Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - MysteryIron

#1
High availability / Re: HA setup with no WAN CARP IP
December 09, 2025, 06:51:39 AM
Can we do something like this? I was able to get IP from my ISP to my virtual switch. But I am running into routing issues at my virtual switch.

[Modem] → hostpci0 (0000:06:00) → Virtual Switch VM
    ↓
[Virtual Switch bridges to two virtio NICs]
    ↓                           ↓
vtnet5 (opnsense1)         vtnet5 (opnsense2)
    ↓                           ↓
  [WAN]                       [WAN]

I was able to get opnsense1 as primary and opensense2 as backup. Failover etc all are working. My trouble is getting the routing done at Virtial Switch. I used Alpine Linux for my virtual switch.

All this on a Micro Firewall with 6 port - 2.5GB nics on motherboard / J6413 processor. I see CPU spiking up, but if this fix works, I won't mind throwing more cores to this.
#2
25.1, 25.4 Series / Vulnerability scanner
February 01, 2025, 02:45:08 AM
I was interested to check did I configure my opnsense correctly, so ran some port scanner from a pen-test tool website.

All good and some recommendations were given. Now I am wondering how to eliminate the information that permits the identification of software platform, tech, server os, http headers etc... Screenshot attached.

Any help appreciated.

#4
I am planning to switch to bridged mode for my nic. This definitely helps.
#5
Figured the answer is here.
https://forum.opnsense.org/index.php?topic=19948.0

Just run - /usr/local/opnsense/scripts/nginx/naxsi_rule_download.php from commandline as root.