Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - athisesanr

#16
Hi Patrick  ;)

I ve received this information when I inspect the UI and still to be try to understand is there any norms to be supported in business edition with restful API for all UI taps?

Also, i just started to edit the config.xml file where I need rules and nats (outbound & 1:1) which is working without full restart.

Anyhow I may recheck with you that config.xml edit is good practice? lets we do have governance and QA during the edits and does it helpful till the full api release?

Thanks,
Athisesanr
#17
Hi Barlod,

thanks for reverts.,

doing pfctl -f thing will flush and config.xml edit will not possible while system live as what i understands. however, I'm trying to fine exact cli or api rules where can directly post interface own or floating as get/post/delete/modify instead of /api/firewall/filter/getRule


flush ALL   pfctl -F all
flush only the RULES   pfctl -F rules
flush only queues   pfctl -f queue
flush only NAT   pfctl -F nat
pfctl -F info   flush all stats that are not part of any rule


also, keep searching any other forums will give exact path to find the solutions at least in cli level.!!

Relevant forum,
https://forum.opnsense.org/index.php?topic=3553.0
https://forum.opnsense.org/index.php?topic=16943.0
https://forum.opnsense.org/index.php?topic=6415.0

Thanks,
Athisesan R

#18
Hi Team,

Greetings.,

I am trying to integrate the MS-AD server for OpnSense LDAP and integration got success also able to login as single user. in the meantime, trying group OU where the all the users are mapped getting login user issue.

"Permission are allowed to all gui and ssh also authentication allowed both ldap and localusers"

I have checked synchronize groups, constraint groups, Automatic user creation from LDAP server integration.

Login scenarios post LDAP success,
1. Induvial User logins - working
2. Group User logind - not working
3. Additional, group user login works if induvial user logged in atleast one time and get disabled or unused.

Thanks,
Athisesan R


#19
Hi Folks,

I am curious to understand does OpnSense support 3rd party security scans such as Rules, vulnerability related.

I'm great if any existing forum extended the same narrow.

example, AlgoSec, LogRhythm and QRader etc.

Thanks,
Athisesan R
#20
Hi Folks,

Anyone can assist here to find the cli format of creating rules/nats. I been looked more forum there are no clueless. I hope there are no easy rules type here that what PfSense followed.

Also, I just verified some API docs that only focus the Automation Filter rules not an exact Floating and Interface rules directly.

Automation filter rules doesn't supports Allies options there.

below docs only focused automation filter rules instead of interface own or floating rules,
https://docs.opnsense.org/development/api/plugins/firewall.html
https://docs.opnsense.org/development/api/core/firewall.html

Thanks,
Athisesan R
#21
Greetings,

I was curious if there was a way to add firewall rules from the command line/console?
Apologies if this has been answered elsewhere, however I could not find anything through my forum search.

Version: OPNsense 24.1.4-amd64

Regards.
Athisesan R
#22
Hi Folks,

I just reworked with Administration Configuration where the Listen Interface under WEBGUI.

HASYNC starts works post add the ha interface into the Lister Interface

System Administration >> WebGUI >> Listen Interface >> Add the Ha interfaces

Thanks,
Athisesan R
#23
Hi Team,

We are facing HA SYNC issue between the two OpnSense VM Firewall post latest patch upgrade from 24.1.3 to 24.1.4

Below checks are verified,
- HA users and Credentials and authorizations are same on both firewall.
- Firewall Rules are allowed.
- Able to reach and SSH one to one VM using HA nics configured IPs and logins.

Looking expediate answer or solution to be checks on shell level.

CLI Error below,
hasync@TR-DZM-NWENG-FW02:/usr $ local/etc/rc.filter_synchronize
send >>>
Host: 172.16.0.1
User-Agent: XML_RPC
Content-Type: text/xml
Content-Length: 117
Authorization: Basic aGFzeW5jOlRhdGFAMTIz
<?xml version="1.0"?>
<methodCall>
<methodName>opnsense.firmware_version</methodName>
<params>
</params></methodCall>received >>>
error >>>

Thanks,
Athisesan R
#24
Hi Team,

Adding my problems to here, that every opnsense action such as route , interface or rules edits gives gui/ping loss and suspecting that automatically rules are plays to deny the traffic. Therefore post pfctl -d cmd execute that allow to another changes.

Is any one help here that why every action on opnsense trigger pf enables and loss the gui/pings drops. Is there way to delete the automatically rules from opnsense.

I'm using opnsense as vm on kvm.

Thanks,
Athisesan



#25
Hi Folks,

Anyone can help us find a way to remove or disable the auto-generated rules in Opnsense.

Having issues with LAN-to-WAN traffic even allowed ANY-ANY for test cases.

Also, I just tried to modify the /usr/local/etc/filter.lib.inc but its root cli ends with permission denied. -(hope root user will have all the rights to add, modify and delete.)
#26
If I disable this option then entire firewall options will be disabled right..!

is there any other way to prevent the manual cli types pfctl -d cmd after every change dones.
#27
Hi Folks,

I'm new to Opnsense and am about to check the possibility of permanent pf disability in Opnsense since we are facing issues like every gui change will get my pf enabled and the get manual enable using pfctl -d on the moments.

Thanks,
Athisesan R