Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - lmgmelim

#1
hey

We want to put 2 OPENSENSE firewalls woking with High Avaibaility (same public IP.). Behind, we have 2 switches (2 SPINE Switches).

From my understanting, OPENSENSE HA works as Active\Master (not a CLUSTER), but my 2 SPINE switches work as ACTIVE\ACTIVE

Can i connect the first switch directly do the first OPENSENSE and the second switch to the second OPENSENSE? it wiil work since theres is only one ACTIVE NODE on the firewall side? What is the best way to connect 2 firewalls and 2 switches in my scenario?
#2
General Discussion / GEO IPs
July 05, 2024, 12:12:06 AM
HELLO

GEO IPs I have been struggling to allow port forward rule just from one country like SPAIN and not allowing for the rest of the world. I have beed using GEO IP from the ALIAS following the link below

https://techlabs.blog/categories/opnsense/set-up-maxmind-geoip-blocking-in-opnsense

Any idea ?
#3
General Discussion / WAN losing IP
July 04, 2024, 11:35:05 PM

hey
My WAN interface every 2 or 3 days loses the public IP.
When this happens i have to disable\enable WAN interface to get the public wich is the same it was before.
Firmware is updated to the last version
Any idea ?

thanks
#4
General Discussion / Use VRFs
May 17, 2024, 12:12:45 AM
Hey

im configure VRFs and VXLANs on CISCO switch in order to isolate my networks.
I have opense as FIREWALL.
Does anybody knows if the OPENSENSE supports VRFs  in order to give internet to those internal networks? and if not...what is the best way to configure OPENSESENSE for this scenario?

Thanks
«
#5
High availability / HA with two switch core
April 28, 2024, 03:55:40 AM

Hey
im setting up a HA scenario with one ISP conecting to both WAN Interfaces of OPENSENSE (ETH01). I need to connect two LAN ports of each opensense to each switch core (i have two switch core with MCLAG).
Should i use BRIDGE interfaces in order to make two physical interfaces on each PFSENSE, act as one, being able to connect to each switch to both firewalls? what is the best for my scenario?