Recent posts

#1
General Discussion / Re: nfSensei ( fork pfsense )
Last post by RES217AIII - August 08, 2026, 10:25:57 PM
Quote from: Nullman on August 08, 2026, 02:13:03 PMIt will support VPP, and thats something that BSDs dont have.

At what network size and data throughput does this become relevant?
#2
General Discussion / Re: Sonicwall TZ300 compatibil...
Last post by pfry - August 08, 2026, 10:06:17 PM
It would probably be a challenge. I can't find a hardware spec offhand, but 2 or 4 cores at 400, 800, or 1000MHz sounds like an embedded device, most likely ARM32. Ethernet is likely provided by a switch chip. Neither device type is well supported by FreeBSD (or any other general-application OS).
#3
26.7 Series / Re: VLAN devices are on LAN IP...
Last post by tonys - August 08, 2026, 09:51:39 PM
Quote from: meyergru on August 08, 2026, 09:00:10 AM
Quote from: tonys on August 08, 2026, 04:19:52 AMHopefully this settles your debate over combining tagged and untagged traffic, LOL.

See you again when this goes horribly wrong and you do not even remember what you did to make that possible. We never said it was not feasible, but depending on what you do, there can be lots of problems. This may be influenced by your NIC hardware on OpnSense, and is especially true for Unifi switches, which have all kinds of problems with VLANs. If you want a taste of it, look here.

The current switch software releases of some switch models have a problem separating untagged and tagged LANs during switch startup. Depending on the startup order of your machines, they can get IPv4 from any of your VLANs (since all of them are presented untagged). With 802.1x enabled, you may see all IPv6 prefixes at once on untagged ports.

But, as Patrick often says: You do you, LOL. The advice given in here is free - and you are also free to take it or leave it.


I'm not using a Unifi nor other switch and have no requirement for one in the foreseeable future. My AP is the Unifi Pro 7 wireless (UFO style) on one Protecli port and my entire network is wireless with the sole exception of an internet-facing OpenVPN Access Server which is on its own dedicated Protecli port.
#4
General Discussion / Sonicwall TZ300 compatibility
Last post by HiddenJoker - August 08, 2026, 08:49:25 PM
Hello,
I am new to this forum and have a question to the Sonicwall TZ300 which i currently have (not actively running, just got it for free).
Is it possible to get OPNsense running on it?

Modelnumber would be:APL28-0B4

Thanks in advance :)
#5
Virtual private networks / Re: wireguard freebsd wg(4) CV...
Last post by paepcke - August 08, 2026, 07:30:55 PM
Quote from: userfw on August 03, 2026, 12:08:51 PMIt's a vulnerability that defeats the purpose of a VPN.

To clear, this bug does only impact the data *authentication* check of the stream cipher on data inbound side -  not the data *encryption* itself!

This bug does NOT leaked direct any information or allowed to manipulate any information without breaking the private / session key first.

This bug (or bug-door) allowed to trick the server to process (parse) unauthenticated data.

Thats bad! But to exploit this, at least some weeks ago, some nation-state-actor level know-how was needed.

With the now publicly accessible open weight ai models it's direct, one shot and reliable reproduce able, possible for *everyone* to directly identify this bug - including a detailed report about the complete implications further down the process chain ...

So, yes. Patch and back port. NOW!
#6
26.7 Series / Re: legacy ipsec settings on 2...
Last post by tentpig - August 08, 2026, 07:16:47 PM
Quote from: nero355 on August 08, 2026, 01:36:51 PMThere has been a lot of IPSec talk lately because of some issues and there is also the fact that there are both a Legacy and a Current way to set things up IIRC so you need to figure all that stuff out first before you start !!

Unfortunately, I see no way to activate any form of "legacy" settings. All attempts to google this yield references to a page in OpnSense which apparently no longer exists, and a few results indicate the functionality was folded into the Connections page. However, on the Connections page, although there is a AES256-SHA1 setting in the drop-down, there's no way to select DH2 (which I believe translates into modp1024). Thus when I attempt to connect, I get a NO_PROPOSAL error.

I really, really, really do not want to have to regress to pfSense to resolve this. I've asked the client to upgrade their IPSEC hardware but that is going to take time for approvals and what not.
#7
26.7 Series / Re: VLAN devices are on LAN IP...
Last post by dseven - August 08, 2026, 06:53:16 PM
That appears to be a discussion thread for an early access release of the switch firmware. The models listed would be those for which that release is/was available.

Google AI tells me that the "Flex" and "Ultra" switches use cheap Realtek SoCs, which default to acting as a dumb switch until the OS and software finish booting and tell them what to do, and that the Pro and Enterprise models use Marvell or Broadcom ASICs, which are flash-backed, and start up already knowing what to do. I don't necessarily believe that this is entirely accurate, but it seems plausible...
#8
General Discussion / Re: Allow Public Internet IPv4...
Last post by patient0 - August 08, 2026, 06:05:22 PM
Quote from: Patrick M. Hausen on August 08, 2026, 04:39:01 PMWhy are people all of a sudden using the exact same overspecific template to ask simple questions on this forum?
I'm sure it's AI generated from a users question.
#9
General Discussion / Re: Allow Public Internet IPv4...
Last post by nero355 - August 08, 2026, 05:37:27 PM
Quote from: Patrick M. Hausen on August 08, 2026, 04:39:01 PMWhy are people all of a sudden using the exact same overspecific template to ask simple questions on this forum? I'm tired of reading through all this nonsense and might not provide answers anymore. Hint: this is not helpful.
+1 :)

I don't like to scroll through stuff that downgrades any monitor/screen to a 320x240 resolution !!!

W-T-F ?!?! :(
#10
German - Deutsch / Re: Vielleicht ein Problem mit...
Last post by Monviech (Cedrik) - August 08, 2026, 05:37:16 PM
Kein Problem, hatte das öfters im Support das Problem gerade mit SIP und auch mit RADIUS.

Schönes Wochenende :)