OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • Archive »
  • 22.7 Legacy Series »
  • [SOLVED] Has anybody had success with QUIC / HTTP3?
« previous next »
  • Print
Pages: [1]

Author Topic: [SOLVED] Has anybody had success with QUIC / HTTP3?  (Read 1249 times)

meyergru

  • Hero Member
  • *****
  • Posts: 1770
  • Karma: 172
  • IT Aficionado
    • View Profile
    • congenio
[SOLVED] Has anybody had success with QUIC / HTTP3?
« on: January 05, 2023, 08:40:58 pm »
I have a running setup including IPv4 and IPv6, but I cannot for the life of me get QUIC to work.

Whenever I try https://cloudflare-quic.com or https://quic.nginx.org/ or https://http3.is/, nothing really happens.

When I try UDP functionality, it works fine, so I am at a loss as to why this does not work.

Has anyone gotten QUIC / HTTP/3 to work over OpnSense? And if so, how?
« Last Edit: January 09, 2023, 10:57:58 pm by meyergru »
Logged
Intel N100, 4 x I226-V, 16 GByte, 256 GByte NVME, ZTE F6005

1100 down / 440 up, Bufferbloat A+

danderson

  • Full Member
  • ***
  • Posts: 107
  • Karma: 9
    • View Profile
Re: Has anybody had success with QUIC / HTTP3?
« Reply #1 on: January 05, 2023, 08:59:31 pm »
I had to modify my chrome icon using the following command line.

"C:\Program Files\Google\Chrome\Application\chrome.exe" --enable-quic --quic-version=h3-29

then https://cloudflare-quic.com and https://http3.is both reported connected via HTTP/3 QUIC (maybe a refresh as well due to cache)

Using latest Opnsense 22.7.10_2
Logged

meyergru

  • Hero Member
  • *****
  • Posts: 1770
  • Karma: 172
  • IT Aficionado
    • View Profile
    • congenio
Re: Has anybody had success with QUIC / HTTP3?
« Reply #2 on: January 09, 2023, 10:57:07 pm »
Never mind, the problem is not OpnSense, but my Windows installation. Firefox and Chrome should now include QUIC support without further ado.

FWIW: I have tried another fresh Windows and it works, whereas I cannot lie my hand on what is wrong, because the problem occurs on my specific PC with every browser, even fresh installs with no plugins.

I suspect that the network stack is the problem, because there are many packages installed that alter it (e.g. Wireshark, VMware workstation). I have verified that UDP traffic on port 443 passes in and out when I use iperf3  and I also disabled the Windows firewall altogether. The packets do not get send when I use a new version of curl (which seems to use WinSock, like most browsers).

I can see with Wireshark that the UDP packets do not go out, while Windows Firewall log does show that it does not block them, either. I also disabled my Antivirus, to no avail. Maybe there are still some WFP filters active that block outgoing UDP packets in some layer between WinSock and network drivers. Probably those filters are still active even when the Antivirus software is disabled.

I am marking this problem as SOLVED now, because OpnSense is not the culprit.
« Last Edit: January 10, 2023, 02:22:45 am by meyergru »
Logged
Intel N100, 4 x I226-V, 16 GByte, 256 GByte NVME, ZTE F6005

1100 down / 440 up, Bufferbloat A+

meyergru

  • Hero Member
  • *****
  • Posts: 1770
  • Karma: 172
  • IT Aficionado
    • View Profile
    • congenio
Re: [SOLVED] Has anybody had success with QUIC / HTTP3?
« Reply #3 on: January 10, 2023, 10:20:20 am »
OMG. It was Avira. But only in the paid, not in the free version. You have to completely uninstall it to make QUIC work...
Logged
Intel N100, 4 x I226-V, 16 GByte, 256 GByte NVME, ZTE F6005

1100 down / 440 up, Bufferbloat A+

  • Print
Pages: [1]
« previous next »
  • OPNsense Forum »
  • Archive »
  • 22.7 Legacy Series »
  • [SOLVED] Has anybody had success with QUIC / HTTP3?
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2024 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2