Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - appasquatic

#1
Found my issue, and my configuration of Caddy is absolved of guilt in the end. A Destination NAT rule was set to "Manual", instead of "Register Rule." Once that was fixed, everything with 26.7 worked for me :o)

Many thanks for your help!
#2
Many thanks! Will try it!
#3
Hi Guys,

I wonder if I might ask for some help?

I run a mail server behind a Caddy reverse proxy which is hosted on a DEC850 device running opnsense 26.1.8_5. Today, I upgraded firmware to opnsense 26.7, and the experience was great, and everything appeared to be working, except the 3rd party plugin for Caddy.

The Outbound NAT configuration carried over perfectly from the upgrade, and from what I could see, so did all of the firewall rules. I've attached the Caddy file for inspection (although it does appear that I'm bullying Caddy, it's the proxying of HTTP and HTTPS ports that stopped working, so my suspicions are aroused. I've watched Poirot, so I've some idea how to pursue a thread, but not the slightest idea how to fix it).

Is there anything easy that you think I might be missing? If so, though lacking professional expertise, I have the vigor of an enthusiast, so I'm ready to try anything I can understand or research.

(I've temporarily rolled back for now, but I'm learning about a work-around whereby I might proxy the HTTPS port via Caddy hosted on Kubernetes on the email server host).

Again, very pleased with the upgrade, but I've just this one sticking point where I think I may have tied myself in knots. Any help appreciated. I'll supply any relevant info. Not to worry if it's too much a pain, since I can always run with my Plan B and upgrade to the latest opnsense anyway.

Thanks again for your time, and great work on the firmware.
 
#4
Wow, that was fast!

Many thanks, working now! :o)
#5
Me too, unfortunately.

I didn't try to register a new API Key license yet, but it sounds like it would not solve the issue.

I don't know how to test if it is an plugin issue, or something else. Any ideas?
#6
24.7, 24.10 Legacy Series / Re: Unbound issues....
November 20, 2024, 11:30:41 AM
Did you change the listening port to 5353 because you want to run DoT locally?
#7
You're absolutely right about QUAD9 suggesting opnsense disable DNSSEC support, I stand corrected. I do wonder that the pihole/opnsense interaction suffers from the same issue?
Personally, I do not use DNS forwarding or pihole for DNS blacklisting, but use Unbound as the recursive resolver and host for the DNS blacklists. Would this not work for your setup as well?
#8
I'm not sure, but from your explanation, it almost seems you are describing an issue with pihole's DNSSEC support, rather than an issue with opnsense. Does DNSSEC work when you forward to (say) QUAD9?
#9
24.7, 24.10 Legacy Series / Re: Some bug and i cant boot
November 09, 2024, 02:49:14 PM
If you have a configuration backup file, you can make a bootable USB from the OPNSense website: Support-->Documentation.
If you don't have a backup, I'm not sure what you can do but re-initialise and configure your system from scratch.
If you can get to the Console, then you might have a shot at restoring from an older snapshot, but from the image you've posted, I'm not certain your box is booting that far?
Sorry I can't assist more, I'm a Newbie at Opnsense. Perhaps some of the Gurus on this forum can assist where my knowledge stops?
#10
Hi Snuffy2,


I'm a Newbie to Opnsense myself. I've recently performed the same operation as yourself (migrating from ISC to KEA) but without the issue you're facing. Two questions for you:

  • When on the Settings page of KEA, did you tick all the relevant interfaces that you'd like to serve DHCP for?
  • When on the Settings page of KEA, did you tick the Firewalls Rules checkbox?

I'll take another look later, but that's all I've got for now. KEA pretty much set itself up for me when I followed the tutorial, so I can't help too much. Maybe the experts who have been using Opnsense for year will chime in when they've a moment to spare? 

Hope this helps  :)