Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Topics - jojothehumanmonkey

#1
hello, thanks, recently updated to `24.7.12_4`

opnsense will not boot, stuck at "Invoking start script 'freebsd'"

if i press 'ctrl+c', i get 'context canceled', then the boot continues and eventually, get to 'login:'

so, why will opnsense not boot fully, is it safe to use?
#2
hello, thanks, hope i am posting in the correct section of the forum,

"System: Access: Users", i click on a user named `user01`

at "User Certificates", i want to add an already existing certificate, i do not want to create a new certificate.
but only i see the plus button, with the text "create new user certificate"

just want to assign an existing certificate to a user.
#3
hello, thanks, my first time, i setup the openvpn server with TOTP login. fantasic, it works great.
i figured out how to make a openvpn firewall rules and that also works well.
but now i need to allow a specific user to a specific machine and port.
how to change the source to a specific openvpn user?

currently, i have this rule


#4
General Discussion / how to mimize disk usage
January 29, 2023, 01:38:20 AM
hello, thanks,

i am confused, by default, if opnsense using a swap file?
and if so, how to move it to memory, same as "/var/log RAM disk" and "/tmp RAM disk"

from dashboard:
"SWAP usage 0 % ( 0/8192 MB )"

from system_advanced_misc.php, this setting is uncheck.
"Swap file Add a 2 GB swap file to the system"

from /etc/rc.conf, there is no "swapfile=", so does that mean, opnsense is not using swap.

swapinfo -k
Device          1K-blocks     Used    Avail Capacity
/dev/gpt/swapfs   8388608        0  8388608     0%

--------------

also, curious, what else does opnsense write to disk?
--- log files
if this is enabled, where does opnsense save logs?
Local Logging    Disable writing log files to the local disk

--- other stuff i would not know about, the so-called "unknown unkowns"

thanks, david
#5
hello, thanks, using     OPNsense 23.1-amd64

using filezilla, when i try to connect to sftp, i get this, no idea why, please help?

Status:   Connecting to 192.168.62.1...
Response:   fzSftp started, protocol_version=11
Command:   keyfile "C:\data\c\combined\.self\opnsense\keys\root\opnsense-home.private.ssh"
Command:   open "root@192.168.62.1" 22
Error:   Connection timed out after 20 seconds of inactivity
Error:   Could not connect to server
#6
Hardware and Performance / DOM - Disk on Module
January 28, 2023, 07:52:01 PM
hello, thanks,

an idea popped into my head, to use a DOM, instead of a hard drive.
when i checked the opnsense dashboard,
i was amazed that only this is used [
SWAP usage 0 % ( 0/8192 MB )
Disk usage 1% / [ufs] (5.4G/442G)


here is the output of df


root@OPNsense:~ # df
Filesystem      1K-blocks    Used     Avail Capacity  Mounted on
/dev/gpt/rootfs 463893544 5926272 420855792     1%    /
devfs                   1       1         0   100%    /dev
devfs                   1       1         0   100%    /var/dhcpd/dev


and then i found out at a supermicro dom 16GiB is approx $40.00

so i wanted to know a few things, please
--- has anyone done this, any advice?
--- any other overall comments?

thanks,
david
#7
hello and thanks,

i have to connect to another openvpn server that uses.

IPv4 Address. . . . . . . . . . . : 10.10.0.21(Preferred)
   Subnet Mask . . . . . . . . . . . : 255.255.0.0
   Default Gateway . . . . . . . . . : 10.10.0.1


my opnsense router for the openvpn connection uses

IPv4 Tunnel Network 10.10.0.0/24


so i need to change the setting for opnsense but not sure what to change it without locking myself out of the router.
would this work?
10.11.0.0/24

and if i make that change, do i need to re-export all the client config files?

thanks so much,
#8
hello and thanks,

i could not find fail2ban package?

is it not supported or is there a opnsense version or alternative.
i am trying to better protect openvpn server.

thanks,
david
#9
hello and thanks,
using opnsense as a home router and working great.

i did a netscan from the internet and noticed that ports such as smtp are `filtered`, not closed.

i am sure there is a logic to that approach but would it not be better to have unused ports closed, to just drop the packets and reply at all?

thanks much,
jojo


#10
hello and thanks,

my opnsense router is running dnscrypt and that is working well.
also, i have installed the shadowsocks server.

on my computer, on the lan from that opnsense router.
i am running a shadowsocks client.

using ms-edge, not using that shadowsocks clients, dnsleaktest results look very good.

using my main browser, firefox, pointing to that shadowsocks client, internet is working.

using firefox, having ENABLED "Proxy DNS when using SOCKS v5"
i do a dnsleaktest, the results are not good, pointing to my isp dns, verizon.

using firefox, having DISABLED "Proxy DNS when using SOCKS v5"
i do a dnsleaktest, the results are good, clearly using the dnscrypt


note: that on the opnsense router, if i setup a ssh tunnel like so, then firefox proxy dns works.
ssh -D 8123 -f -q -N asdffdsa@OPNsense

so why using shadowsocks, the dns is not using dnscrypt server,
but using that ssh tunnel, the dns is using the dnscrypt server?

thanks,
david
#11
hello and thanks,

my opnsense router is running dnscrypt and that is working well.
also, i have installed the shadowsocks server.

on my computer, on the lan from that opnsense router.
i am running a shadowsocks client.

using ms-edge, not using that shadowsocks clients, dnsleaktest results look very good.

using my main browser, firefox, pointing to that shadowsocks client, internet is working.

using firefox, having ENABLED "Proxy DNS when using SOCKS v5"
i do a dnsleaktest, the results are not good, pointing to my isp dns, verizon.

using firefox, having DISABLED "Proxy DNS when using SOCKS v5"
i do a dnsleaktest, the results are good, clearly using the dnscrypt


so why using shadowsocks, the dns is not using dnscrypt server?

thanks,
david
#12
hello and thanks,

in the past, i used a socks5 proxy over ssh, very simple and easy.

now at home, i am using opnsense,  have a road warrior ssl vpn.

so when i am outside the home, i need a simple socks5 proxy for my web browser - firefox.

that caching proxy seems very complex and not sure that it can work as socks5 with firefox

please, can someone help me understand my options.?
thanks,
jojo
#13
hello, newbie to the forum, if i posted in the wrong section, sorry about that.


the log is full of entries like
"wan      Jan 18 16:46:17   185.156.73.65:49302   xxx.xxx.xxx.xxxx:xxxx   tcp   Default deny rule"

i want to disable that from the log.
so using web gui, i goto "firewall/rules/wan" but i cannot find that default deny rule, thus i cannot disable the log.
so what am i doing wrong?

thanks much,
david