Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Topics - hescominsoon

#1
OPNsense 25.1.7_4-amd64
FreeBSD 14.2-RELEASE-p3
OpenSSL 3.0.16

ntopng refuses to start as noted:

2025-05-26T11:40:15-04:00   Error   ntopng   26/May/2025 11:40:15 [Redis.cpp:159] ERROR: to specify a redis server other than the default   
2025-05-26T11:40:15-04:00   Error   ntopng   26/May/2025 11:40:15 [Redis.cpp:156] ERROR: Please start it and try again or use -r   
2025-05-26T11:40:15-04:00   Error   ntopng   26/May/2025 11:40:15 [Redis.cpp:155] ERROR: ntopng requires redis server to be up and running   
2025-05-26T11:40:14-04:00   Error   ntopng   26/May/2025 11:40:14 [Redis.cpp:100] ERROR: Connection error [Connection refused]   
2025-05-26T11:40:13-04:00   Error   ntopng   26/May/2025 11:40:13 [Redis.cpp:100] ERROR: Connection error [Connection refused]   
2025-05-26T11:40:12-04:00   Error   ntopng   26/May/2025 11:40:12 [Redis.cpp:100] ERROR: Connection error [Connection refused]   
2025-05-26T11:40:11-04:00   Error   ntopng   26/May/2025 11:40:11 [Redis.cpp:100] ERROR: Connection error [Connection refused]   
2025-05-26T11:40:10-04:00   Error   ntopng   26/May/2025 11:40:10 [Redis.cpp:100] ERROR: Connection error [Connection refused]   
2025-05-26T11:40:09-04:00   Error   ntopng   26/May/2025 11:40:09 [Redis.cpp:100] ERROR: Connection error [Connection refused]   
2025-05-26T11:40:08-04:00   Error   ntopng   26/May/2025 11:40:08 [Redis.cpp:100] ERROR: Connection error [Connection refused]   
2025-05-26T11:40:07-04:00   Error   ntopng   26/May/2025 11:40:07 [Redis.cpp:100] ERROR: Connection error [Connection refused]   
2025-05-26T11:40:06-04:00   Error   ntopng   26/May/2025 11:40:06 [Redis.cpp:100] ERROR: Connection error [Connection refused]

some more digging shows redis failing:
2025-05-26T11:43:59-04:00   Warning   redis   Failed listening on port 6379 (tcp), aborting.   
2025-05-26T11:43:59-04:00   Warning   redis   Warning: Could not create server TCP listening socket track6:6379: Name does not resolve   
2025-05-26T11:43:59-04:00   Warning   redis   WARNING: The TCP backlog setting of 511 cannot be enforced because kern.ipc.somaxconn is set to the lower value of 128.   
2025-05-26T11:43:59-04:00   Notice   redis   Running mode=standalone, port=6379.   
2025-05-26T11:43:59-04:00   Notice   redis   monotonic clock: POSIX clock_gettime   
2025-05-26T11:43:59-04:00   Notice   redis-server   Configuration loaded   
2025-05-26T11:43:59-04:00   Notice   redis-server   Redis version=7.2.8, bits=64, commit=00000000, modified=0, pid=32198, just started   
2025-05-26T11:43:59-04:00   Notice   redis-server   oO0OoO0OoO0Oo Redis is starting oO0OoO0OoO0Oo   
2025-05-26T11:43:42-04:00   Warning   redis   Failed listening on port 6379 (tcp), aborting.

any ideas?
#2
25.1, 25.4 Legacy Series / opncentral deployment
April 12, 2025, 08:29:46 PM
i have been reading the docs and continue to look through them...trying to figure how opncentral is deployed.  is it a cloud based system provided by Deciso?
#3
i have a macbook running 15.3.2 and i am trying to connect via the included console cable.  i cannot seem to get it to connect.  some pointers would be appreciated.
#4
over the past three days traffic from my remote servers stopped working.  it too me a while to figure out what was not right..but finally after digging i found the automatic firewall rules for the wan interface got deleted after the upgrade.  once i re-created the wan firewall rule for the port forwards traffic began flowing again.  As a test i deleted the port forward rebooted the firewall and then recreated the port forwards...the traffic was blocked..after another reboot no forwarded traffic was allowed..i had to create the wan firewall rule to allow the port forward.
#5
24.7, 24.10 Legacy Series / unable to update
August 31, 2024, 06:31:27 PM
I have a dec appliance(it's a couple of years olkdd) and for some reason it is refusing to upgrade:

***GOT REQUEST TO CHECK FOR UPDATES***
Currently running OPNsense 24.1.10_8 at Sat Aug 31 09:29:01 PDT 2024
Fetching changelog information, please wait... fetch: transfer timed out
fetch: /usr/local/opnsense/changelog/changelog.txz appears to be truncated: 0/144860 bytes
Updating OPNsense repository catalogue...
Waiting for another process to update repository OPNsense
All repositories are up to date.
Checking integrity... done (0 conflicting)
Your packages are up to date.
Checking for upgrades (0 candidates): . done
Processing candidates (0 candidates): . done
Checking integrity... done (0 conflicting)
Your packages are up to date.

Any ideas?
#6
24.7, 24.10 Legacy Series / updating to 24.7
August 23, 2024, 03:52:49 AM
Got it worked put
#7
24.7, 24.10 Legacy Series / ipv6 issues
August 15, 2024, 03:34:16 AM
comcast business...router is bridged.  under Linux dhcpv6 works perfectly....i cannot get it working in Opnsense.  i have tried all the tips i can find...pointers are appreciated.  prefux is set to /55 which works under linux based firewalls.
#8
24.7, 24.10 Legacy Series / enabling boot environments
August 15, 2024, 03:28:16 AM
about a year ago i purchased an opnsense racl appliance9the model escapes me at the moment).  did these last gen devices not ship with zfs by default?
#9
General Discussion / ipv6 and comcast business
June 20, 2024, 02:13:44 AM
i cannot get ipv6 to work with comcast business.  i have it set to prefix delegation at a /55 and tried a prefix hint and without a prefix hint.  modem is in bridge mode.
#10
can the community edition do ssl interception so the contents can be checked by ips or is that only business edition?
#11
Jsut curious how you would do this.  so far i see lots of posts saying the max is rellay 109gbps.  Obviously the folks at pf say if you want to go faster than 10gbps you have to use tnsr as bsd using the kernel isn't capable of going faster.  How would you do it under opnsense as i noted the addition of 25gb interfaces on their appliances?
#12
I have a rule setup that is from my current ip any access is allowed to the system..so shell, webgui..everything.  This rule is et so ONLY this p address has this access.  However when i try to use my hes****.ddns.net opnsense will not allow the access.  I have checked that the ip i have entered and the current ddns address resolve to the same ip.  I also have other firewalls that work fine with this ddns.net dynamic address.  it is the sole deployed opnsense that cannot seem to get it right.  Any ideas as to why this is?
#13
22.7 Legacy Series / failover question
October 12, 2022, 01:04:00 AM
for step 5:
Step 5 - Add allow rule for DNS traffic

were does this rule go?  does it go under firewall rules for the failover interface group or do i need to add it to every other internal interface?  We are not using unbound for dns.

also can both interfaces be tier 1 with different priorities?
#14
22.7 Legacy Series / traffic issue
October 04, 2022, 10:41:25 PM
so i have the following setup:
wan---cable modem(dhcp no static..no routing jsut a modem--dumbswtch

off the dumbswitch is the opnsense on one port with a 76.x.x.x dhcp ip
on the other port is a pfsense on 69.x.x.x. dhcp.

when i am behind the onsense i cannot get to the 69 address.  all other access vectors work fine.  i am sure there is a setting i am missing.  a pointer would be appreciated.
#15
I recently purchased an opnsense appliance for a client.  It appears 1500 dollars was not spent wisely.  it appears 22.7 is not supported on official hardware as their fix for any problem is to reinstall 22.1.  Right now the only email contact i can get to is sales....is there an actual support mailbox at the parent company?
#16
22.7 Legacy Series / multi-wan failover problem
August 11, 2022, 09:29:11 PM
in the previous release i could unplug one wan port and the system would fail over to number 2 without issue.  When the primary was restored it would fail back to the primary.  This is now NOT happening in the newest release.  This has apparently been a bug before..but now short of rebooting hte firewall it will not restore states back to the primary after a fail over to secondary.  any ideas?
#17
Virtual private networks / vpn using dynamic fqdn
August 06, 2022, 09:30:05 PM
I've done it with a sophos firewall where the vpn(via openvpn) instead of looking for an ip looks for a fgdn(aka firewall.dynamicdomain.tld).  Can opnsense be configured to act in this way?
#18
i recently purchased a 3850 appliance and I was trying to go to the community edition but it keeps saying your subscription requires a token.  So far I have been told the only way to go back is to reinstall.  given the lack of a VGA port(use I know there's a console...but that's a bigger pita) can't I just switch repos(even if I have to do it in the root shell) and do it that way?
#19
I have been reading the docs and I cannot find a place to install my et pro telem token.  I know I am missing something..i just can't find it..:)
#20

   Internal      1000baseT <full-duplex>   192.168.255.1
track6
   LAN      1000baseT <full-duplex>   192.168.1.1
   WAN      1000baseT <full-duplex>   98.218.75.122
2001:558:6003:8:a53d:e2e2:250a:db88
   sickcomputer      1000baseT <full-duplex>   192.168.253.1
   wguest      1000baseT <full-duplex>   192.168.254.1


I have tried multiple modems and nics.  I simply cannot get ipv6 to get sent to the internal vlans.  This has been ongoing for a long time.  Any ideas where to start?