OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • Profile of ex2k3 »
  • Show Posts »
  • Topics
  • Profile Info
    • Summary
    • Show Stats
    • Show Posts...
      • Messages
      • Topics
      • Attachments

Show Posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

  • Messages
  • Topics
  • Attachments

Topics - ex2k3

Pages: [1]
1
24.1 Legacy Series / Intel XXV710 status: no carrier
« on: July 20, 2024, 12:06:13 pm »
Hi

i try to get my new box to work, but i still have no connection to a) my switch and b) my isp.

Code: [Select]
ixl0: flags=8863<UP,BROADCAST,RUNNING,SIMPLEX,MULTICAST> metric 0 mtu 1500
        description: WAN (opt1)
        options=4800028<VLAN_MTU,JUMBO_MTU,NOMAP>
        ether 3c:fd:fe:ea:3b:44
        inet6 fe80::3efd:feff:feea:3b44%ixl0 prefixlen 64 scopeid 0x2
        media: Ethernet autoselect
        status: no carrier
        nd6 options=23<PERFORMNUD,ACCEPT_RTADV,AUTO_LINKLOCAL>
        plugged: SFP/SFP+/SFP28 100GBASE-SR4 or 25GBASE-SR (LC)
        vendor: Intel Corp PN: LTF8505-BC-IN SN: F7AVYR1 DATE: 2024-02-02
        module temperature: 34.79 C voltage: 3.31 Volts
        lane 1: RX power: 0.74 mW (-1.32 dBm) TX bias: 0.00 mA

Code: [Select]
ixl0@pci0:10:0:0:       class=0x020000 rev=0x02 hdr=0x00 vendor=0x8086 device=0x158b subvendor=0x8086 subdevice=0x0002
    vendor     = 'Intel Corporation'
    device     = 'Ethernet Controller XXV710 for 25GbE SFP28'
    class      = network
    subclass   = ethernet
ixl1@pci0:10:0:1:       class=0x020000 rev=0x02 hdr=0x00 vendor=0x8086 device=0x158b subvendor=0x8086 subdevice=0x0000
    vendor     = 'Intel Corporation'
    device     = 'Ethernet Controller XXV710 for 25GbE SFP28'
    class      = network
    subclass   = ethernet

i`m using flexoptix 25G LR SFP28, programmed for intel and ubiquity (switch).
Already tried FS.com SFP`s, and a DAC, no carrier.

tried with pfsense, same result.

i have these tunables:

Code: [Select]
ice_ddp_load
if_em_updated_load
if_ice_load
if_ixl_load

if i try to bring it up by hand:
Code: [Select]
root@OPNsense:~ # ifconfig ixl0 media 25Gbase-SR mediaopt full-duplex up
ifconfig: SIOCSIFMEDIA (media): Device not configured

Code: [Select]
root@OPNsense:~ # ifconfig -vvvvvv ixl0
ixl0: flags=8863<UP,BROADCAST,RUNNING,SIMPLEX,MULTICAST> metric 0 mtu 1500
        description: WAN (opt1)
        options=4800028<VLAN_MTU,JUMBO_MTU,NOMAP>
        ether 3c:fd:fe:ea:3b:44
        inet6 fe80::3efd:feff:feea:3b44%ixl0 prefixlen 64 scopeid 0x2
        media: Ethernet autoselect
        status: no carrier
        nd6 options=23<PERFORMNUD,ACCEPT_RTADV,AUTO_LINKLOCAL>
        plugged: SFP/SFP+/SFP28 100GBASE-SR4 or 25GBASE-SR (LC)
        vendor: Intel Corp PN: LTF8505-BC-IN SN: F7AVYR1 DATE: 2024-02-02
Class: 100GBASE-SR4 or 25GBASE-SR
Length: intermediate distance
Tech: Shortwave laser (SN)
Media: Multimode 50um (M5)
Speed: (null)
        module temperature: 34.79 C voltage: 3.31 Volts
        lane 1: RX power: 0.75 mW (-1.26 dBm) TX bias: 0.00 mA

        SFF8472 DUMP (0xA0 0..127 range):
         03 04 07 00 00 00 00 60 40 04 00 06 ff 00 00 00
         00 00 0a 07 49 6e 74 65 6c 20 43 6f 72 70 20 20
         20 20 20 20 02 00 1b 21 4c 54 46 38 35 30 35 2d
         42 43 2d 49 4e 20 20 20 41 20 20 20 03 52 00 fa
         08 1a 67 00 46 37 41 56 59 52 31 20 20 20 20 20
         20 20 20 20 32 34 30 32 30 32 20 20 68 f0 08 63
         00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
         00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00


any ideas?
never had such a thing before...

2
Intrusion Detection and Prevention / IDS/IPS rules not working at all
« on: December 31, 2018, 01:48:02 pm »
hi

i`m running the latest stable version, everything is fine but suricata seems not to work.

i tried some of the abuse.ch rules, urlhaus for example, rules are downloaded, activated and set to block but i can access the any site form the list.

same goes for geoip countryblock, i see a lot of russian ip`s on the firewall, so i set up a rule to block russia, but nothing happens. No alerts from suricata but block actions on the firewall.

hardware is a Little supermicro with Intel Atom and Intel nics, 8gb ram, 120gb ssd.
i went trough the forum already for performance tuning and a suricata guide, no success.
all services are running fine and im a bit cluesless.

edit: static ipv4 on wan and lan, bridged cablemodem.


thats how the alerts look:

2018-12-31T13:53:55.370905+0100
allowed
WAN
2.22.152.33
443
x.x.x.x
60301
SURICATA STREAM excessive retransmissions
 
2018-12-31T13:51:48.254029+0100
allowed
WAN
x.x.x.x
61759
2.20.248.154
443
SURICATA STREAM excessive retransmissions
 
2018-12-31T12:08:27.682942+0100
allowed
WAN
23.0.174.128
443
x.x.x.x
27980
SURICATA STREAM excessive retransmissions
 
2018-12-31T11:57:22.226768+0100
allowed
WAN
192.229.221.214
443
x.x.x.x
15499
SURICATA STREAM excessive retransmissions
 
2018-12-31T11:44:54.118050+0100
allowed
WAN
192.229.221.214
443
x.x.x.x
2291
SURICATA STREAM excessive retransmissions

thanks for any help

Pages: [1]
OPNsense is an OSS project © Deciso B.V. 2015 - 2024 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2