Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - dbots

#1
Quote from: CJ on July 18, 2023, 02:23:35 PM
It seems like you're a bit out of your depth network wise and that this is for a business?  I would recommend you either hire a Network Admin consultant or pick up an OPNSense support contract to help you get this set up.
Thanks.
OK, but I cannot understand how you make this conclusion. Before a while, you suggested to use as gateway an IP address that does not belong in the subnet of the IP address of a terminal.
I am not an expert but on the other hand I don't expect that to be such a difficult problem that would need a network admin to be hired. I think that it's some setting that I cannot find.

Anyway, if someone else has any solution or suggestion, please send.
#2
Quote from: CJ on July 18, 2023, 02:03:10 PM
Set the phone GW to 192.168.1.254
I tried it on my Windows laptop - not working. There is a warning about different subnets.
I also tried to set (on OPNsense) the gateway of IP alias 192.168.20.254 to 192.168.1.254. Still not working.

Quote from: CJ on July 18, 2023, 02:03:10 PM
Another solution would be for you to change the subnet for your LAN to something larger than /24 if all you need is more IPs.
We don't want this - Need to have different subnet.

Thank you
#3
Quote from: CJ on July 18, 2023, 01:56:32 PM
You didn't answer all of my questions.
Quote from: CJ on July 18, 2023, 01:46:11 PM
What does the full phone network config show?
IP:192.168.20.30, subnet:255.255.255.0, gateway: 192.168.20.254 (but not working)

Quote from: CJ on July 18, 2023, 01:46:11 PM
Do you have different filtering requirements for the phones, PBX, and other computers?
No
#4
Quote from: bartjsmit on July 18, 2023, 01:44:45 PM
Assuming you're using WiFi for the phones and not OTG Ethernet, you set the VLAN on the AP's. Either by using multi-SSID or plugging them into a switch port with an untagged VLAN.
Generally though, you should create NAT and access rules for your second subnet to connect to the internet if that's what you want. Unlike LAN, there are no default policies for additional networks.
Bart...
Thank you for replying, from what I understand, if I use VLAN the problem is (since it would be tagged due to OPNsense) there is no way to set the tag on my mobile devices (smartphones).
That's why I would like something simpler, for example just to use the first solution I described with the IP alias but to be able to set it as gateway so that smartphones get online.
#5
Quote from: CJ on July 18, 2023, 01:46:11 PM
What do you mean you added a second LAN without any serious assignment?
What does the full phone network config show?
Do you have different filtering requirements for the phones, PBX, and other computers?
I mean that I did not make any settings on OPNsense and did not create any network. I simply set devices using a subnet (192.168.20.0/24) and since the Asterisk PBX had also an alias in that subnet, it works.
But there is no gateway defined.
Is there a way to use the IP alias set on the OPNsense system (192.168.20.254) as a gateway for LAN2 ?
It's not in interface list so could not choose it.
#6
General Discussion / Question for second network
July 18, 2023, 01:32:11 PM
Hi all,
I am trying to find a solution to the following but without results so please allow me to post the problem:
I have a LAN 192.168.1.0/24 with GW:192.168.1.254 working fine.
There is an Asterisk PBX (192.168.1.200) in that LAN (LAN1) with about 30 phone devices. For phone devices we use Android smartphones running VoIP software (without SIM card). We use smartphones because they are cheap and don't require a static position in the area of the company.
We decided to move the phones from LAN1 in another network in order to free IP addresses.
So, we somehow added a second LAN (LAN2) but without any serious assignment.
I mean we simply added an alias second IP address (192.168.20.200) on the NIC of Asterisk system and on all phones we added static IP from 192.168.20.21 to 192.168.20.50 using IP 192.168.20.200 to find the Aasterisk server.
Everything works fine regarding calls, but now smartphones don't have access to internet.
I tried to create an alias IP on OPNsense (192.168.20.254) but don't know how and if it's possible to use it as gateway so that I set it as gateway on the phones.
I tried to set 192.168.20.0/24 as a VLAN but then we had a problem on the smartphones because the VLAN must be tagged on OPNsense but smartphones do not have such option.
Please reply with any suggestions.
Thank you.
#7
1G internet bandwidth, IDS/IPS throughput not metered, let's say something usual, VPN connections are handled by other system. Thank you.
#8
I mean WAN failover = at least 3 NICs
#9
Thank you. Anyone else that could write his suggestion based on similar experience in enterprise use cases please ?
#10
Thank you for the information, I am aware that I can order ready appliances with excellent hardware but I would like to try and use hardware like what I described. Would it possible to have hardware description for that please ?
Thank you in advance.
#11
Hi all, I would like your opinion about a setup I want to implement.
Our company offices has about 100 users. I want to setup an OPNsense system with all needed configurations such as IDS/IPS, web filtering and failover. Could you please suggest something like a 1U hardware or a mini PC like Dell Vostro ? Would an i5 or i7 be fine ? I would be grateful for any other additional information.
Thank you.