OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • Profile of jeffg »
  • Show Posts »
  • Topics
  • Profile Info
    • Summary
    • Show Stats
    • Show Posts...
      • Messages
      • Topics
      • Attachments

Show Posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

  • Messages
  • Topics
  • Attachments

Topics - jeffg

Pages: [1]
1
19.1 Legacy Series / WAN admin - Firewall Allow but Blocked
« on: April 17, 2019, 05:25:34 am »
I have a situation where I need to enable web administration on the WAN.  I've done this before without issues.  Go to console, shut down packet filter, set WAN firewall to allow my source IP to destination WAN address port 443.  Restart pf.

I just installed a new install of opnsense yesterday, but I can't get this to work.  I'm able to stop pf from a remote console and then access the WAN web admin, but after adding the WAN firewall rule (even to the point of ANY ANY), when pf restarts, I'm blocked by the default fw block rule.  Any thoughts why this would happen?

I know best practice is to vpn or something and access via the lan (and I'll get to that), but I need this to work on the wan first to set everything up properly.  Also, web admin is enabled for all interfaces.

2
General Discussion / Web Server Instructions / Let's Encrypt / Nginx
« on: February 13, 2019, 05:26:27 pm »
I'm needing some guidance on setting up a web server behind OPNSense.  Initially I just did a port forward, but I want TLS.  So I installed the Let's Encrypt Plugin on OPNSense, but I'm not sure how this works with port forwarding as the server itself needs the cert as it does the encryption exchange.  I don't want to open the web server to the world (I have a Alias defined IP ACL).  So just installing Certbot on the webserver is not an option unless it somehow interacts with OPNSense to allow the temporary proxy.  I also don't want to set up some method that copies the cert from OPNSense to the webserver as that would involve too many potential problems and security issues.

I'm also interested in putting a WAF in front of the web server, though this is not required.  So maybe some nginx method is possible, where the Let's Encrypt on OPNSense is served to the Nginx plugin which acts as a front end to my webserver?  Then the Let's Encrypt plugin has something called a HAProxy, so maybe that's the solution?  I'm finding documentation on these aspects of configuration very limited for my situation and I could really use the help trying to get this set up correctly.  Thank you for any help you can provide. 

As an additional note, I need to be able to access it both internally and externally.  DNS will resolve to the external IP, but I don't know if I need to do some reflection or anything since it would need to go out and then back in.

3
General Discussion / Squid memory only cache
« on: April 17, 2017, 03:47:06 pm »
Does anyone know how to configure a memory only cache?  I don't want any disk caching.

I've set the "Memory Cache size in Megabytes" to 4000.  "Enable local cache" is off.  I don't see any hits or big use of memory in the logs / dashboard.

Pages: [1]
OPNsense is an OSS project © Deciso B.V. 2015 - 2021 All rights reserved
  • SMF 2.0.17 | SMF © 2019, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2