Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - NopSled

#1
Zenarmor (Sensei) / Re: Zenarmor on the DEC850
September 15, 2023, 03:48:29 PM
Hi Sy -

Thanks for the reply. I haven't actually purchased the DEC 850 yet.  I am currently running ZA on a Protectli box with no throughput issues at all and wanted to have a good feeling for there not being issues on the 850 before I purchased it.

Thanks!
#2
Zenarmor (Sensei) / Zenarmor on the DEC850
September 15, 2023, 02:39:20 PM
Hello All -

I'm considering upgrading to the DEC850. I know some people think it is crazy to pay that much for hardware when you can build something a lot cheaper, but I see the purchase as a way to support the project. I also like the form factor, passive cooling, SFP+ and low power specs. Anyway, I wanted to see if other users that had any issues with Zenarmor running on the DEC850 platform? Just wanted to check before making that significant investment in an appliance. I've tried ZA on various hardware platforms in the past year, but ran into several random issues with the netmap driver on those platforms. Trying to play it safe and do my homework first.

Thanks!!
#3
My problem is corrected. I submitted a bug report to Zenarmor via the app and they were pretty responsive in seeing what the issue was. While everything on my appliance was working fine, I had modified my web gui port to something other than 80 or 443. They released ver 1.14.3 which corrected the issue. With that fix, the appliance now connects to the cloud console with no issues.

I had various random issues with another platform I attempted to run Zenarmor on, but it runs well on the Protectli VP4650.
#4
Hello Everyone -

I'm running the most recent version of ZA with a Home license. I have been unable to get my instance to register to the cloud portal. When attempting to connect, I get the following message: "We could not communicate connect operation to your device. It might be possible that your device is not reachable at the moment." The appliance is online with good WAN connectivity. Everything appears to be good there. I uninstalled / reinstalled ZA, but get the same results. ZA appears to be working otherwise. Not really sure how to troubleshoot this. Has anyone run into this issue before?

I'm currently running OPNSense 23.7.1_3 on a ProtectLi VP4650 and have no other issues otherwise.

Thanks!
#5
Sorry for the delayed response Sy.

I just loaded Zenarmor to a spare appliance that I have here and it now appears to work correctly blocking social media sites from the web settings portion of the policy. I did notice that I am still able to however get to one of the social media sites (Instagram) with the app on my cell phone. The difference between the two configurations are that the other box I had it installed on was using a single trunked interface with 3 VLANs (only the parent interface selected) and this box has discreet interfaces. I will reload to the other appliance and send the logs via the GUI tomorrow when I can take the other box out of service to reconfigure.

Thanks!
#6
Hello All -

Recent convert from the "other" sense platform to OPNsense. After installing Zenarmor (Home License) and configuring my first policy, I disabled Instagram within the applications. In the report, I see entries in red showing that it was supposedly blocked, but I am still able to get to the site on the web as well as use the app on my cell phone. I am currently running in "Routed Mode (L3 Mode, Reporting + Blocking) with native netmap driver". Wasn't sure how the blocking actually worked or if I missed something possibly. I do have a PiHole running on the network. I saw in the documentation that PiHole could run in parallel with Zenarmor so long as caching is disabled. Would having a PiHole w/unbound DNS running on the network cause issues with the application blocking?

Edit: Since I point clients to PiHole via DHCP, I pointed my machine to use the default resolver on OPNsense instead and got the same result.

Thanks!