PPPoE over an unassigned VLAN no longer connects after upgrading to 26.7.3

Started by downset, August 27, 2026, 06:14:47 PM

Previous topic - Next topic
Hello,

after upgrading OPNsense from 26.7.2_2 to 26.7.3, my PPPoE WAN connection stopped working completely. Restoring the Proxmox snapshot containing OPNsense 26.7.2_2 immediately restored the connection without any other configuration or network changes.

Environment

- OPNsense running as a virtual machine on Proxmox
- OPNsense 26.7.2_2: working
- OPNsense 26.7.3 or possibly 26.7.3_1: not working
- The exact hotfix revision is unfortunately unknown
- The WAN connection is passed to the VM through Proxmox bridge `vmbr0`
- The optical termination device is a Luleey 2.5G XPON Stick SFP ONU
- The stick is connected to a UniFi switch

Network topology

The connection is approximately:

Luleey XPON stick → UniFi switch → VLAN 10 → Proxmox vmbr0 → OPNsense VLAN 10 → PPPoE → WAN

VLAN 10 is both:

- the transport VLAN between the UniFi switch and OPNsense, and
- the VLAN required for the provider's PPPoE service.

Inside OPNsense, VLAN 10 is created on the interface connected to `vmbr0`. The PPPoE device uses this VLAN device as its link interface. The VLAN 10 interface itself is not assigned as a separate OPNsense interface; only the resulting PPPoE device is assigned as WAN.

A separate native VLAN is present on the switch port for access to the management interface of the XPON stick. This management VLAN remained unchanged and should not be involved in the PPPoE connection.

Actual behaviour with 26.7.3

After installing the update and rebooting:

- the PPPoE connection remained completely offline;
- no WAN connection was established;
- the VLAN 10 device was still used as an unassigned interface underneath the PPPoE device;
- additional reboots did not restore the connection.

No changes were made to the OPNsense configuration, Proxmox networking, UniFi switch configuration or XPON stick configuration.

Unfortunately, I did not save the PPP logs before restoring the snapshot because I needed to restore Internet access.


Rollback result

I restored the complete Proxmox snapshot containing OPNsense 26.7.2_2. The PPPoE WAN connection came back immediately without changing or rebooting the UniFi switch, XPON stick or any other part of the network.

This makes the issue appear specific to the update from 26.7.2_2 to 26.7.3.

The 26.7.3 changelog includes the interface-related change "resolve VLAN devices indirectly via interfaces_configure()". Could this affect PPPoE devices that use an otherwise unassigned VLAN device as their link interface?

best regards

Downset


Thanks for the hint to the git issue.

The patch just released there is fixing the problem.

Thanks for the fast support

best regards


Thanks for the quick fix! Had the same issue, luckily was able to recover by disabling and re-enabling the WAN / PPPoE interface after reboot.

Hi,

I have a very similar problem and hope it's ok to reply to this topic, otherwise I can also open a new one.

So when on 26.7.1 my PPPoE config works fine and the connection comes up. I get an IP from the ISP etc and there is no problem as far as I can see.
But if I'm upgrading to 26.7.5 (I also tried to upgrade to 26.7.4 and 26.7.4_1 before multiple times) the PPPoE always fails. The interfaces are up and if I check the Interface Overview/assignments/etc. everything looks the same for me but I don't get a public IP and the status of the WAN interface on the Dashboard is active but "undefined".

I did some research with AI (in fact Claude, ChatGPT and Gemini) and after I tried all the suggested workarounds the AI always comes to the conclusion this must be a bug.
I'm not sure if this is really true because you know AI always sounds pretty sure about everything but isn't always right and after some research I also read a lot about most problems are more config errors than bugs so I guess this is maybe more my problem.

So from the log I can see that the PPPoE just doesn't work, but I'm not sure why. If I do a diff between 26.7.1 log and 26.7.5 log I can see the order of the log messages regarding the WAN interface and PPPoE is a little different but everything happens at the same second. For the AI this is the root cause as the order has to be different and this is a key problem for my config. But as I already mentioned I'm not really sure about this.

Another potential problem according to the AI is that I have 2 10G interfaces for internal traffic and the WAN interface is only a 1G interface. The AI tells me this is a big problem as the 10G interfaces are seen as priority interfaces and the OPNSense tries to connect via those interfaces instead of the 10G which then fails. But I can't see any hint of that in the log files.

I tried to follow the How To Guide about PPPoE over VLAN but it's already 5 years old and I'm not sure if this is still correct after all those years.

Maybe someone can help me, because I now spent so many hours on that problem that I don't know what options are left to solve this issue.

Many thanks in advance.


Not sure why it considers pppoe0 down/unable to come up, but it's probably hidden somewhere in your setup.

Can you share this from 26.7.5?

# pluginctl -Q


Thanks,
Franco

Hello Franco,

I uploaded the old and the new output of this command.

Hope this helps.

Regards,

Fanski

Hmm, I'm assuming your WAN sits on top of igb0? As far as timings go it seems to be down/up during the course of the initial WAN configuration which is suboptimal for PPPoE.

Can you try to add igb0 to a new interface and simply enable it without doing any other settings? Then try a reboot and see if the problem persists.


Cheers,
Franco

Could actually be a driver bug similar to https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=240818

Because when the VLAN is added it takes down the parent interface, which makes mpd5 dail in vain and then apparently needs a kick to proceed.

<13>1 2026-10-03T10:42:50+02:00 fw-KG.XYZ kernel - - [meta sequenceId="226"] <6>[26] igb0: link state changed to DOWN
<13>1 2026-10-03T10:42:50+02:00 fw-KG.XYZ kernel - - [meta sequenceId="227"] <6>[26] vlan7: changing name to 'vlan0.35'

It's not very easy to work around this in userspace.


Cheers,
Franco

Okay I think I know what's going on... can you try to set "VLAN Hardware Filtering" on Interfaces: Settings to "Leave default" and reboot.

The down/up for igb0 and igb1 are in your .1 log as well, just not as annoying to the boot sequence as on .5.  So we're looking for kernel behaviour instead of anything we've done directly.


Cheers,
Franco

Hi Franco,

Quote from: franco on October 06, 2026, 11:15:17 AMHmm, I'm assuming your WAN sits on top of igb0?
so yes the ONT is connected to igb0.

Quote from: franco on October 06, 2026, 11:48:51 AMcan you try to set "VLAN Hardware Filtering" on Interfaces: Settings to "Leave default" and reboot.
did that and unfortunately it didn't solve the issue. still the same behavior. I also tested it with 26.7.1 and at first everything was working except the internet traffic because of state violations, but after playing with the 3 different options and 3 or 4 reboots it worked without a problem and also after some reboots.

Quote from: franco on October 06, 2026, 11:15:17 AMCan you try to add igb0 to a new interface and simply enable it without doing any other settings? Then try a reboot and see if the problem persists.
I think I already tried this before once or twice as it was a suggested workaround, but I tried again and also with the VLAN Hardware Filtering disabled or leave default but this also had no positive effect.

I attached the logs with the VLAN Hardware Filtering default option, and the ones with the dummy interface.

Regards,

Fanski