. This work was also done for more than a decade and finished this year:

community/26.1/26.1.r1:o Shell command escaping improvements and audit

11. Our latest community code is freely available for full third party scrutiny.  :)

12. We're proud of the code, improvements and fixes we've put out. We don't care what anyone but our users think and we're not afraid to make that clear.


Cheers,
Franco
#4
26.7 Series / Re: Unable to Change Tayga Set...
Last post by franco - Today at 09:24:20 AM
#5
26.7 Series / Re: how to recover using an ol...
Last post by PencilHCV - Today at 07:10:30 AM
defaultuserfoo,

I think it's about time you stopped wasting your efforts trying to restore the system and instead performed a fresh installation of OPNsense. Update it to the latest version and reconfigure the firewall rules from scratch.

And don't forget to keep the system up to date and create a backup whenever a new version is released.

Anything else is just a waste of time.

Take it from an IT technician with over 30 years of experience.

Good luck!
#6
Du kannst dir das nicht unbedingt aussuchen. Hast du Apple-Geräte? Dann hast du mDNS.
#7
26.7 Series / Re: how to recover using an ol...
Last post by lmoore - Today at 04:55:24 AM
Quote from: defaultuserfoo on October 10, 2026, 10:41:05 PMIt means that all the rules need to be redone because migrating them doesn't work

It seems you are in the minority of users experiencing the impossibility of migrating firewall and NAT rules.

Perhaps you could invest time working through your issue and find a way to restore your old configuration file and get it working in a way where information already provided has not worked.

Considering the pain this has caused you, and in the interest that another user may some day befall your predicament, you could document the process you used and post it to the list, so they may also benefit from your experience.
#8
General Discussion / 1x NIC + 1x TP‑Link TL‑SG105E ...
Last post by z0rk - Today at 12:29:27 AM
Hi,

Another router on a stick setup question.

I am using Xfinity as my ISP.
I am using OPNsense 26.7

TL-SG108E configuration.

1️⃣ VLAN 10 (WAN/Modem Port)
VLAN ID: 10
Ports:Port 1 → Untagged
Port 5 → Tagged
Ports 2–4 → Not Member

2️⃣ VLAN 20 (LAN‑A, 192.x)
VLAN ID: 20
Ports:Port 2 → Untagged
Port 5 → Tagged
Ports 1, 3, 4 → Not Member

3️⃣ VLAN 30 (LAN‑B, 172.x)
VLAN ID: 30
Ports:Port 3 → Untagged
Port 5 → Tagged
Ports 1, 2, 4 → Not Member

4️⃣ VLAN 40 (LAN‑C, 10.x)
VLAN ID: 40
Ports:Port 4 → Untagged
Port 5 → Tagged
Ports 1–3 → Not Member

5️⃣ PVIDs (Port VLAN IDs)
(see attached)

The modem connects to port 1.
Port 5 connects to PC.

I can ping all subnets. I can access the GUI and SSH. WAN doesn't get an IP address assigned.
WAN is set up to use DHCP for both v4 and v6. All other settings are default.
Initially I left the MAC address blank.
Then I tried setting it to use the MAC address of the physical link, the address of the switch, and a randomly created MAC. I tried these with and without promiscuous mode enabled.
Rebooted the modem/OPNsense in between each setting change as well just for good measure.

No luck at all.

Maybe some wizard can shed some light on this.

Thanks!

---
Edit:
I've tried using the MAC address of my current OPNsense box, set VLAN priority to 6 and 7 respectively, but I am still having the same issue.

tcpdump -ni re0_vlan10 port 67 or port 68
tcpdump: verbose output suppressed, use -v[v]... for full protocol decode
listening on re0_vlan10, link-type EN10MB (Ethernet), snapshot length 262144 bytes
16:29:15.088863 IP 0.0.0.0.68 > 255.255.255.255.67: BOOTP/DHCP, Request from 98:b7:85:1f:be:ad, length 300
16:29:26.118714 IP 0.0.0.0.68 > 255.255.255.255.67: BOOTP/DHCP, Request from 98:b7:85:1f:be:ad, length 300
16:29:48.321257 IP 0.0.0.0.68 > 255.255.255.255.67: BOOTP/DHCP, Request from 98:b7:85:1f:be:ad, length 300
16:29:50.349083 IP 0.0.0.0.68 > 255.255.255.255.67: BOOTP/DHCP, Request from 98:b7:85:1f:be:ad, length 300
16:29:55.381867 IP 0.0.0.0.68 > 255.255.255.255.67: BOOTP/DHCP, Request from 98:b7:85:1f:be:ad, length 300
16:30:09.383068 IP 0.0.0.0.68 > 255.255.255.255.67: BOOTP/DHCP, Request from 98:b7:85:1f:be:ad, length 300
16:30:29.402982 IP 0.0.0.0.68 > 255.255.255.255.67: BOOTP/DHCP, Request from 98:b7:85:1f:be:ad, length 300
16:30:36.421088 IP 0.0.0.0.68 > 255.255.255.255.67: BOOTP/DHCP, Request from 98:b7:85:1f:be:ad, length 300
16:30:48.423105 IP 0.0.0.0.68 > 255.255.255.255.67: BOOTP/DHCP, Request from 98:b7:85:1f:be:ad, length 300
16:31:04.452439 IP 0.0.0.0.68 > 255.255.255.255.67: BOOTP/DHCP, Request from 98:b7:85:1f:be:ad, length 300
16:31:05.516106 IP 0.0.0.0.68 > 255.255.255.255.67: BOOTP/DHCP, Request from 98:b7:85:1f:be:ad, length 300
16:31:07.580611 IP 0.0.0.0.68 > 255.255.255.255.67: BOOTP/DHCP, Request from 98:b7:85:1f:be:ad, length 300
16:31:12.586850 IP 0.0.0.0.68 > 255.255.255.255.67: BOOTP/DHCP, Request from 98:b7:85:1f:be:ad, length 300
16:31:22.670109 IP 0.0.0.0.68 > 255.255.255.255.67: BOOTP/DHCP, Request from 98:b7:85:1f:be:ad, length 300
16:31:33.703175 IP 0.0.0.0.68 > 255.255.255.255.67: BOOTP/DHCP, Request from 98:b7:85:1f:be:ad, length 300
16:31:48.722855 IP 0.0.0.0.68 > 255.255.255.255.67: BOOTP/DHCP, Request from 98:b7:85:1f:be:ad, length 300
16:32:11.326441 IP 0.0.0.0.68 > 255.255.255.255.67: BOOTP/DHCP, Request from 98:b7:85:1f:be:ad, length 300
16:32:16.327227 IP 0.0.0.0.68 > 255.255.255.255.67: BOOTP/DHCP, Request from 98:b7:85:1f:be:ad, length 300
16:32:25.352865 IP 0.0.0.0.68 > 255.255.255.255.67: BOOTP/DHCP, Request from 98:b7:85:1f:be:ad, length 300
^C
19 packets captured
141 packets received by filter
0 packets dropped by kernel
#9
26.7 Series / Re: how to recover using an ol...
Last post by nero355 - October 10, 2026, 11:58:47 PM
Quote from: defaultuserfoo on October 10, 2026, 10:41:05 PMNo. It's not working.

Instead it was made to appear something easy to do.  But it is isn't.

This reminds of the fatal blow Debian struck their users with their stupid brokenarch.  I had been using Debian for about 15 years and then the devs decided to comepletely mess it up, and it was forseeable that the problems would continue to exist in the next release.  So I switched away from Debian.

This is the same crap.  If I knew a good alternative to OPNsense I would switch.
As someone who is using both Debian and OPNsense I totally disagree with you :)

QuoteWe've already had a discussion about the release notes.  The devs refuse to make good release notes.
NOFI but IMHO it's you and not the software...

Maybe try something OpenWRT based or simply buy stuff like TP-Link Omada or Ubiquiti UniFi or HPE Aruba ?!



Good luck! :)
#10
26.7 Series / Re: how to recover using an ol...
Last post by defaultuserfoo - October 10, 2026, 11:22:15 PM
Quote from: defaultuserfoo on October 10, 2026, 10:43:25 PM
Quote from: defaultuserfoo on October 10, 2026, 07:02:17 PM
Quote from: lmoore on October 10, 2026, 04:29:11 AM
Quote from: defaultuserfoo on October 10, 2026, 02:23:16 AMI had only one plugin installed, so I don't expect that any plugin conflicts would need resolving

Referring to page 6, after you powered on the restored system, did you check the 'Status' page and was the 'Resolve plugin conflicts' button there!?

I don't know ...  I'll pay attention to that when I start over.


I've installed the plugin that will be needed and there is no button to resolve plugin conflicts.  I'll check again after importing the old configuration.


There were no conflicts after importing the configuration.  But the plugin (os-maltrail) shows as orphaned.