Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Topics - grimelog

#1
I'm trying to troubleshoot why this is happening. It's blocking the keys from calling home and I cannot figure out why. If I turn all of the security settings off it still does it. How can I filter the web traffic to only see pgp traffic in the live UI so I can troubleshoot and fix this?
#2
I'm trying to update my keyring to install up to date packages on one of my machines. Opensense is blocking the keyring update process with my current firewall rules. I think it's from a redirect to local dns. But, I'm getting errors like error retrieving 'george@rawlinson.net.nz' via WKD:

I tried turning off all filtering, and intrustion detection with no luck. Anyone know what firewall rule I might need to allow pgp updates?
#3
On my Qubes machine I cloned the working settings I currently use for wireless to that lan. I currently, cannot connect to the internet. I know this did work at one point. Any idea what I might be getting stuck on connecting to a tor relay on my Qubes machine. I think this was working before the switch to kea.

I do have intrusion detection and intrusion prevention up, and tried taking both down with no luck so far. Any idea what might be blocking me from connecting to tor?
#4
My setup used to work. What I could do for my rule set was switch my default outbound connection between my wireguard gateway, and non-vpn gateway. Currently, only the non-vpn gateway works. I've doubled checked and everything should be setup fine on Mullvad's end. For whatever reason nothing seems to be getting out of my Wireguard tunnel. Anyone know what might be going on here?

These settings used to work correctly I know for a fact. Maybe, I changed one thing that broke it. Have any tips for how to troubleshoot this?
#5
Recently, I needed to enable my VPN again, and enabling the gateway for it no longer works. I have confirmed that I am successfully handshaking with wireguard. So, that is not the issue.

How I have my DNS setup is Unbound forwards specific queries to DNSMasq, and connecting to those websites works successfully. However, connecting to the websites intended for Unbound does not work if my Wireguard gateway is up. Previously, this behavior worked as expected. Even rolling back to a known working configuration did not work. Is anyone able to help?

In /usr/local/etc/dnsmasq.conf.d/dnsmasq-ipset.conf:
# Add the response for certain A/AAAA lookups to an opnsense alias
ipset=/example_website.com/dont_go_over_vpn


# Uncomment these if Unbound is still your primary DNS server; otherwise you'll have a loop
no-resolv
server=1.1.1.1


The above works for all sites not intended for the vpn. However, the sites intended for the VPN no longer work. I'm guessing this has something to do with the recent changes to DNSMasq and Unbound. In the Unbound gui I forward all example_website.com domains to DNSMasq.

Once I turn "Go out over VPN" to WAN_Mullvad I stop resolving addresses going out over the VPN. Previously, the VPN DNS would go out over the non-VPN tunnel to get the addresses for the VPN, and it no longer seems to be doing that at all.


#6
I turned SMTEN on in the bios for the Dec850. Seems like it might be improving performance of Suricata. Hope we get support for that driver update soon. Some speed tests have been coming in 200 Mb/s faster since I've turned it on. I also have various tuneables turned on. But, the issue started showing up after turning on multithreading. I know this cpu only has 8 threads, and not 16 with multi-threading. But, does that setting still do something for Epyc 302s?

I have to manually assign my ip, and either reboot the firewall or restart Kea to get dhcp up. Networking works out of the router, but my devices are not getting assigned after every reboot. Could this be a bug?

Update: Looks like it was from setting dev.igb.<x>.fc=0. I'd assume other settings from here would have a similar impact. Either that or disabling powerd did it. I was able to get higher speeds intermittently, but those settings were not stable. Gateways kept going down, and download speeds would be 600 Mb/s for awhile, before suddenly dropping to 150 Mb/s. Still have SMT turned on and have not noticed any issues.
#7
Unbound has been leaking my DNS and think it is causing some reliability issues with which Gateway I go out on too. There's also the added concern of potential censorship on social media.

What I basically setup was for my firewall to use Unbound for most DNS queries, and for Unbound to forward a few queries to DNSMasq for the few sites I want going out over another Gateway. Redirecting all queries to Unbound is what's causing my DNS to leak. It did not leak, prior to redirecting all DNS queries to my local resolver.

If I bind the Outgoing Network Interface to only listen to WAN_Wireguard the internet completely breaks for me. If I bind it to WAN only everything works fine. I tried setting up a static route that connects to my VPN endpoint address and that did not work. How can I get this working?
#8
I've tried setting up a URL Table in JSON format for Spamhaus's blocklist using Path expressions. However, I cannot find any expression that can successfully parse it. The JSON validators I've checked claim it is invalid JSON. However, jq can still successfully parse the list. Is this a situation that's kind of like YAML, where it's possible to write valid YAML no parser can interpret? Is this a valid JSON file?
#9
I have a wireguard gateway, which I use as the default route for my traffic. I also have a second gateway I send traffic through that does not play nice with VPNs. This setup works perfectly fine. The problem is my gigabit internet gets cut in half. It definitely has more to do with IPS / IDS than my VPN. However, I'm trying to see if I can gain some performance back by sending my traffic out over multiple endpoints. Maybe, 100 Mbps max.

I have two endpoints setup currently, and they connect to the internet fine. However, the second one does not show an IP address, and I do not believe any traffic is getting sent out. In the widget, The first shows 44.71 MB down, and 7.93 MB up, while second shows 552 B down and 1.94 KB up. I have 0.0.0.0/0 set as the ip. Do I just need to assign random ips to both of the endpoints for this to work?

Would this even work with a gateway? I can't enable routes on this Wireguard instance. In otherwords how would I balance loads across both Wireguard endpoints?
#10
I'm trying to figure out why my firewall's performance degrades with the latest version. So, I'm setting up a virtualbox VM to manually transfer settings. I have a feeling my old config had some rogue setting that's not playing well with the newest version. But, I can't get the installer to load successfully in a VBox environment.

I keep getting an ld-elf invalid file format error. I'm using the dvd installer. Anyone know what might be going on?

https://imgur.com/a/opnsense-vbox-1P7bWFw
#11
I already made sure the issue is not my modem by getting my ISP to reset from their end. I also shut off the modem and firewall, and then restarted them. I tried turning off IPS and IDS, and turning off my VPN. Even though, I've taken out those potential bottenecks I'm still getting download speeds of only 20 Mbps, when I should have gigabit. I do have a bunch of tunables turned on that increased my throughput back on 24.1. I'm on  24.7.10_2.

Have any idea what might be causing my issues? Anyone experiencing slow speeds even after a reset?
#12
My intrusion detection keeps picking up a security company spamming my ports to check for vulnerable VOIP ports. I do not use VOIP, and monit keeps spamming my email with alerts over it. To silence it do I want to reject or block connections on that port? What's the difference between the two?
#13
I'm using Unbound to forward specific websites to DNSmasq, which I use to populate an external alias that sends those connections out through one gateway. On my firewall rulles, I have that rule placed above the rule for routing out my VPN's gateway. All of the default web traffic is supposed to go out over my VPN connection.

Normally, my forwarding rules make me successfully go out without using the VPN; but, on occasion connections still go out over the VPN. Does anyone know what might be causing me to go out the wrong way on occasion?
#14
I have four use cases I'm trying to solve for. There are three solutions, which I need. I've already figured out the two general rules needed, but cannot figure out how to handle the exceptions properly.

I'm using GEOIP to send traffic to different wireguard gateways. If the site is located in the US it goes out though a US server. If not the US it goes out over my preferred wireguard gateway. This works perfectly well. Where I run into trouble is getting the exceptions to route traffic reliably. There are a few sites I either do not want going out over a VPN, or to use a VPN running Socks5.

I tried using the FQDN. That works until the site refreshes their IP. It's an issue with a mismatch between the DNS on my OPNsense box, and what IP the URL currently resolves to.  I also tried using ASN; however, a large amount of sites use the same ASNs. Is there a reliable means of doing this?

Would running a local DNS, and refreshing the database before visiting those sites work? Is there a means of doing that with Unbound?
#15
I'm stuck at setting a certificate for signing my client instance. I have the Mullvad certificate, which OPNsense is not letting me import under System --> Trust --> Certificate, as I do not have access to the private key. I tried importing it through System --> Trust --> Authorities; but, I cannot set that for OpenVPN client. I tried creating my own CA to see if I can sign a certificate using the imported Mullvad certificate as an authority. But, under "Sign a Certificate Signing Request" I do not know what to paste in the CSR file.

How can I properly import the CA given by Mullvad to get OpenVPN working?
#16
I just downloaded the latest bios update. After dding it to a disk, from Arch Linux, it is not bootable on a Dec850. gparted keeps giving an error about not being able to have a partition outside of the disk. I saw a few posts saying that means there's space in the img that needs to be zeroed out. The partition has iba for the flag should I just add boot to that?
#17
I'm using Wireguard, and would like to set it up so I don't have to manually change my endpoint for regional content. I have one entrypoint, and two endpoints. Through firewall rules I'm forcing all traffic to go out through my VPN. Is there any means of forcing traffic for specific websites out through a specific endpoint?
#18
I just picked up a Deeper Network Mini for creating a node in a decentralized VPN service. I don't fully trust the device to not have anything malicious on it. I think I should probably be running some intrusion detection with it being on the network.

I'm not sure which lists to turn on. I just know turning everyone on is not recommended. Which ones should I be running? Are there any other steps I can take to protect myself in case this device has malicious code on it?

Ideally, I'd completely silo it off with a second internet connection, but that's not an option with my building.
#19
Had a bit of an excursion where I had to recover a router without login shell access from any users. To fix this I've added bash as a login shell for my admin user. Should I keep this separate from the admin I use for the gui, locally? Which login shell is best for security purposes? Is there any reason to keep gui and console admins separate?
#20
Can't get in through the gui as a change to a VPN setting locked me out. For the serial console I either have the wrong password, or the fact I disabled root is preventing me from logging in. My main administrator account does not have access through the serial console.

Is there any means of factory resetting the device?