OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • English Forums »
  • Zenarmor (Sensei) »
  • Sensei on OPNsense - Application based filtering
« previous next »
  • Print
Pages: 1 ... 68 69 [70] 71 72 ... 79

Author Topic: Sensei on OPNsense - Application based filtering  (Read 509684 times)

myzar495

  • Newbie
  • *
  • Posts: 5
  • Karma: 0
    • View Profile
Re: Sensei on OPNsense - Application based filtering
« Reply #1035 on: August 15, 2020, 10:11:06 pm »
It looks like setting the IDS from WAN to another interface, even if it's off, should work around this issue.

Perhaps adding this to the knowledge base, or recommending it in the error prompt, would let people know to do this if they choose to use bridged mode?
Logged

mb

  • Hero Member
  • *****
  • Posts: 941
  • Karma: 99
    • View Profile
    • Sunny Valley Networks
Re: Sensei on OPNsense - Application based filtering
« Reply #1036 on: August 17, 2020, 09:26:05 pm »
Hi @myazar495, you're right, thanks for the suggestion. We've updated the warning message.
Logged

bunchofreeds

  • Full Member
  • ***
  • Posts: 203
  • Karma: 11
    • View Profile
Re: Sensei on OPNsense - Application based filtering
« Reply #1037 on: August 20, 2020, 11:45:26 pm »
Help with Sensei App Controls (Home Edition)

UPDATE - I'm making some progress using Sensei Reports and discovering what rule is blocking my progress.
Is it possible to show 'Block Sub Category' in the Reports view?
I can see for example Blocked by 'Application Category Online Utility' but not specifically what Signature it is. Like 'Microsoft Licensing' for example.

I'm trying to create a Policy that restricts internet usage for my kids. More out of interest than anything really, and they are the best testers to be honest.

My approach so far is 'select option>save>test' which is really slow considering the number of options.
Also browser caching on the client is annoying.

My Policy is controlling a set of IP addresses (not an entire subnet) that are assigned to their devices. Being an android phone, android tablet and two windows 10 laptops.
Ultimately I'd like to create a 'Family Safe' setup for the kids and maybe even restrict it to certain times.
Any help or advice on what to do or where to look with regards to configuring Sensei for info on this would be great.

Thanks in advance

 
« Last Edit: August 21, 2020, 01:45:34 am by bunchofreeds »
Logged

sorano

  • Full Member
  • ***
  • Posts: 153
  • Karma: 21
    • View Profile
Re: Sensei on OPNsense - Application based filtering
« Reply #1038 on: August 21, 2020, 04:09:45 pm »
Quote from: bunchofreeds on August 20, 2020, 11:45:26 pm

Ultimately I'd like to create a 'Family Safe' setup for the kids and maybe even restrict it to certain times.
Any help or advice on what to do or where to look with regards to configuring Sensei for info on this would be great.


I've put my kids devices on a separate VLAN.
Then just created a policy named Kids with the rules I wanted for them, added a schedule for that policy and configured the policy to match the kids VLAN interface. Then just sit back and prosper when they start complaining that they cannot watch youtube anymore!  8)

Kinda self explanatory really.
Logged
2x 23.7 VMs & CARP, 4x 2.1GHz, 8GB
Cisco L3 switch, ESXi, VDS, vmxnet3
DoT, Chrony, HAProxy + NAXSI, Suricata
VPN: IPSec, OpenVPN, Wireguard
MultiWAN: Fiber 500/500Mbit dual stack + 4G failover

--
Available for private support.
Did my answer help you? Feel free to click [applaud] to the left

Dayve

  • Newbie
  • *
  • Posts: 9
  • Karma: 1
    • View Profile
Re: Sensei on OPNsense - Application based filtering
« Reply #1039 on: August 21, 2020, 07:02:04 pm »
Is there a way to have Sensei not block when I'm connected to one of my VLAN's?
Logged

sorano

  • Full Member
  • ***
  • Posts: 153
  • Karma: 21
    • View Profile
Re: Sensei on OPNsense - Application based filtering
« Reply #1040 on: August 21, 2020, 08:13:54 pm »
Quote from: Dayve on August 21, 2020, 07:02:04 pm
Is there a way to have Sensei not block when I'm connected to one of my VLAN's?

Yes you can use Exempted VLANs & Networks
Logged
2x 23.7 VMs & CARP, 4x 2.1GHz, 8GB
Cisco L3 switch, ESXi, VDS, vmxnet3
DoT, Chrony, HAProxy + NAXSI, Suricata
VPN: IPSec, OpenVPN, Wireguard
MultiWAN: Fiber 500/500Mbit dual stack + 4G failover

--
Available for private support.
Did my answer help you? Feel free to click [applaud] to the left

Dayve

  • Newbie
  • *
  • Posts: 9
  • Karma: 1
    • View Profile
Re: Sensei on OPNsense - Application based filtering
« Reply #1041 on: August 22, 2020, 01:33:50 am »
Quote from: sorano on August 21, 2020, 08:13:54 pm
Quote from: Dayve on August 21, 2020, 07:02:04 pm
Is there a way to have Sensei not block when I'm connected to one of my VLAN's?

Yes you can use Exempted VLANs & Networks

Guess I need to pay for that option.
Logged

almodovaris

  • Sr. Member
  • ****
  • Posts: 318
  • Karma: 15
    • View Profile
Re: Sensei on OPNsense - Application based filtering
« Reply #1042 on: August 22, 2020, 11:42:02 am »
Nope, each Ethernet port and each VLAN can be filtered by Sensei or not filtered, at your own choice. You are fully free to do that.
Logged
OPNsense HW:

Minisforum Venus series UN100C, 16 GB RAM, 512 GB SSD
T-bao N9N Pro, 16 GB RAM, 512 GB SSD

mb

  • Hero Member
  • *****
  • Posts: 941
  • Karma: 99
    • View Profile
    • Sunny Valley Networks
Re: Sensei on OPNsense - Application based filtering
« Reply #1043 on: August 22, 2020, 07:44:57 pm »
Good morning dear Sensei users,

Some good news. Please give this kernel a test drive and provide feedback.

https://forum.opnsense.org/index.php?topic=17363.msg85539#msg85539

If you don't see your interface show up in Sensei interface configuration, /usr/local/opnsense/mvc/app/controllers/OPNsense/Sensei/Api/ToolsController.php is the file you'll need to play with. You'll need to comment lines which filter your interface:

Code: [Select]
      3                     if (strpos(strtolower($interface), "vmx") !== false && strpos(strtolower($interface), "vlan") == false) {
     74                         $filterflag = true;
     75                     }
Logged

Dayve

  • Newbie
  • *
  • Posts: 9
  • Karma: 1
    • View Profile
Re: Sensei on OPNsense - Application based filtering
« Reply #1044 on: August 23, 2020, 03:00:32 pm »
I installed the test kernel. The only interface I have selected in the UI is the LAN.

Code: [Select]
                    if (strpos(strtolower($interface), "lagg") !== false && strpos(strtolower($interface), "vlan") == false) {
                        $filterflag = true;
                    }

                    if (strpos(strtolower($interface), "vmx") !== false && strpos(strtolower($interface), "vlan") == false) {
                        $filterflag = true;

This is what I see in the ToolsController.php

Not sure which one would be my VLAN20 and do I just edit the "$filterflag" to be false?
Logged

scream

  • Jr. Member
  • **
  • Posts: 61
  • Karma: 2
    • View Profile
Re: Sensei on OPNsense - Application based filtering
« Reply #1045 on: August 23, 2020, 04:08:17 pm »
Quote from: Dayve on August 23, 2020, 03:00:32 pm
I installed the test kernel. The only interface I have selected in the UI is the LAN.

Code: [Select]
                    if (strpos(strtolower($interface), "lagg") !== false && strpos(strtolower($interface), "vlan") == false) {
                        $filterflag = true;
                    }

                    if (strpos(strtolower($interface), "vmx") !== false && strpos(strtolower($interface), "vlan") == false) {
                        $filterflag = true;

This is what I see in the ToolsController.php

Not sure which one would be my VLAN20 and do I just edit the "$filterflag" to be false?

I just commented out the lines with "#" on each of the lines belonging to one interface type.
I do not use VLAN so I can't answer about that. But basicly the filter matches the name of the interface.
So just take a look at "ifconfig" and you should see which you've to comment out.
Logged

almodovaris

  • Sr. Member
  • ****
  • Posts: 318
  • Karma: 15
    • View Profile
Re: Sensei on OPNsense - Application based filtering
« Reply #1046 on: August 24, 2020, 04:39:41 pm »
Speedtest APU2 with Sensei, Aug 22 test kernel: 66.4 Mbps download speed from my own internet provider.

Speedtest APU2 with Sensei, but through OpenVPN from a Linux box behind it, Aug 22 test kernel: 149.5 Mbps download speed from my own internet provider.
Logged
OPNsense HW:

Minisforum Venus series UN100C, 16 GB RAM, 512 GB SSD
T-bao N9N Pro, 16 GB RAM, 512 GB SSD

mb

  • Hero Member
  • *****
  • Posts: 941
  • Karma: 99
    • View Profile
    • Sunny Valley Networks
Re: Sensei on OPNsense - Application based filtering
« Reply #1047 on: August 25, 2020, 04:43:16 am »
In case anyone would like to give 1.6 an early try:

https://forum.opnsense.org/index.php?topic=17363.msg85734#msg85734

Logged

DenverTech

  • Jr. Member
  • **
  • Posts: 53
  • Karma: 3
    • View Profile
Re: Sensei on OPNsense - Application based filtering
« Reply #1048 on: August 27, 2020, 06:58:16 pm »
Just ran into a bug I've not seen before (or I did something wrong). Installed Sensei previously on our company vmware-hosted fw, then removed it to prep for the 20.7 upgrade (just in case). I upgraded without issue. Installed Sensei, went to configure it...and there's no available interfaces. It's blank. They were there in 20.1 just 15 minutes ago.

Possibly because this is a vmware guest, or something else?
Logged

mb

  • Hero Member
  • *****
  • Posts: 941
  • Karma: 99
    • View Profile
    • Sunny Valley Networks
Re: Sensei on OPNsense - Application based filtering
« Reply #1049 on: August 27, 2020, 07:09:11 pm »
Hi @DenverTech, correct;

See here: https://forum.opnsense.org/index.php?topic=17363.msg85734#msg85734

Make sure you're running the netmap test kernel; or the fw will crash.
Logged

  • Print
Pages: 1 ... 68 69 [70] 71 72 ... 79
« previous next »
  • OPNsense Forum »
  • English Forums »
  • Zenarmor (Sensei) »
  • Sensei on OPNsense - Application based filtering
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2024 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2