
OPNsense® ☞ ؟⸮UNOFFICIAL⸮؟ – Self Support Community for community self support.

472 Members
https://opnsense.org/ ° https://wiki.opnsense.org/ ° https://github.com/opnsense ° https://forum.opnsense.org/ ° https://opnsense.org/blog/ ° Announcements: https://forum.opnsense.org/index.php?board=11.0 ••• "OPNsense is open source, FreeBSD-based firewall and routing software developed by Deciso, a company in the Netherlands that makes hardware and sells support packages for OPNsense. It is a fork of pfSense." - https://en.wikipedia.org/wiki/OPNsense ° pfSense is an open source firewall/router computer software distribution based on FreeBSD. It is installed on a physical computer or a virtual machine to make a dedicated firewall/router for a network and has been noted for its reliability and offering a range of features. - https://en.wikipedia.org/wiki/PfSense ••• https://doc.pfsense.org/index.php/Main_Page ••• This room is "World Readable" or according to IRC types, "Logged": https://view.matrix.org/alias/%23OPNsense:matrix.org ••• Listed: https://matrixstats.org/room/!zyeXJfuMWoXfqBNbUK:matrix.org ••• For sharing: #OPNsense:matrix.org ° https://riot.im/app/#/room/#OPNsense:matrix.org ° https://matrix.to/#/#OPNsense:matrix.org ° [#OPNsense:matrix.org](https://matrix.to/#/#OPNsense:matrix.org) ••• Keywords/Tags: #OPNsense #firewall #router #Cisco #secure #security ••••82 Servers

Load older messages

12 Jul 2024
In reply to @toxicpublic:matrix.org
Hello Everyone. Am I becoming crazy or did something happen that blocked ssh access on my opnSense installs untill I upgraded ? I know there was a critical vuln published recently regarding openssh, but I wasn't expecting my firewalls from locking me out...
OPNsense is BSD-based and BSD should be save since 2001(?) regarding RegreSSHion. ("OpenBSD systems are unaffected by this bug, as OpenBSD developed a secure mechanism in 2001 that prevents this vulnerability." - https://blog.qualys.com/vulnerabilities-threat-research/2024/07/01/regresshion-remote-unauthenticated-code-execution-vulnerability-in-openssh-server)
In reply to @royaltiger:matrix.org
OPNsense is BSD-based and BSD should be save since 2001(?) regarding RegreSSHion. ("OpenBSD systems are unaffected by this bug, as OpenBSD developed a secure mechanism in 2001 that prevents this vulnerability." - https://blog.qualys.com/vulnerabilities-threat-research/2024/07/01/regresshion-remote-unauthenticated-code-execution-vulnerability-in-openssh-server)
If OPNsense do so that shouldn't be related to RegreSSHion, but using Keys is nevertheless best practice.
@toxicpublic:matrix.orgtoxic thanks RoyalTiger so wasn't related to RegreSSHion I trust you ;)
Very strange though that my 3 firewalls in carp failover all got their ssh blocked and came back only after upgrade&restart of the service :(
@royaltiger:matrix.orgRoyalTigerHm, wierd. Maybe related to this? But seems more a DNS resolution issue... https://github.com/opnsense/core/issues/7426 For real: Could be anything. 14:45:37
16 Jul 2024
@aber:ungleich.chaber joined the room.18:56:40
17 Jul 2024
@gish:gish.ggGish changed their display name from gish to Gish.00:32:02
@royaltiger:matrix.orgRoyalTigerFirmware System.png
Download Firmware System.png
In reply to @toxicpublic:matrix.org
thanks RoyalTiger so wasn't related to RegreSSHion I trust you ;)
Very strange though that my 3 firewalls in carp failover all got their ssh blocked and came back only after upgrade&restart of the service :(
You not somehow updated your OpenSSH seperatly?
19 Jul 2024
@giacomo_c:matrix.orggiacomo_c joined the room.20:27:08
@giacomo_c:matrix.orggiacomo_cI've got a new opnsense VM install and I'm trying to access the webgui via an opt1 interface that is connected to a network with a linux box. I have confirmed layer3 as I can ping the linux box from the opnsense box, but not vice versa. The opnsense is not allowing webgui or ssh access via that opt1 interface, and the linux box sees relevant TCP ports closed/non-responsive. this is my first foray into the opnsense world. Does the default install allow connections on non lan/wan interfaces? 20:39:01
@royaltiger:matrix.orgRoyalTigerHm, let me think. If I remember it right the normal anti-lockout-rule for SSH and WebGUI should just refer to the setup-LAN while installing. I'm also not sure if normal pinging is forbidden by default. 20:53:19
@giacomo_c:matrix.orggiacomo_cyou know what, i could just try to re-assign the interfaces so that the "LAN" is connected to the network with the linux box and give it another go20:54:27
@royaltiger:matrix.orgRoyalTiger * Hm, let me think. If I remember it right the normal anti-lockout-rule for SSH and WebGUI should just refer to the setup-LAN installed/configured first. I'm also not sure if normal pinging is forbidden by default. 20:54:29
@royaltiger:matrix.orgRoyalTigerYeah, that should work.20:54:42
@royaltiger:matrix.orgRoyalTigerhttps://www.reddit.com/r/OPNsenseFirewall/comments/lex7l2/moving_antilockout_to_a_different_lan_interface/ This should apply till today.20:57:12
@giacomo_c:matrix.orggiacomo_cre-assigning did the trick20:58:31
@giacomo_c:matrix.orggiacomo_cahhh, opt1 has no pass rules by default21:05:48
@giacomo_c:matrix.orggiacomo_cit will listen on all interfaces21:05:57
@giacomo_c:matrix.orggiacomo_cbut without a pass rule, its not gonna let anything through lol21:06:05
@royaltiger:matrix.orgRoyalTigerYep, that's what the default anti-lockout-rule is for, so you aren't able to kill your access with a fw rule by mistake.21:09:20
@giacomo_c:matrix.orggiacomo_cthere was probably a way to setup a temp any any rule from the shell, but i was having trouble finding docs on that21:10:08
@royaltiger:matrix.orgRoyalTigerBut this just applies to the default LAN-interface, because you maybe don't want that other subnets are able to access "MGMT".21:10:22
@giacomo_c:matrix.orggiacomo_cso if i swap these interface assignments around in the webgui, will it still have the same IP assignments to the interface names? 21:12:18
@giacomo_c:matrix.orggiacomo_cright now eth1 = opt 1 and vteth = lan. i set a rule for opt 1 to allow from any to any ipv4. 21:13:13
@giacomo_c:matrix.orggiacomo_cif i switch vtnet = opt1 and eth1 = lan, will all that keep?21:13:28
@giacomo_c:matrix.orggiacomo_cohh, the ips21:14:27
@royaltiger:matrix.orgRoyalTigerUh, good question. As you just change the interface assignment to the added device, all settings in the configuration should still be the same. 21:15:51

Show newer messages

Back to Room ListRoom Version: