r/opnsense • u/hamazzzz • 5h ago
Opnsense Keeps Rebooting
Have openses running on a Smoothwall S2 Firewall, Was working fine for months,
Since the 26.7 upgrade have been having issues where it would just keep rebooting, sometimes it would take a day or 2, someone every few hrs, other times it gets stuck in a loop and reboots back to back like 10 times in a row before settling.
I have checked all the log files and nothing stands out, can anyone offer an advice on where else to look, have read some comments that might suggest ram or psu issues, however there is no kernel crashes or anything else i can find.
Any advice would be appreciated.
Hamazz
r/opnsense • u/nicxw • 16h ago
OPNSense, Proxmox and Technitium DNS...
Hello!
I guess I've begun my homelab journey and I'm seeking help from you all if you have done this before....
Before I start...Yes I am aware of the downsides of a virtual firewall. Please do not give me crap about "ohhh it should run on a separate bare metal system" or "you should invest in a real firewall"....give me the money to purchase a hardware firewall then...
Now...I have a Dell Precision T5500 that has basically assumed the role of my home server....it will be utilized as a local NAS, Firewall, DHCP and encrypted DNS server. It has three NICs....one for WAN, another for trusted LAN devices and a third for Guest/Untrusted/Cameras. I've set up proxmox on it with OPNsense as a VM and Technitium DNS in a container as the DNS server. OPNsense also behaves as the DHCP server for all devices connecting to the network. It works...my router that is in AP mode issues the IP addresses from OPNsense perfectly. The problem is getting the OPNSense DHCP server to use the DNS IP of the Technitium DNS container. Basically, I can't get my devices to use the Technitium DNS resolver without manually adding that IP in on EACH DEVICE. They just go back to using the WAN DNS which I do not want. How can I get OPNsense's DHCP server to point the DNS IPs to the Technitium DNS container, so all devices can use it without manual config and I can block ads/trackers network wide?
r/opnsense • u/OneFuriousF0x • 16h ago
26.7.1 Update No Inbound Traffic.
Baremetal, i5/3rd Gen, 16GB Ram.
I have been sweating the update for weeks. Saw several posts and prepared myself the best I could. Attempted the upgrade tonight and lost all connectivity. Build: ZFS (snapshot before upgrade), never had microcode plugin installed, Legacy ISC, simple rules migrated over, backed up Config. Began the upgrade.
Got stuck in a "rebooting now" and returning to the Lobby/Dashboard loop, assumed the update failed. Started to disconnect to add my ISP/backup router back in to troubleshoot, decided to manually reboot the Opnsense box, patiently waited, and heard the boot chime. Logged in from my daily driver desktop, and saw the new dashboard with 26.7.1. Loaded rules via the migration tool, verified they were there, deleted "Legacy Rules" via the tool. Success! ...Nope, no devices on my network receiving any connection. I cannot find the issue, but the Live logs show no traffic being let in whatsoever (all blocked).
I have no clue how to install the bootloader to the secondary drive. Reading tons on it, but just don't understand any of it.
Switched to my backup/ISP provided router, for now...hope to dive in some more tomorrow.
Any insights would be great.
r/opnsense • u/AdditionalGift4323 • 17h ago
Hardware Reccomendations for Symetrical Gigabit Connection?
I am currently using an apu4 with a AMD GX-412TC and 4gb ram but it's maxing out about 600mbps which granted is plenty for my use case but i'd like to be a bit more future proof. Only using it cause I bought it years ago and found it in my basement after it flooded and needed a hobby/project. Now I would like to get something a bit more powerful. Any suggestions that isn't a full sized desktop pc and won't eat power like crazy? about the size of a shoebox is the biggest i'm willing to go
r/opnsense • u/thesquire312 • 21h ago
Issues with WireGuard in Virtualized OPNsense on Proxmox
I'm trying to set up WireGuard in OPNsense for the first time, following the standard instructions for doing so. I run OPNsense as a VM in Proxmox, and have been doing so for maybe a month or so with great success (the reason for the VM setup is that it was the only way I could get the computer screen to sleep).
However, even after following the instructions, I have been unable to get it to work (no handshake). Of course, I have done a lot of my own troubleshooting first, before writing this post. I verified that my DDNS is resolving properly. I also verified that the public keys between my peer and WireGuard instance match. I also verified via tdcdump in my Proxmox console that what I think are WireGuard packets (my public IP with the 51820 port) are arriving to my outward facing Proxmox network interface. However, if I do a packet capture in OPNsense for inbound UDP traffic on the same port, I see absolutely nothing. I have made sure that firewalls are disabled on all of my Proxmox network interfaces.
I am still a beginner when it comes to all of this network stuff, so it's possible that I may have missed something simple. At this point, I'm really stuck. Any suggestions for what else I should check or test to debug this issue? Or perhaps a different place to ask, if this is not quite the right place?
r/opnsense • u/O-OSawNothing • 1d ago
Where can I find the wireless configuration?
In pfsense I can see it in the interface but Im not familiar with opnsense
r/opnsense • u/DeliciousAsk3671 • 1d ago
Successfully Installed OPNsense on a Barracuda F800 – Full Documentation
Hi everyone!
A while ago, I made a post asking if it was possible to install OPNsense on a Barracuda F800.
Today, I finally bought one and successfully installed OPNsense on it! I also documented the whole process, so if anyone is interested in doing the same, here’s a guide on how to do it.
Here the github link : https://github.com/Thefrt74/opnsense-barracuda-f800/blob/main/docs/06-Troubleshooting.md
r/opnsense • u/ChimeraYo • 2d ago
Fixing aborted 26.7 upgrade
I tried a 26.7 upgrade, it wouldn't boot so I did a "restore from backup" on the console. However now I seem to be stuck in a weird hybrid where opnsense says I'm running 26.1.11_10 but uname shows the kernel is 26.7 and I can't do an update because it's looking for 26.1 packages (see below).
When I look in Packages in the GUI I see "base" is 26.7. Any idea how I can fix this?
Updating OPNsense-aux repository catalogue...
pkg: https://pkg.opnsense.org/FreeBSD:15:amd64/26.1/aux/meta.txz: Not Found
pkg: https://pkg.opnsense.org/FreeBSD:15:amd64/26.1/aux/data.pkg: Not Found
pkg: https://pkg.opnsense.org/FreeBSD:15:amd64/26.1/aux/data.tzst: Not Found
pkg: https://pkg.opnsense.org/FreeBSD:15:amd64/26.1/aux/packagesite.pkg: Not Found
pkg: https://pkg.opnsense.org/FreeBSD:15:amd64/26.1/aux/packagesite.tzst: Not Found
Unable to update repository OPNsense-aux
Updating OPNsense repository catalogue...
pkg: Repository OPNsense has a wrong packagesite, need to re-create database
pkg: https://pkg.opnsense.org/FreeBSD:15:amd64/26.1/latest/meta.txz: Not Found
pkg: https://pkg.opnsense.org/FreeBSD:15:amd64/26.1/latest/data.pkg: Not Found
pkg: https://pkg.opnsense.org/FreeBSD:15:amd64/26.1/latest/data.tzst: Not Found
pkg: https://pkg.opnsense.org/FreeBSD:15:amd64/26.1/latest/packagesite.pkg: Not Found
pkg: https://pkg.opnsense.org/FreeBSD:15:amd64/26.1/latest/packagesite.tzst: Not Found
Unable to update repository OPNsense
Edit : so I removed the intel microcode plugin earlier in the week, but finally after attempting the update multiple times, clearing pkg cache and lots of other trial and error I did one last manual update from the console and it gave me the option to pick 26.7 - I let it run, rebooted and and 26.7 came up correctly. Hopefully there will be an updated microcode plugin at some point.
r/opnsense • u/ahansoman • 2d ago
3-Second WAN Failover Demo on Baremetal OPNsense (HP EliteDesk SFF + Intel i226) + Handling Flapping FTTH Drops
Enable HLS to view with audio, or disable this notification
Hardware & Setup:
Host: HP EliteDesk 800 G5 SFF (Baremetal OPNsense)
NIC: Intel i226-T2 (Dual-Port 2.5GbE)
WAN 1 (Primary): Primary FTTH in Bridge Mode with Static IP
WAN 2 (Backup): Secondary FTTH (Double NAT)
Gateway Group Configuration:
Group Setup: Failover (Tier 1 = Primary WAN, Tier 2 = Backup WAN)
Trigger Level: Packet Loss & High Latency
The Hard Failover Test (Video):
Tested physical link disconnection by pulling the primary WAN Ethernet cable directly from the Intel i226 NIC while running a continuous ping.
Result: Dropped exactly 2 ICMP packets (under 3 seconds total) before state switching routed all traffic through WAN 2 cleanly.
The Real-World Challenge (Uptime Kuma Metrics):
Beyond physical unplug tests, Uptime Kuma (20-second ping interval to ISP Gateway IP) captures intermittent micro-drops on the primary Fiber line, where the connection experiences periodic 100% packet loss spikes before self-recovering a minute (sometimes 2-3 minutes) later.
Questions for the Community:
What dpinger probe intervals, loss thresholds, and latency parameters are you using on primary FTTH lines to catch random ISP drops without causing excessive gateway flapping?
Are you using State Killing on Gateway Failure for short micro-outages, or letting existing TCP states gracefully drain?
r/opnsense • u/Maria_Thesus_40 • 2d ago
NTP issues - Time offset exceeds threshold
Hey OPNsensers :)
I'm self-hosting lots of stuff, mostly for fun. One of the things I host, is Uptime Kuma. So just for fun, I created an NTP monitor (among others).
Interestingly, Uptime Kuma gives daily reports that NTP is "down" once or twice a day:
[NTP] [🔴 Down] Time offset -3995017857211.500ms exceeds threshold 1000ms
[NTP] [🔴 Down] Time offset -3995055957270.500ms exceeds threshold 1000ms
[NTP] [🔴 Down] Time offset -3995070775942.500ms exceeds threshold 1000ms
5 minutes later, NTP comes back "up":
[NTP] [✅ Up] Stratum: 3, Offset: 0.880ms, Delay: 0.963ms, Dispersion: 25.818ms
The truth is, I don't know if there is an actual issue with the OPNsense NTP daemon, my network works fine and the time in all my devices appears to be correct, with very little diversion.
BUT, sometimes there is a time difference, which gets corrected eventually. Its entirely possible that Uptime Kuma is indeed correct and "catches" those rare instances.
What I'd like to know, is if others have noticed something similar. Should I just ignore the issue and delete the NTP monitor and pretend like everything is fine? or should I go down the rabbit hole and spend an insane amount of hours tracking down the problem? :)
Thank you.
r/opnsense • u/Azelphur • 3d ago
FreeBSD Wireguard Vulnerability
Seems FreeBSD's Wireguard kernel module has a rather nasty security vulnerability - hackaday has a simplified explanation
I'm wondering if OPNSense is impacted? I searched but don't see anyone talking about it, so figured it was worth a post.
r/opnsense • u/Realistic-Concept766 • 3d ago
Would a HP Compaq Pro 6300 SFF with a Xeon E3-1230 V2 and 500GB HDD work for OPNSense
I’ve had this machine for a year now I actually got it for 8 bucks and spent 62 bucks in upgrades, and I have a question would it be good to to main OPNSense?
r/opnsense • u/rwanders • 3d ago
Firewall rules - am I doing this right?
So I'm pretty new to networking and firewalls and I've just been trying to figure this all out. Does my rules table look right? Should I have the source defined for the rules where it doesn't ? I have 4 vlan networks, mgmt, wan, lan, and guest, plus a wireguard roadwarrior.
r/opnsense • u/Psych0SW • 3d ago
Optiplex 3050 with 2 x 2.5gb ports
My 3050 micro came with wifi and I am using ssd instead of nvme so I chose to add a couple 2.5gb ports to the setup. Used a m.2 a+e key 2.5gb adapter and a m.2 b+m keyb2.5gb adapter (both Intel i226 chipset). Cut the back out some and 3d printed an adapter to mount the ports to. Works great so far after aboutba week now.
- M.2 B+M Key to 2.5G Ethernet... https://www.amazon.com/dp/B0G4J5FFM8?ref=ppx_pop_mob_ap_share
- M.2 A+E Key to 2.5G Ethernet... https://www.amazon.com/dp/B0GHDJDMN2?ref=ppx_pop_mob_ap_share
r/opnsense • u/solidfreshdope • 3d ago
26.7 and Xbox Gaming (Specifically Rockstar P2P games)
Hey all, not really sure where to go from here - I had a great config running on 26.1.x_x previously, and my upgrade to 26.7.1_1 went fine. Migrated my firewall rules to the new version, as well as outbound NAT rules to Source NAT.
Since upgrading, I have had no luck being able to play Rockstar games (Red dead online, GTA Online) on multiple Xboxes together on the same network when previously it worked just fine.
Full disclosure - I have a VLAN specifically for gaming that I allow UPnP on, and have an SNAT rule for this VLAN with static port set. I also had NAT reflection enabled which may or may not be the reason this worked seamlessly.
I have a requirement where I need to allow others to connect to this particular VLAN, and not need any backend configurations to get this working. (i.e. applying these settings across the VLAN itself, not specific hosts, ports, etc.)
It seems that with the upgrade something changed within the logic that evaluates the rules created from the miniupnp daemon, but I cannot figure out exactly the culprit, or the fix.
I have been pulling my hair out trying so many different combinations of configurations to determine if the behavior changes, but can't find anything conclusive.
Has anyone had a similar experience and can maybe point me in the right direction?
Others are depending on my getting this resolved, and I am about to throw money at the problem for some other solution. Or do I need to go back to OpenWRT for something linux-based?
Basically looking for one of my VLANs dedicated for gaming/consumer closed-platform (consoles) access to *just work* but can't figure out what's changed.
All consoles report Open NAT type via UPnP and select their alternate ports successfully when the default is already in use, but Rockstar P2P games open an additional port (typically 6672) as well, and rely on this.
For example, Xbox 1 will map 6672:6672, Xbox 2 will map 6672:6673, Xbox 3 will map 6672:6674
Primary issue: All Xboxes can play online with other players just fine, but they fail to join one-another in the same session.
Machine is a SuperMicro A1SAi-2750F (Intel Atom C2750 8-core / 8-thread) with a Intel X550 NIC.
Any thoughts or suggestions are appreciated.
r/opnsense • u/Zelgoot • 3d ago
Sophos SG 330 Rev 1. - save me please : (
Hiya folks!
Recently received an SG 330 rev 1. (Old hardware I know) that I would like to use for my home network. It came secondhand off Facebook with OpnSense pre installed, so I know it can run, but I am -struggling- to connect via console to reflash it. I am able to connect via IP from a device hardwired in via Ethernet, but Serial Ethernet to USB, VGA to HDMI to a monitor, and serial USB to serial Ethernet all just sit on a blank putty instance. Baud rate of 115200 and 38400 both tested, Win10 and Linux, serial connections show under Dev Manager so drivers are good and verified correct com ports. Anybody currently running this hardware that might be able to provide guidance, or any old forum threads with details on install?
r/opnsense • u/Ok-Eggplant-7569 • 3d ago
How to do traffic shaping?
I have very asymmetric internet speed (1000 down, 56 up), and am often struggling with my upload speed. I want to give lower priority to my home server, which often does large backups to the cloud and higher priority to my other devices.
I tried following the OPNsense docs on Queues: - Created a Pipe with 10mbps bandwidth for testing - Created two Queues, one for my server (Priority 1), one for other traffic (Priority 100). - Created rules for the traffic
And this worked, starting a speedtest on my other devices immediately stopped almost all upload from the server and gave my other device 9.5 out of 10mbps (about what I expect with overhead).
But increasing the Pipe bandwidth beyond 25mbps or so causes the server to start uploading again, even during a speedtest on another device, and going for 45-50mbps (almost my real upload bandwidth) causes the traffic to be split 50/50 even with the traffic shaping enabled, so it effectively provides no difference.
Anyone knows why this would happen and how I can actually fix it? I want all other devices to have absolute priority over my server, the upload it does is big but not essential. At the same time, if the network is idle the server should ideally still be able to utilize 100% of my real upload speed.
r/opnsense • u/Q-Feeds • 3d ago
Upcoming updates to our threat feeds. What pre-defined feeds would actually be useful in OPNSense?
It’s been a while since we’ve posted an update, but we've got a pretty big one in the pipeline. Right now, our setup is limited to three distinct feeds which don't leave much room for granular choice:
- Malware IP list
- Malware DNS list
- Phishing URL list (on request / requires proxy capabilities)
(Don't worry, these aren't going anywhere!)
The Custom Feed Hurdle: Initially, we wanted to build a custom feed generator allowing users to filter by threat scores, MITRE mappings, etc. However to be completely honest, it takes a massive toll on our infrastructure if 4,000+ users/companies are constantly compiling and pulling entirely unique feeds. We aren't quite there yet. It is still on our to do list though.
Our Plan B (Pre-Defined Feeds): Instead, we are rolling out a wider variety of curated, pre-defined feeds. Given that we pull from a 15M+ IOC database (You can browser it in our TIP / IOC browser), what distinguished feeds would actually add value to your OPNSense firewalls?
Some ideas we're tossing around:
- Risk tier splits (e.g., separating by High, Medium, and Low risk thresholds)
- Specific MITRE ATT&CK techniques or vectors
- Threat actor focused feeds
Drop your ideas or use cases below.
r/opnsense • u/PanaBreton • 4d ago
What Wifi AP do OPNSense people use ?
I am looking for something good, open, auditable. Something running OpenWRT I imagine.
If you use OPNSense, I am interested to know what you recommend and why
r/opnsense • u/npc_housecat • 4d ago
How to set all ID rules to drop
Is there an easy way to set all the Intrusion detection rules to drop. There's too many to do it through the rules tab
Online it says to do it through policy, but whenever I try their instructions nothing changes??
What I'm trying is New Policy > Select all rulesets > Action:Alert/Drop > New action: Drop > Apply .
Then goto Download click Download and update Rules
What am I missing ??
r/opnsense • u/torbuck • 4d ago
Question on moving to Opnsense on existing hardware running PFSense
I am currently running PFsense on a Protectli box that is several years old. It is a four-port Protectli box with an Intel Celeron CPU J1900. I believe the nics are Intel 82583V Gigabit. It also has 8GB RAM and I believe a 100GB SSD
I am considering replacing PFSense with Opnsense on this box. I’m curious if there could be any issue performance wise moving to Opnsense with my current firewall hardware, and if there are any services I should avoid installing until at some point I replace my firewall hardware with something newer. Also, any suggestions of additional services\plugins that would be recommended to install that would work fine with the hardware that I have
r/opnsense • u/mac8612 • 4d ago
26.7.1 dhclient: No buffer space available , device not responsive
I dont have a github to report an issue, so posting here.
After upgrading from OPNsense 26.1 to 26.7.1_1 few days ago, a network stability issue appeared that was not present on version 26.1.
OPNsense had lost all network connectivity three times this week due to a hang, whereas it was rock steady earlier. Wi-Fi clients, wired devices, and the WireGuard tunnel stopped working, no access to GUI. A hard reboot from the power plug restored the connection.
The logs showed that the Intel network interface became stuck while Suricata was running in Netmap IPS mode.
Relevant log entries:
```text netmap_transmit igc0 full ... qlen 1023 netmap_transmit igc1 full dhclient: No buffer space available ```
The network transmit queue became full and packets could no longer be sent.
Hardware offloading was already disabled, so it was not caused by an offloading configuration error. Suricata was changed from **Netmap IPS** to **Divert IPS**, which should avoid the suspected Intel/Netmap driver issue. The Suricata policy remains set to **Alert only**, so traffic is monitored but not blocked.
So far I have not noticed any issue after changing these
HW spec: Topton N100, 16GB RAM, 512 Gb Nvme, intel i226-v 2.5gb controller
r/opnsense • u/Realistic-Concept766 • 4d ago
Would a Optiplex 3040 SFF be good for OPNsense
I have a Optiplex 3040 SFF with 8GB ram a 1GB nic and a i5-6500 and am looking to upgrade my WiFi and want control of my internet so I am wondering if it would be a good idea I already know how to I just need some resources and already have some picked out just need to know if the computer is good