Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - securityconscious

#1
Quote from: EdwinKM on June 06, 2022, 11:31:02 AM
a firewall rule is permanent. Is this for prevention or are you investigating something?
Malware sessions are from inside to outside (internet). You can block known destinations.

Both prevention and investigation. I suspect they are from inside and I don't know what IP they are connecting to. I'm new to firewalls and OPN Sense.
#2
What rules should I make to find short lived connections like ones made by malware?
#4
Quote from: mimugmail on February 17, 2021, 07:17:10 AM
System : Settings : Logging, Disable circular and set the days to preserve logs.

When I go to System>Settings>Logging, I'm unable see to any option for circular.
#5
Quote from: Gauss23 on February 18, 2021, 08:16:53 PM
Quote from: securityconscious on February 17, 2021, 06:18:44 AM
After selecting a mirror a download button will be shown, clicking on the download button is opening the ISO file or IMG file in a new tab instead of allowing me to save it.

Can't reproduce that. Tried with latest Firefox on MacOS. It's not downloading an ISO or IMG. It's a bz2 file. Maybe your browser is not handling that correct.

I assumed it wasn't compressed, so I thought the file extension is ISO or IMG. How are you doing this? Are you right clicking on the download button and selecting save as or just left clicking on the download button?

I'm getting the same problem even now.
#6
Quote from: Gauss23 on February 17, 2021, 07:44:20 AM
Which browser and version are you using? Which OS?

Please tell us what you select in the dropdowns:
- System architecture
- image type
- mirror

This is something I would at least expect when reporting a possible bug on a website.

Then someone can try to find it why your browser is doing that. I just tried some combinations and it works as expected, download starts.

Firefox latest. Fedora OS

System architecture: amd64
image type: any
mirror: any
#7
Quote from: mimugmail on February 17, 2021, 07:17:10 AM
System : Settings : Logging, Disable circular and set the days to preserve logs.

Okay. Thx
#8
Quote from: Fright on February 17, 2021, 07:42:29 AM
client browser does not respect content-type header.
client-side issue

I don't have this problem on other websites, including firewall download sites.
#9
Is there a way to view older entries in the live view of firewall logs?

I want to be able to see all the connections a client makes from the time it starts till it is shutdown. How can I do this? The live view is only showing few connections and older ones are replaced by newer ones.
#10
Quote from: lfirewall1243 on February 15, 2021, 10:45:53 AM
In which context?

We need some more informations.

Type opnsense.org in your browser

Click on Download

Select a mirror

After selecting a mirror a download button will be shown, clicking on the download button is opening the ISO file or IMG file in a new tab instead of allowing me to save it.
#11
When I press the download button, instead of allowing me to save the ISO file or IMG file, it is opening a webpage with garbled text, it is completely freezing the browser, I'm assuming it is the contents of the ISO file or IMG file.

To avoid this problem I have to right click on the download button and select something like save this file as to actually save the ISO file or IMG file.
#12
Is there a way to find out what causes random freezing of OPNSense?

Few days ago, there was a disconnection in WAN side, in the night, OPNSense froze, no clients were on during this time, when I turned on I couldn't access the webUI. I had to hard reset to get it back up.

I was wondering if anyone could have performed a man-in-the-middle attack while there was a disconnection in the WAN side, can I run any integrity checks or view logs? Where can I find system logs if it has  been tampered with?

Or should reinstall the whole thing again?
#13
Quote from: Greelan on January 30, 2021, 06:41:41 AM
If that's your attitude when someone tries to help, good luck with your life. I can see why you were banned from the IPFire forum. Your rule doesn't do what you think it does, but given you seem to know so much about what you are doing, I am sure you will figure it out yourself

I think you wanted to troll me or you have poor reading comprehension.

There is nothing wrong with my attitude, in fact in my opening post I asked what am I doing wrong, do you think I would have asked such a question, if I was sure of myself? You could have answered what I was doing wrong, instead chose to troll me or chose to not apply your mind. Why doesn't my rule do what I think it should?

My opening post says, I blocked every other rule, it implies, the newly created rule is active but other rules are inactive. Yet, you tried to make a thoughtless post, maybe your double-agent from IP Fire, to defend their dirt, you wanted to troll me here.
#14
Quote from: Greelan on January 30, 2021, 06:31:05 AM
Traffic is blocked by default, so if you disabled all other rules, there is no rule to allow the required traffic

I clearly wrote that I made this rule and disabled every other rule, so shouldn't this rule allow access to the IPs in the alias list?

As this rule is active shouldn't it allow access to the IPs in the it's alias list?
#15
I created an Alias list of IPs of websites I visit most, in OPT1 interface using this Alias I created a block firewall rule, in the destination portion, I selected invert match and used this alias, I saved this rule and applied. I disabled every other rule, and I tried accessing those sites and I wasn't able to access them, I couldn't ping them also.

What am I doing wrong?

I want to create a list of IPs to which my network has access, my network must not access to IPs which are not in that list.