OPNsense Forum

Archive => 16.7 Legacy Series => Topic started by: Julien on July 05, 2016, 01:23:19 am

Title: monitor on 16.7
Post by: Julien on July 05, 2016, 01:23:19 am
Hi Guys,
is it possible to configure the FW to send out a email in case of " reboot, WAN is down.... )
i see this option already exist on the notification, but somehow the emails are not sending out.
thank you
Title: Re: monitor on 16.7
Post by: weust on July 05, 2016, 07:49:56 am
So, you're basically asking for something that already exists but you can't get it to work?
Title: Re: monitor on 16.7
Post by: franco on July 05, 2016, 10:34:17 am
It sounds like this is not specific to 16.7... do you receive notifications in general or are there *no* emails whatsoever?
Title: Re: monitor on 16.7
Post by: Julien on July 05, 2016, 07:45:40 pm
yes i receive notification, when i press send test notification.
but whenever the firewall goes down, or rebooted it doesn't send a notification
Title: Re: monitor on 16.7
Post by: bobbythomas on July 05, 2016, 07:50:48 pm
Jamerson,

Do you have two WAN (internet) links? If not then I don't think you will receive any notification as there is no internet connection when WAN link is down. I also have notification enabled and have DDNS configure and I get dynamic ip from my ISP and I get DDNS update notification whenever I get a new IP.

Thank you,
Regards,
Bobby Thomas
Title: Re: monitor on 16.7
Post by: Julien on July 05, 2016, 08:02:52 pm
thank you for your answer.
i tried and removed the WAN cable to see if it will send out email, but it didn't
Title: Re: monitor on 16.7
Post by: phoenix on July 05, 2016, 08:43:08 pm
thank you for your answer.
i tried and removed the WAN cable to see if it will send out email, but it didn't

You haven't really described your configuration as asked in the previous post by bobbythomas, it would help a lot if you gave a clear description of your set-up.
Title: Re: monitor on 16.7
Post by: Julien on July 05, 2016, 11:25:07 pm
thank you for your answer.
i tried and removed the WAN cable to see if it will send out email, but it didn't

You haven't really described your configuration as asked in the previous post by bobbythomas, it would help a lot if you gave a clear description of your set-up.
Hi Phoenix,
Notification configuration is stright forward,
on the notification bar there is nothing else to enable or to configure.
am i missing some steps hier ?
Title: Re: monitor on 16.7
Post by: franco on July 06, 2016, 10:05:17 am
Do you have Multi-WAN? If not, and your servers lie outside of your LAN the notification cannot possibly reach the server as your link is down...
Title: Re: monitor on 16.7
Post by: Julien on July 06, 2016, 08:24:07 pm
Do you have Multi-WAN? If not, and your servers lie outside of your LAN the notification cannot possibly reach the server as your link is down...
thank you Frank,
as i understand the notifications will works, only if there are two WANS ?
yes my VM has two WAN'S
is there somewhere i can select what kind of notifications to send ? like DHCP, new DHCP, Down WAN,..... ?
Title: Re: monitor on 16.7
Post by: bartjsmit on July 07, 2016, 05:22:16 pm
Hi Jamerson,

System, Settings, Notification

Please post what your OPNsense has under SMTP E-Mail, E-Mail Server.

Bart...
Title: Re: monitor on 16.7
Post by: Julien on July 07, 2016, 08:08:56 pm
Hi Jamerson,

System, Settings, Notification

Please post what your OPNsense has under SMTP E-Mail, E-Mail Server.

Bart...
Hi Jamerson,

System, Settings, Notification

Please post what your OPNsense has under SMTP E-Mail, E-Mail Server.

Bart...
Thank you for your answer bartsmit.
see below

(https://s31.postimg.org/b71t800yz/Screen_Shot_2016_07_07_at_8_03_54_PM.png) (https://postimg.org/image/6xx35txpj/)adult image hosting (https://postimage.org/)
(https://s32.postimg.org/o8s4yrokl/Screen_Shot_2016_07_07_at_8_04_04_PM.png) (https://postimg.org/image/h5k9j5j4x/)free image uploading (https://postimage.org/)
Title: Re: monitor on 16.7
Post by: ford on July 07, 2016, 08:54:13 pm
Hi Jamerson,

OK, same here. I want to post it to german threats, but you were faster ;-)

A couple of weeks i found this from January:
<https://forum.opnsense.org/index.php?topic=1990.msg6242#msg6242>

Hmm.

Test mails works fine, but these needs a little bit more content.
btw. I tried 3 mailproviders, but only TLS on 25 works.

cheerz
Rainer
Title: Re: monitor on 16.7
Post by: bartjsmit on July 08, 2016, 12:19:26 pm
Hi Jamerson,

Can you replace the smtp.domain.com FQDN with the internal IP for your internal mail server?

As Bobby Thomas mentioned, you may not receive notification if your mail path depends on the firewall for its internet connection.

If you don't have an internal mail server, you may need to spin up a simple postfix MTA that stores the notification email and forwards it once the connection is back up. You can tune minimal/maximal backoff time parameters to get it to retry soon after the reboot.

Bart...
Title: Re: monitor on 16.7
Post by: Julien on July 08, 2016, 01:09:44 pm
Hi Jamerson,

Can you replace the smtp.domain.com FQDN with the internal IP for your internal mail server?

As Bobby Thomas mentioned, you may not receive notification if your mail path depends on the firewall for its internet connection.

If you don't have an internal mail server, you may need to spin up a simple postfix MTA that stores the notification email and forwards it once the connection is back up. You can tune minimal/maximal backoff time parameters to get it to retry soon after the reboot.

Bart...
Hi Bart,
thank you for your answer.
we don't have a internal mail server, we send with the ISP smarthost.
is it possible to send the warning after the firewall is back ? send the warning after the firewall reach the internet ?
would love to have this configured.
Title: Re: monitor on 16.7
Post by: franco on July 08, 2016, 01:39:16 pm
Hi jamerson,

This would require a relay server in your local network or on the firewall, dispatching the SMTP message as a simple notification client will not save it.

We don't have sendmail in OPNsense (deactivated via FreeBSD build), but we could bring in opensmtpd as a package. But I don't want to do a plugin, the scope is a bit far. May be easier to setup a relay in your internal network.


Cheers,
Franco
Title: Re: monitor on 16.7
Post by: Julien on July 08, 2016, 04:32:25 pm
Thank you Franco for your answers.
we have some customers using internal exchange , but the internal exchange sending using the smarthost, the smarthost won't be a relay unfortunately .
what kind of warning does the firewall send ? if there is a new DHCP detected ? IP conflict ?....
thank you
Title: Re: monitor on 16.7
Post by: franco on July 08, 2016, 05:47:49 pm
Varieties of this message: MONITOR: %s is down, removing from routing group %s

It also requires you to enable gateway monitoring, maybe that's not obvious because the default is off.

I will pick up opensmptd as a package for 16.7.


Cheers,
Franco
Title: Re: monitor on 16.7
Post by: franco on July 08, 2016, 07:48:09 pm
opensmtpd package will be available in the next RC2 update.

https://github.com/opnsense/tools/commit/0d0b43ee9e4637f7daf0642079c97f51d6d1b9bf
Title: Re: monitor on 16.7
Post by: Julien on July 08, 2016, 11:18:15 pm
Thank you Franco,
will this be easy to configure ? when are we expecting the RC2 ?
Title: Re: monitor on 16.7
Post by: franco on July 11, 2016, 11:08:10 am
RC2 this week. For OpenSMPTd tutorial look here: https://calomel.org/opensmtpd.html