Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - votan

#1
Hi,
I intended to do a port forward to my DMZ, but something went wrong and now I cannot access OPNsense GUI anymore (error "PR_END_OF_FILE_ERROR" in browser).

I think I need to change (meaning: delete) the port forward from the command line where I still have access.

A similar problem was described https://forum.netgate.com/topic/59501/show-port-forward-nat-rule-port-via-command-line for pfsense, but I cannot make sense out of it. Probably this is a different implementation.

Can anyone direct me how to change the port forward rules from the command line?
In case you see any other option please direct.

Appreciate your time,
votan
#2
Hello,
I upgraded from 19.7 to 20.1 - in general, the OPNsense works.
With a frequency of 4-5 times a day, I get a DNS problem that I cannot nail down - can you please help:

- Clients in the netwoork cannot resolve DNS anymore when this happens, e.g. I cannot open google.de in the web browser, or ping google.de.
"dig google.de" is not showing me any IP address then.

- If I go to "Interfaces-Diagnostics-DNS Lookup" on the OPNsense GUI, and then enter "google.de" there, I do get
a result, but it takes very long (roughly one minut) until I get a result. The DNS request are reported to take only 20-40ms, so it looks like this is a problem within OPNsense, not upstream

- RE-starting Unbound does not solve the problem

- Re-starting whole of OPNsense does solve the problem, but only for a short amount of time

- htop on OPNsense is not showing me any process that could be a problem / that would be stale

Any idea what could cause the problem, what could be a solution of how I even could nail it down?
Appreciate your help,
votan
#3
19.1 Legacy Series / Re: OpenVPN -> NordVPN
January 04, 2020, 03:04:12 PM
Any update on this? I have the very same problem on OPNsense 19.7.8 and wonder if someone solved this.
Yours
Raspyvotan
#4
Hello,

I would like to use OPNsense after a FritzBox 7560 as modem.
Unfortunately, seems like Fritzbox (Fritz!OS 7.01) has no Bridge mode where it runs as a modem only.
I think this is the reason why I have not yet managed to setup the WAN.

Question:
- What is the best setup here? Should I run FRitzBox and OPNsense as a "cascade of routers", or does anyone have an idea how to force it into Bridge mode? Technical support of my ISP mentioned to "reset" the Fritzbox and try then, but I could not get this up.

- Very likely I also have an open item with the Firewall rules - if I want to try if the internet connection works, I need at least a filter that allows for internet traffic to my LAN. I tried with a filter opening port 80/443 on the LAN, but I am not sure if that does the trick. As I am new to this: Which rule would I need to test if LAN->WAN->FritzBox->Internet works?

- Which setup for WAN is right? I tried FRitzbox with a static IP (192.168.0.1) and WAN with DHCP. Does this work, or do I need to assign Fritzbox and WAN the same address/mask? Thx for any guidance.

Highly appreciate your time,

Yours
Votan
#5
SOLVED

I received my hardware with another OS pre-installed, and somehow the partition table got messed up with.
This post solved the problem (which is not an OPNsense problem, but an OS problem):


https://forums.freebsd.org/threads/corrupt-ada0-error-on-install.49204/

Hopy this helps anyone.

Votan
#6
I am trying to install OPNsense 19.1 on a Qotom Q355G4 (https://www.aliexpress.com/item/Qotom-Mini-PC-Core-i3-i5-i7-with-4-Gigabit-Ethernet-NIC-Pfsense-AES-NI-Fiewwall/32863060778.html?spm=2114.search0104.3.2.6a1734a2C1dvcr&ws_ab_test=searchweb0_0,searchweb201602_9_10065_10068_319_10059_10884_317_10887_10696_321_322_10084_453_10083_454_10103_10618_10307_537_536_10902_10134,searchweb201603_60,ppcSwitch_0&algo_expid=90768865-fccc-4504-b81d-530da2c5ad6f-0&algo_pvid=90768865-fccc-4504-b81d-530da2c5ad6f&transAbTest=ae803_3 respectively http://www.qotom.net/

As an image, I use "AMD64" / "VGA" which I write on an USB stick via dd

I manage to boot from the USB, yet I get a kernel panic:
Message: "the secondary GPT header is not in the last LBA"
"Failed to map the main stack"
"init died (signal 6, exit 0) panic: Going nowhere without my init!"

Can anyone help?

1. Do I use the right imate?
2. I try to boot from USB, the aim is to then install it on the hard disk. Is this the right approach?
3. Any insight that is specific to Qotom? Anyone has this up and running?

Yours
Votan