Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - ArminF

#181
ok, got it to work. Took a few tries.

Screenshots attached numbered
1 > System - Trust - Authority
Internal Root
Key lenght 4096
Digest SHA512
Lifetime 3640 (10 years)

2 > System - Trust - Certificates
Type Server
Key RSA
Key length 4096
Digest SHA512
Lifetime 825

3 >
Set DNS alternative Name DNS and IP


Then exported the LocalCA Cert (System - Trust - Authorities)
As i am on mac i had to set the system default to allow and trust always

Replace the Server Cert on System - Settings - Administration
Reloaded

Result > after reload chrome and safari shows valid

Maybe this helps!
Good Luck
A
#182
Hello lysemose,
you are welcome.

Let me try this today at home and i will report back.

Found this as well: https://superuser.com/questions/1359755/trust-self-signed-cert-in-chrome-macos-10-13
I guess chrome will react the same.

armin
#183
Kleines Update meinerseits

HTTPS URL Scanning
NAT
LAN   TCP   LAN net   *   *   443 (HTTPS)   127.0.0.1   3129
FW (LAN)
IPv4 TCP   LAN net   *   127.0.0.1   3129   *   *

Und auf dem Proxy eine CA einrichten.
Danach jedoch LOG SNI ONLY aktivieren.

Das scannt dann "nur" die URLs aber nicht den traffc.
Damit lassen sich aber die ADS blocker per ACL Liste entfernen.
#184
German - Deutsch / Re: Hardware als "Anfänger"
February 11, 2020, 08:01:29 AM
Bei WiFi stimme ich monstermania zu.

Am besten grübele mal über ein Mesh nach. Derzeit kommen auch die ersten ax Geräte.
Was ich noch suche ist eines wo man Nachts wenn alle pennen abschalten kann.

i3 is ja was "kleines" und zuhause zunageln macht mehr Spass und weniger kaputt :)
Die AppControl also Sensei fehlt mir schon ein wenig. Informativ war dies allemal.
Auch hab ich gerne Ruhe im Netz und hab alles direkt am FW port geblockt was ich nicht brauche.

Derzeit laufen keine 10 Dienste/Protokolle zuhause.

Und nun zurück ins Büro. 24 Cores, 192GB RAM völlig übertrieben aber was macht man(n) nicht alles .

Schönes Tag und vergesst Sabine nicht...
#185
German - Deutsch / Re: LAN bridge verliert Netzwerkkarte
February 11, 2020, 07:24:52 AM
hm.. den workaround hab ich schon mal.
NIC deaktivieren
Aus der Bridge nehmen
speichern
Alles umgekehrt
Danach rebooten...

Hab auch mal in der config.xml geschaut auch dort sieht alles "normal" aus.

komische Sache...
#186
Well, then i am running out of opions.

Check also that your LAN network does not block private addresses.
Interfaces - LAN - Generic configuration - block private networks
#187
Maybe take a look here
https://www.youtube.com/watch?v=vSHRvZYfqco

And have a look on the attached screenshots.
Create Aliases is important otherwise you cannot set the internal Server nore ports
cheers a
#188
Check if you can setup:
Firewall - Alias -> create Port alias with port 5900 and 25565:25569
Firewall - Alias -> create Host Alias with your torrent server.
then
Firewall - NAT - Port Forward -> use WAN interface select destination port Alias and server then save with default.
LAN rule should automatically be created

Docs
https://docs.opnsense.org/manual/nat.html

Good Luck
#189
German - Deutsch / Re: Hardware als "Anfänger"
February 10, 2020, 04:57:06 PM
Hallo,

kleiner Einwand zur Quoton i3 Kiste.
Wenn Du Seinsei installieren willst also AppControl laufen lassen meckert er beim installieren.
Danach ist die CPU beim Sensei Dashboard Aufruf zwischen 75 und 100%

Meine Kiste is soeben zweimal abgeschmiert....

Es geht glaub weniger um Boost als das es im Cores und Cache geht.
Wenn Du das Geld übrig hast würd ich sogar zu einem i7 tendieren.

WOBEI es keine Desktop CPU sind. Der i3U und der i5U haben beiden den gleichen Cache 3MB und beide 4 Threads. Daher macht es kaum einen Unterschied. Gerade Suricata (soll) ja Multithread können.
Der i7-8665U wäre natürlich Traumhaft 8MB cache und 8 Threads.

Anbei noch ein Bild meiner Kiste ohne Sensei (heul)... Die Sophos XG konnte AppControl...

Hatte meine mit RAM aber ohne SSD bestellt. Hatte ne 256 übrig daher.
PS schreib ihnen sie sollen die Pro Forma Rechnung niedriger ausstellen ;)

Fazit: Für Proxy, DHCP, IPS (alle regeln on) und sonstigem Kleinkram mit max 50 Clients reicht der i3 finde ich.
Das WIFI Modul konnte kein AC soll aber ein neues geben mittlerweile und FreeBSD scheint dies auch zu supporten.


Daumendrück!
A

#190
Help us a bit better understanding your problem.

You create a local CA internally System - Trust - Authorities
Afterwards you created a self signed certificte and here is where i lost you...

You installed it where exactly? On a webserver hosting a website?
Or on your OPNSense which actually has already one.

Also for Server you need to have a server cert. Webserver usually to establish the handshake.
For client cert authentication you would need a client cert.

Also import the local authority cert (there is a p12 option) into your pc maybe

hope this helps
a
#191
Happy i found this thread..

Had to route 3129 via NAT and FW Rule
Had to create a local CA

Used options
Enable Transparent HTTP proxy
Enable SSL inspection
Log SNI information only (No Cert installation on clients just URL scan)

Worked!!

Thank you very much
A
#192
German - Deutsch / Re: LAN bridge verliert Netzwerkkarte
February 10, 2020, 09:57:43 AM
Moin Dirk,
Danke für Deine Antwort.

ja das hab ich ebenfalls nochmals geprüft. Die einzelnen NICs stehen alle auf default ohne Werte bei DHCP/IP oder negotiation. Siehe screenshot.

Auch die Tuneables snd noch beide da also Member auf 0 und Bridge auf 1.

Was mich stutzig macht ist das es die NIC aus dem initial Setup ist wo "verloren" geht.
Ob da noch irgendwo etwas an der Konfig noch nicht überschrieben ist... Oder so.

Wo find ich den per SSH die configs der Nics da schau ich da mal rein.
FreeBSD is nicht meine Stärke.

Danke!
A
#193
German - Deutsch / Re: WAN IP nicht im DNS eintragen
February 09, 2020, 07:10:57 PM
Soweit ich Unbound verstanden hab nimmt er default die Domain wo im System Tab eingetragen ist.
Und "listened" auf allen interfaces. Daher wohl auch auf dem WAN.

Ich hab DNS 53 per Port Forward auf 127.0.0.1 geleitet.

Und dazu könntest Du nur das LAN als listener setzen.
Oder mit den Overrides spielen und 127.0.0.1 als override für deine Domain.

gruss A
#194
German - Deutsch / LAN bridge verliert Netzwerkkarte
February 09, 2020, 07:05:28 PM
Salve,

ich hab anhand der Doku eine LAN bridge gebaut.
https://docs.opnsense.org/manual/how-tos/lan_bridge.html

Anfang
igb0 -> WAN
igb1 -> LAN
igb2 -> nicht benutzt aber angelegt als opt1/2
igb3 -> nicht benutzt aber angelegt als opt1/2

Ausgang
igb0 -> WAN
igb1,2,3 -> LAN Bridge


Alle LAN interfaces liefen bis zum reboot. Danach war die erste aus dem Initialsetup igb1 nicht mehr ansprechbar.
NIC war noch da reagierte aber nicht und der Rechner (Frau kotzte.. Netfllx down da es der TV war) war offline.

Also Netzwerkkarte deaktiviert, aktiviert aus der Bridge genommen und wieder rein gemacht und gebootet.

Wird wohl bis zum nächsten reboot halten...
Kann an das irgendwie fixieren?  Komischerweise ist es die NIC aus dem Initial setup

Danke im Voraus!
A

Details: Intel Karten (4 Port)

Details ifconfig
igb0: flags=28943<UP,BROADCAST,RUNNING,PROMISC,SIMPLEX,MULTICAST,PPROMISC> metric 0 mtu 1500
   options=1400b8<VLAN_MTU,VLAN_HWTAGGING,JUMBO_MTU,VLAN_HWCSUM,VLAN_HWTSO,NETMAP>
   ether 00:0e:c4:d1:c3:0d
   hwaddr 00:0e:c4:d1:c3:0d
   inet6 fe80::20e:c4ff:fed1:c30d%igb0 prefixlen 64 scopeid 0x1
   inet 87.102.237.37 netmask 0xfffffc00 broadcast 87.102.239.255
   nd6 options=21<PERFORMNUD,AUTO_LINKLOCAL>
   media: Ethernet autoselect (1000baseT <full-duplex>)
   status: active
igb1: flags=8943<UP,BROADCAST,RUNNING,PROMISC,SIMPLEX,MULTICAST> metric 0 mtu 1500
   options=1400b8<VLAN_MTU,VLAN_HWTAGGING,JUMBO_MTU,VLAN_HWCSUM,VLAN_HWTSO,NETMAP>
   ether 00:0e:c4:d1:c3:0e
   hwaddr 00:0e:c4:d1:c3:0e
   inet6 fe80::20e:c4ff:fed1:c30e%igb1 prefixlen 64 scopeid 0x2
   nd6 options=21<PERFORMNUD,AUTO_LINKLOCAL>
   media: Ethernet autoselect (100baseTX <full-duplex>)
   status: active
igb2: flags=8943<UP,BROADCAST,RUNNING,PROMISC,SIMPLEX,MULTICAST> metric 0 mtu 1500
   options=1400b8<VLAN_MTU,VLAN_HWTAGGING,JUMBO_MTU,VLAN_HWCSUM,VLAN_HWTSO,NETMAP>
   ether 00:0e:c4:d1:c3:0f
   hwaddr 00:0e:c4:d1:c3:0f
   inet6 fe80::20e:c4ff:fed1:c30f%igb2 prefixlen 64 scopeid 0x3
   nd6 options=21<PERFORMNUD,AUTO_LINKLOCAL>
   media: Ethernet autoselect (1000baseT <full-duplex>)
   status: active
igb3: flags=8943<UP,BROADCAST,RUNNING,PROMISC,SIMPLEX,MULTICAST> metric 0 mtu 1500
   options=1400b8<VLAN_MTU,VLAN_HWTAGGING,JUMBO_MTU,VLAN_HWCSUM,VLAN_HWTSO,NETMAP>
   ether 00:0e:c4:d1:c3:10
   hwaddr 00:0e:c4:d1:c3:10
   inet6 fe80::20e:c4ff:fed1:c310%igb3 prefixlen 64 scopeid 0x4
   nd6 options=21<PERFORMNUD,AUTO_LINKLOCAL>
   media: Ethernet autoselect (1000baseT <full-duplex>)
   status: active

bridge0: flags=8843<UP,BROADCAST,RUNNING,SIMPLEX,MULTICAST> metric 0 mtu 1500
   ether 02:3e:52:76:10:00
   inet 192.168.1.1 netmask 0xffffff00 broadcast 192.168.1.255
   nd6 options=1<PERFORMNUD>
   groups: bridge
   id 00:00:00:00:00:00 priority 32768 hellotime 2 fwddelay 15
   maxage 20 holdcnt 6 proto rstp maxaddr 2000 timeout 1200
   root id 00:00:00:00:00:00 priority 32768 ifcost 0 port 0
   member: igb3 flags=143<LEARNING,DISCOVER,AUTOEDGE,AUTOPTP>
           ifmaxaddr 0 port 4 priority 128 path cost 55
   member: igb2 flags=143<LEARNING,DISCOVER,AUTOEDGE,AUTOPTP>
           ifmaxaddr 0 port 3 priority 128 path cost 55
   member: igb1 flags=143<LEARNING,DISCOVER,AUTOEDGE,AUTOPTP>
           ifmaxaddr 0 port 2 priority 128 path cost 55
#195
Ciao Axel,

ich kann es leider nur in der Theorie sagen. Hab im Büro die Firewall noch nicht soweit aktiv.
Zuhause läuft mal alles soweit mit der OPNSense.

Also
Virtuelle IP anlegen (Firewall - Virtual IP)
NAT anlegen (siehe screenshot)
Firewall Rule setzen (VIP zu Internen Server)

Achja, spiele vielleicht noch etwas mit der Richtung (In/Out) herum. Das hatte mir einen Streich gespielt bei meiner Haus und Hof Firewall.

Daumendrück
armin