Problems/comments with "Let's Encrypt" module

Started by Taomyn, March 14, 2017, 08:05:33 PM

Previous topic - Next topic
Quote from: Taomyn on March 20, 2017, 12:32:24 PM
Or I would:

User 'fraenki' has blocked your personal message.

Try again, I've enabled personal messages. (Hello Spambots.)

Done, so you can disable it again if you wish, though I have yet to receive any spam to my Inbox

The auto-generated pf rules look good. They should not cause any harm, especially since you're not using a (HTTP) proxy server on your OPNsense firewall.

Please provide the output of the following commands for both situations, once (with a working internet connection) before running the LE plugin and a second time when the plugin killed your internet connection:

curl --head http://www.opnsense.org/
ping -c 3 8.8.8.8


EDIT: Please also check the firewall log for denied packages under Firewall -> Log Files -> Normal View.


Quote from: Taomyn on March 20, 2017, 07:04:52 PM
Sent results by PM

Thanks again! The results show that your internet connection is still working (PING, DNS, TCP). So the issue does not actually kill you internet connection, but only affects (other) computers in your network.

Would you please repeat these tests on a computer in your network that looses the internet connection?

Thanks
- Frank

Actually I did at the time, and neither worked - sorry, I forgot to grab the info.

Does manually reloading the firewall rules fix your issue? (after you've lost the internet connection)
Firewall -> Diagnostics -> Filter Reload -> Reload Filter


I'm pretty sure I tried that when I first encountered the issue, but I can't be certain. I can try it again when I next get a chance.

Quote from: fraenki on March 21, 2017, 03:58:15 PM
Does manually reloading the firewall rules fix your issue? (after you've lost the internet connection)
Firewall -> Diagnostics -> Filter Reload -> Reload Filter


Good news, this fixes the issue but I'm pretty sure it didn't before with 17.1.2 so maybe something in 17.1.3 fixed that as well.

Don't suppose you know what command I could put into the "Custom command" field of a restart action that would reload the firewall rules? This might help me out and perhaps this should be one of the pre-defined system commands.