Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - Loïc_bzh

#1
Quote from: ceeeeej on March 08, 2025, 12:56:41 AMI have OPNSense setup with Adguard Home and Unbound with DNS over TLS.

I was having some trouble getting the Caddy access lists working to restrict some services to my LAN IPs only. To get this all working I had to setup overrides in Unbound that point these URLs back to my Caddy when on my LAN. i.e. I setup example.website.com in Caddy and then in Unbound I had to setup an override to point this URL back to 192.168.1.1 (where Caddy is running on my opnsense router).

My assumption was that because they were encrypted with DNS over TLS that the Caddy reverse proxy can't intercept them?

Just posting in case anyone has feedback or other ideas here. I was hoping to not require setting these up but it works now.

Hello

You may no longer be concerned about this, but it could help others in the future.

When using AdGuard with DNS over TLS and LAN IP only, you need to use the DNS rewrite of AdGuard.

Go to AdGuard then menu Filter > DNS rewrite > Add DNS rewrite.
For "domain name or wildcard", I specified *.mydomain.tld
For "Enter IP address or domaine name", I specified the IP address of Caddy host so OPNSense IP address.
#2
Patch available from the GitHub issue :

opnsense-patch -c plugins -a kulikov-a cfbe14d
#3
Quote from: ethanvos on September 24, 2025, 04:08:07 AMI have opened a bug report on GitHub for this issue, which includes a little more information as to the nature of the bug.
https://github.com/opnsense/plugins/issues/4953

Thank you! I was going to open the ticket this morning, but you were quicker. :)
#4
Hello,

I would like to implement a WAF with Nginx, but when I click on "Download" to import the NAXSI core rules on "HTTP's=> Naxsi WAF policy" tab, nothing happens and after a few seconds, I get this error from the crash reporter of OPNsense :

PHP Fatal error:  Allowed memory size of 8589934592 bytes exhausted (tried to allocate 8579452928 bytes) in /usr/local/opnsense/scripts/nginx/naxsi_rule_download.php on line 172
For the above error, the memory_limit from /usr/local/opnsense/service/templates/OPNsense/WebGui/php.ini was set to 8G. I had the same error with the original limit set to 1G.

System info:
FreeBSD 14.3-RELEASE-p2 stable/25.7-n271676-ab2281de1853 SMP amd64
OPNsense 25.7.3_7 13101bd9a
Plugins os-acme-client-4.10 os-adguardhome-maxit-1.15 os-ddclient-1.27_4 os-nginx-1.35
OpenSSL 3.0.17
Python 3.11.13
PHP 8.3.25

Thank you for your help.