Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Topics - Snowstorm1491

#1
I have a VPS running OPNsense, so it has only WAN and no LAN.

I have set up "WireGuard Road-Warrior" as wg1, so now wg1 is my "LAN".

I have also set up "WireGuard Selective Routing to External VPN Endpoint" with Mullvad as wg2, so some of the clients from wg1 will be routed through Mullvad, and other routed through WAN of the VPS.

With the clients that are routed through Mullvad, I can just use 10.64.0.1 at the end devices to connect to Mullvad's SOCKS5 proxy without additional setup.

Currently I'm trying to set up so that even clients that are not routed through Mullvad, can use Mullvad's SOCKS5 proxy, without having all their network requests to the Internet being routed through the VPN wg2.

I have installed ShadowSocks on the OPNsense, but I can't find a guide online to set up to achieve what I want.

I'm currently doing trial and error, but I don't understand the difference between "ShadowSocks: Server" and "ShadowSocks: Local".

I have attached my current settings which does not work. Anyone can give me some pointers as to what I'm doing wrong? End devices from wg1 can access the ports 8388 and 1080 on the OPNsense, but curl ip4.me/api/ --socks5 10.10.10.1:1080 gives curl: (52) Empty reply from server, while curl ip4.me/api/ --socks5 10.10.10.1:8388 gets timeout.
#2
I have only IPv4 at home, and I would like to use Wireguard to add the possibility to get to IPv6 only servers.

I rented a VPS at netcup, installed OPNsense there, with the IPv6 subnet aaaa:bbbb:cccc:dddd::/64 and a IPv4 of www.xxx.yyy.zzz. In OPNsense, for WAN, I have set to use DCHP for IPv4 and Static for IPv6 with aaaa:bbbb:cccc:dddd::1/64 as my WAN IPv6 and fe00::1 as gateway. I check with ping that both IPv4 and IPv6 work.

I have followed the Road Warrior guide, initially with only IPv4 to test it out. So the Wireguard tunnel have the IPv4 subnet of 10.10.10.0/24. With only IPv4, the tunnel worked.

Now that I have IPv4 tunnel working, I started to add IPv6 to the Wireguard local interface (aaaa:bbbb:cccc:dddd::a:1/64 in addition to 10.10.10.1/24), and endpoint Allowed IPs (aaaa:bbbb:cccc:dddd::a:2/128 in addition to 10.10.10.2/32).

Client interface IP is aaaa:bbbb:cccc:dddd::a:2/64 and 10.10.10.2/24, allowed ips 0.0.0.0/0, ::/0

After applying the settings, I am able to connect to the tunnel on the client, ping works for aaaa:bbbb:cccc:dddd::1, aaaa:bbbb:cccc:dddd::a:1, but everything outside outside of the OPNsense's aaaa:bbbb:cccc:dddd::/64 is not reachable (I can't ping 2606:4700:4700::1111). However, IPv4 internet is available (I can ping 1.1.1.1).

What did I miss?
#3
For some reason, my WAN DHCP is renewing every few minutes. When this happens, connections from LAN to Internet is dropped for 2 seconds. So every few minutes I lose Internet connection for 2 seconds. Is it to be expected that connections will be dropped when WAN DHCP is renewing lease?

ping logs from LAN client:
PING 1.1.1.1 (1.1.1.1) 56(84) bytes of data.
From 192.168.1.1 icmp_seq=983 Destination Host Unreachable
From 192.168.1.1 icmp_seq=984 Destination Host Unreachable
From 192.168.1.1 icmp_seq=2053 Destination Host Unreachable
From 192.168.1.1 icmp_seq=2054 Destination Host Unreachable
From 192.168.1.1 icmp_seq=2603 Destination Host Unreachable
From 192.168.1.1 icmp_seq=2604 Destination Host Unreachable
From 192.168.1.1 icmp_seq=2605 Destination Host Unreachable


From system logs:
<13>1 2022-08-04T23:03:53+02:00 Ocelot.localdomain dhclient 14374 - [meta sequenceId="1"] New IP Address (vtnet1): xxx.yyy.182.81
<13>1 2022-08-04T23:03:53+02:00 Ocelot.localdomain dhclient 15362 - [meta sequenceId="2"] New Subnet Mask (vtnet1): 255.255.254.0
<13>1 2022-08-04T23:03:53+02:00 Ocelot.localdomain dhclient 16206 - [meta sequenceId="3"] New Broadcast Address (vtnet1): xxx.yyy.183.255
<13>1 2022-08-04T23:03:53+02:00 Ocelot.localdomain dhclient 17299 - [meta sequenceId="4"] New Routers (vtnet1): xxx.yyy.182.1
<13>1 2022-08-04T23:03:53+02:00 Ocelot.localdomain dhclient 18878 - [meta sequenceId="5"] route add default xxx.yyy.182.1
<13>1 2022-08-04T23:03:53+02:00 Ocelot.localdomain dhclient 19817 - [meta sequenceId="6"] Creating resolv.conf
<11>1 2022-08-04T23:03:53+02:00 Ocelot.localdomain opnsense 21296 - [meta sequenceId="7"] /usr/local/etc/rc.newwanip: IPv4 renewal is starting on 'vtnet1'
<11>1 2022-08-04T23:03:53+02:00 Ocelot.localdomain opnsense 21296 - [meta sequenceId="8"] /usr/local/etc/rc.newwanip: On (IP address: xxx.yyy.182.81) (interface: WAN[wan]) (real interface: vtnet1).
<13>1 2022-08-04T23:03:53+02:00 Ocelot.localdomain opnsense 21296 - [meta sequenceId="9"] plugins_configure hosts ()
<13>1 2022-08-04T23:03:53+02:00 Ocelot.localdomain opnsense 21296 - [meta sequenceId="10"] plugins_configure hosts (execute task : dnsmasq_hosts_generate())
<13>1 2022-08-04T23:03:53+02:00 Ocelot.localdomain opnsense 21296 - [meta sequenceId="11"] plugins_configure hosts (execute task : unbound_hosts_generate())
<13>1 2022-08-04T23:11:41+02:00 Ocelot.localdomain dhclient 23714 - [meta sequenceId="1"] Creating resolv.conf
<11>1 2022-08-04T23:11:41+02:00 Ocelot.localdomain opnsense 25784 - [meta sequenceId="2"] /usr/local/etc/rc.newwanip: IPv4 renewal is starting on 'vtnet1'
<11>1 2022-08-04T23:11:41+02:00 Ocelot.localdomain opnsense 25784 - [meta sequenceId="3"] /usr/local/etc/rc.newwanip: On (IP address: xxx.yyy.182.81) (interface: WAN[wan]) (real interface: vtnet1).
<13>1 2022-08-04T23:11:41+02:00 Ocelot.localdomain opnsense 25784 - [meta sequenceId="4"] plugins_configure hosts ()
<13>1 2022-08-04T23:11:41+02:00 Ocelot.localdomain opnsense 25784 - [meta sequenceId="5"] plugins_configure hosts (execute task : dnsmasq_hosts_generate())
<13>1 2022-08-04T23:11:41+02:00 Ocelot.localdomain opnsense 25784 - [meta sequenceId="6"] plugins_configure hosts (execute task : unbound_hosts_generate())
<13>1 2022-08-04T23:21:44+02:00 Ocelot.localdomain dhclient 13102 - [meta sequenceId="1"] New IP Address (vtnet1): xxx.yyy.182.81
<13>1 2022-08-04T23:21:44+02:00 Ocelot.localdomain dhclient 13960 - [meta sequenceId="2"] New Subnet Mask (vtnet1): 255.255.254.0
<13>1 2022-08-04T23:21:44+02:00 Ocelot.localdomain dhclient 14594 - [meta sequenceId="3"] New Broadcast Address (vtnet1): xxx.yyy.183.255
<13>1 2022-08-04T23:21:44+02:00 Ocelot.localdomain dhclient 15499 - [meta sequenceId="4"] New Routers (vtnet1): xxx.yyy.182.1
<13>1 2022-08-04T23:21:44+02:00 Ocelot.localdomain dhclient 17181 - [meta sequenceId="5"] route add default xxx.yyy.182.1
<13>1 2022-08-04T23:21:44+02:00 Ocelot.localdomain dhclient 18506 - [meta sequenceId="6"] Creating resolv.conf
<11>1 2022-08-04T23:21:44+02:00 Ocelot.localdomain opnsense 19811 - [meta sequenceId="7"] /usr/local/etc/rc.newwanip: IPv4 renewal is starting on 'vtnet1'
<11>1 2022-08-04T23:21:44+02:00 Ocelot.localdomain opnsense 19811 - [meta sequenceId="8"] /usr/local/etc/rc.newwanip: On (IP address: xxx.yyy.182.81) (interface: WAN[wan]) (real interface: vtnet1).
<13>1 2022-08-04T23:21:44+02:00 Ocelot.localdomain opnsense 19811 - [meta sequenceId="9"] plugins_configure hosts ()
<13>1 2022-08-04T23:21:44+02:00 Ocelot.localdomain opnsense 19811 - [meta sequenceId="10"] plugins_configure hosts (execute task : dnsmasq_hosts_generate())
<13>1 2022-08-04T23:21:44+02:00 Ocelot.localdomain opnsense 19811 - [meta sequenceId="11"] plugins_configure hosts (execute task : unbound_hosts_generate())
<13>1 2022-08-04T23:30:56+02:00 Ocelot.localdomain dhclient 83332 - [meta sequenceId="1"] New IP Address (vtnet1): xxx.yyy.182.81
<13>1 2022-08-04T23:30:56+02:00 Ocelot.localdomain dhclient 84019 - [meta sequenceId="2"] New Subnet Mask (vtnet1): 255.255.254.0
<13>1 2022-08-04T23:30:56+02:00 Ocelot.localdomain dhclient 84871 - [meta sequenceId="3"] New Broadcast Address (vtnet1): xxx.yyy.183.255
<13>1 2022-08-04T23:30:56+02:00 Ocelot.localdomain dhclient 85210 - [meta sequenceId="4"] New Routers (vtnet1): xxx.yyy.182.1
<13>1 2022-08-04T23:30:56+02:00 Ocelot.localdomain dhclient 87164 - [meta sequenceId="5"] route add default xxx.yyy.182.1
<13>1 2022-08-04T23:30:56+02:00 Ocelot.localdomain dhclient 88029 - [meta sequenceId="6"] Creating resolv.conf
<11>1 2022-08-04T23:30:56+02:00 Ocelot.localdomain opnsense 89254 - [meta sequenceId="7"] /usr/local/etc/rc.newwanip: IPv4 renewal is starting on 'vtnet1'
<11>1 2022-08-04T23:30:56+02:00 Ocelot.localdomain opnsense 89254 - [meta sequenceId="8"] /usr/local/etc/rc.newwanip: On (IP address: xxx.yyy.182.81) (interface: WAN[wan]) (real interface: vtnet1).
<13>1 2022-08-04T23:30:56+02:00 Ocelot.localdomain opnsense 89254 - [meta sequenceId="9"] plugins_configure hosts ()
<13>1 2022-08-04T23:30:56+02:00 Ocelot.localdomain opnsense 89254 - [meta sequenceId="10"] plugins_configure hosts (execute task : dnsmasq_hosts_generate())
<13>1 2022-08-04T23:30:56+02:00 Ocelot.localdomain opnsense 89254 - [meta sequenceId="11"] plugins_configure hosts (execute task : unbound_hosts_generate())


I have tried connecting a VM directly to upstream, and it pings for hours with no packet losses. Either the VM does not renew DHCP leases as frequently or DHCP lease renewal doesn't drop connections.