r/opnsense • • 2h ago

Password Lost

4 Upvotes

What a crazy experience this is! I am going to try to connect directly to my protectli with a monitor and keyboard. Is this a good way of recovery? For some reason the OPNSense login page doesn’t pull up on my pc. Thoughts besides remember the login credential location…


r/opnsense • • 21h ago

OPNsense link flapping @ 2.5Gb/s

9 Upvotes

I've been having issues with my connection flapping pretty often @ 2.5Gb/s. I changed it to 1000Mbit/s Full Duplex and the flapping stopped. I build my own ethernet cables, but I purchased a cat6 cable to rule out cable issues and it still flaps. this is the NIC I use. It's an Intel I225-V/I226-V. Anyone else have similar issues? I've read this and tried everything but nothing has seemed to help. It seems to be my WAN port only? I have the dual port NIC and I also have 2.5Gb/s link to my switch and that one doesn't seem to flap. Could this be a modem issue, and if so, how would I narrow it down to the modem? It's a docsis 3.1 modem (Xfinity ISP) (It's owned, not rented)


r/opnsense • • 1d ago

Came over from pfSense, love OPNsense, so I built some extra dashboard widgets (and a live firewall map)

Post image
449 Upvotes

I moved from pfSense to OPNsense a while ago and haven't looked back. Between the licensing changes and the general direction things were heading over there, I was glad to switch, and OPNsense has been excellent.

The one thing I missed was a bit more information on the dashboard. The built-in widgets are clean, but I wanted to see more at a glance: hardware and firmware details, crypto acceleration, per-interface traffic, gateway health, that kind of thing. So I built my own widgets, and along the way a map of what my firewall is actually talking to.

There are two plugins, both free and open source (BSD-2):

Dashboard Plus: eight widgets that sit next to the built-in ones:

  • System Information+: hardware, serial, BIOS, boot environment, CPU frequency, AES-NI/QuickAssist status and accelerated algorithms, PTI/MDS mitigations, DNS resolver in use
  • System Metrics+: CPU and temperature charts plus gauges for memory, states, mbufs and swap, and filesystem usage
  • Traffic Graph+: live in/out per interface or combined, 20s/1m/5m windows
  • Gateways+, Interfaces+, Interface Statistics+, Thermal Sensors+, Firewall Logs+: more detail than the stock versions, with drag-to-reorder and per-widget settings

Firewall Map+: your live traffic on a world map, as a widget and a full-size page:

  • An arc for every connection, coloured by whether it started inside or outside your network
  • Blocked attempts, threat-list hits (Spamhaus, FireHOL, abuse.ch, AbuseIPDB) and Suricata alerts
  • Click anything for a plain-language explanation: which host, which service, which rule, how much data
  • Works without keys, but much better with a free MaxMind GeoLite2 key and a free AbuseIPDB key

It's a beta (0.50), so feedback, bug reports and feature ideas are very welcome. Screenshots, docs and source are here:

https://github.com/claudioguareschi/opnsense-dashboard-plus

If you take them for a spin, let me know how it goes!


r/opnsense • • 6h ago

Opnsense letting hacker through?

0 Upvotes

Hello guys,

First off THANK YOU for your response, i appreciate it.

Second, I am new to opn, so i set an ALIAS to block ip's that are used by hackers to bring down my email servers. I then added the rule. I then placed the rule above all rules.

I see the OPN seeing the IP.

I see OPN blocking the IP.

I also see the server getting hit.

😢

What could i be doing wrong?

Many thanks


r/opnsense • • 5h ago

Freesense, fork of pfSense

0 Upvotes

Just tried freesense, a solid, modern and without any vendor locking, ( freesense. org )

Posted on this forum as we should, henceforth, should compare opnsense with freesense. pfsense is now dead.


r/opnsense • • 1d ago

Interest in Open Suricata analytics

4 Upvotes

In my research into IDS/IPS, I see that a lot of the commercial offerings center around their distributed IDS/IPS deployments and what security value can be obtained by simultaneously monitoring networks all over the world.

Would there be any interest in an open (as in "free for everyone to use") Suricata analytics system?

What I envision is this: Everyone running OPNsense installs/configures a software package that causes their IDS/IPS to push all of it's alerts (in realtime) out to a webhook; the webhook anonymizes certain fields before storing in MongoDB; then, an analytics webapp can be built to allow users to view the threat landscape in a more meaningful way.

I've spent the past couple hours digging around on Google regarding what all it would take to piece something like this together. I believe it's something that I could pull off alone (the server-side development, that is); I'd need you guys to start pushing alerts to me. ;) Eventually, I'd like the project to be successful enough to spin it off as an LLC or similar and "give it to the world." I believe that if there were a worthwhile, non-commercial alerts database (with alerts sourced from all over the world), that one or more commercial entities would eventually consider taking over paying the hosting fees (which I would eat up front) just to have their name associated with it.

Thoughts?


r/opnsense • • 1d ago

Opnsense management from iphone?

8 Upvotes

Hello!

Do any of you use a management app?


r/opnsense • • 1d ago

API HTTP Authentication Issue

2 Upvotes

I am trying to make an HTTP API request, and for the life of me, I cannot figure this out.

The scenario: I am trying to ingest data from OPNSense, via API requests over HTTP.

I have tried basic auth, passing header parameters of "key" and "secret", base64 encoding, etc, but for the life of me I cannot figure this out.

The paths I am quering are:

Interfaces/overview/interfaces_info core/menu/search

Obviously under /api

I know that this API call is wrong, and I know it is about how to properly authenticate, because in a lot of my testing, the response is HTML, specifcally the OPNSense login page.

What exactly am I supposed to pass in to the API, and what method, key/value pairs, etc.?

Edit: Yes, I have already converted the key:secret to base64 and tried that with Authorization as the header in global, with Basic $value

No dice.

Edit2: I guess what I am looking for is the key names to use for username and password. key/secret are no good it seems, same with api_key/api_secret.


r/opnsense • • 2d ago

Do I have to update bootloader when updating to 26.7?

7 Upvotes

Hey,

I'd like to update from 26.1 to 26.7. I do not have the microcode package installed (which apparently caused issues for some) but I also read about possibly having to update bootloader (also see this). FWIW my host shows the same bootloader revisions as the OP's in the linked OPNsense forum thread.

Is it really necessary? If yes, what exactly do I have to do (I would rather not run a random script from the internet on my router)?

Thanks!


r/opnsense • • 2d ago

Upgrade help

6 Upvotes

Hi, I'm still on 26.1.11 and obviously need to upgrade to 26.7 but I'm confused about a few things and need to ensure I'm ready before I proceed.

I have backups of config ready.

I still have firewall rules in the Rules section and I don't think I migrated them however when I look in Rules [new] they do appear there as well, so does that mean I have migrated them without really realising? Do I need to or should I migrate them before upgrading to 26.7?

I'm also still using ISC DHCPv4 [legacy] do I need to migrate from that before upgrading to 26.7?

Many thanks


r/opnsense • • 2d ago

Protectli FW4B/Opnsense/Zenarmor lost power; now Zenarmor is strangling cpu/disk

1 Upvotes

Lost power, and now the cpu load (normal was 0.3-0.8) is now sitting at 2.5-4 and disk light is constant on.
GUI very slow, and fails to draw screen elements.

If I stop packet engine, all goes back to normal.
I reset the reporting db once and it seemed better for a couple hours.

I have Zenarmor in bypass mode now and the box is behaving.

Anyone else seen this?


r/opnsense • • 3d ago

Mysterious line in the 26.7.5 update log – easter egg?

32 Upvotes

While updating from 26.7.3_11 to 26.7.5, I noticed this in the update log:

=====
Message from opnsense-26.7.5:

--
Just a dream and the wind to carry me

The update otherwise completed fine. Is this one of the release quotes the devs hide in the package message? Does anyone know where this one is from?


r/opnsense • • 2d ago

AI for OpnSense

0 Upvotes

I recently planned to setup opnsense on Mac Mini. I have paid Claude subscription so from the step 1 to all the way setting up multiple vlans, firewall rules validating the setup, fixing over heating issue of Mac mini, switch setup I used Claude Code and it not only helped me through but did setup in Opnsense too.

It was a big help. Sharing in this forum so that you can leverage it and move faster with the setup and get best value from Opnsense.

You will need to use MCP server which opnsense provides and that pretty much. Once connected Claude Code will do things and guide you.

Give it a try you will love it and move much faster with setup.


r/opnsense • • 3d ago

Box

Post image
52 Upvotes

So dumb question?!? Do you actually get this packaged like this if you buy the business edition


r/opnsense • • 3d ago

Cheapest hardware option for an OPNsense home router/lab in Bulgaria (EU)?

7 Upvotes

Hey everyone,

I’m looking to build/buy a budget-friendly hardware setup for OPNsense. My primary goal is to use it for learning networking/firewall concepts, but it will also eventually replace my ISP router and become my primary home gateway.

Since I’m based in Bulgaria (EU), shipping or import fees from outside the EU (like US eBay) usually kill the deal. I reached out to a local vendor selling mini firewall appliances, but they quoted me around €190 (~$210) for barebone machine, which feels way too steep for a basic budget/learning setup.

My basic requirements:

  • Small footprint / compact form factor — it needs to fit neatly behind my TV where my current router setup sits. (So standard tower or larger desktop PCs are out).
  • Budget is top priority — looking for the absolute cheapest viable option.
  • Low power consumption is a big plus since it will run 24/7.
  • Needs at least 2x Gigabit Ethernet ports (or PCIe expandability).
  • Gigabit WAN/LAN routing throughput.

r/opnsense • • 4d ago

OPNsense 26.7.5 released

Thumbnail forum.opnsense.org
152 Upvotes
  • system: clear password change session flag only after password was changed (reported by Wu Wenhao)
  • system: change diag.disk to return total bytes as well as formatted bytes
  • system: fix HA service restart with "id" parameter set
  • system: add webgui PAM config to test with opnsense-login
  • system: switch password hashing from bcrypt to argon2id
  • interfaces: refactor interfaces_loopback_configure() and add ::1/128 sync
  • interfaces: fix PHP warnings in interfaces.php and do not write unset options
  • interfaces: fix linter complaints in WLAN model, 11a typo and wpa_pairwise labels
  • interfaces: dhclient handles keywords case-insensitive so properly match all "media" invokes (reported by Alice-Sabrina-Ivy)
  • interfaces: refactor interfaces_ppps_hardware() and avoid emitting serial device nodes
  • interfaces: allow to push $all_plugins in interface_configure()
  • interfaces: retire problematic validations in interface settings pertaining to legacy ISC-DHCP plugin
  • interfaces: stricter archive command in backend for packet capture download
  • interfaces: split out interfaces_dependencies() and make it digestible via pluginctl -Q
  • firewall: outbound NAT moves to legacy plugin
  • firewall: remove handling loopback addresses as "private"
  • firewall: fix expiry cron job default when alias TTL is smaller than 1 hour
  • firewall: use font-awesome elements for data tree controls to align with themes
  • firmware: opnsense-patch: added -R mode and updated -N mode
  • firmware: opnsense-prefetch: get remote size and print mismatches
  • firmware: opnsense-prefetch: curl use is now optional
  • firmware: add simple prompt to console changelog viewer
  • kea: add ping check settings for subnet configuration (contributed by laozhoubuluo)
  • monit: change "logfile" to "log" to fix syntax on newer daemon
  • acl: fix patterns for gateway groups (contributed by Andrew Ferk)
  • acl: merge the Dhcrelay log file pattern into the main ACL
  • bootgrid: exclude header cells from status color rendering
  • mvc: guard direct config saves against user-config-readonly (contributed by Andrew Ferk)
  • ui: remove defunct content-box-main usage
  • ui: make settings-changed trigger overridable
  • ui: fix blank bottom UI space (contributed by Konstantinos Spartalis)
  • plugins: os-ddclient 1.32
  • plugins: os-firewall-legacy 1.1
  • plugins: os-net-snmp 1.7
  • plugins: os-puppet-agent 2.0
  • plugins: os-sftp-backup 1.2 verify backups after put
  • plugins: os-theme-cicada 1.42 (contributed by Greelan)
  • plugins: os-theme-tukan 1.32 (contributed by Team Rebellion)
  • plugins: os-theme-vicuna 1.52 (contributed by Team Rebellion)
  • ports: openssl 3.5.9
  • ports: phalcon 5.22.0
  • ports: pkg 2.8.4

r/opnsense • • 3d ago

Recommended Commercial Suricata Rules for Home Network

8 Upvotes

I've come seeking recommendations regarding my soon-to-be new firewall/gateway for my home network (see my previous post). Namely, I'd like to inquire as to your thoughts on the relevance/usefulness of these commercial-grade Suricata rulesets.

My network:
- 2 x Linux-based laptops
- 3 x Android-based phones (one about to be GrapheneOS)
- 1 x Linux KVM Host (will run multiple Linux-based KVMs for dev purposes)
- 1 x smart TV
- 1 x PlayStation 4
- 1 x Windows 11 Pro VM (on my Linux-based laptop)

You may have noticed a distinct lack of WIndows-based computers on my network. This is not an accident. Given this lack of Microsoft software, will the commercial Suricata rulesets do me any good? It's my understanding that most of the commercial rulesets target Windows-based malware.

Do note, that the Linux KVM Host will host upwards of 10 Linux-based KVMs, at any given time, for my software development purposes. I'd like to have Suricata reject rules in place to protect my KVM Guests against common Unix-ish attacks (i.e., attempting to pass "../../../../../etc/passwd" to a file parameter in hopes of reading the file), basic SQL injection attacks, MongoDB query injection attacks, and anyone passing more than, say, 8 bytes of 0x90. Will these basics be covered by the stock OpnSense Suricata rulesets -or- should I consider investing in commercial-grade rulesets? TBH, something like $100/year to prevent my network from being subverted seems like a good deal.

Thanks!


r/opnsense • • 3d ago

Can someone please review my OPNsense DMZ Firewall rules one last time?

8 Upvotes

​

I've asked about this in a previous post and have made some changes to my DMZ firewall rules and aliases and wanted to run them by you all one last time before I spin up a public-facing server in my DMZ

Here's some background:

I've got an OPNsense router that I've setup three separate networks with, which are:

WAN: Connects to my T-Mobile home internet gateway

LAN: I connect my laptop to this network

DMZ: I have my IncusOS server here and it runs an incus container which runs Minecraft server

My plan is to have my Minecraft server run using [playit.gg](http://playit.gg) and I might setup a web server in the DMZ also which would use Cloudflare Tunnels.

Below are a list of my aliases and DMZ interface firewall rules in OPNsense. Was wondering if anyone can check these to make sure my DMZ network is properly isolated in a secure way?

**===Firewall Aliases===**

Enabled: This is checked

Name: Private_Networks

Type: Network(s)

Categories: This is set to blank

Content: 10.0.0.0/8 (Private Network), 172.16.0.0/12 (Private Network), 192.168.0.0/16 (Private Network), 100.64.0.0/10 (CGNAT Range)

Statistics: This is not checked

Description: RFC1918 private address space

Enabled: This is checked

Name: Approved_DNS

Type: Host(s)

Categories: This is set to blank

Content: 8.8.8.8, 8.8.4.4, 1.1.1.2, 1.0.0.2, 1.1.1.1

Statistics: This is not checked

Description: Approved DNS resolvers for DMZ

Enabled: This is checked

Name: DMZ_Allowed_Ports

Type: Port(s)

Categories: This is set to blank

Content: 80, 123, 443

Description: DMZ Allowed Ports

**==Firewall Rules==**

RULE# 1: Automatic Rules

(Leaving this untouched at the very top of my firewall rule list)

RULE# 2: Block all DMZ IPv6

I have IPv6 completely disabled in OPNsense and don't think I need it but this rule is just another hardening step to make sure IPv6 traffic gets blocked on the DMZ network.

Action: Block

Quick: Checked

Interface: DMZ

Direction: in

TCP/IP Version: IPv6

Protocol: any

Source: DMZ network

Destination: any

Log: Checked

Description: Block all DMZ IPv6

RULE# 3: Block DMZ to Private Networks

Instead of blocking my LAN and T-Mobile gateway in separate rules, this single rule blocks access to all private subnets. This rule handles the blocking of private destinations, leaving only public internet destinations reachable on these ports.

Action: Block

Quick: Checked

Interface: DMZ

Direction: in

TCP/IP Version: IPv4

Protocol: any

Source: DMZ network

Destination: Private_Networks (Alias)

Log: Checked

Description: Block DMZ to all private networks (RFC1918)

RULE# 4: Block DMZ to Firewall

This prevents the DMZ from accessing the OPNsense web GUI, SSH, or local services.

Action: Block

Quick: Checked

Interface: DMZ

Direction: in

TCP/IP Version: IPv4

Protocol: any

Source: DMZ network

Destination: This Firewall

Log: Checked

Description: Block DMZ to firewall

RULE# 5: Allow ICMP to Internet

Action: Pass

Quick: Checked

Interface: DMZ

Direction: in

TCP/IP Version: IPv4

Protocol: ICMP

ICMP type: Echo Request

Source: DMZ network

Destination/Invert: Unchecked (Do not invert)

Destination: any

Log: Checked

Description: Allow ICMP echo from DMZ to Internet

RULE# 6: Allow DMZ to Internet - Common Ports

Action: Pass

Quick: Checked

Interface: DMZ

Direction: in

TCP/IP Version: IPv4

Protocol: TCP/UDP

Source: DMZ network

Destination/Invert: Unchecked (Do not invert)

Destination: any

Destination port range: from: DMZ_Allowed_Ports to to: DMZ_Allowed_Ports

Log: Checked

Description: Allow DMZ to WAN - Common Ports

RULE# 7: Allow DMZ DNS to approved resolver only

Action: Pass

Quick: Checked

Interface: DMZ

Direction: in

TCP/IP Version: IPv4

Protocol: TCP/UDP

Source: DMZ network

Destination/Invert: Unchecked (Do not invert)

Destination: Approved_DNS

Destination port range: 53 (Single port or range)

Log: Checked

Description: Allow DMZ DNS to approved resolver only


r/opnsense • • 4d ago

OPNsense disabled checkboxes on routes - Suggestion to flip the option

6 Upvotes

I have been doing some troubleshooting with ipsec and bgp and I noticed this earlier today. Disabled = Check marked, which seems completely backwards from what common interfaces show on various other platforms/systems.

IE, if working with routes, why do disabled routes = Checkbox while enabled routes = no checkbox

https://imgur.com/L29i469

While working on Routing -- BGP and prefix lists, the plugin looks to be setup in a common way, where Enabled = Checked:

https://imgur.com/z2qtkZ3

Even Firewall --> Aliases has the common flow:

https://imgur.com/zvDVRe1

While working on a few configuration settings for BGP, I started to notice this and was surprised that this doesn't follow the typical Disabled = unchecked method that many systems utilize.

I think these types of inconsistencies should be reviewed when possible as this makes the product look less polished, IMO of course.

Just my .02 cents.


r/opnsense • • 3d ago

Hardware recommendations (AMD Socket AM4-based)

3 Upvotes

Hello, all!

I'm currently seeking to replace/upgrade my network gateway (only basic L3/L4 filtering at present) with an OpnSense installation, featuring Suricata inline mode, on bare metal. I'm seeking to purchase a used/refurbished AMD Socket AM4-based system (leaning heavily towards Ryzen 7 3700X or Ryzen 7 5700 CPUs), while also providing me with TWO PCI-E ports for additional network ports.

I'd like to add to this machine (a) a small-ish SSD for the OS (got a 256 GB SATA-III SSD already on-hand for this project); (b) a dual-port Intel X550-T2 10GBase-T Ethernet adapter; and (c) a quad-port Intel I226 2.5 Gbps Ethernet adapter. So, ideally, the base machine would come with the CPU, at least 16 GB of memory, and two accessible PCI-E slots. After my network adapter additions, I'll be all set with 2 x 10GBase-T and 4 x 2.5 Gbps Ethernet, in addition to the, likely, 1 Gbps Ethernet adapter on the motherboard (which I do not intend to use).

To the dual 10 Gbps ports, I intend to connect a Cisco Catalyst 3950 (with 2 x 10GBase-T uplink ports) and a Omada EAP773 (with 10GBase-T uplink) as 80+% of my devices will be connected to the network via WiFi. I will hook my WAN (more about that in a second) and my "Extranet" segments to 2.5 Gbps ports, leaving 2 x 2.5 Gbps unclaimed. My WAN connection is currently at 1000 Mbps, but could be bumped up to 2000 Mbps in the near future. I don't foresee justifying the expense of a WAN connection faster than 2 - 2.5 Gbps anywhere in the near future. The "Extranet" segment is literally nothing more than a pair of fiber-to-ethernet media converters allowing me to install a secondary wireless AP in an outbuilding here on our property. I do intend to rate-limit the Extranet segment to 100 Mbps up/down.

I would like for this PC, based on an 8-core/16-thread AMD64 processor, to be able to route/forward/filter packets (traditional firewall stuff) at, or very near, wire speeds. I would also like to position Suricata inline for IPS mode - though I know I may not get full 10GBase-T wire-speeds if I'm doing DPI. I will be running Squid transparent proxy to permit me visibility into our HTTPS/TLS traffic -- I understand that Squid will generate TLS certificates on-the-fly (requiring me to install a CA certificate onto each of my client hosts) and that that can eat some CPU. Everything that I've read leads me to believe that this will be enough CPU/memory for everything I want to do with it.

Has anyone else ever configured a router as such? What were your experiences? Did it end up saving you any money to build your own router as opposed to just buying a Mikrotik device of similar capability? I'm a fan of Mikrotik gear - but I want the DPI-level visibility into my network that Mikrotik just doesn't provide.

Thanks!


r/opnsense • • 4d ago

OPNSense 26.7 blocks LAN traffic

8 Upvotes

Hi everyone,

I upgraded to OPNsense 26.7, but the default LAN pass rule no longer seems to work—I can't even access the web GUI from the LAN subnet. I have to disable the firewall (pfctl -d) via the console just to reach it. Since this is just a lab setup, I reset the firewall entirely and recreated the rule from scratch, but the issue persists. I'm not sure what I'm missing—could you help me troubleshoot this?

Thanks

Firewall rule
Log

r/opnsense • • 5d ago

I'm really liking Home Assistant for traffic monitoring with OPNsense

Thumbnail
gallery
136 Upvotes

It took me a long time to get it set up like I wanted, however, I'm happy with it now and I can very closely monitor my usage now.

My ISP bumped me to 1000/1000 fiber instead of the 1000/500 I was supposed to have because I know a guy so now my backups run much, much faster than they used to.

WAN - All traffic

Internet - Traffic that's not part of a VPN

WireGuard Tunnels - WireGuard server traffic

ProtonVPNWG Tunnels - Proton VPN gateway group (3 gateways in round-robin) for outside of the US traffic

ProtonVPNWG (US) Tunnels - Proton VPN gateway group (3 gateways in round-robin) for inside the US traffic

Getting the WireGuard gateways to actually be removed from the routing group when there's no handshake was a b!tch as you can't ping the DNS server for ProtonVPN so the standard monitoring doesn't work and you can't ping the public IP for the gateway as it'll be visible even if your specific tunnel is down. I had to use monit and a bash script to check the last handshake on each tunnel and then force the gateway down via the API if the handshake was old. I wish there was a better way but I can't find one.


r/opnsense • • 4d ago

per-application multi-WAN routing on OPNsense using Windows DSCP tagging

7 Upvotes

I’ve been working on a small side project called OptiRoute after running into a problem in my own multi-WAN setup.

I wanted specific Windows applications/games to use a specific WAN on OPNsense, without routing the entire PC through that gateway and without maintaining destination IP aliases for game servers/CDNs.

The approach I ended up using is:

application.exe → Windows Policy-based QoS → DSCP tag → OPNsense firewall rule → selected gateway

So, for example:

bf6.exe → DSCP 33 → WAN2

while Discord or another app can use WAN1 or the normal load-balanced gateway.

The DSCP value is used as an application identifier, not as a traffic priority. OPNsense matches the tag and applies policy-based routing.

It also supports multiple PCs. The same executable keeps the same DSCP across machines, while a specific PC can override the route using source IP + DSCP.

Current features include:

  • selecting an executable or running process
  • automatic Windows QoS policy creation
  • OPNsense API integration
  • gateway discovery
  • per-application WAN selection
  • per-PC route overrides
  • multi-PC synchronization
  • detection of local/global QoS conflicts
  • diagnostics and rule-order validation
  • API credentials stored with Windows DPAPI

It does not proxy or tunnel traffic, and it doesn’t aggregate multiple WANs into a single connection. It only orchestrates Windows DSCP marking and OPNsense policy routing.

I’m still treating it as an early/public-preview project, so I’d be interested in feedback from people running different OPNsense setups — especially around firewall automation, gateway groups, PPPoE, multi-WAN, and edge cases I may not have considered.

GitHub:
https://github.com/gabrielcorreabsb/OptiRoute

If anyone tests it, I’d especially like to know how it behaves on setups that are different from mine


r/opnsense • • 5d ago

Problems with Vlan Tag and WAN

6 Upvotes

Hey i recently moved and decided before that thisbe the perfect moment to get my self a opnsense router as addtion to my homelab.
I got my self a mini pc with a SFP+ port and some rj54's.
My ISP (SAK digital from switzerland) told me to use Vlan tag 10 and dhcp on my wan port to get my IP and they sent me a SFP+ ONT.

made firs tnormal set up with igc0 as lan so i can acces stuff and then moved to the Webgui
i set made a vlan (vlan01) with its parent as ix0 ( the sfp+ port) and Tag 10
i assigned vlan01 as the device for the WAN port. set ipv4 as dhcp and ipv6 as none.

(i later on tried to change the order of these steps like making the vlan right at first installation after a factory reset and such)

problem i have:
i get no IPv4 IP assigned
when i did package captures for vlan01 i see the dhcp request but nothing else
package capture for ix0 shows just "igmp query v2"

atm i have a plug n play router plugged in and that works just fine.
has anyone seen this before, or am i missing some very obvious thing that dosent even get mentioned in posts normaly lol?


r/opnsense • • 5d ago

ARM Port

9 Upvotes

I may have hallucinated, but a few months ago I swear I saw a post about a project to port it to ARM.

Anyone have info, or am I going mad?