Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - tdalej

#1
Got the mount solved. 

I have never used the importer script before, always just bulled through manually transferring configurations when needed.
In this case I have two identical Supermicro X10SLH-N6-ST031F (that used to be used for separate locations) that I am going to use one as primary and one as backup.

#2
Sort of. 

I'm trying to the recovery with the importer script to see how it gets handled there compared to manual restore.

I can't get the importer to mount the second USB device -- both the boot USB device and the second fat formatted USB device show up as da0 and da1, an it fails to mount with an "invalid device" message. 



#3
General Discussion / Recovery with a backup file
July 18, 2026, 05:51:14 PM
I'm doing some poking, and I have to identical servers for firewalls -- MAC addresses are different of course.
Last time I did a recovery from one to the other, restoring the backup caused all sort of fun because the MAC addresses don't align.

Is it an accepted practice to edit the backup to alter the MAC addresses first?
Is there a more elegant way to handle the MAC address changes that I'm just missing?

#4
I'd really rather not have to manage the email server.
Not impossible but I'd rather let someone else deal with that bit of it.
And I have been using Yahoo for a long time -- Since they first started offering email addresses -- it had almost all of that when I first set up, but as generally happens, enshitification has taken over.
Time to move.

I don't mind paying for the service, just not exorbitant amounts.

I'm starting to look atservices (like fastmail) that allow a free period to see the feature and support response.
I just went through fastmail and for some reason even though dnschecker.org shows the proper DNS record propagation, fastmail still shows them in an error state.  :/


 

#5
Admins -- If this is off topic for this forum, please remove/delete this.

I have been coasting a long with email services from yahoo for a long time, but enshitification hs taken it's toll.
I have over the years set up my own mail servers in my domains - but I know I don't have the bandwidth to do the administratoin needed to keep the service healthy and clean. 
So, I'm looking for a reliable hosting provider that I can use for IMAP/SMTP services - One that doens't use Google, Amazon, etc. - and I'd like to gp with a company that as ethical as coproprations can be.
I have spent thta last week or so going through reviews and web sites from countless providers -- in most cases, email seems to primarily be a web site hosting add on. 
I have my own domain(s) and already host web sites for each locally.

I have a list of criteria that are required:
IMAP + IMAP Storage - prefer 20GB per mail box or more
SMTP
5 mailboxes at a minimum, but would much prefer accounts managed at domain(s) level so that I can create/remove mailboxes as needed.
Unlimited Aliasing

A Nice to have but not currently in use is Shared Calendars.



The marketing fluff around this is ... very strong.
And there are a lot of them out there.

I'm tossing rocks in the pool at this point in the hope that someone out there has a provider they are happy enough with that they will reccomend them, so I can narrow the field a bit.




#6
I have read the opnsense docs on firewall rules.
It says that "When changing rules, sometimes its necessary to reset states to assure the new policies are used for existing traffic. You can do this in Firewall ‣ Diagnostics ‣ States."
I have done that with no change.

This is the current set of rules enabled on the LAN40 interface.
                automatically generated rules:
       IPv6 *    *    *    *    *    *    *    *    Block all IPv6    
      IPv4+6 *    *    *    *    *    *    *    *    Default deny / state violation rule    
      IPv4+6 TCP/UDP    *    0    *    *    *    *    *    block all targeting port 0    
      IPv4+6 TCP/UDP    *    *    *    0    *    *    *    block all targeting port 0    
      IPv4+6 TCP    <sshlockout>    *    (self)    22 (SSH)    *    *    *    sshlockout    
      IPv4+6 TCP    <sshlockout>    *    (self)    443 (HTTPS)    *    *    *    sshlockout    
      IPv4+6 *    <virusprot>    *    *    *    *    *    *    virusprot overload table    
      IPv4 UDP    *    68    255.255.255.255    67    *    *       allow access to DHCP server    
      IPv4+6 UDP    *    68    (self)    67    *    *       allow access to DHCP server    
      IPv4+6 UDP    (self)    67    *    68    *    *       allow access to DHCP server    
      IPv4+6 *    *    *    *    *    *    *    *    let out anything from firewall host itself    
      IPv4+6 *    (ix0)    *    ! WAN net    *    WAN_GW    *    *    let out anything from firewall host itself (force gw)    

               Rules I have added

      IPv4 *    192.168.40.11/32    *    LAN20 net    *    *    *       Out rule for a single host to any internal network   
      IPv4 *    192.168.20.70/32    *    192.168.40.5/32    *    *    *       In rule for Security Camera    
      IPv4 *    192.168.40.5/32    *    192.168.20.70/32    *    *    *       Out Rule for Security Camera    
      IPv4 *    LAN40 net    *    LAN20 net,  LAN30 net, LAN50 net    *    *    *       Default block out to private subnets rule    
      IPv4 *    LAN40 net    *    LAN20 net, LAN30 net, LAN50 net    *    *    *       Default block in to private subnets rule    

                 Default created at installation
      IPv4 *    LAN40 net    *    *    *    *    *       Default allow WiFi to any rule


Can anyone clue me in?
What am I missing here?
I have tried only In rules and only Out rules and both.   
Nothing seems to work.


#7
NVR is on LAN40 and the camera in question is on LAN20.
LAN40 is used for things that I don't want to have access to the other networks.
Putting that one camera on LAN40 would cost another POE injector, and I already have a POE switch in that location on LAN20 ...

I added out and in rule because I need to be able to register the camera to the NVR and it needs bi directional traffic?
The rules right below block all traffic between those networks if I understand them correctly.

changing to /32 from /24 made no difference. 
Do I need to disable and reenable, or reboot?
#8
General Discussion / Firewall rules/orders for dummies
December 17, 2025, 08:23:07 PM
I just upgraded to 25.7.9_7 and adjusting networks afterwards. 

I have separate physical subnets for various purposes.
One I use for all WIFI and a security camera NVR.
I need _one_ camera on  LAN40 to talk to the NVR on LAN40.
I had the Wifi subnet isolated from the other subnets by the 3rd and 4th rule (successfully I thought).
I tried adding the top two rules for any protocol/any port between 192.168.20.70 and 192.168.40.5
I'm missing something because the block tot eh subnet appears to be working, but the rules prior to that do not.
I'm not sure what I'm missing here, but if anyone can explain it to me like I'm a dummy, I'd appreciate it.


                Automatically generated rules    
      IPv4 *    192.168.20.70/24    *    192.168.40.5/24    *    *    *       In rule for Security Camera    
      IPv4 *    192.168.40.5/24    *    192.168.20.70/24    *    *    *       Out Rule for Security Camera    
      IPv4 *    WIFI net    *    LAN20, LAN30, LAN40, LAN50    *    *    *       Default block out to private subnets rule    
      IPv4 *    WIFI net    *    LAN20, LAN30, LAN40, LAN50    *    *    *       Default block in to private subnets rule    
      IPv4 *    WIFI net    *    *    *    *    *       Default allow WiFi to any rule    
#9
Quote from: franco on November 05, 2025, 08:22:13 AM> Unless .. the keyboard mapping done at installation has changed?

Yes, it's a per install setting not found in the config.xml export. We debated the good and bad about making it more persistent, but it did not seem very important unless you have a special keyboard (diverging from a basic US layout) AND use special characters from the special keyboard.

This doesn't happen for SSH or the web GUI, but it's a possibility for the console.

I mention 1. and 2. because:

With 1. you have to check the authentication settings (an OTP will not allow your plain password to be used, NTP needs to work in order for OTP to work too) and there is a GUI tester for that as well.

For 2. if you have a special keyboard layout and know your password it's easy to infer that it could be susceptible to this problem, but nobody else can tell and certainly not from a password hash. It's also why the default password is rather plain which makes keyboard mapping issues like that very unlikely.

In either case you have all the data to identify the problem and we can help assist with this after diagnosing which one it is.


Cheers,
Franco


At the end of the day I just need to figure out the proper procedure to recover a backup to an identically configured computer (but with obviously different MAC addresses for each interface).

So long as the NIC assignments are done based on interface order Ix0, Ix1 and so on, I should be good -- I know which interface will be the LAN interface and I assume that attaching a laptop directly to that port will allow me to login to the UI (using the known GUI password) and address the console password issue?

I use a standard US keyboard and keyboard layout -- selecting the default in the installer on the recovery installation and _pretty sure_ but not 100% positive I did the same on the original install. 

Sounds like my best approach is to start over and document every step of the recovery.




#10
Quote from: franco on November 04, 2025, 10:21:24 AMWhat's your goal? Breaking access?

The <password/> entry has been compatible across versions forever.

The only thing that could change are:

1. authentication settings
2. console keyboard mapping


Cheers,
Franco

Well, unless a restore does one or both of those things, that's not what this is. <shrug>


Unless .. the keyboard mapping done at installation has changed?
Could that do it?
It's been a while since I did the install of the one I'm restoring, and it's gone through a few upgrades...
I selected the one I always use on the fresh install -- it's common enough I didn't even think about it.

What setting would that be in the backup file?
#11
The config I restored didn't require a login on the local console.
Can't put it on the network to even try the GUI until I am sure the interfaces are properly assigned.

Can I just edit the config file to remove the root/admin userid?
The whole <user> or just blank  <password> like this:  <password></password>
 
#12
I spun up a new install of 25.7.
After getting to the login and doing the basic wizard setup bit, I restored a backup of my running OPNSense running 25.1

None of the passwords from either setup work on the console after reboot.

Is this expected?
Should I have modified the backup file and blanked password fields?
I don't recall seeing anything particular in the docs other than restore steps.

Or is this just some incompatibility between versions?
 
#13
How long does it take to sync up?  Still almost 10 minutes out from local cell tower service time and internal time service from where I work.


Network Time Protocol Status
Status Server Ref ID Stratum Type When Poll Reach Delay Offset Jitter
Unreach/Pending us.pool.ntp.org .POOL. 16 p - 64 0 0.000 +0.000 0.000
Unreach/Pending opnsense.pool.ntp.org .POOL. 16 p - 64 0 0.000 +0.000 0.000
Outlier 134.215.155.177 216.239.35.0 2 u 410 512 377 47.497 +3.974 1.502
Outlier 158.51.99.19 17.253.26.125 3 u 302 512 377 41.426 +1.647 1.390
Outlier 72.14.183.239 127.67.113.92 2 u 42 512 377 16.133 +2.344 2.951
Candidate 108.61.215.221 162.159.200.1 4 u 511 512 377 22.939 +3.755 0.809
Candidate 192.155.94.72 132.163.96.2 2 u 33 512 377 24.175 +4.978 1.317
Outlier 62.72.0.70 209.151.225.100 3 u 163 512 377 50.970 -0.212 4.214
Active Peer 45.79.111.114 127.67.113.92 2 u 258 512 377 56.906 +2.950 1.572
Candidate 72.14.183.39 80.72.67.48 3 u 413 512 377 16.710 +3.197 2.877
Candidate 162.159.200.1 10.162.8.47 3 u 168 512 377 10.624 +2.746 5.546
#14
My time is about 9 minutes off -- compared to two other professionally (more than me at least) managed networks.
The default opnsense pool reported in the logs DNS resolution failure

Error    ntpd    error resolving pool 1.opnsense.pool.ntp.org: Name does not resolve (8)

so I added pool.ntp.org ans us.pool.ntp.org and I'm still seeing status like below.
I do see this and many more servers in the list -- is the "Unreach/Pending" just a side effect of not being in sync?
Although the offset column shows I'm not as far off as it really is ...

I'd really like my gateway to sync up and provide NTP for  the local networks ...






Status     Server     Ref ID     Stratum     Type     When     Poll     Reach     Delay     Offset     Jitter
Unreach/Pending     us.pool.ntp.org     .POOL.     16     p     -     64     0     0.000     +0.000     0.000
Unreach/Pending     opnsense.pool.ntp.org     .POOL.     16     p     -     64     0     0.000     +0.000     0.000
Unreach/Pending     134.215.155.177     216.239.35.0     2     u     14     64     7     48.304     +1.936     0.174
Unreach/Pending     158.51.99.19     17.253.26.125     3     u     16     64     7     42.716     +0.857     0.319
Unreach/Pending     72.14.183.239     45.79.1.70     3     u     13     64     7     16.266     +0.373     0.067
Unreach/Pending     74.208.25.46     198.46.254.130     3     u     13     64     7     36.483     +5.648     2.497
#15
24.7, 24.10 Legacy Series / Re: ssh access
April 04, 2025, 01:34:46 PM
Quote from: dseven on January 07, 2025, 11:34:17 AMI don't disagree with Patrick, but [System -> Settings -> Administration -> Secure Shell -> Listen Interfaces] is a thing....

That only appears to allow a single interface or all.  All is the default.