Recent posts

#1
device to device traffic on the same network segment does not go through your router. You can block the devices from going out to the internet but not from talking to each other, unless they go from one network to another, that needs to be _routed_ by your router i.e. OPN.
Presumably they are all connected via a switch plugged into the internal_lan interface., right?
#2
26.7 Series / Re: PF states created with rou...
Last post by demyers - Today at 09:36:22 PM
Thank you geri441 for letting us know that flushing the state tables clears this issue (until the next reboot). I ran into a similar issue when upgrading to 26.1, which I posted about here, and I've been running 25.7 ever since. Today I upgraded all the way to 26.7 and with your clue I won't have to roll back again.
#3
Zenarmor (Sensei) / Re: Very high SSD writes with ...
Last post by bodenlos - Today at 08:36:46 PM
Quote from: Bunch on Today at 10:53:06 AM...

Environment:
Base OS: Proxmox 9.2.11
Kernel Version: Linux 7.0.14-15-pve
SSD (hardware): Samsung SSD 970 EVO Plus 500GB
OPNsense VM: (Disk setting only) LVM-Thin, 32GB, Cache=Default (no Cache), Discard=on, IO thread=on, SSD emulation=on
OPNsense: OPNsense 26.7.3_11-amd64 FreeBSD 15.1-RELEASE-p3
Zenarmor Engine: 2.6.2
Zenarmor Database: 2.0.26071708
Reporting backend: Local SQLite 3.53.4,1

->> What filesystems are you using on the Proxmox host and inside the OPNsense VM?
#4
I'm using OPNSense 26.7.3
I've searched the forums and tried to follow the advice, most of it seems to be slightly out-of-date, and no matter what I do I can not get this to work.
I'm trying to block internet access to a group alias while allowing LAN access to other devices.
Hopefully somebody will help to point me in the right direction here.  I'm including a screenshot of the rule and the point I gave up.
#5
26.7 Series / Re: Confused by 26.7 upgrade
Last post by Labber53 - Today at 06:56:46 PM
The community has spoken. My contribution is that I am not recommending 26.7 for my clients. I'm running 26.1 in home lab.
My net promoter score dropped from a 8 to a 6. That said, I'm willing to help with crowdsourcing getting things testing and documented.
#6
Have you tried plugging in the network cable?
Haha, no, uh, did you go to Services->GWTF->Settings and set that up first?
#7
26.7 Series / 26.7 changes break TOR configu...
Last post by Labber53 - Today at 06:27:11 PM
The 26.7 updates break os-tor setup. The documentation for TOR no longer works.
1) Advanced mode no longer exposes these options
    - Confirm SOCKS port number: 9050
    - Confirm Control Port: 9051
    - Check Enable Transparent Proxy
    - Confirm Transparent port: 9040
    - Confirm Transparent DNS port: 9053
2) Firewall > NAT  > Port Forward no longer exists for the redirect port 53 to 9043

If you have got tor working on 26.7 can you please share your recipe? (specifically TOR-only network connectivity behind OPNsense)
#8
Quote from: UnicronHD on September 06, 2026, 11:10:53 PMWhich version of OPNsense are you running? Is it amd64 or arm64? Basically I need to know FreeBSD version and architecture to prepare a binary for you.

Thanks, great to hear that the first implementation is ready. I'm happy to test it.

I'm running:

OPNsense 26.7.3_11-amd64
FreeBSD 15.1-RELEASE-p3
OpenSSL 3.5.8
Architecture: amd64
#9
Hi everyone,

I recently changed the interface layout on my OPNsense firewall and noticed something I did not expect with Suricata IDS.

Before the change, Suricata was monitoring my LAN interface and the alerts were easy to associate with traffic from my internal clients. After moving the IDS configuration to another interface, I still see Suricata running and processing traffic, but the number of alerts has dropped significantly.

For example, normal DNS and HTTP/HTTPS traffic is visible in the firewall logs, but some traffic that previously generated Suricata alerts no longer appears in the IDS event list.

My setup is roughly:

OPNsense 26.x
Suricata enabled in IDS mode
ET Open rules enabled
LAN and an additional interface are being monitored
No custom Suricata rules
Hardware offloading is disabled

Is there a specific interface or Home Networks configuration I should check when moving Suricata monitoring between interfaces?

I'm especially interested in understanding whether the interface selection changes which traffic Suricata can actually inspect, rather than simply affecting what is displayed in the alerts.

If anyone has a similar setup, I'd appreciate hearing how you configured the monitored interfaces and Home Networks.
#10
Looks good. Especially being CARP aware. Installed it as replacement for UDP Broadcast Relay