Recent posts

#91
I know the path: in fact, this message help me (install AMD microcode) : https://forum.opnsense.org/index.php?msg=254780
Now, dashboard shows me temperature for each core (CPUx) and an AMD0 unit.
#92
26.1 Series / Re: internet stops! pf_test: ...
Last post by franco - Today at 11:08:09 AM
If you reboot and re-enable Suricata it should be stable now IMO.
#93
26.1 Series / Re: internet stops! pf_test: ...
Last post by RamSense - Today at 11:06:30 AM
ok, I have cleared the model data for OpnVPN.

So there was a migration error with opnvpn, but is that also related to the suricata and wan going down after a minute when suricata is running at reboot? My system runs stable now with suricata disabled.
#94
26.1 Series / Re: UI lockout after 26.1 upgr...
Last post by d0shie - Today at 11:06:12 AM
Coming from this PPPoE connection timeout thread, I've tried the above commands and got nothing for the first one, with indication of migration problems in the second. Here's the (hopefully) relevant log output when it happened:
2026-01-30T01:45:00 Notice kernel <118>[25] *** OPNsense\Interfaces\Settings migration failed from 0.0.0 to 1.0.0, check log for details
2026-01-30T01:45:00 Notice kernel <118>[25] Migrated OPNsense\Firewall\DNat
2026-01-30T01:45:00 Notice kernel <118>[25] Migrated OPNsense\IDS\IDS from 1.1.1 to 1.1.2
2026-01-30T01:45:00 Error config #2 {main} )
2026-01-30T01:45:00 Error config #1 /usr/local/opnsense/mvc/script/run_migrations.php(54): OPNsense\Base\BaseModel->runMigrations()
2026-01-30T01:45:00 Error config #0 /usr/local/opnsense/mvc/app/models/OPNsense/Base/BaseModel.php(939): OPNsense\Base\BaseModel->serializeToConfig()
2026-01-30T01:45:00 Error config Stack trace:
2026-01-30T01:45:00 Error config   in /usr/local/opnsense/mvc/app/models/OPNsense/Base/BaseModel.php:814
2026-01-30T01:45:00 Error config Model OPNsense\Interfaces\Settings can't be saved, skip ( OPNsense\Base\ValidationException: [OPNsense\Interfaces\Settings:dhcp6_norelease] Value should be a boolean (0,1).{yes}
#95
26.1 Series / Re: Post upgrade steps for ZFS...
Last post by OPNenthu - Today at 11:04:45 AM
Quote from: Patrick M. Hausen on Today at 10:55:50 AMYou only need to update the boot loader if the ZFS features of your local pool change.

Unless we do this manually for some reason, is there ever a need to do this after a major version upgrade (of say FreeBSD)?

How would we know from the OPNsense upgrade process if this needs to be done?  Are there warnings posted somewhere, like in the release notes?
#96
26.1 Series / Re: MiniUPNPD
Last post by burre90 - Today at 11:04:38 AM
I had some spare time, so I set up a fresh USB install of OPNsense 26.1 with the default config/settings to test UPnP behavior.

here is the log:

2026-01-30T10:00:39    Error    miniupnpd    pfctl_get_rules_info: Invalid argument
2026-01-30T10:00:39    Error    miniupnpd    pfctl_get_rules_info: Invalid argument
2026-01-30T10:00:39    Error    miniupnpd    pfctl_get_rules_info: Invalid argument
2026-01-30T10:00:36    Error    miniupnpd    pfctl_get_rules_info: Invalid argument
2026-01-30T10:00:36    Error    miniupnpd    pfctl_get_rules_info: Invalid argument
2026-01-30T10:00:36    Error    miniupnpd    pfctl_get_rules_info: Invalid argument
2026-01-30T10:00:33    Error    miniupnpd    pfctl_get_rules_info: Invalid argument
2026-01-30T10:00:33    Error    miniupnpd    pfctl_get_rules_info: Invalid argument
2026-01-30T10:00:33    Error    miniupnpd    pfctl_get_rules_info: Invalid argument
2026-01-30T10:00:33    Error    miniupnpd    pfctl_get_rules_info: Invalid argument
2026-01-30T10:00:33    Error    miniupnpd    pfctl_get_rules_info: Invalid argument
2026-01-30T10:00:22    Error    miniupnpd    pfctl_get_rules_info: Invalid argument
2026-01-30T10:00:18    Error    miniupnpd    pfctl_get_rules_info: Invalid argument
2026-01-30T10:00:18    Error    miniupnpd    ioctl(dev, DIOCCHANGERULE, ...) PF_CHANGE_GET_TICKET: Invalid argument
2026-01-30T10:00:18    Error    miniupnpd    pfctl_get_rules_info: Invalid argument
2026-01-30T10:00:18    Error    miniupnpd    pfctl_get_rules_info: Invalid argument
2026-01-30T10:00:18    Error    miniupnpd    pfctl_get_rules_info: Invalid argument
2026-01-30T10:00:18    Error    miniupnpd    pfctl_get_rules_info: Invalid argument
2026-01-30T10:00:18    Error    miniupnpd    pfctl_get_rules_info: Invalid argument
2026-01-30T10:00:18    Error    miniupnpd    pfctl_get_rules_info: Invalid argument
2026-01-30T10:00:17    Error    miniupnpd    pfctl_get_rules_info: Invalid argument
2026-01-30T10:00:17    Error    miniupnpd    pfctl_get_rules_info: Invalid argument
2026-01-30T10:00:17    Error    miniupnpd    pfctl_get_rules_info: Invalid argument
2026-01-30T10:00:17    Error    miniupnpd    pfctl_get_rules_info: Invalid argument
2026-01-30T09:59:38    Error    miniupnpd    pfctl_get_rules_info: Invalid argument
2026-01-30T09:59:37    Error    miniupnpd    pfctl_get_rules_info: Invalid argument
2026-01-30T09:59:37    Error    miniupnpd    pfctl_get_rules_info: Invalid argument
2026-01-30T09:59:36    Error    miniupnpd    pfctl_get_rules_info: Invalid argument
2026-01-30T09:59:35    Error    miniupnpd    pfctl_get_rules_info: Invalid argument
2026-01-30T09:59:28    Error    miniupnpd    pfctl_get_rules_info: Invalid argument
2026-01-30T09:59:28    Error    miniupnpd    could not open lease file: /var/run/miniupnpd.leases-ipv6
2026-01-30T09:59:28    Error    miniupnpd    could not open lease file: /var/run/miniupnpd.leases


#97
26.1 Series / Re: internet stops! pf_test: ...
Last post by franco - Today at 11:01:58 AM
If you don't need OpenVPN anymore consider clearing the model data using System: Configuration: Defaults: Components.  That would squelch the error.


Cheers,
Franco
#98
Quote from: BeTZe313 on Today at 09:42:26 AMStimmt natürlich auch wieder. Was ich eben auch entdeckt habe ist, dass auf der OPNsense ein Gateway eingetragen ist. Und zwar ist das der Speedlink.
Brauche ich dann das mit dem PPPoE auf der OPNsense überhaupt?

Nein, natürlich nicht. Die Idee bei Nutzung einer OPNsense ist aber, den Provider-Router zu ersetzen. Wozu ist deine OPNsense denn da, wenn du einen Router hast?

Quote from: BeTZe313 on Today at 09:42:26 AMUnd einmal zum tcpdump. Mache ich das aus meinem Netz raus? Oder von außen in mein Netz?

Du machst das auf der OPNsense während du versuchst, von außen (das ist ja das, was nicht funktioniert) auf den Server zuzugreifen.
#99
26.1 Series / Re: internet stops! pf_test: ...
Last post by RamSense - Today at 11:00:02 AM
done.

# pluginctl -m
[OPNsense\OpenVPN\OpenVPN:Overwrites.Overwrite.2dc86d44-1ea6-4e23-a378-2596d7d0f907.servers] Option [1] not in list.{1}
[OPNsense\OpenVPN\OpenVPN:Overwrites.Overwrite.4165f0ee-e909-44dd-93c1-fc0578f52cc6.servers] Option [1] not in list.{1}
Model OPNsense\OpenVPN\OpenVPN can't be saved, skip ( OPNsense\Base\ValidationException: [OPNsense\OpenVPN\OpenVPN:Overwrites.Overwrite.2dc86d44-1ea6-4e23-a378-2596d7d0f907.servers] Option [1] not in list.{1}
[OPNsense\OpenVPN\OpenVPN:Overwrites.Overwrite.4165f0ee-e909-44dd-93c1-fc0578f52cc6.servers] Option [1] not in list.{1}
 in /usr/local/opnsense/mvc/app/models/OPNsense/Base/BaseModel.php:814
Stack trace:
#0 /usr/local/opnsense/mvc/app/models/OPNsense/Base/BaseModel.php(939): OPNsense\Base\BaseModel->serializeToConfig()
#1 /usr/local/opnsense/mvc/script/run_migrations.php(69): OPNsense\Base\BaseModel->runMigrations()
#2 {main} )
*** OPNsense\OpenVPN\OpenVPN migration failed from 0.0.0 to 1.0.1, check log for details
Migrated OPNsense\Interfaces\Settings from 0.0.0 to 1.0.0

and

# pluginctl -g OPNsense.Interfaces.settings
{
    "@attributes": {
        "version": "1.0.0",
        "persisted_at": "1769767092.37",
        "description": "Global interface settings"
    },
    "disablechecksumoffloading": "1",
    "disablesegmentationoffloading": "1",
    "disablelargereceiveoffloading": "1",
    "disablevlanhwfilter": "1",
    "disableipv6": "0",
    "dhcp6_norelease": "1",
    "dhcp6_debug": "1",
    "dhcp6_duid": "00:03:00:01:38:F9:D3:A7:34:BE",
    "dhcp6_ratimeout": "10"
}


BTW: I am not running OpnVPN (anymore, was years back. I am using Wireguard)

#100
Do you need hostwatch?