error reconfiguring IDS => error installing ids rules (Error (1))
Aren't you still trying to get basic routing and firewall working? Then why are you messing with the IDS? How shall anyone on this forum aid you in debugging your NAS access problem when you throw an IDS in the mix?
A couple of days ago I asked you to - reinstalling seems to be a hobby of yours, anyway - take a fresh installation and- configure your three interfaces- configure DHCP on all three- duplicate and adapt the default "allow" rule on "LAN" for all your interfacesthen report back about the reachability of your various networks.
At which point did I mention IDS or ClamAV?If you still want help, do the above and DONT INSTALL OR TOUCH ANYTHING ELSE FOR CRYING OUT LOUD!Otherwise I'm out. Sorry, it's impossible to assist you.
Because my system is online, and so when I'm on the forum doing tests, I switch IDS off, and when I'm not, I switch it back on
QuoteBecause my system is online, and so when I'm on the forum doing tests, I switch IDS off, and when I'm not, I switch it back onWhy? What do you think disabling IDS when you're on the forum and "doing tests" and switching it back on after will provide?
Then you are doing "tests" that are then void to a large extent, because those tests will not be operating on the same environment setup.Like testing antivirus behaviour when all machines are off.
Honestly it looks like you're trying to enable any and every possible capability on OPN before you have your basics understood and working correctly. Let's go back to the right thread with those basics and don't throw any more spanners in. No "trunking" as you were calling it, no services IDS, IPS, ClamAV, no VPNs, nothing other than a routing appliance. Please.
A basic setup consists of internal interfaces, DHCP service, Unbound running, allow all outbound and nothing else.It's very counter productive to enable or tinker with anything else before all of this is working perfectly. E.g. access to your NAS systems across VLANs etc.
And it's in no way less secure than any consumer NAT router/firewall, so you are perfectly fine with a setup like this.