Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - elektroinside

#121
Do you have a rule which allows traffic on that port or forwards the port to something else? You also need to have a service which listens on that port (accepts connections), what is that service? Also, what kind of port are we talking about, TCP or UDP?

If you have no rules allowing/forwarding traffic on that port, try scanning with something else, there's a chance that the scanner is not accurate.

I had my share of problems with OPNsense over time, but security wasn't one of them, never read about the firewall not doing its job, so I'm almost certain it's not OPNsense related :-)
#122
18.1 Legacy Series / Re: 2FA troubles
March 27, 2018, 12:14:57 AM
No worries, we are all constantly learning stuff. Glad to hear you made it work!

Welcome to OPNsense!
#123
And yet, we all here picked OPNsense over pfsense.. and many coming from pfsense.
#124
Very happy to hear it helped.
You're welcome!
#125
Are you scanning from the internet or locally from your LAN?
#126
PPPoE is single threaded and will eat up a lot of CPU if the traffic is intense and the CPU is not powerful enough...

You can disable (set it to "disabled") IPv6 entirely on the WAN.
#127
General Discussion / Re: New user of Opnsense
March 26, 2018, 03:01:07 PM
Hi and welcome!

#1 You can use advanced firewall rules for this
#2 You can use firewall rules and 2FA to enforce ssh, combined with security certificates
#3 Check your IDPS alerts and allow blocked but needed resources
#4 Which ones? Firewall logs?
#5 Don't understand this question
#6 You can create other users and assign permissions, root can be disabled, all from the WebGUI

This is a good starting place to learn about the features of OPNsense:
https://wiki.opnsense.org/manual.html
#128
18.1 Legacy Series / Re: OpenDNS Autoupdate?
March 26, 2018, 02:49:14 PM
It should automatically update your IP address stored and used by your OpenDNS account.

Do you have "Filter DNS requests using OpenDNS" checked?
#129
18.1 Legacy Series / Re: cron to check wan ip?
March 26, 2018, 02:22:16 PM
According to IANA (https://www.iana.org/assignments/iana-ipv4-special-registry/iana-ipv4-special-registry.xhtml), only 100.64.0.0/10 (100.64.0.0 –100.127.255.255) is considered as special purpose address block (https://tools.ietf.org/html/rfc6598).

Is this the case? It is important not to act on any other address blocks.
#130
Good to hear you made it work! CentOS has its firewall enabled by default, so you must add exceptions for anything.

Thanks for your feedback. You can just prepend [Solved] to the title yourself, if you'd like.
#131
Only local resources are denied when captive portal is up? Pinging outside resources works?
#132
Thank you for your feedback, glad to hear it worked out!
#133
18.1 Legacy Series / Re: DMZ trouble with DNS
March 26, 2018, 07:31:05 AM
Thanks for your feedback, appreciated.
Also, you can prepend [Solved] to the title if you feel you no longer have related issues.
Thanks again.
#134
18.1 Legacy Series / Re: Multiple PPPoE not working
March 26, 2018, 07:17:18 AM
Well.. this is over my head, so I'll leave you in very good hands, I'm sure Franco will get to the bottom of this :)
#135
18.1 Legacy Series / Re: [Solved] 18.1.5 issues
March 26, 2018, 01:19:34 AM
WAN: IPv4 is PPPoE, IPv6 is DHCPv6
LAN1: IPv4 is "Static IP", IPv6 is "Track interface"
LAN2: IPv4 is "Static IP", IPv6 is disabled (this is for the guest wifi network, without a captive portal)

On both LANs, DHCPv4 is running, no DHCPv6.
Simple, by the book setup :)