Recent posts

#1
26.1, 26,4 Series / Re: With IPv6, how to get both...
Last post by funtowne - Today at 06:38:51 AM
Quote from: Monviech (Cedrik) on July 30, 2026, 11:52:54 AMMaybe dnsmasq can do it. You can configure different RA pools on the same interface with different flags from what I can see.

But I never tested that.

Out of morbid curiosity I set up DNSMASQ with SLAAC as the mode with the IP range of my ULA ffd0::1000 to ffd0::2000 (ULA truncated). I also set up ra-stateless for :: 

Clients only seemed to get the slaac-generated IPs; the dhcpv6 ULA range did not assign a DHCP ULA address in the range above.

Happy to be wrong here in case I did a misconfigure, but manually-entered ranges including a prefix appear to be ignored for the use case of only defining a ULA range for dhcp. ::1000 to ::2000 without the prefix worked as expected, but only for the GUAs.

I'll double check my work and maybe open a bug report if needed, as the info tip for defining IP ranges does show a prefix (if defined on an interface of course) as a valid input for an ip range.
#2
General Discussion / Re: Roku DNS storm is impactin...
Last post by OPNenthu - Today at 04:32:36 AM
Back with an update.

While using the actual devices for a bit, we could maybe tell there was a little bit of random delay in app and video stream startup but it was quite acceptable.  We could have just as well imagined it due to expectation bias.

The Unbound reports are overgrown now and taking long to load due to the tens of millions of accumulated queries, but this includes metrics from before the limiter was added.  I also noticed the 'syslog-ng' service had stopped and needed a restart, which is concerning.

So... partially solved.  I'll manually clear the reporting data if it doesn't rotate out soon and hopefully that will remain at manageable levels going forward.  We'll see.

Appreciate all the tips so far.

---

@yourfriendarmando: thanks for that.  Did you suggest it because there's a link between these two companies?  I wouldn't be surprised but I don't know.

@newsense: that clears it up, thank you.  As for your observation about the constant telemetry, I did notice something interesting when I was going through the Roku privacy settings that I don't recall seeing earlier (must have been added in an update?).

There were two entries in privacy settings: "Automatic Content Recognition (ACR)" and "Content Viewing Disclosure," both which can be unchecked but were enabled.  This allows visual screen scraping and sending off information to 3rd parties and advertisers.  Unfortunately, disabling them did not stop the DNS storm.
#3
You can create a pass rule so it will pass that port and stop processing. Put it above the qfeeds rule.  Once qfeeds resolve the issue you can delete that port rule
#4
26.1, 26,4 Series / Re: SERVFAIL when domain has ...
Last post by NonGough - Today at 12:36:56 AM
Solved.
Thank you SanjivSharma for your suggestion regarding IPv6.

In System: Settings: General -- Networking (did not find anything in Ubound DNS settings),
the "Prefer to use IPv4 even if IPv6 is available" was unchecked.  After a Console Reboot (i.e., 6) Reboot System), the execution of the software worked as expected.  This package's dedicated domain has two IPv4 addresses in the DNS.

1)  I needed to do a OPNsense reboot.   The software package (accessed by a DNS domain) failed to execute until I rebooted.
2)  I needed to change which browser I used to invoke the software package.  Vivaldi failed while Firefox worked.  Exploring whether network related settings and behaviors are different in these two specific browsers may yield interesting insights when OPNsense is the firewall.
3)  The software package does not have IPv6 addresses, but {up.railway.app} does use them.  {up.railway.app} with some browsers does something differently when a domain has no IPv6 addresses registered with OPNsense as the firewall.  A reason to to have several current browsers on hand in case a complicated interaction of API's, browsers, IPv6 vs. Ipv4, and OPNsense!
4)  There was no reason to have the "Prefer to use IPv4 even if IPv6 is available" checked.  It was originally checked when OPNsense became my firewall in order to minimize learning complications for a firewall newbie to just about anything network/Internet.  With IPv6 now in much wider use, there may no reason to ever have this checkbox checked for today's Internet (newbie or not).
5)  A second software package from the same vendor (no IPv6 addresses and with only 1 IPv4 addess) still failed; even though the first software package now works without a workaround.   Requires a workaround executing under Vivaldi with the built-in Proton VPN temporarily enabled.  After the initialization phase, the Protoon VPN is disabled.  Everything works as expected.  This workaround using Vivaldi also works the the original software package I had problems with.  I will launch one software package in Firefox, then use Vivaldi with Proton VPN temporarily enabled to startup the second software package (these two software packages do not like each others company when executing in the same browser it turns out).
6)   Private (incognito) browser sessions may affect this problem, but I have been unable to determine anything specifically.
7)   There may be other browser settings at play, such as caching, javascript (WebAssembly, JIT), browser vs. Unbound DNS blocklists, extensions, local storage, etc. may be at play .

Delighted to have both software packages now working as expected, albeit with a lot of unanswered questions as to exactly why and why they behave differently with different browsers.
#5
Quote from: Patrick M. Hausen on August 09, 2026, 10:00:35 PMThey have a false positive reporting form in your TIP.

Yep, submitted. Just wondered if there was anything worth doing in the meantime. Hopefully it'll be reviewed swiftly.
#6
26.1, 26,4 Series / Re: SERVFAIL when domain has ...
Last post by SanjivSharma - August 09, 2026, 11:03:08 PM
That IPv6-specific error is the big clue here — Unbound trying to reach an IPv6 nameserver for up.railway.app and failing while the direct-to-AT&T-modem path works fine strongly points to broken IPv6 connectivity or DNS resolution specifically inside OPNsense's network, not a blocklist or plugin issue. Worth checking if Unbound has "Prefer IPv4 for outgoing queries" available under Unbound's advanced settings, since forcing it to skip that broken IPv6 path entirely would confirm the theory fast. CrowdSec and the DHCP services are almost certainly red herrings here given the error is happening at the DNS resolution layer itself, pointing straight at Unbound's IPv6 handling.
#7
German - Deutsch / Re: Neues setup - Fragen zur S...
Last post by Patrick M. Hausen - August 09, 2026, 10:27:18 PM
Die Verantwortung für deine Konfiguration liegt bei dir. Du wirst hier keine "semi-offizielle" Abnahme bekommen. Nicht in einem Community-Forum und kostenlos. Ich mache sowas gerne gewerblich über meine Firma.

Just saying.
#8
German - Deutsch / Re: Neues setup - Fragen zur S...
Last post by name89214 - August 09, 2026, 10:15:48 PM
So, ich habe nochmal meine Einstellungen auf Werkseinstellungen zurückgesetzt und neu begonnen.

Zunächst mal bis hier hin meine Basiskonfiguration. Internet auf LAN funktioniert. Das sollte für Telekom VDSL so passen - ansonsten lasst es mich bitte wissen.

QuoteEinstellungen nach Anleitung "IPv6 for generic DSL dialup" https://docs.opnsense.org/manual/how-tos/ipv6_dsl.html

  • System > General > System: Domain = home.arpa
  • Interfaces > LAN > Static IPv4 address = 192.168.1.2/24
  • Interfaces > WAN > Generic configuration: IPv6 Configuration Type = DHCPv6
  • Interfaces > WAN > DHCPv6 client configuration: Request prefix only = check
  • Interfaces > WAN > DHCPv6 client configuration: Send prefix hint = check
  • Interfaces > WAN > DHCPv6 client configuration: Prefix delegation size = 56
  • Interfaces > LAN > Generic configuration: IPv4 Configuration Type = Static IPv4
  • Interfaces > LAN > Generic configuration: IPv6 Configuration Type = Track interface (legacy)
  • Interfaces > LAN > DHCPv6 client configuration: Request prefix only = check
  • Interfaces > LAN > Track IPv6 Interface: Parent interface = WAN
  • Interfaces > LAN > Track IPv6 Interface: Assign prefix ID = 0

Einstellungen nach Anleitung "PPPoE ISP Setup" https://docs.opnsense.org/manual/how-tos/pppoe_isp_setup.html

  • Interfaces > WAN > Generic configuration: IPv4 Configuration Type = DHCP
  • Interfaces > WAN > Generic configuration: IPv4 Configuration Type = None
  • Interfaces > WAN > Generic configuration: IPv6 Configuration Type = DHCPv6
  • Interfaces > WAN > Generic configuration: IPv6 Configuration Type = None
  • Interfaces > Devices > VLAN > add:
    • Device = vlan0.1.7
    • Parent = igb0 (ab:12:...) [WAN] 
    • VLAN tag = 7
    • Description = vlan0.1.7
  • Interfaces > Devices > Point-to-Point > add:
    • Link Type = PPPoE
    • Link interface(s) = vlan0.1.7
    • Description = igb0_vlan_PPPoE 
    • Username = abc
    • Password = 123
  • Interfaces > Assignments: assign Device = pppoe0 (vlan0.1.7)-igb0...
  • Interfaces > igb0_vlan7_PPPoE: Enable = check
  • Interfaces > igb0_vlan7_PPPoE: IPv4 Configuration Type = PPPoE


Ansonsten noch kleinere settings wie beep, theme, ...

Zu
  • Interfaces > WAN > Generic configuration: IPv4 Configuration Type = DHCP None
  • Interfaces > WAN > Generic configuration: IPv6 Configuration Type = DHCPv6 None

In letzterer Anleitung "PPPoE ISP Setup" (https://docs.opnsense.org/manual/how-tos/pppoe_isp_setup.html) sollte man sowohl IPv4 als auch IPv6 config type als None setzen - entgegen der ersten Anleitung "IPv6 for generic DSL dialup" (https://docs.opnsense.org/manual/how-tos/ipv6_dsl.html).

Passt das so?



Die Tage mache ich mich ans Eingemachte wie Firewall, DNS, DHCP etc. und poste dann nochmal ein update. Besten Dank euch schon mal!
#9
They have a false positive reporting form in your TIP.
#10
Hardware and Performance / Re: AX88179B USB NIC: 57 -> 97...
Last post by patient0 - August 09, 2026, 10:00:17 PM
If you want to get it fixed, you report it to upstream FreeBSD, https://bugs.freebsd.org. With a way to reproduce the issue, link to this forum thread, using less words if you can. Not sure how many people read a short story like that.