Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - Lochkartenknipser

#1
The xxxxx are, of course, just placeholders. 
The OPNsense is connected as usual to a Vodafone cable connection without a Fritzbox. The external DNS is Vodafone, without a VPN or similar. This configuration is a test environment that had always worked up until version 26.1.8.
Unbound is used for internal DNS. The error first occurred after the update to 26.1.9. Among other things, OPNsense updates are tested in this test environment before they go into production. In production, there are OPNsense devices that establish 50 IPsec tunnels. If each tunnel generates 5 Phase 2 entries, we'll have to buy a 100-inch monitor.
I now suspect that after the update to 26.1.9, the DNS service starts up more slowly than StrongSwan, preventing the IPsec endpoints from being resolved.

Markus
#2
Hi,
I installed the update to 26.1.10 and checked the IPsec connection setup again after restarting OPNsense. The issue persists. When establishing the connection, the endpoints cannot be resolved by DNS, and I get 4 Phase 2 entries.

Is anyone else experiencing this problem?

Markus

2026-06-16T09:18:11 Informational charon 17[LIB1] resolving 'xxxxx-xxxxx.xxx4.net' failed: Name does not resolve (local address)
2026-06-16T09:18:11 Informational charon 17[LIB1] resolving 'firewall.xxxx.xxxx.de' failed: Name does not resolve (remote address)
#3
Hi,
your thin-provisioned SSD storage pool, is that a iscsi LUN or a DAS?

Because your problem sounds more like a SCSI error. 
I wouldn't use a PVSCSI controller for a VM like this; instead, I'd use a standard LSILogic SAS controller.
That's because a PVSCSI only really shows its speed when you have a huge amount of random I/O (e.g., HANA DB). But that's not the case here.
Why don't you set up a new OPNsense VM with an LSILogic controller and import the configuration (just to test whether your SCSI errors are gone)?

Markus
#4
Hi,
I took another closer look at the IPsec connection setup. When I have the 5 Phase 2 entries and deactivate and then re-establish the IPsec tunnel via "Connections," all the "Phase 2" and "SA" entries are normal. So there's only one entry, just as it should be.
When I restart the complete OPNsense, I get multiple "Phase 2" and "SA" entries (sometimes 2, sometimes 5 entries). When I look at the log, I find an entry stating that the domain cannot be resolved from the remote host (the local address and remote host are entered via DNS).

2026-06-15T11:44:12 Informational charon17[LIB1] resolving 'firewall.xxxxx-xxxxx.de' failed: Address family for hostname not supported(I have replaced the domain with xxxx).

When I look at the connection log in version 26.1.8, the remote host is resolved immediately and the IPsec tunnel is established right away.
In version 26.1.9, the remote host's domain is resolved with an error, and charon still attempts to establish the tunnel but without success. This results in an additional entry in Phase 2. The tunnel is then established correctly when the first data is sent through the tunnel.
Then another "Phase 2" is established.

Markus
#5
Hi,

After updating from 26.1.8 to 26.1.9, 5 Phase 2 connections are displayed for a single IPSec connection.

You cannot view this attachment.

Settings from Phase 2:

You cannot view this attachment.

The same applies to the SA database.
The SP database is normal, with one relationship for each source and destination.

In version 26.1.8, the relationships were unique and not listed multiple times.
Has something changed in version 26.1.9?

Markus
#6
German - Deutsch / Periodic Traffic Activity
May 25, 2026, 12:59:41 PM
Hallo zusammen,

ich bin auf der Suche nach einer Möglichkeit, Periodic Traffic zu monitoren.
Hintergrund ist das prüfen, ob Daten unkontrolliert abfliesen.

Ich habe das Plugin ntopng installiert. Damit ist das anscheinend möglich, aber nicht in der community edition. Ich sehe in ntopng eine Übersicht über Periodic Activity, kann aber nicht abfragen, was genau passiert (wer sendet oder empfängt). Geschweige denn einen Alarm darauf setzen.

Hat jemand eine andere Lösung für dieses Problem? oder wie kann ich ntopng entsprechend einstellen?
Ich möchte keine externe Infrastruktur aufbauen. Diese Anforderung sollte auf der OPNsense möglich sein.

OPNsense in der Version 26.1.8_5 auf einer Protectli VP6670
Installierte Plugins:
ntopng
redis
wazuh-agent

Grüße
Markus
#7
Hallo ManDal,
so wie sich das anhört, hast Du mehrere Netze über den IPsec-Tunnel geroutet? ist das richtig? wenn ja, prüfe die SAs auf beiden Seiten.
Normalerweise wenn ich VPN site to site IPsec-Tunnels aufbaue, setzte ich erst mal keine Firewallregeln. Denn dann siehts Du wie die Packete in der Firewall aufschlagen (z.B. Ping).
Du schreibst ja, daß der Tunnel stabil steht. Als nächstes müssen die SAs passen und dann noch schritt für schritt die Firewall Regeln setzten, dann passt das.

Grüße
Markus
#8
Hi Elleven,
den Squid produktiv einzusetzen ist ein schwieriges Thema. Wir setzen mehrere OPNsense mit Squid ein in der Konfiguration:
- Transparent
- SSL inspection
- filterung MIME-Types
- Virenscanner Schnittstelle ICAP
- UT1 Blocklisten
- Alias Ausnahmen
- SARG
Aber mit jedem Update der OPNsense ist fraglich ob der Proxy noch komplett funktioniert. Meistens gibt es Probleme. Fragen zu dem Thema werden meist nicht beantwortet.

Wir haben auf 5 Firewalls den Proxy aktuell deaktiviert, was ein sehr unzufriedener Zustand ist.
Mit der aktuellen Version 25.7.10 funktioniert die UT1 Liste über den Link: ftp://ftp.ut-capitole.fr/pub/reseau/cache/squidguard_contrib/blacklists.tar.gz aber die ausgewählten Kategorien werden mit "Apply" nicht übernommen. Nur ein Neustart des Squid-Services löst das Problem. Aber in der Zeit sind alle User Offline.
Aktuell setzen wir den Squid nur in unserer Testumgebung ein.
#9
Hi,

This workaround is only half the story. In version 25.7.3_7, the blocklist is downloaded after adding it, but the changes are only applied after the Squid service is restarted. Simply "Apply" or "Download ACLs and Applay" is not sufficient. Therefore, the Squid service must be restarted every time a change is made to the "Remote Access Control Lists."

Markus
#10
Hallo BüroMensch,

wie Patrick schon schreibt, gib mal ein paar mehr Informationen.
Denn eine 884VA kann eine Telekomversion sein oder Lancom normal. Gibt es auf der Lancom noch mehrere VPN-Tunnels? denn die Telekomversion kann nur 3 gleichzeitige IPSec-Tunnel (v1 oder v2). Ansonsten mußt Du eine Enterprice Option kaufen. Dann hast Du 5 gleichzeitige Tunnels.
Das einrichten eines IPsec-Tunnels (das ist das VPN, das die Lancom spricht) ist kein größeres Problem. Auf der Lancom den Tunnel mit den Lantools vorkonfigurieren und dann die Feinheiten anpassen. Auf der OPNsense den gegenpart konfigurieren und das wars. Firewallregeln nicht vergessen.

Grüße
Markus
#11
Las mal auf dem Win-Server ein Wireshark mitlaufen und schaue was wirklich passiert.

Gruß
Markus
#12
Hallo,
hat das Problem noch jemand?

Gruß
Markus
#13
Hallo,

ich habe unsere Test OPNsense von 25.1.7 auf 25.1.12 hochgehoben. In der OPNsense läuft der Squid Proxy mit der UT1 und MIME types.
In der 25.1.7 funktionieren die MIME types. Wenn ich ein Test .docx herunterlade wird dies geblockt. Entferne ich den MIME type, wird das .docx als virus erkannt (ist korrekt so, ist ein .docx mit eingebautem Testvirus).
Wenn ich die OPNsense nun update auf 25.1.12, wird das .docx immer über die MIME typs geblockt. selbst wenn ich den Eintrag in den MIME types lösche. Die Änderungen werden erst übernommen, wenn ich den Dienst (squid proxy) neu starte oder die gesamte OPNsense.
Wenn ich dann update auf 25.7 ist das Verhalten genau das selbe. Aber zusätzlich kann ich die UT1 nicht mehr herunterladen. Die Kategorien bleiben  leer.

Gruß
Markus
#14
German - Deutsch / Laden von Webseiten dauert lange
June 25, 2025, 11:58:39 AM
Hallo zusammen,
Ich habe eine Frage zum Squid-Proxy. OPNsense Version 25.1.5_5 auf einem Protectli VP2420.
Ich nutze den Squid-Proxy im transparenten Modus mit C-ICAP und ClamAV. Die UT1-Blockliste ist ebenfalls aktiv.
Bislang funktioniert alles einwandfrei. Allerdings habe ich das Problem, dass manche Webseiten bis zu 5 Minuten zum Öffnen brauchen.
Dazu gehört zum Beispiel die OPNsense-Forum-Website. Ich erhalte dann unten im Browser eine Meldung, z. B. ,,Suche use.fontawesome.com".
Auch wenn ich die Website mehrmals neu lade, öffnet sie sich.
Liegt das an den Einstellungen von Squid? Hat jemand einen Tip für mich?

Vielen Dank,
Markus
#15
Hello everyone,
I have a question about the Squid proxy. OPNsense version 25.1.5_5 on a Protectli VP2420.
I'm running the Squid proxy in transparent mode with C-ICAP and ClamAV. The UT1 blocklist is also active.
Everything's working fine so far. However, I'm having the problem that some websites take up to 5 minutes to open.
This includes the OPNsense forum website, for example. I then get a message at the bottom of the web browser, e.g., "Look up use.fontawesome.com."
If I reload the website several times, it opens.
Is this a setting issue in Squid?

Thank you very much
Markus