Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - Julien

#601
Hi Guys,
is there is away to start the openvpn daemon without have to reboot the firewall ?
i keep click on Play but it won't start.

thank you
#602
16.1 Legacy Series / Re: From Cisco to OPNSENSE
July 12, 2016, 10:54:24 AM
i managed to fix it Franco,
one UP link for all switches,
tagged the VLANS on the up links of each switch et voila stuff works.
now the opnvpn is not starting . i have rebooted the firewall twice. but its not starting at all.
any suggestions why ?


thank you
#603
16.1 Legacy Series / Re: From Cisco to OPNSENSE
July 12, 2016, 07:24:34 AM
Quote from: Julien on July 11, 2016, 09:28:27 PM
Quoteon the em2 VLAN 8 have Wifi access point providing DHCP of VLAN 5. somehow the wifi users are not receiving a dhcp from the VLAN 5 over the em2.

This is an odd configuration. Both networks can't terminate on the same LAN unless you specify a bridge that you put on both VLANs, but it would probably be easier to terminate both as the same VLAN 5 or VLAN 8.

how i am supposed to get this working with the bridge ? can you please explain more ? this is new for me.
if i configure the the wifi devices to use vlan40 everything should works ?
so no rules are needed. everything should works out of the box ?
#604
16.7 Legacy Series / Re: [SOLVED] web interface SSL
July 12, 2016, 07:21:27 AM
thank you bart,
we know starts already using it for our exchange.
a big thank you man
#605
16.1 Legacy Series / Re: From Cisco to OPNSENSE
July 11, 2016, 09:28:27 PM
Quoteon the em2 VLAN 8 have Wifi access point providing DHCP of VLAN 5. somehow the wifi users are not receiving a dhcp from the VLAN 5 over the em2.

This is an odd configuration. Both networks can't terminate on the same LAN unless you specify a bridge that you put on both VLANs, but it would probably be easier to terminate both as the same VLAN 5 or VLAN 8.

Quotedo i have to create some firewall rules between the LANS or VLANS ?

LAN is a fully trusted zone so it doesn't need extra rules. This doesn't apply to any other OPTX interface, which needs manual pass rules in order for their traffic to reach their destination.

Quotealso VLAN 9 is a Guest VLAN and want it to be restricted from accessing the rest of the network. which rules i am supposed to create in order to get this fixed ? should i create on each VLAN a Block Rules , Source VLAN  Destination VLAN50 ?

Yes. Exactly the reason why OPTX do not have default allow rules. You add your access rules and/or restriction rules in their respective firewall rule tab to specific other interfaces.


Cheers,
Franco
#606
16.1 Legacy Series / Re: From Cisco to OPNSENSE
July 11, 2016, 09:26:08 PM
i have installed the opnsense on production
hope someone can help me here, which rules need to be created.
on the em0 : i have VLAN 4.5.6 and on the em2 i have VLAN 7.8.9 on each interface of the VLANS and LAN there is allow rule to any.
on the em2 VLAN 8 have Wifi access point providing DHCP of VLAN 5. somehow the wifi users are not receiving a dhcp from the VLAN 5 over the em2.
do i have to create some firewall rules between the LANS or VLANS ?

also VLAN 9 is a Guest VLAN and want it to be restricted from accessing the rest of the network. which rules i am supposed to create in order to get this fixed ?

thank you guys
#607
16.7 Legacy Series / Re: [SOLVED] Country Blocks
July 11, 2016, 05:22:34 PM
thank you Franco.
do you guys have some manual for this IP GEO ?
i would appreciate it
#608
16.1 Legacy Series / Re: From Cisco to OPNSENSE
July 11, 2016, 05:21:08 PM
Thank you Franco.
i am going to start the migration soon.
i'll keep you posted in case i have some difficulties.
#609
16.7 Legacy Series / Re: web interface SSL
July 11, 2016, 01:30:28 AM
Thank you for your answer Jan,
the firewall is not facing the internet, and the access to the firewall is always over the LAN or VPN.
using the self sign certificate gonna be a issue for the security ?
#610
this fixed,
today i've received a update 73 patches, everything is back to normal.
i thought i was on the 16.7 but i am on the 16.1
#611
16.7 Legacy Series / Re: Cash error
July 10, 2016, 04:25:16 PM
this fixed .
after the today update everything is back to normal after reboot.
#612
16.7 Legacy Series / [SOLVED] Cache error
July 10, 2016, 03:25:53 PM
Hi Guys,
i've configured web proxy on a hardware with 120SSD disk,
almost every website i am trying to open it pop's up with the warning.
is the below error a cashing error or a proxy bug ?

The following error was encountered while trying to retrieve the URL: http://www.domain.com

Access Denied.

Access control configuration prevents your request from being allowed at this time. Please contact your service provider if you feel this is incorrect.

Your cache administrator is webmaster.
#613
Hi Guys,
i have lost the netflow Explorer after my hardware reinstalled .
https://docs.opnsense.org/manual/how-tos/netflow_exporter.html
my hardware is a A10
is it some kind of plug in that need to be installed ?

#614
16.7 Legacy Series / [SOLVED] web interface SSL
July 09, 2016, 03:59:45 PM
Hi Guys,
is it possible to create a trusted certificate with the firewall FQDN on it ?
so when the users go to the http://FQDN or https://FQDN will be secure signed.

thank you
#615
16.7 Legacy Series / [SOLVED] Country Blocks
July 09, 2016, 12:24:50 AM
Hi Guys,
we got a lot of chines, Russian Deny attempt in the firewall.
i want to block those attempt .
i found this tutorial https://docs.opnsense.org/manual/how-tos/ips-geoip.html
the issue i have now is the firewall doesn't have a HDD but a 64GB SD.
is this even still possible or the IP GEOIP need right to writ to the SD which is not possible with SD ?
thank you