Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - Antaris

#1
Zenarmor (Sensei) / Re: Sites Blocked but don't log
June 01, 2023, 06:17:25 PM
Sometimes same happened to me, but solved by entering the corresponding domain in the exclusions.
If there is a proper resolution will be glad to try it.
#2
Just take a good SFF workstation (HP Z, Lenovo P, etc..), Intel i340/i350-T4, Intel X520-DA2 second hand and new SSD.
Way more reliable, performant and cheaper than chinese misunderstandings with N5095/5105/6005... They will struggle with Suricata/Zenarmor/VPN to push some serious traffic...
#3
Quote from: SuperMiguel on September 10, 2022, 03:01:22 AM
whats the recommended DB type? mongodb? ES? remote ES? i have a home lic with around ~100 users (mostly IoT)

Depends on the hardware used for OPNsense.
#4
Tutorials and FAQs / Re: How to configure VLANS.
November 16, 2021, 09:44:03 PM
It's better if you have a separate port in the OPNsense. Assign it, enable it, name it TRUNK and DO NOT assign an IP address to it. After this assign your VLANs to the TRUNK port as parent and connect it to the switch. The try to untag your VLANs to specific ports. Avoid to mix tagged and untagged traffic on the same port in BSD, especially if you use netmap(Sensei/Zenarmor)...
#5
Second hand DL360p G8 or PowerEdge R620 are obvious choice here if the noise is not a big concern. DL360p often comes with 2x10G SFP+, R620 usually have only 4x1G...
#6
German - Deutsch / Re: Qemu Guest Agent
August 08, 2021, 08:32:18 AM
Thanks for the great work Frank! Now I can use OPNsense in Proxmox with proper memory management. (ballooning)
#7
Quote from: franco on August 05, 2021, 05:18:09 PM
This doesn't have to be boring :D


Cheers,
Franco

May be it's best time for optimization. Aliases will help a lot. You can also consider migrate some services from be accessible via port forwarding to VPN only these days. Also check the Sensei addon. It turns OPNsense to the best NGFW for the money, that Internet knows IMHO.
#8
General Discussion / LAN with client isolation
June 15, 2021, 01:50:26 PM
I need to set a VLAN on that clients can't see each other. Something like with 255.255.255.255 subnet mask from PPPoE ISP. Is there a way to manage it via DHCP server?
#9
Zenarmor (Sensei) / Re: Trusting Sensei
June 02, 2021, 09:11:09 PM
I use Sensei from the beginning (September 2018) and can't say a single bad word for anyone from the Sunnyvalley team. Worked mostly with Murat and Matt. If I don't trust them, who to trust then? Cisco? Fortinet? Sophos? Zyxel?
This is the best NGFW solution for me. Worldwide. Period.
#10
Zenarmor (Sensei) / Re: Whitelist problem
June 02, 2021, 08:48:19 PM
Solved by Matt via mail.
Last command was:
echo -n "alter table custom_web_category_sites add is_global INTEGER default 0"| /usr/local/bin/sqlite3 /usr/local/sensei/userdefined/config/settings.db
If anyone is in the same situation.
#11
You need at least 3GHz Haswell or newer Intel Core i CPU. At least 8GB RAM depending on simultaneous device count. SSD or 10-15K rpm HDD is a must. The best bang for the buck is a brand SFF PC with 4 port pcie Intel NIC. But it's 2U high...
#12
Zenarmor (Sensei) / Re: Whitelist problem
June 02, 2021, 06:08:39 PM
Full report sent.
#13
Zenarmor (Sensei) / Re: Whitelist problem
June 02, 2021, 06:49:06 AM
Hi sy,

There is a improvement: it not returns error, but domains are still not shown in the list:
#14
I resolve it immediately when happen. Always checking after update. Otherwise the kids go porn and TikTok :(
#15
Zenarmor (Sensei) / Whitelist problem
May 30, 2021, 04:39:22 PM
With this version comes tabbed White/Black lists.
When I'm trying to add domain it returns:

"1220 - SQLite3..prepare(). Unable to prepare statement. 1, table custom_web_category_sites has no column named category_type (errno=2)"

with no success to add the domain.