OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • Profile of geek »
  • Show Posts »
  • Messages
  • Profile Info
    • Summary
    • Show Stats
    • Show Posts...
      • Messages
      • Topics
      • Attachments

Show Posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

  • Messages
  • Topics
  • Attachments

Messages - geek

Pages: [1] 2 3 4
1
24.7 Production Series / Re: Can we now use the openvpn client 2.6.x for windows?
« on: October 17, 2024, 01:21:07 pm »
Mine failed when I tried to update it. Still asks me for a "private key password"

Okay so it works when I do the Export "File Only" Instead of "Archive"

2
24.7 Production Series / Can we now use the openvpn client 2.6.x for windows? (sovled) USE "File Only"
« on: October 17, 2024, 12:06:51 pm »
I remember a while ago there was a problem with openvpn where we couldn't install openvpn client 2.6.x or newer because of compatibility issues. Is this problem now fixed with the latest version of opnsense? can I simply replace my 2.5.x with 2.6.x openvpn gui clients for windows?

3
23.7 Legacy Series / Unable to delete openvpn instance static key
« on: August 04, 2023, 12:56:05 pm »
trying to delete an openvpn instance static key, but unable to do so. get an error message

4
General Discussion / Re: opnsense box not pinging anything on the internet. But internet works!
« on: July 27, 2023, 12:16:50 pm »
So in summary:

Client's on OPNSENSE LAN -> can ping the WAN router (192.168.1.1)
Opnsense BOX (192.168.1.2) -> CANNOT ping the WAN router (192.168.1.1)

Funny part is -> UDP comms work, but ICMP does not. See attached.

I am convinced its the ISP's router that's the problem

5
General Discussion / Re: opnsense box not pinging anything on the internet. But internet works!
« on: July 27, 2023, 12:10:18 pm »
Quote from: cookiemonster on July 27, 2023, 12:07:46 pm
Both WAN and LAN are on RFC1918 networks? Maybe bogons rule is blocking.

Yes. Because the ISPs are shitty and whenever there's a problem, they'll lay the blame on "your firewall" if something goes wrong. So we do it like this (I know Double Nat, bad practice etc...  ;D)

Both Bogons and Private IP Blocks are disabled

6
General Discussion / Re: opnsense box not pinging anything on the internet. But internet works!
« on: July 27, 2023, 11:58:43 am »
There is nothing in live view other than some default deny on IGMP on WAN interface.

However, I did notice something odd. I had the firewall box brought in, plugged it into a different network, reconfigured the interfaces and everything seems to be working. But in that network specifically on the WAN side, its not letting ping go.

My guess is the ONT device (ISP's box) is doing something funny here. I don't think OPNsense is the problem in this case.

Current setup is like this:

ISP ONT device -> LAN IP -> 192.168.1.1 ->> OPNsense WAN IP (192.168.1.2 with gateway set to 192.168.1.1)

LAN side OPNsense IP -> 192.168.2.1

If you see the attached ping jobs, no icmp traffic is being blocked by pfsense.
end-user (windows) clients can ping anything on the internet (8.8.8.8 / 8.8.4.4)

7
General Discussion / Re: opnsense box not pinging anything on the internet. But internet works!
« on: July 22, 2023, 09:31:46 am »
My bad. I ran a ping from a local client to 2 different IPs, log shows it passes

8
General Discussion / Re: opnsense box not pinging anything on the internet. But internet works!
« on: July 19, 2023, 05:37:39 pm »
Local ping works and live view shows packet pass

9
General Discussion / Re: opnsense box not pinging anything on the internet. But internet works!
« on: July 18, 2023, 04:16:06 pm »
attached. Log says "pass" But ping probe says "100% loss"

10
General Discussion / Re: opnsense box not pinging anything on the internet. But internet works!
« on: July 18, 2023, 01:43:33 pm »
Quote from: CJ on July 18, 2023, 01:33:25 pm
I can only imagine that you have something screwed up in your Firewall rules.  What do your WAN rules look like, including the floating and automatic rules?

You are correct. There are an unusual amount of automatic rules.
attached WAN and floating Rules

11
General Discussion / Re: opnsense box not pinging anything on the internet. But internet works!
« on: July 18, 2023, 10:05:56 am »
Quote from: CJ on July 17, 2023, 05:57:34 pm
What does your network look like?

How are you testing ping?

Can you test with a fresh install?
Very simple: 2 Interfaces:

WAN - connects to internet
LAN - connects to lan with a /24 subnet

Testing ping using the ping diagnostics in interfaces menu
Testing with a fresh install is NOT possible as it is on a remote location. That would be my absolute last resort
I am using the latest version.

12
General Discussion / opnsense box not pinging anything on the internet. But internet works!
« on: July 17, 2023, 11:42:27 am »
I have a very weird problem - opnsense box cannot do any ping to WAN/Internet.
(which is why even the WAN gateway shows offline)

- All computers on LAN can ping and access ALL resources on the internet.
- opnsense box can't ping anything on the internet
- opnsense box CAN ping everything on the LAN side
- port probe works fine (I ran a 443 check on google.com)

- for test purposes I even did a allow all rule for all protocols everywhere, it didn't work.

13
23.1 Legacy Series / Encryption algorithm (deprecated)
« on: May 20, 2023, 07:05:07 pm »
While making a new openvpn server in Opnsense (road warrior / remote access)
I saw "Encryption Algorithm" had a text saying "depcrecated"
with the following line:

"Cipher selection for older clients. Only preserved for backwards compatibility reasons."

Does that mean that it will auto negotiate select the encryption algorithm when the client connects to the openvpn server on opnsense? (for a while I thought encryption altogether is disabled, but that seemed silly :P)

14
23.1 Legacy Series / Re: ALL 3 gateways flapping after latest 23.1.7 update
« on: May 05, 2023, 06:20:46 pm »
I just updated to OPNsense 23.1.7_3

Do I need to do anything else? At thhat time I went into gateways and checked the "Disable Host Route" option to fix the problem. I could not find any documentation on what exactly that option is used for other than the help item which said "Do not create a dedicated host route for this monitor.".

15
23.1 Legacy Series / ALL 3 gateways flapping after latest 23.1.7 update
« on: May 05, 2023, 12:28:35 pm »
I use multiwan with different priorities for gateways.
default gateway switching is enabled.
all three gateways are marked as upstream gateways. Everything was fine until I upgraded to 23.1.17

Now all three gateways go offline and online repeatedly at the same time. This has caused a major outage.

In the release notes I read the line
:"system: restructure routing to carry out default gateway switching and address family specific reconfig"

Would this have anything to do with my problem?
Thank you.

Pages: [1] 2 3 4
OPNsense is an OSS project © Deciso B.V. 2015 - 2024 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2