Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Topics - crissi

#1
Hello,

upgraded today to V22-7-11 and recognized the following Syslog errors in backend:


2023-01-19T12:30:30 Error configd.py [dc4fc17f-1320-4ae5-86d3-969fb0e120ec] Script action stderr returned "b'pkg: sqlite error while executing DROP TABLE repo_update; in file pkgdb.c:2320: attempt to write a readonly database'"



2023-01-19T12:30:29 Error configd.py [82367a10-f22f-47e9-97b3-b8bf83c2579f] Script action stderr returned "b'pkg: sqlite error while executing CREATE TABLE packages (id INTEGER PRIMARY KEY,origin TEXT,name TEXT NOT NULL,version TEXT NOT NULL,comment TEXT NOT NULL,desc TEXT NOT NULL,osversion TEXT,arch TEXT NOT NULL,maintainer TEXT NOT NULL,www TEXT,prefix TEXT N'"



2023-01-19T12:29:43 Error configd.py Timeout (120) executing : interface newip 'lagg0'



2023-01-19T12:23:49 Error configd.py Timeout (120) executing : interface newip 'lagg0_vlan


How to solve them?

thx
#2
Hello,

i have a question regarding the openvpn ssl server setup. I have followed the documentation here https://docs.opnsense.org/manual/how-tos/sslvpn_client.html and i can successfully connect with my mobile phone.
I tried now, to set under Firewall – Rules – Register - OpenVPN (auto generated when SSL Server is started) like Allow Access to internal DNS Server, but I'm missing there under Destination to set OpenVPN address ..

When I assign an Interface for example OPEN_VPN_SRV there I have then the possibility to set the address (s. screenshot), and i can also name the Entry to have a better overview.



My questions are:
a.)   Is this the right way to go to set the assign an Interface when I want to build specific Rules for the VPN Clients?
b.)   If yes, is there a way to Hide the auto generated Menu Entry OpenVPN somehow, or did I oversee something in the Setup to do this?

Thx
BR
Crissi
#3
22.7 Legacy Series / configd.py error Timeout 120
November 14, 2022, 05:07:16 PM
Hello,

updated to 22.7.7_1 and get configd.py error Timeout 120 in backend log


#4
I have the Problem that the VPN Client Connections just stopped the next day. I can start them in the Gui without any problem, but the following day they are just stopped again. Checking the Log Files give no indications, why the Services are stopped. When doing the Openvpn Client connections from a DD WRT Router they are stable, running for month without any problem an no disconnects..

I found here an older post about to add a cron job:


https://forum.opnsense.org/index.php?topic=9051.0


I was wondering if this is still the way to go with 22.7.2 as the post is from 2018.

Also as in the post written, this adaptation will not be in the backup. Is there a other solution, what will also survive future firmware updates?

Thx!

#5
Hello,

have updated to 22.7.2 and get the follwoing error in the gui log:


2022-08-18T13:11:09 Error lighttpd (configfile.c.1287) WARNING: unknown config-key: server.dir-listing (ignored)


Login via Gui works fine, just wondering how to solve.

Thx!

#6
Hello,

OPNsense 22.1.10 with Transparent Squid + ICAP + ClamAV

Issue, when the firewall is rebooted, and I test if the AV Filter is working, I get the following Error regarding the Templates in ICAP Log File:


Tue Jul 12 10:19:57 2022, 10462/12678144, ERROR: Unable to find specified template: /tmp/c-icap/templates//virus_scan/en/VIRUS_FOUND



To get the correct OPNsense Template shown, I have to go to Services - C-ICAP - Configuration and press Save Button again.

How to solve?
Thx
#7
Hello,

updated my OPNsense to V 22.1.8_1 . As since os-dnscrypt-proxy 1.12 anon relay option is available in Gui i tried to configure the option, as i already have DNS Crypt with Unbound working well.


Under DNS Crypt - Configuration - Servers i added the 2 Relays with Name and SDNS Stamp (from the official List without the prefix).

Then i went back to General Settings and under Relay List i added the 2 defined relays and saved.

In the Log File i see, that the Anonymizing queries are loaded fine for the defined relays..

But when i check back to the Configuration Page - General and scroll down, the Relay List Field, and Disabled Server List are empty...

Interrestingly if i check the dnscrypt-proxy.toml under /usr/local/etc/dnscrypt-proxy i see that the defined relays and disabled server names are still defined and loaded, even after reboot.

Is this a know issue?

Thx
Crissi
#8
Hello,

I use this configuration for DNS Crypt Proxy with Unbound:
https://forum.opnsense.org/index.php?topic=10670.msg48630#msg48630


Updated now from 22.1.3 all working fine, to 22.1.6. After Update Name Resolution for Clients is not working anymore.


I went then to Unbound – Query Forwarding – Custom Forwarding and added:


Enabled
Domain empty
Server IP 127.0.0.1
Port 5353



Restarted Unbound Service and checked again, but Name Resolution for Clients still not working.

After that, I disabled the Custom Forwarding Rule, and added under System – Settings – General a Public DNS Server and set under Query Forwarding Use System Nameservers, and with the Public added DNS Server the Clients can browse and DNS Resolution is possible.

How can I fix this to leave DNS Servers blank and just get custom DNS with 127.0.0.1 port 5353 with DNS Crypt working again, as it worked perfect with previous version 22.1.3?

Thx
#9
Hello,

Updated to 22.1. ZFS Install with LAGG. Checking dmesg:


debugnet_any_ifnet_update: Bad dn_init result from igb1 (ifp 0xfffff800031f3000), ignoring.
igb1: link state changed to DOWN
lagg0: link state changed to DOWN
debugnet_any_ifnet_update: Bad dn_init result from igb2 (ifp 0xfffff8000505d800), ignoring.
igb2: link state changed to DOWN
debugnet_any_ifnet_update: Bad dn_init result from igb3 (ifp 0xfffff80003f25000), ignoring.
igb3: link state changed to DOWN

igb1: link state changed to UP
igb3: link state changed to UP
igb2: link state changed to UP
lagg0: link state changed to UP


Get the Bad dn_init on all Interfaces (Intel Interfaces), after the Update to OPNsense 22.1.

How to fix?
Thx!
#10
Hello,

updated my ZFS Install today to 22.1. After all Updates are applied and the several reboots are done, when i open the Sensei Dashboard i get a Popup Message "We detected different os architecture. We installing elasticsearch for new os architecture"

Restarted the services, rebooted my fw several times, but no automatically install happens, as the popup suggest..

Has someone else with ZFS Install the same issue? How to fix this?

Thx!
#11
Hi,
I have installed transparent squid proxy with clamav on my opnsense, works perfect. As I use also openvpn with pia on my sense, im trying to force the squid proxy over the VPN Connection, as at the moment when the Proxy is enabled, squid take the WAN Gateway. Searched here in the Forum and tried already with parameter tcp_outgoing_address but without success till know. Seems I have somewhere an error.

Created under /usr/local/etc/squid in the Folders /post-auth and /pre-auth a custom.conf  with the following settings:


acl VPNUsers src 192.168.20.0/24 
tcp_outgoing_address (VPN IP) VPNUsers


Restarted the Fw and tested, but get the following error in squid.log

squid   kid1| commBind Cannot bind socket FD 17 to 151.x.x.x: (49) Can't assign requested address

Tried then to add just the following line to the custom.conf


tcp_outgoing_address {VPN IP}



Still get the same error.

Does someone get this to work?

Thx!
#12
21.7 Legacy Series / DNSCrypt Proxy Service late Start
January 13, 2022, 06:18:00 PM
Hello,

when i restart my fw the DNSCrypt Proxy Plugin is started as the last service... Is there a way to force the DNSCrypt Proxy Plugin to Start early during Boot of the Firewall?

Thx!
#13
Hello,

i have an issue with selective routing. I have OpenVPN running and connected. The whole LAN net is going out to Internet via the OpenVPN connection, as set in the Firewall Rule as Gateway. Now i created an Alias with www.whatsmyip.com and added before the VPN Gateway another Rule with Source LAN net and Destination the Alias and Gateway Default (ISP Connection)

When testing www.whatsmyip.com i see the public address over WAN, when testing with a other Tool, i see the IP from the VPN, so all good.

Then i restarted the Firewall, and tested again the same Websites, but this time, the excluded Alias with whatsmyip.com dont show me the WAN IP as expected, the Alias show me the VPN connected IP., whats is wrong, as the Request should be routed over the WAN Connection.

Could it be, that the Firewall States have not been flushed during the reboot ? How can i prevent this?

Thx!
#14
General Discussion / Maltrail on Opnsense
December 26, 2021, 02:47:26 PM
Hello,

i installed Maltrail Server / Sensor on OPNsense 21.7.7 . Under Maltrail - Sensor - Remote Port Help, if i left the setting empty (as Sensor / Server) on the same Device, i get the error when saving "Field remoteport is required"


The Auto Generated Alias BlocklistMaltrail , and added to a Rule from my side. But the Content in the Alias is empty, nothing loaded, even after reapplying the settings.

Also, in the Gui Settings, is there not yet the possibility to change Gui Access Port Protocol to https?

Any Idea how to Fix this?

Is Maltrail in general Production ready?

Thx!
#15
General Discussion / Question to Aliases
December 26, 2021, 02:13:31 PM
Hello,

im trying to create an Alias LOCAL_NET_GROUP with Standard created Networks LAN net and VLAN10 net. Both Networks are available under Firewall Rules Source / Destination.

When I try to save the created Alias Group I get the error: Entry "LAN net" is not a network.,Entry "VLAN10 net" is not a network.

Should it be not possible, to work under the Aliases with the "Internal" created Networks, as I have them available in the Firewall Rules?

Thx!
#16
General Discussion / Question Mail Gateway
December 21, 2021, 06:59:58 PM
Hello,

i have a couple of gmail mailboxes, and get a lot of spam lately. I saw now in the docu, the option for the setup of a mailgateway, with the Plugins: ClamAV, Postfix, Redis, Rspamd

https://docs.opnsense.org/manual/how-tos/mailgateway.html

Would there be the possibility with the above configuration, for Filtering my Mailboxes? What happens with the Mails, are they locally then on the Firewall itself?

Thx!
#17
Hello,

i have setup Squid Proxy today, and have some Questions to specific Settings:

Web Proxy - Administration - General Proxy Settings - Use alternate DNS-servers

As i use Unbound with DNS Crypt Proxy, what would be the Use Case to specify here different / alternate DNS Servers for the Proxy?

Web Proxy - Administration - Forward Proxy - Access Control List - Allowed destination TCP port and Allowed SSL ports

Is this configuration here the place for "Punch a whole" through the Proxy?

Under Allowed destination TCP port are some ports already predefined, are this just example Ports? Whats the difference between Allowed destination TCP port and Allowed SSL ports in point of configuration?


Web Proxy - Administration - Forward Proxy - SSL no bump sites

Is there an Option to somehow Upload a Domain List what should be excluded directly? Without have to enter manually a lot of Domains?

Thx!
#18
Hello,

after upgrade to 21.7.7. my Spamhaus etc. Alias with the URL TableIPs was empty and update was also not possible. Tried also with several reboots, but nada.

Created the same Alias new again, and URL Table IPs are loaded fine afterwards.

How to prevent this in future? I mean why after an upgrade, the really basic stuff is not working anymore...

Thx!

#19
Hello,
I have a understanding question regarding firewall rules and policy based routing over OpenVPN connection https://docs.opnsense.org/manual/firewall.html to the following Note:

QuoteNote
When using policy based routing, don't forget to exclude local traffic which shouldn't be forwarded. You can do so by creating a rule with a higher priority, using a default gateway.

Please see attached screenshots of my Firewall Rules.

How exactly can I exclude the local traffic which shouldn't be forwarded to the OpenVPN connection in my case, as I actually just want to allow http / https traffic to internet for the VLAN10 over the specific OpenVPN single gateway?

Reading the Note over and over again just confuse me more...

Thx!
#20
Hello,

i use the Unbound custom-options.conf actually with the following settings for DNSCrypt Proxy:

server:
do-not-query-localhost: no
forward-zone:
name: "."
forward-addr: 127.0.0.1@5353


I saw here in this Guide https://nguvu.org/pfsense/pfsense-baseline-setup/#dns%20resolver to make the DNS Resolver authoritative for the local Domain, adding the following snippet to the custom-options:

server:
local-data: "local.lan. 10800 IN SOA pfsense.local.lan. root.local.lan. 1 3600 1200 604800 10800"


My question, can i just add additionally the second setting to the custom-options.conf? Do i need to keep here a specific order somehow?


Thx!