Recent posts

#1
26.7 Series / Re: nginx plugin -> security h...
Last post by MiRei - Today at 01:59:38 PM
After installing 26.7.1_1 the problem in nginx - Security Headers still exists.

Then I tried to install the patch described on github

opnsense-patch 14710e7

The result:
Patching file opnsense/mvc/app/views/layout_partials/base_tabs_header.volt using Plan A...
Reversed (or previously applied) patch detected!  Assuming -R.Hunk #1 succeeded at 1.
Hunk #2 succeeded at 31.
Hunk #3 succeeded at 54.
done

All patches have been applied successfully.  Have a nice day.

Now, going to Services - Nginx the System always crashed.



#2
26.7 Series / Re: OPNsense Protectli boot fa...
Last post by CursedGravity - Today at 01:43:31 PM
Is that ad guard home? 
Before I did the big recent upgrade (the upgrade wasn't done the same day this crashed - it has been running for some time), I did a config export.  That should have everything I need to restore, right?
#3
26.7 Series / Re: OPNsense Protectli boot fa...
Last post by newsense - Today at 01:39:48 PM
If you have third party apps like AGH don't forget to retrieve the config files.

Otherwise simply install 26.7 and check for updates, install any plugins then import the config.xml.
#4
General Discussion / Re: Help needed to update boot...
Last post by emrion - Today at 01:02:33 PM
Quote from: franco on July 24, 2026, 08:06:42 AMOne thing I wanted to test is if it still works in hybrid UEFI/Legacy boot mode. The standard FreeBSD installers do not work well with cross-booting. Easy to test in a VM.


Cheers,
Franco
As you may have seen, it works perfectly in hybrid configurations.

Some things to know:
- It won't put (or propose) a loader where previously there wasn't one (with an exception for freebsd-boot partition, if you use the -f option). Its goal is only to update.
- It doesn't work on MBR scheme and is likely to never change on this point. This software is only for GPT scheme.
- It supports only amd64 and arm64 arches. Knowing that the support for arm64 is recent and is less tested than amd64.

If you or anyone have any question, I will be pleased to answer.
#5
26.7 Series / Re: slow dhcp on wan -> broken...
Last post by lmoore - Today at 12:55:29 PM
Quote from: meyergru on Today at 10:17:54 AMBridge mode of course
Just as I thought.

Thanks for the info re your ONT.

I would expect your Internet traffic will be communicating using the MAC addresses of your WAN port and your ISP's gateway, and the MAC on the bridge will only be seen when communicating with the ONT network.

It isn't clear in my mind why your ONT behaviour occurs when a bridge is used and is for traffic within its network, as opposed to a VIP. Maybe its simply "It is what it is".

On my DSL modem, I have it configured to synchronise its time from the firewall as well as dispatching events to syslog on an internal server, so there is constant activity from the modem to the firewall.
#6
Tutorials and FAQs / Re: [How-To] NPTv6 with dynami...
Last post by Maurice - Today at 12:37:57 PM
You can create an NPT rule for a single /64 using the loopback method as well. That's not unique to the WAN tracking method.

And you can create an NPT rule for a shorter prefix using the WAN tracking method as well, in which case it's up to the user to avoid any collisions. That's not unique to the loopback method.

But I get what Franco said: Someone wanted that feature and now it's there. Nothing wrong with having options.
#7
26.1, 26,4 Series / Re: IPv6 breaks after a while ...
Last post by DWM89 - Today at 12:34:34 PM
hello again!

so i finally had the time to tackle the upgrade to 26.7 and do some testing while not being dependent on ipv6 for a little wile and still the same problem:

i get an IPv6 address on WAN but not on lan, neither with track interface nor with identity association.
also i cannot ping anything via IPv6 from the console on the opnsense itself.

current IPs i get on the WAN:
x:8101:3ff:fc7c:2a5:69ff:fe87:c47a/64
fe80::2a5:69ff:fe87:c47a/64

and my IPv4/30


what could i do next to get this working?
any ideas?
#8
German - Deutsch / Re: Problem oder verständnispr...
Last post by magicas - Today at 12:12:10 PM
Ich versuchs einmal.
Ich denke ich habe es verstanden.
#9
26.1, 26,4 Series / Re: Use Wireguard from Inside ...
Last post by dseven - Today at 12:02:43 PM
WG works from LAN for me, without any port forwarding, or anything else special that I can think of... the typical default rule to allow from LAN to "any" should cover it, I think.
#10
Global: Firewall > Settings > Advanced > Disable reply-to - das sollte nicht gesetzt sein.

Pro Regel: Firewall > Rules > Interface Rules > Regel anklicken > oben links "advanced" einschalten > Source Routing

Bei letzterem kannst du auch einfach nur den Gateway setzen, der benutzt werden soll. Du brauchst wie gesagt für jeden WAN-Anschluss und jeden Dienst je eine Destination NAT Regel und eine dazugehörige Firewall Regel.