Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Topics - ledufakademy

#1
hum openSense is probably having a BIG bug !!!!

what is the best gateway conf for this conf ? (perhaps my problem is here ?)

i have an openVpn client setup , tun is up , ok. (ovpnc2), on WAN iface
VPN-1 UDP    11.11.11.129(gw)   11.11.11.185(ip)    2020-11-14 00:03:44    325 KB    275 KB    up

So i do an assignement of ovpnc2 to virtual iface WAN_VPN (virtual interface in oprder to fully manage incomming and outgoing packets)

then i create 3 virtual ip on "WAN_VPN" using public IPs given by my vpn provider using Interfaces \ Virtual IPs \ settings :

- 11.11.11.101/32 , gw 11.11.11.129
- 11.11.11.102/32 , gw 11.11.11.129
- 11.11.11.103/32 , gw 11.11.11.129

Then i change Upstream gateway to VPN one, same thing for system \ settings \ general

And if i came back to Interface\ WAN_VPN , then simply clic on SAVE :

The following input errors were detected:

    This interface is referenced by IPv4 VIPs. Please delete those before setting the interface to 'none' configuration.
    This interface is referenced by IPv4 VIPs. Please delete those before setting the interface to 'none' configuration.
    This interface is referenced by IPv4 VIPs. Please delete those before setting the interface to 'none' configuration.

(the config seems to work afterall !!)

Where am i  wrong ?
#2
is it possible to totaly purge openvpn configuration ?

Quote2020-11-13T22:26:14   openvpn[21309]   Exiting due to fatal error
2020-11-13T22:26:14   openvpn[21309]   TCP/UDP: Socket bind failed: Addr to bind has no AF_INET6 record
2020-11-13T22:26:14   openvpn[21309]   Socket Buffers: R=[42080->42080] S=[57344->57344]
2020-11-13T22:26:14   openvpn[21309]   TCP/UDP: Preserving recently used remote address: [AF_INET6]2a00:5881:4000::3:1194
2020-11-13T22:26:14   openvpn[21309]   NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
2020-11-13T22:26:14   openvpn[21309]   WARNING: No server certificate verification method has been enabled. See http://openvpn.net/howto.html#mitm for more info.
2020-11-13T22:26:09   openvpn[21309]   Restart pause, 5 second(s)
2020-11-13T22:26:09   openvpn[21309]   SIGUSR1[soft,ping-restart] received, process restarting
2020-11-13T22:26:09   openvpn[21309]   [UNDEF] Inactivity timeout (--ping-restart), restarting
2020-11-13T22:25:13   openvpn[21309]   MANAGEMENT: Client disconnected
2020-11-13T22:25:13   openvpn[21309]   MANAGEMENT: CMD 'state all'
2020-11-13T22:25:13   openvpn[21309]   MANAGEMENT: Client connected from /var/etc/openvpn/client2.sock
2020-11-13T22:25:09   openvpn[21309]   MANAGEMENT: Client disconnected
2020-11-13T22:25:09   openvpn[21309]   MANAGEMENT: TCP send error: Broken pipe
2020-11-13T22:25:09   openvpn[21309]   MANAGEMENT: Client connected from /var/etc/openvpn/client2.sock
2020-11-13T22:25:09   openvpn[21309]   UDP link remote: [AF_INET]89.234.140.3:1194
2020-11-13T22:25:09   openvpn[21309]   UDP link local (bound): [AF_INET]192.168.1.185:0
2020-11-13T22:25:09   openvpn[21309]   Socket Buffers: R=[42080->42080] S=[57344->57344]
2020-11-13T22:25:09   openvpn[21309]   TCP/UDP: Preserving recently used remote address: [AF_INET]89.234.140.3:1194
2020-11-13T22:25:04   openvpn[21309]   NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
2020-11-13T22:25:04   openvpn[21309]   WARNING: No server certificate verification method has been enabled. See http://openvpn.net/howto.html#mitm for more info.
2020-11-13T22:25:04   openvpn[21309]   MANAGEMENT: unix domain socket listening on /var/etc/openvpn/client2.sock
2020-11-13T22:25:04   openvpn[15688]   library versions: OpenSSL 1.1.1h 22 Sep 2020, LZO 2.10
2020-11-13T22:25:04   openvpn[15688]   OpenVPN 2.4.9 amd64-portbld-freebsd12.1 [SSL (OpenSSL)] [LZO] [LZ4] [MH/RECVDA] [AEAD] built on Oct 21 2020
2020-11-13T22:25:04   openvpn[15688]   WARNING: file '/var/etc/openvpn/client2.up' is group or others accessible

Probably vpn provider issue OR issue openvpn : i do a factory reset then re appky the config file ... it's ok
#3
Hello,

when i'm trying to install i am stuck on this message :
"Trying to mount root from ufs:/dev/ufs/OPNsense_Install [ro,noatime]..."

When ussing this image  :
sudo dd  if=OPNsense-20.1-OpenSSL-serial-amd64.img of=/dev/sdf bs=16k

if i deconnect my SATA Disk (target of my future install) : live opnsense si working  (on 4GB CF Card)
#4
it's seems that opnsense default install block multicast traffic on lan ... why ?

(ffe80:: xxxxxx           f02::16            ip            Default deny rule ...)

#5
20.1 Legacy Series / Really a BAD realase.
February 07, 2020, 09:13:02 AM
lot of bug ... never seen that before.
Not production ready ! sure.