Recent posts

#1
General Discussion / Re: Support AmneziaWG
Last post by RamSense - Today at 03:41:10 PM
Getting a 404 error on your links
#2
General Discussion / Re: Support AmneziaWG
Last post by franco - Today at 03:34:11 PM
@ViRtI6587 I have removed your accidental double-post on the other topic.
#3
General Discussion / Re: Open CVEs right after upda...
Last post by franco - Today at 03:32:09 PM
Word on the street is that this issue was not backported to 3.13.x and others for fear of regressions. 3.15 is the first fixed Python release with the fix. It gives you a bit of scope regarding the severity of the issue for existing installations discarding the fact that it is about POP3 as Patrick noted.


Cheers,
Franco
#4
26.7 Series / Re: Upgrade 26.1 -> 26.7 boot ...
Last post by nintendoeats - Today at 03:21:43 PM
Hi, I am in the same situation with an HP Gen9. Did you have any luck in the end?

I am not able to get past this even when the drives are connected via generic USB controllers, which I rather hoped would get me at least up and running.

EDIT: I was able to resolve this by removing the SAS HBA and connecting the ports to the onboard SATA controller. Since I kinda meant to do that at some point anyway this is a permanent solution for me.
#5
26.7 Series / Re: os-upnp plugin not working...
Last post by BondiBlueBalls - Today at 03:18:08 PM
UPnP is working and displaying the internal IP again following the 26.7.3_x update. 🎉

You cannot view this attachment.
#6
26.7 Series / Re: PFS in a ip-sec tunnel wit...
Last post by tuto2 - Today at 03:09:07 PM
Make sure the proposals are actually the same for IKE (the connection or phase 1). Seems like it fails there instead of your phase 2, which use a separate set of proposals.
#7
And now for the end of the story:

Last week, I found that my old system (Ryzen 5900X, X570S mainboard, 2x16 GByte DDR-4, RTX3080) used way too much power. Including my monitor, it took 180W from the wall at idle. Therefore, I changed the CPU to an I7-14700K and the mainboard to a B760 variant and kept the rest of the components. I had made that switch from AMD to Intel before with my PVE server and had much less power consumption afterwards.

When sifting through my parts cabinet, I found the RTL8127 again and for the sake of less consumption, used that instead of the Asus XG-C100C. I thought I could safely do that because I suspected the combination of my old mainboard and the adapter to be problematic.

After the rebuild, the system was at 120W, all was well and for the fun of it, I did a test copying data off a samba share and checking its sha256 before and after. Much to my disbelief, the result was defective in ~1 of 2 cases!

After a bit of testing the new platform, I found that the only other remaining commonality was the RAM and went to test it, only to find that both of my RAM strips were defective! Luckily, these were G.Skill Trident Z Neo with a lifetime warranty bought in 2019 and I got an RMA acknowledged.

Alas, during the test, my Windows 11 system was botched again and I had to do a repair install, which cost me 2 days. Now everything works.

I have not had RAM problems in the last 20 years or so and would never have suspected that.

So, the Realtek RTL8127 is all good and working now. I changed the first port to point here...

#8
General Discussion / Re: Support AmneziaWG
Last post by ViRtI6587 - Today at 02:49:02 PM
AmneziaWG 3.1 for OPNsense 26.7 — Public Beta, Testers Wanted

A community beta of os-amneziawg has been published, adding AmneziaWG 3.1 support for OPNsense 26.7 / FreeBSD 15.x amd64.

The runtime uses the amneziawg-go userspace backend, so no AWG kernel module is required. The project includes native FreeBSD/OPNsense packages, AWG 3.1 config import/export, safe Apply with rollback, selective routing through standard OPNsense Aliases/Gateways/Firewall Rules, TUN/UAPI watchdog checks, SHA-256 release verification, and pinned upstream source versions.

Beta1 is built and tested on FreeBSD 15.1 through GitHub Actions. It has also been migrated on a real OPNsense system from an earlier RC installation to the native beta1 packages; the tunnel and selective routing came back up successfully and are working.

The project is still marked as beta because independent testing on different hardware, WAN configurations, and virtualization platforms is needed.

If you test it, I would really appreciate a report including:

* OPNsense and FreeBSD versions
* WAN type: DHCP / PPPoE / static
* fresh installation or migration
* handshake and bidirectional traffic status
* whether selected destinations go through AWG
* whether non-selected traffic still uses the normal WAN
* behavior after reboot
* approximate throughput/speed

There is also an offline installation method for networks where OPNsense fetch cannot reach GitHub because of regional or ISP restrictions, as well as documented safe recovery and uninstall procedures.

This project is not an official component of OPNsense or Amnezia. A significant part of the AWG 3.1 integration, hardening, testing, and documentation was developed and reviewed with the assistance of generative AI. This is disclosed openly in the repository.

Repository:
https://github.com/sergeyvasilev2363-ai/os-amneziawg

Beta release:
https://github.com/sergeyvasilev2363-ai/os-amneziawg/releases/tag/v3.1.2-beta1

Feedback, testing results, bug reports, and code review are very welcome.
#9
Плагин os-amneziawg для протокола AmneziaWG 3.1 на OPNsense 26.7 — public beta, нужны тестеры

Опубликовал community beta os-amneziawg с поддержкой AmneziaWG 3.1 для OPNsense 26.7 / FreeBSD 15.x amd64.

Runtime работает через amneziawg-go userspace, kernel-модуль AWG не требуется. Есть native pkg, AWG 3.1 import/export, безопасный Apply/rollback, selective routing через штатные OPNsense Aliases/Gateway/Firewall Rules, watchdog TUN/UAPI, SHA-256 и pinned upstream source.

Beta1 собирается и тестируется на FreeBSD 15.1 через GitHub Actions. На реальном OPNsense уже выполнена миграция со старой RC-версии на native beta1 packages: tunnel и selective routing поднялись и работают.

Проект пока beta, потому что нужны независимые тесты на другом железе/WAN/виртуализации.

Если протестируете, очень прошу написать: OPNsense/FreeBSD version, WAN DHCP/PPPoE/static, fresh install или migration, handshake/traffic, selected sites через AWG, остальное через WAN, reboot и скорость.

Также есть offline installation для сетей, где OPNsense fetch не может скачать GitHub из-за региональных/ISP ограничений, и безопасное recovery/uninstall.

Проект не является официальным компонентом OPNsense/Amnezia. Значительная часть AWG 3.1 расширения, hardening, тестов и документации была разработана/проверена с помощью генеративного ИИ — это открыто указано в репозитории.

Repository:
https://github.com/sergeyvasilev2363-ai/os-amneziawg

Beta:
https://github.com/sergeyvasilev2363-ai/os-amneziawg/releases/tag/v3.1.2-beta1
#10
Spanish - Español / Actualizar Firmware de OPNsens...
Last post by LACHI06025 - Today at 02:42:28 PM
Buenos dias a todos, soy nuevo en este forum y trabajando con Opnsense, pero necesito una ayuda amigos, soy de Cuba y tengo una problema a la hora de actualizar el Opnsense que yo trabajo a traves de un proxy Padre que está a nivel de país y no me da salida para que Opnsense pueda recibir los datos, en el proxy solo tengo salida http:// y Https:// entonces necesito una ayuda para ver como puedo actualizar mi opnsense a la ultima version. Saludos