Recent posts

#1
26.7 Series / Re: Crashing after update tp 2...
Last post by Patrick M. Hausen - Today at 06:38:52 PM
If you installed with ZFS (like you should) and created a snapshot of the system before upgrading to 26.7 (like you should), then yes. Otherwise no. Reinstall it is.

Can you use your smartphone to film the error messages scrolling by and then transcribe them?
#2
26.7 Series / Crashing after update tp 26.7....
Last post by mantissa - Today at 06:15:51 PM
A couple of day I update to 26.7.1. I am running a transparent bridge with 2 ports on a protecli device. Up until now everything has run flawlessly for about 6 months. What happens is the device crashes and I cant see the errors as they scroll by so fast I cant read any of them and the device is inaccessible. I have dont a bit of troubleshooting and discovered it is related to the network. If I boot without anything plugged into Ethernet ports everything runs fine but of course the device is useless like that. As soon as I plug in WAN and LAn cables it crashed doing what looks like a diagnostic dump. I have checked log files and there is nothing in them related to this. Is there anyway I can roll back the last update?
#3
26.7 Series / Re: Firewall rules don't seem ...
Last post by ricksense - Today at 04:55:16 PM
Quote from: gpb on Today at 04:01:20 PMIn Firewall - Settings - Advanced, do you have "Disable Anti-lockout" checked?

Unchecked
#4
French - Français / Re: Emploi en télé-travail et ...
Last post by NEOSA - Today at 04:26:48 PM
Bonjour,

Est-ce que la configuration OpenVPN fonctionne de façon autonome sur un poste ?

Bien que nous l'ayons jamais fait, il est possible d'impoter une configuration OpenVPN pour agir en tant que Client sur le firewall lui-même.

En gros :

OPNsense peut agir en tant que client OpenVPN pour se connecter à un serveur OpenVPN distant à l'aide d'un fichier de configuration ⁠.ovpn⁠ (ou ⁠.openvpn⁠).

Méthodes d'importation dans OPNsense
 Importation automatique (Recommandée) :

Dans les versions récentes d'OPNsense (VPN > OpenVPN > Instances ou Clients), un bouton d'importation permet de charger directement votre fichier ⁠.ovpn⁠. L'interface extrait automatiquement la configuration réseau, le serveur distant, ainsi que les certificats et clés cryptographiques inclus dans le fichier.

 Configuration manuelle (Si besoin d'ajustement) :

Si le fichier ⁠.ovpn⁠ contient des options personnalisées non gérées par l'import :

1. Certificats : Importez l'autorité de certification (CA), le certificat client et la clé privée dans System > Trust > Authorities et Certificates.
2. Client OpenVPN : Créez un profil client dans VPN > OpenVPN > Clients en renseignant l'adresse du serveur, le port, le protocole (UDP/TCP) et les chiffrements indiqués dans votre fichier.

Étapes post-importation pour activer le trafic
1. Assignation d'interface :

Allez dans Interfaces > Assignments pour associer la nouvelle interface virtuelle OpenVPN (ex: ⁠ovpnc1⁠).

2. Règles de pare-feu : Dans Firewall > Rules > [Nom de l'interface], ajoutez les règles autorisant le trafic sortant ou entrant selon vos besoins d'accès au réseau distant.

3. NAT / Outbound : Si les équipements du serveur distant doivent voir le sous-réseau local d'OPNsense, configurez la règle de NAT sortant appropriée (Firewall > NAT > Outbound).
#5
26.7 Series / Re: Firewall rules don't seem ...
Last post by gpb - Today at 04:01:20 PM
In Firewall - Settings - Advanced, do you have "Disable Anti-lockout" checked?
#6
26.1, 26,4 Series / Re: Firewall rules migration
Last post by Monviech (Cedrik) - Today at 03:34:11 PM
You can try the import again (it wont duplicate rules) and next to the button you imported it with there will be another button you can press where you can download all validation errors as csv.
#7
German - Deutsch / Re: Fragen zu OpenVPN Server K...
Last post by johnydo - Today at 03:11:36 PM
Ja, irgendwie mag ich das nicht wenn bei Quelle oder Ziel Any drin steht :). Ich denke ich lasse es auf Interface-Ebene.
#8
German - Deutsch / Re: BIOS Einstellungen - Harde...
Last post by johnydo - Today at 03:07:16 PM
Hi,

ja, die CPU hat echte 6 Cores. Soweit ich das über Google etc. gefunden haben schreiben viele aus Sicherheitsgründen sollte man Hyper-Threading auf einer Firewall abschalten, da Hyper-Threading bezüglich Leistung keinen großen Mehrwert bietet. Inwiefern dadurch mehr Sicherheit entsteht kann ich aber nicht beurteilen :).

Bei TPM hatte ich bereits gelesen das es keinen Unterscheid macht ob an oder aus, zum aktuellen Zeitpunkt nutzt OPNSense das nicht. Aber man sollte es aktivieren da es eventuell irgendwann mal eine Rolle spielen könnte...
#9
German - Deutsch / Re: Fragen zu OpenVPN Server K...
Last post by viragomann - Today at 03:05:26 PM
Ja.
Jetzt hast du beides umgesetzt? Interfaces und Aliases. Aber auch ok.

Wenn du einen DNS Server bereitstellst, braucht es dafür auch noch eine Regel. Die kann dann aber auf der Interface Gruppe für beide Bereiche definiert werden.
#10
German - Deutsch / Re: BIOS Einstellungen - Harde...
Last post by viragomann - Today at 03:01:30 PM
Bei Fragen zur Hardware sollte immer erwähnt werden, was ihre Aufgabe ist.

Quote from: johnydo on Today at 10:09:09 AMHyper-Threading   > Deaktivieren
Hyperthreading kann je nach betreibener Software ein Vorteil sein, bspw. für Suricata. Ein Nachteil ist es meines Wissens selten.

i5 kenne ich mit 2, 4 und 6 Kernen. Wenn du einen 6-Kerner hast, wird HT bei normaler Beanspruchung aber auch nicht mehr viel bringen.

Quote from: johnydo on Today at 10:09:09 AMTPM Support > Aktivieren
Ich glaube nicht, dass OPNsense davon einen Nutzen hat. Aber vielleicht übersehe ich etwas.