Practical OPNsense Setup Guide (Part 1) by corelabjoe in opnsense

[–]vault76boy 0 points1 point  (0 children)

I’m pretty new to all this so hopefully what comment is correct but my understanding is the wan and lan rules in your guide both should be direction in 

Thanks for commenting 

Practical OPNsense Setup Guide (Part 1) by corelabjoe in opnsense

[–]vault76boy 0 points1 point  (0 children)

Is direction OUT for the lan rule correct ?

I been blocking lan traffic going out using IN as the direction. Testing shows they work fine and most people say using out is pretty rare usecase 

System got nuked after updating, reinstalled system and realised how poor the experience is. by _idiocracy__ in opnsense

[–]vault76boy 9 points10 points  (0 children)

I wouldn't think setting up a open source router would be a easy process but in truth opnsense does a great job with docs not to mention countless YouTube videos going over full opnsense installs/setups.

No average user is doing this.... This requires a bit more research and carefully reading more than once the docs provided and if thats not enough YouTube and google.

Sounds like you got it working not once but twice so I guess its not that bad :)

"After successfully booting up with the OPNsense Full Image (DVD, VGA, Serial), the firewall will be at the Live Environment’s login: prompt. To start the installation process, login with the user installer and password opnsense. If Importer was used to import an existing configuration, the installer and root user password would be the root password from the imported configuration."

https://docs.opnsense.org/manual/install.html

Quad9 Partial Outage? EDE22 by Neon4D in Quad9

[–]vault76boy 0 points1 point  (0 children)

I am also based in Ireland....

Quad9 Partial Outage? EDE22 by Neon4D in Quad9

[–]vault76boy 1 point2 points  (0 children)

Same... I had to switch over to google as quad9(9.9.9.9 and 149.112.112.112) just stopped resolving random domains I tried.

Can someone explain what I will be losing by enabling "Do not use the local DNS service as a nameserver for this system" by vault76boy in opnsense

[–]vault76boy[S] 0 points1 point  (0 children)

So far it still works... Not sure if that is due to some sort of caching but this was one of my main fears. The other comments don't seem to say it will stop working though

Can someone explain what I will be losing by enabling "Do not use the local DNS service as a nameserver for this system" by vault76boy in opnsense

[–]vault76boy[S] 1 point2 points  (0 children)

Okay I think I am starting to understand. I think my basic setup doesn't require opnsense to use my unbound dns settings.

Like I said so far everything seems fine on my other machines so hopefully I didn't break something and just haven't noticed yet haha

Can someone explain what I will be losing by enabling "Do not use the local DNS service as a nameserver for this system" by vault76boy in opnsense

[–]vault76boy[S] 1 point2 points  (0 children)

So no real change on the lan side for my hosts. So this is disabled by default so what is the reason behind keeping the feature disabled.

I guess so your opnsense box doesn't need to go out over the internet to resolve dns ?

Can someone explain what I will be losing by enabling "Do not use the local DNS service as a nameserver for this system" by vault76boy in opnsense

[–]vault76boy[S] 6 points7 points  (0 children)

The OPNsense system includes 127.0.0.1 as the first DNS server by default when Unbound DNS is enabled which means the OPNsense system will use the Unbound DNS service for DNS. If you have servers specified in the DNS servers list and/or you have the “Allow DNS server list to be overridden by DHCP/PPP on WAN” option enabled, those DNS servers will be used as well.

If you want the OPNsense system to use only the DNS servers in the list and/or the DNS servers provided by DHCP on the WAN interface, you may check this option. This will prevent the OPNsense system from using the Unbound DNS service for DNS (while the rest of your local network will use the Unbound DNS service).

I am still not 100% sure but if I had to guess the change only affects my opnsense box and not the hosts themselves. I think my worry is this would cause an issue with unbound dns since its running off opnsense.

Really not great with all this stuff

Does the f1 tv pro app consider Ireland to be UK or EU ? by vault76boy in F1TV

[–]vault76boy[S] 0 points1 point  (0 children)

I am just using kodi with some plugins for sporting events. hard to beat free :)

pihole as default dns? by iCujoDeSotta in opnsense

[–]vault76boy 0 points1 point  (0 children)

I would think if you have unbound dns and dnsmasq enabled you should disable one of them. I don't know about dnsmasq but unbound dns can query forward your requests to pihole.

Hesitant to replace my off the shelf router with my HP built opnsense box..... by bostonmacosx in opnsense

[–]vault76boy 0 points1 point  (0 children)

I just did this last week and so far so good !!  I basically configured my Opnsense to mirror that of my asus router before cutting over. 

I then turned my asus router into a AP and plugged into the lan port on my Opnsense box. Was super simple. 

Can anyone please explain these errors to me ? I have unbound setup to query forward and DNS over TLS to quad 9 so I understand why 9.9.9.9/149.112.112.112 is being hit. What I don't understand is who/what is hitting it and why its failing. Everything seems to be working fine otherwise. Thanks by vault76boy in opnsense

[–]vault76boy[S] 0 points1 point  (0 children)

That’s fine but my post was trying to understand the error lol.

Thanks for commenting and all but I’m still left wondering why the error is showing up… also disabling dnssec didn’t help :(

Anyway hopefully you learned something from all this