Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Topics - mcouture

#1
High availability / HA with single WAN mac/ip
December 13, 2024, 09:24:38 PM
I would like to setup 2 FWs with carp or otherwise to run in HA mode mainly to support for upgrades.  iE: patch the backup then move primary to backup and patch the master.    CARP should cover this, however I only have access to 1 "authorized" MAC address/IP address.  Will I have to tell my ISP the CARP MAC address is the only authorized MAC address?
#2
The upgrade from 24.1 to 24.7 went flawless...Thank You!!

I'm trying to remove old plugins that no longer exist (os-wireguard).   I ran the automatic resolver however it doesn't remove it from the list.   How do I get this removed???
#3
Running the latest version Opnsense.

Trying to create 3 separate Wireguard VPNs, using separate interfaces.

Created the first Wireguard VPN, and interface just fine.

Created the second Wireguard VPN and no interface is shown (even though Wireguard screen shows "wg2")

Created a third Wireguard VPN and again no interface is shown to assign to...Wireguard shows this as "wg3"

#4
I have 2 Wireguard site-to-site VPNs setup already.   Both ends are OpnSense.   I want to setup a 3rd VPN to a PFSense box and I have not had any luck getting them to handshake (OpnSense to PFSense).    Anybody have any issues in this area?

public keys generated and copied appropriately.

#5
I setup 2 Wireguard site to site tunnels yesterday and everything works as advertised.   I can see both sides of each tunnel.   So far so good right?

Within a couple hours, OpnSense would kernel panic and reboot.   Then within an hour panic again....then again....then again.

I'm running OpnSense in a VM under ProxMox, using KVM64 as the device.    My hardware is a TopCon 6port all-in-one device.     I have 3 more of these devices all running OpnSense under ProxMox without issue.

I was thinking of trying the KMOD version of Wireguard but unsure....thoughts?