Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - jojothehumanmonkey

#17
thanks.

just now i added a firewall rule to block telnet from wan

i have tried several online scanners and they all say the port is filtered, not closed or blocked

#18
thanks,

are you sure about that?

if a door is closed, and someone knocks on it.
if i do not open the door, it is closed.
if i ask 'who is there` and ignore the knocker, then that is filtered.

so it this website wrong?
http://www.ipv6scanner.com/cgi-bin/main.py
OPEN   An application is listening for connections on that port.
CLOSED   No application listening on that port.
FILTERED   The port is blocked by firewall or other network obstacle.
#19
hello and thanks,
using opnsense as a home router and working great.

i did a netscan from the internet and noticed that ports such as smtp are `filtered`, not closed.

i am sure there is a logic to that approach but would it not be better to have unused ports closed, to just drop the packets and reply at all?

thanks much,
jojo


#20
hello and thanks,

my opnsense router is running dnscrypt and that is working well.
also, i have installed the shadowsocks server.

on my computer, on the lan from that opnsense router.
i am running a shadowsocks client.

using ms-edge, not using that shadowsocks clients, dnsleaktest results look very good.

using my main browser, firefox, pointing to that shadowsocks client, internet is working.

using firefox, having ENABLED "Proxy DNS when using SOCKS v5"
i do a dnsleaktest, the results are not good, pointing to my isp dns, verizon.

using firefox, having DISABLED "Proxy DNS when using SOCKS v5"
i do a dnsleaktest, the results are good, clearly using the dnscrypt


note: that on the opnsense router, if i setup a ssh tunnel like so, then firefox proxy dns works.
ssh -D 8123 -f -q -N asdffdsa@OPNsense

so why using shadowsocks, the dns is not using dnscrypt server,
but using that ssh tunnel, the dns is using the dnscrypt server?

thanks,
david
#21
hello and thanks,

my opnsense router is running dnscrypt and that is working well.
also, i have installed the shadowsocks server.

on my computer, on the lan from that opnsense router.
i am running a shadowsocks client.

using ms-edge, not using that shadowsocks clients, dnsleaktest results look very good.

using my main browser, firefox, pointing to that shadowsocks client, internet is working.

using firefox, having ENABLED "Proxy DNS when using SOCKS v5"
i do a dnsleaktest, the results are not good, pointing to my isp dns, verizon.

using firefox, having DISABLED "Proxy DNS when using SOCKS v5"
i do a dnsleaktest, the results are good, clearly using the dnscrypt


so why using shadowsocks, the dns is not using dnscrypt server?

thanks,
david
#22
i installed shadowsocks... all is good. thanks
#23
just before you posted, i figured that out.

going from openwrt to opnsense is a learning process

thanks much!

edit: duh, i replied to the wrong post, my post was the one previous to this one.
but the topic was the same, about socks proxy.
so still it applies - thanks
#24
hello and thanks,

in the past, i used a socks5 proxy over ssh, very simple and easy.

now at home, i am using opnsense,  have a road warrior ssl vpn.

so when i am outside the home, i need a simple socks5 proxy for my web browser - firefox.

that caching proxy seems very complex and not sure that it can work as socks5 with firefox

please, can someone help me understand my options.?
thanks,
jojo
#25
excellent, thanks much
#26
hello, newbie to the forum, if i posted in the wrong section, sorry about that.


the log is full of entries like
"wan      Jan 18 16:46:17   185.156.73.65:49302   xxx.xxx.xxx.xxxx:xxxx   tcp   Default deny rule"

i want to disable that from the log.
so using web gui, i goto "firewall/rules/wan" but i cannot find that default deny rule, thus i cannot disable the log.
so what am i doing wrong?

thanks much,
david