Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Topics - 7queue

#1
On a system that has been running just fine with 24.7 and 25.1 prior to the latest update.

I applied the latest updates and it throws an error when booting now:

CPU0:<ACPI CPU> on acpi0

The system uses DDR5 so it's relatively new hardware.

I reinstalled 25.1 and applied the update with the same result.

Also tried installing the latest FreeBSD on this system and applied updates and it boots fine.

Any hint at how I could track this issue down?

I'm going to try installing 25.1 and apply the updates on a different system and see what happens.

8  )
#2
What protocols, ports and ip addresses do I need to allow on an upstream edge firewall that blocks all outbound traffic unless a specific rule allows it?

So far I've identified UDP 5355 and ICMP to any of these IP addresses:

104.155.129.221
104.198.6.78
34.74.12.235
35.198.172.108
34.65.117.157
34.92.15.156
35.244.50.89
35.189.37.160
#3
Greetings,

I was following Zenarmor instructions to setup proxy. https://www.zenarmor.com/docs/network-security-tutorials/how-to-set-up-caching-proxy-in-opnsense#3-enable-transparent-http-and-ssl-mode and I noticed "Add a new firewall rule".

Well, that didn't go so well, 80/443 access blocked now. I tried to remove those two rules and that hosed the system.

I've put the system aside until I can look at it in depth so it's not a priority. What I was wondering is if anyone else tried those links to add rules and have them work?

Thanks.
#4
New to OPNsense here.

Is there a howto on configuring web GUI access on only LAN segment? Following any of the search results and docs do not work as expected.

On the actual OPNsense system using the diagnostics DNS lookup I get the LAN IP only which is what I want to see returned on any system on the LAN segment. (Do not register system A/AAAA records checked)

Issuing "dig <opnsense fqdn>" on any system on the LAN segment returns all Internal IPs?


For now I've brute forced it in the hosts file on all the systems, there has to be a better way.

Any pointers?

Thanks!