Recent posts

#1
General Discussion / Anyone else hosting a small sc...
Last post by drewhartman - September 14, 2026, 08:48:28 PM
Hi everyone,

I've been running a small Roblox scripting site from my home network for the past few months, routing it through my OPNsense box with some basic traffic rules. It's a pretty low-traffic project (maybe a few hundred hits a day), but I wanted to make sure it doesn't interfere with my normal home bandwidth.

My setup is: OPNsense with a /24 from my ISP, the site runs on a small VPS but I port-forward for local dev testing. The website handles all the actual serving, my OPNsense side is just doing NAT and light QoS.

Curious if anyone else here has a similar setup - running a small web project through their home gateway and how you handle the traffic separation? I've got a simple firewall rule that tags the VPS IP and keeps it on a lower-priority queue, which seems to be working fine so far.

Would appreciate any tips on best practices for this kind of mixed traffic scenario. Happy to share my config rules if useful.

Thanks!
#2
General Discussion / Re: Rclone backup support
Last post by Patrick M. Hausen - September 14, 2026, 08:42:13 PM
Quote from: skittle6674 on September 14, 2026, 07:51:32 PMJust exactly this really. I just want to automate as much as possible, and currently use the Google drive option.

Git, Nextcloud and SFTP are not enough alternatives? 😉
#3
General Discussion / Re: [SOLVED] P2P gaming betwee...
Last post by Bob.Dig - September 14, 2026, 08:13:22 PM
Quote from: nero355 on September 14, 2026, 06:13:50 PMpoint me to a nice explanation
Here you go. Ok, it isn't that good but contains some info which is relevant here too. 

Although I doubt that it makes gaming better than static port does. It would only make a difference if your gaming clients would use the same UDP source ports. But why should they in the first place, these days that would be stupid.
I think Endpoint-independent Port Restricted Cone NAT is more for very big networks, maybe ISPs and their CG-NAT stuff etc.
#4
General Discussion / Re: Rclone backup support
Last post by skittle6674 - September 14, 2026, 07:51:32 PM
Quote from: Patrick M. Hausen on September 13, 2026, 01:27:47 PMWhat exactly are you intending to backup? There isn't much besides the config.xml, really.
Just exactly this really. I just want to automate as much as possible, and currently use the Google drive option.

Quote from: Lucid1010 on September 13, 2026, 01:23:00 PMhttps://rclone.org/downloads/

Since rclone uses a FreeBSD binary, you can run backups directly using a shell script.
I currently back up to Dropbox and S3 via rclone.
That's a good idea, I'll look into this option.
#5
26.7 Series / Re: Firmware upgrade from 26.1...
Last post by KHatfull - September 14, 2026, 07:41:52 PM
Last night (or should I say this morning, 3:00a is morning right?) I went from 26.7.1_1 to 26.7.3_11.  No issues.

  • os-intel-microcode not installed
  • removed theme plugins
  • grabbed a config export
  • ZFS snapshot
  • Ran the upgrade, one boot, all good
  • Copied the bootloader files to the secondary ZFS mirror disk
  • Rebooted, all good.

Process took less than 10 minutes.  All services just fine.

This is how I remember OPNsense upgrades going :)
#6
26.7 Series / Re: AQC107 aq0 + Suricata IPS/...
Last post by chr - September 14, 2026, 06:43:27 PM
Small update:

After disabling Services > Intrusion Detection / Suricata, aq0 no longer shows NETMAP in ifconfig options.

Before disabling IPS on WAN:
  aq0 options included NETMAP

After disabling IPS on WAN:
  options=4802028<VLAN_MTU,JUMBO_MTU,WOL_MAGIC,HWSTATS,MEXTPG>

It has now been stable for several hours with no new aq0 / atlantic / FLB / link reset messages in dmesg.

So this still looks like Suricata IPS/Netmap on the WAN interface triggering the aq/atlantic reinitialization loop after 26.7.3_11. Not sure if this is specific to AQC107 or a broader Netmap/driver interaction.
#7
General Discussion / Re: [SOLVED] P2P gaming betwee...
Last post by nero355 - September 14, 2026, 06:13:50 PM
Quote from: fornax on August 25, 2026, 10:50:15 PMwith OPNSense 26.7.2 this is now resolved via Endpoint-independent NAT.

That's it, no UPnP necessary.
NICE! :)

But could someone point me to a nice explanation about what 'Endpoint-independent NAT' does exactly ?!
#8
German - Deutsch / Re: DNS Setup mit Unbound, DNS...
Last post by Patrick M. Hausen - September 14, 2026, 06:07:26 PM
Dazu kommt doch, dass wir uns in dieser Runde hier gerade innerhalb von Deutschland unterhalten, jedenfalls meistens. Hier ist immer noch ein Rechtsstaat und es gilt die DSGVO. Von welchen ISPs reden wir denn bitte schön?

Was glaubst du wie die Kacke am Dampfen ist, wenn Telekom oder Vodafone dabei erwischt werden, wie sie shady Zeug mit dem Verkehr ihrer ISP-Kunden machen ...

Haben die nicht mal Malware-Filter eingebaut, ohne zu fragen, und das gab einen ziemlichen Shitstorm? Jedenfalls ist "Security on net" bei der Telekom heute erhältlich und optional. Kann ja jedes halten wie sie möchten.
#9
German - Deutsch / Re: DNS Setup mit Unbound, DNS...
Last post by JeGr - September 14, 2026, 05:42:55 PM
Quote from: HBerger on September 10, 2026, 11:44:43 AM
QuoteWarum soll ich irgendeiner Shady Bude meinen kompletten Traffic (via DNS) verraten? Nur weils kostenlos ist? :)
Für business und extended setups, ok.
Aber ist da der dns im opnSense eh die richtige Lösung?

Für Heimanwender, die hängen doch meist am Tropf des ISP, der weiß eh alles. Da kann man auch dessen DNS Resolver verwenden, vorausgesetzt die funktionieren vernünftig? Mir ist bei meinem noch nichts böses aufgefallen (Filtering, Ausfälle und co).

Das hat ja jetzt nicht direkt was mit Business oder Extended Setups zu tun, oder? Ich sehe nur selbst hier und anderswo ständig Private/HomeLab Builds, die dann zum Ende hin alles via VPN %irgendwo% hin schicken damit ja alles verschlüsselt ist. Aber bringt es was, dem VPN Anbieter dann alle Daten - plus ggf. noch Geld - in den Rachen zu werfen? Das hängt eben ganz vom Schutzbedürfnis ab. Und wenn das nicht irgendwo bei "mission critical" bis "Ich bin Edward Snowden" liegt, dann ist der Provider für dich noch die Kleinste Hürde. DER ist nämlich zumindest aktuell und noch an die DSGvO und andere Spielregeln im Land gebunden und muss deinen Kram bzw. die IP Zuordnung wieder löschen. %HochObenSicherVPN% muss das nicht. Oder dir zumindest nicht verraten. Und sitzt meist auch nichtmal in Ländern, wo du sie irgendwo behelligen kannst.

Das ist der eine Knackpunkt. Der andere ist: DNS irgendwo hin zu packen, wo du keine Kontrolle drüber hast. Also 1.1.1.1, 8.8.8.8 und Co. Die mögen schnell sein, aber die können halt morgen Filtern, zensieren, etc. Nutzt du Unbound als Resolver und den Weg über die Roots wird Zensur schwerer. Klar, dein ISP könnte reingrätschen und Port 53 intercepten und umleiten. Das könnte man dann aber erkennen und entsprechen Gegenmaßnahmen ergreifen. Solange die aber - siehe oben - an geltendes Recht gebunden sind, wäre das eine verdammt heikle Sache, sich bei sowas erwischen zu lassen.

Das ist aber der Grund, warum ich DoT/DoH kritisch sehe. DoT kann man genauso einfach blocken wie normales DNS. DoH/DoQ löst kein wirkliches Problem außer den Provider auszuhebeln. Wenn wir aber RogueISP haben, dann kann der einfach die bekannten DoH/DoQ Gegenstellen blocken. Klar kann man dann einen suchen der geht aber dann sind wir auf einem Level, wo wie ich schon weiter oben beschrieben hatte eher dann ein Konstrukt wie DoHoT sinnvoll wäre. Also DoH (DNS via HTTPS) und das via TOR um im Traffic vom TOR Netz unter zu gehen. Dann ist nicht mehr einfach erkennbar, dass das DNS Calls sind. Aber da sind wir dann schon weitaus weiter oben auf der Gefährdungsskala als "ich brauche schnelles DNS" :)

Wenn man selbst die volle Kontrolle möchte, ist es eh am Sinnvollsten, sich intern und extern nen DNS aufzubauen mit Blocklistings und Co (also AGH oder PiHole hinstellen). Und vom externen kann man dann auch wieder via Unbound brav DNS Resolving machen. Den kann man dann auf der Sense als Fallback Forwarder angeben und notfalls auch nen VPN dahin tunneln wenn einem der ISP suspekte Sachen macht. Immer noch besser als gratis oder für 1,39€/mtl den ganzen Kram via Cloudflare, Alphabet oder sonstwen zu jockeln :)

Cheers

Cheers
#10
26.7 Series / Re: Can settings from ver OPNs...
Last post by nero355 - September 14, 2026, 05:21:02 PM
Quote from: lmoore on September 14, 2026, 11:00:00 AM- https://homenetworkguy.com/how-to/migrate-from-isc-dhcp-to-dnsmasq-or-kea-dhcp-in-opnsense/
IMHO this is a very good one that tells you basically all you might need to know and a lot of people on this forum have used it in the past! :)