Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - cookiemonster

#16
thanks for the insight @Patrick M Hausen
#17
Could you install htop, launch with admin privs and sort by CPU ? May show a clue
#18
Wrong domain? It comes from your settings: System | Settings | General
So you need to set the correct domain there and the config will adapt. As for the unix timestamp I'm sure there was a discussion about it before on the forum. It must habe been agreed to leave for a reason. Of course finding the conversion from unix epoch is easy but we all know that.
#19
From https://forum.opnsense.org/index.php?topic=52223.msg269736;topicseen#msg269736 and initially for @philippe_crowdsec

Thank you first of all for allowing to reach you with these product questions.
As I wrote there, I was enthusiastic at the beginning with Crowdsec when you came on this forum to request early users and feedback for it. I went on to install the Crowdsec plugin and moved to a distributed setup where OPN runs the LAPI and expose it to other servers. So far so good.
What disappointed me since then in I think was 2022 was the lack of inclusion of the developments in Crowdsec into this OPN plugin. It can still only install os-crowdsec, the plugin itself, crowdsec and the crowdsec-firewall-bouncer.
So it can "only" list the hub plugins (parsers, scenarios..) and decisions on the OPNsense admin interface but not manage them. Not add them, modify or remove them. The opnsense-generic collection is at version 0.5 on the hub. Version 0.2 for brute force protection. Tells a lot, like it was done and then left. No more collections are available for it. The history in github tells us it was created in 2022, updated once in 2023 and a bit of a generic spruce up this year for labels, tags and such like.

One of the main difficulties in integrating is with other OPN plugins. For example if I run the haproxy plugin (which I do), then the parsing of its log file mainly reports failures to parse. Whether it is because is not vanilla haproxy or freebsd logging I don't know but I had a hard time last time to get your people's attention to this on discord https://discord.com/channels/921520481163673640/1296828602398015540/threads/1342642325226000404 where my continuous attempts were categorised at spam.

Maybe you can begin to see my point. Initial setup of plugin fine but seems almost abandoned since. Interactions in a medium like Discord is hard for a technical issue, and then "staff" were less than helpful.

So, although I don't want it to be a complaintfest, I wanted to provide the context and difficulties.
What do I want from the thread?
A view on what can we expect as improvements to the OPNSense experience of using Crowdsec. Right now it feels we are providing signals and in return a mostly IDS. I'd like to have it explained how to get to use IDP for instance leveraging WAF for haproxy using the plugin.
And does anybody else feel they're using it better than the defaults. How ?

Thank you for reading so far.

p.s. I also contributed this https://forum.opnsense.org/index.php?topic=44839.0 but now I'd love to use SPOA instead but that is not possible due to https://github.com/opnsense/plugins/issues/4923
#21
CPU bottlenecked by storage subsystem perhaps, trying to log.
#22
General Discussion / Re: Password Reset
July 06, 2026, 12:23:16 AM
Very good.
#23
Very graceful Murat. I appreciate the offer. Although I have the time currently, I lack the funds to purchase a licence; despite the favourable conditions.
I hope I will be in a better position soon to take it up, should the offer still be open. Much obliged.
#24
Quote from: philippe_crowdsec on July 02, 2026, 11:25:49 AM@cookiemonster: I'm interested in the discussion about CrowdSec.

The product is free (security engine, scenarios, vpatch, WAF rules, Claude skill, etc.) and is MIT-licensed.
A blocklist is shared amongst users who share signals, for free, and many more are also free of charge.
There is 0 cost on the OpnSense integration.

So I'd be interested to understand your feelings better (or maybe it's about the SaaS console)?
If you have time and the will to discuss this, please PM me.
Hi @philippe_crowdsec - thanks for the note. I will keep it short here so as to not hijack the thread. Yes those are free but my _main_ issue is that the integration was limited and was never advanced. The note since 2024 if I'm not mistaken is:
QuoteAt the moment, the CrowdSec package for OPNsense is fully functional on the command line but its web interface is limited; you can only list the installed objects and revoke decisions. For anything else you need the shell or the CrowdSec Console.
Which means most of the existing and new functionality is unmanageable from the plugin. For instance I can't use SPOA for haproxy on OPN when using the OPN haproxy plugin.
If you are still willing to listen to my points (thank you for the offer) I shall open a new post so we can discuss them. In the open I suspect will be suitable for other users too. If you agree. Again, thank you. Just confirm and I will.
#25
Quote from: thelittleblackbird on June 27, 2026, 12:42:34 AMhere you have it, in the attached file.

I tried to implement the tunnable described in the opnsense documentation about performance:
https://docs.opnsense.org/troubleshooting/performance.html

if you need something else just ask

thanks


If you have set RSS for that performance, it might need revisiting. Maybe it does not help and is detrimental in your case.
#26
Pics seems to be hosted in imgur. Those are unavailable in the UK (I can't see them). But it might apply also to other locales.
#27
It sounds like somehow your firewall rules are or were left too open and allowed traffic into your AdGuardHome port.
If you use the ADGH UI and go to "Setup guide" you'll see it listening to all interfaces unless you've changed from defaults, which are the result of "$ifconfig | grep inet" on your OPN.
That will include your WAN ip address.
Therefore my thinking is firewall rules need revising.
So 1. **Open DNS resolver on the WAN**: seems to have caught it. It might only need reset of firewall states. Hopefully.!
#28
Clear, thank you all contributors.
#29
I don't have a paid subscription but I was at the start very willing to be helpful and was engaged with their support team to help them help me diagnose problems and in return they got to improve their product. It felt the fair tradeoff of being early user/tester for a free product. All as expected.
As time has gone by I am more and more disheartened with the trajectory so far taken, in that it feels now they've had our use, they can move to their paying market with a more mature product.
Again, not unexpected BUT as with the functionality gone that used to be free and the main one, multicore, exactly as you have clearly explained, has had me 1) wondering if it is still worth the machine's stress for what it gets 2) whether to stop using it.
It seems the balance against us is too uneven. The impression that they have taken without giving back to balance the scales a bit for us early testers is the more bitter one.

A similar thinking is growing with Crowdsec to be honest but this is not the place for this one.

So yes, same impressions, same fork in the road. No decision taken yet but feels close. I don't know yet what will replace it though.
#30
Quote from: newsense on June 25, 2026, 08:26:06 PM>>> Avoid Server Certificate Lifetimes > 397 Days


Or simply use your own certificate that can be issued from OPNSense, and enjoy 730 days of certificate validity. This is the hard limit from Apple for private/enterprise CAs

As long as you're controlling everything else on your VPN/devices importing your own CA everywhere is a no brainer.
So is this not going counter to the 397 days advice above? Asking because last time i was on this, the amount of effort I put into in vain was high.