Recent posts

#21
26.7 Series / Re: How reliable is Firewall:D...
Last post by franco - Today at 11:32:54 AM
Then I don't understand your report.  It's merely using labels now instead of rule ids and the first post you talk about are different labels for rule id 41 which actually proves that the patch works.


Cheers,
Franco
#22
26.7 Series / Issue upgrading from 26.7.1_1 ...
Last post by john79 - Today at 11:28:05 AM
Anyone else had any issues upgrading and it not being anything already mentioned in the forum? Loading kernel.old doesnt help, only rebooting to a snapshot before upgrading to 26.7.2_2 get my Opnsense up and running again. I had set firmware setting to a specific mirror, but set it back to default and it still get kernel panic after trying to update again

This is what shows just before the kernel panic:

exec /sbin/init: error 8
init: not found in path /sbin/init:/sbin/oinit:/sbin/init.bak:/rescue/init
panic: no init
cpuid = 3
time = 1786695550
KDB: stack backtrace:
db_trace_self_wrapper() at db_trace_self_wrapper+0x2b/frame 0xfffffe00d2e23cd0
vpanic() at vpanic+0x136/frame 0xfffffe00d2e23e00
panic() at panic+0x43/frame 0xfffffe00d2e23e60
start_init() at start_init+0x265/frame 0xfffffe00d2e23ef0
fork_exit() at fork_exit+0xb7/frame 0xfffffe00d2e23f30
fork_trampoline() at fork_trampoline+0xe/frame 0xfffffe00d2e23f30
--- trap 0, rip = 0, rsp = 0, rbp = 0 ---
KDB: enter: panic
[ thread pid 1 tid 100002 ]
Stopped at      kdb_enter+0x33: movq    $0,0x15a8af2(%rip)
db>

Here is info about my system

CPU: Intel N100
NIC: I226-V
Kernel: 15.1-RELEASE-p1
Userland: 15.1-RELEASE-p1
Installed OPNsense package: 26.7.1_1
No microcode or Realtek add-on package
#23
26.7 Series / Re: How reliable is Firewall:D...
Last post by hharry - Today at 11:24:10 AM
Quote from: franco on Today at 11:11:10 AMJust make sure you actually installed the base package please.

# opnsense-version base

If that's the one mentioned above then make sure your labels are appearing in pfctl:

# pfctl -vvs states | grep rlabel

Then make sure your patch is properly applied and not reversed.

I checked the result with a colleague and firewall live log looks as before.

There's no real way for this to go wrong unless at point 1.


Cheers,
Franco

ok @franco, here it is just for you!
root@OPNsense_LAB:~ # opnsense-version base
26.7.2-label
root@OPNsense_LAB:~ # pfctl -vvs states | grep rlabel
No ALTQ support in kernel
ALTQ related functions disabled
   age 00:08:37, expires in 00:00:29, 104:0 pkts, 24128:0 bytes, rule 50, rlabel c0b243c6-f1d4-471d-8dcf-62046c6215b0
   age 00:08:33, expires in 00:00:10, 511:511 pkts, 14819:14819 bytes, rule 32, rlabel 112afb25dbf20a25190de3292c1a37df, allow-opts, max-mss 1452
   age 00:08:21, expires in 23:59:59, 209:208 pkts, 12939:14956 bytes, rule 33, rlabel 112afb25dbf20a25190de3292c1a37df, allow-opts, max-mss 1452
   age 00:08:15, expires in 00:00:58, 61:60 pkts, 7682:10847 bytes, rule 33, rlabel 112afb25dbf20a25190de3292c1a37df, allow-opts, max-mss 1452
   age 00:08:12, expires in 00:00:52, 20:19 pkts, 4284:7382 bytes, rule 33, rlabel 112afb25dbf20a25190de3292c1a37df, allow-opts, max-mss 1452
   age 00:00:53, expires in 24:00:00, 54:78 pkts, 7088:13173 bytes, rule 28, rlabel 36d299b849ebe9b05a0f6345a51a906b
   age 00:00:24, expires in 00:00:06, 1:1 pkts, 53:117 bytes, rule 27, rlabel fcc89aee950e474ad952872fb6c678aa, allow-opts
   age 00:00:24, expires in 00:00:06, 1:1 pkts, 53:165 bytes, rule 27, rlabel fcc89aee950e474ad952872fb6c678aa, allow-opts
   age 00:00:14, expires in 00:00:16, 1:1 pkts, 76:76 bytes, rule 27, rlabel fcc89aee950e474ad952872fb6c678aa, allow-opts
   age 00:00:02, expires in 00:00:08, 1:1 pkts, 29:29 bytes, rule 27, rlabel fcc89aee950e474ad952872fb6c678aa, allow-opts, max-mss 1360
root@OPNsense_LAB:~ #
#24
26.7 Series / Re: How reliable is Firewall:D...
Last post by franco - Today at 11:11:10 AM
Just make sure you actually installed the base package please.

# opnsense-version base

If that's the one mentioned above then make sure your labels are appearing in pfctl:

# pfctl -vvs states | grep rlabel

Then make sure your patch is properly applied and not reversed.

I checked the result with a colleague and firewall live log looks as before.

There's no real way for this to go wrong unless at point 1.


Cheers,
Franco
#25
26.7 Series / Re: How reliable is Firewall:D...
Last post by hharry - Today at 11:06:36 AM
as i already stated @franco, i followed your steps, and the issue still persists, and provided some details and debug data for you, so you can take that feedback or leave it, upto you...
#26
Nice work indeed! If upstream gives you trouble we can consider integrating via our ports tree. Just let me know in a couple of weeks how this progresses.


Thanks,
Franco
#27
26.7 Series / Re: How reliable is Firewall:D...
Last post by franco - Today at 09:20:15 AM
> as my OPNsense is already running 26.7.2_2-amd64, i only need to apply the patch, yes ?

vs.

> # opnsense-update -zbr 26.7.2-label

The answer is no.
#28
26.7 Series / Re: How reliable is Firewall:D...
Last post by hharry - Today at 09:11:07 AM
Quote from: franco on Today at 08:20:23 AM
Quote from: franco on August 13, 2026, 04:21:54 PM# opnsense-update -zbr 26.7.2-label
# opnsense-patch https://github.com/opnsense/core/commit/a698c1d94a
(does not need a reboot)

Please follow these instructions.

Already did, and the issues noted above all still persist.
#29
General Discussion / Re: Let's AI Opnsense!
Last post by meyergru - Today at 08:27:59 AM
1. I hope you are aware of one unsolvable trust problem once the models or # of tokens get too big to handle with a local LLM: Even if you limit the model to read-only access and implement user safeguards a.s.o.: the user must still trust big tech by using their AIs.

Keep in mind, that there are lots of sensitive data in the firewall configurations, ranging from VPN keys to potentially, CA private keys.
To see where I am going with this, just read this in a similarly sensitive context - the author of that tool does either not comprehend of what he is doing or he really is a sock-puppet (also, at the time he first presented his project, he had no verifiable history in the tech community). He even claims that his tool is "The Proxmox MCP you can hand the keys" - yet all of his attempts are futile in that he is neither an expert in Proxmox nor AI models and he cannot even program himself (all is done by Claude).

I sure hope you do not fall for the same misconceptions.

2. That being said, your links do not work at this time. I always get a 404, so I cannot verify or try out anything you have done - I would never do that on a production machine, BTW and urge others to apply the same caution. There have been attempts lately to lure unaware OpnSense users into installing tools on their boxes, up to creating a facade company website with a catchy name. So, I also hope the moderators are closely watching this.

By now, I would say: Let's not AI OpnSense if the MCP server is implemented in a way that makes non-local LLMs neccessary or needs anything installed on the box itself. I know that is a high hurdle, but hey!
#30
26.7 Series / Re: How reliable is Firewall:D...
Last post by franco - Today at 08:20:23 AM
Quote from: franco on August 13, 2026, 04:21:54 PM# opnsense-update -zbr 26.7.2-label
# opnsense-patch https://github.com/opnsense/core/commit/a698c1d94a
(does not need a reboot)

Please follow these instructions.