Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - beneix

#46
General Discussion / Re: Install PiHole on Opnsense
February 25, 2024, 09:16:13 AM
Before I got myself an OPNSense router, I ran piHole on an RPi. When I switched to OPNSense, I went for AdGuardHome running on the same APU as OPNSense and I am very happy with the result, performance, blocking and GUI. I recommend trying it out.
#47
24.1, 24.4 Legacy Series / Re: Upgraders beware
February 16, 2024, 01:44:19 PM
I think what would be useful would be to have a "Report 24.1 upgrade issues here" thread. This would not be for just venting, it should specifically contain issues encountered as a result of the nominated upgrade – and offer a place for support with such issues.

Perhaps the naming "Upgraders beware" in itself is slightly charged, leading to venting...
#48
24.1, 24.4 Legacy Series / Re: Upgraders beware
February 14, 2024, 06:41:37 PM
OK, I will try when I get a moment. On the APU, how does one choose a boot environment after creating multiple ones using bectl? Is that done via the serial console?
#49
24.1, 24.4 Legacy Series / Re: Upgraders beware
February 14, 2024, 05:56:04 PM
Quote from: Patrick M. Hausen on February 14, 2024, 05:49:30 PM
You can always perform a fresh install and import a saved configuration.
Thanks Patrick, I found your guide on ZFS and roll-back. Just one question: I am on 23.7.10_1. The only install I can download on 23.7 is...23.7. Will importing a configuration backed up from 23.7.10_1 to a 23.7 install cause issues?
#50
24.1, 24.4 Legacy Series / Re: Upgraders beware
February 14, 2024, 04:45:31 PM
Quote from: Patrick M. Hausen on February 14, 2024, 04:17:32 PM
Are you running on ZFS?
No. When I installed this a couple of years ago, I had no idea about ZFS. From what I have just Googled, it seems it is possible to install with ZFS on the APU but I am not sure I am up for the hassle of somehow mirroring the current install to a backup device, reformatting the device with ZFS and restoring the installation...

I deduct from your question that without ZFS, there is no easy way to roll back?
#51
I'm ready to try the upgrade but would like to know if there is a way to prepare so that I can do a full roll-back in case I have issues that are difficult to solve? I am running OPNSense on an APU2E4.
#52
Ï used to have an XDSL connection that meant I had to use QoS to ensure my videoconferencing worked OK. When we were moved to fibre I just updated the bandwidth and quantum numbers in the traffic shaper settings and thought nothing more about it. Because of the much faster connection, things mostly work OK.

Then I decided to run a bufferbloat test and was surprised to see I only got a "C" rating from https://www.waveform.com/tools/bufferbloat. I connected via Ethernet directly to the OPNSense router and ran the test again - same result. Then I tried turning traffic shaping off and now I got a rating of "A". This puzzles me - why does the traffic shaping now make bufferbloat worse on my fibre connection, when it used to make things better on the XDSL connection?

My traffic shaping settings are:
Pipes
Down
  Bandwidth 430 Mbps
  CoDel not enabled
  (FQ-)CoDel ECN enabled
  FQ-CoDel quantum 1290
Up
  Bandwidth 290 Mbps
  CoDel not enabled
  (FQ-)CoDel ECN enabled

Queues
Down
  Weight 100
  mask destination
  (FQ-)CoDel ECN enabled
Up
  Weight 100
  mask source
  (FQ-)CoDel ECN enabled
Rules
Down
  Interface WAN
  Protocol ip
  Source any
  Src-port any
  Destination 192.168.2.0/24 (the OPNSense is 192.168.2.0 and hands out DHCP addresses 192.168.2.1-255)
  Direction both
  Target download queue
Up
  Interface WAN
  Protocol ip
  Source 192.168.2.0/24
  Src-port any
  Destination any
  Direction both
  Target upload queue

I could just leave the traffic shaping turned off and forget about it, but I would like to understand what is going on in case I need to turn it on in the future.
#53
Quote from: Patrick M. Hausen on January 01, 2024, 01:00:22 PM
If you are experiencing packet loss between OPNsense snd the router directly connected to WAN, check for a duplex mismatch of the interfaces involved and check the cabling.
Thanks. On the fibre router, it is showing the interface as 1000 Mbps and full duplex, on the OPNSense the interface is shown as 1000baseT <full-duplex>. Is that what you were referring to?

The cable between the OPNSense and the fibre router is a 25cm CAT6 cable. I have tested changing it for another cable without any effect, and I have also tested the same cable to connect the Smokeping RPi to the fibre router and the result was no packet loss with the same cable that is now connecting the OPNSense to my fibre router.
#54
Quote from: doktornotor on December 31, 2023, 07:55:22 PM
System - Gateways - Single - Edit - Advanced - Data Length. Set this to something else than 0. If 1 does not help, try 32 or 56.
Thanks. I tested changing the data length to 1, then to 32, then to 56. This is the gateway quality graph:


The data length change does not seem to have made any difference. Any other ideas?
#55
Quote from: doktornotor on December 31, 2023, 07:25:57 PM
Maybe you should just quit trying to DoS things with ICMP.
I am afraid I am not knowlegeable enough to understand what you mean, can you please help me understand? Are you suggesting that the pings via ICMP that the Smokeping server sends each minute would be too much for the OPNSense router?

QuoteAdditionally, setting the GW monitoring payload to something other than the default 0 might help to get answers in a more normal way.
How do I set this?

QuoteAre you experiencing some real issues (as opposed to smoking things with ping)?
I am seeing OPNSense show a 15-50% packet loss indication on the Dashboard (this was before I had the Smokeping server installed) and I was wondering if this could explain issues I occasionally have with videoconferencing.
#56
Update: I deactivated the traffic shaping in the OPNSense firewall and made sure that the Smokeping RPi was using external DNS servers (my ISP's and Quad), thereby eliminating AdGuard from the equation. The result (still with Smokeping hooked up behind OPNSense) was that some internet servers saw less maximum loss, some had higher maximum loss over 30 hours of measurements. This tells me the problem is neither with the traffic shaping, nor with AdGuard Home.

Any ideas what could be causing the packet loss? As mentioned, when hooking up the Smokeping RPi after OPNSense, directly to my ISP's fibre router, there is zero loss on all but on external server.
#57
I need help understanding an issue I seem to have with packet loss on my OPNSense router or my ISP fibre gateway.

I have a home network that connects to an OPNSense APU router, which in turn is connected to my ISP's fibre router (see diagram). The ISP router and the APU2E4 both have Gigabit NICs (in the case of the OPNSense APU, Intel I210-AT) and are connected by a brand new CAT6 Ethernet cable.



I was noticing that OPNSense was telling me about packet loss on the gateway, sometimes quite high (30%).



I decided to check the Quality/gateway chart and was shocked to see loss peaks of 50%. Comparing these in time to the traffic on the router, I can tell that the loss percentage goes up when there is little traffic and down when traffic is high, which I can see makes sense.



I am obviously not happy with having loss of this magnitude in the first place. I therefore installed smokeping on a Raspberry Pi and hooked it up to my network. First, I had it connected directly to my ISP's fibre router; then it was not showing any loss at all on Google, BBC, the ISP's DNS server, etc. Only one site showed some loss. Then I moved it and connected it behind the OPNSense router. There, I set smokeping to track some internet servers, the second and first hop of my ISP, the fibre router and the OPNSense router. Below are the results.









There is no indication of a problem behind the OPNSense router, but some internet servers are showing high loss numbers. The gateway (my ISP's fibre router) shows a very minor max loss. Strangely, there is a significant difference in max loss between the first and second hop (as determined by tracert) of my ISP - 62% and 8%, respectively.

At this point, my evidence is ambiguous - there seems to be something with my OPNSense router causing the packet loss, but how can I track this down? I am running AdGuard Home on the router, but it seems odd that this would generate packet loss as measured against the gateway by OPNSense. Also, I intentionally included both a web address version and an IP version of some servers for smokeping to test; for one server, the IP version got slightly less loss, for the other, slightly more. This suugests there is no consistent detrimental impact on packet loss by AdGuard. I also run traffic shaping, set up very simply with an upload queue and a download queue, set at the normal bandwidth delivered by my ISP (as measured by nightly speedtests from OPNSense). The shaping uses FlowQueue-CoDel ECN.

Any suggestions on how to further diagnose this would be very welcome.
#58
Quote from: M4DM4NZ on April 10, 2017, 01:34:53 PM

Step 7.

- Navigate to Firewall > Aliases > View
- Add a new Alias
- Name: VPNTraffic
- Description : VPNTraffic
- Type: Host:
- First entry: 192.168.X.X

NOTE: (enter the IP address of Computers/devices you want to be on the VPN here. I personally enter the IP address of my Wireless router I have attached to my LAN, The wireless router has DHCP enabled so all wireless devices connected to this access point have their traffic passed via the VPN )

Something seems to have changed since the OP - there is nowhere to put "First entry". I have a field "Content", but there I can only choose between a list of other aliases. There is also a "Categories" field.

Where should I enter the ip address(es)?
#59
Quote from: crissi on January 13, 2022, 06:31:14 PM
Hello,

i hope someone can explain me the implications / correct settings of the openvpn client configuration Don't pull routes and Dont add/remove routes

Every VPN Provider seems to have different settings here.

NordVPN
Don't pull routes               -> Unchecked
Dont add/remove routes    -> Checked

AirVPN
Don't pull routes               -> Checked
Dont add/remove routes    -> Unchecked

PIA
Don't pull routes               -> Unchecked
Dont add/remove routes    -> Unchecked

Can someone please help here?
Thx!

I am also confused about this - trying to set up a VPN client for PIA, but since I only want certain clients to go via this interface, I was thinking that also for PIA I should check "Dont add/remove routes". Am I wrong?
#60
After a couple of days' running, it still seems netflow is causing significantly higher CPU use than before the upgrade. I have turned off IPv6 completely (following these instructions) to see if that would help; it made no difference.
  PID USERNAME    THR PRI NICE   SIZE    RES STATE    C   TIME    WCPU COMMAND
15527 root          1  80    0    54M    36M CPU2     2  22.8H  27.78% /usr/local/bin/python3 /usr/local/opnsense/scripts/netflow/flowd_aggregate.py (python3.9)
51856 root          1  21    0    58M    28M accept   3   0:05   1.27% /usr/local/bin/php-cgi
66423 root          1  52    0    58M    28M accept   3   0:02   1.17% /usr/local/bin/php-cgi
83323 root          1  20    0    58M    28M accept   2   0:05   0.29% /usr/local/bin/php-cgi
88671 root         31  20    0  1130M   477M uwait    0  38:39   0.10% /usr/local/AdGuardHome/AdGuardHome -s run
18068 root          1  52    0    58M    29M accept   1   0:06   0.10% /usr/local/bin/php-cgi
14297 root          1  25    0    13M  3792K pause    3   0:00   0.10% /bin/csh
  241 root          7  52    0   104M    42M accept   2  19:32   0.00% /usr/local/bin/python3 /usr/local/opnsense/service/configd.py console (python3.9)
20283 root          1  20    0    88M    60M nanslp   1  11:59   0.00% /usr/local/bin/php /usr/local/opnsense/scripts/routes/gateway_watcher.php interface routes alarm
32301 root          4  20    0    49M    12M kqread   3   8:51   0.00% /usr/local/sbin/syslog-ng -f /usr/local/etc/syslog-ng.conf -p /var/run/syslog-ng.pid
73875 root          1  20    0    13M  2644K bpf      3   4:38   0.00% /usr/local/sbin/filterlog -i pflog0 -p /var/run/filterlog.pid
79273 root          1  25    0    13M  3016K wait     3   3:14   0.00% /bin/sh /var/db/rrd/updaterrd.sh

Does anyone have suggestions as to what I could attempt, other than turning netflow off?