wombat.ch

your Partner for Network Design and CMS

Firewall

Free IPA | 


 steps

On IPA server

IPA uses the following ports to communicate with its services:
TCP ports: 80, 88, 443, 389, 636, 88, 464, 53, 135, 138, 139, 445, 1024-1300
 UDP ports: 88, 464, 53, 123, 138, 139, 389, 445
       
-
-
- - - -
Quellen/Source:
- needed Ports for FreeIPA  
-
- Add a comment

 apu2c4 / 4 GB DDR3-1333 DRAM / WLAN wle200nx / 240GB mSATA Kingston

 List of the Hardware --> Firewall | Hardware


myNet 2017 08where one the design 

FW/opnSense = apu2c4
WAN              = Eth1
eth0              = Eth2
eth1              = eth3 (but later)


 List of IP Range & VLAN --> Firewall | IP & VLAN


 Alle Teile zusammenschrauben und löten.
fw03 cut

 


Link:  PC Engine howto - OS Installation - opnsense
Download opnSense
Etcher
 
 Steps:
  • download the latest serial amd64 installer for OPNSense (e.g. OPNsense-17.7-OpenSSL-serial-amd64.img.bz2
  • Write image to an USB stick using Etcher (Etcher is a graphical writing tool for Mac OS, Linux and Windows)
  • boot apu2 from USB with installed mSATA/SD
  • follow the instructions of the installer

Important: the SD slot on the apu2 boards is directly connected to the CPU and needs the module SDHCI to work.
Do not use an SD to boot FreeBSD based OS like pfSense and OPNSense on apu2 boards. Only very recent kernel versions fully support booting via SDHCI.
Try an USB-SD adapter in case of related troubles. If it works with the USB-SD adapter, but not in the SD slot, then the SDHCI module is missing ...

Installation Steps

The installation process involves a few simple steps.

Note
To invoke the installer login with user installer and password opnsense

Tip
The installer can also be started from the network using ssh, default ip address is 192.168.1.1

  1. Configure console - The default configuration should be fine for most occasions.
  2. Select task - The Quick/Easy Install option should be fine for most occasions. For installations on embedded systems or systems with minimal diskspace choose Custom Installation and do not create a swap slice. Continue with default settings.
  3. Are you SURE? - When proceeding OPNsense will be installed on the first hard disk in the system.
  4. Reboot - The system is now installed and needs to be rebooted to continue with configuration.
opnSense Installation
Problems:
  • Not Booting from the USB Stick
 

 my config:

 libre SSL GUI |System⇒Settings⇒General  Install OpenSSL & LibreSSL system, Firmware, Settings
System  update GUI | via System⇒Firmware    
clamAV Plugin install clamAV  

 


Source/Quellen/Infos:
- OPNSense hinter FB 6490 Cable 
-
-
-


 

 




-


 

 


opnSense Unifi Controller | Unifi how to Install...
opnsense WIFI setup
-


 

 




-


 

 




-


 

 

 

 

 

 

 

 

Add a comment

Add WLAN Interface (IP Adressen entsprechend anpassen)
OpnSense Version

OPNsense 17.7.12-amd64
FreeBSD 11.0-RELEASE-p17
LibreSSL 2.6.4

  Interface - Wireless - Device +add
[Description]
 
   Interface - Assignments select network Port and Press +
select the Interface Name crated
 
    General configuration
Enable Interface
Descritpion [WLAN]
IPv4 Configuration Type [static IPv4]
 
    Static IPv4 configuration
IPv4 address [10.20.20.1]/24
 
   

Common wireless configuration -
Settings apply to all wireless networks on ath0

Standard [802.11ng]
Regulatory settings
County [select]
Location [Indoor]

 
    Network-specific wireless configuration
Mode [Access Point]
SSID [name des Signal]
WPA [x] Enable WPA
     WPA Pre-Shared Key [passowrt]
WPA Mode [WPA2]
 
save & Apply Changes      
System - Gateways - All +add gateway
Interface [WLAN]

Name [GW_WLAN]
 
Services - DHCP - Server
(Select the WLAN Tab)!!!
Enable [x]
Range add from to
DNS Server [add IP]
 

 

 

---

Add a comment
Save your OPNSense Config

System - Configuration - Backups
Dann Download Configuration


system wieder lauffähig machen.
letzes Backup
via System - Configuration - Backups [Restore]
file auswählen und die Firewall rebootet Add a comment

RSS Feed


Warning: file_get_contents(https://www.bsi.bund.de/SiteGlobals/Functions/RSSFeed/RSSNewsfeed/RSSNewsfeed_WID.xml): failed to open stream: HTTP request failed! HTTP/1.1 404 Not Found in /var/www/clients/client2/web2/web/j/modules/mod_jw_srfr/helper.php on line 273

Warning: file_get_contents(https://www.bsi.bund.de/SiteGlobals/Functions/RSSFeed/RSSNewsfessBSIFB/RSSNewsfeed_BuergerCERT.xml): failed to open stream: HTTP request failed! HTTP/1.1 404 Not Found in /var/www/clients/client2/web2/web/j/modules/mod_jw_srfr/helper.php on line 273

Warning: file_get_contents(): php_network_getaddresses: getaddrinfo failed: Name or service not known in /var/www/clients/client2/web2/web/j/modules/mod_jw_srfr/helper.php on line 273

Warning: file_get_contents(http://feeds.joomla.org/JoomlaAnnouncements): failed to open stream: php_network_getaddresses: getaddrinfo failed: Name or service not known in /var/www/clients/client2/web2/web/j/modules/mod_jw_srfr/helper.php on line 273

Warning: file_get_contents(): php_network_getaddresses: getaddrinfo failed: Name or service not known in /var/www/clients/client2/web2/web/j/modules/mod_jw_srfr/helper.php on line 273

Warning: file_get_contents(http://feeds.joomla.org/JoomlaSecurityNews): failed to open stream: php_network_getaddresses: getaddrinfo failed: Name or service not known in /var/www/clients/client2/web2/web/j/modules/mod_jw_srfr/helper.php on line 273

Warning: Invalid argument supplied for foreach() in /var/www/clients/client2/web2/web/j/modules/mod_jw_srfr/helper.php on line 39

Warning: Invalid argument supplied for foreach() in /var/www/clients/client2/web2/web/j/modules/mod_jw_srfr/helper.php on line 39

neusten Links


Warning: count(): Parameter must be an array or an object that implements Countable in /var/www/clients/client2/web2/web/j/modules/mod_quicklistweblinks/helper.php on line 78
many More Links »

part of ...

Linux Counter

Disqus

 

Learning Network

Seti@home & Boinc

myBonic

statistik

 


Who is Online

We have 569 guests and no members online

We have 597 guests, 2 bots and no members online


2 bots:
2 x BOT for JCE