if you really want to do that and really do it, some users would be very grateful to you. Me too of course! ;-)How can I or how can others keep an eye on the development of this feature? Is there a kind of roadmap or something similar?
Should I only add "LAN" interfaces to "protected"?
Is there a way to "not protect" an IP on a protected interface?
10_DMZ (em0_vlan10) -> v4: 172.16.10.254/24 v6/t6: 2003:f2:63c9:63e1:4c1f:32ff:fe6d:4ae/64 20_VPN (em0_vlan20) -> v4: 172.16.20.254/24 30_Pentest (em0_vlan30) -> v4: 172.16.30.254/24 v6/t6: 2003:f2:63c9:63e3:4c1f:32ff:fe6d:4ae/64 40_WifiGuest (em0_vlan40) -> v4: 172.16.40.254/24 v6/t6: 2003:f2:63c9:63e4:4c1f:32ff:fe6d:4ae/64 50_IoT (em0_vlan50) -> v4: 172.16.50.254/24 v6/t6: 2003:f2:63c9:63e5:4c1f:32ff:fe6d:4ae/64 60_Dev (em0_vlan60) -> v4: 172.16.60.254/24 v6/t6: 2003:f2:63c9:63e6:4c1f:32ff:fe6d:4ae/64 70_WiFi (em0_vlan70) -> v4: 172.16.70.254/24 v6/t6: 2003:f2:63c9:63e7:4c1f:32ff:fe6d:4ae/64 80_Server (em0_vlan80) -> v4: 172.16.80.254/24 v6/t6: 2003:f2:63c9:63e8:4c1f:32ff:fe6d:4ae/64 90_Clients (em0_vlan90) -> v4: 172.16.90.254/24 v6/t6: 2003:f2:63c9:63e9:4c1f:32ff:fe6d:4ae/64 LAN (em0) -> v4: 172.16.17.254/24 v6/t6: 2003:f2:63c9:63e0:4c1f:32ff:fe6d:4ae/64 PIA_VPN (ovpnc1) -> v4: 10.56.10.6/32 WAN (igb0) -> v4: 192.168.217.2/24 v6/DHCP6: 2003:f2:63c9:6300:6eb3:11ff:fe1b:aedf/64
# uname -aFreeBSD surtur.my-network.de 11.2-RELEASE-p9-HBSD FreeBSD 11.2-RELEASE-p9-HBSD 4ea457eb7b8(master) amd64
658.955704 [2909] netmap_transmit igb3 from_host, drop packet size 541392904 > 2048683.531482 [2909] netmap_transmit igb3 from_host, drop packet size 541392904 > 2048
Mar 22 18:13:25 opnsense: /usr/local/etc/rc.newwanipv6: Dynamic DNS: updatedns() startingMar 22 18:13:25 opnsense: /usr/local/etc/rc.newwanip: ROUTING: skipping IPv6 default routeMar 22 18:13:25 opnsense: /usr/local/etc/rc.newwanip: ROUTING: skipping IPv4 default routeMar 22 18:13:25 opnsense: /usr/local/etc/rc.newwanip: ROUTING: no IPv6 default gateway set, assuming wanMar 22 18:13:25 opnsense: /usr/local/etc/rc.newwanip: ROUTING: IPv4 default gateway set to wanMar 22 18:13:25 opnsense: /usr/local/etc/rc.newwanip: ROUTING: entering configure using 'opt4'Mar 22 18:13:25 opnsense: /usr/local/etc/rc.newwanip: On (IP address: X.X.X.X) (interface: XXXXX[opt4]) (real interface: ovpnc2).Mar 22 18:13:25 opnsense: /usr/local/etc/rc.newwanip: IP renewal is starting on 'ovpnc2'Mar 22 18:13:25 kernel: ovpnc2: link state changed to UPMar 22 18:13:24 opnsense: /usr/local/etc/rc.newwanipv6: Dynamic DNS: (Success) X.X.X updated to X.X.X.XMar 22 18:13:24 opnsense: /usr/local/etc/rc.newwanipv6: Dynamic DNS: updating cache file /var/cache/dyndns_wan_X.X.X_0.cache: X.X.X.XMar 22 18:13:21 kernel: ovpnc2: link state changed to DOWNMar 22 18:13:21 opnsense: /usr/local/etc/rc.newwanipv6: Resyncing OpenVPN instances for interface WAN.
Mar 22 18:15:55 dhcp6c: dhcp6c REQUEST on igb0 - running newipv6Mar 22 18:15:55 dhcp6c[89888]: add an address 2605:X:X:36:1de7:22c5:7284:90a5/128 on igb0Mar 22 18:15:55 dhcp6c[89888]: add an address 2605:X:X:a900:4262:31ff:fe00:7873/64 on igb1Mar 22 18:15:55 dhcp6c[89888]: add an address 2605:X:X:a9ec:4262:31ff:fe00:7874/64 on igb2_vlan55Mar 22 18:15:55 dhcp6c[89888]: add an address 2605:X:X:a9ef:4262:31ff:fe00:7874/64 on igb2_vlan200Mar 22 18:15:55 dhcp6c[89888]: Received REPLY for REQUESTMar 22 18:15:55 dhcp6c[89888]: Sending RequestMar 22 18:15:55 dhcp6c[89888]: Sending SolicitMar 22 18:15:54 opnsense: /usr/local/etc/rc.linkup: ROUTING: skipping IPv6 default routeMar 22 18:15:54 opnsense: /usr/local/etc/rc.linkup: ROUTING: skipping IPv4 default routeMar 22 18:15:54 opnsense: /usr/local/etc/rc.linkup: ROUTING: no IPv6 default gateway set, assuming wanMar 22 18:15:54 opnsense: /usr/local/etc/rc.linkup: ROUTING: IPv4 default gateway set to wanMar 22 18:15:54 opnsense: /usr/local/etc/rc.linkup: ROUTING: entering configure using 'lan'Mar 22 18:15:54 dhcp6c[89888]: failed to remove an address on igb1: Can't assign requested addressMar 22 18:15:54 dhcp6c[89888]: remove an address 2605:X:X:a9ec:X:31ff:fe00:7874/64 on igb2_vlan55Mar 22 18:15:54 dhcp6c[89888]: remove an address 2605:X:X:a9ef:X:31ff:fe00:7874/64 on igb2_vlan200Mar 22 18:15:54 dhcp6c[89888]: Sending ReleaseMar 22 18:15:54 dhcp6c[89888]: Start address releaseMar 22 18:15:54 dhcp6c[89888]: remove an address 2605:X:X:X:1de7:22c5:7284:90a5/128 on igb0Mar 22 18:15:54 dhcp6c[89888]: Sending ReleaseMar 22 18:15:54 dhcp6c[89888]: Start address releaseMar 22 18:15:54 dhcp6c[89888]: restartingMar 22 18:15:54 opnsense: /usr/local/etc/rc.linkup: HOTPLUG: Configuring interface lanMar 22 18:15:54 opnsense: /usr/local/etc/rc.linkup: DEVD Ethernet attached event for lanMar 22 18:15:54 kernel: igb1: link state changed to UPMar 22 18:15:50 opnsense: /usr/local/etc/rc.linkup: DEVD Ethernet detached event for lanMar 22 18:15:50 eastpect[42809]: nm2::igb1^: permanently promiscuous mode enabledMar 22 18:15:50 eastpect[42809]: nm1::igb1:1: permanently promiscuous mode enabledMar 22 18:15:50 kernel: 750.076995 [2219] netmap_ioctl got 10000 extra buffersMar 22 18:15:50 kernel: 750.069849 [ 736] netmap_extra_alloc allocate buffer 24583 -> 24582Mar 22 18:15:50 kernel: 750.062915 [ 736] netmap_extra_alloc allocate buffer 24582 -> 24581Mar 22 18:15:50 kernel: 750.055985 [ 736] netmap_extra_alloc allocate buffer 24581 -> 24580Mar 22 18:15:50 eastpect[42809]: nm0::igb1:0: permanently promiscuous mode enabledMar 22 18:15:50 kernel: 750.049074 [ 736] netmap_extra_alloc allocate buffer 24580 -> 24579Mar 22 18:15:50 kernel: 750.042410 [ 736] netmap_extra_alloc allocate buffer 24579 -> 0Mar 22 18:15:50 sshlockout[10974]: sshlockout/webConfigurator v3.0 starting upMar 22 18:15:50 kernel: 750.035617 [2216] netmap_ioctl requested 10000 extra buffersMar 22 18:15:50 kernel: igb1: link state changed to DOWNMar 22 18:14:06 dhcp6c[89888]: no responses were receivedMar 22 18:14:06 dhcp6c[89888]: no responses were receivedMar 22 18:14:04 dhcp6c[89888]: no responses were receivedMar 22 18:14:03 dhcp6c[89888]: no responses were receivedMar 22 18:13:49 dhcp6c[89888]: Sending ReleaseMar 22 18:13:49 dhcp6c[89888]: Sending ReleaseMar 22 18:13:48 dhcp6c[89888]: Sending ReleaseMar 22 18:13:48 dhcp6c[89888]: Sending ReleaseMar 22 18:13:41 dhcp6c[89888]: Sending ReleaseMar 22 18:13:41 dhcp6c[89888]: Sending ReleaseMar 22 18:13:40 dhcp6c[89888]: Sending ReleaseMar 22 18:13:40 dhcp6c[89888]: Sending ReleaseMar 22 18:13:37 dhcp6c[89888]: Sending ReleaseMar 22 18:13:37 dhcp6c[89888]: Sending ReleaseMar 22 18:13:37 dhcp6c[89888]: Sending ReleaseMar 22 18:13:37 dhcp6c[89888]: Sending Release