OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • Archive »
  • 18.7 Legacy Series »
  • more complex setup
« previous next »
  • Print
Pages: [1]

Author Topic: more complex setup  (Read 3153 times)

mahescho

  • Jr. Member
  • **
  • Posts: 59
  • Karma: 2
    • View Profile
more complex setup
« on: September 26, 2018, 04:11:07 pm »
Hi,

i plan a a bit more complex setup. See attachment. I've tree VDSL connections. All with static public IPv4 and IPv6. On with an IPv4 subnet and a /48 v6 prefix. The other two get single v4 addresses and a /56 v6 prefix. Internally I plan to have VLANs only and depending on the VLAN different outgoing NAT setups an IPv6 nets. Communication between the VLANs has to work too.

Is this doable with OPNsense?

TIA
Matthias
Logged
OPNsense 21.1.2-amd64
FreeBSD 12.1-RELEASE-p13-HBSD
OpenSSL 1.1.1j 16 Feb 2021

fabian

  • Hero Member
  • *****
  • Posts: 2768
  • Karma: 199
  • OPNsense Contributor (Language, VPN, Proxy, etc.)
    • View Profile
    • Personal Homepage
Re: more complex setup
« Reply #1 on: September 26, 2018, 07:47:10 pm »
I have never used it but OPNsense should be multi-wan capable.
Logged

opnsrcfw

  • Newbie
  • *
  • Posts: 7
  • Karma: 1
    • View Profile
    • MyOpenSourceCode
Re: more complex setup
« Reply #2 on: September 27, 2018, 04:56:07 am »
@mahescho   your network config should be achievable with OpnSense.
Logged
[Firewall - OPNsense 19.7-amd64, FreeBSD 11.2 RELEASE-p11-HBSD]
[Hardware - Dell R210 Xeon E31260L@2.40GHz x8core, 16G RAM 200GB SSD, Dual 1G & Dual 10G NIC, GS728TP Poe+ Switch]
[ISP - D940Mbps / U880Mbps]

mahescho

  • Jr. Member
  • **
  • Posts: 59
  • Karma: 2
    • View Profile
Re: more complex setup
« Reply #3 on: September 27, 2018, 09:10:13 am »
@opnsrcfw Thanks, I thought so, as I did some thing similar with FreeBSD using FIBS. My concern was if this could be done via the GUI.
Logged
OPNsense 21.1.2-amd64
FreeBSD 12.1-RELEASE-p13-HBSD
OpenSSL 1.1.1j 16 Feb 2021

franco

  • Administrator
  • Hero Member
  • *****
  • Posts: 13694
  • Karma: 1176
    • View Profile
Re: more complex setup
« Reply #4 on: September 27, 2018, 12:54:38 pm »
Caveat: Multi-WAN with multiple DHCPv6 WANs does not currently work, but if you're using all static you shall be fine. :)


Cheers,
Franco
Logged

mahescho

  • Jr. Member
  • **
  • Posts: 59
  • Karma: 2
    • View Profile
Re: more complex setup
« Reply #5 on: September 27, 2018, 09:52:46 pm »
@franco: I only use static public IPs  :)

My major headaches at the moment are this: https://forum.opnsense.org/index.php?topic=9786.0 and that: https://forum.opnsense.org/index.php?topic=9804.0
Logged
OPNsense 21.1.2-amd64
FreeBSD 12.1-RELEASE-p13-HBSD
OpenSSL 1.1.1j 16 Feb 2021

franco

  • Administrator
  • Hero Member
  • *****
  • Posts: 13694
  • Karma: 1176
    • View Profile
Re: more complex setup
« Reply #6 on: September 27, 2018, 10:07:15 pm »
Let me answer here. :)

I hope 18.7.4 fixed the first one:

https://github.com/opnsense/changelog/blob/master/doc/18.7/18.7.4#L18

The second question's answer is: Firewall: Virtual IPs. Yes, it also works for IPv6 but the subnet mask may not switch immediately. Try saving anyway.

There *may* be a combination of issue 1 and 2 happening now for you for Virtual IPs on top of PPPoE so we need to go back and fix that as well. PPPoE is an ongoing adventure for us...

As far as binding goes for the services you mentioned... we don't support exclusive binding setups in the plugins so it's more of a primary interface address or all of the set addresses (including virtual IPs). Worst case you will have to install the FreeBSD packages and skip the plugins.


Cheers,
Franco
Logged

mahescho

  • Jr. Member
  • **
  • Posts: 59
  • Karma: 2
    • View Profile
Re: more complex setup
« Reply #7 on: September 28, 2018, 12:42:04 pm »
Thanks.

Binding: Too bad, my hope was that "basics" are covered her. I''ve tried several commercial Linux based firewall and they all failed too when it came to binding and most important being able to create separate configurations for different IPs and ports. At least with OPNsense a complete manual setup of services is possible, as you mentioned.

IPv6 on PPPoE: The latest update fixed the problem. Thanks.

Now I will experiment with "virtual IPs" ...

BTW: My IPv6 issue on static connection persists! https://forum.opnsense.org/index.php?topic=9639.0 I've to use the "pfctl" workaround ...
Logged
OPNsense 21.1.2-amd64
FreeBSD 12.1-RELEASE-p13-HBSD
OpenSSL 1.1.1j 16 Feb 2021

  • Print
Pages: [1]
« previous next »
  • OPNsense Forum »
  • Archive »
  • 18.7 Legacy Series »
  • more complex setup
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2023 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2