Recent posts

#81
General Discussion / Re: Tailscale advertised route...
Last post by endurium - August 09, 2026, 05:41:32 PM
I tried connecting to another device on the WLAN network from a Tailscale-connected device and it worked fine so it looks like Tailscale is routing traffic correctly, it just doesn't work when connecting to the ASUS AiMesh access point so I'm guessing the ASUS is refusing to play ball for security reasons (it's a router configured as a WiFi access point).
#82
26.7 Series / Re: Call for testers - new CPU...
Last post by Patrick M. Hausen - August 09, 2026, 03:56:53 PM
You can skip the boot loader update because OPNsense shipped a workaround in 26.7.1 by late loading of the ucode update.

But if you want to use early loading via loader.conf.local you must update the boot loader first.

Abd yes, the ucode update plugin must be uninstalled before rebooting any system with a boot loader older than 26.7 but 26.7  now active because of an OPNsense update.

How many more times do I need to repeat this? 😉
#83
26.7 Series / Re: Renewed server certificate...
Last post by userfw - August 09, 2026, 02:15:35 PM
I'm getting the same error trying to renew the GUI self-signed cert.
The release notes for 26.7 mentioned the upgrade of openssl to 3.5 and possible issues, maybe related to this and the other thread about exporting OpenVPN profiles?
#84
Portuguese - Português / Re: Failover dual-WAN automáti...
Last post by KugmBewg - August 09, 2026, 02:14:58 PM
Também estou testando uma configuração parecida com fibra como principal e 5G como backup. O failover para o 5G funciona quando desligo a fibra, mas quando a fibra volta nem sempre o tráfego retorna imediatamente para ela. Alguém já passou por isso? Tem alguma configuração específica no gateway group para o retorno ao Tier 1 funcionar de forma mais consistente?
#85
Q-Feeds (Threat intelligence) / Re: Help fixing 'erroneous' Q-...
Last post by Taunt9930 - August 09, 2026, 01:07:02 PM
Quote from: vk2him on August 09, 2026, 12:14:10 AMI searched the qfeeds block file and 43.131.7.8 isn't contained there.

virustotal.com also shows zero reported security issues wirh that ip

Vendors Analysis:
No security vendors flagged this URL as malicious
Final URL:
http://43.131.7.8/
Domain:
43.131.7.8

Look at your logs to see why it's being blocked for you?

All of that is in my original post.

It is being blocked by the qfeeds rule - as indicated by the firewall log, and as indicated by being in the qfeeds event list - despite, as I said above, not being on the IOC list, or the qfeeds alias list on the device itself.

Disabling the qfeeds rule resolves the problem.
#86
26.7 Series / Re: Call for testers - new CPU...
Last post by PencilHCV - August 09, 2026, 09:41:01 AM
Hi all!
this by:
1.-uninstall CPU-Microcode
2.-Upgrade to 26.7.1
3.-Update Boot Loader
4.-Install CPU- Microcode
Do we always have to do this when updating to ver. 26.7.1 or will there be a new version of OPNsense that will work without all the above steps?
Best regards!
//Hugo
#87
26.7 Series / Re: Internal DNS only works fo...
Last post by chrisgtl - August 09, 2026, 08:41:39 AM
Not sure why this isn't working for you. I can resolve without using FQDN.

❯ ping ap
PING ap.internal (10.10.2.4) 56(84) bytes of data.
64 bytes from ap (10.10.2.4): icmp_seq=1 ttl=63 time=0.562 ms
64 bytes from ap (10.10.2.4): icmp_seq=2 ttl=63 time=0.443 ms
#88
General Discussion / Re: nfSensei ( fork pfsense )
Last post by patient0 - August 09, 2026, 07:37:13 AM
Quote from: RES217AIII on August 08, 2026, 10:25:57 PMAt what network size and data throughput does this become relevant?
VPP is a very fast and efficient packet processor and would allow to reach 10Gbit throughput on small, fanless devices.
E.g. the DEC740 can't do 10Gbit with OPNsense (it does 5-6 Gbit) and if the NICs were supported (which they are not) I could saturate my line.

Having said that: VPP seems best suited for routing, since it only supports ACLs (but they seem to be able to do firewall-ish rules).

Two articles about VPP on FreeBSD from Pim van Pelt (who used to run the SIxXS tunnel service with Jeroen Massar) for the interested:

https://ipng.ch/s/articles/2024/02/10/vpp-on-freebsd-part-1/
https://ipng.ch/s/articles/2024/02/10/vpp-on-freebsd-part-2/

He does work and develop for/with VPP (on Debian) and has got a lot of interesting articles about it, in a routing context.
#89
General Discussion / Re: Sonicwall TZ300 compatibil...
Last post by patient0 - August 09, 2026, 07:21:33 AM
Searching the internet for "Sonicwall TZ300 cpu specs" returns https://www.reddit.com/r/sonicwall/comments/m6aemk/ram_and_cpu_specs_of_tz_models/.

It lists a few Sonicwall models, the TZ300 is one of them but there seem to be multiple generation.

QuoteTZ 300 1GB Ram 1.6GHz (2x 800MHz Mips64 Octeon Processor)

If correct, Mips64 would be a show stopper in any case.

Addition: In an TZ300 unboxing video (https://www.youtube.com/watch?v=ath1kafIRVM) at 9:25 it shows in the GUI 2x 800Hz Mips64 Octeon Processor under Dashboard / Multi-Core Monitor. You can verify it yourself if the SonicOS is still on your device.
#90
Hardware and Performance / Re: AX88179B USB NIC: 57 -> 97...
Last post by web - August 09, 2026, 05:44:32 AM
thanks! yeah thats what made me go looking, the numbers just didnt add up for a superspeed link. hope it helps someone else with one of these!!