Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - Julien

#1
This is a community-driven support forum, and no one gets paid for the help provided here.

If you need immediate assistance, consider contacting the Deciso team and purchasing their support services—they'll be able to help you promptly.

Also, remember that politeness goes a long way in getting the help you need. After all, you catch more bees with honey than with vinegar!
#2
23.7 Legacy Series / Firewall Rule Question ( Resolved )
September 25, 2023, 12:46:49 PM
Hi there,

I'm in the process of uploading an ISO to a VMware server from the LAN to VLAN20. There are existing firewall rules allowing any-to-any traffic on both sides. However, I'm currently facing a firewall-related error on the screen. Your assistance in resolving this issue would be greatly appreciated.

Edite: issue is resolved and can be closed
#3
i had this issue last year, i've been working with the support team and they couldnt fix it.
i give up using it.
now i am using Firewall Alias.
#4
23.1 Legacy Series / Re: Print over the vpn
August 20, 2023, 01:55:45 PM
We managed to find the blocked port on the firewall live vieuw
Thank you everyone
#5
23.1 Legacy Series / Re: Print over the vpn
July 31, 2023, 09:21:01 PM
Thank you for your answer
I see we have on the printer Alias the next ports 137/138/139/161/162/427/9100/9220/9500
Still killing the printer during the print
When the users print I don't see anything on the LAN interface being blocked.
#6
23.1 Legacy Series / Re: Print over the vpn
July 29, 2023, 11:28:14 AM
Quote from: slackadelic on July 29, 2023, 04:35:33 AM
Is the tunnel NATing traffic?
The tunnel interface firewall rules is allowing any to any of this what you mean.
#7
23.1 Legacy Series / Print over the vpn
July 29, 2023, 12:41:49 AM
Hello everyone,

We have set up a site-to-site Wireguard VPN to our datacenter. The LAN interface is configured to allow ports 443, 80, 53, and 9100 for printing Konica devices.

However, when the users attempt to print from the remote location to the office, it doesn't work. Printing only functions when we add the rule "any to any."

Could someone advise why this is happening and what I might be missing here? Thank you!
#8
23.1 Legacy Series / Re: Disk is 109% full
July 10, 2023, 05:01:00 PM
Thank you so much found the cause a lot of logs were hanging in /var/log/filter

i've cleaned them and now i got my storage back
#9
23.1 Legacy Series / Disk is 109% full
July 10, 2023, 04:27:54 PM
Hi guys,
today we noticed the box is full %109.


/dev/gpt/rootfs 49G 49G -3.9G 109% /

devfs 1.0K 1.0K 0B 100% /dev

devfs 1.0K 1.0K 0B 100% /var/dhcpd/dev

devfs 1.0K 1.0K 0B 100% /var/unbound/dev

/usr/local/lib/python3.9 49G 49G -3.9G 109% /var/unbound/usr/local/lib/python3


i cannot seem to find the log that full up my disk.

can you please advise how to clean this up ?
#10
Quote from: squarky on May 30, 2023, 11:58:05 AM
Quote from: Julien on May 30, 2023, 11:15:59 AM
i have the same problem with 23.1.7_3.
i advice to go back to 23.1.6 most of people has tested this

Thanks for the tip. I actually just disabled IPv6 (as it's not critical for me for the moment - and have to get some work done) and everything is now working as a charm. DNS resolution back down to ~1ms for locally cached results (and 4ms for results fetched from Cloudflares cache).

I applied the patch mentioned in https://forum.opnsense.org/index.php?topic=34241.msg165713#msg165713 and it fixed some issues, but no the DNS lookup issue.

when you say disabled IPV6 do you mean on Firewall: Settings: Advanced and uncheck the IPV6 ?
on the page you provided i don't see a patch, which one do you mean?
#11
Quote from: franco on May 30, 2023, 08:53:56 AM
@My_Network

https://github.com/opnsense/core/commit/25e2c0a30

# opnsense-patch 25e2c0a30


Cheers,
Franco

Hi Franco,

thank you so much for your answer.
when i enter the command line nothing happens with this machine.
i have the feeling this one is broke.
i tried it on a different one 23.1.8 and it seems to be applied succecefully.

Patching file etc/inc/system.inc using Plan A...
Hunk #1 succeeded at 677 (offset -10 lines).
done
All patches have been applied successfully.  Have a nice day.


#12
Quote from: squarky on May 30, 2023, 10:50:25 AM
DNS resolution has also become very unstable for me after upgrading to 23.1.8. Using Unbound and Cloudflare as upstream DNS.

I've been running dual stack IPv4/IPv6 on my current ISP with no issues for more than half a year, and nothing seams to have changed on their side.

Looking at Smokeping, resolving test.test on unbound from my local network, I see a huge difference after upgrading to 23.1.8. Spikes going over 800ms and even some timeouts. Internal latency is <0.7 ms.

DNS resolution from my wired laptop are now fairly consistent > 40ms (even for cached results) and before the upgrade they were < 1ms for cached results.

I used to have 20/20 on ipv6-test.com, but now various tests time-out (inconsistent between refreshes) so I end up somewhere between 10/20 and 18/20.

I'll try to downgrade to 23.1.7_3 to see if it helps.
i have the same problem with 23.1.7_3.
i advice to go back to 23.1.6 most of people has tested this
#13
thank you for your answer.
i just been doing some reading and i think the issue is related to the 23.17_1 with the gateway switching ect..
i'll have to revers back to 23.1.6 but the box is not reversing.
i'll have to reinstall it
#14
i am facing the same issue with one box 23.1.7_3.
the gateway keeps showing offline but everything is working. only sometimes it has to think about reloading websites.
when i tried the revert back to opnsense-revert -r 23.1.6 on the shell nothing happens on the shell.
supposed to reboot after the command line opnsense-revert -r 23.1.6 ?

#15
23.1 Legacy Series / Questions Regadring Subnets
May 29, 2023, 05:56:13 PM
Hi Guys,

i hope someone can point me to the right direction here.
we have from ISP and /29 Subnet which we have configured our WAN on
XX.XX.XX.XX/29 WAN1
we have added the other 8 IP to virtual IPS and it works fine.
with the second  subnet /29 we did the same add it to the Virtual IPS.
and add both gateways to the System: Gateways: Single

this week we got the 3th subnet to test for our 10GB up links with the same subnet.
when i tried to add the 3rd gateway its error out

The following input errors were detected:

The gateway address "X.XXX.X.X does not lie within one of the chosen interface's IPv4 subnets.


is this because the WAN is /29 and not /32 ?

your help is appreciate it.

thank you