Recent posts

#1
26.1, 26,4 Series / Re: Suricata - Divert (IPS)
Last post by Gorpes - Today at 04:26:13 PM
Hi @Monviech,

I have a follow-up question regarding Divert mode.

My setup is:

- One WAN and one LAN
- Zenarmor is enabled on the LAN interface
- Suricata is running in Divert (IPS) mode
- On LAN I added a Pass + divert-to Intrusion Detection rule (Source: LAN net, Destination: any) above the default "Allow LAN to any" rule.

Everything works as expected:

- Zenarmor inspects the traffic.
- Suricata generates alerts and blocks traffic when configured.
- Traffic matching the divert rule never reaches the default "Allow LAN to any" rule, which I understand is expected.

Is this considered a valid and recommended configuration for a simple home network?

Or would you recommend a different placement of the "divert-to" rule?

Also, is running Zenarmor on LAN together with a "divert-to" rule on the same interface a supported configuration?

Thank you!
#2
Du kannst easy Screen Shots hochladen, wo genau ist das Problem?
#3
German - Deutsch / Fragen zu OpenVPN Server Konfi...
Last post by johnydo - Today at 03:50:17 PM
Hallo zusammen,

ich bin neu hier im Forum und sage hiermit Hallo in die Runde :).

Ursprünglich komme ich aus der Netgate/pfSense Ecke und bin nun mit einer neuen Hardware auch gleich auf ein neues Firewall OS umgestiegen. Letztendlich hat mich einfach die Neugierde dazu gebracht. Meine ersten Eindrücke von OPNSense sind super. An das Regelwerk muss ich mich noch gewöhnen aber ich denke das wird auch noch ;).

Ich habe nun vorerst eine Testfirewall mit OPNSense in der aktuellen Version 26.7.1 aufgesetzt. Gerne würde ich wieder OpenVPN Server für die Einwahl von Endbenutzern nutzen. Es sollen sich ausschließlich Benutzer einwählen können, die Benutzername+Kennwort+Client Zertifikat haben. Des weiteren soll der OpenVPN Server bezüglich Sicherheit nach Stand der Technik laufen. Generell läuft alles schon soweit, sprich ich kann mich mit einem Remotebenutzer einwählen. Ich würde euch aber gerne über die Konfiguration schauen lassen ob das alles so sinnig ist.

Gibt es hier die Möglichkeit mehrere Screenshots hoch zu laden oder kann ich irgendwie eine Konfig einstellen?
#4
26.7 Series / Re: mDNS forwarding between tw...
Last post by julsssark - Today at 03:49:55 PM
Use Firewall->Log Files->Live View and watch traffic going to and from the printer. Confirm that the traffic is not being blocked. You may need a rule to allow the printer to open a connection to the device that wants to print. I don't use AirPrint but Airplay devices need to be able to open connections.
#5
Tutorials and FAQs / Re: Technitium DNS Server on O...
Last post by gehoernchen - Today at 02:53:18 PM
Just updated to OPNsense 26.7, went fairly well, no issues on my side. The dotnet package was nuked however. Thanks to @piepre for mentioning that repository. With https://github.com/sec/dotnet-core-freebsd-source-build, it is possible to upgrade to Technitium DNS Server 15.x due to requiring .NET 10 (which seems to not be available in the official FreeBSD repositories) on FreeBSD 15.

Regarding SQLite - There just seems to be a missing symlink. Beware, potentially dangerous assumptions following - I found https://forums.truenas.com/t/please-please-freebsd-gurus-i-need-your-help/14926/23 which suggested /usr/local/lib/libsqlite3.so (probably coming via the sqlite3 package) is the same as lib3_sqlite that Technitium DNS complains about. So I just symlinked it:

# show the libsqlite3.so
$ file /usr/local/lib/libsqlite3.so
/usr/local/lib/libsqlite3.so: ELF 64-bit LSB shared object, x86-64, version 1 (FreeBSD), dynamically linked, for FreeBSD 15.1, stripped

# install dotnet 10 and create symlinks; wget omitted
$ mkdir /opt/dotnet/dotnet-sdk-10.0.110-freebsd.15
$ tar zxf dotnet-sdk-10.0.110-freebsd.15-x64.tar.gz -C /opt/dotnet/dotnet-sdk-10.0.110-freebsd.15
$ ln -s /opt/dotnet/dotnet-sdk-10.0.110-freebsd.15/dotnet /usr/local/bin/dotnet
$ ln -s /usr/local/lib/libsqlite3.so /opt/dotnet/dotnet-sdk-10.0.110-freebsd.15/shared/Microsoft.NETCore.App/10.0.10/libe_sqlite3

$ file /opt/dotnet/dotnet-sdk-10.0.110-freebsd.15/shared/Microsoft.NETCore.App/10.0.10/libe_sqlite3
/opt/dotnet/dotnet-sdk-10.0.110-freebsd.15/shared/Microsoft.NETCore.App/10.0.10/libe_sqlite3: symbolic link to /usr/local/lib/libsqlite3.so

I suppose this symlink might go stale in the future, but it works (for now).
#6
French - Français / Quelqu'un utilise un logiciel ...
Last post by ArisCalen - Today at 02:06:11 PM
Hello tout le monde, J'ai monté un petit serveur web chez moi (NUC avec Proxmox, OPNsense en VM pour le firewall) et j'ai commencé a utiliser un logiciel SEO pour analyser mon site perso... le souci c'est que j'ai l'impression que certaines requêtes sortantes du logiciel passent pas bien. J'ai des timeouts sur les crawls externes, des fois les résolutions DNS sont lentes ou elles aboutissent pas du tout. Franchement je sais pas si c'est mon ruleset qui bloque des trucs, ou si c'est le logiciel SEO lui-même qui génère un trafic un peu chelou et que Suricata interprète comme suspect. J'ai regardé les logs mais c'est pas super parlant pour moi. Quelqu'un a déjà eu sa avec ce type d'outil ? Ou vous avez des règles spécifiques pour laisser passer les crawlers sans tout ouvrir en mode passoire ?
#7
General Discussion / Re: Problem with ping on one e...
Last post by syshein - Today at 12:54:56 PM
It's currently not a multi-WAN setup, i have a connection to this other private network so i can access my network from there. There are only routes for the IP range of that private network on that interface.
For a test i set a /32 route for the IP of my cloud telephone system over this other private network and that is working as expectet. But when i get the strange ping results, this route is disabled (otherwise i wouldn't see any of this traffic on the WAN interface).

I set a null route for 10.0.0.0/8 but get the same results as before...
#8
26.7 Series / Re: mDNS forwarding between tw...
Last post by nero355 - Today at 12:53:46 PM
Quote from: sjjh on July 30, 2026, 05:37:18 PMA user with an Apple Mac (VLAN 70; IP 10.70.0.1) wants to print on a printer (VLAN 65; IP 10.64.65.203) in a different VLAN.

The printer only supports Airprint (using mdns) for Mac OS (no specific printer driver, using a generic one does not print images).
As someone who really hates mDNS forcing devices like that I would like to suggest the following :
- Setup a CUPS Printer Server by using something like a Raspberry Pi 2B/3B or a small Intel Atom NUC running Linux.
- Let the MacOS Clients talk to that CUPS Printer Server directly via the VLAN Gateway without all the mDNS mess :)



And for random people passing by in the future =>

Here is a list of protocols that I would use and my printer currently has as Enabled Protocols :
- Raw TCP/IP Printing Protocol - Port Number - 9100
- LPR/LPD Protocol - Port Number - 515
- IPP Protocol - Printer URI: ipp://10.x.x.x/ipp/printer

Currently used from : Android/Linux/Windows
And would probably work with Apple stuff too! :)
#9
26.7 Series / Re: CrowdSec remediation block...
Last post by shuvitcrew - Today at 12:30:03 PM
Thanks for this informations! Had the same problem with several firewalls. The wireguard connections are active, but no trafic was passed through.
Disabling the Enable Remediation Component in CrowdSec solved the problem.
#10
General Discussion / Re: Problem with ping on one e...
Last post by meyergru - Today at 11:26:36 AM
Do you operate the two connections from the same location? For multi-WAN setups, you must disable "Reply-To" on WAN connections to avoid assymetric routing.

Also, to avoid your RFC1918 IPs to the main gateway(s), you should set null routes to them: https://forum.opnsense.org/index.php?msg=259031