OPNsense Forum

English Forums => General Discussion => Topic started by: FriendlyObserver on February 10, 2024, 10:35:36 AM

Title: NRPE move from package to plugin on 24.1
Post by: FriendlyObserver on February 10, 2024, 10:35:36 AM
Dear All,

Before upgrading to 24.1, I did use NRPE via the manually installed package. I had/have a LAN firewall rule pointing port 5666/tcp from the LAN network or address to "This Firewall".

After moving to the package, external calls to NRPE always generate: CHECK_NRPE STATE CRITICAL: Socket timeout after 10 seconds. I do not find relevant log entries on the firewall.

Connecting to NRPE set up to listen on port 5666 address 127.0.0.1 allowing the right hosts and allowing arguments. Two commands (check_users and check_load) are set up in the GUI.

When connecting to the firewall via SSH, everything does look quite good:
- Typing check commands (as root) does work well, for example /usr/local/libexec/nagios/check_users -w 5 -c 10
- /usr/local/etc/nrpe.cfg does contain a configuration matching what is set via the GUI and including nrpe_commands.cfg
- /usr/local/etc/nrpe_commands.cfg has the commands defined in the GUI

Probably the issue is to pick the correct listen address and to define the right firewall rule. Can someone help, please?

Regards,

Michael Schefczyk