Quote from: meyergru on February 10, 2026, 10:13:08 PMThis does not look like an MTU issue if you can use those ping sizes - it look just fine.
Did you also use traffic shaping? Maybe the old ISP had lower speeds and you shape it to fit? Happened before...
Just saw that you disabled all shaping...
No idea what could be wrong.
Quote from: meyergru on February 22, 2023, 09:09:46 AMOh, I forgot: You definitely can mix SFP+ 10 Gbps and SFP 1 Gbps in both slots on the DEC7x0: I actually use this with one DAC SFP+ (10GBase-SFI) for LAN and one GPON stick at 1Gbps (technically 1000Base-SGMII) for WAN.
The latter one could even support 2.5 Gbps, but as I said, I never got it running, probably because of the 10 Gbps DAC in the other slot.
Quote from: Boxer on February 10, 2026, 10:00:16 PMI'm on BT PPPOE (Openreach) and just set the wan mtu to 1508 without any issues on websites. Are you on Zen Openreach or Zen City Fibre?
Quote from: coffeecup25 on February 10, 2026, 04:34:22 PMNot to be argumentative but I have been using 5353 for a long time without ill effects. Some 'tutorials' also use it.Just wanted to warn you, because the guys @ https://docs.pi-hole.net/guides/dns/unbound/ made that mistake many years ago and switched from 5353 to 5335 and my guess is OPNsense now uses by default 53053 because of the same reason :)
But I can see your point.
QuoteI have no idea why a port forward is in the mix. I don't use it and never have on either OPNsense or pfSense. As I said , not problems, ever.You don't use any Redirect DNS NAT rules then I am guessing ?
QuoteTo repeat, sometimes there is only one way to do something, but with BSD software there are often lots of ways.Actually if you talk about pure FreeBSD then the explanations written in the FreeBSD Handbook is pretty much the way to do it IMHO : https://docs.freebsd.org/en/books/handbook/
Quote from: Boxer on February 10, 2026, 09:33:10 PMAre you using DNSmasq Router Advertisements or RADVD? I was seeing some peculiarities on some websites unless I explicity set the RA MTU in DNSmasq. Switch to RADVD (if you're using DNSmasq RA) and see if your issues persist