Sensei on OPNsense - Application based filtering

Started by mb, August 25, 2018, 03:38:14 AM

Previous topic - Next topic
Other
Fix: Increase netmap buf_num value to accommodate both Suricata and Sensei on high-end servers

compatibility sensei - suricata low-end devices?
CPU Type Intel(R) Celeron(R) CPU J3160 @ 1.60GHz (4 cores)
Memory: 8GB

Hi @yeraycito,

dev.netmap.buf_num value was low if both Sensei and Suricata was run on -even- different interfaces. This was due to some high-end network adapters having multiple Rx/Tx queues, and thus requiring more kernel memory.

Work on Suricata+Sensei running on the same interface is underway.

I can't deactivate "US-East" Cloud-Node
Machine Version:    1.2.3
UI Version:    19.12.14
Database Version:    1.2.0

Hi @marcri, sensei needs at least two cloud nodes. You should be able to select any other node as the second one. Can you confirm that this is the case? If not let's check it out.

Quote from: mb on December 16, 2019, 07:16:19 PM
Hi @marcri, sensei needs at least two cloud nodes. You should be able to select any other node as the second one. Can you confirm that this is the case? If not let's check it out.
Hi @mb,  selecting an other second node works.
Thanks

@marcri, that's good to hear. A side note: we'll launch another Europe node in the coming year.

Hi,

just wondering: I setup sensei to block advertisments. Sometimes I get the page:

#################
The page you are trying to access is restricted by your organization.

Reason:   Advertisements site access
Client IP:   192.168.1.30
Remote IP:   91.215.103.xxx
Application:   Web Browsing
Application Category:   Web Browsing
Web Category:   Advertisements
#################

And sometimes the connection is just reset: ERR_CONNECTION_CLOSED

Why is this?

Thanks and best regards
Marco

Hi Marco, many thanks for trying sensei.

This happens if the blocked connection is not speaking HTTP. Sensei displays Landing Page only if it is an HTTP connection.

For HTTPS connections, since TLS comes early and client and server does not yet speak HTTP, we cannot display the landing page (behavior to change with TLS inspection feature, see below)

3. For Application control, we do not display since it might be a connection which does not speak HTTP.

For HTTPS connections, block pages will be available along with TLS inspection feature.

For more FAQ, see: https://help.sunnyvalley.io/hc/en-us/articles/360025100613-FAQ

@mb

Today i did a opnsense firmware update to 19.7.8

After this update i can´t start monogdb anymore.

I deleted the report data and even reinstalled the sensei package and did a restart of opnsense but had no luck!

What can i do?

See my screenshot!!

thx
regards rené

Supermicro A2SDi-4C-HLN4F
Team Rebellion Member (sidebar / themes: tukan, cicada & vicuna)

December 18, 2019, 08:18:52 PM #684 Last Edit: December 18, 2019, 08:22:30 PM by opnsenseuser
Quote from: opnsenseuser on December 18, 2019, 04:36:33 PM
@mb

Today i did a opnsense firmware update to 19.7.8

After this update i can´t start monogdb anymore.

I deleted the report data and even reinstalled the sensei package and did a restart of opnsense but had no luck!

What can i do?

See my screenshot!!

thx
regards rené

don´t know where the problem is!

Supermicro A2SDi-4C-HLN4F
Team Rebellion Member (sidebar / themes: tukan, cicada & vicuna)

December 18, 2019, 08:32:01 PM #685 Last Edit: December 18, 2019, 08:33:43 PM by mayo
Same for me. Decided to uninstall and not install anymore.

Quote from: opnsenseuser on December 18, 2019, 08:18:52 PM
Quote from: opnsenseuser on December 18, 2019, 04:36:33 PM
@mb

Today i did a opnsense firmware update to 19.7.8

After this update i can´t start monogdb anymore.

I deleted the report data and even reinstalled the sensei package and did a restart of opnsense but had no luck!

What can i do?

See my screenshot!!

thx
regards rené

don´t know where the problem is!

Quote from: mayo on December 18, 2019, 08:32:01 PM
Same for me. Decided to uninstall and not install anymore.

Quote from: opnsenseuser on December 18, 2019, 08:18:52 PM
Quote from: opnsenseuser on December 18, 2019, 04:36:33 PM
@mb

Today i did a opnsense firmware update to 19.7.8

After this update i can´t start monogdb anymore.

I deleted the report data and even reinstalled the sensei package and did a restart of opnsense but had no luck!

What can i do?

See my screenshot!!

thx
regards rené

don´t know where the problem is!
And the relation to the problem of this thred is??
Can you be more specific why you abandone Sensei?
Proxmox enthusiast @home, bare metal @work.

Simple: every Opnsense update Sensei stops working.
Quote from: Antaris on December 18, 2019, 08:54:58 PM
Quote from: mayo on December 18, 2019, 08:32:01 PM
Same for me. Decided to uninstall and not install anymore.

Quote from: opnsenseuser on December 18, 2019, 08:18:52 PM
Quote from: opnsenseuser on December 18, 2019, 04:36:33 PM
@mb

Today i did a opnsense firmware update to 19.7.8

After this update i can´t start monogdb anymore.

I deleted the report data and even reinstalled the sensei package and did a restart of opnsense but had no luck!

What can i do?

See my screenshot!!

thx
regards rené

don´t know where the problem is!
And the relation to the problem of this thred is??
Can you be more specific why you abandone Sensei?

Quote from: mayo on December 18, 2019, 09:00:06 PM
Simple: every Opnsense update Sensei stops working.
Sensei is relatively new addon to OPNsense. Monogdb in it is even newer. I think we need more patience here...
Proxmox enthusiast @home, bare metal @work.

December 18, 2019, 09:35:33 PM #689 Last Edit: December 18, 2019, 10:20:59 PM by mb
Ok, I think I have an idea about what's going on:

19.7.8 update seems to remove mongodb40 and dependencies.

=====
Message from opnsense-19.7.8:

--
Roar!
Checking integrity... done (0 conflicting)
Deinstallation has been requested for the following 3 packages:

Installed packages to be REMOVED:
boost-libs-1.72.0
icu-65.1,1
snappy-1.1.6_1

Number of packages to be removed: 3


Update: Problems is related to mongodb package. Elasticsearch is fine. We're shipping new mongodb40 packages momentarily. Will update the thread.