Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - abalsam

#16
Development and Code Review / Re: Wireguard in opnsense
September 05, 2018, 04:59:50 AM
I read through the howto and it references the wireguard 0.3 plugin.  However, when I checked the version installed with pkg I see I am 0.1.  Do you know when 0.3 will be available through pkg?

Thanks
#17
Development and Code Review / Re: Wireguard in opnsense
September 03, 2018, 11:17:26 PM
Sounds great as I am also having issues connecting to the wireguard.com test connection and the azirev configurations.  Also, please update the howto to include instructions on how to connect to VPN servers/providers.

Thanks
#18
17.1 Legacy Series / Re: VPN and IP's
March 06, 2017, 11:26:48 PM
Depending on how the VPN is set up, the machine in VPN can communicate with other machines on the same subnet directly but everything else ends up routed through the VPN.  If that is the case with your configuration, you may need to set up a NAT from the internet to the NAS so that the NAS thinks it is communicating with a local IP address.

Hope this helps.
#19
16.7 Legacy Series / Re: Remote administration via SSH
December 22, 2016, 04:36:14 AM
I noted that you said this is for a lab environment.  That almost always means private IP address used on the WAN interface. Please double check on the WAN interface settings that the "Block Private Networks" option is not checked.  Otherwise it would block all traffic coming into the WAN interface.
#20
When I reviewed the content of the mirror, it looks like some of the same packages are present in multiple locations (which implies symlinks on the source).  If I just did a sync of the entire mirror, I am afraid I would be copying more than I would need to.  Is there a document that I can refer to that would tell me how to set up a local mirror?

Thanks
#21
Thank you sir.
#22
I have found OPNSense to be a full featured, well documented and easy to use solution that can have a small memory/processor footprint (depending on what features are actively in use).  I am therefore using it as my standard firewall not only for my home but also for my test labs.  This means that when all of my labs are running, I have 10 to 20 OPNSense VMs running at once.  When a series of patches are then released, I have to go through the update process on all of the instances.  Since, at the end of the update process the downloaded files are deleted and I am unable to find a way to point to a dedicated caching proxy where the update files can be downloaded again locally, the same files need to be downloaded from the internet again and again (consuming bandwidth).

I was wondering if there are any plans to support configuring a dedicated caching proxy for updates only.  Alternatively, is there a way to download and centrally maintain update files for select platforms (similar to what Ubuntu offers) so that I could have an internal mirror I could point my VMs to?

Thanks
#23
I was going through the list of what is to be completed prior to release 17.1 and saw the line "reverting CARP usage back to BSD standards."  I was hoping for more information on how the current CARP implementation deviates from BSD standards and what functionality would be lost in doing so.

Thanks