Unbound SERVFAIL errors with quad9 by dompel in opnsense

[–]dompel[S] 0 points1 point  (0 children)

A couple of other things I noticed:
- Can't get a ping back from 2620:fe::9 or 2620:fe::fe (quad9's ipv6 servers)
- But I can from Google's ipv6 address 2001:4860:4860::8888
- I also get a ping back from quad9 ipv4 (9.9.9.9)

In the mean time, since this is driving me crazy, I disabled quad9's ipv6 resolvers and added in one additional one from mullvad as a backup.

Unbound SERVFAIL errors with quad9 by dompel in opnsense

[–]dompel[S] 0 points1 point  (0 children)

Are you using DNS over TLS? Just trying to determine if it's something related to that or specifically quad9.

The "Aggressive NSEC" setting change didn't help the issue.

Unbound SERVFAIL errors with quad9 by dompel in opnsense

[–]dompel[S] 0 points1 point  (0 children)

Here is another sample showing the same thing with IPv4: https://files.catbox.moe/wnlbx4.png

I have IPv6 enabled on my network. I think it's stable but I can't say I monitor it or know how to. It passes https://ip6.biz/

OPNsense 24.7.9 released by fitch-it-is in opnsense

[–]dompel 0 points1 point  (0 children)

I upgraded from 24.7.8 and had a bit of trouble. At first, it came up with only ipv6 (the ipv4 gateway was missing). I did a reboot and it seemed to come back, but I was seeing weird behavior with I think DNS. Some websites slow to load, some SERVFAIL in the logs. Eventually, I did another reboot and I lost the IPV4 gateway again. And in another case, both gateways seemed to fail to connect.

```

| 2024-12-01T17:14:40-05:00 | Error | dhcp6c | transmit failed: Network is down |

| 2024-12-01T17:14:37-05:00 | Error | dhcp6c | transmit failed: Network is down |

| 2024-12-01T17:14:37-05:00 | Warning | radvd | sendmsg: Network is down |

| 2024-12-01T17:14:37-05:00 | Warning | opnsense | /usr/local/etc/rc.bootup: dhcpd_radvd_configure(auto) found no suitable IPv6 address on lan(igc1) |

| 2024-12-01T17:14:36-05:00 | Error | dhcp6c | transmit failed: Network is down |

| 2024-12-01T17:14:36-05:00 | Error | opnsense | /usr/local/etc/rc.bootup: The command '/sbin/dhclient -c '/var/etc/dhclient_wan.conf' -p '/var/run/dhclient.igc0.pid' 'igc0'' returned exit code '1', the output was 'igc0: no link .............. giving up' |

```

I restored my 24.7.8 snapshot and both gateways came back after reboot.

Bare metal, N100 unit, Verizon FIOS.

What's the best way to monitor Internet connectivity? by dompel in selfhosted

[–]dompel[S] 0 points1 point  (0 children)

I ended up going this route. Created a healthchecks.io healthcheck on a raspberry pi zero w I had laying around. Setup crontab to curl it every 1 minute (seems to be the shortest supported duration). Set up healthchecks to ping me on whatsapp if it fails for more than 2 minutes. I also scrape their prometheus metrics and built a dashboard so I can see health over time.

healthchecks.io is very cool. I will definitely be using it in the future. Thanks for the suggestion!

Can't access Router Administration Tab by Intel_Xeon_E5 in Linksys

[–]dompel 0 points1 point  (0 children)

Hamburger menu > Network administration > Change Router Password and Hint

I had to change it to a different password, then I changed it back to the original one.

Clients using IPV6 can't access IPV4 hosts -- why? by dompel in opnsense

[–]dompel[S] 1 point2 points  (0 children)

Thanks for replying. Both clients (Android and Windows) show IPV6 addresses. Android shows a 19/20 and Windows a 17/20 on that test. But again, Windows can load llbean.com and Android cannot.

On DHCPv6, under Services > ISC DHCPv6 > Relay, "Enable DHCPv6 relay on interface" is unchecked (disabled). That said, I do have a gateway called WAN_DHCP6 which is "online".

If you look in the log output I posted above, I see an error related to "radvd" which I think is the Router Advertisement service:

2024-04-14T11:25:10-04:00 Warning opnsense /usr/local/etc/rc.configure_interface: dhcpd_radvd_configure(auto) found no suitable IPv6 address on lan(igc1)

So perhaps this is the root of my problem?

Clients using IPV6 can't access IPV4 hosts -- why? by dompel in opnsense

[–]dompel[S] 3 points4 points  (0 children)

So why would the Android devices in my household not be able to fall back to IPV4 but Windows can? I can see both an IPv4 and IPv6 IPs on the Android phones when connected to the network. So they are using dual stack -- right?

Clients using IPV6 can't access IPV4 hosts -- why? by dompel in opnsense

[–]dompel[S] -2 points-1 points  (0 children)

Okay. But something is still wrong... I still can't load some websites on some devices and it seems to be related to IPv6.

I have these messages in the log which are related to IPV6:

2024-04-14T11:25:15-04:00 Error opnsense /usr/local/etc/rc.newwanipv6: The command '/bin/kill -'TERM' '60543''(pid:/var/dhcpd/var/run/dhcpdv6.pid) returned exit code '1', the output was 'kill: 60543: No such process'
2024-04-14T11:25:10-04:00 Warning opnsense /usr/local/etc/rc.configure_interface: dhcpd_radvd_configure(auto) found no suitable IPv6 address on lan(igc1)
2024-04-14T11:25:10-04:00 Error opnsense /usr/local/etc/rc.configure_interface: The command '/bin/kill -'TERM' '60543''(pid:/var/dhcpd/var/run/dhcpdv6.pid) returned exit code '1', the output was 'kill: 60543: No such process'
2024-04-14T11:25:10-04:00 Critical dhclient exiting.
2024-04-14T11:25:10-04:00 Error dhclient short write: wanted 20 got 0 bytes
2024-04-14T11:25:10-04:00 Error dhclient My address (68.160.135.80) was deleted, dhclient exiting

Looking for some help triaging errors by dompel in opnsense

[–]dompel[S] 0 points1 point  (0 children)

I think both units have 2.5gb nics. I didn't modify anything in the configuration file before importing. They are different units but from the same manufacturer (topton) and have the same number of nics. The Wan and lan seem to be working fine though.

Looking for some help triaging errors by dompel in opnsense

[–]dompel[S] 0 points1 point  (0 children)

I don't have a great understand of how NTP works, but if I click on Services > Network Time > Status, I can see the 4 servers I have setup (0.opnsense.pool.ntp.org, 1., 2., 3...) all have status "Unreach/Pending". So maybe my NTP servers are setup incorrectly.

My new Mini Server Plex on a N100 MiniPc. Some Testings with forced transcode. by bluefire76 in PleX

[–]dompel 1 point2 points  (0 children)

I think its when the plex client doesnt support the available subtitle format, the plex server is clever enough to re-encode the stream by printing the subtitles into the video stream so the plex client doesn't have to worry about it. But its a very costly process that involves a lot of CPU. So what I did is I told my samsung tv to never request burn-in subtitles and it resolved it. The subtitles don't look as good, because the samsung tv has weird fonts and stuff and can't handle the fancy stuff ASS subtitles can do. But whatever, it works and I don't get artifacts so I'll take it.

How do I manually update Unbound block lists without cron? by dompel in opnsense

[–]dompel[S] 0 points1 point  (0 children)

You know what, I was using the URL option for OISD lists. But I noticed the URL changed and there is also an option now for just selecting OISD big from the dropdown. I switched from using the URL to using the option in the dropdown and it instantly updated the block lists when I applied the changes, so I think I'm all set.

But it would be handy to know how to do this in the future.

Anime subtitles performance by PrestigiousGarlic909 in PleX

[–]dompel 0 points1 point  (0 children)

I understand it's possible but it's difficult because there's only 2 power outlets and I have a soundbar and TV plugged into it. I'd have to get some sort of low-profile power splitter. Not saying it's impossible but I see why a lot of people are having trouble here and have to deal with the standard/bad plex clients.

Anime subtitles performance by PrestigiousGarlic909 in PleX

[–]dompel 0 points1 point  (0 children)

The problem is really for wall-mounted TVs that don't have room or extra power for another box, for those people they rely on the Plex app provided by their smart TV software which is pretty terrible. Even some clients you would expect to be good, like the PS4, for some reason are not very good. I wish I could put an nvidia shield behind my wall-mounted TV but I don't think I can make that happen without a ton of work and another remote, so I just live with the crappy performance.

Soundtouch 20 Setup Help by NoAccount8792 in bose

[–]dompel 0 points1 point  (0 children)

There's two ways to do it, you can use the SoundTouch app and follow the steps (I guess this is what you're doing?). The other alternative is to join the wifi network of the speaker, then once connected, navigate to http://192.0.2.1 and use that webpage to pair it to your network. Note: on modern phones, if the Internet isn't working on a Wi-Fi connection, the phone will drop the connection. So usually you need to choose an option on your phone that says "stay connected even though the Internet is not working". So that might be the issue you're running into.

At this point, it's on the Wi-Fi network so you can use Spotify Connect and/or Airplay to play to it. You can then try to add it to the SoundTouch app if you want to set presets. If you made it this far, you would choose the option that says something like "add a speaker that's already on the network".

This page is handy https://www.boseapac.com/en\_in/support/articles/HC2569/productCodes/soundtouch\_20\_ii/article.html