Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - smajor

#46
No, the only thing I made sure to do was set the power options in OS X first so it would never go into sleep. This writes them to PRAM so your firewall won't go into hibernation with a different OS.

I then just used the OPNsense CD I made and installed it by booting from the CD.  When it was done it booted fine.
#47
When I was testing, I ran it on one of the original "white" Mac minis (Core 2, 18.3GHz) I had lying around - the answer is - not much at all for a home router. It's very efficient.
#48
15.7 Legacy Series / Re: Squid cache seems to not be used
December 16, 2015, 07:48:08 PM
I was looking for roughly the same, there is a ticket in for some expanded Squid options via the GUI.  I hope the 16.1 milestone for them comes true! (I also wish I could code at all so I could help.)

https://github.com/opnsense/core/issues/417
#49
I'm not using OPNSense with VB, but I have used VirtualBox on the same model Mac mini you have.

My experience mirrors yours on network thru-put and high CPU usage. Don't get me wrong, VirtualBox is fantastic for needing to run something once in awhile (free!), but for a better experience I'd look at Parallels or VMware (We use the former at work and I use the latter at home.)

I switched to VMware for my 24/7 app and my CPU usage for the same version of Windows dropped to 1/3rd what it was and my transfer speeds improved drastically.

Before I bought, I downloaded the 30 day trial. You might want to give it a try and see if it solves your issues.

Alternately, for home, I picked up one of these small form factor HPs for about $50US on eBay and reused a 100MB USB Ethernet Adapter on my WAN side. OPNsense works wonderfully with it!

http://www.newegg.com/Product/Product.aspx?Item=N82E16883281931
#50
15.7 Legacy Series / Re: Firewall: NAT: Port Forward
December 14, 2015, 02:31:48 AM
Mine looks just like yours, except as you noted from your examples mine uses WAN.

When setting up the NAT, you need to click Advanced and it should be in the list as "WAN Address" I believe.
#51
15.7 Legacy Series / Re: DNS MX Record?
December 07, 2015, 11:54:20 PM
Quote from: smajor on December 06, 2015, 06:06:33 PM
Apologies if this is in the GUI and I'm overlooking it.  I'm interested in having OPNsense take over my DNS duties as it seems to do everything I need for my relatively simple LAN.

I need one host to have an MX record, but I can't seem to find an option to add it. If it does not exist, maybe a simple checkbox "
  • Add an MX Record for this host" could be done at some point?
Okay, I looked high and low for this, I don't believe it currently exists. I'm going to make a formal request over in GitHub.  :)
#52
15.7 Legacy Series / [SOLVED] DNS MX Record?
December 06, 2015, 06:06:33 PM
Apologies if this is in the GUI and I'm overlooking it.  I'm interested in having OPNsense take over my DNS duties as it seems to do everything I need for my relatively simple LAN.

I need one host to have an MX record, but I can't seem to find an option to add it. If it does not exist, maybe a simple checkbox "
  • Add an MX Record for this host" could be done at some point?
#53
15.7 Legacy Series / Re: Random Non-Responsiveness
November 29, 2015, 12:09:49 AM
For what it is worth, I went all week with 15.7.18. No problems at all. I just updated to 15.7.20 with no other changes and I'll see how that goes.
#54
15.7 Legacy Series / Re: Random Non-Responsiveness
November 25, 2015, 03:26:15 PM
Thanks for the reply. I know it may not be of much help, but my usage for OPNsense right now is not too complex:

- WAN interface, statically assigned from my ISP.
- LAN interface, 10.0.1.1/24.
- DHCP 10-100 range and statically assigned addresses in 200-225 range.
- * URL lists, a mix of URL Table (IPs) and URL IP types aliased to firewall rules.
- About a dozen NAT enteries.

Not too exotic. Since rebuilding on the 21st it's been stable.

* I'm not using any aliases/url rules currently and am on 15.7.18.  I'm trying to test one thing at a time so I can at least tell you "when I added this, I saw it again."
#55
15.7 Legacy Series / Re: Random Non-Responsiveness
November 22, 2015, 03:04:04 PM
So, this morning I walk into no internet, no response on the LAN side, figure it's just a reboot again.  OPNsense comes up, still no internet. I can get to its console, no errors.  Reboot again. Check settings. Everything seems to be in order. Intranet is okay, WAN is configured, just no talking.

I pull the old OPNsense box I was using off the shelf, plug it in and everything works. I'm at a loss. Something isn't stable here, I'm going to try and investigate some more.

Edit: I've tried re-configuring both the LAN and WAN on the box, still no WAN. My WAN adapter is a USB dongle, I tried a different one, still no WAN.  I tried reverting to a previous configuration, still no WAN.  Status shows "up" LEDs on both ends of the adapters lit, just no traffic.

Whatever happened to this box probably has corrupted a service beyond my ability to locate. I will probably rebuild it again, this time sticking with 15.7.18. As I mentioned, the two recent changes I did were update to 15.7.19 and enable DHCP.  I'd much rather have an operable DHCP, so I'll test the other way first.
#56
15.7 Legacy Series / Re: Random Non-Responsiveness
November 21, 2015, 08:50:10 PM
Really? DHCP is a core service, I'd hope it is stable. I didn't see anything over in the issues at Github for this. Maybe a dev will comment soon.
#57
15.7 Legacy Series / Random Non-Responsiveness
November 21, 2015, 07:02:48 PM
Hi all, somewhere around 15.7.19, or my enabling DHCP, OPNsense has started randomly freezing. All interfaces go dead and I'm forced to power off and back on.  I run the CPU headless, so I don't see what might be happening on the screen. I've attached a display for "next time."

The interval can be completely random.  Several days to just hours apart.  Mostly the latter.

I thought maybe the older hardware I was on was having a problem, so I migrated to a newer box.  The exact same issues happen with it.

The web GUI doesn't detect a programming, but I submitted one via that mechanism anyhow in hopes that may show something. Are there any other logs available via the shell I can look at or submit?
#58
Thanks, it seems to have accepted a rule with that. Currently testing.  I think you meant:

fetch https://raw.githubusercontent.com/opnsense/core/b05657e166ce90cc485122f2debe7605a6f54e50/src/etc/inc/util.inc

;)
#59
No worries at all, I'm glad to be able to contribute some troubleshooting time.
#60
I gave the fix a try, while I can now select it, I received an "Unresolvable source alias 'Panama' for rule 'PA 25 Block'" for that URL rule.

Using the non-Table version still works as expected with the same URL source.