Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Topics - wbravin

#1
General Discussion / firewall best practices
February 17, 2025, 12:09:09 AM
Hello all

I am in the throws of deploying opnsense (after 2 years) and i have the following project to be deployed next week.

1) go live with opnsense

2) re-assign ip4 addresses in a more logical sequence. I currently have dhcp assignments from 192.168.1.50 to 192.168.1.99. I also have about 20 IOT devices that i would want to reassign

3) start deployment of security system. Ther cameras, video doorbell and keypad will be installed on wednesday of next week

I do not use any cloud service for any devices or solutions. I am using a proxmox server as my main server and on this server i am running truenas scale, opensense and home assistant as VM and Tailscale qan pihole as LXC. In addition I have a backup bare metal truenas scale. I have 6 pcs around the house.

The truenas servers hold very personal documents and generic media

My server only connect to the internet to receive updates and to allow me (and a few individuals) remote access to everything (me) and only to certain datasets the other individuals 
I kind understand the need and i kind of know how to set up virtual networks.

My thinking would be to to setup a vn for all my servers one for my iot one for my pcs and one for guest (mainly individuals coming to my home and connecting their phone). I would like to build certain automation (emergencies) in home assistant to notify authorities. In addition HA will need to push notifications (including pictures and or videos from my security solution to my phone.

Can someone please direct me to documentation on where to learn and find best practices to set firewalls? In addition do I need to set up firewalls?

Thank you all in advance for the assistance provided

       
#2
General Discussion / Guidance on new lan set up
February 07, 2024, 10:49:16 AM
Hello all

I have been tinkering with OPNsense on or off for the last year.


I have OPNsense running (in a vanilla configuration) as a Proxmox VM on a dell r720 and for learning ant trying it out it runs perfectly.

The R720 is then connected to a managed switch (netgear GS724t) and I will my use 2 older ausus routers as wifi access points. These access points all have guest network access control> simple

I have:
2 servers running truenas
2 PCs
2 HTPC
and 2 tablets (running  Home assistant dashboards)
100mbps service from my IP provider 

No Vlans or anything else for that matter (i'm now learning on how to configure vlans and firewalls rules)

Now is the time that i will deploy it on my network.

This will mean moving the rack to my loft.


The HTPCs the TV, AMP and the PCs to a new local 2.5 gb switch In 3 rooms)  all swithwes will be connected with 6E directly from the OPNsense environment  (the HTPCs will have new NIC installed)

Since the time i started to learn and tinker with OPNsense technology has advanced to the point that I will take this opportunity to upgrade and improve my LAN environment.

My 2 objectives are:

       
  • increase my lan from 1gb to 2.5 gb for my PCs
  • Connect my server with a 10gb connection between them and have a 2.5gb access for the PCS
  • Allow remote access to my music (Jellyfin) and document environment (considering Tailscale) for myself and a few others
To achieve this, i will need to add/replace my NIC on the r720, the HTPC and some PCs to allow 2.5 and 10gb lan


My question


If i construct VLANs on OPNsense, do i need to connect OPNsense to a smart switch?


or Can i just connect the r720 to simple switches and then connect all my devices to the local switch




Thank you so much for your patience, guidace and help in this matter


#3
Hello all

I'm new to OpNsense.

I will use this solution as mu main router and firewall for my home environment

I installed in Proxmox on a dell r720. At the moment OPNsense is not operational because i'm still learning.  i plan to make it my main router and firewall solution by end of August.

In addition to OPNsense the Proxmox on the dell R720 will have as VMs Home Assistant and Tuenas

I need to have wifi functionality for Home Assistant to connect some devices

I currently run an Asus RT 87U as my main router and a DSL AC68U  as a wifi access point

I would also like to turn the RT87U in to an access point in september when i will go live with OPNsense

These 2 access points are connected via wireline to each other at the moment and at a later date to proxmox

My questions:

When i will make OPNsense my main router in September, will i need to add to the proxmox server a USB dongle with a wifi capability?

Or will OPNsense and all other VMs on the same proxmox server will serve wifi access point for for the server?

Or will i need to passthrough the wifi USB to Home Assistant 

Many thank for your patience and help in this matter.

Be all well
#4
General Discussion / installing a wifi 6 USB
May 24, 2023, 06:01:24 PM
Hello all


I have currently installed OPNsens 2.7 1.11 as a VM on Proxmox  on a DELL R710 for home use

I have been learning OPNsense and I added it as a VM on proxmox 7 late last year. As far as i can tell all is working well with no issues. I later added Home Assistant OS as a vm

Now the time has come to make OPNsense my main router for my house.

I would like to add a wifi 6 USB and wifi powerline repeaters to this mix.

1) would this be possible/make sense or work?

3) would i need to pass it through from proxmox to OPNsense and Home assistant

2) i see that a version 23.1 is available. however when i go to updates i do not see it available. How do i upgrade to this version ?  I can not see this upgrade ?

#5
General Discussion / opnsense install on esxi
August 29, 2022, 07:16:47 AM
Hello all

I'm new to opnsense and i'm not an it guy

My Current setup
Router: asus rt ac87u with ip 192.168.1.1

I was gifted an HP ml 350 g6 with vmware 6.7 installed.... great (btw i know nothing about vmware and i'm learning as i go)

I set up opnsense according to youtube video i saw.

opnsense will boot up and give me an ip 192.168.1.1 great

I login as root and opnsense selec 2 to change the ip to 192.168.1.5

I go to the GUI at that address and configure OPNsense in a vanilla configuration great.
( i do not want opnsense to be my main router for the moment or anything else until i know what i'm doing.

Once this is achieved i will make opnsense my main router and my asus  as an access point)

my issue;

When i login to opnsense via a web page and i configure it, I then go to the dashboard. I see a message thast i'm running on a installation media and i should reboot. Fine

in the vm it does reboot

when it finishes it presents to me ther original ip address 192.168.1.1  why?

I changed the lan ip in the configuration in the gui and in the shell in option 2
what am i missing?
thank you in advance for your help
#6
General Discussion / cannot access internet
July 22, 2020, 04:42:00 PM
hello all

I am a newbie at opnesens. I managed to install it on a dell r710.

This is a vanilla installation. No vlans no firewall.

opnsense lan is connected (192.168.1.2) to a dumb switch and i do see the other attached devices

from my pc which is in an other room i can access the opnsense server

my wan is set to ppoe with username and password from eolo (ISP) mtu 1500

the dashboard gives me messages than wan is up and displaying ip addresses from the isp
lan 192.168.1.2
wan 100.119.92.52  (i think this is an ipv6 address) how do i change it?
wan-gw 81.74.xx.xx.

the DNS i tried with 8.8.8.8 and with the DNS server address supplied by the ISP to no avail

I can ping www.yahoo.com and googlw .com with success

Yet i cannot access the internet from other devices

this solution is still in development phase. i still need to purchase the necessary smart switches and more powerlines


what am i missing?

Thank you
#7
General Discussion / fresh installation
June 29, 2020, 07:39:57 PM
hello all

I am a neophyte at opensense.

after a weekend spent to build and configure a dell r710 and after spending time to properly have the usb port read my usb, i finally got to install opnsene 20.1 on a 1tb hd.

Now I have the server boot and go straight to the opnsense script

I know nothing about opnsense and i am learning from the installation guide and the videos on youtube.

I did not assign lan or wan during the scipt.  The server is connected to one port of the NIC.

I do not want to use this server as a router for the moment therefore i did not assign a lan address.. if i add a lan ip from the console menu I assign an on the console level i assign a  it as dhcp

issues

1) why during the boot phase of opnsense do i always get ask for credentials before displaying the console menu?

2) how do i stop this?

Thank you for your patience and response


#8
Hello all; I am a noob of noob. I have been watching on youtube various videos relating to choosing, installing and configuring opnsense.

I live in a very old house in Italy. The house is built in stone and concrete and it has 3 floors. Although i remodelled some of the house infrastructure I have no way of running cables.

At the moment I have 2 servers running freenas and one of the servers is based on a consumer pc architecture. Currently the whole house is connected via gigabit powerline and they are connected to simple switches and it all works well. Currently I have an asus rt ac87u as a router that is sitting in the living room. It currently provides me with my wifi needs.

So because i have too much time on my hands I decided to have a more robust and flexible router. (I have IOT, remote users such as my daughter who lives in the UK and friends in Canada and home automation).

So I buy a dell r710 because it has 4 lan ports. Yes it is an overkill but I will replace it next spring with an R610. I receive my internet service from EOLO (which transmit via radio waves and I receive the signal via a dish in turn connects to a eolo box (which is a small brick that has the satellite feed in and the out goes to the wan port of my current router in the living room.

My next step Is to install all IT equipment in a rack and move it to the loft.
I will move the internet feed from the living room to the loft.

So now opnsense will be in the loft which will be connected to a managed switch which will have direct connection to the server environment. Then I plan going from the switch to a powerline connection which will connect all my pcs in my house fine.

Finally my question:
I want to use current router as an AP (I read that this is possible)

Can I leave the current router in the living room and have it fed by a powerline and still act as an AP?

I fear that moving the asus to the loft i will not have sufficient band strength to feed my guests and I when we are on the ground floor or outside in the yard.

Thank you for taking the time to read this and responding