Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - sorano

#1
26.1 Series / Re: OPENvpn settings
March 27, 2026, 08:17:14 AM
Quote from: LisaMT on March 27, 2026, 01:15:28 AMMy opnsense is a server, and when I travel I can connect to the OpenVPN server with my OpenVPN client config.  All using Ubuntu  24.04. 
Keep in mind the OpenVPN still works fine, but in Opnsense there's no longer a way to generate client configs and export them.  YES I can create a new client config as an 'instance', but there doesn't seem to be a way to export that into a file that can be imported into NetworkManager.
In the previous opnsense version the client config/export worked great. 

I can export client configs perfectly fine from VPN: OpenVPN: Client Export.

Could it be that your OpenVPN server is still under legacy config?
If so you should recreate the OpenVPN server with the modern design and remove the os-openvpn-legacy plugin.
#2
Quote from: nicholaswkc on March 26, 2026, 08:37:06 AMMy claim is valid n not over panaroid about security. I cannot disclose the country I live in. 
I added RESET WAN interface every 10 min using cron job.



Well, hate to be that guy but from an external perspective it does indeed look pretty paranoid. Especially considering the duration of those posts spanning over years...

Do you have any proof to backup your claims of it being valid? Like do you have any IDS/IPS/SIEM logs to show?

Otherwise I would start there, it might even be a good exercise for you in order to strengthen your own cybersecurity.

Wazuh agent is available in OPNsense community plugins. Install it together with Suricata, spend some time configuring it. Install a Wazuh server on another host and ship the data from the Wazuh agent on OPNsense to the server.

If you hardware supports it I would also extend it with SPAN/Mirror for your WAN interface. You can use another host with Zeek for that.

At least try to bring some proofs to prove your point, otherwise you risk ending up sounding like a madman or a troll spreading FUD.
#3
I own a couple of Yubikeys and use them for public cloud services and I totally disagree that this deserves priority in OPNsense.

It's obviously more of a business edition feature that a very low percentage of core edition users will ever use.
#4
Thanks for this great guide! Successfully upgraded my i226 to 2.32.

Anyone know where I can get the firmware files for IX driver NICS?

device     = '82599ES 10-Gigabit SFI/SFP+ Network Connection'

dev.ix.0.fw_version: eTrack 0x800003de
#5
26.1 Series / Re: RA with dnsmasq
February 06, 2026, 11:48:21 AM
I also just upgraded and am a bit confused by the phrasing on the IPv6 changes.

"Dnsmasq is now the default for DHCPv4 and DHCPv6 as well as RA out of the box.  One thing that the upstream software cannot cover is prefix delegation so that is no longer offered by default.  Use another DHCPv6 server in this case."

I previously used Track interface and ISC was handling the DHCPv6, KEA is handling DHCPv4.

Now I switched from Track Interface (legacy) to Identity association and obviously my clients cannot get any DHCPv6.

What would be the correct way forward?
Can I keep KEA for DHCPv4 and use DNSmasq for DHCPv6?
Or should I migrate everything from KEA and use DNSmasq for both?
#6
I think Zenarmor is one of the worst examples of reverse feature creep I've ever seen in an application.

At the time, Sensei was actually one of the reasons that made me decide to switch from pf to OPN. Paid for home license for two years but after losing features year after year it was not worth it in the end. Looks like they are still trying to find ways to limit their application.
#7
25.7, 25.10 Series / Re: HAProxy - what did i do?
November 05, 2025, 10:40:35 AM
Quote from: erbmur on November 03, 2025, 07:51:35 PMHi all,

I setup haproxy a long time ago and through blood and sweat I managed to get it to work.
I now want to make some changes and I can't remember what I did!

The main problem I am having is I want to change my front end authenticator from authelia to tinyauth.
looking at the config file, I have a bunch of stuff I somehow managed to manually add to the file, under my public facing services I have a line in the config saying  # WARNING: pass through options below this line, with a bunch of stuff I somehow managed to stick underneath it, but I don't remember where or how I did it, and I need to make some changes to these.

if it helps, whenever I test syntax, I get a soft warning message with a bunch of "[WARNING] (33030) : config : parsing [/usr/local/etc/haproxy.conf.staging:132] : a 'http-request' rule placed after a 'use_backend' rule will still be processed before."

That warning is just a warning and depending on how complex your HAProxy rules are it can be something you just you have to live with. I've been having it for as long as I can remember.
#8
May I suggest tunable replacing realteak with Intel NIC.
#9
You could take a look at LNAV:

https://lnav.org/
#10
Yeah it's that zenarmor crap doing it.

My OPNsense installation have been alot more "Zen" since I just stopped using that piece of trash software.
#11
Then don't lol.

Current DHCPB is not going away (yet).


I'm very happy to see them implement KEA as it's the way.
#12
Cloudflares WAF is a god compared to Zenarmor.

You cannot even compare them feature wise.
#13
Quote from: athurdent on August 09, 2023, 09:28:15 AM
Oh boy, I used to be a big fan of Zenarmor. Now I'm actually considering cancelling my subscription.

Yeah, I canceled my home subscription. Not really worth it anymore, poor QA along with nerfing features was enough for me.

Who cares about a fancy webui when the core features gets broken.
#14
I've never added whitelisted entries from the reporting tab so I wouldn't know.

I add my whitelisted domain in:

Services --> Unbound DNS --> Blocklist
Whitelist Domains: Input FQDN or use regexp.
#15
Does the gateway reply to ICMP?

Try pinging it from your PC.