Recent posts

#1
26.1, 26,4 Series / Re: DEC840 slow upload test wh...
Last post by tedhughes - Today at 04:02:01 AM
Reviving this because I have the same symptom on the same hardware, and I've been able to rule out a lot of the variables you couldn't.

Setup
  • DEC840, WAN on ax0, LAN on ax1 (8 tagged VLANs + untagged LAN)
  • 8 Gbps symmetrical fiber, static /26, no PPPoE (key difference from OP's setup)
  • WAN transceiver: FS SFP-10G-T (30m), on Deciso's tested-modules list for the DEC800 series
  • LAN: passive SFP+ DAC to a UniFi 10G switch

Symptom

Download 3.5-4.7 Gbps. Upload pinned at ~600-870 Mbps, consistently, regardless of test method or target. Notably it has twice briefly exceeded 1.1 Gbps mid-test before collapsing back — so it behaves like a dynamic loss mechanism, not a static cap.

The control test that matters

A Mac Studio connected directly to the ONT — same static IP, same cable, same ONT port — gets ~6 Gbps in both directions. Circuit, provisioning, and the ISP upload policer are all demonstrably fine. The cap only appears when traffic passes through the DEC840.

What I've ruled out (all measured, not assumed)
  • Forwarding capacity — iperf3 Mac <-> OPNsense, 8 streams: 9.11 Gbit/s aggregate
  • LAN segment / DAC / switch — single stream: 2.65 Gbps up / 4.09 Gbps down, ~0 retransmits
  • Interface errors — netstat -i -I ax0 -w 1 during sustained upload: zero errs, zero idrops, both directions
  • CPU — top -aSH during upload: all cores essentially idle
  • Shaper — pfctl -sq empty, no pipes/queues configured
  • IDS/IPS/DPI — Suricata, Zenarmor, ntopng all stopped, nothing attached via netmap
  • Hardware offload — CRC/TSO/LRO disabled, verified absent from ifconfig flags: no change
  • pf scrub — disabled: no change
  • MSS — SYN-ACKs show mss 1460, not clamped
  • VPN policy routing — LAN clients egress the correct static IP
  • Flow control — dev.ax.0.rx_pause/tx_pause=1 + reboot: no change, media line reports rxpause,txpause regardless

Packet-level finding

tcpdump on ax0 during upload shows SACK blocks in the returning ACKs across multiple independent flows:

sack 1 {73849:78193}
sack 1 {53577:75297}
sack 1 {73849:101361}

Receivers are reporting gaps in the upload stream — frames leave ax0 and don't all arrive, while every counter on my side stays clean. Advertised receive windows on those flows also shrink under load (2045 -> 2003 -> 1972). Per-flow throughput works out to roughly 120-160 Mbit/s; 4-5 parallel flows sums to the observed ceiling.

Version ladder (tested identically at each step)


Version  FreeBSD base  Upload
24.7.7  14.1  ~600 Mbps
24.7.12  14.1  ~600 Mbps
25.1.12  14.2  ~600 Mbps

Continuing up the ladder; will update with results.

Tunables — factory Deciso defaults, unmodified:

dev.ax.0/1.iflib.override_nrxds = 2048 x8
dev.ax.0/1.iflib.override_ntxds = 2048 x8
dev.ax.0/1.link_workaround = 1
dev.ax.sph_enable = 0

Where this leaves it

The OP's switch-bypass test (ONT -> switch -> DAC -> SFP+, no copper transceiver in the path) produced no change, which points away from the transceiver and toward the ax TX path itself. I'm running the equivalent test on my side and will report back.

Two questions for anyone who's been here:

1. Has anyone with a DEC840/DEC850 achieved sustained multi-gig upload on ax0 with a real WAN — and if so, on what version?
2. Is there any known asymmetry in how axgbe handles TX for forwarded/NAT'd traffic vs locally-originated? Everything I can measure says the interface is healthy and the packets simply don't all survive the trip.

Happy to provide full pcaps or run any test that would help.
#2
26.7 Series / Dashboard services widget unre...
Last post by erwinvanlonden - Today at 03:57:25 AM
With the latest update the services widget content becomes nearly unreadable since the contrast between the background and characters is nearly the same. Can this be adjusted in some way. I assume it's some CSS value initiated in some js script.

#3
26.7 Series / Re: 26.7 DHCP WAN gateway onli...
Last post by RedVortex - Today at 02:41:07 AM
Patch 26.7.1_1 fixes this issue
#4
26.7 Series / Re: 26.7 Default Gateway no lo...
Last post by RedVortex - Today at 02:40:30 AM
Quote from: franco on July 23, 2026, 08:40:08 PMNote that due to 26.7.1(_1) not rebooting you need to restart the "Gateway Watcher" service to apply the fix.  It also has to be _1 specifically. .1 doesn't have the fix.

I also confirm that 26.7.1_1 fixes this issue, thanks Franco !
#5
General Discussion / Re: Periodic NIC issues (?) wi...
Last post by fornax - Today at 02:05:14 AM
First time for everything, I guess... yesterday I had an issue that was only resolved after bouncing the WAN interface instead of LAN like every other time. In a fit of frustration I reinstalled the OS today, so it's on a fresh 26.7. That should rule out OS corruption or weird config issues from me tinkering with things. I also installed the -igc2 kernel. Will continue to monitor.
#6
26.7 Series / Re: Update to 26.7 fails and c...
Last post by richaras - Today at 01:55:29 AM
if you were able to go back to a running environment using a snapshot...I would remove the os-cpu-microcode-intel plugin, run a health check...if all is good, try the upgrade again...I have read where many people had isues with the intel microcode installed...once removed , the upgrade worked...Good Luck.
#7
General Discussion / Re: Rules under version 27
Last post by MoonbeamFrame - Today at 12:35:42 AM
As per the release notes:

Quotefirewall: legacy rules pages move to plugin

Look for:

os-firewall-legacy
#8
General Discussion / Rules under version 27
Last post by headbanger - Today at 12:24:47 AM
I know when version 26 rolled out Rules[New] was added.  I never migrated and kept using the legacy rules.  Now I am on version 27 and I am unable to edit any rules.  Rules [New] and Rules legacy are gone and there is only Rules.  Do I now have to do a migration?  I see migration assistant.  It talks about exporting the rules, editing the rules and then importing them.  Don't know how to edit them in XML.  I already did an export of te entre configuration.  Am I safe ub assuming that is I mess this up I can import the configuration and get back to where I am?  Any help would be appreciated.
#9
26.7 Series / Update to 26.7 fails and canno...
Last post by ANOMPI - July 26, 2026, 11:01:08 PM
Hello,

I have several OPNsense firewalls and most of them do upgrade from 26.1 to 26.7 but one fails, scrolling on the console goes very fast, so I captured it in a video and hope that it helps to give me some hints.  For now i roll back a snapshot of this opnsense unit.

https://drive.google.com/file/d/1jjizi3W1PxyN8KlQsWSi4uj2NHP8QHeX/view?usp=drivesdk

At 1:30 the config is not loaed, configd is not started?  Seen that with other updates as well, but via Ctrl-C (2:28) and after reboot going into single user mode check if config is there and then reboot again solved it for my other routers.
Then at 3:00 i see some errors and I step into single user mode
Then at 5:34 the last part of logging appears with several errors, about dnsmasq and setup_hostwatch.sh and then the login prompt, but the prompt does not accept my password, nor the default opnsense password.

And no WebGUI available as well, as if network adapters are not initialized it seems.

As side note, Zenarmor is installed, but it was installed on another node as well and did not give issues.


What to do?
#10
26.7 Series / Re: slow dhcp on wan -> broken...
Last post by lmoore - July 26, 2026, 11:00:34 PM
@meyergru & @patrick - Thank you!

I would think of the bridge more as a simple switch interface in this set up.

It would be nice if the vether-kmod could be fixed to work with FreeBSD 15 & 16 as it would make for a cleaner configuration.