Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Topics - Timmy

#1
Hi all,

I have a setup with OpnSense at one location 'home' - it has a static WAN IP and runs a WireGuard server. I have a second location 'remote' on an EdgeRouter X. I have set that up with a WireGuard client config that connects to home. That site has firewall rules and routes configured to connect to resources at home from the LAN on remote.

I also setup a WireGuard server on the EdgeRouter for remote access / support if I needed - but that site is about to go behind CG NAT and I won't be able to connect to it anymore.

I am trying to workout what gateway and routes I need to setup on the OpnSense device to permit access from the 'Home' LAN to the resources in the 'Remote' LAN.

ie, load the web interface on 192.168.8.46

When I am on the OpnSense router I can ping the WG client IP 172.16.16.4 - but I can't ping it from any device on the LAN.

(IPs in the image are all made up, but reflect the environment, ie the LAN / WG subnets are all different.

Any advice?



Thanks
#2
23.7 Legacy Series / Near constant PTR lookups in DNS logs
September 15, 2023, 02:09:04 AM
On my current install of OpnSense I have near constant lookups for PTR records for all my internal IPs (ones reserved in DHCP, and any standard leases. There are blocks of lookups only a few seconds apart - example attached.

Screenshot of lookups https://i.imgur.com/NlNkDR3.png

As an example of how many requests are being made:
https://i.imgur.com/vXTvlvi.png
https://i.imgur.com/aBtM6eN.png

Much searching lead me to a possible patch Unbound.inc for how it was handling aliases for 23.7 -> https://github.com/opnsense/core/pull/5925

However I think unbound.inc has been patched in my deployment already.

When I first installed the system it was using Unbound for DNS, but I moved to AdGuard. Moving back to Unbound for DNS didn't change anything. Unbound is not currently running as a service.

I was reading somewhere that it was a reporting component creating all the requests, but I have turned off most of the reporting I could find that I thought could be generating the request.


Report config:
https://i.imgur.com/be36sP4.png

Collected reports:
ipsec-packets
ipsec-traffic
lan-packets
lan-traffic
opt1-packets
opt1-traffic
opt2-packets
opt2-traffic
opt3-packets
opt3-traffic
opt4-packets
opt4-traffic
system-cputemp
system-mbuf
system-memory
system-processor
system-states
wan-packets
wan-traffic


Installation:
Version: 23.7.3   
Architecture: amd64   
Commit: 273c5bf46

Any ideas?

Thanks.