Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - Shild73

#1
Quote from: EricPerl on June 05, 2025, 11:02:24 PMOrgA (Right):
The FW icon is OPN, right?
 With 3 interfaces?
* WAN - 192.168.0.254/24
* LAN - 172.17.32.1/21
* KSPD_A - 10.62.65.254/24

Yes. this is an OPNsense.

The WAN is used to access the Internet. KSPD is a secure network with no Internet access. To access both networks from the same computer, I use a LAN with prescribed access to services via System: Routes

interface

Quote from: EricPerl on June 05, 2025, 11:02:24 PMOrgB (Left) has one interface KSPD_B - 10.62.70.254/24
Clarity was be improved if interfaces had different names in both orgs... We're looking at screens and it's not obvious which side they belong too.

coordinator

Quote from: EricPerl on June 05, 2025, 11:02:24 PMAnd then there's a machine in OrgA that's dual homed (on LAN & KSPD)???

I tried to register 172.17.39.13/21 and 10.62.65.13/24 on the same interface so that 10.65.70.59 would gain access to the server.
#2
Quote from: viragomann on June 05, 2025, 05:30:12 PMWhat we are seeing as blocked in the recent log is a obviously respond packet from 10.62.65.13. This means, that the request packet obviously didn't pass OPNsense.
So possibly it went directly from the KSPD to 10.62.65.13. But this machine used OPNsene as default gateway and hence sens packets destined to the other building to it.

Your network diagram shows that the KSPD has als an IP in 10.62.65.0/24. Naturally it sends packets destined to 10.62.65.13 directly to the device, but not to OPNsense.


Disabled the second interface on the server, which was directly connected to 10.62.65.0/24. Only Lan 172.17.39.13/21 remained + additionally registered 10.62.65.13 on the card.


Another log
#3
I started DHCP on KSPD and got this log

log
#4
Now incoming traffic from IP 10.62.70.59/24 has completely disappeared, there is only outgoing traffic.

this is the only thing that is recorded in the

log
#5
I'll try to fix the network now
#6
Organization A KSPD
gateway 10.62.65.254

Organization B KSPD
gateway 10.62.65.254

lan gateway 172.17.32.1


Both organizations use a coordinator to communicate with each other via the KSPD channel.
#7
Yes, I use natting the traffic so that the lan united one network.

I did as you said, but opnsense still blocks the connection.

KSPD
log
#8
Please tell me what rule and on what interface should there be so that 10.62.70.0/24 can interact with all other networks?
#9
Yes, I need to be able to connect from 10.62.70.10/24 to 10.62.65.0/24, and even better, I need the 172.17.32.0/21 network to also be able to interact with these networks.
#10
There is an organization network, everything works properly. The organization built another building. The networks are united using a secure channel (KSPD). The problem arose in that from the address 10.62.65.13 you can easily connect to 10.62.70.59, but on the contrary, opnsense blocks the connection. For the third day I cannot understand what this is connected with. Please help me solve the problem.

network diagram

lan

KSPD

log
#11
After switching to 25.1.6_4, the host names in Reporting: Traffic stopped being displayed. Previously, the developers implemented this moment. Can you tell me what could be the reason?

Realization
#13
I have installed updates, but there are a lot of errors in the log. Can someone remind me of the command to reinstall all packages?
#14
23.7 Legacy Series / Re: DNS doesn't work
September 22, 2023, 03:43:08 PM
I tried running Dnsmasq DNS, it still doesn't work. Unbound DNS changed the checkboxes in the main settings, the only thing I added was static host.
#15
23.7 Legacy Series / DNS doesn't work
September 22, 2023, 12:35:10 PM
I configure Unbound DNS, as soon as I turn it on, the Internet disappears. I turn it off, everything works, but there is a need to do static redirection. I ask for help with tinctures. In System: Settings: General DNS registered.
Settings DNS https://drive.google.com/file/d/1N9svEjDOTv0CjWui9nLNxqSgHZuK-vt4/view?usp=sharing
Settings LAN https://drive.google.com/file/d/1rMEMERUe1lGS89yDzX5esgtpk_6EO0Xq/view?usp=sharing