Home
Help
Search
Login
Register
OPNsense Forum
»
Archive
»
21.1 Legacy Series
»
Shared forwarding various failures when using it
« previous
next »
Print
Pages:
1
[
2
]
3
Author
Topic: Shared forwarding various failures when using it (Read 10060 times)
Matzke
Jr. Member
Posts: 73
Karma: 2
Re: Shared forwarding various failures when using it
«
Reply #15 on:
June 13, 2021, 02:42:18 pm »
As soon as activating "disable force gateway" I sporadically loose Internet Connectivity (I will say I can't connect from clients in LAN to WAN).
As soon as deactivating it, everything works as expected (I tried it with and without shared forwarding enabled).
Therefore I didn't do other tests because basic functionality (Firewall/Routing from LAN to WAN) was lost.
Logged
Matzke
Jr. Member
Posts: 73
Karma: 2
Re: Shared forwarding various failures when using it
«
Reply #16 on:
June 14, 2021, 06:09:50 pm »
Hello,
as already written yesterday, unfortunately it still does not work for me. Also, I have not entered any floating rules (see screenshots) that somehow spark in between.
Can anyone still help me? In my opinion, this is still a bug and I find it a pity that the OPNSense team is not investigating the issue more intensively here. As soon as a configuration error turns out, you can refer to the documentation and do not treat the thread further, but to put no further force into it I find very unfortunate.
@Franco: So again my question - what can I contribute to the error diagnosis?
Translated with
www.DeepL.com/Translator
(free version)
Logged
mimugmail
Hero Member
Posts: 6767
Karma: 494
Re: Shared forwarding various failures when using it
«
Reply #17 on:
June 14, 2021, 07:18:48 pm »
What happens when you disable the balancing rule or just allow it. Does Openvpn still have problems with topology?
Logged
WWW:
www.routerperformance.net
Support plans:
https://www.max-it.de/en/it-services/opnsense/
Commercial Plugins (German):
https://opnsense.max-it.de/
Matzke
Jr. Member
Posts: 73
Karma: 2
Re: Shared forwarding various failures when using it
«
Reply #18 on:
June 15, 2021, 02:23:51 pm »
Dear Mimugmail,
please tell me, what I should change in this rule?
a) disable this rule -> then I can't go into internet
b) just allow this rule -> I don't understand
c) change the gateway in this rule to * (but then I don't have policy based routing according to franco)
By the way (before changing anything) - when I dialin via openvpn and shared forwarding is enabled I even can't ping the firewall itself. I would assume that a rule on LAN interface shouldn't interfere here?
Logged
mimugmail
Hero Member
Posts: 6767
Karma: 494
Re: Shared forwarding various failures when using it
«
Reply #19 on:
June 15, 2021, 09:27:00 pm »
Just remove the Gateway in the rule and tell me if it works. Shared forwarding is enabled by default, if there would be a general problem you wouldnt be the first and only one having such phenomenons
Logged
WWW:
www.routerperformance.net
Support plans:
https://www.max-it.de/en/it-services/opnsense/
Commercial Plugins (German):
https://opnsense.max-it.de/
Matzke
Jr. Member
Posts: 73
Karma: 2
Re: Shared forwarding various failures when using it
«
Reply #20 on:
June 15, 2021, 09:56:28 pm »
I just forgot, I have a second OPNSense with only one Gateway and therefor no rule for gateway-switching.
There it is exactly the same. And when I remeber, shared forwarding was turned off in default (but I updated to OPNSense 21 it was no fresh installation).
By the way just to be sure - franco asked me if I have policy based routing. A fresh installation doesn't have a lot firewall rules (only some standard-floating), interface-rules are empty. When shared forwarding is enabled by default and it requires policy based routing it shouldn't work on any installation.
Logged
Matzke
Jr. Member
Posts: 73
Karma: 2
Re: Shared forwarding various failures when using it
«
Reply #21 on:
June 16, 2021, 09:49:17 am »
Just to show - attached the firewall-rules of
a) LAN-Interface (vlan20 internal)
b) OpenVPN-Roadwarrior-Interface
c) Gateway-Tab - no multiple LAN Gateways
This is configuration of a second OPNSense - here also OpenVPN won't work woth topology subnet and shared forwarding turned on.
Logged
Matzke
Jr. Member
Posts: 73
Karma: 2
Re: Shared forwarding various failures when using it
«
Reply #22 on:
June 16, 2021, 11:33:25 am »
... just verified with opnsense21.1-Install-ISO and a test in virtualbox:
- Shared forwarding is enabled by default
- OpenVPN Topology net30 is default (subnet isn't default although net30 is deprecated)
Logged
mimugmail
Hero Member
Posts: 6767
Karma: 494
Re: Shared forwarding various failures when using it
«
Reply #23 on:
June 16, 2021, 12:08:32 pm »
Is there a reason why you assign Openvpn as an Interface and add a gateway? Maybe this has strange side effects I'm not aware of
Logged
WWW:
www.routerperformance.net
Support plans:
https://www.max-it.de/en/it-services/opnsense/
Commercial Plugins (German):
https://opnsense.max-it.de/
Matzke
Jr. Member
Posts: 73
Karma: 2
Re: Shared forwarding various failures when using it
«
Reply #24 on:
June 16, 2021, 02:23:06 pm »
I just set an interface per OpenVPN Link - the gateway was set automatically. I also don't change something in interface settings - everything is left blank.
Attached you will see my VPN-Interface-Configuration (OPNSense Firewall 1).
I did this because I want to limit traffic from special roadwarriors or VPN-Members via firewall. Without the interface-assignment I was unable to create firewall rules which worked.
I tried to filter in the standard OpenVPN Interface (one interface for all different server/clients/tunnels) but it seems to be the encapsulated traffic at this interface. No rule with IP-Addresses of the VPN-Clients ever worked.
If this is wrong, please tell me how to solve this and I will delete the interface assignments.
Logged
Matzke
Jr. Member
Posts: 73
Karma: 2
Re: Shared forwarding various failures when using it
«
Reply #25 on:
June 20, 2021, 12:12:36 pm »
Hello,
how can we best continue here - I am happy to help with tests and protocols.
How can I filter OpenVPN traffic via firewall without creating specific interfaces (as in the post before)?
Another question - all my internal network traffic is VLAN-tagged on one physical interface - can there be a problem here? The second firewall also has VLAN tagging active.
The fact is, the problem still exists and is also clearly on the two things:
openvpn topology subnet + shared forwarding on.
Furthermore, it is unfortunately not yet clarified why I sporadically lose the connection to the Internet with the multi-WAN firewall rule and it also comes back and disappears again (alternating) without any changes? This also occurs exclusively when shared forwarding is enabled.
Logged
Matzke
Jr. Member
Posts: 73
Karma: 2
Re: Shared forwarding various failures when using it
«
Reply #26 on:
June 23, 2021, 08:39:08 pm »
Dear mimugmail,
I did a first try:
- deleted all OpenVPN Firewall rules
- deleted Interface assignment of OpenVPN tunnels (so I have now only one OpenVPN tab in Firewall
- restarted OpnSense
- turned on shared forwarding (OpenVPN topology subnet is already turned on)
I am very surprised, but OpenVPN now seems to work in this constellation.
I will continue to monitor it and get back to you later. But if this is really the case, then a note in the documentation would be very important not to assign OpenVPN interfaces. Maybe this should even be blocked or not offered in the web interface?
I will also observe whether the sporadic Internet outages are now gone and I will have a try with new Firewall-Rules in OpenVPN tab.
Logged
mimugmail
Hero Member
Posts: 6767
Karma: 494
Re: Shared forwarding various failures when using it
«
Reply #27 on:
June 23, 2021, 11:13:59 pm »
OK,good progress!
Logged
WWW:
www.routerperformance.net
Support plans:
https://www.max-it.de/en/it-services/opnsense/
Commercial Plugins (German):
https://opnsense.max-it.de/
Matzke
Jr. Member
Posts: 73
Karma: 2
Re: Shared forwarding various failures when using it
«
Reply #28 on:
July 04, 2021, 08:28:06 pm »
Dear Mimugmail,
I have been observing the behavior for some time now and can report the following (and would like to split the topic a bit, although it all has to do with shared-forwarding)
- after deleting the interface assignment of OpenVPN the topology subnet works like a charm
so here my first question
a) is this a bug, that assigned interface + shared forwarding + topology subnet won't work
b) I opened a separate thread but got no sufficient answer - when should I assign an interface to OpenVPN and when not (for example when using an NordVPN tunnel and I have to route specific traffic through it (guest network) I had to assign an interface for this OpenVPN instance.
- I still have some hickup with my internet-traffic. As soon as I use gateway-group and shared forwarding I have internet-dropouts (some seconds or minutes). After modifying firewall rule to use the default gateway instead of gateway-group it works like a charme, but it doesn't use my second gateway :-)
So I think, there is still a bug with shared forwarding and gateway group.
Please let me know, how I can assist the investigation
Logged
Matzke
Jr. Member
Posts: 73
Karma: 2
Re: Shared forwarding various failures when using it
«
Reply #29 on:
July 07, 2021, 10:17:01 pm »
Hi Mimugmail,
do you have an answer for my still existing problems or how can I assist in solving the problems?
Thanks a lot
Logged
Print
Pages:
1
[
2
]
3
« previous
next »
OPNsense Forum
»
Archive
»
21.1 Legacy Series
»
Shared forwarding various failures when using it