OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • Profile of FreeMinded »
  • Show Posts »
  • Messages
  • Profile Info
    • Summary
    • Show Stats
    • Show Posts...
      • Messages
      • Topics
      • Attachments

Show Posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

  • Messages
  • Topics
  • Attachments

Messages - FreeMinded

Pages: [1]
1
24.1 Legacy Series / Re: Update with crowdsec Plugin
« on: November 14, 2024, 05:26:51 pm »
For my understanding: Is this issue something that has to be solved on the crowdsec side or on the OPNsense side?
Is there an open issue on either side? I could not find any yet.

2
24.1 Legacy Series / Re: Update with crowdsec Plugin
« on: November 13, 2024, 09:43:36 am »
I can confirm the issue. It happend to me again while updating from 24.7.5 to 24.7.8
The first part of the update ran fine and firewall rebooted, it got stuck while updating the plugins
Trying to stop or disable crowdsec from the GUI doesn't do it. had to use
Code: [Select]
kill -9

3
23.7 Legacy Series / Re: Web GUI PR_CONNECT_RESET_ERROR when accessed over VPN
« on: November 07, 2023, 12:38:43 pm »
I downgraded to 23.7.7 Web GUI works again over WireGuard VPN.

4
Virtual private networks / Re: Restart Wireguard after WAN Interface gets ready
« on: November 07, 2023, 12:36:12 pm »
I downgraded from OPNsense 23.10_2 (business) to 23.7.7_3 (community). Now the WireGuard tunnels come up automatically again on reboot.

If I can help with finding the underlying issue, let me know how.

5
23.7 Legacy Series / Web GUI PR_CONNECT_RESET_ERROR when accessed over VPN
« on: November 07, 2023, 12:16:18 pm »
Yesterday, probably since the Update to OPNsense 23.10_2 b9c704d69 (Business Edition), I started getting PR_CONNECT_RESET_ERRORn in the browser when accessing the Web GUI through VPN.

The Web GUI works properly when accessed localy.

The Web GUI Log ist full of
Code: [Select]
2023-11-07T12:13:30 Error lighttpd (/usr/obj/usr/ports/www/lighttpd/work/lighttpd-1.4.71/src/mod_openssl.c.3310) SSL: -1 5 40: Message too long

I use a WireGuard Tunnels to manage OPNsense Firewalls.

No sure it's connected to the update, but I don't see that behavior on systems with OPNsense 23.10

Any ideas?

6
Virtual private networks / Re: Restart Wireguard after WAN Interface gets ready
« on: November 06, 2023, 10:27:02 pm »
Quote from: franco on November 06, 2023, 03:17:01 pm
For FQDN based endpoints there will be another fix for 23.7.8. WireGuard is plug and play like that :D

Nice! What about the business edition? I have the feeling that I didn't have this issue before switching to the business edition but currently don't have a quick way to verify.

7
23.1 Legacy Series / Re: Port forwarding / Firewall Destination Issue
« on: November 06, 2023, 10:24:36 pm »
Quote from: vpx on July 17, 2023, 03:14:38 pm
In the Lobby->Dashboard under Interfaces does it show the correct IP for WAN_PORT?

yes, it does.

8
Virtual private networks / Re: Restart Wireguard after WAN Interface gets ready
« on: November 06, 2023, 03:14:14 pm »
Quote from: malac on September 09, 2023, 01:46:07 pm
i monitore wireguard now via monit, works fine for me

Would you mind posting your Monit settings? I'm struggling setting it up correctly. Thanks in advance.

9
23.1 Legacy Series / Re: Port forwarding / Firewall Destination Issue
« on: July 17, 2023, 10:03:04 am »
I still think the WAN_PORT_address should point to the address on that interface, no matter what the subnet is. This does not seem to be the case.

10
23.1 Legacy Series / Re: Port forwarding / Firewall Destination Issue
« on: July 14, 2023, 08:01:38 pm »
It's the DHCP from the ISP. Init7 to be precise.

11
23.1 Legacy Series / Re: Port forwarding / Firewall Destination Issue
« on: July 14, 2023, 02:41:33 pm »
The Firewall rule was created (automatically by the NAT Port Forwading rule).

But looking at the WAN Interface again, I might have found the reason. I get IPv4 address x.y.z.237/24 assigned. So it's not a /32  but a whole /24 subnet range. Still the IP address on the interface is clear and WAN_FIBER_Port address should point to it.

12
23.1 Legacy Series / Port forwarding / Firewall Destination Issue
« on: July 14, 2023, 02:10:55 pm »
I'm a recent immigrant from the pfSense World and the following situation drove me crazy. I suspect a possible bug (or at least an unexpected behavior) and would be happy to be enlightened by a OPNsense guru if it's not.

I set up a Port Forwarding from my main WAN Interface (WAN_FIBER_Port) to a local network IP. As destination address I had WAN_FIBER_Port address set. All the traffic hitting the Firewall was being rejected by the default deny / state violation rule. The Logs showed the Firewalls Public IP as destination. After a while I realized that the rule does not apply.

It started to work when I set the destination to any. Later I tried manually setting the public IP or WAN_FIBER_Port net and both worked as well.

I was - coming from pfSense - expecting that WAN_FIBER_Port address would be the public IP which the interface gets by DHCP in this case. Somehow this does not seem to be the case. Interestingly WAN_FIBER_Port net works.

Is this intended behavior?

13
23.1 Legacy Series / Re: Unbound host override not resolving hostname with local/search domain
« on: June 27, 2023, 08:18:07 pm »
I finally found the error. I had an DHCP Option 43 configured from an earlier attempt which I had totally forgotten about. :-[

14
23.1 Legacy Series / Re: Unbound host override not resolving hostname with local/search domain
« on: June 25, 2023, 08:31:34 pm »
Thanks for your reply! It works in my pfSense but not with OPNsense. I just can't find where the difference is. So I'm looking for what I might have missed in the config.

15
23.1 Legacy Series / [SOLVED] Unbound host override not resolving hostname with local/search domain
« on: June 25, 2023, 07:13:51 pm »
Hi, I'm an immigrant from the pfSense country and fairly new here. I got around with OPNsense very well so far, but I just can't get my head around why the host overrides are not working as expected. I tried everything, googling, searching this forum, chatgpt... to no avail.

I use Unifi network devices with a central Unifi Controller which is somewhere else and accessible through a WireGuard VPN. In order to register Unifi devices with the controller the lookup the hostname "unifi" in the local network which should resolve to the IP of the controller. I use the unbound default configuration (as far as I understand). The are their own network and there in a dedicated DHCP Pool.

I set the domain and search domain in the DHCP settings of the corresponding network. I created a host override for unifi.mydomain.tld.
I can resolve it as long as I use the FQDN, but not with the hostname only I get errors. Depending on how I query NXDOMAIN, SERVFAIL or No answer.
It seems like it is not using or respecting the search domain.

Has anyone an idea what I am missing to make this work? I can certainly post more details if required.

Pages: [1]
OPNsense is an OSS project © Deciso B.V. 2015 - 2024 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2