Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Topics - dcol

#101
General Discussion / Forum categories
November 20, 2017, 04:46:27 PM
I suggest two new forum categories
IDS/IPS  and  Feature Requests
Feature Requests get lost within other categories. Or maybe just use Github for those.
IDS/IPS is an animal all its own and deserves its own category.
#102
Intrusion Detection and Prevention / IDS block time
November 20, 2017, 04:06:52 PM
I just realized that OPNsense has a set time to release a block for IDS. What is this time period and is it possible to make it adjustable or change the value from the shell?

Here is a screenshot from the console, but not sure if this is IDS related. If not, then what does this message mean?
#103
I am using the IPS with the LAN interface and everything seems to work normally.
When I use the WAN Interface with IPS, with or without the LAN, I get constant up and down of the WAN link in 3-5 second intervals. When IPS is disabled the WAN link is stable. Tried restarts and even a reinstall of OPNsense.
Both WAN and LAN are on the same quad Intel NIC. Even tried to isolate the WAN on its own Intel i210T1 with same results.
Only custom setting is tunables - kern.ipc.nbmclusters=1000000
Any ideas?
#104
General Discussion / One WAN Multiple IP's
November 16, 2017, 10:31:17 PM
In an environment with one gateway and 4 WAN public IP's, from a performance aspect, would it be better to use virtual IP's and NAT to each server on it's own interface. Or one LAN interface using NAT 1:1 directing each public IP to a server.
#105
17.7 Legacy Series / IDS Alerts
November 16, 2017, 12:45:45 AM
Hello all,
I never see any ET-Open alerts unless I add the WAN IP in the Home networks (HOME_NET).
I read that this is just the 'noise' that you see. Like in other firewalls.
Do I actually need to keep the WAN IP in the Suricata HOME_NET or are these triggers not making it through the WAN anyway, which is why I do not see them in alerts when the WAN IP is not included in HOME_NET.

Just think I need some clarification on this. Thanks
#106
17.7 Legacy Series / Disk space size
November 15, 2017, 05:11:58 PM
I notice that OPNsense, when doing a new install, only assigns a portion of the hard disk, or in my case SSD, to the UFS. I used guided installation. Manual Installation locks up in UEFI mode

When I installed on a 64GB SSD it only allocated 28GB to UFS
When I installed on a 128GB SSD it only allocated 76GB to UFS

Why is that and is there a way to expand it to use the full capacity?

[UPDATE] I guess this extra space is used for the swap slice. Not sure what the swap space is used for or if we need it.
#107
General Discussion / Configuration Cloud Backup
November 15, 2017, 12:33:32 AM
The OPNsense doc https://docs.opnsense.org/manual/how-tos/cloud_backup.html is way out of date and not applicable anymore.
Are there any more recent guides anywhere, or can someone post in this thread the steps.
#108
17.7 Legacy Series / Trouble with SMTP notifications
November 14, 2017, 12:45:25 AM
Trying to setup notifications for the first time and I have an issue with authentication.
Two email servers cannot verify the user/password. I run these email servers and know how to set them up. Using an account that has ports 2525 (Non-SSL), and 465 (SSL) for relaying mail. Neither port can authenticate the user.
I use this user with many other email clients with no issues. Even tried other users. I can see the connection flow which terminates when the sender cannot authenticate.

Is there somewhere in OPNsense that I can check the settings internally? Seems like we may have an encrypted login or something weird going on. My systems do not support encrypted logons. Besides, no need to encrypt a logon anyway when using SSL.

Here is an example of the flow using STARTTLS.
2017-11-13 16:19:56,276 - [    548590] C --> EHLO firewall.opnsense
2017-11-13 16:19:56,277 - [    548590] S <-- 250-wsip-10-0-0-1.tc.ph.cox.net. Please to meet you
2017-11-13 16:19:56,277 - [    548590] S <-- 250-AUTH LOGIN
2017-11-13 16:19:56,277 - [    548590] S <-- 250-AUTH=LOGIN
2017-11-13 16:19:56,277 - [    548590] S <-- 250-STARTTLS
2017-11-13 16:19:56,277 - [    548590] S <-- 250 OK
2017-11-13 16:19:56,313 - [    548590] C --> STARTTLS
2017-11-13 16:19:56,313 - [    548590] S <-- 220 Go ahead
2017-11-13 16:19:56,434 - [    548590] C --> EHLO firewall.opnsense
2017-11-13 16:19:56,434 - [    548590] S <-- 250-wsip-10-1-1-0.tc.ph.cox.net. Please to meet you
2017-11-13 16:19:56,434 - [    548590] S <-- 250-AUTH LOGIN
2017-11-13 16:19:56,435 - [    548590] S <-- 250-AUTH=LOGIN
2017-11-13 16:19:56,435 - [    548590] S <-- 250 OK
2017-11-13 16:19:56,466 - [    548590] C --> AUTH PLAIN Y29sMUByc21tYWlsLmNvbQBjb2wxQHJzbW1haWwuY29tAHRlc3RlcjEyMw==
2017-11-13 16:19:56,467 - [    548590] S <-- 334 UGFzc3dvcmQ6
2017-11-13 16:19:56,485 - [    548590] S <-- 535 5.7.3 Authentication unsuccessful.
2017-11-13 16:19:56,503 - [    548590] C --> AUTH PLAIN Y29sMUByc21tYWlsLmNvbQB0ZXN0ZXIxMjMA
2017-11-13 16:19:56,503 - [    548590] S <-- 334 UGFzc3dvcmQ6

As you can see the AUTH PLAIN is the issue. I cannot accept that type of authentication. How can I change that?
#109
17.7 Legacy Series / Unbound restarts
November 13, 2017, 12:55:56 AM
Figured I start a new thread instead of reviving an old one.
Unbound DNS restarts every few seconds when IPS Mode is enabled. DHCP server is disabled, I don't need it.
If I uncheck the IPS Mode, then Unbound DNS stays on as well as the internet connection.

This is a fresh install of OPNsense 17.7 on a Supermicro system with an 8 core Intel C2758.Using all the default IDS settings. Everything works great until I turn on IPS mode. Tried 2 different Intel igb NIC's.

[UPDATE] Reinstalled OPNsense from scratch and now there are no more issues with Unbound.
#110
General Discussion / Suricata issues in PFsense
October 17, 2016, 07:18:01 PM
What's up with the PFsense community when it comes to Suricata? Whenever I ask questions as to why it is taking so long to implement Inline Suricata, the post or thread gets deleted. I get the impression there is some bad blood between PFsense and OPNsense. As soon as OPNsense was mentioned, the threads were shut down. Luckily I was able to catch a post before one thread was shut down that suggested I look at OPNsense if I needed Inline Suricata. I did just that in testing and will start using it in production soon. Seems PFsense has one guy working on Inline Suricata in PFsense that just disappears for months on end because he says 'I have paid projects that take priority'. I can understand that, but do not understand in keeping everyone hanging with little to no progress reports for months on end. Nor do I understand such little support on an important feature. OPNsense seems like a much more 'community friendly' forum to me. I will be eventually replacing PFsense in all my installations because I see PFsense as a dying project at this point. It has run it's course and is losing people like me.
#111
Intrusion Detection and Prevention / IDS questions
October 14, 2016, 01:34:50 AM
Can I use my custom rules in Intrusion Detection? I have a few Snort/Suricata rules I wrote that I need to add.
Also, is 'IPS Mode' the same as inline mode. If not, how do I turn on inline mode, or is that on by default?

I am looking to switch over from PFsense because they are dragging their feet on IPS/IDS inline mode.
Thanks in advance.