OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • Archive »
  • 21.1 Legacy Series »
  • syslog on WAN with Public IP not sending into IPSec even with NAT
« previous next »
  • Print
Pages: [1]

Author Topic: syslog on WAN with Public IP not sending into IPSec even with NAT  (Read 13008 times)

dstr

  • Newbie
  • *
  • Posts: 32
  • Karma: 0
    • View Profile
syslog on WAN with Public IP not sending into IPSec even with NAT
« on: June 28, 2021, 04:51:53 pm »
Hi,

I have the problem that the syslog server is only sending from the wan interface and if this is an Public IP the syslog Server is not finding its route into the IPsec Tunnel. I tried to add an outbound NAT Rules by its still not working even though the natted address is in the IPSec Tunnel.


Its still on the WAN interface and not on the enc0 interface

Enabled
Transport
Hostname
Description
Commands
UDP(4)   172.35.2.227

ESP IPv4 tunnel   10.2.4.248/29   172.35.0.0/16   AES (256 bits) + SHA256 + 21 (NIST EC 521 bits)

it seems that the Ips in the tunnel are not placed as a route to any interface so it can find it.

how to change this please?

if the WAN interface IP is an subnet in the tunnel, it works.

why is it only sending from WAN interface?
« Last Edit: July 01, 2021, 05:01:30 pm by dstr »
Logged

dstr

  • Newbie
  • *
  • Posts: 32
  • Karma: 0
    • View Profile
Re: syslog on WAN with Public IP not sending into IPSec even with NAT
« Reply #1 on: July 01, 2021, 05:03:59 pm »
Found the workaround -> Bridge between WAN interface and the interface that is in the IPSec Tunnel. It would be much easier to just bind the syslog to the interface though, wierd that syslog"-ng" does not support such an basic function.

How worthy is next gen without basic functions?
Logged

dstr

  • Newbie
  • *
  • Posts: 32
  • Karma: 0
    • View Profile
Re: syslog on WAN with Public IP not sending into IPSec even with NAT
« Reply #2 on: July 02, 2021, 10:30:17 am »
Hasnt outlived an reboot. So wasnt an workaround.
Still the question why cant I bind the syslog server to an interface?
Logged

dominico

  • Newbie
  • *
  • Posts: 2
  • Karma: 0
    • View Profile
Re: syslog on WAN with Public IP not sending into IPSec even with NAT
« Reply #3 on: November 09, 2021, 08:05:51 am »
Have you found a feasible solution for this issue? I am facing with same problems. I just noticed that in pfsense you can set-up sending interface for syslog.
Logged

Patrick M. Hausen

  • Hero Member
  • *****
  • Posts: 6925
  • Karma: 583
    • View Profile
Re: syslog on WAN with Public IP not sending into IPSec even with NAT
« Reply #4 on: November 09, 2021, 08:10:53 am »
Quote from: dstr on July 02, 2021, 10:30:17 am
Hasnt outlived an reboot. So wasnt an workaround.
Still the question why cant I bind the syslog server to an interface?
Because nobody has implemented that feature, yet?
Logged
Deciso DEC750
People who think they know everything are a great annoyance to those of us who do. (Isaac Asimov)

Patrick M. Hausen

  • Hero Member
  • *****
  • Posts: 6925
  • Karma: 583
    • View Profile
Re: syslog on WAN with Public IP not sending into IPSec even with NAT
« Reply #5 on: November 09, 2021, 10:57:45 pm »
I have started working on it ...
Logged
Deciso DEC750
People who think they know everything are a great annoyance to those of us who do. (Isaac Asimov)

Auriok

  • Newbie
  • *
  • Posts: 3
  • Karma: 0
    • View Profile
Re: syslog on WAN with Public IP not sending into IPSec even with NAT
« Reply #6 on: November 23, 2021, 10:15:20 pm »
Quote from: pmhausen on November 09, 2021, 10:57:45 pm
I have started working on it ...

Wonderful to hear!  Was looking for how to do this and glad I found this.
Logged

EHRETic

  • Newbie
  • *
  • Posts: 41
  • Karma: 0
    • View Profile
Re: syslog on WAN with Public IP not sending into IPSec even with NAT
« Reply #7 on: December 31, 2021, 08:33:42 am »
Quote from: pmhausen on November 09, 2021, 10:57:45 pm
I have started working on it ...

Lovely to hear that too, I just started to implement Wazuh in my lab and was figuring out why one of my FW was not able to send logs back to the server ;D
Logged

  • Print
Pages: [1]
« previous next »
  • OPNsense Forum »
  • Archive »
  • 21.1 Legacy Series »
  • syslog on WAN with Public IP not sending into IPSec even with NAT
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2024 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2