Same here. It started happening when my paid subscription ended a few days ago.
This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.
Show posts MenuQuote from: wirefall on October 27, 2024, 11:23:30 AM
I think I had this problem, too. Right after 24.7.7 update WG stops to work. I always saw a 124kb received from WG/OPNsense (e.g. on my iPhone), then it stops.
However, after some restarts this problem is just gone. WG works as expected and I haven't touched anything. Strange.
See here: https://forum.opnsense.org/index.php?topic=43653.0
So maybe it is not related to Zenarmor?
Quote from: Taunt9930 on October 25, 2024, 11:17:22 PM
Did you send feedback/logs to Sunneyvalley through the UI? Have you had any feedback from them?
Quote from: zzup on July 24, 2024, 08:44:58 AMQuote from: ruuskil on July 24, 2024, 07:28:13 AMQuote from: zzup on July 24, 2024, 05:14:23 AM
On a side note. Any reason to run CrowdSec and zenarmor together? I always thought they did the same thing. (still learning some of this as it is a hobby).
I'm doing it and it works without any issues. It does give extra layer of security especially if you run servers.
Do you run it to protect the lan or wan side? I have not really looked into it much as i though that zenarmor covered it. But if it helps the wan side as i use quite a bit of port forwarding that would be great. And if it does not mess with zenarmor that is a must. Which sounds like it doesn't based on your comment.
Quote from: zzup on July 24, 2024, 05:14:23 AM
On a side note. Any reason to run CrowdSec and zenarmor together? I always thought they did the same thing. (still learning some of this as it is a hobby).
Quote from: knight2f6 on January 06, 2023, 02:13:02 AMBecause you can't run zenarmor and suricata on the same interface, that's why. Maybe in the future it's possible but not today.
why would anyone want to run an IDS on the WAN interface? beside for documenting who wanted to get into your network.
Quote from: knight2f6 on January 06, 2023, 02:13:02 AMFW only checks what ports are allowed to transmit/receive traffic. IPS is there to stop the actual attack on those ports. It can do this while running on either LAN or WAN interface.
the reason for having a FW is to stop attacks and for IDS/IPS to tell you who made it through so you can do something about it.
Quote from: knight2f6 on January 06, 2023, 02:13:02 AM
I have no doubt that there are 1000s of 1000s of attach on the other side of the fw. if you ran an IDS on the WAN side you would be overwhelmed by alerts.
my 2 cents.
Quote from: knight2f6 on January 04, 2023, 07:30:40 PM
I might have figured it out. I am running Zenarmor which binds to the same interface. I "believe" that Zenarmor is receiving the packets and does not forward it to the next module, Suricata. I suspect that if I uninstall Zenarmor then Suricata would start working. I say suspect, because I decided I rather keep Zenarmor and use that and did not want to go through uninstalling it to test the hypothesis. So, if you have other solutions that bid to your interface, try removing them and see if Suricata can work as a standalone module that has control of the interface.
good luck.