Recent posts

#1
26.7 Series / Re: "old" rules show up in "Ru...
Last post by Monviech (Cedrik) - Today at 01:18:03 PM
Sure, and then the next user is like "Why are my rules orange I don't understand whats going on".

We did the most we could with the links. I would have hoped users try to click them if they don't find the edit button.
#2
26.7 Series / Audit - security
Last post by Karla - Today at 01:08:13 PM
I made an audit - security and got this output:

***GOT REQUEST TO AUDIT SECURITY***
Currently running OPNsense 26.7.1_1 (amd64) at Wed Aug  5 13:06:29 CEST 2026
Fetching vuln.xml.xz: .......... done
unbound-1.25.1_1 is vulnerable:
  unbound -- multiple vulnerabilities
  CVE: CVE-2026-56444
  CVE: CVE-2026-56416
  CVE: CVE-2026-55991
  CVE: CVE-2026-55990
  CVE: CVE-2026-55973
  CVE: CVE-2026-55717
  CVE: CVE-2026-55708
  CVE: CVE-2026-54478
  CVE: CVE-2026-52863
  CVE: CVE-2026-50252
  CVE: CVE-2026-50251
  CVE: CVE-2026-50248
  CVE: CVE-2026-50243
  CVE: CVE-2026-50046
  CVE: CVE-2026-50045
  CVE: CVE-2026-46582
  CVE: CVE-2026-44690
  CVE: CVE-2026-44687
  CVE: CVE-2026-44621
  CVE: CVE-2026-42955
  CVE: CVE-2026-41637
  CVE: CVE-2026-40691
  CVE: CVE-2026-32665
  CVE: CVE-2026-14586
  WWW: https://vuxml.freebsd.org/freebsd/f63b4b88-6901-4c12-b13d-5a821e25e9bf.html

python313-3.13.14 is vulnerable:
  Python -- poplib module, when passed a user-controlled command, can have additional commands injected using newlines
  CVE: CVE-2025-15367
  WWW: https://vuxml.freebsd.org/freebsd/6d3488ae-2e0f-11f1-88c7-00a098b42aeb.html

  Python -- imaplib module, when passed a user-controlled command, can have additional commands injected using newlines
  CVE: CVE-2025-15366
  WWW: https://vuxml.freebsd.org/freebsd/0be929a5-2e0f-11f1-88c7-00a098b42aeb.html

3 problem(s) in 2 package(s) found.
***DONE***
#3
26.7 Series / Re: "old" rules show up in "Ru...
Last post by tessus - Today at 01:02:21 PM
Quote from: SchengFui on Today at 12:34:42 PMi think this is normal, they are shown but you cannot edit them.

in the commands-column you can only lookup the rule reference, after migration, you can edit them.

Ahhhh, thanks! This makes sense.

Just an idea for the devs for the future: a reference could have a different color. The text (columns in the row of the rule) is shown as black, but a reference could be shown as blue or orange.
#5
26.7 Series / Re: OpenVPN CLient Export fail...
Last post by Monviech (Cedrik) - Today at 01:00:22 PM
I just tested the export and it works for me.

Maybe you are doing something wrong with your certificates?

Try using openssl on the command line to check if your CA and your Leaf certificates are correctly issued.
#6
German - Deutsch / Re: Zentrale Verwaltung mehrer...
Last post by FrazoN11 - Today at 12:46:03 PM
hast 'nen Punkt///
#7
Den gleichen Namen wie das vergleichbare Produkt von Deciso würde ich vermeiden.

https://docs.opnsense.org/vendor/deciso/opncentral.html
#8
26.7 Series / Re: "old" rules show up in "Ru...
Last post by SchengFui - Today at 12:34:42 PM
i think this is normal, they are shown but you cannot edit them.

in the commands-column you can only lookup the rule reference, after migration, you can edit them.
#9
26.7 Series / "old" rules show up in "Rules ...
Last post by tessus - Today at 12:26:23 PM
I am running OPNsense 26.1.11_10-amd64 and even though I have never touched the Migration Assistant (nor created any new rules manually), all my rules are shown on the Firewall: Rules [new] page.

I am slightly confused right now. According to all the posts regarding the migration to the new rules setup, one has to actually migrate the old rules by exporting the legacy rules and importing them into the new GUI (Rules [new]).
I have never done that, yet they are shown.

I also just tested to change the description of one of my legacy rules.... and guess what, the new description shows up under "Rules [new]".

So, what is going on?

Why do they show up under "Rules [new]", even though I never migrated them?
How do I know whether my rules are really migrated (and not just an echo from my legacy rules)?
#10
26.7 Series / Re: Asking for Sanity Check be...
Last post by proctor - Today at 12:12:16 PM
Quote from: Patrick M. Hausen on July 30, 2026, 08:11:25 AMThe second instance of the CPU identification lines starting with "CPU: Intel(R) Celeron(R) J6412 @ 2.00GHz (1996.80-MHz K8-class CPU)" shows that the plugin ran. If there is an update for your CPU model, it was applied.

Patrick, can you please explain, in what way the referenced line indicates the run of the plugin? - I see a similar line in my dmesg output, but the plugin is not installed.

---<<BOOT>>---
Copyright (c) 1992-2025 The FreeBSD Project.
Copyright (c) 1979, 1980, 1983, 1986, 1988, 1989, 1991, 1992, 1993, 1994
    The Regents of the University of California. All rights reserved.
FreeBSD is a registered trademark of The FreeBSD Foundation.
FreeBSD 15.1-RELEASE-p1 stable/26.7-n283674-12334a596709 SMP amd64
FreeBSD clang version 19.1.7 (https://github.com/llvm/llvm-project.git llvmorg-19.1.7-0-gcd708029e0b2)
[1] VT(vga): resolution 640x480
[1] CPU: Intel(R) Atom(TM) CPU C3558 @ 2.20GHz (2200.21-MHz K8-class CPU)
[1]  Origin="GenuineIntel"  Id=0x506f1  Family=0x6  Model=0x5f  Stepping=1
[1]  Features=0xbfebfbff<FPU,VME,DE,PSE,TSC,MSR,PAE,MCE,CX8,APIC,SEP,MTRR,PGE,MCA,CMOV,PAT,PSE36,CLFLUSH,DTS,ACPI,MMX,FXSR,SSE,SSE2,SS,HTT,TM,PBE>
[1]  Features2=0x4ff8ebbf<SSE3,PCLMULQDQ,DTES64,MON,DS_CPL,VMX,EST,TM2,SSSE3,SDBG,CX16,xTPR,PDCM,SSE4.1,SSE4.2,x2APIC,MOVBE,POPCNT,TSCDLT,AESNI,XSAVE,OSXSAVE,RDRAND>
[1]  AMD Features=0x2c100800<SYSCALL,NX,Page1GB,RDTSCP,LM>
[1]  AMD Features2=0x101<LAHF,Prefetch>
[1]  Structured Extended Features=0x2294e283<FSGSBASE,TSCADJ,SMEP,ERMS,NFPUSG,MPX,PQE,RDSEED,SMAP,CLFLUSHOPT,PROCTRACE,SHA>
[1]  Structured Extended Features3=0xac000400<MD_CLEAR,IBPB,STIBP,ARCH_CAP,SSBD>
...

Thanks a lot!