Recent posts

#1
26.7 Series / Re: Some SSL certificate help ...
Last post by Patrick M. Hausen - Today at 08:35:42 PM
System > Trust > Certificates

Click on the "+", select "Create Certificate Signing Request", continue with all your data. After you signed the CSR with your CA in the same menu click on the "edit" icon for the CSR - the little pencil. Paste the signed certificate date into the empty box at the top labelled "Certificate data". Save. Done.
#2
26.7 Series / Re: Some SSL certificate help ...
Last post by fornax - Today at 08:32:26 PM
When you perform the step on the Certificates page to generate the CSR, it creates a line on that page. Once you have the cert from the CA, you click the Edit button on that same line. There'll be an empty box in the edit page for you to paste in the cert.
#3
German - Deutsch / Re: Umstieg auf Kea DHCP
Last post by Patrick M. Hausen - Today at 08:31:10 PM
Hier die Leases mit meinem IOT VLAN ausgeklappt.
#4
German - Deutsch / Re: Umstieg auf Kea DHCP
Last post by Patrick M. Hausen - Today at 08:29:35 PM
Aber Auto collect will man doch sowieso. Dann wird in jedem VLAN die Interface-Adresse der OPNsense an die Clients verteilt. Goldrichtig.

Und hinterher hast du alle Subnets/VLANs übersichtlich in einer Liste, und einen Reiter weiter alle Reservierungen über alle Subnets in einer Liste zum auf- und zuklappen. Leases dito. Das Interface ist einfach viel besser, siehe Screenshots.
#5
German - Deutsch / Re: Umstieg auf Kea DHCP
Last post by spooner.arthur - Today at 08:22:03 PM
Mmh, OK, finde ich nicht so schön und übersichtlich beim ISC.

Also unter Kea DHCP v4 unter Settings und Interfaces anklicken / auswählen, wo man einen DHCP benötigt z.B. 5 Stück und dann unter
Subnets pro VLan je einen neuen Subnet Eintrag anlegen, richtig?

Aber wo geb ich den DNS und das Gateway mit, das habe ich gerade durch Zufall gefunden, da muss man den "Auto collect option data" Haken entfernen.
Mmh, OK.

Oder ist der "Dnsmasq DNS & DHCP" Server die bessere Alternative zum ISC DHCP?
#6
26.7 Series / Re: Upgrade advice to OPNsense...
Last post by tangofan - Today at 07:33:17 PM
I upgraded 5 weeks ago to 26.7.1_1 with Zenarmor, Crowdsec, QFeeds and Tailscale installed and I didn't have any problem with the upgrade, but I paid attention to the things below:

- There were some issues with the newer FreeBSD version in 27.1, which manifested when running the os-cpu-microcode-intel plugin. At the time the recommendation was to uninstall this plugin before upgrading, update the OPNsense bootloader and only afterwards reinstall the plugin. I suggest that you search the forum for this, since there were plenty of posts on this subject.

- If you have not yet migrated the firewall and NAT rules to the new UI, you will need to install a new plugin in 26.7 to be able to edit them. That plugin (os-firewall-legacy IIRC) is already available in later versions of 26.1, at which time I installed it. I waited with the migration until after the upgrade to 26.7, but it's probably better to execute that migration before the upgrade. I found the migration to be very easy, just follow the instruction in the migration tool and remember to go through all the tabs of that tool.

As always, read the release notes and download your config before the upgrade and (if you run ZFS, which I hope everyone does) create a snapshot.
#7
Zenarmor (Sensei) / Re: Cancelling my subscription...
Last post by tangofan - Today at 07:08:49 PM
My OPNsense box is a little over two years old and I had Zenarmor running for two years with a home subscription, using a local elasticsearch DB. The lifetime writes of my SSD are about 5.7 TiB, which is very mild compared to the rated typical lifespan of an SSD. So I suspect those who have a wear problem with their SSD have some additional features or logs turned on or turned to a higher logging level.

What made me discontinue my Zenarmor home subscription and ultimately uninstall Zenarmor were performance problems like the one I described here. I don't know, if those particular problems could have been solved by multicore support (single I don't know how granular the workload for a particular connection can be shared between different threads), but not having it or getting it means that I definitely would have to get a system with a CPU that has higher single-core performance than an Intel J6412. And that just didn't seem to be worth it.

So I would agree with the assessment that Zenarmor has a growing problem with positioning themselves. I understand that they don't want their free edition or their home edition subscription to cannibalize their commercial subscriptions (particularly in the SMB sector, where you might not need enterprise-level sizing). My assumption is that the main purpose of the free and home tiers is to have a showcase to home-labbers, in the hope that some of them would carry a positive experience into their workplace and thus increase Zenarmor's commercial subscription base. However as the home-labber experience turns less positive, that "carryover" effect is much less likely to happen. Thus I am surprised that they don't offer multithreading (with a limited thread count) in the free and home editions.
#8
26.7 Series / Re: Some SSL certificate help ...
Last post by Ed V. - Today at 07:07:40 PM
Not to be completely clueless - but can you unpack that a bit?

Edit the CSR in what way?

The text of it?

E.g. the part that has "MIIEvzCCAqcCAQAwMDELMAkGA1UEBhMCVVMxITAfB" and so on...

How it's created?

I like to think I have some competence in the tech world, but this is proving that maybe I don't have as much as I thought.
#9
German - Deutsch / Re: Umstieg auf Kea DHCP
Last post by stulpinger - Today at 06:40:45 PM
"Bei dem ISC DHCPv4 hatte man pro Interface seine DHCP Settings"

Antwort auf kärntnerisch "no na nit", auf "Deutsch" das ist selbstverständlich

im DHCP-Server lägst Du fest, im welchen Bereich die IP-Adressen geliefert werden und deshalb
lässt man auch Platz im Range für fixe IPs,
egal ob ISC oder KEA
#10
German - Deutsch / Re: SSD Killer gesucht
Last post by stulpinger - Today at 06:30:09 PM
Zenarmor am Laufen ?