Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - cookiemonster

#1366
At a guess Iar.hed (and franco surely will correct me) unbound_configure_do() is just a task in the plugins_configure dns () function. It doesn't mean it starts up Unbound.
If you give it time to start up all services, do you see it running? sudo ps -aux | grep -i unbound should do it
#1367
General Discussion / Re: Traffic from LAN -> OPT
November 06, 2023, 10:28:16 PM
yes, apologies both.
#1368
General Discussion / Re: Provider compatability
November 06, 2023, 12:09:41 AM
the "software" is reliant on the physical connection only to establish the physical links. It'll use what that link provides to sync a speed.
Note of caution though. RJ11 at least in the UK are used (still) to connect xDSL lines which need an authentication before the link gets established and a session created on BRAS at the ISP edge. That means for the user, that they need to enter credentials on a device doing this handshake. OPN has PPoE , PPE and others for the WAN. This I expect to "work" for one WAN. As to the speeds achieved via this RJ11 to RJ45, I don't know but imagine it depends on quality of the connector and other extraneous factors.
As to two broadband lines, then you would have the same option for the second port on the appliance and you'll clearly need one more interface at least for LAN i.e. minimum 3 interfaces.
Finally, those two WANs, once setup, can not be used to "aggregate" the bandwith but I suppose you already know that.
#1369
General Discussion / Re: Traffic from LAN -> OPT
November 05, 2023, 11:43:00 PM
> The default rules should allow you to do this with no changes.  LAN has access to everything.
I believe a rule is needed on every new network created by the addition of a new interface. LAN doesn't get access to them by default and this is what the OP needs.
On OPT interface you need a rule:
Action: pass
Interface : OPT
Direction : in
TCP and Protocol : to your needs
Source: LAN net
Destination: OPT net
#1370
show your port forward rule please
#1371
Right, I begin to understand.
You're probably missing an allow in firewall rule in on the LAN interface. Source "IPTV net". That is a rule that will allow traffic in on the LAN interface, for traffic coming from the IPTV network.
Might not free you from having to deal with igmp proxying requirements but start from there.
#1372
Assuming you mean Wifi AP not API :) . Depends on requirements.
If commercial/industrial: they often require auth options, multi SSD, VLAN support, etc. One set of choices.
If consumer: If is home and you are in control of your requirements, perhaps you can share them. At the most basic level an old router set to AP can work and better if you can install DD-WRT or similar on it.
#1373
that could be the managed switch. It needs to allow the VLAN to accept traffic on the access port that is used to carry those packets.
#1374
23.7 Legacy Series / Re: NGINX no resolver defined
November 03, 2023, 11:44:18 AM
One can be added in some nginx contexts but that's not in the UI as far as I can see so it would need a custom include I imagine.
That said, bimbar is right, and unless you have a very specific requirement to go down that route, then the name resolution should be the global one. The question is why is your nginx installation not using it.  Are you using the plugin?
#1375
that is better, yes. Switch doing the switching rather than the router
#1376
OK. First I'd do a checkconfig Unbound-checkconf as a very basic sanity check.That tells you it won't bomb out and the configuration of itself is OK.
Then you need to look around it. What rules are in place in the firewall that might be problematic.
Frankly shouldn't be a problem from one minor OPN version to the next.
Any chance of diagraming your setup? See, "my wan/lan/ect dropped" doesn't give anything to work with :)
You'd want to consider when it happens, drop to a shell on the affected client, do dig or nslookup requests and follow the packet on the firewall live session with adequate logging set or a packet capture.
#1377
sorry to interfere. I wouldn't replace new config with old one after an update/upgrade of the software/application that uses it. It's normal to have different configs from one version to another.
You really need to diagnose the setup that post update doesn't seem to work correctly, if there is time or rollback but not a partial rollback that will just make it worse (most likely).
#1378
23.7 Legacy Series / Re: Suricata IPS Multi Tenancy
November 01, 2023, 09:54:41 PM
it is free and the actual name is AdGuardHome. It is free and there is a plugin for OPN by mimugmail.
It's pretty good. I only use it for blocking adverts but has an easy push-of-a-button block for quite a few services, including tiktok.
#1379
that info is for if you wanted to run the command from the shell as per OP.
These or at least some of these hooks are there in the UI, the automations tab.