OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • English Forums »
  • Zenarmor (Sensei) »
  • Sensei on OPNsense - Application based filtering
« previous next »
  • Print
Pages: 1 ... 20 21 [22] 23 24 ... 79

Author Topic: Sensei on OPNsense - Application based filtering  (Read 509682 times)

mb

  • Hero Member
  • *****
  • Posts: 941
  • Karma: 99
    • View Profile
    • Sunny Valley Networks
Re: Sensei on OPNsense - Application based filtering
« Reply #315 on: May 21, 2019, 06:15:02 pm »
Dear Sensei users,

Sensei 0.8.0.beta10 is out. This brings back VLAN child interfaces and fixes a bug with Cloud Threat Intel. You should now see much better uptimes.

Also addressed: libXdmcp, an Elasticsearch dependency package, is updated to version 1.1.3, fixing a security issue.

Complete list is as follows:
  • VLAN child interfaces are back
  • Better availability for Cloud servers
  • Fixed senseigui.log directory creation error which resulted in a bumpy new install
  • Elasticsearch dependency libXdmcp upgraded to release 1.1.3. To update, please use OPNsense update manager
  • New feature: Engine Bypass: you can now temporarily bypass Sensei engine at runtime. This allows you to pause packet processing without completely stopping Sensei
  • Whitelisting a web category from Live Blocked Sessions Explorer now works
  • Fixed a bug in which you couldn't set the deployment sizes larger than 100 users
  • More reliability fixes

Enjoy :)

Sensei team
« Last Edit: May 21, 2019, 06:28:18 pm by mb »
Logged

the-mk

  • Full Member
  • ***
  • Posts: 156
  • Karma: 15
    • View Profile
Re: Sensei on OPNsense - Application based filtering
« Reply #316 on: May 21, 2019, 08:51:30 pm »
@mb: thanks for the clarification - I need to do a deeper check it on the weekend...
Logged

OPNsense4ever

  • Newbie
  • *
  • Posts: 29
  • Karma: 2
    • View Profile
Re: Sensei on OPNsense - Application based filtering
« Reply #317 on: May 22, 2019, 07:10:28 pm »
elasticsearch shut down because it started to run out of disk space. How do I tune that? I've got a little over 300GB available for a family of 4 and a few guests a week.

Thanks!
Logged

mb

  • Hero Member
  • *****
  • Posts: 941
  • Karma: 99
    • View Profile
    • Sunny Valley Networks
Re: Sensei on OPNsense - Application based filtering
« Reply #318 on: May 22, 2019, 07:58:03 pm »
Hi @OPNsense4ever

You can use the following guide to determine for how many days you can have your reporting data.

https://guide.sunnyvalley.io/sensei/getting-started/getting-ready#disk-space

Then navigate to Sensei -> Configuration -> Reporting & Data

and set the maximum number of days to store reporting data.

When you set this number to a value smaller than the current one, Sensei will confirm with you if you want the surplus data to be deleted.

For this you need Elasticsearch to stay open, temporarily disable Health check to prevent Sensei from shutting it down again.
« Last Edit: May 22, 2019, 08:02:10 pm by mb »
Logged

OPNsense4ever

  • Newbie
  • *
  • Posts: 29
  • Karma: 2
    • View Profile
Re: Sensei on OPNsense - Application based filtering
« Reply #319 on: May 25, 2019, 12:34:38 am »
Sweet! Thanks!
Logged

JohnDoe17

  • Newbie
  • *
  • Posts: 40
  • Karma: 5
    • View Profile
Re: Sensei on OPNsense - Application based filtering
« Reply #320 on: May 28, 2019, 05:28:35 pm »
I'm new to Sensei, but I'm loving it so far!  Great work!

I do occasionally get a "crash report" notification though.

Here is the sequence of events:

0) Sensei was not installed.
1) Upgraded OPNsense from 18.7.10_4 to 19.1.8.
2) Installed Sensei 0.8.0.beta10.
3) Successfully completed the initial Sensei configure wizard.
4) Noticed a "crash report" when I went to the OPNsense Dashboard.

Unfortunately, I don't have the crash report in front of me at the moment, but I *did* submit it, so hopefully you'll get it from the OPNsense team eventually.  It was something about PHP crashing with bad data related to the "TCP Service Security" password.  I'll keep you posted if I see it again.
Logged

mb

  • Hero Member
  • *****
  • Posts: 941
  • Karma: 99
    • View Profile
    • Sunny Valley Networks
Re: Sensei on OPNsense - Application based filtering
« Reply #321 on: May 28, 2019, 05:30:41 pm »
Hi @JohnDoe17,

Thanks, great that you found Sensei useful for you.

One question: did you install Sensei 0.7 or the new 0.8 version?
Logged

JohnDoe17

  • Newbie
  • *
  • Posts: 40
  • Karma: 5
    • View Profile
Re: Sensei on OPNsense - Application based filtering
« Reply #322 on: May 28, 2019, 05:35:02 pm »
Quote
2) Installed Sensei 0.8.0.beta10.
Logged

mb

  • Hero Member
  • *****
  • Posts: 941
  • Karma: 99
    • View Profile
    • Sunny Valley Networks
Re: Sensei on OPNsense - Application based filtering
« Reply #323 on: May 28, 2019, 05:36:56 pm »
Thanks JohnDoe17, I missed that.

Having a look at it if we're missing something. In the meantime, if you encounter it again, feel free to email the screenshot to sensei - at - sunnyvalley.io.

Logged

JohnDoe17

  • Newbie
  • *
  • Posts: 40
  • Karma: 5
    • View Profile
Re: Sensei on OPNsense - Application based filtering
« Reply #324 on: May 28, 2019, 06:11:31 pm »
I got the crash to happen again.

Note that "Rainbow#Bicycle" is the password I was using for the test.  Does Sensei handle the "#" symbol in a password?

Code: [Select]
[28-May-2019 11:08:17 America/Chicago] PHP Fatal error:  Uncaught Error: Class 'OPNsense\Sensei\Exception' not found in /usr/local/opnsense/mvc/app/models/OPNsense/Sensei/Telnet.class.php:111
Stack trace:
#0 /usr/local/opnsense/mvc/app/models/OPNsense/Sensei/Telnet.class.php(75): OPNsense\Sensei\Telnet->connect()
#1 /usr/local/opnsense/mvc/app/models/OPNsense/Sensei/Sensei.php(151): OPNsense\Sensei\Telnet->__construct('127.0.0.1', 4346, 1, '', 1)
#2 /usr/local/opnsense/mvc/app/models/OPNsense/Sensei/Sensei.php(134): OPNsense\Sensei\Sensei->runTelnetCommands('127.0.0.1', 4346, 'Rainbow#Bicycle', Array, Array)
#3 /usr/local/opnsense/mvc/app/controllers/OPNsense/Sensei/Api/EngineController.php(89): OPNsense\Sensei\Sensei->runCLI(Array)
#4 [internal function]: OPNsense\Sensei\Api\EngineController->cliAction()
#5 [internal function]: Phalcon\Dispatcher->callActionMethod(Object(OPNsense\Sensei\Api\EngineController), 'cliAction', Array)
#6 [internal function]: Phalcon\Dispatcher->dispatch()
#7 /usr/local/opnsense/www/api.php(26): Phalcon\Mvc\Application->handle()
#8 {main in /usr/local/opnsense/mvc/app/models/OPNsense/Sensei/Telnet.class.php on line 111
Logged

mb

  • Hero Member
  • *****
  • Posts: 941
  • Karma: 99
    • View Profile
    • Sunny Valley Networks
Re: Sensei on OPNsense - Application based filtering
« Reply #325 on: May 29, 2019, 02:10:25 am »
Dear Sensei users,

Sensei 0.8.0 Release Candidate 1 is out. This marks the first step into releasing 0.8 and towards 1.0. There will be no 0.9 :)

Change log is as follows:
  • Per-process health monitoring. Sensei engine now checks heartbeats from its packet processors and taking the corrective action in case of trouble.
  • Customizable live session explorers. You can now customize which columns to be displayed and re-organize columns. Just drag a column and drop it on its new place.
  • Performance improvement for Active Directory Module
  • Engine logs older than two weeks are automatically purged now
  • Fixed a bug with Sensei CLI API which caused some errors be reported in OPNsense Crash Reporter
  • Default report retention time has been adjusted to be 7 days. You can set this to as high as 90 days

We're running 0.7 to 0.8 upgrade tests. As soon as they show that we're good to go, 0.7 users will be reported of the new 0.8 update.

Enjoy :)

Sensei team
« Last Edit: May 29, 2019, 02:13:31 am by mb »
Logged

patcsy88

  • Newbie
  • *
  • Posts: 18
  • Karma: 1
    • View Profile
Re: Sensei on OPNsense - Application based filtering
« Reply #326 on: May 29, 2019, 01:42:31 pm »
Just reinstalled OPNsense and the RC1 on APU2C4 with 2GB Swap - so far so good!
Logged

mb

  • Hero Member
  • *****
  • Posts: 941
  • Karma: 99
    • View Profile
    • Sunny Valley Networks
Re: Sensei on OPNsense - Application based filtering
« Reply #327 on: May 29, 2019, 01:48:31 pm »
@patcsy88, thanks for sharing your experience. Glad to hear that.

@JohnDoe17, can you have a look and see if 0.8.0.rc1 is solving your issue?
Logged

hbc

  • Hero Member
  • *****
  • Posts: 501
  • Karma: 47
    • View Profile
Re: Sensei on OPNsense - Application based filtering
« Reply #328 on: May 29, 2019, 03:36:27 pm »
@mb: Any news concerning CARP? As soon as I start sensei on CARP master, I have split communication. Cannot ping between CARP members and both nodes are master, dhcp service is communication-interrupted.

Sensei just on backup node seems to works, but except for proxy there is no traffic passing.
Logged
Intel(R) Xeon(R) Silver 4116 CPU @ 2.10GHz (24 cores)
256 GB RAM, 300GB RAID1, 3x4 10G Chelsio T540-CO-SR

mb

  • Hero Member
  • *****
  • Posts: 941
  • Karma: 99
    • View Profile
    • Sunny Valley Networks
Re: Sensei on OPNsense - Application based filtering
« Reply #329 on: May 29, 2019, 03:43:13 pm »
Hi @hbc,

Since running the netmap bridge application produces the same result, we suspect this to be a netmap issue. I've been trying to get Chelsio adapter to see if we can re-produce this.

In the meantime, any chances you can try the same setup with a different adapter -- preferably em or igb?

Logged

  • Print
Pages: 1 ... 20 21 [22] 23 24 ... 79
« previous next »
  • OPNsense Forum »
  • English Forums »
  • Zenarmor (Sensei) »
  • Sensei on OPNsense - Application based filtering
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2024 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2