Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - kohly

#1
Hi,

after upgrading both of our HA firewalls to OPNsense 26.7.1 we observed an issue with the CrowdSec remediation component.

When Enable Remediation Component (IPS) is enabled, a large amount of legitimate traffic is blocked by the automatically created CrowdSec (IPv4) firewall rules. This affects both inbound and outbound connections. Among others, we observed failures with WireGuard, Wazuh agents, MeshCentral agents and normal HTTPS traffic.

The firewall log contains entries such as:

  • CrowdSec (IPv4) in
  • CrowdSec (IPv4) out

Disabling only Enable Remediation Component (IPS) immediately restores normal operation. The CrowdSec agent, log processor (IDS) and LAPI can remain enabled without any issues.

We also tested allowlisting the firewall's own WAN/CARP addresses, but this did not change the behaviour.

At the moment the only usable workaround is to leave the remediation component disabled.

If there is any additional information or debugging output that would be helpful, I would be happy to provide it.

Best regards
kohly
#2
German - Deutsch / gelöscht
March 10, 2025, 02:37:16 PM
wegen desinteresse gelöscht
#3
this resolves the issue!

8)
#4
German - Deutsch / Re: kein Graph für CPU im Dashboard
September 26, 2024, 06:12:35 PM
x86-64-v2-AES (default)
identisch zu den anderen instanzen
#5
German - Deutsch / kein Graph für CPU im Dashboard
September 26, 2024, 04:54:59 PM
Hallo,

ich habe zwei OPNsense im Cluster als VM unter Proxmox die, im Gegensatz zu anderen Instanzen mit ähnlichem/gleichem Setup, im Dashboard keinen Graphen für CPU anzeigen. OS/Browser sind dabei nicht entscheidend.

Unterschied: die 'gegensätzlichen Instanzen' wurden mit dem neueren ISO 24.x installiert, die beiden 'fehlerhaften' mit dem älteren 23.x.

Wonach könnte ich suchen wollen?

Bin für jede Hilfe dankbar!

VG
kohly
#6
Quote from: Bob.Dig on May 29, 2024, 07:55:54 PM
Quote from: kohly on May 29, 2024, 04:23:03 PM
What can i do?
Use the latest nano image and don't select the mirror yourself.

found the nano image and was able to deploy it on oci.
what kind of ease!
#7
solved the problem: just not install ca_root_nss
BR
Christian
#8
Quote from: Bob.Dig on May 29, 2024, 07:55:54 PM
Use the latest nano image and don't select the mirror yourself.

Thank you for your response.

I found a 13.1 image at ftp-archive.freebsd.org and will try again with this one.

BR
Christian
#9
Hi!

I like to give this torial a try but it seems the version 13.1 of FreeBSD is no more available.
So i used 13.2 instead.
I was able to dd the image to the disk, also the reboot to FreeBSD works like a charm.

When i execute the opnsense-bootstrap.sh.in i get the error that ca_root_nss is already unlocket.
Then the script ends.

What can i do?

BR
Christian