Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - kermitxyz

#1
Changing from the on-board NIC (Fujitsu S920) to another network port in the router seems to have resolved the issue.  The router and switch indeed couldn't auto-negotiate.  Perhaps a driver issue?
#2
Quote from: ludarkstar99 on December 12, 2024, 02:43:24 AMAlso, make sure there's a firewall rule in LAN interface, on top of the list, allowing the lan subnet (source) to the modem address (destination), without force any gateway or gateway group - just leave default.
Since you said "also" do I need to do both this and the other suggestion?  I am struggling with this now!
#3
Note - if I disable the fibre (default) gateway, I can then ping both 192.168.100.100 (the address of the 4G interface) and 192.168.100.254 (the address of the 4G modem).  It is just when the preferred gateway is working that I can no longer ping these IPs.

This is not a major problem, but it would be useful to be able to access the 4G modem via web.

#4
Quote from: Patrick M. Hausen on December 11, 2024, 11:38:40 PMAdd an outbound NAT rule on that particular interface.
As in Firewall > NAT > Outbound ?

Changed Modem to Hybrid (auto after manual rules)

I have created rule:

Interface: LAN
Destination address 192.168.100.254/32
Translation/target : 4G_IF_Address (i.e. the 4G modem interface)

But this does not help.
#5
I have created a failover group and all works fine, but I cannot access the configuration page of the 4G modem

The LAN address is 192.168.123.0

The modem is attached to one of the router interfaces with static IP 192.168.100.100  and the modem has static IP 192.168.100.254

Under System: Gateways: Configuration  The 4G gateway has IP 192.168.100.254

Ping monitoring works, failover works, and I CAN ping 192.168.100.254 from an SSH session to the router.  However, I can't ping it from my desktops

What do I need to do to fix this?  I wondered about adding a route in system  > routes but it says "Do not enter static routes for networks assigned on any interface of this firewall"

Any advice most welcome 
#6
General Discussion / Re: Failover to 4G
December 09, 2024, 10:51:18 PM
Anyone ??  :)
#7
General Discussion / Re: Local DNS
December 08, 2024, 11:23:18 PM
Hi Patrick

That works fine - thank you. 

For future reference if anyone else reads this post, I did have to restart the router after making the changes (restarting the service alone for some reason was not enough)

Cheers
Richard
#8
General Discussion / Re: Local DNS
December 08, 2024, 12:16:36 AM
So if I want "dev" to resolve to 192.168.123.123

I use * as the host and "dev" as the domain?

It works, but is that right?  I am not convinced I've done that properly.
#9
General Discussion / Re: Local DNS
December 07, 2024, 10:26:24 PM
Thanks, I'll check that.  Which is the better way though?
#10
General Discussion / Local DNS
December 07, 2024, 10:12:04 PM

I wish to have the OPNSense router enable DNS resolution for local hosts.  I can see two ways:

1. Use UnboundDNS and enable "Register DHCP Static Mappings"

2. Disable UnboundDNS and use DNSMasq instead.  I think the latter is better as I can then add other static hostnames other than those assigned by DHCP.

Is this the best way?

I am enjoying learning OPNSense so thank you for the help ;)
#11
General Discussion / Failover to 4G
December 07, 2024, 10:09:49 PM
Aim - Fibre failover to 4G if fibre fails

I can see two ways:

1. Have both as a gateway, but with different priorities
2. Use the Gateways > groups option

Which is better practice? 

Secondly...

On OpenWRT the 4G router was connected to the multiple port network card in the router and on a different subnet.   

With OPNSense, should I do the same (although I am not sure *how* yet) or should I just give the 4G router an IP address on the same subnet, connect it to my switch itself and create an interface with that IP address?

thank you for any advice :)
#12
A re-install of OPNSense fixed the issue.

Just for completeness, the only explanation of which I can think is that the router and switch were struggling to auto-negotiate on the port and a reboot of the switch somehow fixed that.  I recall a similar incident nearly twenty years ago when trying to get some PCs to connect to a Cisco switch.  We just couldn't work out why certain machine didn't work until enabling portfast on the ports in question.

If anyone can think of any other possible reasons I remain curious....
#13
Thanks for the help all.

Re-installing OPNSense today and being a little more confident has fixed all the issues.  I'm sure I'll be along again soon with more questions as I delve deeper and try to learn more.

Cheers
Richard
#14


I have just changed my main router to OPNSense on a new x86 device.  After rebooting the opensense router, I can't get any response (ping/GUI) from the OPNSense device unless I reset the switch on my network core.  Once the switch reboots, all is well (can access the router and WAN interface comes up)

My first thought was some MAC / ARP issue, but having power-cycled the whole core the problem persists.

I know this is odd - does anyone have any thoughts?
#15
Hello everyone!

My first post here.

Until now, I have been running two OpenWRT devices - one as main router and one as WiFi access point.  I configured the access point to use the IP of the main router as it's gateway, and all was well (main router also providing DHCP for clients)

I have now replaced the Main Internet router with OPNSense.  However, this setup no longer works.  So, I have two questions:

1. Is this by design, to stop some creating a rogue WiFi access point (makes sense)

2. What do I need to do to get this working?  (I *can* ping the AP from my desktop, but *can't* ping it from inside OPNSense - SSH session etc. and vice-versa)

I have a fairly good grasp of networking but am new to OPNSense (which I am trying as I read it is far superior to OpenWRT... perhaps that's another discussion entirely  ;)

Thanks
Richard