Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - xofer

#31
17.1 Legacy Series / 17.1.1 ipsec reneg delays
February 22, 2017, 01:44:53 PM
I have configured site to site ipsec from one opnsense to another and clients have intermittent connection issues through the connection. At some point the tunnel drops and renegotiation is not successful for several minutes.

Going through the log, i stumbled upon this:
peer A:
Feb 22 14:30:02 peerA charon: 06[IKE] sending cert request for -----cert information deleted as this is a public forum----
Feb 22 14:30:02 peerA charon: 06[IKE] sending cert request for -----cert information deleted as this is a public forum----


peer B:
Feb 22 14:30:02 peerB charon: 12[IKE] received 2 cert requests for an unknown ca



Ipsec negotiation succeeds 2 minutes(!) later.

The strange thing is that ipsec is configured to use Mutual PSK, not certificates. The certificates in question are used for OpenVPN clients on peer A.


Why does ipsec use these certificates at all?
Am I right to suspect that this is the cause for the delay that one peer tries to authenticate using these CAs?
#32
17.1-re has been up for 5 days now without a single watchdog timeout in the logs.
Even the occasional non-fatal timeout i used to have from time to time are gone now.

I vote for this realtek driver to be included in the next release.
#33
Quote from: the-mk on February 10, 2017, 03:32:52 PM
Quote from: xofer on February 10, 2017, 03:20:45 PM
...
17.1 upgrade lost the console with my VGA monitor though - neither VGA or EFI works. But i'd rather live without a console than without Internet :-)
take a look at System>Setting>Administration - there is a setting named primary console - you might want to switch to VGA console and reboot

Well, as i said - neither VGA or EFI works - where do you suppose I changed from one to another?

But I don't actually want to bring new topics to this thread. If we can get rid of those pesky re0 watchdog timeouts on Zotac ci323, I will be over the moon and don't care that much about the console. Or I will drag an HDMI monitor to that particular room and try that.
#34
Just put 17.1-re on one of my ci323 boxes that seemed to do the watchdog timeout thing on a weekly basis. Lets see if it lasts longer now.

17.1 upgrade lost the console with my VGA monitor though - neither VGA or EFI works. But i'd rather live without a console than without Internet :-)
#35
Seems that compiling a different realtek driver might help:
https://forum.pfsense.org/index.php?topic=103841.msg684436#msg684436
#36
Same here.
kernel: re0: watchdog timeout endlessly and only power cycle helps.
Seems to be a trouble with the re(4) driver and/or Zotac hardware or combination thereof.

At the same time the system itself is responsive, you can log in from terminal, the error is logged, etc. And it never seems to be re1 for us, no matter which is assigned to LAN or WAN.

The most baffling thing is that its totally random. We had one crashing regurarly at one office. At the same time we have two ci323 working in different locations and one of them has never crashed in two months and the other one crashed several times for a week and now has not done it in more than month or so. Does not seem to be related to traffic intensity.

Generally disabling HW acceleration etc did not seem to help us. Temp also not an issue (cooled room, well below 20C). As the box might work for days, its pretty hard to diagnose.

After a couple of weeks we decided to replace ci323 with a different mini-pc that has 2 intel NICs and have had no trouble since.
#37
16.7 Legacy Series / OpenVPN certificate CRL automation
January 05, 2017, 05:19:58 PM
We are signing our VPN user certificates outside OPNsense box.

Where does OPNsense save the CRL that is imported through the web gui?

Can I upload the CRL to OPNSense box without importing it through the web GUI? For instance with scp. Or have OPNsense pull the CRL from another server at an interval?
#38
Quote from: sidney_v on December 08, 2016, 07:16:23 PM
xofer : you just copy /var/etc/dnsmasq-hosts to /etc/hosts ? do you have an example of /var/etc/dnsmasq-hosts ?
No, i appended it.
Basically what i did:
cat /var/etc/dnsmasq-hosts >> /etc/hosts
and then restarted dnsmasq

They are the same format so it worked. Be aware that it is strictly a workaround, not a solution! Web configurator still writes things to /var/etc/dnsmasq-hosts and these changes will not reach /etc/hosts and also /etc/hosts might be overwritten at some other point (I don't really know when this is created - mayb on boot, maybe if you change your nameserver or host name).

Haven't had a chance to test patch f31e5560 - and cannot test at the moment (70 people using the router right now...). But if it solves the problem of dnsmasq loading the correct file this is by far better than mucking about with the files. I just did a quick hack to not get phonecalls in the morning.
#39
Quote from: franco on December 08, 2016, 08:15:01 AM
Not my most favourite solution, but more reports came up. Run this from the console and restart/reboot:

# opnsense-patch cd6cdba1b

https://github.com/opnsense/core/commit/cd6cdba1b


Cheers,
Franco
Got hit by this now. Upgraded and none of the dns overrides work.

dnsmasq-hosts is readable:
-rw-r--r--  1 root  wheel  475 Dec  8 17:41 /var/etc/dnsmasq-hosts

Tried the patch above, but still nothing.

Its as if dnsmasq does not load /var/etc/dnsmasq-hosts at all. At the same time it DOES read /etc/hosts (and logs this):
Dec  8 17:41:35 mono dnsmasq[89726]: read /etc/hosts - 2 addresses

So as a workaround i just appended the contents of /var/etc/dnsmasq-hosts to /etc/hosts and restarted dnsmasq so my users will not kill me in the morning...
#40
Factory reset? Its a PC.
Installed on no different SSD, still same. Does not report any errors on the OPNsense itself. I would assume that memory errors would show up in dmesg?
#41
I put a testing rig together from random pieces:
- Intel(R) Atom(TM) CPU D525 @ 1.80GHz (4 cores)
- 4GB RAM
- 120GB SSD
- 2x RTL8169 (yeah, i know they suck, but...)

There is no load to speak of, only me connected to it and trying to configure.
When I press restart on either DHCP service or DNS Forwarder service ping times out from the LAN side for about 20-30 seconds and then its back on. All traffic from LAN to OPNsense is stalled for this period.
#42
I have discovered, that no configuration change/apply is actually needed. Just restarting the DHCP or DNS Forwarder service takes the LAN interface totally down for ~20 seconds. Is this normal for OPNsense or is it just me?
#43
Hi,

i'm testing the opnsense for the first time. I noticed the LAN goes down (no ping, etc) even on the most minute changes.
For instance when creating a new DNS Forwarder host override and applying settings results in the router being offline for ~20 seconds. Same when adding a static DHCP mapping.

Is this normal for opnsense? Does it always take the interface down in addition to restarting dnsmasq on those changes.