Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - lshantz

#1
I used OpenVPN for several years until the major changes made and have not got it going again. We finally made an effort to get it running and we thought all was well. We put a remote firewall into production after testing on the work bench and all was good. It stopped working after about 24 hours. We don't know why. We went out and turned off the static TLS and it still does not work. Out of frustration we went to IPSEC. Got it working. Less than an hour later, it too stopped working. We have spent hours trying to discover what is wrong. To the point, we have started looking at alternative firewalls.

It just struck me that since we are using CARP, is there a possibility that CARP is somehow causing us all this grief. I was quite surprised to see so little traffic on this topic. Either not very many people are using VPN here, or they are not having the trouble. But for it to work fine one minute and then stop with no changes being made is driving me mad.
#2
We are having almost the exact same issue. However, we have an even simpler setup. When we first set it up from scratch it worked! We had established a tunnel fairly quickly, but just as quickly the system kept trying to send data over the WAN port instead of the LAN. So what has us perplexed is, for the first few minutes it was fine. I could see unifi server and other servers for a very brief moment and then it either tries to send it over the WAN or it fails the get permission to make the initial handshake over the WAN. It feels like an underlying OS issue almost. I went down the rabbit hole of bad hardware first, but I've replaced it and no change.
#3
I wonder if what we are having trouble with is related. I used to use OpenVPN but lately with the changes and terrible docs, we gave up and went to IPSEC. Set it up fairly quickly and easily and poof it worked. Minutes later it stopped. NO changes were made. As best as I can tell it is an underlying OS issue. Permission to access the WAN port is getting denied, AFTER it was working. Sometimes a reboot of both FW's solves it but rarely. I think there is much more to this though. I just am not good enough to spend the time documenting all the things we are seeing.
#4
Historically there are answers when they have time. So are you saying they no longer jump in and help users unless they pay for help?
#5
There seems to be a lot of 0 replies lately. They must be very busy. I do recall in the new "instances" setup for servers, that you can enter the IP address and or subnet to connect to. Instances/local network/Local Network
#6
For some reason, I see all these messages and many people reading, but 0 replies. I do not understand why. I had the same problem. There have been MANY changes to OpenVPN and how it works. You will need to basically start over from what I can see. The old legacy stuff is pretty much gone. Now you have to create instances. The problem I'm running into is the new documentation is pretty lacking. Good luck.
#7
24.7, 24.10 Legacy Series / OpenVPN setup new
November 15, 2024, 09:19:19 PM
Delete please
#8
I started a fresh install, since every update seemed to cause the system to go down. I suspect legacy things were clashing. Anyhow now there are a couple of issues that I do not understand.

2024-11-12T17:57:06-07:00   Error   ntpd   error resolving pool 3.opnsense.pool.ntp.org: Name does not resolve (8)   
2024-11-12T17:57:06-07:00   Error   ntpd   error resolving pool 2.opnsense.pool.ntp.org: Name does not resolve (8)   
2024-11-12T17:57:06-07:00   Error   ntpd   error resolving pool 1.opnsense.pool.ntp.org: Name does not resolve (8)   
2024-11-12T17:57:06-07:00   Error   ntpd   error resolving pool 0.opnsense.pool.ntp.org: Name does not resolve (8)   
2024-11-12T17:56:54-07:00   Error   ntpd   error resolving pool 3.opnsense.pool.ntp.org: Name does not resolve (8)   
2024-11-12T17:56:53-07:00   Error   ntpd   error resolving pool 2.opnsense.pool.ntp.org: Name does not resolve (8)   
2024-11-12T17:56:52-07:00   Error   ntpd   error resolving pool 1.opnsense.pool.ntp.org: Name does not resolve (8)   
2024-11-12T17:56:51-07:00   Error   ntpd   error resolving pool 0.opnsense.pool.ntp.org: Name does not resolve (8)   
2024-11-09T22:46:40-07:00   Error   ntpd   error resolving pool 3.opnsense.pool.ntp.org: Name does not resolve (8)

This is one issue. Yet, if I ping those addresses they resolve and answer back just fine. I saw that a device was not using these servers, but going to an alternate. I wondered why. This is what I see.

The other issue, I'm guessing related is:
The DNS query name does not exist: <!DOCTYPE. [for Hulu]   
2024-11-13T14:20:04-07:00   Error   firewall   The DNS query name does not exist: if. [for Hulu]   
2024-11-13T14:20:04-07:00   Error   firewall   The DNS query name does not exist: <!--. [for Hulu]   
2024-11-13T14:20:04-07:00   Error   firewall   The DNS query name does not exist: Eyebrow:. [for Hulu]   
2024-11-13T14:20:04-07:00   Error   firewall   The DNS query name does not exist: Headline:. [for Hulu]   
2024-11-13T14:20:04-07:00   Error   firewall   The DNS query name does not exist: <script>. [for Hulu]   
2024-11-13T14:20:04-07:00   Error   firewall   The DNS query name does not exist: <style>. [for Hulu]   
2024-11-13T14:20:04-07:00   Error   firewall   The DNS query name does not exist: \@media. [for Hulu]   
2024-11-13T14:20:04-07:00   Error   firewall   The DNS query name does not exist: }. [for Hulu]   
2024-11-13T14:20:04-07:00   Error   firewall   The DNS query name does not exist: Subscriptions. [for Hulu]   
2024-11-13T14:20:04-07:00   Error   firewall   The DNS query name does not exist: Bundle. [for Hulu]   
2024-11-13T14:20:04-07:00   Error   firewall   The DNS query name does not exist: Enjoy. [for Hulu]   
2024-11-13T14:20:04-07:00   Error   firewall   The DNS query name does not exist: <img. [for Hulu]

It appears that a device is sending some sort of HTML file? So far I have not found which device is blasting this. I guess it IS rejecting the request, but as much as it is hammering the system, I would think this could impact performance.

Any suggestions welcomed. Thanks in advance.
#9
I'm disappointed that no one at the top chooses to followup on this. I gave up on Opnsense because of so many issues almost a year ago, but thought I'd come back and give it another try. Brand new install, with not much special going on yet. Bam, wi-fi calling sporatic. I get the message from AT&T sorry, your call can not be completed, please try again later. Turn off Wi-Fi and poof, it works. So I am thinking a port is blocked. All we need to do is find out which one.
#10
Okay, thanks. Was sure hoping to avoid another expensive switch. I just figured it should be simple to direct connect the two to each other, but apparently not so much.
#11
This thing is driving me nuts.

I'm not totally understanding. Are you saying to add the route to the NAS or the firewall? You can't just add a route in the firewall under system without adding things. For instance, under my gateway selection is just the WAN port. So you must mean on the NAS?
#12
I apparently have a lack of understand on how to make my unbound DNS to do what I want.

I have a unique setup I guess. I have two Synology NAS units. I wanted faster throughput so bought 2 10gbps NICS. I attempted to connect the high speed cable to my switch to only find out that even though it has 2 Fiber ports, they support 1gbps! WHY!? Dumb.. so as a work around, I have connected the cable directly from one NAS to the other. This is when my problems began. So to kind of draw a word picture:
NAS 1 has 2 IP addresses.
NIC 1 is on 192.168.100.x
NIC 5 is on 192.168.1.x (high speed)

NAS 2 has 2 IP addresss.
NIC 1 is on 192.168.100.x
NIC 5 is on 192.168.1.x (high speed)

All of a sudden my SMB server names started dropping out. I can still connect via IP, but when I drop to bash and ping from a workstation on the .100 subnet, NAS1 is is trying to resolve to NIC5!! I do not understand how this is even possible, but, if I ping NAS.FQDN, it resolves properly to NIC1.

So I went and added over rides in Unbound. I gave it the server name with proper IP address  and that did not work. I then added under aliases the server name and still no go.

So what am I doing wrong? How can I get it to properly resolve everytime? I have tried under general to add A record registration, I have tried changing the local Zone Types, but nothing seems to work. I don't even understand how Unbound even knows those NIC5's exist, since they are not connected anywhere except to each other. I also tried making those NIC5 gateways each other.
#13
 :o Really!! Dang... Well thanks for replying and keep up the good work.

At least I have documented a work around above for anyone else suffering from this weird issue. Oh, one thing.. it takes awhile to configure NTOPNG how I want it and it appears that this config data is stored in REDIS. I would very much like to capture/save this config data so when it does down again, I can quickly restore back to my setup. This is the 3rd or 4th this has happened over the last couple of years. Thanks in advance.
#14
Obviously someone finally paid attention and corrected what ever got borked. It is now working after the latest update. You can lock/close this thread now. It would be nice to get an acknowledgement of what was wrong and what was done to fix it in the patch though.
#15
Okay, I suspected as much. Didn't even look at the template one, but how does that help me solve the mystery?  :o