OPNsense Forum

English Forums => General Discussion => Topic started by: birdpark on July 25, 2019, 12:31:40 PM

Title: Help with the TOR plugin
Post by: birdpark on July 25, 2019, 12:31:40 PM
Hi.
I am new to OPNsense and need some tips on routing all my traffic through TOR.
All the LAN traffic should go through TOR.
And the firewall setup should allow only traffic from the TOR service on WAN.

So far I had enabled the plugin and set it to listen on the LAN interface, but while I could see the TOR circuits formed in diagnostics,
my LAN traffic wasnt routed. I also tried to enable the 'Trasparent Proxy' option in 'advanced' and setup port forwarding, but failed.
A tutorial would help me a whole lot.
Title: Re: Help with the TOR plugin
Post by: birdpark on July 30, 2019, 10:10:51 PM
I will probably never find out by meself
Title: Re: Help with the TOR plugin
Post by: fabian on July 31, 2019, 05:19:55 PM
Did you add a firewall rule to redirect the traffic?
Title: Re: Help with the TOR plugin
Post by: birdpark on August 03, 2019, 07:43:45 PM
Now I cant get it to start in order to test it. My error is:
don't know how to load module '/boot/kernel/kernel'
can't load 'kernel'

Maybe its a good time to replace my sd card with an msata ssd.
But about my TOR problem, I think that was the issue, because I did not add firewall rules, except allow all.
So I think then maybe my question was more about the firewall rules that I needed to get it working.
But can you say more about how I can forward the traffic from LAN to the TOR service?
Because TOR doesnt get an interface of its own, so then how do I redirect traffic to it?
Title: Re: Help with the TOR plugin
Post by: fabian on August 03, 2019, 09:06:04 PM
You can configure TOR DNS and a transparent port. You need a DNAT rule (Port Forward) to forward the DNS traffic of this network to the TOR DNS and all TCP traffic to the TOR transparent port. You may not need UDP in that network so you can just block it.