1
19.7 Legacy Series / Re: strongswan.conf location
« on: August 15, 2019, 08:48:10 pm »
Thanks rainerle, that was exactly what I was looking for!
This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.
| Primary | 172.18.0.101/24 |
| Secondary | 172.18.0.102/24 |
| Virtual IP | 172.18.0.100/24 |
| Interface | WAN |
| Source | any |
| Source Port | * |
| Destination | * |
| Destination Port | * |
| NAT Address | 172.18.0.100 |
| NAT Port | * |
| Static Port | NO |
Never add outbound NAT rules that could match the WAN/Public IP addresses of the cluster. This includes both rules that have the public IP addresses listed explicitly and also rules that have any set as a source. These NAT rules will cause other problems/unintended behavior, and will break outbound connectivity from the secondary node when it is in a BACKUP state.
Go to Firewall -> NAT and select outbound nat. Choose manual outbound nat on this page and change the rules originating from the 192.168.1.0/24 network to use the CARP virtual interface (172.18.0.100).
traceroute to OPNsense-firewall (X.X.X.75), 30 hops max, 60 byte packets
1 PFsense-firewall (192.168.76.254) 0.220 ms 0.217 ms 0.213 ms
2 * * *
3 * * *
4 * * *
5 * * *
6 isp-upstream-gateway (X.X.X.73) 3.376 ms 3.261 ms 3.259 ms
7 isp-upstream-gateway (X.X.X.73) 3.861 ms 3.801 ms 3.851 ms
8 isp-upstream-gateway (X.X.X.73) 4.415 ms 4.398 ms 4.385 ms
9 isp-upstream-gateway (X.X.X.73) 4.926 ms 4.971 ms 4.961 ms
10 isp-upstream-gateway (X.X.X.73) 5.523 ms 5.559 ms 5.628 ms
11 isp-upstream-gateway (X.X.X.73) 6.155 ms 6.135 ms 6.108 ms
12 isp-upstream-gateway (X.X.X.73) 6.723 ms 6.719 ms 6.771 ms
13 isp-upstream-gateway (X.X.X.73) 7.355 ms 7.262 ms 7.298 ms
14 isp-upstream-gateway (X.X.X.73) 7.926 ms 7.795 ms 7.845 ms
15 isp-upstream-gateway (X.X.X.73) 8.461 ms 8.456 ms 8.511 ms
16 isp-upstream-gateway (X.X.X.73) 9.009 ms 9.167 ms 9.075 ms
17 isp-upstream-gateway (X.X.X.73) 9.690 ms 9.687 ms 9.681 ms
18 isp-upstream-gateway (X.X.X.73) 10.235 ms 10.233 ms 10.205 ms
19 isp-upstream-gateway (X.X.X.73) 10.838 ms 10.857 ms 10.856 ms
20 isp-upstream-gateway (X.X.X.73) 11.448 ms 11.441 ms 11.380 ms
21 isp-upstream-gateway (X.X.X.73) 11.894 ms 11.898 ms 11.895 ms
22 isp-upstream-gateway (X.X.X.73) 12.537 ms 12.518 ms 12.515 ms
23 isp-upstream-gateway (X.X.X.73) 13.125 ms 13.172 ms 13.049 ms
24 isp-upstream-gateway (X.X.X.73) 13.719 ms 13.671 ms 13.664 ms
25 isp-upstream-gateway (X.X.X.73) 14.246 ms 14.278 ms 14.271 ms
26 isp-upstream-gateway (X.X.X.73) 14.822 ms 14.849 ms 14.841 ms
27 isp-upstream-gateway (X.X.X.73) 15.406 ms 15.417 ms 15.415 ms
28 isp-upstream-gateway (X.X.X.73) 15.975 ms 15.880 ms 16.000 ms
29 isp-upstream-gateway (X.X.X.73) 16.536 ms 16.619 ms 16.567 ms
30 isp-upstream-gateway (X.X.X.73) 17.119 ms 17.032 ms 17.029 ms
/sbin/bsdlabel -B -r -w ada0s1
auto FAILED with a return code of 1.
x BSD Installer started a
x DFUI connection on tcp:9999 successfully established a
x ,- opened pty to '/sbin/sysctl -n hw.physmem' a
x < 17138442240 a
x `- closed pty to '/sbin/sysctl -n hw.physmem' a
x `/sbin/sysctl -n hw.physmem` returned: 17138442240 a
x ,- opened pty to '/sbin/sysctl -n kern.disks' a
x < da0 ada1 ada0 a
x `- closed pty to '/sbin/sysctl -n kern.disks' a
x `/sbin/sysctl -n kern.disks` returned: da0 ada1 ada0 a
x /dev/mirror exists. Surveying. a
x ,- opened pty to '/usr/bin/find /dev/mirror/* | /usr/bin/sed a
x "s/\/dev\/mirror/mirror/"' a
x < mirror/OPNsenseMirror a
x `- closed pty to '/usr/bin/find /dev/mirror/* | /usr/bin/sed a
x "s/\/dev\/mirror/mirror/"' a
x `/usr/bin/find /dev/mirror/* | /usr/bin/sed "s/\/dev\/mirror/mirror/"` a
x returned: mirror/OPNsenseMirror a
x Testing mirror/OPNsenseMirror a
x Invoking survey for mirror/OPNsenseMirror a
x Surveying Disk: mirror/OPNsenseMirror ... a
x | Media sector size is 512 a
x | Warning: BIOS sector numbering starts with sector 1 a
x | Information from DOS bootblock is: a
x | The data for partition 1 is: a
x | sysid 165 (0xa5),(FreeBSD/NetBSD/386BSD) a
x | start 63, size 234441585 (114473 Meg), flag 80 (active) a
x | beg: cyl 0/ head 1/ sector 1; a
x | end: cyl 132/ head 15/ sector 63 a
x | The data for partition 2 is: a
x | <UNUSED> a
x | The data for partition 3 is: a
x | <UNUSED> a
x | The data for partition 4 is: a
x | <UNUSED> a
x `->>> Exit status: 0 a
x ,-<<< Executing `/sbin/bsdlabel -B -r -w ada0s1 auto' a
x | bsdlabel: unable to get correct path for ada0s1: No such file or a
x directory a
x `->>> Exit status: 1 a
mountroot: waiting for device /dev/gpt/rootfs...
Mounting from ufs:/dev/gpt/rootfs failed with error 19.
Mounting from ufs:/dev/mirror/OPNsenseMirror failed with error 22./boot/config: -S115200 -D
/oading /boot/defaults/loader.confsion 1.1port