!zyeXJfuMWoXfqBNbUK:matrix.org

OPNsense® ☞ ؟⸮UNOFFICIAL⸮؟ – Self Support Community for community self support.

486 Members
https://opnsense.org/ ° https://wiki.opnsense.org/ ° https://github.com/opnsense ° https://forum.opnsense.org/ ° https://opnsense.org/blog/ ° Announcements: https://forum.opnsense.org/index.php?board=11.0 ••• "OPNsense is open source, FreeBSD-based firewall and routing software developed by Deciso, a company in the Netherlands that makes hardware and sells support packages for OPNsense. It is a fork of pfSense." - https://en.wikipedia.org/wiki/OPNsense ° pfSense is an open source firewall/router computer software distribution based on FreeBSD. It is installed on a physical computer or a virtual machine to make a dedicated firewall/router for a network and has been noted for its reliability and offering a range of features. - https://en.wikipedia.org/wiki/PfSense ••• https://doc.pfsense.org/index.php/Main_Page ••• This room is "World Readable" or according to IRC types, "Logged": https://view.matrix.org/alias/%23OPNsense:matrix.org ••• Listed: https://matrixstats.org/room/!zyeXJfuMWoXfqBNbUK:matrix.org ••• For sharing: #OPNsense:matrix.org ° https://riot.im/app/#/room/#OPNsense:matrix.org ° https://matrix.to/#/#OPNsense:matrix.org ° [#OPNsense:matrix.org](https://matrix.to/#/#OPNsense:matrix.org) ••• Keywords/Tags: #OPNsense #firewall #router #Cisco #secure #security ••••84 Servers

Load older messages


SenderMessageTime
11 Oct 2024
@lunaxquinn:matrix.orgLuna 💎tcpdump does show the packets coming in, i know the request is being dropped somewhere but just to confirm the tcpdump output what am i looking for on each line to confirm it's being blocked?03:27:51
@lunaxquinn:matrix.orgLuna 💎

it's just this over and over until the connection times out

03:27:42.543796 IP 127.0.0.1.29563 > 127.0.0.1.8899: Flags [S], seq 2869557022, win 65228, options [mss 16344,nop,wscale 7,sackOK,TS val 1457228288 ecr 0], length 0
03:28:48
@lunaxquinn:matrix.orgLuna 💎i did specify floating rules to explicity allow connections from / to 127.0.0.1 to be allowed in both directions, first match and to log the rule but nothing shows in the live log03:29:21
@targetball:matrix.orgtargetballYou should see the 127.0.0.1:random_curl_port > 127.0.0.1:http_server_port . If it after that it responds in reverse order then you know the http server got the curl packets through the firewall.03:31:02
@targetball:matrix.orgtargetballIt's been a while since I configured my opnsense firewall at work but the rule allowing access to localhost should be done with allowing traffic to the loopback interface rather than a specific IP. I'll try to look up a doc or something.03:33:57
@lunaxquinn:matrix.orgLuna 💎the traffic is only going one way correct. I've just added a rule to allow all from any to any on loopback interface and still no joy but i might have added the rule incorrectly03:36:07
@lunaxquinn:matrix.orgLuna 💎thats strange, when i add rules at the top of the floating rules for pass in/out from 127.0.0.1 to 127.0.0.1 any port using the Null4 gateway i stop seeing any output in tcpdump entirely03:44:09
@lunaxquinn:matrix.orgLuna 💎if i disable those rules the output comes back, still no connection though03:44:37
@targetball:matrix.orgtargetballI just saw this. Is there a service running on port 8899? You said you did curl earlier but the webui should be on port 80.03:46:09
@lunaxquinn:matrix.orgLuna 💎there is a service running on 8899, it's not registering any connection attempts at all so the packets aren't reaching the port03:46:49
@lunaxquinn:matrix.orgLuna 💎im also having the same connection issues when trying to connect to any TCP port listening on 127.0.0.1, not just my services. trying to ssh 127.0.0.1 and curl http://127.0.0.1 are just easier ways to reproduce the problem for others03:48:15
@lunaxquinn:matrix.orgLuna 💎i get the same output in tcpdump when trying to use curl or ssh to talk to services via 127.0.0.103:49:21
@targetball:matrix.orgtargetballBest of luck! I'm going to got to bed 💤 . The general troubleshooting thing i'd suggest is shutting off each of your firewall rules to see if that's the culprit. 03:49:51
@targetball:matrix.orgtargetball* Best of luck! I'm going to go to bed 💤 . The general troubleshooting thing i'd suggest is shutting off each of your firewall rules to see if that's the culprit. 03:50:03
@lunaxquinn:matrix.orgLuna 💎no worries, i'll dig a little deeper, hopefully i can find the solution. Thank you for the tips though, gives me something to work with 😎03:51:11
@lunaxquinn:matrix.orgLuna 💎you were right, one of my rules was causing the problem. after adjusting the rule everything is working fine 🥳04:08:34
@rp:mpfau.de@rp:mpfau.de joined the room.13:30:44
@sauceee:matrix.org@sauceee:matrix.org joined the room.16:57:23
12 Oct 2024
@sauceee:matrix.org@sauceee:matrix.orgYall tapn https://t.me/+32cFzLuOiacxZmM012:49:37
@sauceee:matrix.org@sauceee:matrix.org left the room.16:02:53
@geobarrod:matrix.orgfbsd joined the room.23:54:36
13 Oct 2024
@geobarrod:matrix.orgfbsd changed their display name from geobarrod to gbr.01:01:45
@geobarrod:matrix.orgfbsd changed their display name from gbr to g.01:02:41
@geobarrod:matrix.orgfbsd changed their display name from g to fbsd.01:02:50
14 Oct 2024
@saucerr:matrix.orgsaucerr joined the room.16:01:25
@saucerr:matrix.orgsaucerr Cashapp Apple Pay Cpns Dave method Coinbase loading Airb&b Verizon iPhone 15 method Apple product method Vermont Rent relief Sba method Carding cc sites Gas station Sauce ( free gas ) bank drops Wells Fargo Loan sauce Shein method https://t.me/+32cFzLuOiacxZmM016:27:38
@saucerr:matrix.orgsaucerr Cashapp Apple Pay Cpns Dave method Coinbase loading Airb&b Verizon iPhone 15 method Apple product method Vermont Rent relief Sba method Carding cc sites Gas station Sauce ( free gas ) bank drops Wells Fargo Loan sauce Shein method https://t.me/+32cFzLuOiacxZmM016:36:45
@0nn0:matrix.orgOnno MilkManzJourDaddy-OE: please ban the spammers 21:30:35
15 Oct 2024
@saucerr:matrix.orgsaucerr Cashapp Apple Pay Cpns Dave method Coinbase loading Airb&b Verizon iPhone 15 method Apple product method Vermont Rent relief Sba method Carding cc sites Gas station Sauce ( free gas ) bank drops Wells Fargo Loan sauce Shein method https://t.me/+32cFzLuOiacxZmM009:15:18
@rp:mpfau.de@rp:mpfau.de left the room.10:34:55

There are no newer messages yet.


Back to Room ListRoom Version: