Environment
- OPNsense 26.7.1_1 (amd64), FreeBSD base 15.1-RELEASE-p1
- Previously working: OPNsense 25.7.3_7, FreeBSD base 14.3-RELEASE-p2
- Hardware: Intel E810-XXV-2 (dual-port SFP28, 25G), PCI passthrough (Proxmox/QEMU, ice0/ice1)
- ice0 (WAN): 25GBase-LR optical SFP28 module, connected directly to ISP fiber (Init7, Switzerland), no intermediate media converter
- ice1 (LAN): 25GBase-CR DAC to a local switch — unaffected, works fine on both OS versions
- NIC firmware unchanged across both OS versions: fw 7.3.4 api 1.7 nvm 4.30 etid 8001b891 netlist 4.2.5000-1.14.0.2b9b23c0 oem 1.3415.0
Problem
After upgrading from 25.7.3_7 to 26.7.1_1, ice0 fails to establish link on every boot:
ice0: All configured link modes were attempted but failed to establish link.
ice0: The device will restart the process to establish link.
ice0: Possible Solution: Check link partner connection and configuration.
ifconfig ice0 shows status: no carrier, and sysctl dev.ice.0.current_speed reports Unknown speed. ice1 on the same card comes up normally.
Troubleshooting performed (all on 26.7.1_1, no effect)
- sysctl dev.ice.0.advertise_speed=0 → rejected, value stays at 128
- sysctl dev.ice.0.advertise_speed=64 (0x40, exact bitmask for 25G, matching the module's only reported supported media 25GBase-LR per ifconfig -m ice0) → explicitly rejected: ice0: User-specified speeds ("0x0040") not supported
- ifconfig ice0 media 25GBase-LR → ifconfig: SIOCSIFMEDIA (media): Operation not supported by device / ice0: Media change is not supported.
- sysctl dev.ice.0.allow_no_fec_modules_in_auto=1 → accepted, no change in link behavior
- Full VM power-cycle (poweroff + start, not just reboot) at the hypervisor level → no change
Workaround
Reverted to the previous ZFS boot environment (25.7.3_7 / FreeBSD 14.3-RELEASE-p2) via bectl activate ; reboot. Link immediately established:
ice0: Link is up, 25 Gbps Full Duplex, Requested FEC: RS-FEC, Negotiated FEC: RS-FEC, Autoneg: False, Flow Control: None
Expected behavior
ice0 should negotiate link at 25G with RS-FEC on the LR optic, as it did prior to the FreeBSD 15.1 base upgrade, since the module, firmware, and physical link partner are unchanged.
Suspected cause
Looks like a regression in the FreeBSD 15.1 ice(4) driver's link/FEC capability negotiation specifically for SFP28 optical (LR) modules — the DAC-connected port (ice1) on the same card and firmware is unaffected, which points at driver-side link mode/FEC negotiation logic rather than hardware or firmware.
Environment
Problem
After upgrading from 25.7.3_7 to 26.7.1_1, ice0 fails to establish link on every boot:
ice0: All configured link modes were attempted but failed to establish link.
ice0: The device will restart the process to establish link.
ice0: Possible Solution: Check link partner connection and configuration.
ifconfig ice0 shows status: no carrier, and sysctl dev.ice.0.current_speed reports Unknown speed. ice1 on the same card comes up normally.
Troubleshooting performed (all on 26.7.1_1, no effect)
Workaround
Reverted to the previous ZFS boot environment (25.7.3_7 / FreeBSD 14.3-RELEASE-p2) via bectl activate ; reboot. Link immediately established:
ice0: Link is up, 25 Gbps Full Duplex, Requested FEC: RS-FEC, Negotiated FEC: RS-FEC, Autoneg: False, Flow Control: None
Expected behavior
ice0 should negotiate link at 25G with RS-FEC on the LR optic, as it did prior to the FreeBSD 15.1 base upgrade, since the module, firmware, and physical link partner are unchanged.
Suspected cause
Looks like a regression in the FreeBSD 15.1 ice(4) driver's link/FEC capability negotiation specifically for SFP28 optical (LR) modules — the DAC-connected port (ice1) on the same card and firmware is unaffected, which points at driver-side link mode/FEC negotiation logic rather than hardware or firmware.