Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Topics - JasMan

#21
Hey,

I've an IPsec connection to the network of a friend of mine (192.168.0.0/24). He has an Raspi with Nextcloud (192.168.0.10) which I would like to use to backup my OPNsense config regularly.

But OPNsense can't reach this address. When I traceroute the destination raspi.fritz.box from the web interface, OPNsense sends this traffic to the WAN interface/Internet and not through the IPsec tunnel.

# /usr/sbin/traceroute -w 2 -n  -m '18'  'raspi.fritz.box'
traceroute to raspi.fritz.box (192.168.0.10), 18 hops max, 40 byte packets
1  10.0.224.1  1.122 ms  0.631 ms  0.628 ms
2  [WAN IP]  5.984 ms  5.896 ms  5.888 ms
3  * * *
4  * * *
5  * * *
....


From my LAN behind the OPNsense  I can reach the Nextcloud client. So it's not a general routing issue.
Any ideas to solve this or for a workaround?

Thanks
Jas

#22
Hey,

I've enabled the IDS and IPS mode for the WAN interface only on my OPNsense 19.7.2.

I noticed that the IDS/IPS log shows sometimes the client IP, and sometimes the OPNsense WAN interface IP as source IP of blocked connections (see attachment, red client IP, green WAN IF IP). NAT is not enabled.

Of course I would like to see always the client IP to identify the client which tries to initialize the connection.

Any idea how to do that or why I see sometimes the WAN IP?

Thank you.
Jas






#23
Hey,

When I switch to the "Inspect" view in the overview of any interfaces firewall rules, most of the statistic columns shows "N/A". Only the NAT and Floating rules shows values for states, packets and bytes.

Do I have to enable something to see the statistics for all rules?

Thanks.

Jas
#24
Hey,
I've a stange issue with my clock radio, which is able to play Internet radio streams as wake-up sound.

Once or twice a week the radio is not able to start the stream when it should wake me up.
I did an capture on the LAN side of the OPNsense aplliance (see attachment). It looks like the clients ACK for the SYN-ACK never reached his destination. The server retransmit the SYN-ACK again and again, and the client retrasnmit his ACK again and again, too.
The firewall and IPS log showed no blocked packets. I will now capture the WAN side to be sure that the packet has left the OPNsense appliance.

Funny fact: this happens only when the stream is started by the wake-up timer. When I start the radio manually, the stream starts always without any problem.

Any idea what can cause this issue? Is there another log were I should have a look to be sure, that nothing was blocked?
Thanks.

Jas
#25
Hey,

I have an issue with an TCP connection (LAN client downloads data from WAN server). I did some troubleshooting and found out, that a packet with RST flag set is blocked by the firewall (I guess), when a packet with FIN flag set was send before in the TCP session.
An example:

RST packet blocked

  • Session between Client and Server is up and running
  • Client decides to close the session and sends an FIN/ACK packet to the server
  • Server apparently ignores the FIN/ACK packet and still sends data packets to the client
  • Client sends an RST packet to the server, which is blocked by the OPNsense aplliance. I can see the packet in the packet trace on the LAN site but not on the WAN site.
  • Server still sends data packets, but the client don't acknowledge them. He stops when the clients receive window is "full".

RST packet is not blocked

  • Session between Client and Server is up and running
  • Client decides to close the session and sends an RST packet to the server
  • Server sends ACK packet and stops sending data

Is this a normal behaviour?
I think my issue has to do with this behaviour, because when the RST packet is blocked the session state remains open on the server. When a certain limit has reached, I guess the server will not allow any more connections from/to my IP address.

Jas Man
#26
General Discussion / Logging for all firewall rules
December 31, 2018, 04:00:50 PM
Hey,
I'm curios if OPNsense has a switch or option, where I can enable the logging for all firewall rules at once.

Why? When the ruleset becomes bigger and bigger, and you found out that an client has access to something that it shouldn't have, it's difficult to find the rule which allowes the traffic.
In this case it would be great to temporary enable the logging for all rules at once to check the log which rule allowes the specific traffic.

Thank you.
Jas Man

#27
Hi,
I've noticed that some logs like those from NTP and Unbound showes only old entrys. I guess the circular logging is not working for those logs.

The log files under /var/log/ for this services have reached the configured maximum file size (System: Settings: Logging: Log File Size (Bytes), 20.000.000 Bytes on my OPNsense) and therefore, I guess, logging has stopped.

I haven't found any known issue about that. Maybe I've forgot only a setting or something like this.
The circular logging for the system log looks fine. The file has reached the maximum size too, but new logs are shown and the old ones dissapear.

Any idea?

Thank you.
Jas Man
#28
Hi,
I switched back from a PPoE Connection and therefore I can use IDS/IPS again.
I noticed that Suricata fails to start when I activate the rule list "abuse.ch/URLhaus". The following error is shown in the logs:

Aug 24 14:03:22    suricata: [100180] <Error> -- [ERRCODE: SC_ERR_INVALID_SIGNATURE(39)] - error parsing signature "drop http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected"; flow:established,from_client; content:"GET"; http_method; content:"/url=http://wordpress.p364918.webspaceconfig.de/614tiscfz/com/us|26|data=02|01|rcorm1@jcp.com|ec2a6ed25318490bd27608d6077bf11e|9c0ac0b90217468aa4322649cd6ed297|0|0|636704626242706015|26|sdata=g3qlynktc59ma3fllqbbfs0uwnigsem1mwi/cdfotvu=|26|reserved=0"; http_uri; depth:250; isdataat:!1,relative; content:"na01.safelinks.protection.outlook.com"; http_host; depth:37; isdataat:!1,relative; metadata:created_at 2018_08_21; reference:url, urlhaus.abuse.ch/url/45633/; classtype:trojan-activity;sid:80908733; rev:1;)^M" from file /usr/local/etc/suricata/opnsense.rules/abuse.ch.urlhaus.rules at line 1595

I thougt "Okay, maybe there's a problem with the list. Wait some days and check again." But the issue still exist.

I've found only one other topic in this forum with nearly the same issue, but this was still unsolved. So I'm wondering why nobody else have this problem.
Is this an issue of Spamhouse or maybe OPNsense?

Jas
#29
Hi,

ich habe einen IPsec Tunnel zwischen meiner OPNsense und einer Fritz!Box 6590 aufgebaut. Der Tunnel läuft stabil, gute Performance, alles super.

Nun möchte ich aber aus dem LAN der Fritz!Box mehrere Subnetze auf meiner OPNsense erreichen. Und da komme ich nicht weiter. Hier mal die Eckdaten:

Fritz!Box 6590
LAN: 192.168.0.0/24
WAN: öffentliche, dynamische IP (DynDNS vorhanden)

OPNsense
LAN1: 192.168.1.0/24
LAN2: 192.168.2.0/24
OpenVPN: 192.168.3.0/24
WAN: öffentliche, dynamische IP (DynDNS vorhanden)

Mein Wunsch ist alle drei Subnetze aus dem LAN der Fritte zu erreichen, und das möglichst mit nur einem Tunnel.
Was ich bereits probiert habe:


  • Drei VPNs auf der Fritte eingerichtet mit identischer Phase1, und mit angepasster Phase2 für das jeweilge Remote Subnetz der OPNsense. Auf der OPNsense habe ich dann einen VPN Tunnel mit jeweils einer Phase2 für jedes Subnetz angelegt

  • Drei Tunnel (für jedes Subnetz einen) auf beiden Seiten mit den selben Einstellungen in Phase1, und mit angepasster Phase2 für das jeweilge Remote Subnetz

  • Drei Tunnel (für jedes Subnetz einen) auf beiden Seiten mit den unterschiedlichen PSK Keys und ID Einstellungen in Phase1, und mit angepasster Phase2 für das jeweilge Remote Subnetz

Bei allen Varianten geht aber immer nur ein Subnetz online. Ich hab es einmal geschaft zwei Subnetze online zu bekommen. Aber ich weiß nicht warum und weshalb...... :-[

Bekommt man überhaupt mehrere Subnetze über die Fritte mit nur einem VPN/Tunnel geschaltet (mehrere SAs), oder muss man zwangsweise für jedes Subnetz einen Tunnel aufbauen?

Hat das schon mal einer hinbekommen?

Thanks.

Jas
#30
Hi,

I've updated OPNsense to 18.1.12 on Friday and noticed today, that I've a lot of internal traffic that is dropped by the firewall. The source of those dropped packets are clients within my LAN subnet. The destination is always the IP of the OpenVPN server adapter.

After some investigation I found out, that Unbound has two IP addresses for the OPNsense FQDN: the management IP that I've set up for HTTPS and SSH, and the IP for the OpenVPN interface.

Name:    jaswall.mgmt.home.arpa
Addresses:  192.168.1.1
          192.168.15.1


Therefore when I access the WebGUI via the FQDN, my client get's somethimes the management IP, and sometimes the OpenVPN adapter IP. The packets to the OpenVPN adapter IP are dropped of course. The OpenVPN adapter is only for routing and DNS for the VPN clients.

When I disable my OpenVPN server, the second IP for the OPNsense FQDN in Unbound is gone.

Name:    jaswall.mgmt.home.arpa
Addresses:  192.168.1.1



I'm not sure if this was already before the update. But I've never noticed so many droppes of internal packets in my firewall.

Is there an option where I can disable this behaviour? Or is this an issue?
Thank you.

Jas Man
#31
Hi,

I've set up an IPsec tunnel from my OPNsense 18.1.5-amd64 to an AVM Fritz!Box 7590 to backup my data to another location.

When the backup is running, it uses nearly the complete WAN upload speed of 5 Mbit/s. But the IPsec NetFlow graph shows round about 9 Mbit/s which is not possible (see attachment).

I've already tried to add the IPsec interface to the "Egress only" setting in the NetFlow data, but without success.

Can somebody explain this? Or is it a bug?

Thank you.
Jas Man