Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - binaryanomaly

#151
Thanks. I created now .../Favorites/Menu.xml which kind of works.

Unfortunately every time I click an entry the menu structure below opens as well where the corresponding item is. Is there a way to prevent that?

<menu>
    <Favorites order="1" cssClass="fa fa-star">
        <FW-Aliases order="10" VisibleName="FW Aliases" url="/ui/firewall/alias" cssClass="fa fa-list-alt fa-fw">
            <Edit url="/ui/firewall/alias/*" visibility="hidden"/>
        </FW-Aliases>
        <LAN_IFG-FW_Rules order="20" VisibleName="FW LAN-IFG Rules" url="/firewall_rules.php?if=LAN_IFG" cssClass="glyphicon glyphicon-fire"/>
        <Live order="30" VisibleName="FW Live Log" url="/ui/diagnostics/firewall/log" cssClass="fa-eye"/>
        <Leases order="90" url="/status_dhcp_leases.php" cssClass="fa fa-bullseye fa-fw">
            <Details url="/status_dhcp_leases.php?*" visibility="hidden"/>
        </Leases>
    </Favorites>
</menu>

#152
After thinking about it. What I probably would want is only a way to create/edit that additional xml for the Menu System.
I'd just create a favorite Section containing links to the pages I use most frequently and place it on the very top. I can do that manually, no problem. Is there a way to access this xml from the web ui or do i need to ssh in and create/edit it from cli?

A link from the FW page to the live log would certainly be convenient but only solving that particular problem.
No I don't use browser back and forward in general anymore as it often breaks the use of many web apps.
#153
Not sure I understand why there should be a problem with ACLs it would only be a reference to the original page/URL in a different navigation section that is sticky at the very top.

The motivation is that I'm currently changing a lot between different pages I need often and are nested on 3rd level of the navigation for example Firewall -> Rules -> Interface Group Rules and then switching to Firewall -> Log Files -> Live View. Every time I switch the former 3rd level nav is collapse and I end up clicking a lot when this could be solved very conveniently by marking the pages as favorites and having them always displayed in a top favorite setcion.
#154
Hi,

Fortigate and other firewalls have a favorite navigation functionality that allows you to favorite navigation items that are often used which then appear on top of the navigation in your favorites section for quick access. This is very convenient and efficient.

As far as I know there isn't something like that available for OPNsense? (Aware of the search functionality)
Could this be a usability and efficiency improvement?

Cheers
#155
QuoteYou are definitely my hero of the day, @binaryanomaly!

The App "Serial" does the JOb correctly, and I can even use Serial-USB-Converters, I didn't have Mac Drivers for!

T H A N K    Y O U !

You're very welcome! Glad it worked out well  ;D
#156
Ok, I was able to solve it myself:

There's a configuration option that needs to be enabled:
Services -> Unbound DNS -> General -> DHCP Static Mappings:  Register DHCP static mappings in the DNS Resolver (ticked)

I didn't notice this because naturally you start without static mappings and when adding them later my systems disappeared from DNS. I'm not quite sure if the logic makes sense to enable this by default for dynamically mapped clients/hosts but not for statically mapped ones - it seems inconsistent to me.

However - problem solved!  8)
#157
Quote from: Alphakilo on April 20, 2018, 12:25:36 PM
does "system" resolve without the .localdomain suffix?

No
ping: cannot resolve system: Unknown host

Edit
nslookup gives this:


nslookup system.localdomain
Server: 10.0.0.1
Address: 10.0.0.1#53

** server can't find system.localdomain: NXDOMAIN
#158
Hi,

I have a pretty simple standard setup of opnsense. I use the DHCPv4 service of opnsense.

System -> Settings -> General -> Domain: localdomain
Services -> DHCPv4 -> [LAN] -> Domain name: (is empty)
   
The default is to use the domain name of this system as the default domain name provided by DHCP. You may specify an alternate domain name here.

Service -> Unbound DNS -> General ->  DHCP Registration: ticked

If this option is set, then machines that specify their hostname when requesting a DHCP lease will be registered in the DNS Resolver, so that their name can be resolved.

Now I would expect that I can refer to systems by their local domain name, i.e. system.localdomain from a client that is registered by the DHCP service and provided with the ip of opnsense for dns resolution. Instead I get:
ping: cannot resolve system.localdomain: Unknown host
Accessing by IP works just the DNS resolution not.

DNS lookup via Interfaces -> Diagnostics -> DNS Lookup: Does not work either

Why is this not working, have I done something wrong?
The unbound service is running, resolution of internet domain names works and I do not see anything suspicious in the provided logs.


#159
QuoteAre your working with Mac OS as well? I think Problem 2 might be a specific Mac/USB2Serial Cabel/Serial Console Issue.

I installed it on an APU2 board from a Mac as well. It worked fine here.

I was using https://www.decisivetactics.com/products/serial/ with 115200 8n1 settings as recommended here on http://pcengines.ch/howto.htm#serialconsole

After the initial installation was done I rebooted and used the Web UI for configuration via the LAN connection.

Edit:
Maybe worth to mention: Some features only started to work properly after I've upgraded to the latest opnsense patches. You may want to do that right after you have the Web UI working.
#160
Hi,

QuoteI wanted to ask, if opnsense provides the ability to view which computers on my LAN, are visiting which websites on the internet. Would Insight - Netflow Analyzer provide this information?

I actually wanted to ask something very similar. But I'm interested in all traffic/protocols not just web.

  • Now I can see partially what is going on in the livelog but that seems to be just the recent events and then gone.
  • The overview is a summary and too high-level, no drill down possible.
  • Plain view is too raw.
  • None of them resolves to hostnames. Only very basic filtering is possible.

Do I have overlooked something or is there really no UI supported, flexible reporting available for Firewall traffic?
I couldn't spot something in the documentation.

As a start I would like to see stuff such like:

  • Which hostnames generates what amount of traffic
  • Which hostnames traffic is being blocked and why (what rule)
  • IP range owner/country of targetip
  • ...

This is very crucial information out of a Firewall to me - otherwise it's mostly a blackbox executing some rules?
Is this is information really not available as a dynamically searchable, UI friendly report or did I just not yet find it?

Thanks for infos and explaining me how best practice to achieve what I intend would be.
#161
10 € from me.

Private user here that just got started - still finding out if this is it for me. However, appreciate the effort and FOSS in general. 👍🏻
#162
After thinking it back and forth I decided that the simplest and cleanest approach is to buy a separate Wifi Access Point. Ubiquiti UniFi AP-AC-Pro in case someone wondered. Very happy with it - Problem solved.
#163
Hi,

I'm new here and I'm trying to figure out what a reasonable setup with my constraints could be.

Situation

       
  • Fiber router of ISP I have to use
  • Router comes with good wifi, I want to use this and avoid another wifi AP
  • Router can only provide natted private IP range internally no transparent mode
I have a pcengines device where I already installed OPNsense. Now I would like to:

       
  • Route all incoming/outgoing traffic through OPNSense
  • Provide the dhcp server with OPNSense also for wifi
  • Have all internal devices in the same network, no routing for internal traffic


Can that somehow reasonably be achieved?

I see no problems with wired clients as I can connect them exclusively via the firewall.

But for wireless clients I'm not sure how I could this in a reasonable and secure way. I know I could probably do something with VLANs but i.e. exposing the dhcp server on the WAN interface in order to allow wifi clients that connect to the isp router obtain an ip feels wrong and somewhat dangerous

EDIT (fabian): Mark as solved