Quote from: JeGr on September 04, 2026, 01:01:33 PMWenn die Entscheidungen durch sind, ist es nur noch ein Zusammmenstecken der Komponenten. Je nach Konfiguration kannst du dann AGH auf internem Interface auf 53 lauschen lassen, Unbound auf 5353 umziehen und dem AGH als Forward dann localhost:5353 verpassen damit er das an den internen Unbound weitergibt. Der macht dann die Endauflösung via Roots und Resolving. Wenns DNSmasq ist, gleiches Spiel. Das was die Clients bekommen/erreichen sollen, sollte auf Por 53 laufen, den Rest packt man auf andere Ports und forwarded da hin.
Kea ist da eigentlich DHCP-technisch völlig simpel und annähernd gleich mit ISC zu konfigurieren. Außer du hast große Sonderlocken mit irgendwelchen DHCP Optionen und Co., das könnte dann problematischer werden, aber für Standard run-of-the-mill normalen DHCP gibts da gar nicht viel zu failen.
Quote from: pfry on Today at 07:50:12 AMThanks, Steve.
Sure, just run all connections through the firewall. I do this. In general you just need enough compute power in your firewall (varies by application) and appropriate connectivity (e.g. lots of ports on the firewall and/or virtual ports via one or more managed Ethernet switches).
Quoteallow-opts
By default, packets with IPv4 options or IPv6 hop-by-hop or destina-
tion options header are blocked. When allow-opts is specified for a
pass rule, packets that pass the filter based on that rule (last
matching) do so even if they contain options. For packets that match
state, the rule that initially created the state is used. The im-
plicit pass rule, that is used when a packet does not match any
rules, does not allow IP options or option headers. Note that IPv6
packets with type 0 routing headers are always dropped.
Configuration Information.
Interface assignments:
em0 -> [MGMT]
igb0 -> [WAN]
igb1 -> [LAN]
Management IP address: 10.200.128.2/24
Management Gateway address: 10.200.128.1
Internal DNS server: 10.199.201.254
Configuration steps to prepare a system as a Transparent Firewall using the Serial console.
Perform a Factory Reset of OPNsense.
- Connect a computer to the serial port on the OPNsense device using a baud rate of 115200
- Power on OPNsense device
Ignore configuration importer
When message appears regarding interface assignment options, press a key when prompted.
- Do you want to configure LAGGs now? [y/N]: <Enter>
- Do you want to configure VLANs now? [y/N]: <Enter>
The list of available interfaces.
Valid interfaces are:
igb0 b4:96:91:8c:a0:f8 Intel(R) I350 (Copper)
igb1 b4:96:91:8c:a0:f9 Intel(R) I350 (Copper)
igb2 b4:96:91:8c:a0:fa Intel(R) I350 (Copper)
igb3 b4:96:91:8c:a0:fb Intel(R) I350 (Copper)
em0 48:4d:7e:ee:1b:4e Intel(R) I219-LM SPT(5)
- Enter the WAN interface name or 'a' for auto-detection: <Enter>
- Enter the LAN interface name or 'a' for auto-detection
NOTE: this enables full Firewalling/NAT mode.
(or nothing if finished): <Enter>
- Enter the Optional interface 1 name or 'a' for auto-detection
(or nothing if finished): em0
- Enter the Optional interface 2 name or 'a' for auto-detection
(or nothing if finished): igb0
- Enter the Optional interface 3 name or 'a' for auto-detection
(or nothing if finished): igb1
- Enter the Optional interface 4 name or 'a' for auto-detection
(or nothing if finished): <Enter>
The interfaces will be assigned as follows:
OPT1 -> em0
OPT2 -> igb0
OPT3 -> igb1
- Do you want to proceed? [y/N]: y
The OPNsense banner after completing the boot process.
*** OPNsense.localdomain: OPNsense 26.7.3_11 (amd64) ***
OPT1 (em0) ->
OPT2 (igb0) ->
OPT3 (igb1) ->
HTTPS: SHA256 6E C9 0B 92 1B AB C9 15 20 B1 D2 76 08 EF 80 98
C4 6F E0 91 4C 04 EE 05 FB FB 34 AA 49 F8 7F F2
FreeBSD/amd64 (OPNsense.localdomain) (ttyu0)
login:
Log in as root.
- Select option 2 - Set interface IP address
- Select 1 - OPT1 (em0)
- Configure IPv4 address OPT1 interface via DHCP? [y/N] N
- Enter the new OPT1 IPv4 address. Press <ENTER> for none:
> 10.200.128.2
- Enter the new OPT1 IPv4 subnet bit count (1 to 32):
> 24
- For a WAN, enter the new OPT1 IPv4 upstream gateway address.
- For a LAN, press <ENTER> for none:
> 10.200.128.1
- Do you want to use the gateway as the IPv4 name server, too? [Y/n] n
- Enter the IPv4 name server or press <ENTER> for none:
> 10.199.201.254
- Configure IPv6 address OPT1 interface via DHCP6? [y/N] <Enter>
- Enter the new OPT1 IPv6 address. Press <ENTER> for none:
> <Enter>
- Do you want to enable the DHCP server on OPT1? [y/N] <Enter>
- Do you want to change the web GUI protocol from HTTPS to HTTP? [y/N] <Enter>
- Do you want to generate a new self-signed web GUI certificate? [y/N] <Enter>
- Restore web GUI access defaults? [y/N] Y
The OPNsense banner after IP assignment.
*** OPNsense.localdomain: OPNsense 26.7.3_11 (amd64) ***
OPT1 (em0) -> v4: 10.200.128.2/24
OPT2 (igb0) ->
OPT3 (igb1) ->
HTTPS: SHA256 6E C9 0B 92 1B AB C9 15 20 B1 D2 76 08 EF 80 98
C4 6F E0 91 4C 04 EE 05 FB FB 34 AA 49 F8 7F F2
0) Logout 7) Ping host
1) Assign interfaces 8) Shell
2) Set interface IP address 9) pfTop
3) Reset the root password 10) Firewall log
4) Reset to factory defaults 11) Reload all services
5) Power off system 12) Update from console
6) Reboot system 13) Restore a backup
Enter an option:
- Select option 0 - Logout
Log in to the WebGUI.
- Interfaces -> Neighbors -> Automatic Discovery
- Enabled: untick
- Click 'Apply'
Update descriptions for OPT1, OPT2 & OPT3.
- Interfaces -> [OPT1]
- Description: MGMT
- Click 'Save'
- Interfaces -> [OPT2]
- Description: WAN
- Click 'Save'
- Interfaces -> [OPT3]
- Description: LAN
- Click 'Save'
- Click 'Apply changes'
Add and assign the Bridge interface.
- Interfaces -> Devices -> Bridge
- Add
- Member interfaces: WAN, LAN
- Click 'Save'
- Click 'Apply'
- Interfaces -> Assignments
- Add
- Description: BRIDGE
- Select device from drop-down list: bridge0 ()
- Click 'Save'
- Click 'Apply'
- Interfaces -> [BRIDGE}
- Enable: tick option
- IPv4 Configuration Type: None
- IPV6 Configuration Type: None
- Click 'Save'
- Click 'Apply changes'
Disable firewall Source NAT.
- Firewall -> NAT -> Source NAT
- Mode: Disable Source NAT rule generation
- Click 'Apply'
Configure Unbound to forward queries to the internal DNS server.
- Services -> Unbound -> Query Forwarding
- Use System Nameservers: tick
- Click 'Apply'