Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Topics - athisesanr

#1
Hi Folks,
     
      I just try to understand the master and slave election using carp advertised skew (To determine which physical or virtual machine has a higher priority, the advertised skew is used. A lower skew means a higher score)

Now question is, if i have 10 connection means i do have 10 virtual IPs, so by default I didn't configured any advertised skew even preempt disable on 2nd firewall. so how the carp master will be selected now ?

I could see in my two machine like FW01 and FW02 , that FW01 is always master even i try to reboot it may went slave and back to master once FW01 is up.

Then, now what is calculation behind the master selection if everything is default value in both machine ?


Thanks, 

#2
Hi Folks,

I have a question regarding IPsec with DANT and SNAT as below steps that I'm trying in OpnSense FW,

Let have steps are configured and checking the connections.,

- IPsec between Site A (OpnSense) to Site B (FortiGate)     (policy-base tunnel Up)
- Site A has a local network of 100.100.100.0/27
- Site B has a local network of 100.200.100.0/27
- Site A has a some vlan connectivity with their internal VLAN network (such 10.10.10.15)
- Site B want to connect 10.10.10.15 through the NAT ip of 100.100.100.10 - this ip chosen from Site B Local subnet free ip.
- ensured that Site A local subnet 100.100.100.0/27 have connectivity to 10.10.10.15
- Able to reach from Site B to Site A local subnet OpnSense configured ip such as interface ip and carp ip.
- Unable to reach from Site B to Site A IP of 100.100.100.10 which is nat to 10.10.10.15
- having port forward NAT (DNAT) on IPsec interface like below,
          (src-100.200.100.10 , dst-10.10.10.15 , translated-100.100.100.10)
- having outbound NAT (SNAT) on internal vlan interface like below,
          (src- 100.200.100.10,dst-100.100.100.10, tanslated-10.10.10.15)


so, checking the traffic, I can able to get the reply from vlan network but i couldn't ping from site B to opn internal vlan network via nat.

16:27:31.135755 IP 100.100.100.10 > 10.10.10.15: ICMP echo request, id 14098, seq 1628, length 64
16:27:31.136089 IP 10.10.10.15 > 100.100.100.10: ICMP echo reply, id 14098, seq 1628, length 64

Hence, I think, I miss somewhere in NAT, can anyone guide to me here.,

pls note all the interface rules are any-any.,

Thanks,


         






#3
24.1, 24.4 Legacy Series / OpnSense remote Backup
May 16, 2024, 11:10:59 AM
Hi Team,

I'm checking backup possibility of opnsense which is only available local and cloud backup from UI.

is there any possible to send a backup from opn to targeted backup server with in LAN or any api query to run the config backup from backup device to opnsense vm directly ?

Thanks,
Athisesan R
#4
24.1, 24.4 Legacy Series / OpnSense Upgrade Query
May 16, 2024, 11:08:22 AM
Hi Team,

I'm looking upgrade possibility of direct upgrade without using mirror, like download the latest patch and transfer to opnsense shell specfic folder to run any upgrade check and run commands.

currently, I'm using 24.1 version which is possible to upgrade from mirror once the firewall have a connection internet.

Thanks,
Athisesan Ramar
#5
Hi Team,

I am trying to configure RABC policy using Microsoft LDAP.

LDAP configuration done and able to test it with LDAP IDs are login successful.

and while importing required LDAP Ids into users and enabling groups for them and getting user auto removal from the groups when login.

Is any once faced the issue previously and can any one help this to short it out ?

Thanks,
Athisesan R

#6
Hi Team.

I'm looking docs for VMware tool installation for opnsene vm which is running in vmware platform,

Can anyone assist like how to install the vmware tool for opnsense vm in vmware platform ?

Thanks,
Athisesan R
#7
Hi Team,

I'm recently installed opnsense in VMware ESXI platform where deployment completed and try to make the CARP between the two machine gets formed but unfortunately I'm receiving master on both machine.

I did TS on Rules where placed correctly and HA SYNC working as expected and I could see the CARP protocal running (224.0.0.1 and 224.0.0.18) in interfaces.

I tried restart, carp disable, persistence mode those are not helping and thoroughly checked  that Virtual IP configuration where placed as it is.

I do have receiving IANS arp from connected top layer physical firewall
      100.100.102.250   7          00:00:5e:00:01:0a >>>> VIP
      100.100.102.252   0          00:50:56:90:01:6a >>>> FW1
      100.100.102.253   1          00:50:56:90:a5:82 >>>> FW2

I did upgrade the system and still issue remain the same.

CARP issue faced version of OPNsense 24.1 and 24.1.5_3-amd64

General Log file that we receiving both machines,

2024-04-17T23:46:57   Notice   opnsense   /usr/local/etc/rc.syshook.d/carp/20-openvpn: Resyncing OpenVPN instances for interface (100.100.102.250).   
2024-04-17T23:46:57   Notice   opnsense   /usr/local/etc/rc.syshook.d/carp/20-openvpn: Carp cluster member " (100.100.102.250) (10@vmx0)" has resumed the state "MASTER" for vhid 10   
2024-04-17T23:46:53   Notice   opnsense   /usr/local/etc/rc.syshook.d/carp/20-openvpn: Resyncing OpenVPN instances for interface (100.100.102.250).   
2024-04-17T23:46:53   Notice   opnsense   /usr/local/etc/rc.syshook.d/carp/20-openvpn: Carp cluster member " (100.100.102.250) (10@vmx0)" has resumed the state "BACKUP" for vhid 10   
2024-04-17T17:47:42   Notice   opnsense   /usr/local/etc/rc.syshook.d/carp/20-openvpn: Resyncing OpenVPN instances for interface (100.100.102.250).   
2024-04-17T17:47:42   Notice   opnsense   /usr/local/etc/rc.syshook.d/carp/20-openvpn: Carp cluster member " (100.100.102.250) (10@vmx0)" has resumed the state "MASTER" for vhid 10   
2024-04-17T17:47:38   Notice   opnsense   /usr/local/etc/rc.syshook.d/carp/20-openvpn: Resyncing OpenVPN instances for interface (100.100.102.250).   
2024-04-17T17:47:38   Notice   opnsense   /usr/local/etc/rc.syshook.d/carp/20-openvpn: Carp cluster member " (100.100.102.250) (10@vmx0)" has resumed the state "BACKUP" for vhid 10

So, can anyone help me out to how to resolve this issue ?

Thanks,
Athisesan R

 
#8
Hi Team,

Greetings.,

I am trying to integrate the MS-AD server for OpnSense LDAP and integration got success also able to login as single user. in the meantime, trying group OU where the all the users are mapped getting login user issue.

"Permission are allowed to all gui and ssh also authentication allowed both ldap and localusers"

I have checked synchronize groups, constraint groups, Automatic user creation from LDAP server integration.

Login scenarios post LDAP success,
1. Induvial User logins - working
2. Group User logind - not working
3. Additional, group user login works if induvial user logged in atleast one time and get disabled or unused.

Thanks,
Athisesan R


#9
Hi Folks,

I am curious to understand does OpnSense support 3rd party security scans such as Rules, vulnerability related.

I'm great if any existing forum extended the same narrow.

example, AlgoSec, LogRhythm and QRader etc.

Thanks,
Athisesan R
#10
Greetings,

I was curious if there was a way to add firewall rules from the command line/console?
Apologies if this has been answered elsewhere, however I could not find anything through my forum search.

Version: OPNsense 24.1.4-amd64

Regards.
Athisesan R
#11
Hi Team,

We are facing HA SYNC issue between the two OpnSense VM Firewall post latest patch upgrade from 24.1.3 to 24.1.4

Below checks are verified,
- HA users and Credentials and authorizations are same on both firewall.
- Firewall Rules are allowed.
- Able to reach and SSH one to one VM using HA nics configured IPs and logins.

Looking expediate answer or solution to be checks on shell level.

CLI Error below,
hasync@TR-DZM-NWENG-FW02:/usr $ local/etc/rc.filter_synchronize
send >>>
Host: 172.16.0.1
User-Agent: XML_RPC
Content-Type: text/xml
Content-Length: 117
Authorization: Basic aGFzeW5jOlRhdGFAMTIz
<?xml version="1.0"?>
<methodCall>
<methodName>opnsense.firmware_version</methodName>
<params>
</params></methodCall>received >>>
error >>>

Thanks,
Athisesan R
#12
Hi Folks,

Anyone can help us find a way to remove or disable the auto-generated rules in Opnsense.

Having issues with LAN-to-WAN traffic even allowed ANY-ANY for test cases.

Also, I just tried to modify the /usr/local/etc/filter.lib.inc but its root cli ends with permission denied. -(hope root user will have all the rights to add, modify and delete.)
#13
Hi Folks,

I'm new to Opnsense and am about to check the possibility of permanent pf disability in Opnsense since we are facing issues like every gui change will get my pf enabled and the get manual enable using pfctl -d on the moments.

Thanks,
Athisesan R