Recent posts

#1
26.7 Series / Re: 26.7.6: unbound (and syslo...
Last post by mnaim - Today at 01:06:15 PM
Updated to 26.7.6 again.
Run opnsense-update -zkr 26.7.6-hyperv

After 5min it seams ok (older kernel already crashed few processes after 5min)
Will keep eye on it little bit longer.
#2
26.7 Series / Re: Update Problems version 26...
Last post by franco - Today at 12:50:33 PM
Hi Constantin,

Can you test this kernel?

https://forum.opnsense.org/index.php?topic=53114.msg275459#msg275459


Cheers,
Franco
#3
Estou passando pelos mesmo problema vez o outra a navegação das maquinas simplesmente para de funcionar só retorna quando reinicio.

segue o link com os prints-- https://drive.google.com/drive/folders/1IFbj6VMwfMzH8gfX2MwNTsh9Xprr8mwW?usp=drive_link



#4
FreeBSD already applied the fix to HEAD (write only once instead of thrice) and it will be MFC'd (backported to STABLE) in 2 weeks. The batched write enhancement is still under revision.
#5
26.7 Series / Update Problems version 26.7.6...
Last post by CK_beats - Today at 12:34:41 PM
Hello community,
I could really use your help with the update to version 26.7.6.

The update process completes normally, the firewall restarts (Microsoft Hyper-V) and boots without errors.
However, Unbound DNS fails to run afterwards.
If I start the service manually, it runs for about 5 seconds before the following error appears in the log:
[8815:3] error: pythonmod: Exception occurred in function operate, event: module_event_moddone

From the specific Unbound logs, I was able to see last night that the buffer was unavailable. However, during a second attempt, I increased it to 10 MB (up from the default 4 MB).

Since Unbound won't start, nothing else is working, of course.

What did I do wrong?
Our OPNsense instance runs as the core router directly connected to the FTTH modem (VLAN 7). Apart from that, it manages 3 VLANs and handles DNS and DHCP; Squid and HAProxy are, of course, essential components.

Everything is standard, except for one third-party plugin (os_abusedipdb).

Has anyone else perhaps run into this same problem?
Up until now, all updates have always gone through without issues.

Best regards,
Constantin
#6
General Discussion / Re: netgate freebsd performanc...
Last post by franco - Today at 12:25:30 PM
Same as always: wait for stable branch merge.

Also, are we going to hear Netgate praise itself every two weeks now on their blog for open source work while forgetting to push any CE code commits for 6 months?

Feels like a new marketing strategy.  I wish them the best.  :)


Cheers,
Franco
#7
General Discussion / netgate freebsd performance pa...
Last post by Lucid1010 - Today at 12:00:52 PM
https://www.netgate.com/blog/ding-dong-ditch-the-doorbell-prank-in-freebsds-iflib
Is it possible to backport this patch to OPNsense, or should we wait until FreeBSD applies it?


#8
High availability / Re: CARP Question
Last post by Seimus - Today at 11:48:12 AM
In regards of the unbound "fail", the answer in regards of CARP is no. CARP does not track processes (keepalived can but that is not supported in FBSD).
Currently implementation of CARP in FBSD tracks only NIC state change, e.g is very static.

Which means if any of your processes, routing protocols or paths on OPN fail the CARP will not trigger a failover.

I personally run DNS outside of OPN, where I use keepalived between two DNS nodes (one node is on RPI other in PRX LXC) and VIP is given to the clients.
https://github.com/SeimusS/Pihole-HA

Just for info
https://github.com/opnsense/core/issues/10654#issue-5053589060

Regards,
S.

#9
High availability / Re: CARP Question
Last post by Seimus - Today at 11:23:13 AM
That would work how you describe it, but, its a bit overengineered. Like why not right.

But from pure NW perspective and OPNsense perspective. You can set the CARP to failover WAN + LAN if any of those fails be it LAN or WAN, one triggers the another.

I would create CARP for LAN/VLANs with 3 IPs (for that you have IPs). And WAN with a single IP (as you dont have more).
Have it implemented so a LAN failure triggers WAN failover and vise versa and sync between the FWs what is needed.

We tested this setup between two DECs in a LAB where DECs are connected to MLAGs towards Mikrotik and it works very fast and reliable.

Regards,
S.
#10
High availability / Re: CARP Question
Last post by marjohn56 - Today at 11:15:51 AM
OK, I am thinking a little differently. I had an instance a week or two ago where Unbound decided to go gaga, not for any reason I could see, it just did, it's not happened before. Now, I'm not sure CARP would pick this up, as the interfaces were still responding. I also have Home Assistant, that now watches the Unbound service, it also watches the gateways, and flags a warning etc. I'm going to use this flag to close one of the LAN ports on the switch so the primary router will be seen as down by the Proxmox instance and promote itself. This is the theory anyway, in practice we'll see what happens.