Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - miruoy

#16
Same/comparable issue on my end. Although my configuration is using DNSBL.

2020-12-18T09:20:51 kernel -> pid: 63934 ppid: 1 p_pax: 0xa50<SEGVGUARD,ASLR,NOSHLIBRANDOM,NODISALLOWMAP32BIT>
2020-12-18T09:20:51 kernel [HBSD SEGVGUARD] [unbound (63934)] Suspension expired.
2020-12-18T09:20:51 kernel pid 63934 (unbound), jid 0, uid 59: exited on signal 11


What additional info can I/we append to investigate this issue further? Should we revert to the previous version?
#17
General Discussion / Re: 2 lan to 1 wan
July 23, 2020, 01:51:40 PM
Quote from: janne on July 22, 2020, 01:20:47 PM
Hi.
No I mean two LANs (em0 and em3) to one WAN (em1)

Hi @Janne

Welcome to the forum!

Judging from the way you asked your question I would presume you are very new to networking. You should probably read up on some routing and switching principles since you seem to be very interested in that.

Now the functionality that you are looking for is explained here >> https://docs.opnsense.org/manual/nat.html#outbound
opnSense does howeve manage this by default so as long as your lan segments (subnets) are properly configured you're g2g.

Basically you can have multiple lan segments share the same outbound gateway or even multiple gateways (gw groups). You will also be able to Layer3 route packets from lan segment a to lan segment b.

Hope this helps to steer you in the right direction. Good luck and reach out when you need a hand!
#18
20.1 Legacy Series / Re: 20.1.4 - ntopng
July 21, 2020, 01:22:15 PM
Confirmed that the issue is fixed after upgrade to version OPNsense 20.1.8_1
#19
20.1 Legacy Series / Re: 20.1.4 - ntopng
June 17, 2020, 02:12:48 PM
Quote from: mimugmail on June 15, 2020, 06:13:16 PM
Upstream patch is available, couple of weeks to go

Great news && thanks for the update! Let us know if you need testers.
#20
Hey welkom op het forum!  8)

Ziet er een leerrijke opstelling uit voor je.

Wat bedoel je juist met een "WLAN-Ethernet Bridge" ?? Er bestaan "devolo" kits waarmee je een ethernet signaal over je powerline kan sturen. Indien nodig hebben deze vaak ook nog een WiFi AP ingebouwd.

Is dat iets waar je naar op zoek bent om uw madam content te stellen?
#21
Quote from: 405Computer on June 09, 2020, 12:06:44 AM
Thanks, but that wasn't the key to it. I had heard that 5060 wasn't always UDP. When I look at the live logs and then make a phone call, there is a "default" rule somewhere blocking this port 5060



These logs show you that the destination port is NOT 5060 but some other (prolly) random port. The source port is 5060 though so you should prolly add an extra FW rule to PASS SRC.PORT == 5060.
#22
20.1 Legacy Series / Re: 20.1.4 - ntopng
June 02, 2020, 04:50:02 PM
Quote from: andrema2 on June 02, 2020, 04:39:44 PM
Is there a way to install ntopng 3.8 ? I believe this version was ok with freebsd

Mimugmail has posted a temporary workaround in this thread to revert to the old version:
If your system is unusable you can always revert to old version via CLI:

opnsense-revert -r 20.1.3 ntopng

Your mileage may vary though. On my end the old version on fails after about 5 minutes of runtime.
#23
You should also look into the --ping combined with --ping-restart options. I usually set these to 10 and 60 respectively for S2S ovpn connections.
#24
Quote from: zesu on May 29, 2020, 09:57:40 AM
Feature request added. Thanks.

Please post the link to the request in this thread. I'm also very interested in this feature :)
#25
20.1 Legacy Series / Re: 20.1.4 - ntopng
May 15, 2020, 03:39:11 PM
Quote from: mimugmail on May 15, 2020, 03:02:39 PM
I'm here :)

Ah good to know you're in the loop and already investigating :D

We will be patient until you provide more feedback. Let us know if we can do some additional tests to assist in solving this.
#26
20.1 Legacy Series / Re: 20.1.4 - ntopng
May 15, 2020, 11:49:27 AM
Hi @all

Issue still present on 20.1.6 with ntop-ng 1.2 and redis 1.1

Not sure if this is related but syslog indicates
ntopng: [Utils.cpp:3351] WARNING: ntopng has not been compiled with libcap-dev

ntopng logs does not show any errors.

Is there already a ticket logged for this to the maintainer m.muenz or can we add him to the conversation?

[edit] Removed dev email
#27
Good to hear this solved your issue. At least for now.

Afaick there are 3 ways you can form the logic on FW rules in opnSense.

  • Define rule on the interface the traffic is coming into
  • Create a floating rule that can be applied before or after all other rules. Depending if the quick flag is activated for the rule
  • Create rules on groups of interfaces so that you are not forced to duplicating the rules on every single interface

After that you also need to take into account all the Automatically created rules.

Imho the rule that you are describing should NOT let out any traffic other than traffic generated by the UTM itself. If you have solid prove that this is happening, can deliver traces, and have some time to spare for follow up traces and testing I would suggest creating a bug report so the devs can have a look at it.

I would also be wise to run this issue through the IRC users.
#28
General Discussion / Re: Rules for use Torrent service
December 11, 2018, 09:40:50 AM
There is only 1 field named "Destination" in the port forwarding config. Study the screenshot below to be spoon fed.



Do note though that this should really be obvious if you have any experience with networking. Study this small diagram and It should become clear on why we are using the WAN as the "Destination" in the PAT rules.

External User/App ==> WAN ==> Your opnSense ==> Your Torrent Box

Also read up on this article to clarify what you are configuring.

I hope this helps you in better understanding your configuration.
#29
As a temporary quick workaround you can define a group containing all your VLANS and define an explicit block for inter vlan traffic.
#30
General Discussion / Re: Rules for use Torrent service
December 10, 2018, 06:59:44 PM
Looking at your NAT rule it looks like you are not forwarding correctly. Destination should be the WAN if address, not the server you are redirecting to. Your live FW log should show you that is the if where the packets are being dropped.

If this does not resolve the issue you should verify the live FW logs and/or run a packet capture on your WAN if to verify the packets are coming through to your end and are not being intercepted/blocked by the ISP.

Keep seeding!