Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Topics - Psychic49

#1
Good afternoon!
I went through several OpenVPN setup tutorials and am confident I have almost everything setup correctly (internal CA,  server certificate, OpenVPN Server with aforementioned server certificate, user with client certificate). I made a test connection from my phone using the OpenVPN client and importing the .ovpn profile. The connection was successful and I see it under the "Connection Status" tab.

This is where things get a little weird and I'm left with a few questions.
1. I've tried pinging back and fourth (from phone to servers, gateway, and vice versa). Looking through the firewall logs, I can see the traffic getting allowed. However, the response is never received. I ran a packet capture and checked it out in Wireshark and it said the same thing. I can see my ping requests going out (from VPN-ed client to the default gateway, or to a server it should have access to) but the response is never received. And this isn't unique to ping, I can't seem to receive any kind of response. But the traffic is definitely not getting blocked. I also cannot ping the VPN client from the firewall itself or servers behind the firewall, even though firewall logs show the traffic being allowed. I've tried pinging the client IP from all the different interfaces.

None of the tutorials I followed did anything with NAT so I'm thinking there may be a routing problem, but I don't know how to solve the problem. And this leads me into my seconds question...

2. I used the setup wizard to create the OpenVPN server. It did NOT create a new interface under Interfaces. However, looking at the interfaces under Firewall -> Rules, I do see a new one named "OpenVPN". But, if I go back to Interfaces and go to Assignments, I see that there is a new interface that is ready to be created. So I went ahead and added/enabled it. This resulted in a second OpenVPN interface being listed Firewall -> Rules.

Something tells me that I shouldn't do this, but I feel like the interface needs to be Enabled at the very least. Is there a reason why the Interface wasn't created by OPNsense but it still shows up under Firewall -> Rules?

3. During the setup for the OpenVPN server, it asked for the "IPv4 Tunnel Network" and the "IPv4 Local Network/s". I don't want the clients to have access to my LAN. I had already created a designated DMZ that I would allow them access to instead and put that CIDR into the IPv4 Local Network/s field. However, I don't understand the logic behind the "IPv4 Local Network/s" setting. I'm just going to create firewall rules for the OpenVPN interface to allow it access to where I want it to access. So what's the purpose behind this setting, why is it necessary? 
#2
21.1 Legacy Series / No Outbound Traffic Reporting
January 29, 2021, 03:39:54 AM
The "Out (bps)" does not appear to be populated with any data. Interestingly enough, the "Top hosts out (bps)" graph is populated.

Sensei is running on Guest and LAN interfaces.
Suricata is running on WAN interface.

#3
See pictures below.

What's going on here? Is this a known bug? The only module that works (partially) is reporting -> traffic.

Traffic Graph (dashboard): https://i.imgur.com/dOFLUyM.png
NetData (the spikes only go up to 6mbps, and not even during the testing time): https://i.imgur.com/OE8P1Hx.png
Reporting -> Traffic - partially working, graphs on top half zeroed: https://i.imgur.com/WeNIZOx.png
Reporting -> Insight - data way off, stating 14MB total traffic
#4
General Discussion / Geoblock via Alias Not Working
December 20, 2020, 01:21:50 AM
As a test, I created an alias for Canada (also did the MaxMind setup beforehand) and created a WAN rule as seen below: WAN out, any source, destination Canada alias, IPv4+IPv6, Any protocol, Reject.

However, nothing is getting blocked. I've ran a few simple tests such as going to google.ca, but so far no results.

https://i.imgur.com/QTNeOOS.png
#5
Hi all,

Yesterday I setup an OPNsense server to replace my old router. I'm still learning how to use it to track down network problems. Every few hours, I experience a momentary network outage across all my devices that lasts about 15 seconds.

Checking the console, I see many NVMe errors and I'm thinking they might be related.

Has anyone else ever experienced problems like this NVMe drives and do you think these errors are the cause of my problems?
I restarted my server an hour ago and haven't had any network outages since, and no errors in the console. I'm willing to bet that when the next outage happens, there will be errors in the console.

https://i.imgur.com/eylDvIW.jpg
(sorry image didn't come through correctly the first time)

Also, where can I go to analyze historical data from this period of time?

I'm running Sensei on LAN, Suricata on WAN, and Clam AV. I'm using the below NIC and running on an Optiplex (used) with a 9th gen i5 and a 250gb NVMe.

https://www.amazon.com/gp/product/B002JLKNIW/ref=ppx_yo_dt_b_asin_title_o03_s00?ie=UTF8&psc=1
#6
Hardware and Performance / i3-10100 Build
December 07, 2020, 12:27:04 AM
I've finally acquired the resources necessary to begin purchasing parts, but this is my first OPNsense build and I'd be grateful for any specific hardware suggestions. My budget is $300-600, but can be flexible. Will be using OPNsense for IPS, Sensei, adblocking, geoblocking, and web content filtering for up to 15 devices. I really want to go for the i3 to be on the safe side. I do indeed own a rack, but the rack builds seem rather expensive.
Parts wise, I was thinking:
Processor: i3-10100 - $105
Motherboard: ASUS Prime B460M-A LGA 1200 - $122
PCIe NIC: Dell Intel PRO/1000 VT Quad Port Server Adapter LP PCI-E with Both BR - used $43
RAM: TEAMGROUP T-Force T1 DDR4 16GB Kit (2 x 8GB) 2666MHz - $50
SSD: 860 EVO 250GB - $50
CPU Cooler: Noctua NH-L9i - $40
Case: Rosewill 2U Server Chassis RSV-Z2700 - $100
Power Supply: EVGA 110-BQ-0500-K1 500W Bronze - $75
Total: $585
I've only built one other computer before, so I realize that this proposed build is probably a mess, that's why I'm reading out to the community.

Any help would be appreciated!!