Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - pkejval

#1
Quote from: h3krn on March 26, 2024, 01:03:59 PMIt's far from perfect, but I hope someone finds this useful?

https://gist.github.com/h3krn/17c6610281e585d6b4efb43d1395802d

Grtz, Harm

Thank you very much! This is most missing feature of KEA DHCP for me. You should try to upstream this into OPNsense.
I adjusted it little bit because it gave me double domain for some hosts: https://gist.github.com/pkejval/49ff234bb81da59fde6ca1b03f4d4240/revisions
#2
Since 22.1 I have many and many messages like this in console:

2022-03-03T06:58:20.424022+01:00 <fw hostname> lighttpd 23685 - - (connections.c 717) unexpected TLS ClientHello on clear port (<client IP>)

It's on my VLAN with CaptivePortal mostly with Android phones connected. Captive portal doesn't have "Transparent proxy" enabled. What can be root of this "problem"?
#3
I can confirm that there is problem with updating from 20.1 to 20.7. If Endpoint Allowed IPs configuration contains its own LAN subnet, wireguard won't start. I admit it was completely Wireguard config misunderstood but it worked before.

Example:
GW ip 192.168.3.1/24 - if Endpoint Allowed IPs on that machine contains 192.168.1.0/24, 192.168.3.0/24 - WG won't start. Remove 192.168.3.0/24 and it will start and works as expected.