Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - tong2x

#211
General Discussion / Re: NAT - Port Forwarding
August 29, 2019, 12:14:09 PM
in my setting
"destination" is "This firewall"

to my understanding it mean

interface "WAN" is wait connection in this interface
destination is the "firewall" or self, or machine with the WAN interface

redirect target, because the target is an internal PC/machine
so IP of your target machine or CA machine
redirect port, if not the same port as external...

in my case I access, my CCTV server, with external port 888 redirected to the proper http port internally
#212
19.7 Legacy Series / Re: Firewall Rules not working?
August 29, 2019, 11:57:03 AM
you may want to
check if the rules have been applied (no "apply" button in upper right)
check the "automatically generated rules, you have 9, maybe 1 is in conflict
is it safe to assume you have set IP as source 172.16.16.23/32 and destination 172.16.16.122/32

screen shot of the actual rule setting would be nice.
#213
19.7 Legacy Series / Re: Multi-wan FailOver (FO) issue
August 29, 2019, 05:49:52 AM
@proxykid
are you using 19.7.3?
#214
mine is alittle different but having issue also with 19.7.3
my setup
2 wan (W1 and W2)
2 lan (LAN1 and Lan2/vlan15)

both can access the internet if using gateway
"default" , multiwan, or wan1
forcing wan2 as gateway will result to no Internet.

using tracroute diagnostic in "interfaces", opnsense, basically routes all trafic to wan1
even if I use wan2 as port to test the trace.
(I can see because all connect in traceroute uses the router ip of my wan1)

A little different but something is wrong with how it is routing and "choosing" the gateway.
(wan2 is functional if I directly access the modem)

FIXED:
I fixed my issue with WAN2 by removing wan2 interface (gateway groups and the WAN2 interfece itself etc..), then setting it up again...
now in tracerout the correct router(modem2) is being used. maybe a bad setting somewhere on upgrade that cause it to incorrect route wan2 to wan1
#215
19.7 Legacy Series / Re: ntopng
August 19, 2019, 05:43:25 AM
typical issue is that the DB is corrupt

in that case, you need to press the [Reset] button
#216
just saw your diagram and you have dmz already..
#217
Quote from: AdSchellevis on August 15, 2019, 09:07:48 AM
The rules where there before, but not visible for the end-user.
You can also use the inspect button (top right corner) now to see which rules actually are triggered.

Is this a multiwan setup by the way? and when did the issue start (which version)?

mine is dev build 75, was ok on build 44
mine is on a multiwan, but forcing the default or specific wan does not help either
almost same, outgoing seems ok but internal transfer/access seems to be blocked
#218
19.7 Legacy Series / Re: Force gateway broken?
August 17, 2019, 03:00:32 AM
it didnt help, confirmed issue is replicable.
from production (working) to delopment (no internet).

opnsense, has internet access, I can use diagnostic to ping and trace route outside/public IPs.
and I can easily switch from development to production.
but the internal LAN has no internet, from the looks of it is as if the gateway is not returnning data to LAN (not sure). I can see in the live view that the machine im using is making dns request (and it is green).
it is as if the gateway is not responding the the reuest or ignoring...

the captive portal shows up, but does not connect to the internet..

if you need me to do something, just instruct me and let me know
#219
General Discussion / Re: Problem with Captive Portal
August 17, 2019, 01:55:40 AM
it may be a DNS issue or a firewall rule issue
it would be clear if more info such as settings and screen shoots of rules

just post here when available, have a nice vacation
#220
General Discussion / Re: Redis/Notpng reset
August 17, 2019, 01:52:49 AM
oh right... now I remember...

maybe the button should be rename Reset DB, Reset config so it will be much more clear
#221
General Discussion / Re: Problem with Captive Portal
August 16, 2019, 06:39:39 PM
setup detailes and config?
one lan? ips etc.

without captive evrything is ok?
#222
General Discussion / Re: Redis/Notpng reset
August 16, 2019, 06:36:17 PM
i think i found it before but cant seem to remember were?

where is it located?
#223
19.7 Legacy Series / Re: Force gateway broken?
August 16, 2019, 02:36:12 AM
agree, help said by checking the box opnsense will use the routing table not the asisgned gateway.

would that mean any rule assigned to wan2 will be diverted to system "default"
and
would multiwan(load ballance) used system default?

or is this just a temporary solution for the issue?
#224
19.7 Legacy Series / Re: Multi-WAN problem
August 15, 2019, 07:33:08 AM

had issues also but not same setup...
mine is load balance mode. cant figured out to reroute so I just went back to "production"

everything was working on .44 dev version but after upgrading to .72... routing got messed up for some reason...

going to production without any changes or re config fixed the routing issue.
#225

direct domain to a specific WAN interface
is it possible, without using an IP as basis?
since most servers nowadays uses either load balancers or cloud.

ex.
www.domain1.com
will only go out of wan2

www.domain2.com
will only go out of wan1