Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - vpx23

#121
Rule #7 was the LAN net to LAN net, maybe you already deleted it?

https://whatsmyip.com shows your private address?

Please show a screenshot of both https://whatsmyip.com and https://ipchicken.com
#122
Du müsstest ja noch ein VLAN für die Telefonanlage erstellen (z.B. 50), sonst weiß sie ja gar nicht wohin die Pakete gehen sollen.

Der Internet-Traffic würde dann über das Default-VLAN 1 laufen. Im VLAN 50 kannst du dann das Gateway vom WAN VLAN 20 eintragen und bei LAN das Gateway vom WAN VLAN 10.
#123
First you need to create 3 host aliases, just call them as you listed:

Name: NONVPN:
Content: 192.168.5.2-192.168.5.100

Name: OpenVPN_USA
Content: 192.168.5.101-192.168.5.150

Name: OpenVPN_INT
Content: 192.168.5.151-192.168.5.200

In the LAN rules change the source of #1 to NONVPN.

In rule #5 change the source to OpenVPN_INT and the destination to any (to be changed later).

In rule #6 change the source to OpenVPN_USA.

Delete the rules #2, #3, #4 and #7

Delete the Out-Gateways because they don't make any sense.

Now you just have to get your USA OpenVPN working and add another one for your offshore VPN.

Enter the gateway for the offshore VPN in the rule with the OpenVPN_INT source.
#124
OK,

1. Show us a screenshot of System->Gateways->Single
2. Show us a screenshot of Interfaces->WAN
3. Show us a screenshot your VPN->OpenVPN (->Clients?) configuration
(black out any passwords)

www.whatismyip.com will show your public IP address of the WAN interface not your private address inside the LAN.

Also you can't have the source address of your LAN devices as a gateway. Are these xxx_Out aliases in Firewall->Aliases?
#125
We need to know what are WAN_PPOE (interface or gateway?), 178_Out, 180_OUT, 179_Out, NORDVPN_VPN4 or we won't get any further. I'm not sure if there are actually any gateways set up under System->Gateways->Single.
#126
The last rule is obsolete because LAN-to-LAN traffic is handled by your switch and not by the router (OPNsense in this case).
#127
23.1 Legacy Series / Re: locked out of appliance?
July 06, 2023, 08:33:14 PM
Do you mean you had "Settings->Administration->Secure Shell->Listen Interfaces" set to e.g. ix0 for LAN and now the new hardware has e.g. igb0 for the LAN interface?

In this case couldn't you just edit the backup file and change this setting to any again? Assumed that the file wasn't encrypted with a password.
#128
Hallo Mark,

wir haben so ziemlich den gleichen Aufbau mit den Multi-WANs (1. Leitung Internet, 2. Leitung Cloud PBX) und Load-Balancing. Nur zusätzlich noch LTE und SAT im Tier 2 als Backup.

Bei dem Cloud PBX muss man ja zwingenderweise die Telekomleitung verwenden, weil die Telefone auf anderen Leitungen DNS-Query Fehler haben (tel.t-online.de ignoriert Anfragen von fremden Leitungen).

IPSec lief zu der Zeit noch nicht richtig, deshalb kann ich nicht sagen ob es einen Einfluss darauf hatte aber wir hatten Probleme mit Webbrowser, Teams, Outlook etc.

Wenn die Firewall die Leitungen wechselte waren die Verbindungen durch die "Sticky Connections" wohl noch auf der anderen Leitung und es ging alles erst nach ein paar Minuten wieder (Timeout?).

Erst hatte ich "Shared forwarding" deaktiviert, da ich gelesen hatte, dass es auch Probleme machen kann mit Multi-WAN, aber am Ende war es wohl das Deaktivieren von "Sticky connections" was die Verbindungsprobleme behoben hatte.