Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - cyrus104

#16
I have WAN1 connected to my ISP which sometimes goes down for a minute or two. I have WAN2 connected to an LTE Modem so one is igb0 and the other is ibg1.

WAN1 latency is around 90ms, WAN2 is around 170ms.

I have 2 VPNs setup, one is OpenVPN and the other is Wireguard, they are used to support different services.

When I have a failure, I can see that both VPNs route through WAN2 and their latency jumps up. A few minutes after WAN1 comes back up the OpenVPN VPN will switch back to WAN1 and you can see the latency creep down. However, the Wireguard VPN never switches back and the latency stays high and I can see the traffic on my LTE modem.

I wanted to check if there is a setting that I'm missing or a way to force it to restart the connection, I know Wireguard isn't an always on type of connection but not sure what is happening there.

I'm not skilled with Monit but I guess I could use something like that to restart the service if the latency of the OpenVPN and Wireguard aren't close but I would like to see if there is a setting in the configs that I'm missing.

Thanks
#17
21.7 Legacy Series / Nut Failure
August 30, 2021, 04:00:25 PM
I am running the latest OPNsense 21.7 and am trying to plug in my APC UPC into it. I have NUT running on a Debian 10 system and it works with the usbhid-ups driver.

I can't get it to work with OPNsense, the diagnostic page never loads. Is there a place in the logs, I can check.

Secondarily, my Debian 10 box is pushing the NUT info out on the network and I have another machine that can pull the info but not my OPNsense.

Thanks
#18
This has been extremely useful to get Next Cloud setup using LE and HAproxy.

I did want to make one change to the HAproxy error message to have it render properly.


HTTP/1.1 403 Forbidden
Cache-Control: no-cache
Connection: close
Content-Type: text/html
Retry-After: 60

<html><body><h1>403 Forbidden</h1>
Request forbidden by administrative rules.
</body></html>
#19
I know this is an old thread but still very valid. I just realized that my ISP is blocking port 80 while trying to setup LetsEncrypt and HAProxy.

I would like to see if there is another way to do this.
#20
Understood, I checked and made sure that the syslog is still printing out the error I have in code above.

Here is my version info from the dashboard:
OPNsense 20.7.7_1-amd64
FreeBSD 12.1-RELEASE-p11-HBSD
OpenSSL 1.1.1i 8 Dec 2020

Thank you for helping.
#21
That's a negative, getting the same error in syslog.
#22
# opnsense-update -t opnsense
The package 'opnsense' is already installed.
Your system is up to date.

Version is OPNsense 20.7.7_1 right now and confirmed it was switched to stable.
#23
I thought I was on stable but looks like I was/am on dev. I've changed it back and that removed a :devel package but otherwise no change.

I'm guessing I can't go back to stable, I'll need to wait for the next stable release.
#24
I just upgraded from 20.7.5 to 20.7.7 using the regular upgrade process, 20.7.5 was working perfect since installing it and survived several reboots. I made a backup configuration right before the upgrade.

After the upgrade I went from see the gateway status for my wan and multiple vpn clients but now only 1 of the vpns is showing an online status the other show offline (but are workign). I've included the syslog for when I try to reboot the dpingers that fail to start.

I have checked/deleted the /tmp/pppoe0*(WAN) files, same with ovpnc1*(EXPRESSVPN).

Dec 20 15:17:24 op opnsense-devel[81393]: /status_services.php: Choose to bind WAN on Array since we could not find a proper match.
Dec 20 15:17:24 op opnsense-devel[81393]: /status_services.php: The WAN IPv4 gateway address is invalid, skipping.
Dec 20 15:17:30 op opnsense-devel[81393]: /status_services.php: Choose to bind EXPRESSVPN_VPNV4 on Array since we could not find a proper match.
Dec 20 15:17:30 op opnsense-devel[81393]: /status_services.php: The EXPRESSVPN_VPNV4 IPv4 gateway address is invalid, skipping.
#25
Sounds like you are pretty much there. I've been using this for split tunneling for awhile and it's working pretty well.

Settings for the Gateway:
Interface is the WG named interface that is used in Interfaces
IP Address was manually set to the internal IP address to the wireguard server WG server that I'm connecting to. For me it's a .1 while the address that I'm using for my router is .2 set in the VPN/Wireguard settings.
Upstream Gateway: unchecked
Far Gateway: checked

I have been using the Hybrid setting for my NAT, so I manually created a new NAT rule:
Interface name is the same as the Gateway being my WG named interface
TCP/IP: IPv4
Protocol: any
Source: any
Destination: any
Translation/target: Interface address

Firewall rule:
I made a very simple change in the VLAN that I wanted to push over WG instead of directly to the WAN. In the final rule that put everything to WAN, I change the Gateway to WG Gateway that I created and named in step one.

I do find that I need to restart the WG server after these settings to make sure that everything comes up as expected. Finally I check the external IP address on the machines that are on that VLAN to ensure they are all going through the WG tunnel.

Side note: I did go to and use both WG guides in docs.opnsense.org but I found them both to have issues. I did send an email with some corrections that all it to work for me but I haven't heard anything.

https://docs.opnsense.org/manual/how-tos/wireguard-client.html
https://docs.opnsense.org/manual/how-tos/wireguard-s2s.html
#26
Yeah, I'm a little confused by this as well.

I'm having a really difficult time right now and might look at doing a double router solution to avoid the internal VLANs from being disrupted. I got a few tips from the pfsense forums but none of them were the exact problem I'm having.

I have a very poor WAN connection and it keeps dropping / super high packet drop or latency spikes and during the time the WAN is coming back up I loose all intraVLAN traffic. The main 2 rules I have are for the VLANs to talk, I used aliases with the internal address of each VLAN, gateway is * (I think is default). The second rule is an inverse of anything in the above alias which routes it out to the WAN gateway.
#27
Any thoughts on this?
#28
20.7 Legacy Series / Re: Mellanox ConnectX-3 support
November 22, 2020, 03:27:55 PM
That's good to hear. I now have them all disabled.

Any idea how to get the interface to detect the 56gbps speed?
#29
20.7 Legacy Series / Re: Mellanox ConnectX-3 support
November 22, 2020, 04:09:48 AM
I haven't gotten far enough along in rebuilding my network to get a full iperf using the 56gbps cards. I have 1 installed in my OPNsense box. I'm installing them in my 3 ESXi machines and a TrueNAS box today. That should give me a much better understanding of their performance.

Part of my issues was not knowing the link speed that the OPNsense actually negotiated to.

I wanted to see what you would put for all of the hardware offloading options. I uploaded a picture of my config, I think I've disabled all offloading. I left VLAN hardware filtering on but can turn that off if you recommend it.

The iperfs that I have done are from other machines with 10Gbps which all pull around 9.4Gbps if I run: iperf -c -p -P 20

Thanks for the quick response.
#30
20.7 Legacy Series / Mellanox ConnectX-3 support
November 21, 2020, 10:18:04 AM
I was able to follow mimugmail's instructions that were posted to the forum and to the site at the bottom of this post. I was able to get the driver to autoload on boot and updated the firmware.

These cards are able to do 56Gbps instead of just 40Gbps if being used with an FDR cable and capable switch such as the SX6036 I'm using. I have this card in some ESXi machines and everything is detected as 56Gbps as expected.

I would like to see if there is a way to set these cards at the faster speed in OPNsense, the interface settings only offer autoselect, 1G, 10G, and 40G right now.

I would also like to see if there are specific options to enable OPNsense to take "full" advantage of these cards such as hardware offloading. I am using VLANs so, the hardware offloading might not work.

Any help would be greatly appreciated.

https://www.routerperformance.net/opnsense/mellanox-connecx-management-in-opnsense/