OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • Profile of cnaslund »
  • Show Posts »
  • Topics
  • Profile Info
    • Summary
    • Show Stats
    • Show Posts...
      • Messages
      • Topics
      • Attachments

Show Posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

  • Messages
  • Topics
  • Attachments

Topics - cnaslund

Pages: [1]
1
General Discussion / How to avoid Double NAT with Fritz!Box
« on: February 10, 2018, 03:47:11 am »
My thank you's to the dev's for their hard work on this great product.  I happily contribute to support for dev's who save me time and frustration!

I'm hoping some of you will be able to help me with my doubleNAT issue:

I have the following Setup:

Internet (VLAN10) Fibre---> (PublicIP):Fritz!Box 7490(NAT, FW enabled, Port Sharing Exposed Host for single IP) --> Static Private IP *.*.1.* --->ESXi 6.0:WAN--->Static Private IP *.1.*:WAN NIC:OPNSense 18.1 (DHCP, NAT, FIREWALL)LAN NIC: --> Managed Switch (Private IP *.*.30.*) --> Home Servers/PC's, Devices

When I connect directly to the Fritz!Box 7490 using SpeedTest.net, I get 900/500Mb speeds
When I connect through OPNSense using SpeedTest.net, I get 349/359Mb speeds
When I do a tracert of 8.8.8.8 when connected directly to Fritz!Box LAN port I get single private IP from Fritz!Box as first leg of the trace.
When I do a tracert of 8.8.8.8 when connected directly to OPNSense LAN (via the managed switch) I get two Private IP's in the trace with the first leg being the OPNSense IP, the second leg being the Fritz!Box.

My research yields that the Fritz!box 7490 does not have DMZ.  Rather, I've configured the Fritz!box to have a dedicated Shared Port which is supposed to allow all ports available to the IP of the OPNSense Fireware. This appears to work as my UPnP settings have no issues.

Question:
How do I remove the double NAT issue with OPNSense being behind the Fritz!box to improve my network speeds?  If I turn off NAT on Fritz!box, I get no internet (or access to the Fritz!box for that matter).  I'm a neophyte with this sort of device so clear instructions would be appreciated if possible.

Thank you

2
18.1 Legacy Series / Creating a Certificate Signing Request under 18.1 yields empty .crt files
« on: February 01, 2018, 10:38:30 pm »
Is the process of creation of a CSR for submission to a CA authority supposed to create blank files?  Only one file (the .key) had any information in it despite several attempts.  This issue is found under 18.1_1

3
General Discussion / OPNsense 17.7.12-amd64 Web GUI HTTPS Not Trusted by Chrome63 or Edge
« on: January 24, 2018, 01:49:51 am »
Logging into Opnsense 17.1.12 URL using either an IP or a server name like opnsense.localdomain with Chrome 63 gives a warning that the OPNSense CA is not trusted.  I added the CA certificate into Trusted Root Certificates and the Browser (as well as Windows 10 Edge) refuses to trust the certificate. 
I also created a self-signed certificate using the OpenSSL v3.ext in creation to use the new SubjectAltName with the server domain as as alternate IP.1 IPV4 address and added it to the Trust section of Opnsense.  I then added this self-signed certificate (along with my rootkeyCA.pem key) to my browsers.  Both browsers still complain about OpenSense's CA certificate as being invalid. 
Please advise on how I can fix this CA certificate.

Pages: [1]
OPNsense is an OSS project © Deciso B.V. 2015 - 2024 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2