Quote from: Monviech (Cedrik) on January 08, 2026, 11:11:04 AMI guess Stunnel is a Userland proxy, meaning any traffic it receives and forwards, will most likely not be reinjected into the kernel space (e.g. so PF or Suricata can see it), but copied directly on the outgoing interface.What do you want?' sounds more direct and can be rude in some contexts, while 'What is it you want?' is slightly more formal or neutral
You could probably put another router between the Stunnel OPNsense, and the LAN, which acts as a transparent IPS bridge:
https://docs.opnsense.org/manual/how-tos/transparent_bridge.html
Quote from: Sisko on Today at 10:08:58 AMI also recently replaced my ISP's cable modem /w a Netgear CM2000 which meets and exceeds the specs of the ISP's modem.
DP750 [EC:74:D7:02:F3:ED] [1.0.21.31]doFailover:SIPStack.cc(10270)->Switched to a new NAPTR SRV result
DP750 [EC:74:D7:02:F3:ED] [1.0.21.31]doFailover:SIPStack.cc(10277)->SRV name changed, update message Via and set reset flag
DP750 [EC:74:D7:02:F3:ED] [1.0.21.31]cb_nict_kill_transaction:SIPStack.cc(7675)->SIPStack(0): Kill NICT transaction 85357(REGISTER)
DP750 [EC:74:D7:02:F3:ED] [1.0.21.31]run:SIPStack.cc(1616)->SIPStack(0): Active transactions: 1
DP750 [EC:74:D7:02:F3:ED] [1.0.21.31]lookup:DNS.cc(221)->lookup| host: tel.t-online.de, srv_host: tel.t-online.de, clearOnly: 0, mode: 0, registrarIP: 0.0.0.0
DP750 [EC:74:D7:02:F3:ED] [1.0.21.31]isDomainCached:DNS.cc(1091)->CHECK isDomainCached host tel.t-online.de
DP750 [EC:74:D7:02:F3:ED] [1.0.21.31]isDomainCached:DNS.cc(1138)->CHECK isDomainCached i 0 host tel.t-online.de vs. stg010-l01-mav-pc-rt-001.edns.t-ipnet.de
DP750 [EC:74:D7:02:F3:ED] [1.0.21.31]isDomainCached:DNS.cc(1138)->CHECK isDomainCached i 1 host tel.t-online.de vs. lei001-l01-mav-pc-rt-001.edns.t-ipnet.de
DP750 [EC:74:D7:02:F3:ED] [1.0.21.31]isDomainCached:DNS.cc(1096)->CHECK isDomainCached i 2 host tel.t-online.de
DP750 [EC:74:D7:02:F3:ED] [1.0.21.31]isDomainCached:DNS.cc(1099)->CHECK isDomainCached i 2 j 0 unreachable 1 srv 1 transport 2 vs. 2 srv_host tel.t-online.de vs. tel.t-online.de
DP750 [EC:74:D7:02:F3:ED] [1.0.21.31]isDomainCached:DNS.cc(1129)->DNS cache: 2:0, host: tel.t-online.de is unreachable
DP750 [EC:74:D7:02:F3:ED] [1.0.21.31]isDomainCached:DNS.cc(1099)->CHECK isDomainCached i 2 j 1 unreachable 1 srv 1 transport 2 vs. 2 srv_host tel.t-online.de vs. tel.t-online.de
DP750 [EC:74:D7:02:F3:ED] [1.0.21.31]isDomainCached:DNS.cc(1129)->DNS cache: 2:1, host: tel.t-online.de is unreachable
DP750 [EC:74:D7:02:F3:ED] [1.0.21.31]isDomainCached:DNS.cc(1099)->CHECK isDomainCached i 2 j 2 unreachable 0 srv 1 transport 2 vs. 2 srv_host tel.t-online.de vs. tel.t-online.de
DP750 [EC:74:D7:02:F3:ED] [1.0.21.31]isDomainCached:DNS.cc(1124)->Fetch DNS A record from DNS cache for host tel.t-online.de
DP750 [EC:74:D7:02:F3:ED] [1.0.21.31]isDomainCached:DNS.cc(1138)->CHECK isDomainCached i 3 host tel.t-online.de vs. null
DP750 [EC:74:D7:02:F3:ED] [1.0.21.31]isDomainCached:DNS.cc(1138)->CHECK isDomainCached i 4 host tel.t-online.de vs. null
DP750 [EC:74:D7:02:F3:ED] [1.0.21.31]isDomainCached:DNS.cc(1138)->CHECK isDomainCached i 5 host tel.t-online.de vs. null
DP750 [EC:74:D7:02:F3:ED] [1.0.21.31]isDomainCached:DNS.cc(1138)->CHECK isDomainCached i 6 host tel.t-online.de vs. null
DP750 [EC:74:D7:02:F3:ED] [1.0.21.31]isDomainCached:DNS.cc(1138)->CHECK isDomainCached i 7 host tel.t-online.de vs. null
DP750 [EC:74:D7:02:F3:ED] [1.0.21.31]isDomainCached:DNS.cc(1138)->CHECK isDomainCached i 8 host tel.t-online.de vs. null
DP750 [EC:74:D7:02:F3:ED] [1.0.21.31]isDomainCached:DNS.cc(1138)->CHECK isDomainCached i 9 host tel.t-online.de vs. null
DP750 [EC:74:D7:02:F3:ED] [1.0.21.31]isDomainCached:DNS.cc(1138)->CHECK isDomainCached i 10 host tel.t-online.de vs. null
DP750 [EC:74:D7:02:F3:ED] [1.0.21.31]isDomainCached:DNS.cc(1138)->CHECK isDomainCached i 11 host tel.t-online.de vs. null
DP750 [EC:74:D7:02:F3:ED] [1.0.21.31]isDomainCached:DNS.cc(1138)->CHECK isDomainCached i 12 host tel.t-online.de vs. null
DP750 [EC:74:D7:02:F3:ED] [1.0.21.31]isDomainCached:DNS.cc(1138)->CHECK isDomainCached i 13 host tel.t-online.de vs. null
DP750 [EC:74:D7:02:F3:ED] [1.0.21.31]isDomainCached:DNS.cc(1138)->CHECK isDomainCached i 14 host tel.t-online.de vs. null
DP750 [EC:74:D7:02:F3:ED] [1.0.21.31]isDomainCached:DNS.cc(1138)->CHECK isDomainCached i 15 host tel.t-online.de vs. null
DP750 [EC:74:D7:02:F3:ED] [1.0.21.31]isDomainCached:DNS.cc(1138)->CHECK isDomainCached i 16 host tel.t-online.de vs. null
DP750 [EC:74:D7:02:F3:ED] [1.0.21.31]isDomainCached:DNS.cc(1138)->CHECK isDomainCached i 17 host tel.t-online.de vs. null
DP750 [EC:74:D7:02:F3:ED] [1.0.21.31]isDomainCached:DNS.cc(1138)->CHECK isDomainCached i 18 host tel.t-online.de vs. null
DP750 [EC:74:D7:02:F3:ED] [1.0.21.31]isDomainCached:DNS.cc(1138)->CHECK isDomainCached i 19 host tel.t-online.de vs. null
DP750 [EC:74:D7:02:F3:ED] [1.0.21.31]lookup:DNS.cc(260)->check isDomainCached returned true
DP750 [EC:74:D7:02:F3:ED] [1.0.21.31]snd_message:SIPStack.cc(7154)->setNetworkConnected
DP750 [EC:74:D7:02:F3:ED] [1.0.21.31]snd_message:SIPStack.cc(7158)->Last Good IP Addr:0.0.0.0
DP750 [EC:74:D7:02:F3:ED] [1.0.21.31]snd_message:SIPStack.cc(7181)->Present IP Addr:217.0.147.197
DP750 [EC:74:D7:02:F3:ED] [1.0.21.31]snd_message:SIPStack.cc(7189)->Previous Addr: 217.0.147.69
DP750 [EC:74:D7:02:F3:ED] [1.0.21.31]findCachedConnection:SIPStack.cc(1733)->No cached TCP connection found
DP750 [EC:74:D7:02:F3:ED] [1.0.21.31]findCachedConnection:SIPStack.cc(1733)->No cached TCP connection found
DP750 [EC:74:D7:02:F3:ED] [1.0.21.31]GS_WEB DEBUG hasPermission /cgi-bin/api.values.get
DP750 [EC:74:D7:02:F3:ED] [1.0.21.31]GS_WEB DEBUG Finished CGI Request:/cgi-bin/api.values.get
DP750 [EC:74:D7:02:F3:ED] [1.0.21.31]GS_WEB DEBUG Initializing WEB process...
DP750 [EC:74:D7:02:F3:ED] [1.0.21.31]GS_WEB DEBUG hasPermission /cgi-bin/api.values.get
DP750 [EC:74:D7:02:F3:ED] [1.0.21.31]GS_WEB DEBUG Finished CGI Request:/cgi-bin/api.values.get
DP750 [EC:74:D7:02:F3:ED] [1.0.21.31]GS_WEB DEBUG Initializing WEB process...
DP750 [EC:74:D7:02:F3:ED] [1.0.21.31]unreachable:DNS.cc(898)->set unreachabletel.t-online.de, ip: 217.0.147.197
DP750 [EC:74:D7:02:F3:ED] [1.0.21.31]snd_message:SIPStack.cc(7312)->transaction: 85358 has NO MORE destination to retry
DP750 [EC:74:D7:02:F3:ED] [1.0.21.31]snd_message:SIPStack.cc(7345)->SIPStack(0) message cannot connect to - tel.t-online.de:5060DP750 [EC:74:D7:02:F3:ED] [1.0.21.31]unreachable:DNS.cc(898)->set unreachabletel.t-online.de, ip: 217.0.147.197
DP750 [EC:74:D7:02:F3:ED] [1.0.21.31]snd_message:SIPStack.cc(7312)->transaction: 85358 has NO MORE destination to retry
DP750 [EC:74:D7:02:F3:ED] [1.0.21.31]snd_message:SIPStack.cc(7345)->SIPStack(0) message cannot connect to - tel.t-online.de:5060Quote from: OPNenthu on Today at 10:23:09 AMIf they are meant to cascade, is there a way to make the policies work like pf 'quick' rules, on first match? Alternatively, can anyone think of a creative hack to make this scheme work as intended and still support dynamic prefixes? :)
DP750 [EC:74:D7:02:F3:ED] [1.0.21.31]lookup:DNS.cc(507)->Failed to resolve DNS A query for host: tel.t-online.deDP750 [EC:74:D7:02:F3:ED] [1.0.21.31]isDomainCached:DNS.cc(1091)->CHECK isDomainCached host tel.t-online.de
DP750 [EC:74:D7:02:F3:ED] [1.0.21.31]isDomainCached:DNS.cc(1138)->CHECK isDomainCached i 0 host tel.t-online.de vs. stg010-l01-mav-pc-rt-001.edns.t-ipnet.de
DP750 [EC:74:D7:02:F3:ED] [1.0.21.31]isDomainCached:DNS.cc(1138)->CHECK isDomainCached i 1 host tel.t-online.de vs. lei001-l01-mav-pc-rt-001.edns.t-ipnet.de
DP750 [EC:74:D7:02:F3:ED] [1.0.21.31]isDomainCached:DNS.cc(1138)->CHECK isDomainCached i 2 host tel.t-online.de vs. null
DP750 [EC:74:D7:02:F3:ED] [1.0.21.31]isDomainCached:DNS.cc(1138)->CHECK isDomainCached i 3 host tel.t-online.de vs. null
DP750 [EC:74:D7:02:F3:ED] [1.0.21.31]isDomainCached:DNS.cc(1138)->CHECK isDomainCached i 4 host tel.t-online.de vs. null
DP750 [EC:74:D7:02:F3:ED] [1.0.21.31]isDomainCached:DNS.cc(1138)->CHECK isDomainCached i 5 host tel.t-online.de vs. null
DP750 [EC:74:D7:02:F3:ED] [1.0.21.31]isDomainCached:DNS.cc(1138)->CHECK isDomainCached i 6 host tel.t-online.de vs. null
DP750 [EC:74:D7:02:F3:ED] [1.0.21.31]isDomainCached:DNS.cc(1138)->CHECK isDomainCached i 7 host tel.t-online.de vs. null
DP750 [EC:74:D7:02:F3:ED] [1.0.21.31]isDomainCached:DNS.cc(1138)->CHECK isDomainCached i 8 host tel.t-online.de vs. null
DP750 [EC:74:D7:02:F3:ED] [1.0.21.31]isDomainCached:DNS.cc(1138)->CHECK isDomainCached i 9 host tel.t-online.de vs. null
DP750 [EC:74:D7:02:F3:ED] [1.0.21.31]isDomainCached:DNS.cc(1138)->CHECK isDomainCached i 10 host tel.t-online.de vs. null
DP750 [EC:74:D7:02:F3:ED] [1.0.21.31]isDomainCached:DNS.cc(1138)->CHECK isDomainCached i 11 host tel.t-online.de vs. null
DP750 [EC:74:D7:02:F3:ED] [1.0.21.31]isDomainCached:DNS.cc(1138)->CHECK isDomainCached i 12 host tel.t-online.de vs. null
DP750 [EC:74:D7:02:F3:ED] [1.0.21.31]isDomainCached:DNS.cc(1138)->CHECK isDomainCached i 13 host tel.t-online.de vs. null
DP750 [EC:74:D7:02:F3:ED] [1.0.21.31]isDomainCached:DNS.cc(1138)->CHECK isDomainCached i 14 host tel.t-online.de vs. null
DP750 [EC:74:D7:02:F3:ED] [1.0.21.31]isDomainCached:DNS.cc(1138)->CHECK isDomainCached i 15 host tel.t-online.de vs. null
DP750 [EC:74:D7:02:F3:ED] [1.0.21.31]isDomainCached:DNS.cc(1138)->CHECK isDomainCached i 16 host tel.t-online.de vs. null
DP750 [EC:74:D7:02:F3:ED] [1.0.21.31]isDomainCached:DNS.cc(1138)->CHECK isDomainCached i 17 host tel.t-online.de vs. null
DP750 [EC:74:D7:02:F3:ED] [1.0.21.31]isDomainCached:DNS.cc(1138)->CHECK isDomainCached i 18 host tel.t-online.de vs. null
DP750 [EC:74:D7:02:F3:ED] [1.0.21.31]isDomainCached:DNS.cc(1138)->CHECK isDomainCached i 19 host tel.t-online.de vs. null
DP750 [EC:74:D7:02:F3:ED] [1.0.21.31]isDomainCached:DNS.cc(1150)->DNS cache, all 0 matching hosts unreachable
DP750 [EC:74:D7:02:F3:ED] [1.0.21.31]isDomainCached:DNS.cc(1158)->DNS cache, no other hosts reachable, clear cache
DP750 [EC:74:D7:02:F3:ED] [1.0.21.31]lookup:DNS.cc(497)->Search DNS A cache for host: tel.t-online.deis found: 0
DP750 [EC:74:D7:02:F3:ED] [1.0.21.31]lookup:DNS.cc(507)->Failed to resolve DNS A query for host: tel.t-online.de
DP750 [EC:74:D7:02:F3:ED] [1.0.21.31]snd_message:SIPStack.cc(6976)->Last good IP Addr:0.0.0.0
DP750 [EC:74:D7:02:F3:ED] [1.0.21.31]addAuthInfo:SIPStack.cc(3182)->no credential provided, no authentication header in REGISTER
DP750 [EC:74:D7:02:F3:ED] [1.0.21.31]snd_message:SIPStack.cc(7453)->no credential cached for server IP: 255.255.255.255
DP750 [EC:74:D7:02:F3:ED] [1.0.21.31]snd_message:SIPStack.cc(7518)->(608) REGISTER sip:tel.t-online.de SIP/2.0 Via: SIP/2.0/UDP 192.168.100.109:5060;branch=z9hG4bK950146522;rport From:
DP750 [EC:74:D7:02:F3:ED] [1.0.21.31]"+MeineTelefonNummer" <sip:+MeineTelefonNummer@tel.t-online.de>;tag=365872417 To: <sip:+MeineTelefonNummer@tel.t-online.de> Call-ID: 115409531-5060-1@BJC.BGI.BAA.B
DP750 [EC:74:D7:02:F3:ED] [1.0.21.31]AJ CSeq: 30233 REGISTER Contact: <sip:+MeineTelefonNummer@192.168.100.109:5060>;reg-id=1;+sip.instance="<urn:uuid:00000000-0000-1000-8000-EC74D702F3ED>"
DP750 [EC:74:D7:02:F3:ED] [1.0.21.31] Max-Forwards: 70 User-Agent: Grandstream DP750 1.0.21.31 Supported: path Expires: 3600 Allow: INVITE, ACK, OPTIONS, CANCEL, BYE, SUBSCRIBE, NOTIF
DP750 [EC:74:D7:02:F3:ED] [1.0.21.31]Y, INFO, REFER, UPDATE Content-Length: 0
DP750 [EC:74:D7:02:F3:ED] [1.0.21.31]cb_transport_error:SIPStack.cc(7759)->SIPStack(0): Transport error (-1) for transaction 84683
DP750 [EC:74:D7:02:F3:ED] [1.0.21.31]clearRegistrarIP:SIPStack.cc(7730)->JF::RegistrarIP cleared
DP750 [EC:74:D7:02:F3:ED] [1.0.21.31]cb_transport_error:SIPStack.cc(7915)->transaction: 84683 has NO MORE destination to retry
DP750 [EC:74:D7:02:F3:ED] [1.0.21.31]waitForResponse:SIPTransaction.cc(1160)->Request 84683 is cancelled or killed
DP750 [EC:74:D7:02:F3:ED] [1.0.21.31]performRegistration:SigControl.cc(3400)->transaction got code 2:-1
DP750 [EC:74:D7:02:F3:ED] [1.0.21.31]Event:Event.cc(1128)->========================================
DP750 [EC:74:D7:02:F3:ED] [1.0.21.31]Event:Event.cc(1129)->Event: SIG_REGISTERED_NOTIFY_HS
DP750 [EC:74:D7:02:F3:ED] [1.0.21.31]Event:Event.cc(1130)->========================================
DP750 [EC:74:D7:02:F3:ED] [1.0.21.31]run:Event.cc(1084)->Dispatching event 264 (SIG_REGISTERED_NOTIFY_HS) on port -1:-1
DP750 [EC:74:D7:02:F3:ED] [1.0.21.31]processSigRegisteredNotifyHS:Dect.cc(6075)->DECT: [RII:010101] processSigRegisteredNotifyHS: HS(1) no change in sip registration mask 0.
DP750 [EC:74:D7:02:F3:ED] [1.0.21.31]cb_nict_kill_transaction:SIPStack.cc(7675)->SIPStack(0): Kill NICT transaction 84683(REGISTER)
DP750 [EC:74:D7:02:F3:ED] [1.0.21.31]run:SIPStack.cc(1616)->SIPStack(0): Active transactions: 1
DP750 [EC:74:D7:02:F3:ED] [1.0.21.31]performRegistration:SigControl.cc(3465)-> ---- check 1 statusCode -1
DP750 [EC:74:D7:02:F3:ED] [1.0.21.31]performRegistration:SigControl.cc(3520)-> ---- check 4 regRetryWait[0] 20
DP750 [EC:74:D7:02:F3:ED] [1.0.21.31]performRegistration:SigControl.cc(3525)->SigCtrl::performRegistration on acct 0, regRetries:3, retryAfter:0, regRetryWait:20
DP750 [EC:74:D7:02:F3:ED] [1.0.21.31]run:SigControl.cc(2574)-> --- performReg check status reg 0 on 0, uptime 857739, regExp 0, tVal 0
DP750 [EC:74:D7:02:F3:ED] [1.0.21.31]run:SigControl.cc(2574)-> --- performReg check status reg 0 on 0, uptime 857740, regExp 0, tVal 0
DP750 [EC:74:D7:02:F3:ED] [1.0.21.31]run:SigControl.cc(2574)-> --- performReg check status reg 0 on 0, uptime 857741, regExp 0, tVal 0
DP750 [EC:74:D7:02:F3:ED] [1.0.21.31]run:SigControl.cc(2574)-> --- performReg check status reg 0 on 0, uptime 857742, regExp 0, tVal 0
DP750 [EC:74:D7:02:F3:ED] [1.0.21.31]run:SigControl.cc(2574)-> --- performReg check status reg 0 on 0, uptime 857743, regExp 0, tVal 0