Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - evanevery

#1
I've been trying to find a portable 5G wifi hotspot router which will establish a VPN tunnel back to my network.  I have a couple of GL.inet devices but the only PORTABLE product I can find which provides BOTH 5G and OpenVPN is the Inseego M3000.  So I purchased one.

I've been banging away all morning on the OpenVPN config options and exporting OVPN config files but the M3000 just keep rejecting the config with "Invalid Configuration File" and a not-so-helpful "Please correct the issue" message while never specifically saying what it is unhappy about (and you have to have a valid VPN config BEFORE you can see the VPN log files...)  I've Googled a few OVPN settings the Inseego doesn't like and I've been monkeying around with those but no matter what I do, I can't get the config file(s) to be accepted.  I've sent a support request to them and am waiting to hear back.  While they post a support phone number, when you call it simply says to call your cellular ISP for assistance.  Nice!  I'm only guessing the amount of frustration I would be in for if I called my cellular provider to discuss an OpenVPN configuration back to my firewall...

Short of discussing all the details of what I have tried (somewhat blindly), I'm curious if anyone on the forum might have gotten an Inseego device to properly open an OpenVPN tunnel with an OpnSense router.  I've tried to minimize my configuration options as much as possible just to get a simple config file and connection up (cert elimination, etc), but no joy so far....

Anyone?
#2
I've been networking since the early 80's (inc installation of the second DEC SEAL firewall on the Internet).  I'm moving from a Watchguard M370 to an Deciso DEC3842 router/firewall at my home.  I was pretty comfortable with the watchguard configuration but I currently find some of the OPNSense workflow a little confusing.  I'm sure this will all pass with time.  Anyway...

Searched this forum (lots of good info), but I have a simple question which I'm losing in the details...

- I chose several Rule Sets to download/enable for IPS, and
- Wrapped them in a single policy with "Action = Alert, Drop" -> "New Action = Alert"

I monitored the alerts for a while and now I want to "promote" a single rule set to "Drop" ("ET open/emerging scan")

Would it be best practice to remove that one ruleset from my "Alert" policy (priority 1) and then simply add it to a new "Drop" policy (priority 0)?  I'm also guessing that a "DROP" action will also "Alert", right?

- As an alternative I see I can also click on the "Configured Action" and change it (from Alert to Drop) from an "Alert Info" dialog, would that be a preferred method (rather than creating a second policy)?