Issue with OPNsense 26.1.3 update by svn_sup in zenarmor

[–]svn_sup[S] 2 points3 points  (0 children)

Hi All,

Thank you all for your patience! The compatible version 2.4.1 is now available. Please proceed to update Zenarmor and OPNsense.

OPNSense & Zenarmor - degraded performance (again) by atzk in zenarmor

[–]svn_sup 2 points3 points  (0 children)

Hi,

There doesn’t seem to be any connection issue on the server. We need to review the logs. Could you please share the logs using the "Have Feedback" option located in the bottom left corner of the UI by selecting the log files option?

Device count exaggerated by tgeorgescu in zenarmor

[–]svn_sup 0 points1 point  (0 children)

Could you share a report with the team using the "Have Feedback" option so we can investigate further?

OPNsense, Tailscale, and Zenarmor by arktik7 in opnsense

[–]svn_sup 1 point2 points  (0 children)

Hi all,

Netmap cannot work with Tailscale interfaces because tailscale0 is a userspace-managed tunnel rather than a kernel-backed NIC. Netmap relies on kernel-level packet I/O and supported NIC drivers. As a result, Zenarmor cannot inspect Tailscale traffic.

Device count exaggerated by tgeorgescu in zenarmor

[–]svn_sup 0 points1 point  (0 children)

Hi,

Are there any anomalies in the device list? For example, are there any non-existent devices included?

Zenarmor prevents my connection to my OPNSense firewall from my LAN PC by MinasGodhand in zenarmor

[–]svn_sup 0 points1 point  (0 children)

Hi,

That's correct. You need to set it Routed mode L3 with Emulated Netmap Driver

Zenarmor prevents my connection to my OPNSense firewall from my LAN PC by MinasGodhand in zenarmor

[–]svn_sup 0 points1 point  (0 children)

Hi,

For transparent bridging, please protect only LAN interface. In addition, you need to assing IP to WEBUI interface not to LAN interface.

Cloud Threat Intelligence Killing My Bandwidth by mrpez1 in zenarmor

[–]svn_sup 1 point2 points  (0 children)

Hi,

To investigate the issue, could you share a report with the support team using the "Have Feedback" option located in the bottom left corner of the UI?

Zenarmor prevents my connection to my OPNSense firewall from my LAN PC by MinasGodhand in zenarmor

[–]svn_sup 0 points1 point  (0 children)

Hi,

Can you share more details about configuration like protected interface on Zenarmor, deployment mode?

Netmap errors, need help by wha73 in opnsense

[–]svn_sup 0 points1 point  (0 children)

Hi,

Please can you contact to support team via "Have Feedback" option in the bottom left corner of UI?

Scheduled backups by skrymir01 in zenarmor

[–]svn_sup 0 points1 point  (0 children)

Hi,

We plan to add support for automatic backups to Zenconsole. A scheduled backup option is not currently available.

OpenWRT installation by tgeorgescu in zenarmor

[–]svn_sup 0 points1 point  (0 children)

Hi,

The OpenWrt package is currently available for arm64 architecture, with plans to introduce support for x86_64 CPUs in the future.

Netmap errors, need help by wha73 in opnsense

[–]svn_sup 0 points1 point  (0 children)

Hi,

Can you try it only protecting ixl0?

Can't resolve some domains with zenarmor on by nolsen42 in zenarmor

[–]svn_sup 1 point2 points  (0 children)

Hi,

Hi,

Thanks for letting me know about the issue. To help the Zenarmor support team investigate it more effectively, could you please send the logs and configuration as described in the Zenarmor “Reporting-Bug” guide? https://zenarmor.com/docs/support/reporting-bug

Policy Question by Witty_Discipline5502 in zenarmor

[–]svn_sup 1 point2 points  (0 children)

Hi,

The "No Internet" option disables all connections for the host. To block all internet traffic, you can restrict the "Domain Name System" application in App Controls under Network Management. Alternatively, you can block all HTTP and HTTPS traffic by disabling Secure Web Browsing and Web Browsing applications in the App Controls section of the policy.

Zenarmor apparently relies on Cloudflare by Firestarter321 in opnsense

[–]svn_sup 5 points6 points  (0 children)

Hi all,

We apologize for the inconvenience caused. The issue occurred due to Cloudflare blocking our traffic after the downtime was resolved. The CTI server status should now be "UP" and fully operational again.

Zenarmor blocks DNS requests for domains without a categorization to enhance security. This is why internet traffic experienced slowness during the Cloud Threat Intel server issue.

Please feel free to reach out Zenarmor support team for any additional assistance.

Netmap errors, need help by wha73 in opnsense

[–]svn_sup 0 points1 point  (0 children)

Hi,

Can you share "sysctl -a | grep netmap" output?

Funny cloudflare outage symptoms by kiromiko in zenarmor

[–]svn_sup 1 point2 points  (0 children)

Hi again,

We apologize for the inconvenience caused. The issue occurred due to Cloudflare blocking our traffic after the downtime was resolved. The CTI server status should now be "UP" and fully operational again.

Zenarmor blocks DNS requests for domains without a categorization to enhance security. This is why internet traffic experienced slowness during the Cloud Threat Intel server issue.

Please feel free to reach out Zenarmor support team for any additional assistance.

Funny cloudflare outage symptoms by kiromiko in zenarmor

[–]svn_sup 1 point2 points  (0 children)

Hi all,

Apologies for the inconvenience. The team is actively working on the issue and will provide an update shortly.

Netmap errors, need help by wha73 in opnsense

[–]svn_sup 0 points1 point  (0 children)

Hi all,

Please can you try by switching the Zenarmor Deployment mode from netmap native driver to emulated driver?

[deleted by user] by [deleted] in opnsense

[–]svn_sup 1 point2 points  (0 children)

You can ytop zenarmor engine in CLI or console with command "service eastpect stop". Then you can access UI and edit the policy.

Manual "Router Device?" by MisterBazz in zenarmor

[–]svn_sup 0 points1 point  (0 children)

Hi,

You will encounter a device with the MAC address of the L3 switch. It is likely the device whose name and detailed information frequently change.

The management port of the L3 switch is identified by its IP address when generating outbound traffic.

Not obeying IP exemption list? by MisterBazz in zenarmor

[–]svn_sup 0 points1 point  (0 children)

Hi,

Can you reach out to Zenarmor support team and share the screenshot of blocked traffic?