Questions tagged [opnsense]

56 questions
4
votes
1 answer

Which LAGG type should be used for MLAG switches to CARP firewalls?

My network setup involves two firewalls in a Common Address Redundancy Protocol (CARP) group, each connected to an MLAG (Multi-Chassis Link Aggregation) configuration of Mikrotik switches. Onward ports on the switches are bonded using LACP. …
Tintin
  • 205
3
votes
2 answers

OPNsense WAN failover causes disruption when non-active WAN is down

I have the latest version of OPNsense set up in a VM on ESXi 7. OPNsense is very similar to pfSense, and I suspect the solution would apply to both. All the NICs are PCI passthrough devices: A management interface WAN 1, my preferred WAN to be used…
2
votes
1 answer

I am unable to access services on the WAN IP from within the network

Normally, this would not be a desired configuration, but I am setting up a NextCloud server, and to validate the domain, it requires that it be able to access it through the public IP address. No matter what I do, I cannot get this to work. It…
2
votes
1 answer

NTP Traffic, but NTP not installed

I have recently started with OPNSense and have limited outgoing traffic to HTTP/s, SSH ports. When analyzing my blocked traffic i found sporadic outgoing NTP-Requests from my local Linux machine. I am not very familiar with NTP. I am now wondering a…
2
votes
1 answer

Should I run 2 firewalls or manage everything from one?

I currently have a UniFI Firewall in place and I plan to get a OPNsense firewall mainly for a VPN. Setup: Modem - OPNsense Firewall - UniFI Firewall - VLANS (Rules made by UniFi) Are there any advantages of running a setup with 2 firewalls or should…
Ben
  • 23
1
vote
1 answer

OpenVPN on OPNsense, everything routed through tunnel but shouldn't

I have the following Setup An OPNsense on which OPNVPN is running. I created an VPN instance and also some users. As the "Server (IPv4)" I have set 10.123.0.0/24. Under Routing I have set nothing. Then I use the "Client Specific Overrides" feature.…
1
vote
0 answers

Complex Network Architecture Trouble

I hope that someone can help me because it's very complicated/messy. I'll explain the situation. I have the 2 locations: SiteA and SiteB. They are connected in VXLAN over IPSEC between them with 2 OPNSense firewalls. The network they share is…
Stefano
  • 21
1
vote
0 answers

Cant connect OpenVPN server TLS Error: tls-crypt unwrapping failed from OpnSense

Client legasy https://postimg.cc/F1vxf4Y3 Trust (auth&cert) https://postimg.cc/0rC0DBS3 *111.311.115.122 SEVER IP 222.239.212.126 CLIENT IP OpnSene (is client)* CLIENT CONFIG generated by script…
dr.ipkins
  • 13
  • 1
  • 4
1
vote
1 answer

Inter-VLAN connection issues when devices use Wi-Fi and OPNsense router

I am trying to segregate devices in my home network with 2 different VLANs: HOME and IOT. I have the following network devices: 1 cable modem 1 OPNsense router with WAN, LAN and OPT1 ports 1 Netgear MS108EUP managed switch with 8 ports 1 Netgear…
1
vote
0 answers

LogStash and parsing OPNSenser logs

My logs are coming in as follows: <134>May 24 14:39:32 edge.internal filterlog[2535]:…
Jason
  • 3,961
  • 20
  • 70
  • 109
1
vote
2 answers

NFS Mouting Failing due to illegal port

I have a VM machine that has a public IP interface and a private IP interface. The private interface is assigned 192.168.50.78. Then I have a dedicated host that acts as my "router" using private IP 192.168.50.1 and this is, therefore, my gateway…
Granwille
  • 191
1
vote
0 answers

Routing issue on Debian 11 VM

I updated my OPnsense "router/gateway" to 23.1 a few days ago, and now I am experiencing an issue with one of my machines. I have one machine with OPnsense installed that acts as a basic NAT router for my private subnet 192.168.50.0/24. This…
1
vote
1 answer

OPNsense move interface to other hardware port

I have an OPNsense with interfaces directy configured to the hardware ports. The corresponding switch port is also an access port. We plan to change the switch port to a trunk port to transport multiple VLANs via this port. Is there a way to move…
Lithilion
  • 131
1
vote
0 answers

Wireguard Destination Host Unreachable on internal network

I'm setting up Wireguard to tunnel from a cloud VM to our internal network. The local server is using the Wireguard plugin for OPNSense. OPNSense acts as firewall, dhcp, etc. The cloud VM is not behind any firewall or anything. Server: interface:…
cclloyd
  • 623
1
vote
1 answer

OPNsense NAT/Port Forward: Forward multiple protocols and ports

I want to forward ICMP and specific TCP and UDP ports on OPNsense but I'm unable to find a concise solution. Specifically I want to forward ICMP, http, https and UDP 32768-65535. I'm adding a new port forward in the port forwarding section…
1
2 3 4