Recent posts

#1
26.7 Series / Re: how to recover using an ol...
Last post by defaultuserfoo - Today at 11:22:15 PM
Quote from: defaultuserfoo on Today at 10:43:25 PM
Quote from: defaultuserfoo on Today at 07:02:17 PM
Quote from: lmoore on Today at 04:29:11 AM
Quote from: defaultuserfoo on Today at 02:23:16 AMI had only one plugin installed, so I don't expect that any plugin conflicts would need resolving

Referring to page 6, after you powered on the restored system, did you check the 'Status' page and was the 'Resolve plugin conflicts' button there!?

I don't know ...  I'll pay attention to that when I start over.


I've installed the plugin that will be needed and there is no button to resolve plugin conflicts.  I'll check again after importing the old configuration.


There were no conflicts after importing the configuration.  But the plugin (os-maltrail) shows as orphaned.
#2
26.7 Series / Re: how to recover using an ol...
Last post by defaultuserfoo - Today at 11:19:20 PM
Quote from: (MARLOO) on Today at 04:57:54 AMThan you can setup your manual backup,sftp backup with cron job,screenshoot of your plugin and many other things you like.

Oh, are you suggesting to log in on the console and set up a cron job to use the ftp client to make a copy of /conf/config.xml?

Is there a better way?  I could as well use scp maybe.  Unfortunately, rsync is not installed.  Or is there a way through the web interface?
#3
26.7 Series / Re: how to recover using an ol...
Last post by defaultuserfoo - Today at 10:43:25 PM
Quote from: defaultuserfoo on Today at 07:02:17 PM
Quote from: lmoore on Today at 04:29:11 AM
Quote from: defaultuserfoo on Today at 02:23:16 AMI had only one plugin installed, so I don't expect that any plugin conflicts would need resolving

Referring to page 6, after you powered on the restored system, did you check the 'Status' page and was the 'Resolve plugin conflicts' button there!?

I don't know ...  I'll pay attention to that when I start over.


I've installed the plugin that will be needed and there is no button to resolve plugin conflicts.  I'll check again after importing the old configuration.
#4
26.7 Series / Re: how to recover using an ol...
Last post by defaultuserfoo - Today at 10:41:05 PM
Quote from: (MARLOO) on Today at 08:03:52 PM
Quote from: defaultuserfoo on Today at 07:09:55 PMOh so I have to use 25.7 and no 26.  I don't want to migrate the rules.  That won't work.  The router needs to be working again since a couple days ago.  I'll try to get it set up with 25.7 and deploy it.

Then I'll have to use the spare machine and set that up and see if the rules can be migrated somehow and either switch the machines or the disks, or migrate the currently broken one.  Having a spare really pays out big time.



Do whatever you want, but why do you not want to migrate the rules?

Migrating the rules does not mean changing them. It means validating your existing rules so they work with the new rules system in 26.7.

No it doesn't.  It means that all the rules need to be redone because migrating them doesn't work.  After importing the rules you get a mess of rules that don't work anymore because of the way things work with the new rules has changed and the old ones are not compatible.

I've done it at home a couple months ago and was left with a ruined firewall which I had to redo.  I was told here that I shouldn't have migrated the rules and that it would be many years before a migration would be required.

I've tried it yesterday when I suddenly found I can't edit the rules anymore after upgrading.  Exporting the old rules and importing them created yet again a total mess with a mixture of immutable rules and non-working rules and maybe some rules weren't imported. The import gets stuck with a popup window having a checkbox and checkmark in it and if you keep clicking on that you get unclear error messages and are left with no idea as to what you're supposed to do now.  You can keep importing the rules over and over but that is futile.

There is no migration.  It does 100% not work.

QuoteThat way, you can also keep receiving updates.

Only when I redo the whole firewall, and I don't want to do that again.

QuoteOPNsense is not obsolete. It is a well-maintained and well-documented system. Major changes are announced in the release notes and discussed in the forum, so it is important to follow those before upgrading an old configuration.

No.  It's not working.  I already said here that this so-called migration was handled badly because there must be a big fat warning in the release notes that your firewall will be broken and that you better wait the however many years before ever trying this so-called migration.  Instead it was made to appear something easy to do.  But it is isn't.

This reminds of the fatal blow Debian struck their users with their stupid brokenarch.  I had been using Debian for about 15 years and then the devs decided to comepletely mess it up, and it was forseeable that the problems would continue to exist in the next release.  So I switched away from Debian.

This is the same crap.  If I knew a good alternative to OPNsense I would switch.

We've already had a discussion about the release notes.  The devs refuse to make good release notes.

QuoteThe developers put a lot of work into maintaining the ecosystem and keeping it up to date. Reading the release notes and planning migrations is part of running a firewall, especially after a major architecture change.

Good luck with the recovery. At least now you know why the release notes exist.



The relase notes suck.  Look up the discussion about it we had.

It's not about the release notes anyway.  The problem is that there is no way to update the OPNsense instances anymore because doing that will break the firewall rules and the firewall needs to be completely redone.  That makes OPNsense obsolete.

Maybe I'll find an alternative.  If I have to start over from scratch I can as well switch to something else.
#5
German - Deutsch / Re: [Gelöst] Unbound-DNS Erw...
Last post by k0ns0l3 - Today at 10:24:56 PM
ich bleibe vorerst bei 5353 , mit mDNS ich habe nicht vor danke für Hinweis ;))

lg k0ns0l3
#6
General Discussion / Re: netgate freebsd performanc...
Last post by Greelan - Today at 10:17:26 PM
All of that said, there is no doubt a lesson in repeated CVEs happening due to similar reasons (input sanitization). I assume the tests have been hardened on that front.

As a matter of interest, does the development team use AI for vulnerability spotting?
#7
My humble hypothesis.

Intel Management Engine (ME) in BIOS? If so make sure that's enabled.
Try flashing with the 2MB bin.

If that fails,
The Winbond is a SPI, and is likely write-blocking.
You could ask vendor for procedure to update i226 firmware, or venture down path on how to hack that SPI 8pin to allow flashing the i226.

#8
26.7 Series / Re: PPPoE over an unassigned V...
Last post by franco - Today at 09:36:34 PM
Hi Franski,

Okay, just wanted to double check.  Let me try to come up with debug output for your case.  The patch not working would indicate the VLAN is up when it is supposed to wait for it to come up... which is silly because it will be down a split second later?  It's not easy to work around this when the kernel lives on its own schedule.

Maybe you can try to increase the sleep to 5 seconds in order to catch the down window?


Cheers,
Franco
#9
26.7 Series / Re: Unable to Change Tayga Set...
Last post by franco - Today at 09:33:16 PM
Looks like we're debugging this live on Saturday evening with Cedrik :D
#10
26.7 Series / Re: Unable to Change Tayga Set...
Last post by franco - Today at 09:29:58 PM
We bubbled up the error but that's all... it was probably always there and/or is still restarting.  Will check on Monday.


Cheers,
Franco