Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - Stephan M.

#1
Hi everyone,

I'm reaching out because I'm facing an issue with OPNcentral. First, a bit of background.

We have 12 Deciso firewalls that we want to manage centrally. To achieve this, we spent a significant amount of time evaluating OPNsense and built a separate lab environment where we recreated and tested nearly every scenario we could think of. The testing was extensive, we learned a lot, and we were able to implement the environment exactly as intended in the lab.

We then started deploying everything in production. All the knowledge we gained from the lab was incorporated into the rollout, and the deployment is in progress.

We now have a dedicated management appliance, ofm01 (DEC-2770), which is used exclusively for centralized management. It is properly licensed, has only a single active interface configured with the LAN address 10.18.23.250/21, and the WebGUI port has been changed to 4444. Appropriate firewall rules (NEW) have been created to allow the required communication. According to the live firewall log, however, the Anti-Lockout rule is handling the traffic. Additionally, LDAPS is configured successfully, and OPNcentral has been set up according to the documentation, except for certificate distribution. Certificate validation is currently disabled (the corresponding checkbox is unchecked).

We also have two firewalls (DEC-4280) also properly licensed, fw03 (10.18.23.251) and fw04 (10.18.23.252), which are fully configured as well. They are accessible via https://10.18.23.251:4444/ (and the corresponding address for fw04). All three systems have been configured successfully. Both firewalls are running in an HA configuration and synchronize successfully via a scheduled cron job. At this point, all three systems are running Business Edition 26.4.

The hosts were added to OPNcentral, and centralized provisioning worked flawlessly for several weeks—until about four weeks ago, just before I went on vacation. After I returned (and nobody had made any changes in the meantime), OPNcentral was no longer able to communicate with the managed hosts. Every connection attempt now times out, and I only receive a cURL error 28 after 20 seconds. As a result, centralized firewall rule management—the primary feature we intend to use—is no longer possible.

Here are the troubleshooting steps I've already performed:

* All firewalls are directly accessible WebGUI from using the configured URL from OPNcentral without any issues.
* I successfully tested ICMP connectivity using the Diagnostics tools between ofm01 and fw03, as well as between ofm01 and fw04. Both tests completed without packet loss.
* For troubleshooting purposes, there are currently permissive ANY firewall rules in place, allowing traffic from any source via any protocol to This Firewall on any port.
* I generated a new API key for the existing OPNcentral API user — no change.
* I created a completely new API user along with a new API key — also no change.
* I updated all three systems to Business Edition 26.4.1p2 (current patch level) and rebooted them.

None of these measures made any difference.

I've spent several days trying to identify the root cause, but without success. In our lab environment, the exact same OPNcentral setup—with the same IP addresses and configuration—has been working flawlessly for many weeks. Unfortunately, I can't get the production environment working again.

I'm hoping someone here may have an idea or can point me in the right direction.

Thank you very much in advance!


Best regards,

Stephan M.