[SOLVED] Issues with User Manual - "Configure Spamhaus (E)DROP"

Started by shred, November 01, 2017, 04:04:55 AM

Previous topic - Next topic
I'm trying to configure Spamhaus DROP/EDROP using the guide on the OPNsense user manual that can be found here: https://wiki.opnsense.org/manual/how-tos/edrop.html. However, I'm running into some issues:

1. When creating the alias, the user manual states to set the update frequency to 1 for each day. However, there is no option in OPNsense to set an update frequency.

2. When creating the firewall rule to block, there is no way to set the alias I created (spamhaus_drop and spamhaus_edrop) as the source as directed in the user manual.

Is there another way to go about setting up Spamhaus DROP/EDROP?

The update frequency is in days, so 1 day is min.
I cannot reproduce this, for me it's working fine, 17.7.7_1

Do you run latest with _1?

Yes, I'm running on 17.7.7_1.

1. I don't see any option to set an update frequency at all. See attached screenshot.

EDIT: I figured it out. I had "URL (IPs)" selected and not "URL Table (IPs)". Once I selected that, it shows the "Update Freq. (days)" box where I can enter in a number. One small annoyance is I can't simply change the Type and Save as it keeps giving me an error that "Alias type may not be changed for an existing alias.", so I have to delete everything and create them again. Not a huge issue, but just something I wonder as to why you can't just change the type.

2. I think I might have figured out the issue with the firewall rule. You have to select "Single host or Network" as the Source and then type in "spamhaus_drop". I just left the dropdown box that says 32 at default.

It's probably worth clarifying this in the OPNsense user manual/wiki. It would also be nice the firewall rules section could see all of the alias you've created. Either automatically show up as an option you can just select as the Source or when you start typing in the alias name, it appears. Is there a way to provide inputs on the user manual or do most of the developers read these threads?

EDIT: After re-creating the aliases as "URL Table (IPs)", they show up in the Source drop down list. However, it seems that if you create an alias that is a "URL (IPs)", they do not show up in the Source drop down list for firewall rules. Not sure if this is intended or not? Possible bug?