Recent posts

#1
26.7 Series / Re: PPPOE Connection Keep drop...
Last post by nicholaswkc - Today at 05:56:21 AM
Quote from: Patrick M. Hausen on October 06, 2026, 10:51:03 AMYou wrote you had it up and running? Now you say it's been down since day one? What is it?

Since day 1, the PPPOE connection is keep connect and disconnect. I still can browse youtube but cannot connect in Real Time application like stock trading.
#2
26.7 Series / Re: how to recover using an ol...
Last post by defaultuserfoo - Today at 05:21:05 AM
Thanks!  I didn't realise that the mirror list also has the old versions.

I'm not sure if the old disk is still readable.  One has failed and the other one can't be booted from.  It would be great if I could read the current configuration from the disk, but that is very difficult because the file system on it is ZFS.

Is the current configuration even stored on the disk or can it only be gathered and exported by a running instance?

It sucks that we can't automatically store the config on an ftp server or send it by email at least once daily when it has been changed.  If that were possible I would have set that up and I'd have the current config now.
#3
Quote from: tyra on Today at 04:04:15 AMТекущий стабильный релиз:

os-xray v3.1.2

---

Репозитории:

Оригинальный проект MrTheory:

https://github.com/MrTheory/os-xray

Наш форк:

https://github.com/SpyLive/os-xray

Спасибо MrTheory за оригинальную разработку и основу проекта.

Дальнейшее развитие форка будет продолжаться с сохранением открытого подхода и обратной совместимости с оригинальной архитектурой os-xray.
обновиться от Оригинальный проект MrTheory: до SpyLive/os-xray можно? или полная переустановка? у меня переключения между Instance через apply не переключает(apply крутится без остановки) останавливаю через ctrl f5 только через индивидуальные боковые старт, стоп включаю выключаю, restart all так же крутится не останавливаясь остановка таже через ctrl f5 .
#4
26.7 Series / Re: how to recover using an ol...
Last post by (MARLOO) - Today at 02:51:07 AM
Open OPNsense Download.             https://opnsense.org/download/

Scroll down to Full mirror listing.

Choose a mirror.

Open the releases/ folder.

Select the required version, for example 25.7/.

Download the image suitable for your system, usually:


OPNsense-25.7-OpenSSL-dvd-amd64.iso.bz2
For an amd64 system, you can use the dvd or vga image. The serial image is intended for systems using a serial console.

You can also access the release archive directly here:

OPNsense release archive               https://pkg.opnsense.org/releases/

--------No, unfortunately the original OPNsense firmware version is usually not stored in config.xml------------

You can only determine the version from external information, such as:

The backup filename or its date.

Old installation media.

System emails, screenshots, or update logs.

The old disk, if it is still readable.

The configuration history stored on the previous installation....
#5
26.7 Series / Re: how to recover using an ol...
Last post by defaultuserfoo - Today at 02:48:03 AM
That's a good idea and I'd have tried that, but I don't have a version that old, only older ones.  I looked at the website and didn't see an archive of old versions so I could download a version of the right age.  Is there one?

The backup is from August of last year.

PS: Oh I found this: https://pkg.opnsense.org/releases/25.7/

I'll try that tomorrow ...

Does it somewhere say in the config from which version it is?  I looked and didn't find that info in the file.
#6
26.7 Series / Re: how to recover using an ol...
Last post by (MARLOO) - Today at 02:31:38 AM
Because the backup is more than a year old, I would suggest:

Install the same OPNsense version that was running before the disk failure.

Restore the configuration and verify the interface assignments.

Check that all required plugins are installed again.

First check the interfaces, then the firewall rules, and test one change at a time.

Keep the original backup untouched and create a new backup before making any major changes.

This way, you can troubleshoot the problem calmly and avoid making several changes at once.
#7
26.7 Series / Re: Wireguard vs. DNS resoluti...
Last post by oc - Today at 01:22:16 AM
First and foremost, my apologies for the late reply. I was finally able to reboot the OPNsense today. It is now updated to 26.7.6

OK, while the condition exists (for recollection, aside from a long boot time because the wireguard service hangs for minutes, wireguard clients connected through the OPNsense don't have DNS resolution until the DNS service is restarted, afterward all works well until the next reboot, and this was linked to having outbound wireguard connections to external hosts with dynamic IPs resolved through URLs - and I've tried with A records with long TTLs rather than the typical 5min offered by dynamic dns - it didn't bring anything - the only (unacceptable) workaround I found to reduce boot time and not trigger the issue was replacing the external wireguard server host names DNS names with their IPs - but I had to revert back to their names, as the IPs can change over time):

root@OC-OPNsense01:~ # ifconfig wg4
wg4: flags=10080c1<UP,RUNNING,NOARP,MULTICAST,LOWER_UP> metric 0 mtu 1420
        description: 127OPNSense_WG_Server (opt15)
        options=180000<LINKSTATE,NETMAP>
        inet 10.127.127.1 netmask 0xffffff00
        groups: wg wireguard
        nd6 options=109<PERFORMNUD,IFDISABLED,NO_DAD>
root@OC-OPNsense01:~ #

root@OC-OPNsense01:~ # wg show wg4
interface: wg4
  public key: *************************************=
  private key: (hidden)
  listening port: 51***

peer: *************************************==
  preshared key: (hidden)
  endpoint: *************************************=:49222
  allowed ips: 10.127.127.2/32
  latest handshake: Now
  transfer: 929.85 KiB received, 10.81 KiB sent
  persistent keepalive: every 25 seconds

peer: *************************************==
  preshared key: (hidden)
  allowed ips: 10.127.127.4/32
  transfer: 0 B received, 11.42 KiB sent
  persistent keepalive: every 25 seconds

peer: *************************************==
  preshared key: (hidden)
  allowed ips: 10.127.127.3/32
  transfer: 0 B received, 11.56 KiB sent
  persistent keepalive: every 25 seconds

peer: *************************************==
  preshared key: (hidden)
  allowed ips: 10.127.127.6/32
  transfer: 0 B received, 11.56 KiB sent
  persistent keepalive: every 25 seconds

peer: *************************************==
  preshared key: (hidden)
  allowed ips: 10.127.127.7/32
  transfer: 0 B received, 11.56 KiB sent
  persistent keepalive: every 25 seconds

peer: *************************************==
  preshared key: (hidden)
  allowed ips: 10.127.127.8/32
  transfer: 0 B received, 11.56 KiB sent
  persistent keepalive: every 25 seconds

peer: *************************************==
  preshared key: (hidden)
  allowed ips: 10.127.127.5/32
  transfer: 0 B received, 11.56 KiB sent
  persistent keepalive: every 25 seconds
root@OC-OPNsense01:~ #

root@OC-OPNsense01:~ # netstat -rn -f inet
Routing tables

Internet:
Destination        Gateway            Flags         Netif Expire
default            **********.1       UGS            igb3
1.1.1.1            **********.1       UGHS           igb3
10.6.0.1           link#11            UHS             wg0
10.6.0.5           link#6             UH              lo0
10.10.112.0/24     link#5             U               re0
10.10.112.112      link#6             UHS             lo0
10.14.0.0/16       link#12            U               wg2
10.14.0.1          link#12            UHS             wg2
10.14.0.2          link#6             UHS             lo0
10.127.2.0/24      link#14            U            vlan02
10.127.2.1         link#6             UHS             lo0
10.127.3.0/24      link#15            U            vlan03
10.127.3.1         link#6             UHS             lo0
10.127.4.0/24      link#16            U            vlan04
10.127.4.1         link#6             UHS             lo0
10.127.7.0/24      link#18            U            vlan07
10.127.7.1         link#6             UHS             lo0
10.127.11.0/24     link#19            U           vlan011
10.127.11.1        link#6             UHS             lo0
10.127.12.0/24     link#20            U           vlan012
10.127.12.1        link#6             UHS             lo0
10.127.60.0/24     link#2             U              igb1
10.127.60.1        link#6             UHS             lo0
10.127.127.0/24    link#10            U               wg4
10.127.127.1       link#6             UHS             lo0
**********.      192.168.60.1       UGHS           igb2
127.0.0.1          link#6             UH              lo0
**********.     **********.       UGHS           igb3
**********.     **********.       UGHS           igb3
**********.    10.14.0.1          UGHS            wg2
192.168.6.0/24     10.6.0.1           UGS             wg0
192.168.8.0/24     192.168.60.1       UGS            igb2
192.168.8.8        192.168.60.1       UGHS           igb2
192.168.60.0/24    link#17            U            vlan06
192.168.60.6       link#6             UHS             lo0
192.168.60.166     link#6             UHS             lo0
**********      10.14.0.3          UGHS            wg2
**********./23    link#4             U              igb3
**********.     link#6             UHS             lo0
root@OC-OPNsense01:~ #

also while the condition persists:

root@OC-OPNsense01:~ # tcpdump -ni wg4 port 53
tcpdump: verbose output suppressed, use -v[v]... for full protocol decode
listening on wg4, link-type NULL (BSD loopback), snapshot length 262144 bytes
15:54:37.102597 IP 10.127.127.2.49847 > 10.127.127.1.53: 2782+ A? app-analytics-services.com. (44)
15:54:37.115132 IP 10.127.127.1.53 > 10.127.127.2.49847: 2782 6/0/0 A 192.179.26.138, A 192.179.26.139, A 192.179.26.100, A 192.179.26.102, A 192.179.26.101, A 192.179.26.113 (140)
15:54:37.176938 IP 10.127.127.2.57407 > 10.127.127.1.53: 8073+ A? mtalk.google.com. (34)
15:54:37.178119 IP 10.127.127.1.53 > 10.127.127.2.57407: 8073 2/0/0 CNAME mobile-gtalk.l.google.com., A 142.250.99.188 (79)
15:54:37.181977 IP 10.127.127.2.59601 > 10.127.127.1.53: 31715+ HTTPS? oauthaccountmanager.googleapis.com. (52)
15:54:37.187173 IP 10.127.127.2.61051 > 10.127.127.1.53: 3209+ A? oauthaccountmanager.googleapis.com. (52)
15:54:37.188306 IP 10.127.127.1.53 > 10.127.127.2.61051: 3209 8/0/0 A 172.217.114.4, A 172.217.119.4, A 172.217.116.4, A 172.217.112.4, A 172.217.117.4, A 172.217.113.4, A 172.217.118.4, A 172.217.115.4 (180)
15:54:37.194013 IP 10.127.127.1.53 > 10.127.127.2.59601: 31715 0/1/0 (109)
15:54:40.701918 IP 10.127.127.2.54830 > 10.127.127.1.53: 53225+ HTTPS? whatismyipaddress.com. (39)
15:54:40.704719 IP 10.127.127.1.53 > 10.127.127.2.54830: 53225 1/0/0 HTTPS (112)
15:54:40.707118 IP 10.127.127.2.51708 > 10.127.127.1.53: 59126+ A? whatismyipaddress.com. (39)
15:54:40.709549 IP 10.127.127.1.53 > 10.127.127.2.51708: 59126 2/0/0 A 104.19.223.79, A 104.19.222.79 (71)
15:54:41.677629 IP 10.127.127.2.56885 > 10.127.127.1.53: 54150+ A? safebrowsing.google.com. (41)
15:54:41.712736 IP 10.127.127.1.53 > 10.127.127.2.56885: 54150 5/0/0 CNAME sb.l.google.com., A 142.251.121.91, A 142.251.121.93, A 142.251.121.190, A 142.251.121.136 (124)

and after restarting the inbound wireguard service assosciated with wg4:

root@OC-OPNsense01:~ # ifconfig wg4
wg4: flags=10080c1<UP,RUNNING,NOARP,MULTICAST,LOWER_UP> metric 0 mtu 1420
        description: 127OPNSense_WG_Server (opt15)
        options=80000<LINKSTATE>
        inet 10.127.127.1 netmask 0xffffff00
        groups: wg wireguard
        nd6 options=109<PERFORMNUD,IFDISABLED,NO_DAD>
root@OC-OPNsense01:~ #

root@OC-OPNsense01:~ # wg show wg4
interface: wg4
  public key: ***********************************=
  private key: (hidden)
  listening port: 51***

peer: ***********************************==
  preshared key: (hidden)
  allowed ips: 10.127.127.5/32
  transfer: 0 B received, 1.30 KiB sent
  persistent keepalive: every 25 seconds

peer: ***********************************==
  preshared key: (hidden)
  allowed ips: 10.127.127.2/32
  transfer: 0 B received, 1.30 KiB sent
  persistent keepalive: every 25 seconds

peer: ***********************************=
  preshared key: (hidden)
  allowed ips: 10.127.127.4/32
  transfer: 0 B received, 1.30 KiB sent
  persistent keepalive: every 25 seconds

peer: ***********************************=
  preshared key: (hidden)
  allowed ips: 10.127.127.3/32
  transfer: 0 B received, 1.30 KiB sent
  persistent keepalive: every 25 seconds

peer: ***********************************=
  preshared key: (hidden)
  allowed ips: 10.127.127.6/32
  transfer: 0 B received, 1.30 KiB sent
  persistent keepalive: every 25 seconds

peer: ***********************************=
  preshared key: (hidden)
  allowed ips: 10.127.127.7/32
  transfer: 0 B received, 1.30 KiB sent
  persistent keepalive: every 25 seconds

peer: ***********************************=
  preshared key: (hidden)
  allowed ips: 10.127.127.8/32
  transfer: 0 B received, 1.30 KiB sent
  persistent keepalive: every 25 seconds
root@OC-OPNsense01:~ #

root@OC-OPNsense01:~ # netstat -rn -f inet
Routing tables

Internet:
Destination        Gateway            Flags         Netif Expire
default            **********.1       UGS            igb3
1.1.1.1            **********.1       UGHS           igb3
10.6.0.1           link#11            UHS             wg0
10.6.0.5           link#6             UH              lo0
10.10.112.0/24     link#5             U               re0
10.10.112.112      link#6             UHS             lo0
10.14.0.0/16       link#12            U               wg2
10.14.0.1          link#12            UHS             wg2
10.14.0.2          link#6             UHS             lo0
10.127.2.0/24      link#14            U            vlan02
10.127.2.1         link#6             UHS             lo0
10.127.3.0/24      link#15            U            vlan03
10.127.3.1         link#6             UHS             lo0
10.127.4.0/24      link#16            U            vlan04
10.127.4.1         link#6             UHS             lo0
10.127.7.0/24      link#18            U            vlan07
10.127.7.1         link#6             UHS             lo0
10.127.11.0/24     link#19            U           vlan011
10.127.11.1        link#6             UHS             lo0
10.127.12.0/24     link#20            U           vlan012
10.127.12.1        link#6             UHS             lo0
10.127.60.0/24     link#2             U              igb1
10.127.60.1        link#6             UHS             lo0
10.127.127.0/24    link#10            U               wg4
10.127.127.1       link#6             UHS             lo0
**********.      192.168.60.1       UGHS           igb2
127.0.0.1          link#6             UH              lo0
**********.     **********.       UGHS           igb3
**********.     **********.       UGHS           igb3
**********.    10.14.0.1          UGHS            wg2
192.168.6.0/24     10.6.0.1           UGS             wg0
192.168.8.0/24     192.168.60.1       UGS            igb2
192.168.8.8        192.168.60.1       UGHS           igb2
192.168.60.0/24    link#17            U            vlan06
192.168.60.6       link#6             UHS             lo0
192.168.60.166     link#6             UHS             lo0
**********.   10.14.0.3          UGHS            wg2
**********.    link#4             U              igb3
**********.    link#6             UHS             lo0
root@OC-OPNsense01:~ #

root@OC-OPNsense01:~ # tcpdump -ni wg4 port 53
tcpdump: verbose output suppressed, use -v[v]... for full protocol decode
listening on wg4, link-type NULL (BSD loopback), snapshot length 262144 bytes
16:00:36.087124 IP 10.127.127.2.64118 > 10.127.127.1.53: 5792+ A? clientservices.googleapis.com. (47)
16:00:36.087366 IP 10.127.127.1.53 > 10.127.127.2.64118: 5792 1/0/0 A 142.251.45.142 (63)
16:00:36.131512 IP 10.127.127.2.57188 > 10.127.127.1.53: 37694+ HTTPS? oauth2.googleapis.com. (39)
16:00:36.131542 IP 10.127.127.2.59348 > 10.127.127.1.53: 17623+ A? oauth2.googleapis.com. (39)
16:00:36.132579 IP 10.127.127.2.57722 > 10.127.127.1.53: 22940+ HTTPS? oauthaccountmanager.googleapis.com. (52)
16:00:36.143661 IP 10.127.127.1.53 > 10.127.127.2.59348: 17623 1/0/0 A 173.194.43.95 (55)
16:00:36.155291 IP 10.127.127.1.53 > 10.127.127.2.57188: 37694 0/1/0 (96)
16:00:36.169684 IP 10.127.127.1.53 > 10.127.127.2.57722: 22940 0/1/0 (109)
16:00:36.297808 IP 10.127.127.2.56151 > 10.127.127.1.53: 28843+ HTTPS? whatismyipaddress.com. (39)
16:00:36.301613 IP 10.127.127.2.49337 > 10.127.127.1.53: 12610+ A? whatismyipaddress.com. (39)
16:00:36.302416 IP 10.127.127.1.53 > 10.127.127.2.56151: 28843 1/0/0 HTTPS (112)
16:00:36.304267 IP 10.127.127.1.53 > 10.127.127.2.49337: 12610 2/0/0 A 104.19.223.79, A 104.19.222.79 (71)
16:00:36.402933 IP 10.127.127.2.49214 > 10.127.127.1.53: 3553+ A? mtalk.google.com. (34)
16:00:36.416478 IP 10.127.127.2.49813 > 10.127.127.1.53: 7412+ HTTPS? accounts.google.com. (37)
16:00:36.421684 IP 10.127.127.2.65452 > 10.127.127.1.53: 1891+ A? accounts.google.com. (37)
16:00:36.422557 IP 10.127.127.2.54808 > 10.127.127.1.53: 57995+ A? android.clients.google.com. (44)
16:00:36.422611 IP 10.127.127.2.61247 > 10.127.127.1.53: 44304+ A? optimizationguide-pa.googleapis.com. (53)
16:00:36.433098 IP 10.127.127.1.53 > 10.127.127.2.61247: 44304 8/0/0 A 172.217.115.4, A 172.217.114.4, A 172.217.112.4, A 172.217.119.4, A 172.217.116.4, A 172.217.118.4, A 172.217.117.4, A 172.217.113.4 (181)
16:00:36.433182 IP 10.127.127.1.53 > 10.127.127.2.65452: 1891 1/0/0 A 192.179.26.84 (53)
16:00:36.437620 IP 10.127.127.2.63627 > 10.127.127.1.53: 14093+ A? safebrowsing.google.com. (41)
16:00:36.463892 IP 10.127.127.1.53 > 10.127.127.2.49813: 7412 0/1/0 (87)
16:00:36.484631 IP 10.127.127.1.53 > 10.127.127.2.49214: 3553 2/0/0 CNAME mobile-gtalk.l.google.com., A 192.178.163.188 (79)
16:00:36.495860 IP 10.127.127.1.53 > 10.127.127.2.63627: 14093 5/0/0 CNAME sb.l.google.com., A 172.253.117.136, A 172.253.117.91, A 172.253.117.93, A 172.253.117.190 (124)
16:00:36.504379 IP 10.127.127.1.53 > 10.127.127.2.54808: 57995 17/0/0 CNAME android.l.google.com., A 173.194.203.113, A 192.178.163.101, A 192.178.163.139, A 173.194.43.102, A 173.194.43.138, A 173.194.43.113, A 173.194.43.101, A 173.194.43.139, A 173.194.43.100, A 173.194.202.113, A 173.194.202.102, A 173.194.203.100, A 173.194.203.139, A 173.194.203.101, A 173.194.203.138, A 173.194.203.102 (324)
16:00:36.557426 IP 10.127.127.2.57793 > 10.127.127.1.53: 4819+ A? map1.whatismyipaddress.com. (44)
16:00:36.557442 IP 10.127.127.2.53819 > 10.127.127.1.53: 21823+ A? cmp.inmobi.com. (32)
16:00:36.557448 IP 10.127.127.2.61382 > 10.127.127.1.53: 24745+ A? a.pub.network. (31)
16:00:36.557454 IP 10.127.127.2.62172 > 10.127.127.1.53: 47220+ A? www.googletagmanager.com. (42)
16:00:36.557459 IP 10.127.127.2.62954 > 10.127.127.1.53: 13340+ HTTPS? ds6.probe.whatismyipaddress.com. (49)
16:00:36.559827 IP 10.127.127.1.53 > 10.127.127.2.57793: 4819 2/0/0 A 104.19.222.79, A 104.19.223.79 (76)
16:00:36.561446 IP 10.127.127.2.54688 > 10.127.127.1.53: 32486+ A? ds6.probe.whatismyipaddress.com. (49)
16:00:36.565763 IP 10.127.127.1.53 > 10.127.127.2.62954: 13340 0/1/0 (108)
16:00:36.567314 IP 10.127.127.1.53 > 10.127.127.2.54688: 32486 0/1/0 (108)
16:00:36.577499 IP 10.127.127.2.55008 > 10.127.127.1.53: 54460+ HTTPS? a.pub.network. (31)
16:00:36.581438 IP 10.127.127.2.63439 > 10.127.127.1.53: 16517+ HTTPS? app.fusebox.fm. (32)

NOTE: I anonymized some of the public IPs, ports, and keys. If any of that is necessary for troubleshooting, please let me know and I'll provide it.

Thanks again for looking at this!
#8
26.7 Series / Re: Intel E810 fails to link o...
Last post by homelabber - Today at 01:09:17 AM
Update to 26.7.6 fixed it for me, DDP is working fine. No more safe mode :)
I did have to add a tunable for it to work properly with init7:
  • dev.ice.0.requested_fec
  • Value: FC-FEC/BASE-R
#9
26.7 Series / how to recover using an old co...
Last post by defaultuserfoo - Today at 12:50:12 AM
Hi,

so the storage medium of the router failed because one of the disks of the RAID1 failed and the other disk was removed while the system was still running.  Now it won't boot anymore.

I put in new disks and installed the current OPNsense version and imported the latest configuration I have which is well over a year old.  The import was successful but the firewall rules are totally messed up and need to be redone.

And I can't edit the firewall rules.  I guess I need to install the plugin for that, but I didn't see it in the list of plugins, and I don't know what it's called.

Is there no way to edit the firewalls rules now?
#10
There's no RS-232 serial port on the Protectli.  It has a USB-C port labeled "COM" which is internally wired to the FTDI UART and can only be used for that purpose:

https://kb.protectli.com/kb/v1000-hardware-overview/

They supply a USB cable with the unit.