OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • Profile of tigs »
  • Show Posts »
  • Messages
  • Profile Info
    • Summary
    • Show Stats
    • Show Posts...
      • Messages
      • Topics
      • Attachments

Show Posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

  • Messages
  • Topics
  • Attachments

Messages - tigs

Pages: [1]
1
Virtual private networks / Can I setup the opnsense box as an IPsec vpn client?
« on: January 04, 2021, 09:23:33 pm »
I have been trying to play with IPsec server on an AWS. I have setup an IPsec server, and I am able to configure my desktop PC (win 10) or synology NAS to connect to it without any issues. However, I would like to connect my opnsense box to it so all local devices go through the same tunnel without having to configure them individually. I want my opnsense box work the same way as it does as an openVPN client. Can I accomplish this, configuring the opnsense as an Ipsec client?

I have the following info available and nothing more:
Server IP:
IPsec PSK:
Username:
Password:

Here is the link I followed to setup the IPsec server on a ubuntu server
https://github.com/hwdsl2/setup-ipsec-vpn

2
16.1 Legacy Series / Re: Is this a bug?
« on: March 17, 2016, 12:54:31 am »
Quote from: themelon on March 14, 2016, 04:08:30 am
Not a bug.  On those boards if you do not have the dedicated IPMI interface plugged in it piggybacks the second 1g port.

I think you can disable that functionality in the BIOS but I have not actually tried in the one I have as I use the dedicated port.

Well, it is convenient to have this "feature" , I am not completely sure I understand how this could happen with only Opensense. As I mentioned in the post, if, as you mentioned this is controlled in the BIOS, I should observe the same phenomenon with pfsense as well.

With opnsense, the IPMI port is connected to the LAN network, treated as a LAN client, and being assigned a LAN IP address. This is not right for sure. It is supposed be only accessible to administrator through IPMI port, now every LAN client can access it and manage it.

3
16.1 Legacy Series / Is this a bug? update, I still believe this is a bug
« on: March 14, 2016, 02:21:16 am »
I have a supermicro A1SRi-2758F motherboard
http://www.supermicro.com/products/motherboard/Atom/X10/A1SRi-2758F.cfm

It has 4 gigabit ports and 1 dedicated IMPI ports. My setup is as follows:

ethernet port 0 = WAN
LAN = bridge 0 =ethernet port 1 + 2
ethernet port 3 = un-used

IPMI port = unused

However, if I log into the opnsense GUI interface through LAN ports,  under /status/DHCP leases, I can see the IPMI port has an IP address. This IP is accessible through the bridge 0, I have full access to IPMI management interface WITHOUT pluggin into IPMI port. This is not the case with pfsense. My understanding is you have to have ethernet cable plugged into the IPMI port to access IPMI management.

4
16.1 Legacy Series / Re: DYDNS error with dns-o-matic
« on: March 01, 2016, 09:07:15 pm »
I wonder whether this has been fixed in the newer release. I use opendns filtering service, and the dynamic dns service it uses, dns-o-matic, is broken in this 16.1 release. I don't know whether it has been fixed in the later updates

I have tried nO-ip as well. It seemed to work.

I like opnsense, and looking forward to comeback.

Thanks

5
16.1 Legacy Series / DYDNS error with dns-o-matic
« on: February 06, 2016, 02:59:48 am »
I have been unable to get dns-o-matic work work properly. It always shows an error message on my dns-o-matic account, and email notification of the error. It seems the "username" was not properly submitted.

Quote
OpenDNS details:
Errors requiring your attention

!yours
History


6
General Discussion / Re: Connection to Internet VPN provider privateinternetaccess.com
« on: February 03, 2016, 03:49:23 am »
Quote from: StevenE on January 28, 2016, 04:49:25 pm
however I can't get it to set the routing correctly.

What do you mean by this? be specific.

I use PIA as well. I have no problem routing and connect. My problem is the variable speed.

7
16.1 Legacy Series / Re: WAN interface limited to 100M-base
« on: February 01, 2016, 01:26:19 am »
PIA=Private internet access, a VPN service provider, offering openvpn.

8
General Discussion / Re: where to find onlder builds? specifically the 32 bit based on freeBSD 8.3
« on: February 01, 2016, 12:52:56 am »
Unfortunately, I have not been lucky. I have a 100M cable, mostly 130M in real life. Openvpn downs it to 20-30M with my 8-core C2758 Rangely supermicro board and 8G of RAM.

Any trick to share?

I have tried difference things:

1. BF-128-cBC versus AES-128-cbc
2, with or without powerD
3, with or without BSD hardware acceleration

What else can I try?

The CPU usage is 13% MAX, RAM usage is also low. Throughput is as expected when openvpn is off.

9
General Discussion / Where to find older builds? Specifically the 32 bit based on freeBSD 8.3.
« on: January 31, 2016, 08:01:09 pm »
I was trying pfense. I found this version is best with openvpn throughput.

The equivalent pfsense version is 2.1.5, 32 bit.

Thanks

10
16.1 Legacy Series / Re: WAN interface limited to 100M-base
« on: January 31, 2016, 03:19:37 pm »
Thanks. It is the same board.

Did the factory reset. Problem solved,

Do you use VPN service? What is your performance on openvpn?

I am with PIA, There is a lot of variability. I dont know why. Still tweaking.

Thanks

11
16.1 Legacy Series / Re: WAN interface limited to 100M-base
« on: January 31, 2016, 01:31:31 pm »
Thanks for the reply.

I have tried different connection. It was plugged into modem's gigabit Lan port, it was also plugged into a switch which is connected to another gigabit router.

If I plug the computer to the switch, it was fast.

12
16.1 Legacy Series / WAN interface limited to 100M-base
« on: January 31, 2016, 05:46:20 am »
I have supermicro C2758 mini itx board with 8G RAM, 4 ethernet ports.

I just install the 16.1 version. The WAN was set to autodetection by default. However, it is limited to 100M-base interface only. I have changed WAN to a different ethernet port, it is still the same. I have also tried to force it to 1000M-based, it doesn't change.

Any idea?
Thanks





Pages: [1]
OPNsense is an OSS project © Deciso B.V. 2015 - 2024 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2