Recent posts

#1
26.7 Series / Re: Fatal error: Uncaught Erro...
Last post by dstr - Today at 08:17:41 AM
Any recommendations on how to do a safe upgrade?
Im using zfs btw
would a fsck before upgrading help?
#2
General Discussion / Transparent Firewall with High...
Last post by RunTheEngine - Today at 08:13:34 AM
Hello,

i have two OpnSense (DEC 697) and configured like this https://docs.opnsense.org/manual/how-tos/transparent_bridge.html
LAN1: Management 172.16.16.0/24 + Default GW
LAN2: untagged VLAN 1
LAN3: untagged VLAN 1111
LAN4: PFYNC  10.0.0.x/30
BRIDGE: (LAN2+LAN3)
Alle 6 LANs conntected to Mainswitch Aruba R0X25A
Now we want to have a failover. We have add Pfsync (direct connection between the to nodes)

HA is not working:
With Spanning Tree -> no connection
Without Spanning Tree -> Broadcastflood
With Loop-protect -> better, but if a reboot one node, the interfaces are up, but the bridge not working and then a small broadcastflood.

Has anyone a working solution without a loop?

Best Regards
Momme
#3
I broke my 26.7 system by tinkering with packages, resulting in an incompatible kernel which would not boot. So I started new, restored my backup and ditched ISC on my way. Fresh 26.7 with no custom packages again.

The question remains: I'd like to install a daemon written in Python, which would require a number of Python extensions. In particular

- psutil
- paho-mqtt
- pyyaml

The packages names relate to the base python version, eg py312-psutil. How would I install that, without putting my system at risk? Regards

Christian
#4
Hi there. It might not be the best option, but it works. I imported two certificates: the ISRG2 Root X2 and the Root YE intermediate.
System: Trust: Authorities
#5
Virtual private networks / Re: IPSec VTI
Last post by volga629 - Today at 02:40:04 AM
Additional sysctl



root@fw01:~ # /sbin/sysctl -a | grep ipsec
<118>[4] .ELF ldconfig path: /lib /usr/lib /usr/lib/compat /usr/local/lib /usr/local/lib/compat/pkg /usr/local/lib/compat/pkg /usr/local/lib/ipsec /usr/local/lib/perl5/5.42/mach/CORE
<6>[17] ipsec0: changing name to 'ipsec10'
<118>[23] Setting up routes for ipsec10...done.
<118> IPSECVTI1 (ipsec10) -> v4: 10.0.31.1/30
<6>[823] ipsec1: changing name to 'ipsec11'
<6>[71870] ipsec1: changing name to 'ipsec20'
<6>[80585] ipsec1: changing name to 'ipsec20'
<6>[84757] ipsec10: promiscuous mode enabled
<6>[84774] ipsec10: promiscuous mode disabled
<6>[85026] ipsec10: promiscuous mode enabled
kern.features.ipsec_natt: 1
kern.features.ipsec: 1
net.inet.ipsec.def_policy: 1
net.inet.ipsec.esp_trans_deflev: 1
net.inet.ipsec.esp_net_deflev: 1
net.inet.ipsec.ah_trans_deflev: 1
net.inet.ipsec.ah_net_deflev: 1
net.inet.ipsec.ah_cleartos: 1
net.inet.ipsec.dfbit: 0
net.inet.ipsec.ecn: 0
net.inet.ipsec.debug: 0
net.inet.ipsec.min_pmtu: 576
net.inet.ipsec.random_id: 0
net.inet.ipsec.offload.verbose: 0
net.inet.ipsec.filtertunnel: 1
net.inet.ipsec.natt_cksum_policy: 0
net.inet.ipsec.check_policy_history: 0
net.inet.ipsec.async_crypto: 0
net.inet.ipsec.crypto_support: 50331648
net.inet6.ipsec6.def_policy: 1
net.inet6.ipsec6.esp_trans_deflev: 1
net.inet6.ipsec6.esp_net_deflev: 1
net.inet6.ipsec6.ah_trans_deflev: 1
net.inet6.ipsec6.ah_net_deflev: 1
net.inet6.ipsec6.ecn: 0
net.inet6.ipsec6.debug: 0
net.inet6.ipsec6.filtertunnel: 1
net.enc.out.ipsec_bpf_mask: 1
net.enc.out.ipsec_filter_mask: 0
net.enc.in.ipsec_bpf_mask: 2
net.enc.in.ipsec_filter_mask: 0
root@fw01:~ #
#6
Virtual private networks / IPSec VTI
Last post by volga629 - Today at 02:17:06 AM
Good Day Community !!!!
If I am writing or asking question then the issue pretty sure is close to bug state. I am building networks over 18 years, for me create VTI set is normally takes between 15 to 20 min max, include FRR eBGP.
I ran into issue where latest version OPNsense 26.7.2_2-amd64 FreeBSD 15.1-RELEASE-p2, VTI is not passing any traffic. All traffic 0 in or out in bytes.
Tunnel is in state ESTABLISHED and no retransmissions.
That state before firewall where are I don't see any traffic on tcpdump enc0 interface.
I see that in opnsense bind VTI interface to loopback, but nothing is routed through.


Any hint what else I can check. Really appreciate on hard work of all people who keeping lights on !!!




root@fw01:~ # swanctl --list-sas
no files found matching '/usr/local/etc/strongswan.opnsense.d/*.conf'
da254f91-ea8e-49ef-b1ba-c1727fa06ec9: #10, ESTABLISHED, IKEv2, e1c7516a937db119_i 30276a85361654fa_r*
  local  'local pub ip' @ local pub ip[500]
  remote 'remote pub ip' @ remote pub ip[500]
  AES_GCM_16-256/PRF_HMAC_SHA2_384/MODP_2048
  established 2319s ago, rekeying in 11528s
  a9d737db-caa5-46a3-abd7-23b4a655c683: #8, reqid 10, INSTALLED, TUNNEL, ESP:AES_GCM_16-256
    installed 2319s ago, rekeying in 966s, expires in 1641s
    in  c46dd99b,      0 bytes,     0 packets
    out c56e5526,      0 bytes,     0 packets
    local  0.0.0.0/0
    remote 0.0.0.0/0
bf665be7-7931-4993-9c03-50d54c1f5c6a: #13, ESTABLISHED, IKEv2, b4c20eab1d170db2_i 7e733c1ad763743a_r*
  local  'local pub ip' @ local pub ip[500]
  remote 'remote pub ip' @ remote pub ip[500]
  AES_GCM_16-256/PRF_HMAC_SHA2_256/ECP_521
  established 988s ago, rekeying in 13095s
  2c9e658d-075b-478d-832e-118dfc95d592: #11, reqid 20, INSTALLED, TUNNEL, ESP:AES_CBC-256/HMAC_SHA2_256_128
    installed 988s ago, rekeying in 2397s, expires in 2972s
    in  c93e99c6,      0 bytes,     0 packets
    out c9a00496,      0 bytes,     0 packets
    local  0.0.0.0/0
    remote 0.0.0.0/0
root@fw01:~ #

ipsec10: flags=1008051<UP,POINTOPOINT,RUNNING,MULTICAST,LOWER_UP> metric 0 mtu 1400
        description: IPSECVTI1 (ipsec10)
        options=0
        tunnel inet local pub ip --> remote pub ip
        inet 10.0.31.1 --> 10.0.31.2 netmask 0xfffffffc
        groups: ipsec
        reqid: 10
        nd6 options=29<PERFORMNUD,IFDISABLED,AUTO_LINKLOCAL>

ipsec20: flags=1008051<UP,POINTOPOINT,RUNNING,MULTICAST,LOWER_UP> metric 0 mtu 1400
        options=0
        tunnel inet local pub ip --> remote pub ip
        inet 192.41.100.1 --> 192.41.100.2 netmask 0xfffffffc
        groups: ipsec
        reqid: 20
        nd6 options=29<PERFORMNUD,IFDISABLED,AUTO_LINKLOCAL>



As side not, please add some warning that will be good visual when "Policies" check mark is set.

#7
Development and Code Review / Re: Go With The Flow - free pl...
Last post by toby - August 25, 2026, 11:51:59 PM
Quote from: Monviech (Cedrik) on August 25, 2026, 04:22:41 PMI know I could download the package and extract it but not having the source code browsable (since its in a private repo) is a bit meh.

Once the plugin is more developed and feature rich (and stable), then I'll switch the repo to public. Until then I don't really want to invite code-related comments. For now, focus on the product and whether it offers something useful to you.
#8
26.7 Series / Re: UDP Broadcast Relay – Bloc...
Last post by 8b4df00d - August 25, 2026, 11:11:37 PM
Thanks for the suggestion! That's definitely a workaround and something I've kept in mind.

Still, I would really prefer a native solution on the OPNsense firewall itself rather than introducing an external host/container to my network.
#9
General Discussion / Re: P2P gaming between two com...
Last post by fornax - August 25, 2026, 10:50:15 PM
I had set this issue aside while I was dealing with bigger things, but with OPNSense 26.7.2 this is now resolved via Endpoint-independent NAT.

  • Gaming device IPs added to a firewall alias ("GamingHosts").
  • Source NAT set to hybrid mode.
  • Add a Source NAT rule:
    • Interface: WAN/IPv4/UDP
    • Source address: GamingHosts
    • Endpoint independent: Checked
  • I had previously set up a Static Port rule. Not sure if it's still necessary but I kept it for TCP and just removed UDP to avoid conflict:
    • Interface: WAN/IPv4/TCP
    • Source address: GamingHosts
    • Static-port: Checked

That's it, no UPnP necessary.
#10
26.7 Series / Re: UDP Broadcast Relay – Bloc...
Last post by Patrick M. Hausen - August 25, 2026, 10:45:30 PM
You can run Avahi on a system (VM, Raspi, Docker, ...) in your internal LAN and configure it to announce the static IP address of the printer.