Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Topics - aleco

#1
Hi everyone, I've been using OPNsense for about a month, so I'm still a new user. Apologies if I'm missing something obvious.

I'm looking for the best way to regularly back up the OPNsense configuration (including plugin configs like Zenarmor) to my local NAS, preferably via SMB. I noticed there's an option to back up to Google Drive, and there are plugins for Nextcloud and Git, but I don't have a Git or Nextcloud server. My goal is to backup the OPNsense config to my NAS, which I already back up to the cloud (encrypted).

Does anyone have a script or cron job that achieves this? I'm surprised there's no built-in option in the GUI for local NAS backups, and unfortunately, I'm not familiar with writing shell scripts (especially when it comes to adding error alerts).

Any advice or examples would be greatly appreciated. Thanks in advance!
#2
Hi all,

I've recently set up Zenarmor and noticed an issue where it logs traffic with 10.x.x.x source IPs, but none of this appears in OPNsense. My LAN runs on the 192.168.1.x subnet with around 20 devices (mostly Apple and IoT, all with fixed IPs). I don't have any 10.x.x.x networks configured in OPNsense, just an unused 192.168.20.x VLAN and an unused 192.168.33.x WireGuard interface. I also don't think there's anything unusual in my firewall rules.

The Zenarmor Live Sessions show proper device hostnames, but in the "Src hostname" column I'm seeing randomised 10.x.x.x IPs instead of the 192.168.1.x IPs the devices really have.

Could blocking DNS over HTTPS/TLS be causing devices to randomize their source IPs in the 10.x.x.x range for DNS requests?

I'm running OPNsense 24.7.4 on a Protectli device with Unbound DNS (DNS over TLS enabled, using Cloudflare, Google, and Quad9). Zenarmor is installed as a plugin and only monitors the LAN interface (igc1). My switch is from UniFi, and I use a Linksys Velop mesh system in bridge mode, with the child node connected wirelessly.

The problem is that Zenarmor's reports are nearly unusable. None of my real devices show up, and both the top local and remote hosts are filled with random 10.x.x.x IP addresses. The Egress New Connections Heatmap is also completely populated by these 10.x.x.x IPs.

I initially set Zenarmor to block DNS over HTTPS/TLS in its default policy, but the 10.x.x.x traffic didn't appear immediately. I've since turned off the DNS over HTTPS/TLS block to see if it resolves the problem, but it hasn't yet. I'm wondering if it might take hours or days for my devices to realize that DNS over HTTPS/TLS isn't blocked anymore. The 10.x.x.x issue appeared around the same time I upgraded from the free to the home version of Zenarmor.

I also tried switching to the emulated netmap driver, but that didn't help either. And a block rule on OPNSense blocking all traffic from 10.0.0.0/8 doesn't show a single hit. So why is Zenguard mainly seeing traffic to and from 10.x.x.x?

Any suggestions on how to troubleshoot this?
Thanks for your help!

EDIT: Here is Reports > Facts for the past 30 minutes:
Connections: 2.670
Bytes Uploaded: 5.8 MB
Bytes Downloaded: 128.8 MB
Packets Uploaded: 32.258
Packets Downloaded: 162.663
Active Users: 1
Total Authenticated Users: 0
Unique Local IP Addresses: 2.670
Unique Remote IP Addresses: 2.670
Unique Apps: 55
Unique Local Devices: 16


Isn't that weird? Exactly 2.670 connections, unique local IP addresses (!) and unique remote IP addresses? In 30 minutes, with only 16 local devices?
#3
Hi OPNsense community,

I'm a complete novice and could really use some help setting up my Protectli Vault preconfigured with OPNsense. It was just delivered, but I'm stuck trying to connect. I've searched everywhere and can't find clear steps for the initial setup. Here's what I've tried so far:

1. Ethernet Connection (Firewall to Router):
I connected Port 1 of the firewall to my Linksys Velop router. The firewall was assigned the IP 192.168.1.201, and the router shows an OPNsense device at this IP. However, trying to SSH (ssh root@192.168.1.201) results in a timeout.

2. Web Interface Access:
I attempted to access the web UI at the IP the firewall was assigned via https://192.168.1.201, but no luck.

3. Serial Console (via CoolTerm):
I used the provided COM port cable, connected it to my MacBook Air, and used CoolTerm. The settings are 115200/8-N-1, and it shows the RTS and DTR indicators as active (green). While it shows I'm connected and the byte count increases when I press Enter, the screen remains blank. Other baud settings (e.g. 9600) didn't help either.

4. Direct Ethernet Connection (Mac to Firewall):
I connected my MacBook Air via a Belkin 2,5G Ethernet dongle to Port 4 of the firewall, disabling all other network interfaces in macOS. My Mac assigned a self-assigned IP (169.254.147.18), and I still couldn't reach the firewall.

Unfortunately, I don't have an HDMI screen or a USB keyboard to connect directly to the device. I've taken a day off to set up the firewall, but I can't even connect to it. I would greatly appreciate any advice on what I should try next.

Thanks in advance for your help!
#4
Hi everyone,

I'm new to OPNSense and currently using a Linksys mesh router/AP system for my home network. I'd like to change my setup so that the routing and firewall tasks are handled by OPNSense on a dedicated Mini PC, instead of relying on my Wi-Fi hardware for these functions. My plan is to switch the Linksys system into bridge mode and later replace it with UniFi access points.

I'm looking for a budget-friendly Mini PC with passive cooling, low TDP (6-15W), and preferably 2x Intel NICs (as I've read Realtek can cause issues, is that true?). While the official OPNsense hardware is great, it's unfortunately too expensive and bulky for my needs. I need something very compact, as I plan to hide it somewhere in my living room.

Regarding the CPU, I assume the Intel N100 is a good choice, but I've also heard that Ryzen 3 U-series chips might be suitable. However, I'm a bit overwhelmed by all the CPU options and naming conventions, so any guidance here would be helpful.

I don't need Wi-Fi or many ports since I'll be running this Mini PC headless as a firewall. My main concern is being able to consistently connect to it from my MacBook. If that becomes an issue, I might need to buy a small display and keyboard as well.

The device should handle OPNSense, including VPN and ad-blocking, for up to 3 people. Additionally, I have various IoT devices that may generate some internet traffic, and I might want to set up a second VLAN for these devices and guest access.

I've been reading about various brands, such as Acemagician, ASUS, Fitlet, Glovary, Mele, Minisforum, Minix, Neosmay, Odroid, Protectli, Qotom, Topton, XCY, and Zotac. However, I have no experience with these brands and am unsure which ones offer reliable, fanless Mini PCs with 2.5Gbps Intel NICs and modern CPUs. I'd greatly appreciate any insights on which brands are trustworthy and which models you would recommend.

Any recommendations or experiences would be greatly appreciated. Thanks in advance!

–––
UPDATE: Here's what I purchased: https://forum.opnsense.org/index.php?topic=42462.msg213758#msg213758