Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Topics - enor

#1
Hardware and Performance / x710-da2 in an gen4 x4 port?
December 09, 2023, 06:34:28 PM
X710-da2 is a full duplex dual 10 gigabit card pci gen3 x8. Will this be bottlenecked in a x4 port?

pcie gen3 x4 can manage 32Gbps

However since nic is full duplex I need to count on 40Gbps would mean it will be bottlenecked?

#2
General Discussion / Howto change NIC ?
November 07, 2023, 10:46:38 AM
Hello,
I have a dual nic which I want to change to another nic. There is only on pci slot so I can't run them in paralell.

I have VLAN's running aswell.

Do I just replace nic and configure it in CLI? Will VLAN's continue to work ?

Couldn't find any docs on this. Just some posts that make it sounds like it's a pain to achive without braking everything.
#3
General Discussion / Nat reflection problems 23.7
August 07, 2023, 08:21:35 PM
Running Opnsense 23.7 and have been trying to set up nat reflection on my portforward.

Have a simple forward for port 22, fine to access it externaly on wan ip but not internally against wan ip.

Have enabled the following in Advanced
* Reflection for port forwards
* Reflection for 1:1
* Automatic outbound NAT for Reflection

Have also enabled reflection in port forward rule.

Have searched some and other people seems to have had the same problem, but seems it has resolved when they enabled the settings in advanced. Am I missing something else?

Cheers.
#4
I have a new default installation of opnsense where I have added 2 portfowarding rules.

Running with 10Gb dual nic and and an i5-12500 cpu(3Ghz, boost 4.1Ghz)
Installation is virtualized and using pci passthrugh for nic.

Been playing around with iperf3 and I notice that upload speed max out at ~9.37. Download jump around abit between 8-9.37. Guessing that when the CPU can't boost anymore speed goes down..

Why is there a difference? Ofc. there are a few firewall rules for incomming on WAN but not that many, have firewall rules between VLAN's but that does not drag down speed.
Is it translating back to local ip's which is more resource intensive then the other way?


In the end it does not really matter just curious.
#5
General Discussion / Geoblock, block all, allow some
December 26, 2022, 08:00:47 AM
Hello,
looking into geoblocking and I am wondering how it works.

Examples displays that you define countries which to block. However I would like to block everything and allow some countries and then continue matching next rule in list if country ip is allowed(can you do that?).

Wouldn't that be faster aswell? Since it would reduce the number ip ranges to check against?

#6
Hello,
got some problems with my opnsense setup. 2-3 times/hour i loose connection to opnsense(routing) and maybe after 30secs everything comes back up again. I have looked at the logs but I don't know howto interpret the logs.

I do not use ipv6 and DHCPv6 Server is stopped. I have stopped the VPN client but doesn't seem to help either.

This is what I see in logs after I get connection back to the router. system->General logs

Jan 23 12:19:06    dhcp6c[24494]: Sending Solicit
Jan 23 12:18:34    dhcp6c[24494]: Sending Solicit
Jan 23 12:18:18    dhcp6c[24494]: Sending Solicit
Jan 23 12:18:14    opnsense: plugins_configure newwanip (,opt4)
Jan 23 12:18:14    opnsense: /usr/local/etc/rc.newwanip: Resyncing OpenVPN instances for interface VpnVPN.
Jan 23 12:18:14    kernel: pflog0: promiscuous mode enabled
Jan 23 12:18:14    kernel: pflog0: promiscuous mode disabled
Jan 23 12:18:14    opnsense: plugins_configure vpn (,opt4)
Jan 23 12:18:13    opnsense: /usr/local/etc/rc.newwanip: The VPN_VPNV4 monitor address is empty, skipping.
Jan 23 12:18:13    opnsense: /usr/local/etc/rc.newwanip: The VPN_VPNV6 monitor address is empty, skipping.
Jan 23 12:18:13    opnsense: /usr/local/etc/rc.newwanip: The WAN_DHCP monitor address is empty, skipping.
Jan 23 12:18:13    opnsense: /usr/local/etc/rc.newwanip: The WAN_DHCP6 monitor address is empty, skipping.
Jan 23 12:18:13    opnsense: plugins_configure monitor ()
Jan 23 12:18:13    opnsense: /usr/local/etc/rc.newwanip: ROUTING: skipping IPv6 default route
#7
Hello,
running opnsense and first of all I will apologize that I do not have any debug information but that's because I do not know where to look.

Recently I upgraded to OPNsense 19.7.8-amd64 and I have also switched to qotom Q555G6 hardware and since then I have had problems. When installing new hardware I restored from backup created from old hardware.

1a. When I create a firewall rule and hit apply the rule/rules does not work. However after a random amount of minutes the rule/rules suddenly starts to work and all is fine.

1b. It also happens that rules that I have is not applied after I reboot opnsense, need to disable/reenable them and I have to wait for random amount of minutes for hem to be applied.

2. I have also experienced short times of none internet access, everything goes down but then suddenly is up again. Would generaly have blamed ISP but I am not sure anymore. Since it comes up pretty fast after it happens I haven't been able to debug where the problem recides.

Have anyone experienced the same problem? Anyone got a suggestion on how I should trie to debug this?

Maybe it's time for a fresh install =/