Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Topics - Joerg

#1
Hi,

I'm using the actual updated OPNsense on a ZOTAC-CI323nano cube. Configured physical WAN Interface and one LAN Interface with some VLANS.
So far the Performance is really great.
As soon I activate the Intrusion Detection IPS mode the download rate goes down by 30%.
The CPU load is below 20% then.
In case I activate the abuse.ch/* rules the Internet Connection will drop after a few minutes. In the alert tab I do not see any drop packets.

Any Idea or in which area I should look?
#2
16.1 Legacy Series / VLAN <--> VPN traffic
June 10, 2016, 05:11:48 PM
Hi,

I think I need a little help from someone who can point me in the right direction.
Just a little bit to my setup. I have one WAN connection and several VLANS to keep the things separated. I have a permanent VPN to the US which is currently connected to a FritzBox over there. The Tunnel phase2 is set to one VLAN. So far so good most of the traffic in this VLAN goes to the VPN. But when I ping my local WAN address OPNsense decide to send the traffic directly to my local WAN interface. Is there a way to deny that? I managed with a simple access rule with an Alias that the traffic goes not to the other VLAN's. I really like to access my wan interface but from my US IP-Address.

Many thanks for some good ideas  ;)