Recent posts

#1
26.7 Series / Re: OPNsense 26.7.4 - VLAN tra...
Last post by RES217AIII - Today at 06:58:40 AM
Even if my post doesn't help you solve the specific problem, I wanted to write because I'm trying to understand your approach. You never stop learning, and I might get some ideas to rethink my own network design.

As I understand it, you are trying to get the most out of your existing 1G and 2.5G components. However, the current issue following the upgrade is a direct result of software bridging on the OPNsense.
In my opinion, using OPNsense purely as a bridge or Layer 2 switch fails to leverage its capabilities and doesn't align with its intended design.

Using the firewall as an L2 switch to connect these two worlds within the same VLANs creates a highly complex stack involving LACP, VLAN tagging, BSD bridges, and firewall rules.

Even if the problem is resolved, the solution remains fragile, places unnecessary load on the firewall CPU, and introduces extra latency.

To meet your bandwidth requirements, how about considering these solutions instead?

1.  A central 2.5G/10G switch handles all L2 switching in hardware. This offloads the OPNsense, allowing it to connect to the network via a clean trunk.
or
2.  Separating the 2.5G devices into their own subnets at Layer 3. This allows you to use OPNsense exactly as it was designed to be used.

Communication (mDNS, SSDP) between the networks can be ensured using a multicast relay, for example (https://forum.opnsense.org/index.php?topic=52705.0).
#2
26.7 Series / Re: OPNsense 26.7.4 - VLAN tra...
Last post by merrins63 - September 29, 2026, 11:06:34 PM
Quote from: nero355 on September 29, 2026, 03:17:58 PMI have got a question that really bugs me :

Why would you do this =>
Quote from: merrins63 on September 28, 2026, 01:38:52 PMI also have an Intel i226 2.5 GbE trunk, with corresponding VLAN interfaces bridged to the X550/LAGG VLAN interfaces.
Aren't you effectively Bridging 2x 2,5 Gbps with 2 x 10 Gbps ?!

What is the purpose of such a setup ??

The issue I'm trying to solve with this design is mainly about making the best use of the different network speeds available in my home.

I have a traditional 1 GbE wired network, which is perfectly adequate for many of my wired IoT devices. However, my wireless access points and newer switches are capable of 2.5 GbE.

I need my wired and wireless IoT devices to remain on the same VLANs and subnets, while allowing the 2.5 GbE side of the network to make use of the faster interfaces rather than forcing everything through the existing 1 GbE switching infrastructure.

I'm also planning to upgrade my Internet connection to 2000/200 in the next few months, and I already have several multi-gigabit devices that will be able to take advantage of that bandwidth.

Previously, I used the more traditional approach of a single 24-port Gigabit Ethernet switch. However, with affordable 2.5 GbE switches now readily available, I wanted to take advantage of the Cat6A cabling already installed throughout my house.

The important point is that this design isn't intended for redundancy. The objective is to utilise the available 1 GbE and 2.5 GbE links efficiently while keeping devices within their existing VLANs.

Using bridged VLAN interfaces on OPNsense allows me to achieve that design.

Hopefully that explains the reasoning behind my setup a little better.
#3
26.7 Series / Re: OPNsense 26.7.4 - VLAN tra...
Last post by merrins63 - September 29, 2026, 11:05:40 PM
Quote from: Patrick M. Hausen on September 29, 2026, 01:20:12 PMThese definitions match the interface configuration. I am out of ideas ... er ... one moment ...

Did you check this option?



If you did not that would perfectly explain your observed symptoms.

ISC creates the necessary firewall rules for DHCP to work by default, if I remember correctly. For Kea that's optional, because some users complained that OPNsense should not create any rules automatically giving full control to the admin.

Quote from: Patrick M. Hausen on September 29, 2026, 01:20:12 PMThese definitions match the interface configuration. I am out of ideas ... er ... one moment ...

Did you check this option?



If you did not that would perfectly explain your observed symptoms.

ISC creates the necessary firewall rules for DHCP to work by default, if I remember correctly. For Kea that's optional, because some users complained that OPNsense should not create any rules automatically giving full control to the admin.


Yes this setting was already enabled by default. I turned it off, applied the settings then re enabled it

It made no difference and behaviour using Kea DHCP still persists

Cheers
#4
26.7 Series / Re: Android IPv6 issues: In my...
Last post by astronaut - September 29, 2026, 10:11:14 PM
QuoteSome of those things can run alternative software like :
- UBPorts Ubuntu Touch
- Jolla SailFish
- PostmarketOS

Maybe IPv6 works a lot better in one of those ?! :)

My tinkering time budget is already allocated to other things, therefore I am currently not considering switching to any of these.

Beyond that, I expect that when I use one of those alternative OSs, I might end up with a perfectly running IPv6 network, but with not much to use it for (except a browser, perhaps.) I do make use of more or less well designed apps on my smartphone, and I assume that the majority of apps is not available on these OSs. Or is my assumption wrong?

Anyway, thanks for the advice. :-)
#5
26.7 Series / Re: Connections suddenly block...
Last post by BoerBart - September 29, 2026, 08:33:36 PM
Quote from: nero355 on September 29, 2026, 07:08:11 PMPost your network setup and all the Firewall Rules for the LAN Interface.

Is the Mini PC a Single NIC model or Dual/Quad NIC ?


And in general : The more info you provide, the less guessing we all have to do! ;)

Sure - I'll do my best in providing what's needed; I don't have much experience networking-wise, so it's a bit of guessing what is needed.

Network setup
Modem of provider --> TP-Link archer AX50 (bridge mode) --> TP-Link TL-SG108E switch --> single NIC Mini PC.

Switch port layout
Port 1 is TP-Link archer AX50
Port 2 is Single NIC Mini PC #1
Port 2 is Single NIC Mini PC #2

Switch VLAN (802.1Q) configuration
VLAN ID     VLAN Name     Member Ports     Tagged Ports     Untagged Ports
1     Default     1-8    1-8   
5     Redacted    2-3    2-3       
10    Redacted    2-3    2-3       
15    Redacted    2-3    2-3       
20    Redacted    2-3    2-3       
25    Redacted    2-3    2-3       
30    Redacted    2-3    2-3       
50    Redacted    2-3    2-3       
80    Redacted    2-3    2-3       
101   Redacted    2-3    2-3       
110   Redacted    2-3    2-3       
111   Redacted    2-3    2-3       

All firewall rules that are either directly on the LAN interface, or the rule itself contains multiple interfaces, including LAN, are exported to a csv file that can be downloaded here:
https://filebin.net/aer3hx75u8wj72il

If more information is needed - happy to deliver more. I've restarted all devices/networking equipment earlier today without luck.
#6
26.7 Series / Re: Connections suddenly block...
Last post by nero355 - September 29, 2026, 07:08:11 PM
Post your network setup and all the Firewall Rules for the LAN Interface.

Is the Mini PC a Single NIC model or Dual/Quad NIC ?


And in general : The more info you provide, the less guessing we all have to do! ;)
#7
26.7 Series / Re: Android IPv6 issues: In my...
Last post by nero355 - September 29, 2026, 07:00:02 PM
Quote from: astronaut on September 29, 2026, 05:49:25 PMMy Android device is a Fairphone 6.
Some of those things can run alternative software like :
- UBPorts Ubuntu Touch
- Jolla SailFish
- PostmarketOS

Maybe IPv6 works a lot better in one of those ?! :)
#8
Dutch - Nederlands / Re: Chromebook van school op t...
Last post by nero355 - September 29, 2026, 06:56:30 PM
Tja, DoT/DoH is altijd ellende...

Ik ken die dingen niet echt, maar ik weet wel dat op het moment dat je zegt dat ze van een School/Bedrijf zijn dat je kans hebt dat ze aan een of andere "Beheerserver" vast zitten en je dus 'User vs. Admin/Root rechten' problemen kan verwachten.

Heeft dat ding iets van een Console/Terminal waarmee je wat dingen kan checken ?!
- Ping op IP
- Ping of Domeinnaam
- Hetzelfde met Traceroute
- En eventueel nog wat nslookup/dig/drill dingetjes...
#9
German - Deutsch / Re: OPNcentral hält sich nicht...
Last post by Stephan M. - September 29, 2026, 06:17:47 PM
Nach Tagen der Fehlersuche lag es dann schlicht und ergreifend an den Anführungszeichen.
Also hier für Alle, die zukünftig auf das Problem stoßen!


Korrekt funktioniert folgendes: no_proxy=10.0.0.0/8,172.16.0.0/12,192.168.0.0/16,.unseredomain.de


Im OPNcentral muss es wie folgt konfiguriert werden:

# /usr/local/opnsense/service/conf/configd.conf.d/proxy.conf
[environment]
HTTP_PROXY=http://10.19.241.33:3128
HTTPS_PROXY=http://10.19.241.33:3128
http_proxy=http://10.19.241.33:3128
https_proxy=http://10.19.241.33:3128
FTP_PROXY=http://10.19.241.33:3128
ftp_proxy=http://10.19.241.33:3128
NO_PROXY=10.0.0.0/8,172.16.0.0/12,192.168.0.0/16,.unseredomain.de
no_proxy=10.0.0.0/8,172.16.0.0/12,192.168.0.0/16,.unseredomain.de


Beste Grüße und viel Erfolg!
#10
26.7 Series / Connections suddenly blocked o...
Last post by BoerBart - September 29, 2026, 06:09:25 PM
I've been using OPNsense for about two years now, never had any issue, until a few days back. I've set up a few VLANs in OPNsense that are all functioning properly, but I'm having issues on the LAN interface since recently. My idea is that the issue started either because of:

- An OPNsense update;
- Using the rule migration tool.

OPNsense version: 26.7.4_1
Architecture: amd64
Updated on: Sun Sep 20 15:14:10 UTC 2026

I'm running two Peladn N95 nodes in Proxmox, both are fully up-to-date as well.
Firmware version of the Peladn network devices: rtl8168h-2_0.0.2 02/26/15

The two peladn nodes, my PC, phone and such are all on the same LAN interface. OPNsense is running on a VM in the Proxmox cluster, i've got quite a few other containers/VMs running, each in several VLANs. Two days ago (after running the migration tool), I noticed that the internet on my phone got spotty, and today i've noticed it on my PC. When looking at the firewall logs, I noticed that (randomly to me) connections are being dropped, though not all. A page or Whatsapp message sometimes loads/gets delivered, and the next time it keeps loading/sending. Here are the output details for one of them of the Live View:
 
__timestamp__ 2026-09-29T15:48:11
ack 3901492930
action [block]
anchorname
datalen 39
dir [in]
dst 34.54.185.247
dsthostname
dstport 443
ecn
id 13033
interface vtnet0
ipflags DF
ipversion 4
label Default deny / state violation rule
length 91
offset 0
protoname tcp
protonum 6
reason match
rid 02f4bab031b57d1e30553ce08e0ec131
rulenr 13
seq 3881579953:3881579992
src 192.168.1.225
srchostname
srcport 40708
status 2
subrulenr
tcpflags PA
tcpopts
tos 0x0
ttl 64
urp 63

When looking at Firewall -> Diagnostics -> Statistics -> Rules, my assumption that this is rule 13:
@13 block drop in log inet all label "02f4bab031b57d1e30553ce08e0ec131"

    15
    :
     
    59
    :
     25 2026
    evaluations
    :
     11538
    packets
    :
     1700
    bytes
    :
     171359
    states
    :
     0
    nodes
    :
     0
    limit
    :
     0
    nat/rdr
    :
     0
    route
    :
     0
    inserted
    :
     uid 0 pid 0
    state_creations
    :
     0
    time
    :
     tue sep 29

This issue only happens on the LAN interface, all other interfaces are running just fine. I can't seem to figure out what I can do to solve this. I do not have any other rules that block traffic on the LAN interface.