Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - feedt

#1
Resolved, the problem was the MTU of 1400 for the vSwitch that's need to be set at VM level, leaving the default (1500) on the virtual nic at hypervisor level
#2
Good morning forum, i'm trying to integrate OPN (latest stable) as a firewall on my XCPNG (xen) cluster on Hetzner but cannot get VM behind it browsing web.

Some tech stuff: on Hetzner, each physycal host is connected in a vswitch (vlan) with a public subnet binded to it ( https://docs.hetzner.com/robot/dedicated-server/network/vswitch/ ). So, in a guest vm, if we attach his interface to the vswitch/vlan (MTU 1400) and give an ip from the public subnet, the VM can browse with this new public ip (tested, working).

The problem: i made the same exact configuration for the WAN side of OPNsense istance with some VM connected to the LAN (behind NAT) and those VM can only ping/resolve external addresses but got timeout when browsing internet. Tried reset, pfctl -d, review ruleset but nothing seems help

Any hint? Thank you
#4
Hi there, i was able to put OPNSense (latest sable) in front some VM on Hetzner Cloud (tip https://community.hetzner.com/tutorials/how-to-route-cloudserver-over-private-network-using-pfsense-and-hcnetworks).

VM are connected through a private network, hetzner use 10.0.0.1 to route traffic to all VMs
Everything seems working except for IDS/IPS (no block/alert, tried different settings). Any hint?

Thank you for your effort
#5
18.1 Legacy Series / Re: HAproxy with GeoIP
June 11, 2018, 09:38:21 AM
No one?  :'(
Maybe some firewall rule can help to redirect traffic based on ip source?
#6
18.1 Legacy Series / HAproxy with GeoIP
June 08, 2018, 11:25:28 PM
Hi, i'm trying to understand if it's possible get HAproxy working with GeoIP statement's (es. if US then IP1, if DE then IP2).

I'd like to dismantle some IT stuff using OPNsense as a firewall and loadbalancer

Thanks for any hint or reply
#7
Same problem but fixed as now. Just troubleshoot with vultr's team and they applied a fix