Thanks @davesworld - Great stuff!
I'd forgotten what my Vigor130 interface even looked like! :o
I'd forgotten what my Vigor130 interface even looked like! :o
This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.
Show posts MenuQuote from: Ric878 on August 05, 2018, 03:35:46 AM
If I remove the OPNsense box from the equation, I consistently get the faster 900 - 940 Mbps speed test results.
QuoteWe need to identify a parent interface before we start configuring VLANs, the parent interface refers to the physical interface where the VLANs will reside, e.g igb3 or ix0. Due to inconsistent behaviour with some NICs, you should not assign your parent interface to any interface in pfSense. Its sole function is to act as the parent interface to the VLANs we create.
Quote from: RicAtiC on July 29, 2018, 10:44:06 PMIt certainly looks like your VLAN tag is being dropped - hence OPNsense offering an IP from your untagged 192.168.0.X network. (This was the same symptom as I previously experienced when I neglected to add the relevant ports to the vswitches within my ESXi install). Is there any way to check whether your tags are getting through at all? Perhaps a manual setup on one of the laptops to confirm it can access only via that set vlan?
My log shows the following:
Jul 29 22:27:52 dhcpd: DHCPOFFER on 192.168.0.6 to 34:xx:a9:7f:xx:8b (LiLaLaptop) via re0
Jul 29 22:27:52 dhcpd: DHCPDISCOVER from 34:xx:a9:7f:xx:8b (LiLaLaptop) via re0
Jul 29 22:27:44 dhcpd: DHCPOFFER on 192.168.0.6 to 34:xx:a9:7f:xx:8b (LiLaLaptop) via re0
Jul 29 22:27:44 dhcpd: DHCPDISCOVER from 34:xx:a9:7f:xx:8b (LiLaLaptop) via re0
Jul 29 22:27:40 dhcpd: DHCPOFFER on 192.168.0.6 to 34:xx:a9:7f:xx:8b (LiLaLaptop) via re0
Jul 29 22:27:39 dhcpd: DHCPDISCOVER from 34:xx:a9:7f:xx:8b via re0
I doubble checked the configured DHCPv4 config an the range is correct (192.168.10.X)?! So why does the firewall offer an IP from the DEFAULT VLAN?
Any Idea?
Quote from: RicAtiC on July 29, 2018, 10:58:31 PMI have left the untagged interface and in fact have a number of machines connected to it - one of which is my AP similar to how yours seems to act.
Did you delete the physikal interface (on my APU-Board it`s called "re0") in the "Interface" -> "Assignment" menu? So you only have the VLANs (for example VLAN10 on re0) or did you leave it?
Quote from: Jessfu on July 25, 2018, 08:47:27 AMThe static IPs, in my case are 172.17.X.1/24 and the DHCP server range is set 172.17.X.100-199 with all other settings on that page blank. I'm guessing your differing X locations may just have been typos?
The VLAN interfaces have static IPs (192.168.X.100). For each VLAN a DHCP range from 192.168.X.1 to 192.168.X.99 is configured.
Jul 27 20:59:24 dhcpd: DHCPACK on 172.17.20.103 to 00:1b:24:9f:xx:05 (nc2400) via em2_vlan20
Jul 27 20:59:24 dhcpd: DHCPREQUEST for 172.17.20.103 (172.17.20.1) from 00:1b:24:9f:xx:05 (nc2400) via em2_vlan20
Jul 27 20:59:24 dhcpd: DHCPOFFER on 172.17.20.103 to 00:1b:24:9f:xx:05 (nc2400) via em2_vlan20
Jul 27 20:59:23 dhcpd: DHCPDISCOVER from 00:1b:24:9f:xx:05 via em2_vlan20IPv4 * This Firewall * 212.32.245.132 * * ALLOW OPNsense Update WAN Jul 24 20:48:13 61.xxx.xxx.xx:3118 212.32.245.132:80 tcp USER_RULE: ALLOW OPNsense Update
WAN Jul 24 20:48:10 61.xxx.xxx.xx:62638 212.32.245.132:443 tcp USER_RULE: ALLOW OPNsense Update
Quote from: franco on July 24, 2018, 08:09:31 AMHa! Yes, no expectation that that would occur. Figured if this is the only thing that doesn't appear to work on my network but that I had a work-around, then it was simply easier to just perform the work-around!
The problem won't go away by expecting fixes from our side when we don't even know what's wrong.
root@OPNsense:~ # fetch https://pkg.opnsense.org/FreeBSD:11:amd64/18.1/sets/changelog.txz.sig
changelog.txz.sig 100% of 1332 B 8498 kBps 00m00sTimeout while connecting to the selected mirror. Quote from: thereaper on July 20, 2018, 06:01:25 PMAnother thought - have a look at using Dnsmasq DNS (the DNS forwarder in OPNsense, rather than Unbound resolver) - I have a feeling it may support whitelisting.
More refined question. How do I whitelist DNS queries from my LAN clients on OPN box ? (forget VPN).
System: Firmware
Firmware status check was aborted internally. Please try again.
Updates
Version Date
18.1.10 2018-06-21
18.1.9 2018-05-31
18.1.8 2018-05-17
18.1.7 2018-05-03System Information
Name OPNsense.local.lan
Versions OPNsense 18.1.12-amd64
FreeBSD 11.1-RELEASE-p11
LibreSSL 2.6.5root@OPNsense:~ # pkg update -f
Updating OPNsense repository catalogue...
Fetching meta.txz: 100% 1 KiB 1.5kB/s 00:01
Fetching packagesite.txz: 100% 135 KiB 138.1kB/s 00:01
Processing entries: 100%
OPNsense repository update completed. 506 packages processed.
All repositories are up to date.
root@OPNsense:~ # pkg upgrade -n
Updating OPNsense repository catalogue...
OPNsense repository is up to date.
All repositories are up to date.
Checking for upgrades (16 candidates): 100%
Processing candidates (16 candidates): 100%
Checking integrity... done (0 conflicting)
Your packages are up to date.