Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - jt-socal

#1
Seemed like a wireguard issue to me.  Wireguard was unresponsive to web interface changes, the latest handshake on dashboard was blank, the "VPN/Wireguard/Diagnotics" was blank.  As another possible hint, I was getting errors under Dashboard, Interface Statistic, Road_Warrior; those are not happening anymore. 

Hope that helps, thanks for the great software,JT
#2
Worked, everything back to normal.
#3
Any test I should run to debug whatt is going on to see if some in upgrade script can be improved?

Everything is working great, except wireguard.

I restored my config from backup, so I have all interfaces and gateways back. 

I'll fresh install 24.1 shortly and restore setting from backup again.
#4
I upgraded to 24.1.  I had a road_warrior setup and two outgoing wireguard VPNs with policy based routing.  Everything has been working for years before the upgrade, but nothing works since. 

I ended up removing gateways and interfaces and removing all wireguard instances and peers.  I now cannot even create an interface without manually creating my own keys via console commands wg genpsk and wg genkey.  The gear button for "Generate New Keypair" does not work. 

I then create a peer and add it.  Then I go to interfaces, assignments, select wg1 click add and get, "The following input errors were detected:The interface "wg1" does not exist. Make sure to apply its configuration first."  So I go back to wireguard and try disabling all and enabling all again, but error repeats.
Is there something obvious I am doing wrong or any suggestions to get wireguard to work again? 

Also, when I go to the dashboard, it says, "No WireGuard instance defined or enabled."  But there is one defined and enabled.
Suggestions please. 
#5
I have this or similar problem too.  My post was here:  https://forum.opnsense.org/index.php?topic=36942.msg180942 

There is a suggestion to diagnose there, but I have not had time to do that yet.
#6
23.7 Legacy Series / Re: Outbound Nat on WG Tunnels
November 14, 2023, 01:28:00 AM
I don't think it is related, but how do I test?
#7
Any help or suggestions for your troubled friend here?   :-[ :'(
#8
Ugh, that was it, apologies. 
#9
On Firefox, http://router/ui/diagnostics/firewall/statistics#info does not work correctly.  Looks fine on Chrome.
#10
23.7 Legacy Series / Router Not Always Able to Access LAN
November 11, 2023, 02:16:42 PM
I found this as my router's git backup keeps failing.  It has been happening since 27.7 and same problem exists in 27.7.8.  (Note: could be me)

My router is mostly unable to connect via TCP to my LANs.  In other words, the GIT backup works sometimes, but mostly not.

To confirm it is not some firewall rule, I created a first firewall rule in my floating rules to allow any direction on any interface the network on a relevant LAN.  I enabled logging and the rule is hit, but cannot access the LAN.  I confirmed same problem on another LAN (a vLAN) and same problem.  I am able to connect from one lan to the other no problem.  I am able to PING from the router to the same LAN ip no problem.

Suggestions please. 
#11
Try going into Firewall, NAT, Outbound and hit save.  I have a similar problem. 
#12
23.7 Legacy Series / Outbound Nat on WG Tunnels
November 11, 2023, 01:50:04 PM
Since I believe 27.7.7, my wireguard tunnels do not work on reboot until I go into GUI/Firewall/NAT/Outbound and hit Save.  I have "Hybrid outbound NAT rule generation" selected by no manual rules

I figured 27.7.8 would fix, but does not.  Maybe it is me though too.

Suggestions, please. 
#13
I am not using Suricata and have an unstable WAN interface (dmesg above).  I'm not certain my issue is the same, but the unstable interface is new and not seeing complaints of similar issues in the dslreports forum for my ISP.

I am now getting this new messages in dmesg
arpresolve: can't allocate llinfo for redacted on ixl0
arpresolve: can't allocate llinfo for redacted on ixl0
#14
I'm also having problems with WAN link going down and up.  This has not happened in the past, though I cannot be certain it is not my ISP.  dmesg attached