Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - wirehire

#1
you can block all, thats have input ips , and allow only what you want.
#2
you can out a us alias and and a allow rule only for this as source or destiny. or negatate the alias on all rules.
#3
for the handshake ,it needs only the wg ips/net

can you post the full config from the ios device , without priv keys?
#4
have you tried with another key pair?

the log in ios , say no handshake?

you can see udp pakets in the firewall log?

which ips are in the allowed config from your ios device?
#5
no right, the services dont start clearly.

But i try it next days again. I thought defguard are a good tool, rust code, mfa not only on the app side ,opnsense plugin.

But!

Documentation, really really bad. Bugs ( opnsense ) weeks open. Sound like with Version 1.0 they split the features to no enterprise / with enterprise license.

The developers must paid, thats are clear, but in the last time you see often, that opensource code goes the paid way and finally closed.

And when you go in to support opnsense , why no good documentation?

defguard with opensense = can really go enterprise wireguard vpn, but now it does not good work.

But try!! When more people from the opnsense community will try defguard, they will eventually kick in and the support level goes up!

I hear from many people / buisness peoples, the want wireguard , the like wiregurad , but the want a mfa layer. Only asymetrics keys, yes security are good, but too loose the config ( windows , not fully encrypted , malware) and you have they keys . With mfa you have a extra security layer.

I dont understand why its are not in the code from beginning. Like you must put in a code for the connect and then a new psk where handled from peer to peer , or you must proof the psk token, with a code, and then the connection are working.

Greets

#6
Web Proxy Filtering and Caching / Re: Squid not working
October 23, 2024, 09:02:13 AM
So i fight with this module.

What i want, web filterung for specific user for specific websites.
without the old buisness plugin opnporxy i can block all and give websites free, but this wher eonly for all users.

with the opnproxy plugin i have many erros , users can not authetificate:

   Error   (basic_pam_auth)   in openpam_dispatch(): all modules were unsuccessful for pam_sm_authenticate()

User where authificate can accees all websites! , but it have all deny all , and only one website allow.
we though to use ist in our buisness , when test are ready, but when it has no forced block all fallback mode, i have no garanty that all things are right , how  i configured.

so how can i find out where i missconfigured? The policy tester say , the rule is right, but on the real side, user has accees to everthing, when authification comes right.

Failure : athentification:

   Error   (basic_pam_auth)   in openpam_dispatch(): all modules were unsuccessful for pam_sm_authenticate()

Picture one deny all for the web user

Picture two allow opnense website

#7
Have you done this with the opnproxy plugin?
#8
Web Proxy Filtering and Caching / Re: Squid not working
October 22, 2024, 12:56:15 PM
ok with a fresh opnsense install , same settings , its works .

So finaly question, how can a user purge all data from a plugin? so he can go started from scratch. everytime install a new sense , sounds no good.
#9
Web Proxy Filtering and Caching / Re: Squid not working
October 22, 2024, 10:40:48 AM
So i purge the plugins and clear the config file to start from scartch, but it works not anymore.

What is my goal:

Proxy without ssl isprection, only sni information because of url .

I have created a user, this has a block rule with * , so everything and an allow rule for two three pages.

The policy tester says that they work.

In the browser I enter squid as proxy port 3128 https also, but rich can call any page and there is no query for the user data for the proxy.

The opnproxy takes effect via the normal settings with the white and black lists or?

I also see in the log that the requests go through the proxy and are called up. why is there not even a user query without a user?

Does anyone run squid with opnproxy plugin and could show me his config? Slowly I don't know where to start.


#10
purge , must i have clear the squid from the config.xml or clear a folder?
#11
Web Proxy Filtering and Caching / Squid not working
October 21, 2024, 02:01:29 PM
Hello,

i setup a squid proxy  , with the os-OPNProxy .

I want setup different policy for different users.

But with Firefox its comes no credentials ask. Have anyone simular Problems? Firefox has no Options to set the username and Password or i dont see it.

edge browser also, so i think i have misconfigured.

How can i purge squid,redi,opnproxy? so that the configs are gone? deinstall and reinstall brings the old config.

#12
Hardware and Performance / Dec4240 Console Port
October 06, 2024, 07:34:38 AM

Hey,

we look for to buy a dec4240 appliance. Have anyone running it? We want use zenamor with ca 100 clients.
My question are , remote access , when gui and ssh stuck. The console port and usb port are rs232? Why no rj45 port. How can we access without stay on the applaince. Can we connect with a adapter the port to a switch ? Or used with a converter? How you used this?
#13
24.7, 24.10 Production Series / Re: wireguard 2fa defguard
September 24, 2024, 03:17:04 PM
but i will try defguard, and can tell , if this tool are good for the community!
#14
24.7, 24.10 Production Series / Re: wireguard 2fa defguard
September 24, 2024, 03:07:37 PM
because its a external pkg, so i would here of othe rpeople use that tool or have other ideas for a 2fa/mfa option for wireguard with opnsense.
#15
24.7, 24.10 Production Series / wireguard 2fa defguard
September 24, 2024, 02:37:22 PM
Hey ,

i read that defguard has a plugin for the opnsene , with that plugin 2fa for wireguard are possible. have anyone run this setup with defguard or how you secure your wireguard vpn ? or other options for 2fa /mfa for wireguard?