OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • English Forums »
  • Zenarmor (Sensei) »
  • ZenArmor Reports for local hosts (Odd Behavior)
« previous next »
  • Print
Pages: [1]

Author Topic: ZenArmor Reports for local hosts (Odd Behavior)  (Read 3235 times)

DoBoY

  • Newbie
  • *
  • Posts: 13
  • Karma: 0
    • View Profile
ZenArmor Reports for local hosts (Odd Behavior)
« on: January 01, 2023, 05:34:00 pm »
I can't seem to find any good info regarding an issue I have found(if it even is one)

My Top local hosts report includes external addresses? A mix of both actually, and some are not resolving to proper alias's that are defined internally.

Now good the mix out of outside and inside IP's be due to a config on the opnsense? I am not sure where zenarmor pulls the data for "local hosts" All my internal hosts are non routable ip's of course.

ie.. I have a docker server running rtorrent and other apps, most of those rtorrent ip's are being recorded in local hosts even though they are external routable user's ?

I am not sure i am explaining this correctly but I expected Top local hosts to include only internal network objects?

Logged

mb

  • Hero Member
  • *****
  • Posts: 941
  • Karma: 99
    • View Profile
    • Sunny Valley Networks
Re: ZenArmor Reports for local hosts (Odd Behavior)
« Reply #1 on: January 01, 2023, 06:35:01 pm »
Hi @DoBoY,

Happy New Year!

We're aware of this problem. This affects Top Local and Top Remote Hosts charts. We're testing the fix in pilot environments.

We'll ship the fix with 1.12.3 tomorrow / Tuesday.
Logged

DoBoY

  • Newbie
  • *
  • Posts: 13
  • Karma: 0
    • View Profile
Re: ZenArmor Reports for local hosts (Odd Behavior)
« Reply #2 on: January 01, 2023, 06:45:37 pm »
Well that's terrific news. Happy i was not crazy :)

Thanks.

So I  guess in the future I should wait a bit before upgrading to see if there any known issues, is there a good ressource we can access to verify that the latest versions have not included some unknown bugs/misbehaviors?

Logged

DoBoY

  • Newbie
  • *
  • Posts: 13
  • Karma: 0
    • View Profile
Re: ZenArmor Reports for local hosts (Odd Behavior)
« Reply #3 on: January 03, 2023, 11:59:34 pm »
Quote from: mb on January 01, 2023, 06:35:01 pm
Hi @DoBoY,

Happy New Year!

We're aware of this problem. This affects Top Local and Top Remote Hosts charts. We're testing the fix in pilot environments.

We'll ship the fix with 1.12.3 tomorrow / Tuesday.

I guess there was more bugs to squash before releasing the fix? Any new ETA, I am running out of time on my 15 day trial.
Logged

sy

  • Hero Member
  • *****
  • Posts: 598
  • Karma: 44
    • View Profile
Re: ZenArmor Reports for local hosts (Odd Behavior)
« Reply #4 on: January 04, 2023, 01:07:35 pm »
Hi,

The test process needs a bit more time. It will be shipped by the end of this week. Please contact the team by using the upper right corner of Zenarmor GUI to extend the trial time.
Logged

DoBoY

  • Newbie
  • *
  • Posts: 13
  • Karma: 0
    • View Profile
Re: ZenArmor Reports for local hosts (Odd Behavior)
« Reply #5 on: January 05, 2023, 01:58:25 am »
Quote from: sy on January 04, 2023, 01:07:35 pm
Hi,

The test process needs a bit more time. It will be shipped by the end of this week. Please contact the team by using the upper right corner of Zenarmor GUI to extend the trial time.

Ok So i have upgraded to latest version and it seems better now, maybe you can answer a quick question?

I have multiple alias's created from dynamic dns urls that get resolved to ip addresses in order to use in incoming firewall rules.

All I see is the external IP in the various reports, which then on hover gets resolved to an external generic url/dns name from the web. Can i not get it to use the internal DNS cache to populate ?

ie.. should they not get resolved to

A) My internal alias name's?
B) The dynamic URL that I defined in the alias?

Thanks

« Last Edit: January 05, 2023, 02:01:12 am by DoBoY »
Logged

sy

  • Hero Member
  • *****
  • Posts: 598
  • Karma: 44
    • View Profile
Re: ZenArmor Reports for local hosts (Odd Behavior)
« Reply #6 on: January 05, 2023, 08:02:56 pm »
Hi,

You can set the DNS server in the Configuration - Reporting & Data - DNS Enrichment for Reports. But hostname Infos are used for the source machines. 
Logged

DoBoY

  • Newbie
  • *
  • Posts: 13
  • Karma: 0
    • View Profile
Re: ZenArmor Reports for local hosts (Odd Behavior)
« Reply #7 on: January 05, 2023, 08:38:05 pm »
Quote from: sy on January 05, 2023, 08:02:56 pm
Hi,

You can set the DNS server in the Configuration - Reporting & Data - DNS Enrichment for Reports. But hostname Infos are used for the source machines.

I have that feature enabled already and does not help. My guess is that when it does a reverse lookup since it's a dynamic dns it does not resolve to the url that is located in the alias, as in it does not check it's own DNS/PTR table  even it even has one. it goes outside and those ip's do not have a public PTR since they are dynamic
« Last Edit: January 06, 2023, 12:17:15 am by DoBoY »
Logged

packetmangler

  • Newbie
  • *
  • Posts: 19
  • Karma: 2
    • View Profile
Re: ZenArmor Reports for local hosts (Odd Behavior)
« Reply #8 on: January 06, 2023, 03:25:27 am »
if you do a host lookup on those IP addresses from a host on your network what do they resolve to? 

I wouldn't expect anything outside of opnsense to know what anything inside of your aliases resolve to as that's not how DNS works.
Logged

  • Print
Pages: [1]
« previous next »
  • OPNsense Forum »
  • English Forums »
  • Zenarmor (Sensei) »
  • ZenArmor Reports for local hosts (Odd Behavior)
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2024 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2