Welcome, Guest. Please login or register.

Show Posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.


Messages - tuaris

Pages: [1]
1
VPN / Firewall Rules for PPTP VPN clients
« on: October 19, 2019, 10:06:19 AM »
I already have the default rule in place to allow PPTP clients to access hosts on the remote network (LAN).  No issue when a PPTP VPN client makes an outbound connection to a host on the LAN.



The hosts on the LAN are unable to make outbound connections to (or ping) any of the VPN clients.  Additionally, VPN clients are unable to communicate with each other.
What additional firewall rules do I need to add?

This is what my LAN rules currently are:


2
Firewall/NAT / Re: NAT Port Fowarding Ranges Not Workig Correctly
« on: September 09, 2019, 03:45:54 AM »
I manually re-flashed one of the devices and it appears that r176 solved the issue

3
Firewall/NAT / Re: NAT Port Fowarding Ranges Not Workig Correctly
« on: September 09, 2019, 03:12:38 AM »
Trying to upgrade to r176 and I'm getting "No image file has been uploaded.".  Tried it on two 156 i386 systems and one 167 amd64 system, all three have the same problem.

4
Firewall/NAT / Re: NAT Port Fowarding Ranges Not Workig Correctly
« on: August 01, 2019, 08:11:18 AM »
I just tested in on a different device that is on 2.11.1b167 and it's the same behavior.

5
Firewall/NAT / NAT Port Fowarding Ranges Not Workig Correctly
« on: August 01, 2019, 08:05:02 AM »
Looks like (at least on build 156) when setting up a Firewall: NAT forwarding rule using a range of ports, only the first port is used as the destination. 

For example I want to create a new rule to forward ports 5269 to 5271 to the internal client 192.168.0.2

- In the "External port range" field I put in 5269 in the first box and 5271 in the second.
- In the "NAT IP" field I put 192.168.0.2
- In the "Local port" field I enter 5269.
- I click save and the corresponding Firewall rules to allow the traffic on this port range are created correctly.

The expected result is that the end port will be calculated automatically so an traffic going to port 5270 will be redirected to 192.168.0.2:5270
The actual result is traffic destined for port 5270 is being redirected to 192.168.0.2:5269

This can be demonstrated with netcat

On: 192.168.0.2 start up two netcat processes
Code: [Select]
```
# nc -l 5270
```
```
# nc -l 5269
```

On an external client make the connection (X.X.X.X is the public IP of the t1n1wall):
Code: [Select]
```
nc X.X.X.X 5270
```

In the t1n1wall log, note the destination port
Code: [Select]
```
Aug  1 02:57:32 <local0.info> stargate pfmon[86]: 02:57:31.881624 em0 @50 pass X.X.X.X,13376 -> 192.168.0.2,5269 PR tcp len 20 40 -S in match
```

On the external client, send some data
Code: [Select]
```
nc X.X.X.X 5270
Test
```

The data is received on the netcat process listening on port 5269:
Code: [Select]
```
# nc -l 5270
```
```
# nc -l 5269
Test
```

6
This is with the 2.11.1b165 image for AMD64.  I've tried it with different SD cards, both were new.  It looks like this problem: https://sourceforge.net/p/t1n1wall/bugs/13/

Code: [Select]
cpu_reset: Stopping other CPUs
PCEngines apu2
coreboot build 20160307
-2064 MB DRAM

SeaBIOS (version ?-20160307_153453-michael-desktop64)
Found mainboard PC Engines PCEngines apu2
multiboot: eax=0, ebx=0
boot order:
1: /[email protected]/[email protected]/usb-*@1
2: /[email protected]/[email protected]/usb-*@2
3: /[email protected]/[email protected]/usb-*@3
4: /[email protected]/[email protected]/usb-*@4
5: /[email protected]/*@14,7
6: /[email protected]/*@11/[email protected]/[email protected]
7: /[email protected]/*@11/[email protected]/[email protected]
8: /[email protected]/pxe.rom
9: pxen0
10: scon1
11:
Found 19 PCI devices (max PCI bus is 02)
Copying SMBIOS entry point from 0x77fb7000 to 0x000f3110
Copying ACPI RSDP from 0x77fb8000 to 0x000f30e0
Copying MPTABLE from 0x77fdc000/77fdc010 to 0x000f2f30
Copying PIR from 0x77fdd000 to 0x000f2f00
Using pmtimer, ioport 0x818
Scan for VGA option rom
Running option rom at c000:0003

Google, Inc.
Serial Graphics Adapter 08/22/15
SGABIOS $Id: sgabios.S 8 2010-04-22 00:03:40Z nlaredo $ ([email protected]) Sat Aug 22 09:25:30 UTC 2015
Term: 80x24
IO4 0
Turning on vga text mode console
SeaBIOS (version ?-20160307_153453-michael-desktop64)
XHCI init on dev 00:10.0: regs @ 0xfeb22000, 4 ports, 32 slots, 32 byte contexts
XHCI    extcap 0x1 @ feb22500
XHCI    protocol USB  3.00, 2 ports (offset 1), def 0
XHCI    protocol USB  2.00, 2 ports (offset 3), def 10
XHCI    extcap 0xa @ feb22540
Found 2 serial ports
ATA controller 1 at 3010/3020/0 (irq 0 dev 88)
EHCI init on dev 00:13.0 (regs=0xfeb25420)
ATA controller 2 at 3018/3024/0 (irq 0 dev 88)
Searching bootorder for: /[email protected]/*@14,7
Searching bootorder for: /[email protected]/memtest
Searching bootorder for: /[email protected]/setup
Found sdcard at 0xfeb25500: SD card SL08G 7580MiB
XHCI no devices found
Initialized USB HUB (0 ports used)
All threads complete.
Scan for option roms
PCengines Press F10 key now for boot menu:
Select boot device:

1. SD card SL08G 7580MiB
2. Payload [memtest]
3. Payload [setup]

Searching bootorder for: HALT
drive 0x000f2e90: PCHS=0/0/0 translation=lba LCHS=966/255/63 s=15523840
Space available for UMB: c1000-ef000, f0000-f2e90
Returned 262144 bytes of ZoneHigh
e820 map has 6 items:
  0: 0000000000000000 - 000000000009f800 = 1 RAM
  1: 000000000009f800 - 00000000000a0000 = 2 RESERVED
  2: 00000000000f0000 - 0000000000100000 = 2 RESERVED
  3: 0000000000100000 - 0000000077fae000 = 1 RAM
  4: 0000000077fae000 - 0000000078000000 = 2 RESERVED
  5: 00000000f8000000 - 00000000fc000000 = 2 RESERVED
enter handle_19:
  NULL
Booting from Hard Disk...
Booting from 0000:7c00
/kernel text=0xb779a8 data=0xe6090+0x310568 -
/mfsroot size=0x1c12000
Copyright (c) 1992-2018 The FreeBSD Project.
Copyright (c) 1979, 1980, 1983, 1986, 1988, 1989, 1991, 1992, 1993, 1994
        The Regents of the University of California. All rights reserved.
FreeBSD is a registered trademark of The FreeBSD Foundation.
FreeBSD 11.2-RELEASE-p11 #349641: Tue Jul 16 22:56:32 IST 2019

-snip-

Code: [Select]
md0: Preloaded image </mfsroot> 29433856 bytes at 0xffffffff8136dfa0
usbus0: 480Mbps High Speed USB v2.0
ugen0.1: <AMD EHCI root HUB> at usbus0
uhub0: <AMD EHCI root HUB, class 9/0, rev 2.00/1.00, addr 1> on usbus0
g_access(944): provider md0a has error 6 set
g_access(944): provider md0a has error 6 set
g_access(944): provider md0a has error 6 set
uhub0: 2 ports with 2 removable, self powered
ugen0.2: <vendor 0x0438 product 0x7900> at usbus0
uhub1 on uhub0
uhub1: <vendor 0x0438 product 0x7900, class 9/0, rev 2.00/0.18, addr 2> on usbus0
uhub1: 4 ports with 4 removable, self powered
SMP: AP CPU #1 Launched!
SMP: AP CPU #3 Launched!
SMP: AP CPU #2 Launched!
Timecounter "TSC" frequency 998149877 Hz quality 1000
Trying to mount root from ufs:/dev/md0 []...
random: unblocking device.
kern.coredump: 1 -> 0
net.enc.in.ipsec_filter_mask: 1 -> 2
Configuration device not found; trying again in 5 seconds (2 attempt(s) left)...
Configuration device not found; trying again in 5 seconds (1 attempt(s) left)...


****************************Waiting (max 60 seconds) for system process `vnlru' to stop... done
Waiting (max 60 seconds) for system process `bufdaemon' to stop... done
Wai
Syncing disksting (max 60 se, vnodes remainconds) for system process `syncer' toing... 0  stop... 0 done
All buffers synced.
Uptime: 34s
uhub1: detached

The operating system has halted.
Please press any key to reboot.

7
The problem appears to be with the firewall rules.  I tried some rules from http://blog.up-link.ro/freebsd-how-to-install-and-configure-a-pptp-server-with-mpd5-on-freebsd-8-2/ and they worked for me.   Patch is in the bug report.

https://sourceforge.net/p/t1n1wall/bugs/37/

8
General Questions / Re: Setting up for Local Development
« on: June 20, 2019, 04:38:37 AM »
I was able to build a functional image using `FreeBSD 11.2-RELEASE-p10 (199506)`.  I did run into some trouble while doing so.  Specifically with WPA hostapd.  Looks like there have been some code changes to it since the release of 11.2.  The patch below resolved those issues for me.

https://sourceforge.net/p/t1n1wall/bugs/36/

Additionally I saw some error messages generated by one of the perl scripts:

Code: [Select]
Populating MiniBSD tree: /usr/t1n1wall/build11/t1n1fs/
Copy //libexec/ld-elf.so.1 -> /usr/t1n1wall/build11/t1n1fs//libexec/ld-elf.so.1 (0/0/0555)
Copy //usr/sbin/wpa_supplicant -> /usr/t1n1wall/build11/t1n1fs//usr/sbin/wpa_supplicant (0/0/0555)
Populating MiniBSD tree: /usr/t1n1wall/build11/t1n1fs/
ERROR while copying file //bin/t1n1box
Link /usr/t1n1wall/build11/t1n1fs//bin/t1n1box -> /usr/t1n1wall/build11/t1n1fs//bin/[
Link /usr/t1n1wall/build11/t1n1fs//bin/t1n1box -> /usr/t1n1wall/build11/t1n1fs//bin/test
ERROR while copying file //bin/t1n1box
Link /usr/t1n1wall/build11/t1n1fs//bin/t1n1box -> /usr/t1n1wall/build11/t1n1fs//bin/cat
ERROR while copying file //bin/t1n1box
Link /usr/t1n1wall/build11/t1n1fs//bin/t1n1box -> /usr/t1n1wall/build11/t1n1fs//bin/chmod
ERROR while copying file //bin/t1n1box
Link /usr/t1n1wall/build11/t1n1fs//bin/t1n1box -> /usr/t1n1wall/build11/t1n1fs//bin/cp
ERROR while copying file //bin/t1n1box
Link /usr/t1n1wall/build11/t1n1fs//bin/t1n1box -> /usr/t1n1wall/build11/t1n1fs//bin/date
ERROR while copying file //bin/t1n1box
Link /usr/t1n1wall/build11/t1n1fs//bin/t1n1box -> /usr/t1n1wall/build11/t1n1fs//bin/dd
ERROR while copying file //bin/t1n1box
Link /usr/t1n1wall/build11/t1n1fs//bin/t1n1box -> /usr/t1n1wall/build11/t1n1fs//bin/df
ERROR while copying file //bin/t1n1box
Link /usr/t1n1wall/build11/t1n1fs//bin/t1n1box -> /usr/t1n1wall/build11/t1n1fs//bin/echo
ERROR while copying file //bin/t1n1box
Link /usr/t1n1wall/build11/t1n1fs//bin/t1n1box -> /usr/t1n1wall/build11/t1n1fs//bin/expr
ERROR while copying file //bin/t1n1box
Link /usr/t1n1wall/build11/t1n1fs//bin/t1n1box -> /usr/t1n1wall/build11/t1n1fs//bin/hostname
ERROR while copying file //bin/t1n1box
Link /usr/t1n1wall/build11/t1n1fs//bin/t1n1box -> /usr/t1n1wall/build11/t1n1fs//bin/kill
ERROR while copying file //bin/t1n1box
Link /usr/t1n1wall/build11/t1n1fs//bin/t1n1box -> /usr/t1n1wall/build11/t1n1fs//bin/ls
ERROR while copying file //bin/t1n1box
Link /usr/t1n1wall/build11/t1n1fs//bin/t1n1box -> /usr/t1n1wall/build11/t1n1fs//bin/ln
ERROR while copying file //bin/t1n1box
Link /usr/t1n1wall/build11/t1n1fs//bin/t1n1box -> /usr/t1n1wall/build11/t1n1fs//bin/mkdir
ERROR while copying file //bin/t1n1box
Link /usr/t1n1wall/build11/t1n1fs//bin/t1n1box -> /usr/t1n1wall/build11/t1n1fs//bin/mv
ERROR while copying file //bin/t1n1box
Link /usr/t1n1wall/build11/t1n1fs//bin/t1n1box -> /usr/t1n1wall/build11/t1n1fs//bin/ps
ERROR while copying file //bin/t1n1box
Link /usr/t1n1wall/build11/t1n1fs//bin/t1n1box -> /usr/t1n1wall/build11/t1n1fs//bin/rm
ERROR while copying file //bin/t1n1box
Link /usr/t1n1wall/build11/t1n1fs//bin/t1n1box -> /usr/t1n1wall/build11/t1n1fs//bin/sh
ERROR while copying file //bin/t1n1box
Link /usr/t1n1wall/build11/t1n1fs//bin/t1n1box -> /usr/t1n1wall/build11/t1n1fs//bin/sleep
ERROR while copying file //bin/t1n1box
Link /usr/t1n1wall/build11/t1n1fs//bin/t1n1box -> /usr/t1n1wall/build11/t1n1fs//bin/stty
ERROR while copying file //bin/t1n1box
Link /usr/t1n1wall/build11/t1n1fs//bin/t1n1box -> /usr/t1n1wall/build11/t1n1fs//bin/sync
ERROR while copying file //bin/t1n1box
Link /usr/t1n1wall/build11/t1n1fs//bin/t1n1box -> /usr/t1n1wall/build11/t1n1fs//sbin/dhcpcd
ERROR while copying file //bin/t1n1box
Link /usr/t1n1wall/build11/t1n1fs//bin/t1n1box -> /usr/t1n1wall/build11/t1n1fs//sbin/camcontrol
ERROR while copying file //bin/t1n1box
Link /usr/t1n1wall/build11/t1n1fs//bin/t1n1box -> /usr/t1n1wall/build11/t1n1fs//sbin/kldstat
ERROR while copying file //bin/t1n1box
Link /usr/t1n1wall/build11/t1n1fs//bin/t1n1box -> /usr/t1n1wall/build11/t1n1fs//sbin/ifconfig
ERROR while copying file //bin/t1n1box
Link /usr/t1n1wall/build11/t1n1fs//bin/t1n1box -> /usr/t1n1wall/build11/t1n1fs//sbin/adjkerntz
ERROR while copying file //bin/t1n1box
Link /usr/t1n1wall/build11/t1n1fs//bin/t1n1box -> /usr/t1n1wall/build11/t1n1fs//sbin/dmesg
ERROR while copying file //bin/t1n1box
Link /usr/t1n1wall/build11/t1n1fs//bin/t1n1box -> /usr/t1n1wall/build11/t1n1fs//sbin/fastboot
Link /usr/t1n1wall/build11/t1n1fs//bin/t1n1box -> /usr/t1n1wall/build11/t1n1fs//sbin/fasthalt
Link /usr/t1n1wall/build11/t1n1fs//bin/t1n1box -> /usr/t1n1wall/build11/t1n1fs//sbin/halt
ERROR while copying file //bin/t1n1box
Link /usr/t1n1wall/build11/t1n1fs//bin/t1n1box -> /usr/t1n1wall/build11/t1n1fs//sbin/init
ERROR while copying file //bin/t1n1box
Link /usr/t1n1wall/build11/t1n1fs//bin/t1n1box -> /usr/t1n1wall/build11/t1n1fs//sbin/ipfw
ERROR while copying file //bin/t1n1box
Link /usr/t1n1wall/build11/t1n1fs//bin/t1n1box -> /usr/t1n1wall/build11/t1n1fs//sbin/kldload
ERROR while copying file //bin/t1n1box
Link /usr/t1n1wall/build11/t1n1fs//bin/t1n1box -> /usr/t1n1wall/build11/t1n1fs//sbin/kldunload
ERROR while copying file //bin/t1n1box
Link /usr/t1n1wall/build11/t1n1fs//bin/t1n1box -> /usr/t1n1wall/build11/t1n1fs//sbin/ldconfig
ERROR while copying file //bin/t1n1box
Link /usr/t1n1wall/build11/t1n1fs//bin/t1n1box -> /usr/t1n1wall/build11/t1n1fs//sbin/mdconfig
ERROR while copying file //bin/t1n1box
Link /usr/t1n1wall/build11/t1n1fs//bin/t1n1box -> /usr/t1n1wall/build11/t1n1fs//sbin/mdmfs
ERROR while copying file //bin/t1n1box
Link /usr/t1n1wall/build11/t1n1fs//bin/t1n1box -> /usr/t1n1wall/build11/t1n1fs//sbin/mount
ERROR while copying file //bin/t1n1box
Link /usr/t1n1wall/build11/t1n1fs//bin/t1n1box -> /usr/t1n1wall/build11/t1n1fs//sbin/mount_cd9660
ERROR while copying file //bin/t1n1box
Link /usr/t1n1wall/build11/t1n1fs//bin/t1n1box -> /usr/t1n1wall/build11/t1n1fs//sbin/mount_msdosfs
ERROR while copying file //bin/t1n1box
Link /usr/t1n1wall/build11/t1n1fs//bin/t1n1box -> /usr/t1n1wall/build11/t1n1fs//sbin/newfs
ERROR while copying file //bin/t1n1box
Link /usr/t1n1wall/build11/t1n1fs//bin/t1n1box -> /usr/t1n1wall/build11/t1n1fs//sbin/nologin
ERROR while copying file //bin/t1n1box
Link /usr/t1n1wall/build11/t1n1fs//bin/t1n1box -> /usr/t1n1wall/build11/t1n1fs//sbin/ping
ERROR while copying file //bin/t1n1box
Link /usr/t1n1wall/build11/t1n1fs//bin/t1n1box -> /usr/t1n1wall/build11/t1n1fs//sbin/ping6
ERROR while copying file //bin/t1n1box
Link /usr/t1n1wall/build11/t1n1fs//bin/t1n1box -> /usr/t1n1wall/build11/t1n1fs//sbin/reboot
ERROR while copying file //bin/t1n1box
Link /usr/t1n1wall/build11/t1n1fs//bin/t1n1box -> /usr/t1n1wall/build11/t1n1fs//sbin/route
ERROR while copying file //bin/t1n1box
Link /usr/t1n1wall/build11/t1n1fs//bin/t1n1box -> /usr/t1n1wall/build11/t1n1fs//sbin/shutdown
ERROR while copying file //bin/t1n1box
Link /usr/t1n1wall/build11/t1n1fs//bin/t1n1box -> /usr/t1n1wall/build11/t1n1fs//sbin/sysctl
ERROR while copying file //bin/t1n1box
Link /usr/t1n1wall/build11/t1n1fs//bin/t1n1box -> /usr/t1n1wall/build11/t1n1fs//sbin/umount
ERROR while copying file //bin/t1n1box
Link /usr/t1n1wall/build11/t1n1fs//bin/t1n1box -> /usr/t1n1wall/build11/t1n1fs//usr/sbin/hostapd
ERROR while copying file //bin/t1n1box
Link /usr/t1n1wall/build11/t1n1fs//bin/t1n1box -> /usr/t1n1wall/build11/t1n1fs//usr/bin/fetch
ERROR while copying file //bin/t1n1box
Link /usr/t1n1wall/build11/t1n1fs//bin/t1n1box -> /usr/t1n1wall/build11/t1n1fs//usr/bin/su
ERROR while copying file //bin/t1n1box
Link /usr/t1n1wall/build11/t1n1fs//bin/t1n1box -> /usr/t1n1wall/build11/t1n1fs//usr/bin/gzip
Link /usr/t1n1wall/build11/t1n1fs//bin/t1n1box -> /usr/t1n1wall/build11/t1n1fs//usr/bin/gunzip
ERROR while copying file //bin/t1n1box
Link /usr/t1n1wall/build11/t1n1fs//bin/t1n1box -> /usr/t1n1wall/build11/t1n1fs//usr/bin/uptime
Link /usr/t1n1wall/build11/t1n1fs//bin/t1n1box -> /usr/t1n1wall/build11/t1n1fs//usr/bin/w
ERROR while copying file //bin/t1n1box
Link /usr/t1n1wall/build11/t1n1fs//bin/t1n1box -> /usr/t1n1wall/build11/t1n1fs//usr/bin/killall
ERROR while copying file //bin/t1n1box
Link /usr/t1n1wall/build11/t1n1fs//bin/t1n1box -> /usr/t1n1wall/build11/t1n1fs//usr/bin/logger
ERROR while copying file //bin/t1n1box
Link /usr/t1n1wall/build11/t1n1fs//bin/t1n1box -> /usr/t1n1wall/build11/t1n1fs//usr/bin/netstat
ERROR while copying file //bin/t1n1box
Link /usr/t1n1wall/build11/t1n1fs//bin/t1n1box -> /usr/t1n1wall/build11/t1n1fs//usr/bin/nohup
ERROR while copying file //bin/t1n1box
Link /usr/t1n1wall/build11/t1n1fs//bin/t1n1box -> /usr/t1n1wall/build11/t1n1fs//usr/bin/tail
ERROR while copying file //bin/t1n1box
Link /usr/t1n1wall/build11/t1n1fs//bin/t1n1box -> /usr/t1n1wall/build11/t1n1fs//usr/bin/tar
ERROR while copying file //bin/t1n1box
Link /usr/t1n1wall/build11/t1n1fs//bin/t1n1box -> /usr/t1n1wall/build11/t1n1fs//usr/bin/top
ERROR while copying file //bin/t1n1box
Link /usr/t1n1wall/build11/t1n1fs//bin/t1n1box -> /usr/t1n1wall/build11/t1n1fs//usr/bin/touch
ERROR while copying file //bin/t1n1box
Link /usr/t1n1wall/build11/t1n1fs//bin/t1n1box -> /usr/t1n1wall/build11/t1n1fs//usr/sbin/ntpd
ERROR while copying file //bin/t1n1box
Link /usr/t1n1wall/build11/t1n1fs//bin/t1n1box -> /usr/t1n1wall/build11/t1n1fs//usr/sbin/ntpctl
ERROR while copying file //bin/t1n1box
Link /usr/t1n1wall/build11/t1n1fs//bin/t1n1box -> /usr/t1n1wall/build11/t1n1fs//usr/sbin/ancontrol
ERROR while copying file //bin/t1n1box
Link /usr/t1n1wall/build11/t1n1fs//bin/t1n1box -> /usr/t1n1wall/build11/t1n1fs//usr/sbin/arp
ERROR while copying file //bin/t1n1box
Link /usr/t1n1wall/build11/t1n1fs//bin/t1n1box -> /usr/t1n1wall/build11/t1n1fs//usr/sbin/chown
ERROR while copying file //bin/t1n1box
Link /usr/t1n1wall/build11/t1n1fs//bin/t1n1box -> /usr/t1n1wall/build11/t1n1fs//usr/sbin/chroot
ERROR while copying file //bin/t1n1box
Link /usr/t1n1wall/build11/t1n1fs//bin/t1n1box -> /usr/t1n1wall/build11/t1n1fs//usr/sbin/diskinfo
ERROR while copying file //bin/t1n1box
Link /usr/t1n1wall/build11/t1n1fs//bin/t1n1box -> /usr/t1n1wall/build11/t1n1fs//usr/sbin/ndp
ERROR while copying file //bin/t1n1box
Link /usr/t1n1wall/build11/t1n1fs//bin/t1n1box -> /usr/t1n1wall/build11/t1n1fs//usr/sbin/pwd_mkdb
ERROR while copying file //bin/t1n1box
Link /usr/t1n1wall/build11/t1n1fs//bin/t1n1box -> /usr/t1n1wall/build11/t1n1fs//usr/sbin/traceroute
ERROR while copying file //bin/t1n1box
Link /usr/t1n1wall/build11/t1n1fs//bin/t1n1box -> /usr/t1n1wall/build11/t1n1fs//usr/sbin/traceroute6
ERROR while copying file //bin/t1n1box
Link /usr/t1n1wall/build11/t1n1fs//bin/t1n1box -> /usr/t1n1wall/build11/t1n1fs//usr/local/sbin/dnsmasq
ERROR while copying file //bin/t1n1box
Link /usr/t1n1wall/build11/t1n1fs//bin/t1n1box -> /usr/t1n1wall/build11/t1n1fs//usr/local/bin/dudders
ERROR while copying file //bin/t1n1box
Link /usr/t1n1wall/build11/t1n1fs//bin/t1n1box -> /usr/t1n1wall/build11/t1n1fs//usr/local/bin/ez-ipupdate
ERROR while copying file //bin/t1n1box
Link /usr/t1n1wall/build11/t1n1fs//bin/t1n1box -> /usr/t1n1wall/build11/t1n1fs//usr/local/sbin/mpd5
ERROR while copying file //bin/t1n1box
Link /usr/t1n1wall/build11/t1n1fs//bin/t1n1box -> /usr/t1n1wall/build11/t1n1fs//sbin/modem-stats
ERROR while copying file //bin/t1n1box
Link /usr/t1n1wall/build11/t1n1fs//bin/t1n1box -> /usr/t1n1wall/build11/t1n1fs//sbin/pfctl
ERROR while copying file //bin/t1n1box
Link /usr/t1n1wall/build11/t1n1fs//bin/t1n1box -> /usr/t1n1wall/build11/t1n1fs//sbin/pflogd
Warning: one or more libraries were not found!
Populating MiniBSD tree: /usr/t1n1wall/build11/t1n1fs
Copy //lib/libc.so.7 -> /usr/t1n1wall/build11/t1n1fs/lib/libc.so.7 (0/0/0444)
Copy //lib/libcrypt.so.5 -> /usr/t1n1wall/build11/t1n1fs/lib/libcrypt.so.5 (0/0/0444)
Copy //lib/libcrypto.so.8 -> /usr/t1n1wall/build11/t1n1fs/lib/libcrypto.so.8 (0/0/0444)
Copy //lib/libelf.so.2 -> /usr/t1n1wall/build11/t1n1fs/lib/libelf.so.2 (0/0/0444)
Copy //lib/libipsec.so.4 -> /usr/t1n1wall/build11/t1n1fs/lib/libipsec.so.4 (0/0/0444)
Copy //lib/libkvm.so.7 -> /usr/t1n1wall/build11/t1n1fs/lib/libkvm.so.7 (0/0/0444)
Copy //lib/libm.so.5 -> /usr/t1n1wall/build11/t1n1fs/lib/libm.so.5 (0/0/0444)
Copy //lib/libncurses.so.8 -> /usr/t1n1wall/build11/t1n1fs/lib/libncurses.so.8 (0/0/0444)
Copy //lib/libncursesw.so.8 -> /usr/t1n1wall/build11/t1n1fs/lib/libncursesw.so.8 (0/0/0444)
Copy //lib/libpcap.so.8 -> /usr/t1n1wall/build11/t1n1fs/lib/libpcap.so.8 (0/0/0444)
Copy //lib/libthr.so.3 -> /usr/t1n1wall/build11/t1n1fs/lib/libthr.so.3 (0/0/0444)
Copy //lib/libutil.so.9 -> /usr/t1n1wall/build11/t1n1fs/lib/libutil.so.9 (0/0/0444)
Copy //lib/libz.so.6 -> /usr/t1n1wall/build11/t1n1fs/lib/libz.so.6 (0/0/0444)
Copy //usr/lib/libpam.so.6 -> /usr/t1n1wall/build11/t1n1fs/usr/lib/libpam.so.6 (0/0/0444)
Copy //usr/lib/libssl.so.8 -> /usr/t1n1wall/build11/t1n1fs/usr/lib/libssl.so.8 (0/0/0444)
Copy //usr/local/lib/libreadline.so.7 -> /usr/t1n1wall/build11/t1n1fs/usr/local/lib/libreadline.so.7 (0/0/0644)
Finished Stage 4

I think those errors get generted by this line (in `4crunch.sh`):

Code: [Select]
perl $MW_BUILDPATH/freebsd11/build/minibsd/mkmini.pl $MW_BUILDPATH/freebsd11/build/minibsd/t1n1box.files  / $MW_BUILDPATH/t1n1fs/
Also this line is a little weird too.

Code: [Select]
Warning: one or more libraries were not found!
Not sure if that's a problem.  So far my built images operates exactly as your release images (PPTP VPN bug and all  ;) )

9
Feature Requests / Re: VMware Tools Installation
« on: June 19, 2019, 05:13:54 AM »
The emulators/open-vm-tools-nox11 port doesn't need perl, but still pulls in python:

Code: [Select]
[email protected]:~ # pkg info
fusefs-libs-2.9.9              FUSE allows filesystem implementation in userspace
gettext-runtime-0.19.8.1_2     GNU gettext runtime libraries and programs
glib-2.56.3_3,1                Some useful routines of C programming (current stable version)
indexinfo-0.3.1                Utility to regenerate the GNU info page index
libdnet-1.12_1                 Simple interface to low level networking routines
libffi-3.2.1_3                 Foreign Function Interface
libiconv-1.14_11               Character set conversion library
libmspack-0.9.1                Library for Microsoft compression formats
libxml2-2.9.8                  XML parser library for GNOME
open-vm-tools-nox11-10.3.0_1,2 Open VMware tools for FreeBSD VMware guests
pcre-8.43                      Perl Compatible Regular Expressions library
pkg-1.10.5_5                   Package manager
python27-2.7.16                Interpreted object-oriented programming language
readline-7.0.5                 Library for editing command lines as they are typed

10
General Questions / Setting up for Local Development
« on: June 08, 2019, 07:45:50 PM »
Is there documentation on how to setup your local environment for development?  I've recently become more interested t1n1wall after having tried OPNSense for a year after migrating from m0n0wall.   

I'd like to try to see if I can upgrade the PHP version to 7.3 and maybe integrate two missing pieces that would make this an ideal firewall appliance.  Those two piecing being the DHCP service patch I submitted and https://www.freshports.org/net/miniupnpd/.

11
Code: [Select]
Version 2.11.1b149 built on Mon Sep 10 00:28:35 IST 2018
Platform Generic PC (serial console)
Architecture i386

12
VPN / PPTP VPN Not Accepting conections and L2TP Breaks Site-to-Site
« on: June 06, 2019, 07:45:13 PM »
I'm migrating from M0n0wall, I manually rebuilt my config page by page to sort of start "fresh".  PPTP was working fine in m0n0wall.

For t1n1wall, enabling the PPTP VPN appears to work according to the logs:

Code: [Select]
Jun  6 14:38:17 <daemon.info> stargate mpd: Multi-link PPP daemon for FreeBSD
Jun  6 14:38:17 <daemon.info> stargate mpd:
Jun  6 14:38:17 <daemon.info> stargate mpd: process 1605 started, version 5.8 ([email protected] 00:31 10-Sep-2018)
Jun  6 14:38:17 <daemon.info> stargate mpd: PPTP: waiting for connection on 0.0.0.0 1723

But attempting to connect from a client just times out.  Nothing is logged on the t1n1wall side.

So then I attempt L2TP/IPsec (since you have that option).  It works, very nicely except that when it's enabled, my site-to-site IPSec tunnels break with:

Code: [Select]
ERROR: phase2 negotiation failed due to time up waiting for phase1
INFO: request for establishing IPsec-SA was queued due to no phase1 found

Turning off L2TP re-enabled my site-site tunnels.

13
I'd like to see fields to override the default gateway that is given out to clients in the DHCP pool.   I created this patch: https://sourceforge.net/p/t1n1wall/bugs/35/

14
I've been a long time m0n0wall user and have tried the 'modern' alternative 'sense's.  They have their use and place, (one more than the other  ;D ). 

I do miss the leanness and simplicity offered by m0n0wall and think both t1n1wall and smallwall are good continuations.  However you would do better to combine your efforts and have a single project.  I would be glad to sponsor some development of features I'd like to see (while keeping it light weight).

Really the only addition's I'm looking for is to bring over some additional configuration fields/options for the DHCP server for reservations, and have the phase 2 components of IPsec separated out from the phase 1 so that a phase 1 can have multiple phase 2's.

Pages: [1]