Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Topics - gsellc

#1
18.7 Legacy Series / Upgrade Path question
May 06, 2018, 07:20:56 AM
I'm preparing to put together a configuration to be shipped to a remote site. Is there going to be a "headless" upgrade path from 18.1 to 18.7, or should I just wait until 18.7 becomes the production series. I have options and would rather wait if I'll be unable to upgrade remotely.
#2
root@opnsense:~ # pkg upgrade -n
Updating OPNsense repository catalogue...
pkg: Repository OPNsense load error: access repo file(/var/db/pkg/repo-OPNsense.sqlite) failed: No such file or directory
pkg: http://pkg.opnsense.org/FreeBSD:11:i386/18.1/latest/meta.txz: Not Found
repository OPNsense has no meta file, using default settings
pkg: http://pkg.opnsense.org/FreeBSD:11:i386/18.1/latest/packagesite.txz: Not Found
Unable to update repository OPNsense
Error updating repositories!
root@opnsense:~ # curl http://pkg.opnsense.org/FreeBSD:11:i386/18.1/latest/packagesite.txz
<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>404 Not Found</title>
</head><body>
<h1>Not Found</h1>
<p>The requested URL /FreeBSD:11:i386/18.1/latest/packagesite.txz was not found on this server.</p>
</body></html>
#3
I'm setting up a Soekris Net6501 with 18.1 to replace an identical piece of hardware running OpenBSD 6.0 or thereabouts. Installation and basic configuration went fine. The device sits on a network with 3 VLANs (plus the unused native VLAN 1 - designated "LAN" on this box) and 3 "WAN" connections. The WAN connections are consumer grade DSL and use a routing modem, so on the OPNSense router I have interfaces as such:

em0:
        inet 172.40.1.1 netmask 0xffffff00 broadcast 172.40.1.255
em1:
        inet 192.168.1.2 netmask 0xffffff00 broadcast 192.168.1.255
em2:
        inet 192.168.2.2 netmask 0xffffff00 broadcast 192.168.2.255
em3:
        inet 192.168.3.2 netmask 0xffffff00 broadcast 192.168.3.255
em0_vlan10:
        inet 172.40.10.1 netmask 0xffffff00 broadcast 172.40.10.255
        vlan: 10 vlanpcp: 0 parent interface: em0
em0_vlan20:
        inet 172.40.20.1 netmask 0xffffff00 broadcast 172.40.20.255
        vlan: 20 vlanpcp: 0 parent interface: em0
em0_vlan30:
        inet 172.40.30.1 netmask 0xffffff00 broadcast 172.40.30.255
        vlan: 30 vlanpcp: 0 parent interface: em0


Hopefully self explanatory.

The situation is that I followed the multi-wan instructions:

Docs » User Manual » How to's » Setup Multi WAN

And the setup all seemed to be very straightforward, everything is working as advertised, but performance is abysmal. Often connections fail entirely and when they don't fail they react VERY VERY slowly. It feels a lot like an MTU issue on a PPPoE connection, however there is no PPPoE and the MTU was 1500 on all interfaces on the router this one is replacing with no MSS clamping or other such configs in place.

If I modify my PBRs on the individual VLAN firewall allow rules to use a specific default gateway instead of using the gateway group traffic immediately flows normally. In my mind this eliminates the thought that the problem could be:

NAT related
MTU related
DNS related (actually this seems to be working fine since it's proxied)
Uplink related (tested all 3)

At this point there is no VPN configured, no IPS/IDS, nothing else fancy. I'm not sure what else to look at to troubleshoot this further.

Love the product and look forward to making it work for me in this configuration. Thanks in advance.