Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - zaggynl

#1
German - Deutsch / Re: Upgrade auf Version 22.7
July 30, 2022, 05:42:27 PM
Had the same, think it was a remainder of the sensei package/repo?

Appears ok after a: 'pkg remove php74-pecl-mongodb'
#2
21.7 Legacy Series / Re: Everything Seen to Work
July 29, 2021, 09:14:18 PM
Upgraded from 21.1.8, 21.1.9  to 21.7 on a DEC630, went quick, no issues spotted!
#3
20.7 Legacy Series / 20.7 update experience
July 31, 2020, 06:26:06 PM
hardware: OPNsense A10 Quad Core SSD Desktop Gen2 SKU: DEC630

-update from 20.1.9 to 20.1.9-1: OK
-update to 20.7: stuck after reboot, USB console showed no output
removed power, put back after 10s, resumed and finished update without issue, router came back after a couple minutes.


#4
Same for me, did a health check as my opnsense box didn't come up after upgrade.
On console it was showing tar errors, I might have forced a reboot to soon?
After a ctrl+c it continued with boot and functioned normally.
#5
 19.1.6 to 19.1.7 Update went OK for me, reboot was quick.

Edit: it rebooted twice? showed rebooting in UI, then dashboard 19.1.7, then rebooted again, second time took longer.
#6
Quote from: mimugmail on March 21, 2019, 02:34:44 PM
Overrides can also be done via dnscrypt-proxy if you need them. Also Adblocking is now available vial the plugin itself.

Thanks.
Had a look at using dnscrypt-proxy alone but the webui of pihole proved to be more featured.
#7
Quote from: franco on March 20, 2019, 09:23:16 PM
I'm guessing same Unbound problem as Bind has:

> When you are using Overrides in Unbound you can not use ``do-not-query-localhost``.


Cheers,
Franco

Thanks for the reply, I have a number of Overrides, after removing the do-not-query-localhost line Unbound starts!
#8
I'm running into the same issue.
I can enable and start Unbound but it will not start after adding Advanced Settings part per: https://wiki.opnsense.org/manual/how-tos/dnscrypt-proxy.html
do-not-query-localhost: no
forward-zone:
name: "."
forward-addr: 127.0.0.1@5353


No error messages appear in webui or log.
I can start unbound from shell with -d -v, it shows no errors at that time in shell or in ui log.

Goal is to forward incoming requests to my pihole VM, which should get its DNS replies from dnscrypt on opnsense.
#9
19.1 Legacy Series / Re: OPNsense 19.1 released update!
January 31, 2019, 08:50:04 PM
No issues after installing, only took a couple minutes longer than usual.
#10
I'm experiencing this in 18.7.8, had to change port alias to port number before Port Forward rule worked again.
#11
Thank you, good to hear.
#13
-Backed up config
-Reset to defaults
-Restored config
-no more duplicate pings but still no IDS warnings or blocking
#14
Changed IDS settings to below, enabled syslog alerts, changed interfaces to LAN only


Dashboard shows Suricata running:




Ping stats look weird:
Rutube.ru
64 bytes from 185.165.123.77 (185.165.123.77): icmp_seq=1 ttl=57 time=851 ms
64 bytes from 185.165.123.77 (185.165.123.77): icmp_seq=2 ttl=57 time=9.70 ms
64 bytes from 185.165.123.77 (185.165.123.77): icmp_seq=1 ttl=57 time=1853 ms (DUP!)
64 bytes from 185.165.123.77 (185.165.123.77): icmp_seq=3 ttl=57 time=9.53 ms
64 bytes from 185.165.123.77 (185.165.123.77): icmp_seq=3 ttl=57 time=70.9 ms (DUP!)
64 bytes from 185.165.123.77 (185.165.123.77): icmp_seq=3 ttl=57 time=941 ms (DUP!)
64 bytes from 185.165.123.77 (185.165.123.77): icmp_seq=4 ttl=57 time=9.74 ms
64 bytes from 185.165.123.77 (185.165.123.77): icmp_seq=3 ttl=57 time=1161 ms (DUP!)
64 bytes from 185.165.123.77 (185.165.123.77): icmp_seq=4 ttl=57 time=953 ms (DUP!)
64 bytes from 185.165.123.77 (185.165.123.77): icmp_seq=3 ttl=57 time=2319 ms (DUP!)


Google DNS:
64 bytes from 8.8.8.8: icmp_seq=13 ttl=122 time=2.76 ms
64 bytes from 8.8.8.8: icmp_seq=12 ttl=122 time=1344 ms (DUP!)
64 bytes from 8.8.8.8: icmp_seq=11 ttl=122 time=2679 ms (DUP!)
64 bytes from 8.8.8.8: icmp_seq=13 ttl=122 time=903 ms (DUP!)
64 bytes from 8.8.8.8: icmp_seq=14 ttl=122 time=2.76 ms
64 bytes from 8.8.8.8: icmp_seq=12 ttl=122 time=2156 ms (DUP!)
64 bytes from 8.8.8.8: icmp_seq=13 ttl=122 time=1160 ms (DUP!)
64 bytes from 8.8.8.8: icmp_seq=12 ttl=122 time=2394 ms (DUP!)
64 bytes from 8.8.8.8: icmp_seq=11 ttl=122 time=3779 ms (DUP!)
64 bytes from 8.8.8.8: icmp_seq=13 ttl=122 time=1802 ms (DUP!)


Edit: 
Ping results returned to normal after disabling IDS:
64 bytes from 185.165.123.77 (185.165.123.77): icmp_seq=38 ttl=57 time=10.1 ms
64 bytes from 185.165.123.77 (185.165.123.77): icmp_seq=39 ttl=57 time=9.57 ms
64 bytes from 185.165.123.77 (185.165.123.77): icmp_seq=40 ttl=57 time=9.62 ms
64 bytes from 185.165.123.77 (185.165.123.77): icmp_seq=41 ttl=57 time=9.66 ms
64 bytes from 185.165.123.77 (185.165.123.77): icmp_seq=42 ttl=57 time=9.74 ms