Commit Graph

604 Commits (0dd678d19fca66d456021845aa046ae9f836b26c)

Author SHA1 Message Date
Ad Schellevis 0dd678d19f VPN: OpenVPN - add a tip for client specific overrides and subnet topology 6 months ago
Stephan f01d95c6cf unbound: small warning about forwarding to system nameservers in multi-WAN setups 7 months ago
satrapes 64c73024ed
Add a ProtonVPN Road Warrior setup page (#521)
* Add ProtonVPN WireGuard page

---------

Co-authored-by: Dimitris Paraskevopoulos <dimitris.paraskevopoulos@u-blox.com>
7 months ago
Ad Schellevis 46d56a8e71 git-backup - remove "master" and add a tip about "branch" creation, might clarify https://github.com/opnsense/plugins/issues/3132 7 months ago
Ad Schellevis 0c57a39f65 System: Gateways: Group - add a note in the example about the "gateway" selection. closes https://github.com/opnsense/docs/pull/518 7 months ago
Ad Schellevis 60825064db stylefix 8 months ago
satrapes 07b8c50c59
Update terminology on Wireguard how-to pages (#517) 8 months ago
Ad Schellevis eb0fdefcf9 ETPro-telemetry - add product information links 8 months ago
Ad Schellevis 7b27b51f1d VPN: IPsec - add DPD so we have aplace holder to mention the "enable" flag 8 months ago
Ad Schellevis 8a48dce6da System/Access/Servers - add compliance option and some cleanups. closes https://github.com/opnsense/docs/issues/514 8 months ago
Ad Schellevis 467f9585e0 Installation / ESXi - align network driver choice to VMware's compatibility guide. 8 months ago
Ad Schellevis 03b004d1b5 System: Gateways: Group - better explain groups and point to the requirement of addresses. closes https://github.com/opnsense/docs/issues/513 8 months ago
Ad Schellevis bcb0368cc4 VPN / OpenVPN - some typos in sslvpn_instance_s2s.rst 8 months ago
Ad Schellevis 1798c1c868 VPN: WireGuard - add baseline documentation and move examples. closes https://github.com/opnsense/docs/issues/504 8 months ago
Monviech 7bfa32740c
Update ipsec-swanctl-rw-ikev2-eap-mschapv2.rst (#510)
Hint that IPv6 transport doesn't work with UDP Encapsulation
8 months ago
Ad Schellevis dab8d004d9 VPN / IPsec / General context - explain constraints when using both tunnels and connections. closes https://github.com/opnsense/core/issues/6950 8 months ago
Ad Schellevis 1392c4e471 Setup/Updates - add some troubleshooting tips (most common causes for update issues). 8 months ago
Daniel Aleksandersen 2f1b56bc93 mdns-repeater only supports up to 5 interfaces
Upstream documentation:
fbe78e7ffd/mdns-repeater.c (L330)
8 months ago
Maurice Walker d1043f1da6 DHCPv6: document downstream prefix delegation 8 months ago
Ad Schellevis 8086c52a2d fix minor compile issues 8 months ago
Ad Schellevis 8d8a939f83 System: Configuration: History - update documentation with new MVC implementation, closes https://github.com/opnsense/docs/issues/503 8 months ago
Ad Schellevis 51b9acd79f Interfaces: Neighbors - add initial documentation, closes https://github.com/opnsense/docs/issues/506 8 months ago
Monviech 54eef60c16
Wireguard - Reworked wireguard s2s completely & added MTU + MSS to wireguard client (#498)
* Update wireguard-client.rst - Add MTU and MSS hints

* Update wireguard-s2s.rst - Add MTU and MSS hints

* Update wireguard-s2s.rst - changed mss values

* Update wireguard-s2s.rst - Reworked How-To completely

* Update wireguard-client.rst - adjusted mss value

* Update wireguard-client.rst - Different mss values for IPv4 and IPv6

* Update wireguard-s2s.rst - Improved some aspects

* Update wireguard-client.rst - Improved some aspects

Normalization rules should have different MSS values for either IPv4, or IPv4+IPv6.

Changed the protocol back to any, since I'm unsure if selecting TCP only means IPv4 TCP, since there is also only IPv6 selectable.

* Update wireguard-s2s.rst

- Omitted Source Port in Firewall rules
- Added tip and note about dynamic WAN IP

* Update wireguard-s2s.rst - Terminology changes 23.7.6

- Changed Local to Instance
- Changed Endpoint to Peer
- Added information about CARP vhid tracking to mitigate HA problems.
- Added note about Keepalive for NATed sites.
8 months ago
Monviech d16635ca9a
ipsec-swanctl-rw-ikev2-eap-mschapv2 (#501)
* created ipsec-swanctl-rw-ikev2-eap-mschapv2.rst

* Update vpnet.rst

Changed the position of Legacy and New > 23.1
Added how-tos/ipsec-swanctl-rw-ikev2-eap-mschapv2 to doctree in New > 23.1

* Update ipsec-swanctl-rw-ikev2-eap-mschapv2.rst

General structure of How-To added

* Update ipsec-swanctl-rw-ikev2-eap-mschapv2.rst

Populated Prerequisites

* Update ipsec-swanctl-rw-ikev2-eap-mschapv2.rst

* Update ipsec-swanctl-rw-ikev2-eap-mschapv2.rst

Populated IPsec connection settings for roadwarriors

* Update ipsec-swanctl-rw-ikev2-eap-mschapv2.rst

Fixed IP address formatting in pools

* Update ipsec-swanctl-rw-ikev2-eap-mschapv2.rst

* ipsec-swst Version completedanctl-rw-ikev2-eap-mschapv2.rst - Fir

* Update vpnet.rst - Switched Positions for client config

* Update ipsec-swanctl-rw-ikev2-eap-mschapv2.rst - Version 1.0

* Update ipsec-swanctl-rw-ikev2-eap-mschapv2.rst

- Added DNS configuration payload information to pools and clients https://github.com/opnsense/core/pull/6864
- Added hint that ncp client is not affiliated with Deciso B.V.

* Update ipsec-swanctl-rw-ikev2-eap-mschapv2.rst - Added Routing

hint for Windows RAS Client in Split Tunneling mode.
8 months ago
Monviech 3cc00bfdf5
Update nat_reflection.rst (#507)
* Update nat_reflection.rst

- Fixed typo (asynchronous should be asymmetrical traffic)
- Added note about "reply-to" in specific setups with VPN WAN

* Update nat_reflection.rst

- Fixed VTI NAT description, referenced the tunables to make it work
8 months ago
Stephan 7c208a30b5 unbound: update DNSBL sources list and explain wildcard lists 9 months ago
Ad Schellevis 4a79cb9aed Services: Intrusion Detection - make a note about emulated mode as this is often a more stable solution when there are traffic issues with network cards / drivers. 9 months ago
Ad Schellevis 9f1bee2aa0 VPN: IPsec - add some migration notes when moving from tunnels to connections. 9 months ago
Ad Schellevis 8d030c3596 minor compile issue in https://github.com/opnsense/docs/pull/489 9 months ago
Cedrik Pischem e86e01f1db
How-To for Reflection and Hairpin NAT added (#489) 9 months ago
Ad Schellevis f3b42ec79e System: Configuration: Backups - history setting moved as part of https://github.com/opnsense/core/issues/6828 9 months ago
Ad Schellevis 5aa468ceba Authentication - LDAP: add new "constraint groups" property implemented in d971257fd9 9 months ago
Alexander Münch ded92025fc Fix: Typo in reverse_proxy.rst 10 months ago
xilmen 946e9471e4
Change path for update (#492) 10 months ago
Hiigaraa c2745b3ddc
Update Orange FTTH guide with additionnal info and troubleshooting section (#475) 10 months ago
Thomas 1eecec559c
manual: how-to for FritzBox IPv6
New HowTo to explain the setup of an OPNsense as IPv6
router / firewall behind an AVM Fritz!Box (common German Router)
10 months ago
Monviech c0c1bb9e5c
Update carp.rst - fixed Build Warnings and added note (#490) 10 months ago
Ad Schellevis 6f042673be IDPS / User defined rules - glue howto (https://github.com/opnsense/docs/pull/485) into document 10 months ago
Ad Schellevis 25b61f66a4 VPN: OpenVPN - explain interaction with CARP, including the new option introduced in f56c6e2a0b 10 months ago
Monviech ceed02cc9c
How-To added for suricata bypass feature (#485) 10 months ago
Monviech cb07e622b6
Update carp.rst - Add IPv6 CARP Section (#488) 10 months ago
Ad Schellevis c3651bb78f Wazuh agent - point to debug toggle when the logging is too limited to find issues. 10 months ago
Franco Fichtner b4146d3959 manual: update Dynamic DNS for native backend changes 10 months ago
Ad Schellevis e3eef04970 add wazuh-agent documentation 10 months ago
Ad Schellevis 62d8fc1915 Community Plugins / HAProxy - ditch outdated documentation without owner. 11 months ago
Failing Root 097db9d6ae
fix typo (#482) 11 months ago
Ad Schellevis a899fe3000 VPN/IPsec add Miscellaneous section to explain tunables, starting with PMTU/DF bit 11 months ago
Stephan de Wit f134b6f3bd firewall: diagnostics: states: document the kill-all-states button 12 months ago
Stephan de Wit d577cf7f7f unbound: small rephrase/addition based on new MVC page 12 months ago
Stephan de Wit d8f42f0484 gui: rephrase search input and document tokenization of search phrases 12 months ago