Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Topics - cambrbr

#1
I have installed ntopng on my opnsense and was looking at network connectivity inside my IOT network (that has a solar inverter, charging station and battery). All three are from different vendors.

I noticed activity that is originating from the gateway inside the IOT network (diagram attached). I thought it was a bit strange that the gateway was trying open SSH or http connections to hosts inside the IOT network.

But perhaps it is not strange, and it is intended behavior from ntopng to check open ports on hosts? Can someone confirm/deny this ?
#2
I have a few VLANs in my homelab that need to be able to reach the internet (diagram is in the attachment)

My test "server" VLAN is sitting behind a router that is NOT my opnsense box. I created a transit vlan between that router and my opnsense firewall. I put in the correct route back to the 192.168.130.0 network through the 172.16.0.2 gateway in the transit network (otherwise no ping reply) and I have opened up the firewall to allow this traffic to go anywhere when originating from the transit network.

When I put a network client into my 192.168.130.0 subnet, I can ping the default gateway in that subnet (192.168.130.1), and I can ping the firewall interface of the transit subnet I created (172.16.0.1).

However, a host in 192.168.130.0/25 cannot reach (not even ping) the internet. The firewall log shows traffic is allowed to pass, but I don't get a ping reply.

Any other network I created that is "'directly" attached to the OPnsense FW works flawlessy (e.g. the services network).

Am I missing a route or default gateway somewhere ? Is it because the 192.168.130.0 network is not "known" to OPnsense ?

(PS: I'm not a routing specialist, I'm a hobbyist so do bear with me when I ask something stupid).

#3
Hi,
I have created a new VLAN (10). That VLAN needs access to internet, and certain LAN services.

DHCP is working fine, and I have added port 53 for access to Unbound DNS on the firewall. However, when I want to allow HTTP to internet, it does not work. The destination "WAN net" does not work.  When I allow * as destination, it does work, but that also allows access to LAN resources using HTTP, which is something I don't want.

What am I doing wrong ?

#4
I just upgraded my OPNSense FW to the latest version. Zenarmor Engine, Reporting Database and Cloud Agent are all running, but I don't see any traffic (not under Reports, not under Live Sessions, not under Activity Explorer) since that update.

Has anyone experienced this issue too ? I do think Zenarmor is working in the background (blocks ads etc).

The ZEnarmor plugins have all been updated to the latest version

os-sensei (installed)   1.15.2
os-sensei-agent (installed)   1.15.2
os-sensei-updater (installed) 1.15
os-sunnyvalley (installed) 1.3

These plugins are showing as "N/A" under Tier. Is that normal ? All other plugins show e.g. Tier 3