Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - bartjsmit

#1471
Don't fear the VLAN ;-)

The Register has a gentle introduction: https://www.theregister.co.uk/2017/06/30/vlans_at_20/

In a nutshell; you trunk as many VLAN's as you want to use to OPNsense on a tagged port, and add untagged ports to the switch for all the bits of kit that you want to connect to each zone.

TL-SG105E is fine too, but the price per port is a bit higher than for the 108.

Bart...
#1472
For around the same cost, you can purchase a TP-Link SG108e managed switch and trunk the necessary VLAN's to OPNsense.

Just a thought

Bart...
#1473
Are you allowing icmp6? Does radvdump show the beacon information you are expecting? Have you packet traced the NDP traffic? Any host firewalls getting in the way?

Bart...
#1474
General Discussion / Re: Multi-Level Configuration
July 26, 2018, 08:19:50 AM
Yes, you need routing both ways for the return packets to make it back to the source, or you need an outbound NAT on OPNsense.

It's much easier to have static routes on your NAT gateway for all internal subnets. A few protocols won't even work with double NAT.

Bart...
#1475
If you have a fixed IP address, you can configure your clients with that; no need to use an FQDN.

What I meant was, even if you have a variable IP address you still have to have some constant to reliably connect to your VPN; i.e. a dynamic DNS service.
#1476
General Discussion / Re: Multi-Level Configuration
July 25, 2018, 03:43:42 PM
Does the internet router know where 10.0.0.0/8 lives?

Bart...
#1477
A VPN increases security by reducing your attack surface through moving services from public to private networks. The time that you have a public IP address has little bearing on that. You need a dynamic DNS record to reach the VPN server anyway, and there is no security in obscurity.

TL;DR: static IP for VPN is not more insecure

Bart...
#1478
18.1 Legacy Series / Re: IPv6 not working in VMware
July 23, 2018, 11:00:10 PM
Quote from: gex on July 23, 2018, 04:17:31 PM
so you can configure and can use e.g. OpenVPN only over IPv6?

Gregor

Yes, indeed. One /64 from the ISP range for the LAN and one for the VPN. Both LAN clients and VPN clients can browse over IPv6.

Not exclusively, no. OpenVPN won't connect over IPv6 only. You can give the server and clients 169.254.0.0/16 (a.k.a. IPv4 link-local) addresses if you don't want a routable IPv4 tunnel

Bart...
#1479
18.1 Legacy Series / Re: IPv6 not working in VMware
July 23, 2018, 03:12:11 PM
Works fine on ESXi 6.0 with ISP delegated range.

Bart...
#1480
Are these users in a directory somewhere? My first port of call would be Radius.

Bart...
#1481
Does your openvpn tunnel use a tap or a tun device?

Bart...
#1482
18.1 Legacy Series / Re: 2 Factor authentication
July 17, 2018, 08:25:55 AM
From the console use option 13 to return the firewall to a state before you locked yourself out.

Bart...
#1483
You need to separate them at layer 2 or layer 3 to force them to go through the firewall. That means (respectively) putting them on different VLAN's or on different IP subnets, or preferably both.

Different subnets is easiest, since the firewall is a router out of the box. You will need to move the web server to a different firewall network interface with a separate switch. If you don't want to have multiple firewall interfaces and multiple switches, VLAN separation is the answer.

Bart...
#1484
Post a screenshot of Services: Network Time: General to show settings?

Your time needs to be close to the current time, so set it approximately in the console e.g.

# date 181107183500

Bart...
#1485
Don't HE give you a static range? Zonomi will host your aaaa records for free, if there's not too many of them.

Bart...