Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Topics - dcol

#41
I am setting up a new OPNsense box using 22.1.6. My old box is @ 21.7.8. I have all the settings rules in place and appears to be working ok so far.

I noticed that when looking at the Firewall Live View it now shows 'Default deny / state violation rule'.

Is this 'state violation rule' message something new for version 22, or do I have a settings to fix?

Thanks to all for a great firewall. Been using for 5 years now.
#42
Chelsio T520 driver shows as unsupported in tunables. I can manually load driver with 'kldload if_cxgbe' in the shell, but 'if_cxgbe_load' shows unsupported in the tunables. I cannot use the T520 unless I manually load the driver after I boot. Was there a change?
#43
I tried to update to v22, but had to revert back to 21.7.8. I have two LAN interfaces on different subnets. One was fine but the other keep crashing after about 45 seconds. Tried to update to 22.1.6 with same issue.

Is there something I need to do before I update? What info is needed to help the community. I have a simple install with one WAN and two LANS. the only plugins I use are Suricata and Monit.

Please help
#44
Virtual private networks / 2FA for specific ports
October 15, 2021, 01:23:36 AM
I am running remote desktop software that I am now required to use 2FA. Is there a way to tunnel specific ports using 2FA via OpenVPN or other method? This is a new area for me, so be gentle. These ports are now NAT'ed to the specific IP's. I am told they now need 2FA. Is this even possible?
Thanks all.
#45
21.7 Legacy Series / Listen queue overflow
October 06, 2021, 11:32:45 PM
System General log:
sonewconn: pcb 0xfffff800c816a000: Listen queue overflow: 193 already in queue awaiting acceptance

This error is recent since my updates to 21.7.3, maybe a coincidence.
Saw many references but no reasons or solutions to this error in the system logs. Did not make any recent changes to hardware. Most references mentioned a NIC overflow. If this is true, how can I tell which NIC, I have 6 in this system.
Tried adding kern.ipc.soacceptqueue value=1024 as some suggested. Made no difference.

Any suggestions on how to track this down?
And why is it always 193 in the queue? That seems strange to me. Is there a way to dump the queue?
#46
21.7 Legacy Series / [Feature Request]
August 17, 2021, 12:46:05 AM
Didn't see anywhere in the forums for feature requests. Which can be another feature request

I would like to be able to add a custom Cron job in the WebGUI. Just a simple run this command on this schedule. Maybe it's already there. I couldn't find it.
#47
21.7 Legacy Series / Firewall requires reboot
August 15, 2021, 08:31:37 PM
I have an OPNsense appliance with Intel NIC's connected to a Westell G60 DSL Model using PPPoE on the WAN port. The modem is set to bridge mode.

Here is the issue. Every time the modem loses power or Internet connectivity, the firewall needs to be rebooted before the WAN works again. Is there something that I can do in the firewall to automatically reboot if the WAN or gateway is down?

I did see in another port the option for "Periodic reset". Where is this found?
#48
21.7 Legacy Series / GeoIP2 questions
August 05, 2021, 08:54:23 PM
I now have a subscription to GeoIP2. I ran GeoLite2 previously and used the following URL:
https://download.maxmind.com/app/geoip_download?edition_id=GeoLite2-Country-CSV&license_key=<MY KEY>&suffix=zip

I assume I now use:
https://download.maxmind.com/app/geoip_download?edition_id=GeoIP2-Country-CSV&license_key=<MY KEY>&suffix=zip

I cannot tell if it is working since I do not know how to force an update, or know how to apply a twice weekly update. I also assume that the alias cron job does the GeoIP2 update.

Are my assumptions correct?
#49
21.7 Legacy Series / Viewing CPU usage per service
August 01, 2021, 11:16:29 PM
Is there a way to view CPU usage per service? Maybe a shell command?

I am using 21.1.9 and I noticed the CPU was at 60-70% driving my CPU temps high. I did a restart and now the usage is where it should be at 0-10%

How can I tell what is causing this high CPU usage? I did try resetting the netflow data and that made no difference. Only a reboot brought the usage down. I also noticed when the CPU usage was high, the memory usage was also much higher than normal using 12-14GB when normally it is at 3-4GB

Specs:Intel  i7-6700, 32GB

Thanks
#50
21.1 Legacy Series / IPv6 not working
May 18, 2021, 01:50:59 AM
I have no IPv6 connectivity. Had it before the last update, but not sure if that had anything to do with it.
Dashboard shows dhcpv6 and a WAN_DHCP6 gateway running
LAN has iPv6 Configuration Type as track interface with prefix ID 0
WAN has IPv6 Configuration Type set to DHCPv6 and Prefix delegation size=64
There are no VLANs
Unbound has DNS64 Support Disabled
Custom options are

server:
do-not-query-localhost: no

forward-zone:
   name: "."
   forward-addr: 127.0.0.1@5353
   forward-addr: ::1@5353

On the client side, IPv6 is enabled DHCP. ipconfig shows a Link-local IPv6 Address.
Any help appreciated to get IPv6 working again.
#51
Here is an issue I just came across and not sure how to handle.
I have a floating rule that blocks certain countries from sending email on port 25.
The issue is, I use a backup email service which accepts email when my primary MX Record is not available, then forwards the email when it is available.

What I think is happening is by blocking the port it is forcing the email to use the next level MX server. Should I be rejecting these connections instead of blocking? Not sure how to handle this? Maybe I should not be blocking port 25 at all and let the email server handle the spam, which does not have very good GeoIP blocking capabilities.
#52
Hi,
I have two LAN interfaces, LAN1:192.168.100.1/24 and LAN2:192.168.200.1/24.
I installed DNSCrypt-Proxy using the online tutorial, IPv6 works fine in LAN2, but LAN1 does not have IPv6 connectivity. I changed both LAN's IPv6 to Track Interface to WAN with different Prefix ID's.
An ipconfig shows IPv6 IP's and DNS for both LAN's. IPv4 works fine on both LAN's.
I am using DHCP on both LAN's

What am I missing? What other info can I share to help solve this mystery?

Thanks
#53
21.1 Legacy Series / Need DNS help
April 03, 2021, 11:31:42 PM
Hi,
I followed the tutorial on DNS Security to the letter and it just opened up a bunch of issues.

All I want is to have IPv4 and IPv6 available using DNSSEC. After I setup using the tutorial I had a bunch of DNS issues. Everything started resolving to IPv6 and then I had access issues. Outlook not working on the LAN. No access to Socks proxies. Seems all my IPv6 custom locations don't work because everything resolves to IPv6. I use static IP's from my ISP and they do not have IPv6 IP's available yet.

I don't know where to start. Is there a way to set overrides so certain domains are forced to resolve to IPv4? Or a way to always use IPv4, then use/fallback to IPv6 if no IPv4 DNS record exists?

As an example, if I tracert my email server domain, it returns an IPv6 address, but there is no IPv6 address on that server so I cannot get to it. Same with external proxies I access.

I did resort to disabling IPv6 on my NIC to access things, but I don't want all my users to have to do that. I do want to have access to IPv6 only sites. And I did set prefer IPv4 over IPv6.

Any help is appreciated.
#54
21.1 Legacy Series / ntopng not working
March 31, 2021, 05:54:15 PM
Hi all,
I thought I would give ntopng a go and can not get the ntopng or redis server to start.
Also errors during reboot with connection errors.
2021-03-31T08:48:15   ntopng[86560]   [Redis.cpp:150] ERROR: to specify a redis server other than the default   
2021-03-31T08:48:15   ntopng[86560]   [Redis.cpp:149] ERROR: Please start it and try again or use -r   
2021-03-31T08:48:15   ntopng[86560]   [Redis.cpp:148] ERROR: ntopng requires redis server to be up and running   
2021-03-31T08:48:14   ntopng[86560]   [Redis.cpp:99] ERROR: Connection error [Operation timed out]

Searched posts and could not find and answers. Did not set a password and used all the default settings.
Also noticed there is no /var/redis/db file

Do I need a Firewall Rule to make this work?
#55
21.1 Legacy Series / Revisiting NordVPN setup
February 13, 2021, 07:40:26 PM
Hi all,
I have looked at archived posts on setting up NordVPN from here
https://support.nordvpn.com/Connectivity/Router/1292598142/OPNsense-18-7-setup-with-NordVPN.htm

Two questions:
1. Has anything notably changed in the installation pertaining to usage on 21.1?
2. What changes need to be made to the setup if I am using a NordVPN dedicated IP?

Thanks to all for a great product for years!
#56
20.7 Legacy Series / Question after lighttpd patch
January 06, 2021, 09:46:40 PM
I applied the patch to fix unbound and noticed these messages. How do I know if I should remove these items?
I know I am using unbound, but do not know what lighttpd is.

You may need to manually remove /usr/local/etc/unbound/unbound.conf if it is no longer needed.
You may need to manually remove /usr/local/etc/lighttpd/lighttpd.conf if it is no longer needed.
You may need to manually remove /usr/local/etc/lighttpd/modules.conf if it is no longer needed.
You may need to manually remove /usr/local/etc/lighttpd/conf.d/access_log.conf if it is no longer needed.
You may need to manually remove /usr/local/etc/lighttpd/conf.d/auth.conf if it is no longer needed.
You may need to manually remove /usr/local/etc/lighttpd/conf.d/cgi.conf if it is no longer needed.
You may need to manually remove /usr/local/etc/lighttpd/conf.d/cml.conf if it is no longer needed.
You may need to manually remove /usr/local/etc/lighttpd/conf.d/debug.conf if it is no longer needed.
You may need to manually remove /usr/local/etc/lighttpd/conf.d/dirlisting.conf if it is no longer needed.
You may need to manually remove /usr/local/etc/lighttpd/conf.d/evhost.conf if it is no longer needed.
You may need to manually remove /usr/local/etc/lighttpd/conf.d/expire.conf if it is no longer needed.
You may need to manually remove /usr/local/etc/lighttpd/conf.d/fastcgi.conf if it is no longer needed.
You may need to manually remove /usr/local/etc/lighttpd/conf.d/magnet.conf if it is no longer needed.
You may need to manually remove /usr/local/etc/lighttpd/conf.d/mime.conf if it is no longer needed.
You may need to manually remove /usr/local/etc/lighttpd/conf.d/mysql_vhost.conf if it is no longer needed.
You may need to manually remove /usr/local/etc/lighttpd/conf.d/proxy.conf if it is no longer needed.
You may need to manually remove /usr/local/etc/lighttpd/conf.d/rrdtool.conf if it is no longer needed.
You may need to manually remove /usr/local/etc/lighttpd/conf.d/scgi.conf if it is no longer needed.
You may need to manually remove /usr/local/etc/lighttpd/conf.d/secdownload.conf if it is no longer needed.
You may need to manually remove /usr/local/etc/lighttpd/conf.d/simple_vhost.conf if it is no longer needed.
You may need to manually remove /usr/local/etc/lighttpd/conf.d/ssi.conf if it is no longer needed.
You may need to manually remove /usr/local/etc/lighttpd/conf.d/status.conf if it is no longer needed.
You may need to manually remove /usr/local/etc/lighttpd/conf.d/trigger_b4_dl.conf if it is no longer needed.
You may need to manually remove /usr/local/etc/lighttpd/conf.d/userdir.conf if it is no longer needed.
You may need to manually remove /usr/local/etc/lighttpd/conf.d/webdav.conf if it is no longer needed.
#57
General Discussion / AP IP access from WAN
October 14, 2020, 06:42:00 PM
I have two subnets LAN (192.168.1.1/24) and Wifi (192.168.2.1/24)
The Access Point IP is 192.168.2.254 and the GUI port is 1080
I can get to the AP from the 192.168.2.x subnet but not from the WAN.

I setup a NAT rule (attached) to access the AP from the internet. I can access the OPNsense GUI but not the AP.

The other thing I would like to do is get to the AP from the LAN.
The second attachment is the firewall log.
#58
20.7 Legacy Series / non existing rule seen in log
October 06, 2020, 09:05:04 PM
Here's one I cannot figure out. I have an IPv6 rule in the Live View (see pic) That does not exist in any of my rules.
The label 'Block All IPv6' does not exist in any of my rules.
If this is because I have the Advanced firewall setting set to IPv6 disable, then how can I stop the log entries.
#59
20.7 Legacy Series / Bridging different MTU networks
October 06, 2020, 05:13:24 PM
It it ok to bridge different local subnets from different switches that have different MTU's?
I assume OPNsense would handle the fragmentation internally, but maybe not.

Please advise.
#60
20.7 Legacy Series / Block subnets
September 29, 2020, 08:14:29 PM
I have a basic default setup with two LAN interfaces and one WAN gateway. Everything works fine, except LAN1 can ping and get to shares on LAN2 and vice versa. I do not want the LAN's to have any connection between them.

I have NAT outbound set from each subnet going to the same NAT address, which is the WAN IP address. I assume this is where the connection is since no LAN block rule works.

How do I block the subnets?