Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - pixelmeister

#1
Hi, I would like to add my story to this - spoiler: no solution yet

21.6 with realtek 1Gb/4x1GB > realtek 1Gb/4x2.5Gb

Migration from "old" to "new" hardwware was a nightmare and the new hardware is not working yet.

Its a Family class smart home with lots of Youngsters busting bandwith with everything the can get

Running rock solid through COVID 5 people HomeOffice - A huge THANK YOU to all opnsense "builders"

just wanted to start using more QoS and Security Feature which the "old" CPU can't handle well
(I like to be on the save side and keep everthing under 30% load in general)

old:
  • using opnsense since about 2021 (never reinstalled, just upgraded)
  • 26.1.10
  • consumer miniitx asrock N4105
  • exsys 4x1GB pcie card (realtek)
  • lots of VLANs and Native LANS

new:
  • complete new install 26.X upgraded to latest
  • 26.1.10
  • consumer miniitx GigaByte B550M K
  • digitus 4x2.5GB pcie card (realtek 8125B)
  • same config as above

my facts:
  • working with IT since more than 35 years
  • no crack, but serious PC knowledge
  • general network understanding
  • unifi Networkstack
  • gracefule to all facepalm explainers and Layer8-knowledge extenders
  • awareness of being the problem :-)

  • the new hardware is running with opnsense 26.1.10
  • on an USB RJ45 everything works LAN side
  • WAN side 1Gb Realtek running
  • 4xLAN card was dedected after driver install (plugin)
  • no DHCP is working in either LAN side of the PCiecard

As the setup identicall and the hardware are IMHO very similar I do not see any Error on my side - I would love to find it and solve it!

Things that I recouldniced during working on this nearly 2 weeks after work (which is surely not the best time to make critical things)

After last setup LEGACY DHCP is not shown up any more? on my old running setup (and first migrations tests legacy DHCP was still there)
legacy DHCP should not be used - deactivated
I do not use any 2.5Gb switch they are prepared in the rack and not in the testsetup (maybe? the card does not fallback to 1Gb correctly?)
At my first test with my old 25.x opnsense USB Stick the card was recouldniced from the first start without doing a plugin or driver install

I do not know if this helps anybody or anybody could help me?
I will/have to try do get it done anyway :)

Yes for sure I searched and read a lot but - found a lot of useful help here to improve my understanding, but nothing that may solve my problem

Test still pending: trying 2.5Gb switch to attach, try to attach with manual setup network settings, ...?

best regards
Antonio



#2
General Discussion / Re: UDP Broadcast Relay
December 20, 2021, 09:40:01 PM
I struggled with my miniDLNA since weeks (came from another FireWall Software AND started use VLANs stricter)

It needed tons of forum threads and lots of hours - do some missunderstanding from my side - i used a wrong plugin and did tweak wrong rules  :o.

At the END: THANK YOU Major!!! (was so tired when read your posts the first time - Major56 burned in my brain ;D)

So: Thank you marjon56 - would really spend you a big big chocolate and a nice coffee(or tea)

For all others struggling with miniDLNA - use this plugin - set source empty and watch your livelog - Ports 8200 and 1900 (UDP/TCP) and you are done.
Using VLC on windows from VLAN-A to VLAN-S (miniDLNA) and other DENON-devices that find the server from VLAN-M. Even my Teufel seems to work. But I have to stop for today and get some sleep.

Once again - marjon56 - you saved my Christmas! (family expected to play Christmas songs from the Devices as usual
#3
Vielen Dank für die Antwort, ich komme mit dem Forum noch nicht so gut zurecht - habe erst jetzt entdeckt, dass ich explizit markieren muss, Antworten gemailt zu bekommen :-).

Deswegen ein nachträgliches Danke!  :D

Ich versuche das mit den Logeinträgen auch zu nutzen, aber irgendetwas verstehe ich bei opnsense noch nicht ganz. Denn ich sehe meist Datenverkehr an meinen "untersten" Deny Regeln aufschlagen, die "Allow" Regel"darüber entspricht aber aus meine Sicht genau dem aus dem Log - spricht aber nicht an.

Wie sollte denn diese einfache Regel aussehen um meinen Kindern den Drucker aus VLAN 10.0.20.* den Drucker in VLAN30 mit der IP 10.0.50.30 das ZielPort 631 verfügbar zu machen?
(Mir ist klar, dass es nicht bei dieser einen Regel bleiben wird! Aber nur für mein Verständnis)

Habe mich schon mehrere Nächte im Forum herumgeschlagen, und eigentlich dachte ich, ich verstehs, aber irgendwas scheine ich misszuverstehen  ::)
#4
Hallo,
ich bin noch sehr neu bei opnsense,
habe jahrelang mit Astaro/Sophos UTM gearbeitet und kenn mich mit IT recht gut aus, bin aber kein Netzwerk-crack, habe diverse Switches schon durch, aber jeder "Vokabel-Wechsel" bringt mich an die Grenzen  :o

und komme daher mit einigen Dingen trotz intensiver Dokunutzung noch nicht klar - ich denke einfach noch nicht opnsense passend.

Daher mein Hilferuf  :)


  • Kann ich aus Firewall Regeln die im Livelog aufschlagen eine Firewallregel machen?
    Bzw. gibt es dazu ein Plugin.
  • Gibt es hier irgendwo im Forum (oder woanders) eine Liste einfacher "Default" Regeln? (Regelset für Mailverkehr/Samba/Linux Updates/Youtube verbieten/...

Vielen Dank!
#5
Thank you very much!

Just did it for the first server  :D

For other opnsense newbees
Keep in mind that ALL changes need to be applied!  ;D
AND in some window masks - you have to active the rule - if not ticked before!  ;)
#6
Thank you very much!
Allready started to test, ...
will post in the evening when I have success
:D
#7
21.7 Legacy Series / opnsense newbie question DMZ NAT
August 21, 2021, 01:20:41 AM
Hi,
I was using different gear since the last 10 years and wanted to switch to opensource.
So I am familiar to general network stuff, linux and servers, but I am totaly confused, by the different
vocabs/meanings  :o. So far most things I allready figured out (VLANs/LAN/DHCP/...)

So most network parts are running  :D fine - Thank you opnsense Team!

But I couldn't get my DMZ setup running, searched the Internet and the forum but couldn't find an simple example that would fit. Guess I am just not seeing it.

I have one public IP 1.2.3.4 <-> opnsense with 5 nics, WAN, LAN1,LAN2,LAN3 and DMZ
the DMZ uses 10.0.10.1 there are 2 servers hosting 3 services

10.0.10.10 hosts 2 webservers
     Port 80 a.mydomain.com
     Port 88 b.mydomain.com

10.0.10.11 hosts 1 webserver
     port 8000 c.mydomain.com

I have absolutely no clue where to start, I tried to follow lots of tutorials but had no success.

I am unsure what NAT to use and in which field where to but what values.

Tried to make ALIASES for external IP, internal IP and the subdomains but failed.

Even if I get just one service back up running I would be glad :-)
best regards
Antonio