OPNsense Grundkonfiguration: Unterschied zwischen den Versionen

Aus Xinux Wiki
Zur Navigation springen Zur Suche springen
 
(10 dazwischenliegende Versionen desselben Benutzers werden nicht angezeigt)
Zeile 9: Zeile 9:
 
  SSH PORT 2222  
 
  SSH PORT 2222  
 
=System: Gateway: Configuration=
 
=System: Gateway: Configuration=
  WANGW 192.168.4.254
+
  WANGW 192.168.HS.254
 
  Interface: WAN
 
  Interface: WAN
 
  (x) Upstream Gateway
 
  (x) Upstream Gateway
Zeile 17: Zeile 17:
 
  ( ) Block private networks
 
  ( ) Block private networks
 
  IPv4 Configuration Type:  Static IPv4
 
  IPv4 Configuration Type:  Static IPv4
  192.168.4.2xx/24
+
  192.168.HS.2XX/24
 
  GW: WANGW
 
  GW: WANGW
 +
 
=Interfaces: Assignments=
 
=Interfaces: Assignments=
 
  em2: DMZ
 
  em2: DMZ
Zeile 44: Zeile 45:
 
  Disable reply-to: (x) Disable reply-to on WAN rules
 
  Disable reply-to: (x) Disable reply-to on WAN rules
  
==Firewall: NAT: Outbound==
+
==Firewall: NAT: Source NAT==
 +
Mode: Manual Source NAT rule generation
 
{| class="wikitable"
 
{| class="wikitable"
! Interface !! Source !! Source Port !! Destination !! Destination Port !! NAT Address !! NAT Port !! Static Port !! Description
+
! Interface !! Version !! Protocol !! Source !! Port !! Destination !! Port !! Translate Source IP !! Translate Source Port !! Description
 
|-
 
|-
| WAN || INSIDE net || * || * || * || Interface address || * || NO ||
+
| WAN || IPv4 || * || LAN network || * || * || * || Interface address || * || LAN ins Internet
 
|-
 
|-
| WAN || SERVER net || * || * || * || Interface address || * || NO ||
+
| WAN || IPv4 || * || DMZ network || * || ! 10.88.0.0/16 || * || Interface address || * || DMZ ins Internet, kein NAT zu den anderen DMZs
 
|-
 
|-
| WAN || DMZ net || * || ! 10.88.0.0/16 || * || Interface address || * || NO ||
+
| WAN || IPv4 || * || SERVER network || * || * || * || Interface address || * || SERVER ins Internet
 
|}
 
|}
==Firewall: Rules==
+
 
 +
==Firewall: Aliases==
 
{| class="wikitable"
 
{| class="wikitable"
! Interface !! Protocol !! Source !! Port !! Destination !! Port !! Gateway !! Schedule !! Description
+
! Parameter !! Wert
 
|-
 
|-
| DMZ || IPv4 * || DMZ net || * || * || * || * || * ||  
+
| Enabled || (x)
 
|-
 
|-
| SERVER || IPv4 * || SERVER net || * || * || * || * || * ||  
+
| Name || HOST
 
|-
 
|-
| INSIDE || IPv4 * || INSIDE net || * || * || * || * || * ||  
+
| Type || Host(s)
 +
|-
 +
| Content || 192.168.HS.XX
 +
|-
 +
| Statistics || ( )
 +
|-
 +
| Description || Arbeitsstation des Teilnehmers
 
|}
 
|}
 +
 +
==Firewall: Rules==
 +
Alle Regeln mit '''Action: Pass''' und '''Direction: in''', Interface '''WAN'''.
 
{| class="wikitable"
 
{| class="wikitable"
! Interface !! Protocol !! Source !! Port !! Destination !! Port !! Gateway !! Schedule !! Description
+
! Interface !! Version !! Protocol !! Source !! Port !! Destination !! Port !! Gateway !! Description
 +
|-
 +
| WAN || IPv4 || TCP || HOST || * || WAN address || 2222 || * || SSH auf die Firewall
 +
|-
 +
| WAN || IPv4 || TCP || HOST || * || WAN address || 4444 || * || WebGUI
 
|-
 
|-
| WAN || IPv4 TCP || HOST || * || WAN address || 2222 || * || * ||  
+
| WAN || IPv4 || ICMP || * || * || * || * || * || Ping generell von Aussen
 
|-
 
|-
| WAN || IPv4 TCP || HOST || * || WAN address || 4444 || * || * ||  
+
| LAN || IPv4 || || LAN network || * || * || * || * || LAN to any
 
|-
 
|-
| WAN || IPv4 ICMP || * || * || * || * || * || * ||  
+
| DMZ || IPv4 || *  || DMZ network || * || * || * || * || DMZ to any
 +
|-
 +
| SERVER || IPv4 || *  || SERVER network || * || * || * || * || SERVER to any
 
|}
 
|}
 +
 
=System: Gateways: Configuration=
 
=System: Gateways: Configuration=
 
{| class="wikitable"
 
{| class="wikitable"
Zeile 108: Zeile 127:
 
=Zertifikat einpflegen=
 
=Zertifikat einpflegen=
 
;Zertifikat holen
 
;Zertifikat holen
*wget https://web.samogo.de/certs/it213.xinmen.de.tgz
+
*wget https://web.samogo.de/certs/it2XX.xinmen.de.tgz
 
;Entpacken
 
;Entpacken
 
*tar -xvzf it2*.xinmen.de.tgz
 
*tar -xvzf it2*.xinmen.de.tgz

Aktuelle Version vom 31. August 2026, 13:50 Uhr

System: Settings: Administration

(x)  Enable HTTP Strict Transport Security                  
TCP port 4444
(x) Disable web GUI redirect rule             
(x) Disable DNS Rebinding Checks                      
(x) Enable Secure Shell                
(x) Permit root user login      
(x) Permit password login                              
SSH PORT 2222 

System: Gateway: Configuration

WANGW 192.168.HS.254
Interface: WAN
(x) Upstream Gateway

Interfaces: WAN

( ) Block bogon networks
( ) Block private networks
IPv4 Configuration Type:  Static IPv4
192.168.HS.2XX/24
GW: WANGW

Interfaces: Assignments

em2: DMZ
em3: SERVER

Interfaces: SERVER

Enable (x)
IPv4 Configuration Type: Static IPv4
IPv4 address: 10.0.10.1/24

Interfaces: DMZ

Enable (x)
IPv4 Configuration Type: Static IPv4
IPv4 address: 10.88.2xx.1/24

Services: Dnsmasq DNS & DHCP

DHCP Range: 172.17.2xx.100 bis 172.17.2xx.200

Interfaces: LAN

Enable (x)
IPv4 Configuration Type: Static IPv4
IPv4 address: 172.17.2xx.1/24

Hinweis

Am Client DHCP Adresse neubeziehen

Firewall

Firewall: Settings: Advanced

Disable reply-to: (x) Disable reply-to on WAN rules

Firewall: NAT: Source NAT

Mode: Manual Source NAT rule generation
Interface Version Protocol Source Port Destination Port Translate Source IP Translate Source Port Description
WAN IPv4 * LAN network * * * Interface address * LAN ins Internet
WAN IPv4 * DMZ network * ! 10.88.0.0/16 * Interface address * DMZ ins Internet, kein NAT zu den anderen DMZs
WAN IPv4 * SERVER network * * * Interface address * SERVER ins Internet

Firewall: Aliases

Parameter Wert
Enabled (x)
Name HOST
Type Host(s)
Content 192.168.HS.XX
Statistics ( )
Description Arbeitsstation des Teilnehmers

Firewall: Rules

Alle Regeln mit Action: Pass und Direction: in, Interface WAN.

Interface Version Protocol Source Port Destination Port Gateway Description
WAN IPv4 TCP HOST * WAN address 2222 * SSH auf die Firewall
WAN IPv4 TCP HOST * WAN address 4444 * WebGUI
WAN IPv4 ICMP * * * * * Ping generell von Aussen
LAN IPv4 * LAN network * * * * LAN to any
DMZ IPv4 * DMZ network * * * * DMZ to any
SERVER IPv4 * SERVER network * * * * SERVER to any

System: Gateways: Configuration

Parameter Wert
Name DNSGW
Interface WAN
Address Family IPv4
Priority 255
IP Address 192.168.HS.88
Upstream Gateway ( )

System: Routes: Configuration

Parameter Wert
Disabled No
Network Address 10.88.0.0/16
Gateway DNSGW - 192.168.4.88
Description UNSERE DMZs

Systemnamen setzen

System: Settings: General

  • Hostname: opnsense
  • Domain: it213.xinmen.de

Zertifikat einpflegen

Zertifikat holen
Entpacken
  • tar -xvzf it2*.xinmen.de.tgz
Zertifikat

fullchain.pem

Private Schlüssel

privkey.pem

Hostname IP Test
  • host opnsense.it2XX.xinmen.de

opnsense.it2XX.xinmen.de has address 192.168.HS.2XX

System: Trust: Certificates

  • +
    • Import existing Certificate
    • Description: star.it2XX.xinmen.de
Certificate data

Hier muss der Inhalt von fullchain.pem rein.

Private key data

Hier muss der Inhalt von privakey.pem rein.

Dann sichern

System: Settings: Administration

  • SSL Certificate: star.it2XX.xinmen.de

Dann Zertifikat testen