Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - x86

#1
I´ve downloaded the .cer and .key file and manually imported the certificate data in the trust store.
Changed the certs in nginx plugins and it works. But thats not really feasable in the future.
#2
Sadly i can´t help you, but i´m also running into issues with the Acme Client on 26.1.10

The last certificate renewal in may worked fine. Now my certs are expired. Nothing changed, except for installing updates.
Took a look around in the ACME-Client, tried to manually renew the certs.
Logfile says all is well and good, certificates have been renewed.

In the ACME-Client Certificates Section in WebGUI it still shows the old cert data. Also in the System-Trust-Certificates the old certificates are shown
Deleted one of the old certs and re- set it up in the ACME-Client, but no dice. Logs says everything is fine, but the issue renewal date, last ACME status and last run in WebGUI show "pending | unknown | unknown"

SystemLog:
2026-08-03T11:52:23
opnsense
AcmeClient: successfully issued/renewed certificate: ssm.domain.tld
2026-08-03T11:52:20
opnsense
AcmeClient: AcmeClient: The shell command returned exit code '0': '/usr/local/sbin/acme.sh --issue --syslog 6 --log-level 1 --server 'letsencrypt' --webroot /var/etc/acme-client/challenges --home '/var/etc/acme-client/home' --cert-home '/var/etc/acme-client/cert-home/6a706479e2b058.98895336' --certpath '/var/etc/acme-client/certs/6a706479e2b058.98895336/cert.pem' --keypath '/var/etc/acme-client/keys/6a706479e2b058.98895336/private.key' --capath '/var/etc/acme-client/certs/6a706479e2b058.98895336/chain.pem' --fullchainpath '/var/etc/acme-client/certs/6a706479e2b058.98895336/fullchain.pem' --domain 'ssm.domain.tld' --days '60' --force --keylength '4096' --accountconf '/var/etc/acme-client/accounts/65e9c826dfbdb6.16991821_prod/account.conf''
2026-08-03T11:52:00
opnsense
AcmeClient: using challenge type: SSM
2026-08-03T11:52:00
opnsense
AcmeClient: using IPv4 address: XXX.XXX.XXX.XXX
2026-08-03T11:51:59
opnsense
AcmeClient: account config is valid (CERT_HOME): netadmin@domain.tld
2026-08-03T11:51:59
opnsense
AcmeClient: account is registered: netadmin@domain.tld
2026-08-03T11:51:59
opnsense
AcmeClient: using CA: letsencrypt
2026-08-03T11:51:59
opnsense
AcmeClient: issue certificate: ssm.domain.tld

ACME-Log:
2026-08-03T11:52:20
acme.sh
[Mon Aug 3 11:52:20 CEST 2026] Installing full chain to: /var/etc/acme-client/certs/6a706479e2b058.98895336/fullchain.pem
2026-08-03T11:52:20
acme.sh
[Mon Aug 3 11:52:20 CEST 2026] Installing key to: /var/etc/acme-client/keys/6a706479e2b058.98895336/private.key
2026-08-03T11:52:20
acme.sh
[Mon Aug 3 11:52:20 CEST 2026] Installing CA to: /var/etc/acme-client/certs/6a706479e2b058.98895336/chain.pem
2026-08-03T11:52:20
acme.sh
[Mon Aug 3 11:52:20 CEST 2026] Installing cert to: /var/etc/acme-client/certs/6a706479e2b058.98895336/cert.pem
2026-08-03T11:52:20
acme.sh
[Mon Aug 3 11:52:20 CEST 2026] And the full-chain cert is in: /var/etc/acme-client/cert-home/6a706479e2b058.98895336/ssm.domain.tld/fullchain.cer
2026-08-03T11:52:20
acme.sh
[Mon Aug 3 11:52:20 CEST 2026] The intermediate CA cert is in: /var/etc/acme-client/cert-home/6a706479e2b058.98895336/ssm.domain.tld/ca.cer
2026-08-03T11:52:20
acme.sh
[Mon Aug 3 11:52:20 CEST 2026] Your cert key is in: /var/etc/acme-client/cert-home/6a706479e2b058.98895336/ssm.domain.tld/ssm.domain.tld.key
2026-08-03T11:52:20
acme.sh
[Mon Aug 3 11:52:20 CEST 2026] Your cert is in: /var/etc/acme-client/cert-home/6a706479e2b058.98895336/ssm.domain.tld/ssm.domain.tld.cer
2026-08-03T11:52:20
acme.sh
[Mon Aug 3 11:52:20 CEST 2026] Cert success.
2026-08-03T11:52:19
acme.sh
[Mon Aug 3 11:52:19 CEST 2026] Le_LinkCert='https://acme-v02.api.letsencrypt.org/acme/cert/065d65698150dc3b62dd96c5f05b112c55ba'
2026-08-03T11:52:19
acme.sh
[Mon Aug 3 11:52:19 CEST 2026] Downloading cert.
2026-08-03T11:52:18
acme.sh
[Mon Aug 3 11:52:18 CEST 2026] Le_OrderFinalize='https://acme-v02.api.letsencrypt.org/acme/finalize/1606878407/540226864361'
2026-08-03T11:52:18
acme.sh
[Mon Aug 3 11:52:18 CEST 2026] Let's finalize the order.
2026-08-03T11:52:18
acme.sh
[Mon Aug 3 11:52:18 CEST 2026] Verification finished, beginning signing.
2026-08-03T11:52:18
acme.sh
[Mon Aug 3 11:52:18 CEST 2026] ssm.domain.tld is already verified, skipping http-01.
2026-08-03T11:52:18
acme.sh
[Mon Aug 3 11:52:18 CEST 2026] Getting webroot for domain='ssm.domain.tld'
2026-08-03T11:52:15
acme.sh
[Mon Aug 3 11:52:15 CEST 2026] Single domain='ssm.domain.tld'
2026-08-03T11:52:15
acme.sh
[Mon Aug 3 11:52:15 CEST 2026] The domain key is here: /var/etc/acme-client/cert-home/6a706479e2b058.98895336/ssm.domain.tld/ssm.domain.tld.key
2026-08-03T11:52:01
acme.sh
[Mon Aug 3 11:52:01 CEST 2026] Creating domain key
2026-08-03T11:52:01
acme.sh
[Mon Aug 3 11:52:01 CEST 2026] Using CA: https://acme-v02.api.letsencrypt.org/directory

The certificates seem to be renewed on the file system:
root@opnsense:/var/etc/acme-client/cert-home/6a706479e2b058.98895336/ssm.domain.tld # ls -lha
total 44
drwxr-x---  3 root wheel  512B Aug  3 11:52 .
drwxr-x---  3 root wheel  512B Aug  3 11:52 ..
drwxr-x---  2 root wheel  512B Aug  3 11:52 backup
-rw-r-----  1 root wheel  3.8K Aug  3 11:52 ca.cer
-rw-r-----  1 root wheel  5.9K Aug  3 11:52 fullchain.cer
-rw-r-----  1 root wheel  2.1K Aug  3 11:52 ssm.domain.tld.cer
-rw-------  1 root wheel  995B Aug  3 11:52 ssm.domain.tld.conf
-rw-r-----  1 root wheel  1.7K Aug  3 11:52 ssm.domain.tld.csr
-rw-r-----  1 root wheel  188B Aug  3 11:52 ssm.domain.tld.csr.conf
-rw-------  1 root wheel  3.2K Aug  3 11:52 ssm.domain.tld.key
root@opnsense:/var/etc/acme-client/cert-home/6a706479e2b058.98895336/ssm.domain.tld #
#3
German - Deutsch / Re: VPN Probleme bei Multi-WAN?
November 23, 2022, 10:54:41 AM
Du meintest wahrscheinlich diese Einstellungen:
#4
German - Deutsch / Re: VPN Probleme bei Multi-WAN?
November 23, 2022, 10:51:26 AM
Ja, ich habe auch mehere OPNsense mit Multi-WAN im Einsatz, das Problem hatte ich aber auch noch nie.
Aber das ist die einzige bei der beide WAN Anschlüsse über PPPoE mit VLAN7 laufen, daher vermute ich da fast den Knackpunkt.
Die Firewalleinstellungen sind unspektakulär:

WAN01
Protokoll   Quelle   Port   Ziel   Port   Gateway   Zeitplan   Beschreibung       
IPv4 UDP   *   *   Diese Firewall   1194 (OpenVPN)   *   *         
IPv4 ICMP   *   *   Diese Firewall   *   *   *   

WAN02
Protokoll   Quelle   Port   Ziel   Port   Gateway   Zeitplan   Beschreibung       
IPv4 UDP   *   *   Diese Firewall   1194 (OpenVPN)   *   *         
IPv4 ICMP   *   *   Diese Firewall   *   *   *   

#5
German - Deutsch / Re: VPN Probleme bei Multi-WAN?
November 23, 2022, 09:18:41 AM
Hi,

ist nur ein OpenVPN-Server, der steht auf "any" bei den Interfaces.

mfg
#6
German - Deutsch / VPN Probleme bei Multi-WAN?
November 23, 2022, 09:03:14 AM
Hallo,

ich habe ein Problem und komme nicht so wirklich drauf wie ich das lösen könnte, vielleicht habt ihr ja noch Ideen.
Folgende Config:
OPNsense mit 2x PPPoE (2x Glasfaser mit den Telekom Modems, also über VLAN7) als Multiwan konfiguriert.
LAN,DMZ und ein weiteres Netzwerk an physikalischen Nics, keine weiteren VLANs.

VPN-Server mittels des Wizards konfiguriert, ein paar Einstellungen angepasst, aber nichts wildes, eigentlich nur die Verschlüsselung etwas höher als den Standard konfiguriert.

Problem:
Über die WAN1 öffentliche IP bekomme ich ohne Probleme eine VPN-Verbindung, über die WAN2 nicht.
TLS-Handshake fail, check your network connectivity.
Freigaben sind soweit konfiguriert, die Pakete kommen bei der Firewall an.
Was ich bisher bei der Packet capture gesehen habe, kann ich allerdings nicht so ganz zuordnen, denn wenn ich über die WAN2 IP versuche die Verbindung aufzubauen, werden mir beim WAN1 Interface im Paketmitschnitt die Antwortpakete angezeigt, allerdings mit der WAN2 IP als Absender. Also alles komplett seltsam.
Sieht dann in etwa so aus:
WAN02
pppoe0 2022-11-23
08:05:49.296205 length 118: (tos 0x0, ttl 122, id 2167, offset 0, flags [none], proto UDP (17), length 114)
VPN-Client-IP.2983 > WAN02-IP.1194: [udp sum ok] UDP, length 86

WAN01
pppoe5 2022-11-23
08:05:49.296567 length 130: (tos 0x0, ttl 64, id 12494, offset 0, flags [none], proto UDP (17), length 126)
WAN02-IP.1194 > VPN-Client-IP.2983: [udp sum ok] UDP, length 98


Jemand eine Idee dazu?

mfg
#7
General Discussion / Re: MDNS Issues
March 25, 2022, 11:33:23 AM
It got even weirder yesterday when i tried to deploy some clients to the vlans.
I´ve got the vlans 10,20,30 and 40, all on ix0, all configured IP-Adresses/Networks over the webgui, everything was showing fine, DHCP-Server activated for the networks.
I did not get DHCP-Response in VLAN20 and VLAN30, also no network connectivity with static ip set on the client...
Checked my Switchconfigs up an down, thought i had misconfigured VLANS somewhere, everything was fine, checked the webgui again, everything was fine, deleted all VLAN interfaces/networks and VLANs, configured again, everything seemed fine, issue still persisted.
Logged on to the console via ssh, switched to shell, ifconfig showed all the interfaces with the according IP Adresses...
Exited the Shell with Crtl+d, then it struck my eye... the VLAN Interfaces 20 and 30 above the console starting menu did not show any ip adresses.

Assigned the ip adresses over the console menu, suddenly DHCP and networking was working and also the MDNS Repeater started without issues.

Has anyone ever encountered something like this?
#8
General Discussion / Re: MDNS Issues
March 18, 2022, 01:13:07 PM
Yup, this is weird.
Just tried on a different installation, set up interfaces and VLANs the same, seems to be working ootb.
Computers are strange ¯\_(ツ)_/¯
#9
General Discussion / Re: MDNS Issues
March 18, 2022, 08:20:58 AM
Of course i had the subnets assigned to the VLAN Interfaces.
MDNS-Repeater apparently has issues with different interfaces using the same MAC-address.
As soon as i manually assigned different MAC-adresses to the VLAN interfaces MDNS-Repeater was able to read the ip addresses of the interfaces correctly.
#10
General Discussion / Re: MDNS Issues
March 17, 2022, 05:12:21 PM
So... it might be working, i have to check sometime soon...
At least it shows as running in the webgui for now and the shell does not throw an error.
I had to manually assign different MAC-Adresses for the VLAN-Interfaces.
#11
General Discussion / Re: MDNS Issues
March 17, 2022, 04:50:41 PM
It really is not finding the interfaces of the vlans. No issues with physical interfaces it seems.


root@opnsense:~ # mdns-repeater -f ix0 igb0
mdns-repeater: dev ix0 addr 192.168.173.10 mask 255.255.255.0 net 192.168.173.0
mdns-repeater: dev igb0 addr 192.168.1.254 mask 255.255.255.0 net 192.168.1.0
^C
root@opnsense:~ # mdns-repeater -f ix0_vlan20 ix0_vlan10
mdns-repeater: send bind(): Address already in use
mdns-repeater: dev ix0_vlan20 addr 0.0.0.0 mask 0.0.0.0 net 0.0.0.0
mdns-repeater: send bind(): Address already in use
mdns-repeater: recv setsockopt(IP_ADD_MEMBERSHIP): Address already in use
mdns-repeater: unable to create socket for interface ix0_vlan10
mdns-repeater: exit.
root@opnsense:~ # mdns-repeater -f foo bar
mdns-repeater: send bind(): Address already in use
mdns-repeater: dev foo addr 0.0.0.0 mask 0.0.0.0 net 0.0.0.0
mdns-repeater: send bind(): Address already in use
mdns-repeater: recv setsockopt(IP_ADD_MEMBERSHIP): Address already in use
mdns-repeater: unable to create socket for interface bar
mdns-repeater: exit.
root@opnsense:~ #


So... i need this working. Are there any other options?
#12
General Discussion / Re: MDNS Issues
March 17, 2022, 04:43:06 PM
Also...
when trying to bridge LAN and ix0_vlan10 on shell this happens:

root@opnsense:~ # mdns-repeater -f ix0 ix0_vlan10
mdns-repeater: dev ix0 addr 192.168.173.10 mask 255.255.255.0 net 192.168.173.0
mdns-repeater: send bind(): Address already in use
mdns-repeater: dev ix0_vlan10 addr 0.0.0.0 mask 0.0.0.0 net 0.0.0.0
^C


seems to me like the mdns repeater has issues getting the ip addresses of vlan interfaces.

#13
General Discussion / MDNS Issues
March 17, 2022, 04:25:03 PM
Hello,
i´ve got issues with the MDNS plugin.
Current config is like this:
ix0 - LAN
ix0_vlan10 - stuff
ix0_vlan20 - other stuff
ix0_vlan30 - even more stuff

Tried from the gui to bridge the stuff and other stuff networks, MDNS Icon is red and can not be activated.
Tried to bridge lan and other stuff network, MDNS seems to be running.
Stopped it.
Switched to Shell, tried:
root@opnsense:~ # mdns-repeater -f ix0_vlan10 ix0_vlan20
mdns-repeater: send bind(): Address already in use
mdns-repeater: dev ix0_vlan10 addr 0.0.0.0 mask 0.0.0.0 net 0.0.0.0
mdns-repeater: send bind(): Address already in use
mdns-repeater: recv setsockopt(IP_ADD_MEMBERSHIP): Address already in use
mdns-repeater: unable to create socket for interface ix0_vlan20
mdns-repeater: exit.


so... whats happening here? And how do i make it work?
#14
Braucht es nicht zu wissen?
Die 192.168.198.43 ist im gleichen Netz wie mein Client.
Und ausgehend sollte die Opnsense auch in der Lage sein zu erkennen dass das 192.168.198.0/23 Netz direkt an ihrer WAN-Schnitstelle angeschlossen ist und dementsprechend die Pakete nicht zu ihrem Standardgateway schicken.
#15
Hi,

nein, ich möchte nicht routen.
Ich möchte an meinem Client die http://192.168.198.43 aufrufen und dabei mit Port 80 auf dem Server mit der 192.168.1.155 ankommen.