Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - adam.blackburn

#1
20.1 Legacy Series / Re: nat reflection & dual nat
August 19, 2020, 02:42:41 PM
I actually have a set up like this and I had to set up Nat reflection at the edge router

My understanding is that the OPNsense doesn't actually know what your true WAN IP is because the WAN IP is actually a LAN IP from the edge. Because of this, it wouldn't be able to do reflection.
#2
20.1 Legacy Series / Very high pfsync traffic
August 19, 2020, 09:23:48 AM
Hi All,

I am a bit stumped about what is going on
We have had a huge amount of data usage over the last few days and I have finally tracked it down to pfsync!

It looks like it is unicast traffic and over the last few days it has broadcast about 12TB
I've attached (hopefully it works) a screenshot showing the high usage from the insight page

Any ideas where to look and see why it is doing this?

Thank you!
#3
I believe I figured it out, for anyone who ever looks at this in the future:

You don't need to set the vhid unless you do wan the traffic to go out both wans like a round robin type of deal it seems

My second issue ended up being an issue upstream. If I didn't have the issue upstream then my issue would have been figuring out why its going out via both WANs! Which again would be due to the vhid being set

Sorry for posting when not needed, maybe it will help someone else
#4
Hi all,

I'm running into an issue with a new set up and not sure what is going wrong.
I have two virtual OPNsense instances set up in HA which is working and all traffic is going out on our default WAN IP without issue

For reference, the CARP WAN interface is using vhid 1

I added a WAN IP alias on vhid 1 and set up a NAT outbound for an internal machine and that is working as expected
I tried adding another WAN IP alias on vhid 1 and once I click apply, my internal machines begin experiencing drop outs (about 50%)

I am assuming it is trying to route out both WAN IPs but not sure what the next step is to correct that.

I will have about 10 WAN IP addresses that I need to set up so hopefully I'm just missing a step

Any ideas?

Thank you