Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - JdeFalconr

#16
19.7 Legacy Series / Re: System Reboots Itself!
September 21, 2019, 04:39:11 AM
Anyone? ::bump::
If you need more info I'm happy to provide it. I see historically there have been several threads about "Fatal trap 12: page fault" but most seem to do with not being able to boot which is not my situation.
#17
19.7 Legacy Series / System Reboots Itself!
September 20, 2019, 03:27:49 PM
Thanks in advance for your help. Newly-built system that looks to be rebooting itself randomly. I'm really not sure how to troubleshoot this. I don't see much in logs but one of the problem/crash reports comes up every time after this happens. Below is what at first looks to me like the possible cause. Help!!!

EDIT: From what I see there are some known issues with Apollo-lake-based chipsets. Do I need to do anything to get Opnsense working reliably with those or does the current software release (19.7) already incorporate those fixes?

(KHTML, like Gecko) Chrome/76.0.3809.132 Safari/537.36
FreeBSD 11.2-RELEASE-p14-HBSD  07680caafe9(stable/19.7) amd64
OPNsense 19.7.4_1 2da6de42b
Plugins os-dyndns-1.17 os-upnp-1.3
Time Fri, 20 Sep 2019 06:22:57 -0700
OpenSSL 1.0.2s  28 May 2019
PHP 7.2.22
dmesg.boot:
arp: 172.20.0.150 moved from 38:8b:59:24:9e:13 to 3c:28:6d:31:e1:7b on igb1


Fatal trap 12: page fault while in kernel mode
cpuid = 3; apic id = 06
fault virtual address = 0x100000000
fault code = supervisor read data, page not present
instruction pointer = 0x20:0xffffffff8300b260
stack pointer         = 0x28:0xfffffe01da5537c0
frame pointer         = 0x28:0xfffffe01da553810
code segment = base 0x0, limit 0xfffff, type 0x1b
= DPL 0, pres 1, long 1, def32 0, gran 1
processor eflags = interrupt enabled, resume, IOPL = 0
current process = 12 (swi4: clock (0))


My hardware:
ASRock J3455B-ITX (Intel J3455-based)
2x4GB DDR3-1600
120GB SATA SSD
PicoPSU 90W
Intel 82576-based 2x1GB NIC

EDIT: A bit more info from a more recent crash. I just wiped my SSD, reinstalled and then restored my prior config. It crashed again but got a bit more in the logs:

Fatal trap 12: page fault while in kernel mode
cpuid = 0; apic id = 00
fault virtual address = 0x7f00000000
fault code = supervisor read data, page not present
instruction pointer = 0x20:0xffffffff83006260
stack pointer         = 0x28:0xfffffe01da5537c0
frame pointer         = 0x28:0xfffffe01da553810
code segment = base 0x0, limit 0xfffff, type 0x1b
= DPL 0, pres 1, long 1, def32 0, gran 1
processor eflags = interrupt enabled, resume, IOPL = 0
current process = 12 (swi4: clock (0))
#18
I hope this post helps someone else out there having trouble achieving open NAT; I know it can be a bear for some people and it's a potentially frustrating technical issue for many users.

This is with both an XB1 console as well as the Xbox Console Companion app on my PC running. If you don't care about the Xbox Console Companion then you can omit those portions of the setup (personal computer alias, forwarding and firewall rules for TCP/UDP 60200). I didn't want to use upnp due to the security risks it poses (letting any LAN client open inbound ports automatically). I get that I'm effectively doing the same thing here but the difference is this approach limits the scope to just the Xbox and to specific ports. I did a bit of Google searching so some of the below suggestions (like the NAT reflection and the outbound NAT rule) were from what I found there. The rest was just following guides on port forwarding and the necessary ports to open. My selection of ports is based on https://www.bungie.net/en/Help/Troubleshoot?oid=13610#PortForwarding. Really when thinking about this what I mostly did was manually set up what upnp does automatically. I did note that when adding/changing just about any of the above rules I had to reset firewall states for the change to fully take effect (Firewall/Diagnostics/States Reset/check both boxes). I've attached screenshots of some of the relevant rules on my box for your own reference.

Here's what I did:

1. Aliases
XboxOneXPortForwardTCP: port 3074
XboxOneXPortForwardUDP: ports 88,500,3074,3544,4500,1200
XBoxOneX_Ports_TCP: ports 53,80,3074,7500:7509,30000:30009,443
XBoxOneX_Ports_UDP: ports 53,88,500,1001,3074,3544,4500,1200:1299
XboxOneX_IP: <private IP for my XB1X>
Manetheren: <private IP for my computer running Xbox Console Companion; sub it for yours>
TeredoPortForwardingGroup: port 60200

2. Port Forwarding Rules
I created a few port forwarding rules (see attached image) for the necessary TCP and UDP ports. Not mentioned on the Bungie Support page I linked above were those Teredo ports (TCP and UDP 60200) used by the Xbox Console Companion app. Important here was to ensure that NAT Reflection was enabled for those forwarding rules; that's an option in the NAT rule settings. I also chose the option to automatically create associated firewall rules for the forwarding rules.

3. Firewall Rules
I created rules (see attached image) to open all XB1X TCP and UDP ports for the XB1X IP address only. The rest of the necessary rules were auto-created.

4. Outbound NAT Rule
An outbound NAT rule (see attached image) was required for the XB1X. The key setting there is to check the "Static Port" box.


What you have to do to get this working for you:
--You must assign a static IP address to your Xbox One and if you want to use Xbox Console Companion a static IP to your PC. I chose to do that with DHCP reservations.
--Substitute the alias IP addresses "Manetheren" and "XboxOneX_IP" above for the respective IPs of your devices.
--Set up the above things. As a reminder you will not need to create WAN firewall rules for any of the port forwarding rules that are set to auto-create associated firewall rules.
#19
Tutorials and FAQs / Re: XboX One and NAT
September 15, 2019, 10:10:31 PM
Quote from: blackdwarf on June 02, 2018, 08:52:01 PM
Short Version:


  • Give your XB1 (or PS4, same process required) a static IP
  • Install/Enable UPNP
  • Set "User Specified Permissions" to "allow 88-65535 10.1.1.x/32 88-65535", where 10.1.1.x is the static ip of the XB1/PS4
  • Firewall>NAT>Outbound - Set to Hybrid/Manual rule generation
  • Create a rule with the following set: "Source Address - Single Host or network - 10.1.1.x" & "Static Port - Checked"
  • Do a hard-reboot of your XB1/PS4 (shutting it down and pulling the power for 2 mins will do"

You should now have a NAT Type of Moderate (XB1), or Type 2 (PS4).

UPnP is a pretty bad security risk unless there's been some recent mitigation I'm not aware of. It effectively lets any LAN host open whatever port they want on the firewall. I've run without UPnP for years using Meraki gear and have open NAT on two Xbox One's, only specifying the needed ports for the devices. OPNSense is also a stateful firewall just like my MX64; there's no reason why you can't get open NAT without effectively putting your XB1 in a DMZ and without UPnP.
#20
Thanks in advance for your help.

Not quite sure what to make of this; when I went through the setup process and the live installer (19.7 VGA image) it had no problem detecting a PCIE NIC I have (based on the Intel 82576 chipset; yes it's on the HCL). However once I installed OPNSense it lost track of the NIC and no longer detects it at all. Based on https://www.freebsd.org/cgi/man.cgi?query=igb&sektion=4&manpath=freebsd-release-ports I'm not sure if this driver is auto-loaded or if I have to load it myself somehow. If the latter I have no idea whatsoever how and I don't see anything about it in documentation. I can see some lines about the devices in logfiles so I know they're being detected, I just don't understand why they don't show up. If I get into shell as root and do an ifconfig this NIC isn't listed (unsurprisingly).

I'll freely admit now that I know next to nothing about Linux, in case you couldn't tell already. Also in case it helps I have an Intel J3455 board (ASRock J3455B-ITX).

After some Google searching I tried editing my /boot/loader.conf/local file to add the line "if_igb_load="YES"" per the above website but that didn't help. I've since removed that file (as it didn't exist before I created it).

A few lines of logfile I find when I search for the interface name ("igb"):

QuoteSep 13 05:02:16   kernel: Module pci/igb failed to register: 17
Sep 13 05:02:16   kernel: module_register: cannot register pci/igb from kernel; already loaded from if_igb.ko
Sep 13 04:59:38   kernel: Module pci/igb failed to register: 17
Sep 13 04:59:38   kernel: module_register: cannot register pci/igb from kernel; already loaded from if_igb.ko
Sep 13 10:23:19   opnsense: /usr/local/etc/rc.bootup: Warning! dhcpd_radvd_configure(auto) found no suitable IPv6 address on igb1
Sep 13 10:23:13   opnsense: /usr/local/etc/rc.bootup: Accept router advertisements on interface igb0
Sep 13 10:23:13   opnsense: /usr/local/etc/rc.bootup: The command '/sbin/dhclient -c '/var/etc/dhclient_wan.conf' -p '/var/run/dhclient.igb0.pid' 'igb0'' returned exit code '1', the output was 'igb0: no link .............. giving up'
Sep 13 10:23:00   kernel: igb1: netmap queues/slots: TX 4/1024, RX 4/1024
Sep 13 10:23:00   kernel: igb1: Bound queue 3 to cpu 3
Sep 13 10:23:00   kernel: igb1: Bound queue 2 to cpu 2
Sep 13 10:23:00   kernel: igb1: Bound queue 1 to cpu 1
Sep 13 10:23:00   kernel: igb1: Bound queue 0 to cpu 0
Sep 13 10:23:00   kernel: igb1: Ethernet address: <MAC ADDR>
Sep 13 10:23:00   kernel: igb1: Using MSIX interrupts with 5 vectors
Sep 13 10:23:00   kernel: igb1: <Intel(R) PRO/1000 Network Connection, Version - 2.5.3-k> port 0xe000-0xe01f mem 0x92000000-0x9201ffff,0x91400000-0x917fffff,0x92040000-0x92043fff at device 0.1 on pci1
Sep 13 10:23:00   kernel: igb0: netmap queues/slots: TX 4/1024, RX 4/1024
Sep 13 10:23:00   kernel: igb0: Bound queue 3 to cpu 3
Sep 13 10:23:00   kernel: igb0: Bound queue 2 to cpu 2
Sep 13 10:23:00   kernel: igb0: Bound queue 1 to cpu 1
Sep 13 10:23:00   kernel: igb0: Bound queue 0 to cpu 0
Sep 13 10:23:00   kernel: igb0: Ethernet address: <MAC ADDR>
Sep 13 10:23:00   kernel: igb0: Using MSIX interrupts with 5 vectors
Sep 13 10:23:00   kernel: igb0: <Intel(R) PRO/1000 Network Connection, Version - 2.5.3-k> port 0xe020-0xe03f mem 0x92020000-0x9203ffff,0x91c00000-0x91ffffff,0x92044000-0x92047fff at device 0.0 on pci1
#21
Quote from: opnfwb on September 09, 2019, 05:10:50 AM
Quote from: JdeFalconr on September 09, 2019, 04:51:39 AM
Thank you! I'm liking where you're going. Could you kindly point me towards the PicoPSU you purchased? There are quite a few out there - some rather expensive it looks like - and I'd want to make sure to get the right one.

I purchased a completely overkill 120w PicoPSU here: http://www.mini-box.com/picoPSU-120-120W-power-kit
I bought it because at the time with a coupon code it was the same cost as a lesser 90W model. You could easily get away with a 90W on this system and be fine.

You'll have to weigh other costs. For instance, I already had RAM, a case, and some spare SSDs laying around. I also had an assortment of dual and quad port NICs. So for me, I made more sense to just get a board and PicoPSU and put everything together. If you have to buy all of those components, the Fitlet2 is a compelling choice because it's just plug-and-play out of the box.

Either way, the J3455 is an excellent and powerful router platform.

Thank you! That's very helpful. Yeah I'm thinking I agree with you about the J3455. I'm kind of amazed at how much a Mini-ITX case costs; they're not too far off from the cost of the motherboard itself, not to mention that PicoPSU.

Speaking of the power supply, how did you calculate the power needs and know that you could get by with just the 90W version? I'm not questioning you, rather I'm just trying to understand. 
#22
Quote from: 2Gnu on September 09, 2019, 01:03:58 AM
Another option to consider is the Fitlet2.  This is what I'm using for OPNsense.  https://www.amazon.com/fitlet-fitlet2-J3455-Barebone/dp/B078V6MT9D
More money than the link in your post, to be sure.
Differences between the CPUs:
http://cpuboss.com/cpus/Intel-J3455-vs-Intel-Celeron-J1800
The J3455 also has the AES instruction set which I wanted for OpenVPN.  The J1800 does not.
https://ark.intel.com/content/www/us/en/ark/products/78866/intel-celeron-processor-j1800-1m-cache-up-to-2-58-ghz.html
The Fitlet2 carries a 5-year warranty and their support has been excellent.
Quiet, runs cool and has been reliable.
Sounds like a commercial but just a happy home user, hoping it helps someone else.

Thank you, I appreciate the info very much. I thought I'd checked that processor for AES-NI but as it turns out I was looking at the wrong chip's specs. So much for that cheap one. I've heard a number of references to Fitlet2 so that looks like a good possibility, albeit more expensive as you mentioned.
#23
Quote from: opnfwb on September 09, 2019, 03:16:39 AM
Another vote for the J3455 platform. I purchase an Asrock j3455m board, a PicoPSU, and a quad port Intel NIC. The system idles around 8-10watts and runs without any fans. It also is compatible UEFI booting OPNsense.

Here's a link to the board I purchased: https://asrock.com/mb/Intel/J3455M/

Thank you! I'm liking where you're going. Could you kindly point me towards the PicoPSU you purchased? There are quite a few out there - some rather expensive it looks like - and I'd want to make sure to get the right one.
#24
First and foremost apologies for what I'm sure is an often-asked question. I don't see any consolidated source of hardware info around here like a sticky post.

I'm looking to build a new OPNSense box for home use in the spectrum between the Reasonable and Recommended spec (https://docs.opnsense.org/manual/hardware.html, probably tending towards Recommended. Low energy use is preferred, otherwise I'd be using an old PC. Like everyone I want to eat my cake and have it too and want costs at a minimum.

Something like this appliance (https://www.amazon.com/Firewall-Micro-Appliance-Gigabit-Barebone/dp/B01KLECNDG/ref=sr_1_9?keywords=micro+firewall+appliance&qid=1567974011&s=gateway&sr=8-9) looks perfect. However despite reviews on that one I'm wary of no-name devices unless the community can vouch for them. Does anyone have a similar recommendation? The Zotac CI325 looks decent but it has extra bells and whistles and a higher electrical footprint as a result.

Thanks for your help.

#25
Hardware and Performance / T5740 Performance?
August 04, 2016, 01:16:45 AM
I'm looking to moving to OPNSense from M0n0wall and need to purchase some updated hardware. I've heard great things about the ability of the HP t5740 to run pfSense. However I don't see much about it running OPNSense. Do any of you use the t5740 for your hardware and, if so, how does it treat you?

My reason for caution is that the CPU meets the requirements in terms of frequency (1.6Ghz) but it's single-core. This device would be used in a home environment with just a few users on a ~50mbps connection so it's not a super-demanding situation. Otherwise this device fits my needs perfectly for an electricity-saving, relatively small and quiet appliance. Obviously I would have to buy the expansion module and add a dual-port Intel NIC. All together I hope to only spend around $100 on the whole setup.

Thanks for the help.