2
0
mirror of https://github.com/opnsense/docs synced 2024-11-10 19:10:55 +00:00
Commit Graph

294 Commits

Author SHA1 Message Date
Ad Schellevis
0c57a39f65 System: Gateways: Group - add a note in the example about the "gateway" selection. closes https://github.com/opnsense/docs/pull/518 2023-11-15 17:48:11 +01:00
Ad Schellevis
60825064db stylefix 2023-11-09 15:54:54 +01:00
satrapes
07b8c50c59
Update terminology on Wireguard how-to pages (#517) 2023-11-09 14:55:40 +01:00
Ad Schellevis
8a48dce6da System/Access/Servers - add compliance option and some cleanups. closes https://github.com/opnsense/docs/issues/514 2023-11-08 15:12:22 +01:00
Ad Schellevis
bcb0368cc4 VPN / OpenVPN - some typos in sslvpn_instance_s2s.rst 2023-11-04 15:33:05 +01:00
Monviech
7bfa32740c
Update ipsec-swanctl-rw-ikev2-eap-mschapv2.rst (#510)
Hint that IPv6 transport doesn't work with UDP Encapsulation
2023-10-31 13:27:29 +01:00
Daniel Aleksandersen
2f1b56bc93 mdns-repeater only supports up to 5 interfaces
Upstream documentation:
fbe78e7ffd/mdns-repeater.c (L330)
2023-10-20 09:28:56 +02:00
Ad Schellevis
8086c52a2d fix minor compile issues 2023-10-16 10:15:21 +02:00
Monviech
54eef60c16
Wireguard - Reworked wireguard s2s completely & added MTU + MSS to wireguard client (#498)
* Update wireguard-client.rst - Add MTU and MSS hints

* Update wireguard-s2s.rst - Add MTU and MSS hints

* Update wireguard-s2s.rst - changed mss values

* Update wireguard-s2s.rst - Reworked How-To completely

* Update wireguard-client.rst - adjusted mss value

* Update wireguard-client.rst - Different mss values for IPv4 and IPv6

* Update wireguard-s2s.rst - Improved some aspects

* Update wireguard-client.rst - Improved some aspects

Normalization rules should have different MSS values for either IPv4, or IPv4+IPv6.

Changed the protocol back to any, since I'm unsure if selecting TCP only means IPv4 TCP, since there is also only IPv6 selectable.

* Update wireguard-s2s.rst

- Omitted Source Port in Firewall rules
- Added tip and note about dynamic WAN IP

* Update wireguard-s2s.rst - Terminology changes 23.7.6

- Changed Local to Instance
- Changed Endpoint to Peer
- Added information about CARP vhid tracking to mitigate HA problems.
- Added note about Keepalive for NATed sites.
2023-10-15 15:04:43 +02:00
Monviech
d16635ca9a
ipsec-swanctl-rw-ikev2-eap-mschapv2 (#501)
* created ipsec-swanctl-rw-ikev2-eap-mschapv2.rst

* Update vpnet.rst

Changed the position of Legacy and New > 23.1
Added how-tos/ipsec-swanctl-rw-ikev2-eap-mschapv2 to doctree in New > 23.1

* Update ipsec-swanctl-rw-ikev2-eap-mschapv2.rst

General structure of How-To added

* Update ipsec-swanctl-rw-ikev2-eap-mschapv2.rst

Populated Prerequisites

* Update ipsec-swanctl-rw-ikev2-eap-mschapv2.rst

* Update ipsec-swanctl-rw-ikev2-eap-mschapv2.rst

Populated IPsec connection settings for roadwarriors

* Update ipsec-swanctl-rw-ikev2-eap-mschapv2.rst

Fixed IP address formatting in pools

* Update ipsec-swanctl-rw-ikev2-eap-mschapv2.rst

* ipsec-swst Version completedanctl-rw-ikev2-eap-mschapv2.rst - Fir

* Update vpnet.rst - Switched Positions for client config

* Update ipsec-swanctl-rw-ikev2-eap-mschapv2.rst - Version 1.0

* Update ipsec-swanctl-rw-ikev2-eap-mschapv2.rst

- Added DNS configuration payload information to pools and clients https://github.com/opnsense/core/pull/6864
- Added hint that ncp client is not affiliated with Deciso B.V.

* Update ipsec-swanctl-rw-ikev2-eap-mschapv2.rst - Added Routing

hint for Windows RAS Client in Split Tunneling mode.
2023-10-15 15:02:27 +02:00
Monviech
3cc00bfdf5
Update nat_reflection.rst (#507)
* Update nat_reflection.rst

- Fixed typo (asynchronous should be asymmetrical traffic)
- Added note about "reply-to" in specific setups with VPN WAN

* Update nat_reflection.rst

- Fixed VTI NAT description, referenced the tunables to make it work
2023-10-15 14:59:46 +02:00
Ad Schellevis
8d030c3596 minor compile issue in https://github.com/opnsense/docs/pull/489 2023-10-02 15:54:27 +02:00
Cedrik Pischem
e86e01f1db
How-To for Reflection and Hairpin NAT added (#489) 2023-10-02 15:37:01 +02:00
Ad Schellevis
5aa468ceba Authentication - LDAP: add new "constraint groups" property implemented in d971257fd9 2023-09-27 09:08:44 +02:00
Hiigaraa
c2745b3ddc
Update Orange FTTH guide with additionnal info and troubleshooting section (#475) 2023-09-01 13:21:18 +02:00
Thomas
1eecec559c
manual: how-to for FritzBox IPv6
New HowTo to explain the setup of an OPNsense as IPv6
router / firewall behind an AVM Fritz!Box (common German Router)
2023-08-29 14:06:09 +02:00
Monviech
c0c1bb9e5c
Update carp.rst - fixed Build Warnings and added note (#490) 2023-08-28 09:50:46 +02:00
Monviech
ceed02cc9c
How-To added for suricata bypass feature (#485) 2023-08-26 11:02:01 +02:00
Monviech
cb07e622b6
Update carp.rst - Add IPv6 CARP Section (#488) 2023-08-25 13:18:39 +02:00
Ad Schellevis
62d8fc1915 Community Plugins / HAProxy - ditch outdated documentation without owner. 2023-08-08 14:49:38 +02:00
Matt Jolly
b5401626f2
Fix typo'd port (#481) 2023-07-12 13:25:02 +02:00
Ad Schellevis
470ff9702c OpenVPN - add new Instances module 2023-06-29 19:09:02 +02:00
Sam Wilson
1cc6809fdc
Update multiwan.rst (#480) 2023-06-29 15:22:46 +02:00
Michael
5f24f0de2f
Update multiwan.rst (#478)
Add a note to disable shared forwarding when using multiwan with sage tier in gw groups
2023-06-28 15:40:18 +02:00
Ad Schellevis
d46cf057ed missing new-line, closes https://github.com/opnsense/docs/issues/476 2023-06-25 19:46:25 +02:00
Ad Schellevis
d1b8f3c680 Sky UK tutoriali: escape quotes. closes https://github.com/opnsense/docs/pull/474 2023-05-25 09:03:50 +02:00
sjjh
0982c72fc1 Update insight.rst: typo
Netlfow -> Netflow
2023-05-18 08:12:07 +02:00
Franco Fichtner
5f50d046fd dnscrypt-proxy: listen address is automatic on IPv6 so the daemon trips over itself
See: https://github.com/DNSCrypt/dnscrypt-proxy/issues/1217
2023-05-08 10:11:37 +02:00
Hiigaraa
cc565a2ca5
Update Orange FTTH guide to follow the changes in the Orange infrastructure (#468) 2023-04-26 17:29:21 +02:00
Franco Fichtner
c8b3bb0043 orange fr: note change in 23.1.6 about VLAN-PCP on DHCP(v4) 2023-04-20 10:51:50 +02:00
Franco Fichtner
86480ca98d dnscrypt-proxy: same same but not different
Remvoe the Unbound workaround asa "default" suggestion.  Standalonew
works fine so just make sure to reflect this correctly in the document.
2023-04-20 10:47:02 +02:00
Franco Fichtner
0a0a607146 bind: improve documentation for 23.1.6, remove faulty advanced section
Better blocklist support exists in Unbound and since Bind can run as
standalone there is no need to transform the faulty advanced options
to the file-based override that Unbound still supports.
2023-04-20 10:40:23 +02:00
Ad Schellevis
b9fbf01aa6 cloud_backup - fix typo 2023-04-18 16:25:43 +02:00
Ad Schellevis
c22256a674 VPN/IPsec/Examples - add a note about connecting childre. closes https://github.com/opnsense/core/issues/6451 2023-03-29 16:27:46 +02:00
Ad Schellevis
39187fbf03 System/Settings/Administration - reorganise settings a bit and add missing options. Also explain the risks of using "listen interfaces" and how to properly use them. Loopbacks are intended to create the environment needed to reliably bind a service in a changing world. 2023-03-28 16:50:58 +02:00
Ad Schellevis
c4c8ac2078 Access / Servers / Radius - add mnissing options 2023-03-27 17:38:49 +02:00
Justin Horton
d5f3033ae9
Update "first" WireGuard instance number (#459) 2023-03-05 10:51:26 +01:00
Joseph Shanak
b93ca29af3
Fix typo (#458) 2023-03-04 21:10:54 +01:00
Michael
e5472386dc
manual: make note about IPv6 24 hour disconnect (#454)
https://forum.opnsense.org/index.php?topic=32259.msg156936;topicseen#msg156936
2023-02-13 10:28:36 +01:00
Justin Horton
c44d97b664 Fix typos in wireguard-client.rst 2023-02-05 22:59:15 +01:00
Daniel Melzak
106cf9fc0e
Some warnings and an example for clarity (#444)
* Some warnings and an example for clarity 

Added a warning about overlapping networks for the LAN and Wireguard interfaces, as doing so will cause the clients not to be able to communicate with each other properly. Added an example to request another PD from your ISP, as ATT only hands out /64s and one will not be enough to subnet the networks properly.

* Clarification and briefness

Tried to add just enough information to clarify that it is a completely separated network that requires routing to reach the LAN interface.
2022-12-31 09:40:29 +01:00
Ad Schellevis
1c8f849bd3 VPN/IPsec - add NAT before IPsec example. 2022-12-29 17:34:38 +01:00
Ad Schellevis
19310b18bd VPN: IPsec - add example (23.1) 2022-12-22 18:35:25 +01:00
Ad Schellevis
ac814e6b56 VPN: IPsec - add new VTI example 2022-12-22 15:34:02 +01:00
Ad Schellevis
6aa29ff96b VPN: IPsec - reformat section, split generic logic and legacy/mvc parts. 2022-12-19 21:48:09 +01:00
Bogdan A
efd7d10d19
docs: fixed documentation related to GDrive backup (#443) 2022-12-13 19:31:05 +01:00
Marcus Zurhorst
af35265136
Explain automatic nightly remote backup in cloud_backup.rst (#420)
* Explain automatic nightly remote backup in cloud_backup.rst
2022-10-28 08:44:32 +02:00
Ad Schellevis
f3a97487a7 Access / Servers - ldap two-factor 2022-08-04 21:55:54 +02:00
Ad Schellevis
9076705a57 VPN/IPsec - fix IPSec phase 2 instructions . closes https://github.com/opnsense/docs/issues/403 2022-05-23 18:15:56 +02:00
Ad Schellevis
c97248f6ad Squashed commit of the following:
commit e0670007e940a0af4d37fc687bd5203d833c53aa
Author: Ad Schellevis <ad@opnsense.org>
Date:   Mon May 23 16:33:31 2022 +0200

    Interfaces / Setup guides - minor cleanups for https://github.com/opnsense/docs/pull/404 and add to index

commit ebcf61dfb51ad60d0e67ac684952a3501aa1ea4f
Author: Ad Schellevis <ad@opnsense.org>
Date:   Mon May 23 14:43:50 2022 +0200

    OPNcentral - Multi tenancy using host groups for BE 22.4.1

commit 2012c773c9
Author: Jascha Kirchhoff <jakieu@users.noreply.github.com>
Date:   Sat May 21 12:08:17 2022 +0200

    Update dt_ger_iptv_07.png

    Edit to remove personal information

commit 7eba7806b1
Author: Jascha Kirchhoff <jakieu@users.noreply.github.com>
Date:   Sat May 21 12:04:00 2022 +0200

    Added DT IPTV setup

    Setup guide for Deutsche Telekom Germany Magenta TV IPTV
2022-05-23 16:35:24 +02:00