Recent posts

#91
25.7, 25.10 Series / Re: CALL FOR TESTING: IPv6 imp...
Last post by franco - January 18, 2026, 01:52:51 PM
Then the code in dhcp6c repo wasn't pulled correctly? Or are you using the "no release" option, too? With that option it is rather hard to do anything sane and I've kept it to use infinite lifetimes otherwise it breaks the promise of the option...

https://github.com/opnsense/dhcp6c/commit/52dfc21489

1.) is still evolving on the master branch. Had a wrong assumption that RENEW would already trigger a full reload but that wasn't the case.

The two commits seem to be needed as well and I'm not sure they apply cleanly to 25.7.11. Still testing a bit.

https://github.com/opnsense/core/commit/c31d9430e
https://github.com/opnsense/core/commit/fafe519de


Cheers,
Franco
#92
25.7, 25.10 Series / Re: 25.7.11 GeoIP
Last post by MoonbeamFrame - January 18, 2026, 01:42:12 PM
And it is working fine for the other firewalls that I already upgraded to 25.7.11

But I won't be doing the rest until I have this one working.
#93
25.7, 25.10 Series / Re: 25.7.11 GeoIP
Last post by meyergru - January 18, 2026, 01:20:18 PM
No, no change there. Yet, for me, GeoIP works fine.
#94
25.7, 25.10 Series / Re: After updating Opnsense fr...
Last post by wide - January 18, 2026, 01:10:36 PM
Hi,

System is fully functional and stable after reboot if I don't open the WebGUI. So clean start and staying away from management keeps the load and memory consumption in similar levels what were before the 25.7.11_1 update. Is it sure that my case is connected to this Neighbors: Automatic Discovery feature?
#95
25.7, 25.10 Series / Re: 25.7.11 GeoIP
Last post by MoonbeamFrame - January 18, 2026, 01:08:40 PM

Did I miss some changes between 25.7.10 and 25.7.11?

The restored config was running as expected on 25.7.10.
#96
25.7, 25.10 Series / Re: 25.7.11 GeoIP
Last post by meyergru - January 18, 2026, 12:57:37 PM
Maybe you wanted to block certain regions from accessing your forwarded ports and forgot that implicit NAT rules are prioritized over interface rules?

In order to make that work, you need to create floating block rules for your WAN interface or use the inverted range in the source part of your NAT rules.
#97
Virtual private networks / Re: Redirect dns traffic throu...
Last post by hushcoden - January 18, 2026, 12:53:05 PM
Quote from: cs1 on January 08, 2026, 02:47:13 PMIf you want to send any local DNS request to a local Unbound through wireguard to an upstream DNS, the easiest way is to use the documentation for wireguard selective routing (https://docs.opnsense.org/manual/how-tos/wireguard-selective-routing.html) and modify it to only tunnel DNS traffic from any firewall IP to the upstream DNS IPs.
Are you referring to the section "Dealing with DNS Leaks"? If so, which of the 5 points/solutions would you recommend?

Tia.
#98
25.7, 25.10 Series / Re: 25.7.11 GeoIP
Last post by MoonbeamFrame - January 18, 2026, 12:39:50 PM

Maybe, but the current dataset was reported to have downloaded.

For both datasets the expected number of ranges are shown in the GeoIP settings tab.
#99
General Discussion / Re: dsnmasq dhcp-script
Last post by Patrick M. Hausen - January 18, 2026, 12:23:21 PM
Put this in the first line of /home/dhcp_lease.pl

#!/usr/local/bin/perl

and make the script file executable (chmod 755). The use only the script path in the configuration.
#100
25.7, 25.10 Series / Re: 25.7.11 GeoIP
Last post by zyon - January 18, 2026, 12:16:22 PM
The free version of the Maxmind database is only updated on Mondays and Fridays, I believe, right?