Recent posts

#1
26.7 Series / Re: Unbound stopps suddenly
Last post by notspam - September 08, 2026, 11:36:36 PM
Perhaps a new approach for dns filter lists in unbound:

Here is the breakdown of how AVM optimized the native DNS filter lists introduced in FRITZ!OS 8.40 / 8.50 to minimize RAM and CPU impact.
------------------------------
## 1. RAM Optimization (Memory Efficiency)

* Highly Compressed Data Structures: AVM does not store the imported text files as raw strings. Instead, during the import process, the FRITZ!Box parses and compiles the domains into highly efficient data structures (likely optimized Tries or compressed Bloom Filters). This reduces the memory footprint to a fraction of the raw file size.
* Low Footprint for Millions of Domains: Real-world testing by the community shows that importing heavy lists like HaGeZi Multi PRO combined with TIF (Malware)—totaling around 2.3 million blocked domains—only increases the RAM usage of an older FRITZ!Box 7590 (which only has 512 MB RAM) by a moderate 5% to 10%. There remains plenty of headroom on all supported models.
* No External Storage Required: Unlike early community speculations, you do not need to connect a USB drive or utilize the internal NAS storage to handle large blocklists. The RAM management handles everything internally.

## 2. CPU and Performance Optimization

* Algorithmic Complexity (O(1) / O(log n)): Thanks to the specialized search trees mentioned above, lookup times are mathematically decoupled from the list's size. Whether a list contains 10,000 or 2.5 million entries, the time it takes to check a domain remains nearly identical. The router never performs a slow sequential string search.
* The "Paradoxical" CPU Relief: User reports from the FRITZ! Labor beta phase revealed that the overall CPU load often decreases during normal web browsing when the filter is active.
* Why this happens: When tracking, advertising, or malware domains are instantly blocked at the DNS stage, the FRITZ!Box never has to establish those TCP/UDP connections, route the packets, or handle Network Address Translation (NAT) for them. Less junk traffic means less work for the CPU.
* Integration with Packet Acceleration: The DNS filtering engine is deeply integrated into FRITZ!OS and operates in tandem with AVM's hardware-level routing accelerators. This ensures that filtering does not bottleneck your overall internet throughput.

In short, AVM has successfully implemented this feature directly into the core of their lightweight Linux-based firmware, making it significantly more resource-efficient than running a heavy Docker container or Pi-hole on an external device.

#2
Zenarmor (Sensei) / Re: Cancelling my subscription...
Last post by abenaou - September 08, 2026, 10:17:09 PM
I agree with most of what was said in this thread, the other thing I feel very limiting is the number of policies, having just 5 policies can become a serious limitation for the home licence subscribers.

I wish other database back ends were considered, obviously the developers have their own reasons, but I feel between elastic and sqlite the choices are restrictive as both could wear out the disk while having an external mariadb handling the database aspect would make things more flexible.

Anyway, this is unrelated to the first post but thought giving some feedback can help improve the product.
#3
26.7 Series / Re: Firewall can't access serv...
Last post by viragomann - September 08, 2026, 10:10:17 PM
Quote from: creatronics on September 08, 2026, 08:16:26 PMA NAT rule redirects all traffic to WAN 80 and 443 to ´the loopback address.
So port forwarding is in play here. But this rule might be defined on the WAN or LAN interface and hence only affect traffic entering there.

I guess, there is mo possibility to forward traffic coming from the firewall itself (localhost). Don't know. But maybe it works if you enable NAT reflection in the rule.

Otherwise, is there a real need to have HAproxy listening on loopback?
I have it just on WAN and acess it from inside networks as well.
#4
Hardware and Performance / Re: Power loss recovery on Pro...
Last post by pfry - September 08, 2026, 09:29:09 PM
Quote from: Nullman on September 08, 2026, 02:05:29 PM[...]Modern motherboards show no signs of life if the battery goes below 2.5V.[...]

I haven't had a problem with mine (a few Asrock, Asus, Gigabyte, and Supermicro boards). I've noticed that most eat batteries when powered off (5 year life at best), and one Asrock Rack board eats them in no time (perhaps a year). It boots fine, though - the only obvious symptom is the time (it has few meaningful configuration options).

I wish the bloody things used flash for configuration (active as opposed to backup, and some of mine are old enough to lack even that). A (convenient, supported) bigger battery option would be nice, too (e.g. 2 AA). Oh, context: I like to use systems for 10+ years these days. Advances in compute just aren't as exciting as they were 25+ years ago.
#5
General Discussion / Re: Trying to block an alias g...
Last post by tangofan - September 08, 2026, 09:06:27 PM
Quote from: The Crazy Squirrel on September 07, 2026, 11:14:26 PMI don't know why, but now it's working.  I didn't change anything from my original post.
Was it time?  Was it a cache?  I have no idea.

What might have happened is that the state for internet access was still active in the firewall state table. You can clear individual states under Firewall -> Diagnostics -> States and under the "Actions" tab you can also reset the whole state table.
#6
Zenarmor (Sensei) / Re: Very high SSD writes with ...
Last post by bodenlos - September 08, 2026, 08:57:50 PM
Thanks for sharing your findings. I can add some further real-world data points that seem to support the same pattern:

I am seeing the same behaviour on three additional production systems with essentially the same system design. The absolute write volumes differ somewhat, but the result is consistent: when the Zenarmor engine is running, SSD host writes increase by approximately 4–5x compared with the baseline without Zenarmor.

Based on the measured write rates and the respective SSD endurance ratings (TBW), the specified endurances would be reached after approximately 2–4 years of operation, depending on the SSD and system.

For comparison, on my own system with the 320 TBW rating of my Kingston NV3, that corresponds to roughly 9.1 years at the baseline write rate, compared with only 2.3 years with Zenarmor enabled. (TBH: are endurance projections, not predictions of actual SSD failure.)
What makes this particularly concerning is that these are Proxmox hosts running several other servers and services, which already generate a substantial amount of disk I/O. Nevertheless, the additional write load associated with Zenarmor exceeds the combined baseline workload by several times. Essentially for the purpose of persisting reporting and connection metadata!

At this point, the consistency across multiple systems makes me strongly suspect a fundamental design or implementation issue in how much data Zenarmor writes and how those writes are performed. Whether the main contributor is the record volume, SQLite WAL/checkpointing, cleanup operations, write amplification, or a combination of these still needs to be investigated. But the resulting sustained write load seems difficult to justify for a reporting feature, particularly on appliances with limited SSD endurance.

I would therefore really like to see Zenarmor investigate the root cause and provide a technical explanation and mitigation for the local reporting backend. Ideally, there should also be an option to disable persistent reporting entirely while keeping the filtering/security engine active, for users who do not need historical reporting data.
#7
26.7 Series / Re: Some SSL certificate help ...
Last post by Ed V. - September 08, 2026, 08:26:03 PM
@fornax

That's exactly what I'm trying to do.

Replace the existing (now expired) SSL certificate with a new /renewed certificate from a Publicly Available CA.

The CA's I've attempted are:

CACert (my usual CA)
SSL.com (a fairly well-known CA)
DigiCert (the "granddaddy" CA, only surpassed by Verisign)
LetsEncrypt (ACME based CA)

In each case, I imported /uploaded the Root CA and Intermediate CA bundles before generating the CSR and uploading the signed certificate.

In all attempts, I get the:

"missing CA key"

error message.

#8
26.7 Series / Firewall can't access servers ...
Last post by creatronics - September 08, 2026, 08:16:26 PM
Hi,
first: thanks to all of you for providing a great forum for OPNsense.
We have an installation with HA setup and HA-proxy up and running. The only ting I just can't get to work, is to get the firewall to access it's own ha proxy and the server bhind it.

ha runs on a loopback ip 127.1.2.3 to make it independend of the WAN and LAN interfaces, which might change on failover.
A NAT rule redirects all traffic to WAN 80 and 443 to ´the loopback address.

everything is working perfectly except one thing: when I try to do a configuration backup on the master to our internal nextcloud server: nothing. Make it the slave and it accesses the Nextcloud via the master and it's working.
No matter what I tried, I just can't get it to work.

doing a curl -vvv on the nextcloud server gives something like this:

connect to 111.222.333.444 port 443 from 111.222.333.444 port 59859 failed: Connection refused

The OS is trying to create a connection from the WAN IP to the WAN IP (which is a pppoe device btw.)

And no matter what, there are no log entries for NAT or firewall rules. HA-proxy is seeing nothing, too.

Any idea which checkbox is missing?

Thank you all,

Michael
#9
Hardware and Performance / Re: Power loss recovery on Pro...
Last post by OPNenthu - September 08, 2026, 07:58:10 PM
Quote from: cottec on September 08, 2026, 02:11:49 PMas my emmc is dead and I'm barely within warranty I might still send it to them

did you try updating the NIC's firmware with the newer build?

I kept the NIC firmware as-is and honestly now with OPNsense 26.7.x I feel even less of a reason to change it.  Things seem to be behaving.

If they're going to ship you a new one anyway you might as well ask them if they can update it.

BTW, you probably saw my note above about setting the date manually in FreeBSD the first time you boot after a battery change / CMOS reset.  Coreboot doesn't let you set the system time unfortunately so until you do it in the OS you'll have problems getting NTP to sync.  FYI.

I agree w/ Nullman, these things do seem to go through batteries faster than the typical PC/laptops I'm used to.  However, I think the first production units (the "v1" if you will) did have some issue.
#10
Zenarmor (Sensei) / Re: Very high SSD writes with ...
Last post by RamSense - September 08, 2026, 07:33:09 PM
I can add another real-world data point to this.

I have been investigating unexpectedly high SSD wear on a Deciso DEC850v2 running OPNsense with Zenarmor and the local SQLite reporting backend. The original SSD became heavily worn after roughly two years of operation and I have now had to replace it.

My network is not particularly large: around 40 active devices in a normal home/family environment.

I opened a support case with Zenarmor on August 21 and supplied them with the measurements and logs I had collected. During that investigation, Zenarmor support confirmed that around 45 session records per second for approximately 40 devices is considered normal, and also explained that a single website visit can generate another 10–15 records because connections/sessions and DNS requests are recorded for reporting.

The preserved IPDR logs from my old installation show continuous activity in conn_all.sqlite, together with periodic cleanup/incremental-vacuum operations. The database was operating in SQLite WAL mode. Unfortunately, I did not record the instantaneous size of conn_all.sqlite-wal before the old SSD was removed, which Zenarmor support has subsequently asked about.

I am not claiming that Zenarmor alone has been conclusively proven to have caused the SSD failure. However, it is a very serious suspected contributor. The important point for me is that the high record rate is apparently considered normal Zenarmor workload, rather than the result of some abnormal client on my network.

Since replacing the SSD, I rebuilt OPNsense without reinstalling Zenarmor. So far, the excessive SSD write behaviour that triggered this investigation has not returned. In other words, removing Zenarmor from the new installation has, at least for now, clearly removed the abnormal write-load problem we were seeing.

Because of that, I currently have no intention of reinstalling Zenarmor until there is a convincing technical explanation or solution for the local write behaviour.

At this point I have also not received any reimbursement for the SSD that had to be replaced, nor have I received a concrete technical fix or mitigation from Zenarmor. The case is still open and I am still waiting for a substantive response from their technical/development team.

Their suggested workaround has been remote Elasticsearch, but to me that does not fully answer the underlying question: why does the normal local Zenarmor reporting workload generate enough sustained write activity that SSD endurance becomes a concern on an official Deciso appliance?

I have retained the old IPDR logs, SSD wear data and other evidence. I would therefore be very interested in further measurements from others in this thread, especially controlled Zenarmor ON/OFF comparisons and findings around SQLite WAL/checkpointing, cleanup and write amplification.

Your A/B measurements are particularly interesting because they seem consistent with the direction of what I observed, although my measurements were collected differently.