OPNsense 24.1.8, May 2024 Update
7:38
Пікірлер
@ThatTylerGuy963
@ThatTylerGuy963 4 сағат бұрын
Thx
@weedfreer
@weedfreer 10 сағат бұрын
Can you configure software to run in the sandbox in such a way so as to be able to return the sandbox with the software remaining installed upon closing/opening it?
@DanRiegsecker
@DanRiegsecker 11 сағат бұрын
Thank you for you work! Worked perfectly without trouble!
@sheridans
@sheridans 11 сағат бұрын
I appreciate the feedback! Thanks for testing!
@anejey
@anejey 17 сағат бұрын
Awesome, worked right off the bat.
@sheridans
@sheridans 15 сағат бұрын
Great to hear! Thanka for taking the time to let me know.
@sswulffable
@sswulffable 17 сағат бұрын
Win 11... Because of the now ZERO privacy expectations and lack of admin control over your Own Paid For computer property, I personally will NEVER own a win 11 pc... I'm done
@sheridans
@sheridans 15 сағат бұрын
I can't say I blame you
@MichaelMossmanNZ
@MichaelMossmanNZ 9 сағат бұрын
You own the hardware ... if you CHOOSE to run Windows as your O/S, then you own a licence to use it =)
@codingandtech5909
@codingandtech5909 21 сағат бұрын
Like Anyrun perhaps Virus total is another one that is more commonly used. Many might not know anyrun well maybe they do was new to me. Mostly used Virus total. Will give anyrun a shot.
@sheridans
@sheridans 18 сағат бұрын
I plan on covering more of these types of tools 👍
@paulh6395
@paulh6395 Күн бұрын
I had to go into my bios and turn on virtualization then i could install it.I used to use sandboxie many years ago.
@sheridans
@sheridans Күн бұрын
Yes, PC requires virtualisation support, and it needs to be enabled.
@justsurfin5013
@justsurfin5013 Күн бұрын
I remember that, belive rhe Sandbox was added in windows 7
@sheridans
@sheridans Күн бұрын
The feature appeared in Windows 10 insider editions in 2018, from my research.
@justsurfin5013
@justsurfin5013 Күн бұрын
@sheridans nah because I remember it had XP on it. Yeah, was called XP Mode
@sheridans
@sheridans Күн бұрын
XP mode was a thing, all virtual so yeah similar, just the current sandbox uses version of Windows installed. Virtualbox (even hyperv), proxmox,etc support more customisation, take snapshots, revert back, network customisation. It's a handy tool for convenience if you don't have (or want to use other options). Good feedback 🙏
@lynxissiodorensis2319
@lynxissiodorensis2319 Күн бұрын
Except it's not secret nor hidden. But it's a tool, alright.
@sheridans
@sheridans Күн бұрын
Fair enough, many people are anware it exists. The goal of this channel is to help educate people with tech :)
@gurtelem3586
@gurtelem3586 Күн бұрын
Thanks.
@sheridans
@sheridans Күн бұрын
Thank you
@dannypolsky1581
@dannypolsky1581 2 күн бұрын
You forgot to say word "Eureka".😅😅😅
@tongtongwang
@tongtongwang 2 күн бұрын
does this install will delete everything in my C drive?
@sheridans
@sheridans Күн бұрын
the video explains this, not if you choose the right options during the upgrade process
@starupiva
@starupiva 2 күн бұрын
Which windows version are you using?
@sheridans
@sheridans Күн бұрын
needs to be at least Pro, doesn't work with home
@daleus2
@daleus2 2 күн бұрын
Just updated and installed - absolutely spot on. Good work!
@sheridans
@sheridans 2 күн бұрын
Awesome! Thanks for the feedback 👍
@2008spoonman
@2008spoonman 3 күн бұрын
The “secret tool” is just a light version of Hyper-V. It creates 1 vm in a separate network segment. 😊
@sheridans
@sheridans 3 күн бұрын
@@2008spoonman many people seem not be familiar, there's certainly more secure options. If I recall correctly, reboots from within the sandbox will also persist data, for example if installing software that needs to survive a reboot.
@johnygogo
@johnygogo 3 күн бұрын
Genius!!! I spent half a day trying every other solution and nothing worked BUT THIS ONE. Thank you very much. Those buggers tried everything from stopping me to install Windows11 and you my friend helped, thanks!
@sheridans
@sheridans 3 күн бұрын
Awesome feedback, thank you! Glad it worked for you
@2008spoonman
@2008spoonman 5 күн бұрын
So the sandbox has internet connectivity but not to your internal LAN ?
@SarmedAmeen
@SarmedAmeen 5 күн бұрын
On my Windows 10 Pro, it's not connected!
@sheridans
@sheridans 3 күн бұрын
Networking can be disabled, by default it's enabled and it will create it's own network, 172.27.x.x for example, WITH NAT ENABLED.
@SarmedAmeen
@SarmedAmeen 3 күн бұрын
@@sheridans Thanks for replying but in my case it's disabled by default, can you please let me know what is needed to enable it? And thanks in advance!
@sheridans
@sheridans 3 күн бұрын
@SarmedAmeen if you drop to a command prompt and type "ipconfig" can you it assigned the class b private range, starting 172.x? Might be your firewall or something blocking it
@SarmedAmeen
@SarmedAmeen 3 күн бұрын
@sheridans Thanks for pointing this out to me! You're right; it is my Symantec firewall blocking it. Thank you again for your reply; I highly appreciate it, and thanks for the very useful videos!!!
@SmoMo_
@SmoMo_ 5 күн бұрын
This is brilliant, exactly what I need right now!
@sheridans
@sheridans 5 күн бұрын
Appreciate your feedback. There was a fsir amount of time involved in doing this. Thank you.
@OH2023-cj9if
@OH2023-cj9if 5 күн бұрын
7mins to tell us it's only on pro and not home versions.
@sheridans
@sheridans 5 күн бұрын
My bad, apologies I thought I had mentioned in the intro :( Quite right observation. I've updated the video description to make it more clear. Thanks for your feedback.
@RenderRevolution
@RenderRevolution 18 сағат бұрын
@OH2023-cj9if you can buy pro for less than 8 dollars, fully genuine. 100% work it only for this, plus if you really wanted it you would buy pro. Clearly you don't need it bad enough 😅 Merry Christmas, hope Santa brought you pro so you can sandbox!!
@codingandtech5909
@codingandtech5909 18 сағат бұрын
@@sheridans But it should have been made available on Home edition as well. Dam Microsoft
@sheridans
@sheridans 17 сағат бұрын
Technically you can get it running on Home editions, I'm not covering that as it's more than likely against YT terms.
@vjy-rdy
@vjy-rdy 15 сағат бұрын
Thx for saving my time
@samaitcheson7057
@samaitcheson7057 5 күн бұрын
I thought I had a decent knowledge of Windows 11 but I didn't know about this. Great tip!
@sheridans
@sheridans 5 күн бұрын
We're always learning :) Thanks for feedback 🙏
@Mudflap1110
@Mudflap1110 5 күн бұрын
Haha. Windows is such crap
@sheridans
@sheridans 14 сағат бұрын
This is why I spend most of my time on FreeBSD, Arch if gaming, Windows for the Photoshop, Premier, etc.
@chuxxsss
@chuxxsss 5 күн бұрын
I'm having problems getting OPNsense to load on the N100 model. I unarc the .bz2 file to a dvd but only get to the mouse pointer before it stops.
@bobrobertsNotUrBob
@bobrobertsNotUrBob 5 күн бұрын
does the sandbox have the same license key as the host OS?
@sheridans
@sheridans 5 күн бұрын
not sure why a license matters, it's a one-time use thing?
@bobrobertsNotUrBob
@bobrobertsNotUrBob 5 күн бұрын
@@sheridans for testing software which is tied to that machine id
@sheridans
@sheridans 3 күн бұрын
@@bobrobertsNotUrBob As far as I'm aware, emulates enteprise which is a volume license, hence can't be activated. If you have software bound to host product key, I'm assuming it will fail.
@bobrobertsNotUrBob
@bobrobertsNotUrBob 3 күн бұрын
@@sheridans ok thx
@bartje885
@bartje885 6 күн бұрын
Another question, is it possible to connect OPNsense tailscale plugin via another exit node in my network and setup an interface based on that connection? So to use the Tailscale plugin as a client rather than a server?
@sheridans
@sheridans 5 күн бұрын
Never tried it, you could possibly setup aj outbound nat rule to achieve this
@jasonbottjen4315
@jasonbottjen4315 6 күн бұрын
Works perfectly. Thanks for the plugin, the dashboard widget, and this great video showing how to set it up!
@sheridans
@sheridans 6 күн бұрын
As far as I'm aware, the dashboard widget isn't available yet, that's in the next release
@jasonbottjen4315
@jasonbottjen4315 6 күн бұрын
@sheridans correct. It is not released yet as of this writing, but I saw the merge so thanks in advance!
@sheridans
@sheridans 5 күн бұрын
Appreciate that, thank you
@TonyGauderman
@TonyGauderman 6 күн бұрын
Thank you for this!!! I was using the bsd ports version, and struggled a little migrating to this one, but once I figured it out, it's pretty simple.. to get all the config into the new plugin, I assentially had to start over, but it's simple.. I followed the following steps: Go to tailscale ports directory (/usr/ports/security/tailscale) and run "make deinstall" Rename or remove /var/db/tailscale/tailscaled.state (otherwise it will reuse old config and not take options from GUI) Delete existing node from tailscale portal (I couldn't find a way to re-use it, and if you leave it, you end up with a "host" and a "host-1" in the portal) Create new key in tailscale Add key to OPNsense GUI Enable exit node and advertised routes Enable Tailscale Go to tailscale portal and enable exit nodes and routes for new node If you are using opnsense as an exit node, select new exit node from your existing clients I WAS able to use the same interface and rules as I had previously built. Again, thank you for creating this, it's awesome to have this built into the GUI!!
@sheridans
@sheridans 6 күн бұрын
Awesome feedback, thank you! Quite correct, removing /var/db/tailscale and setting it back up from fresh is the easiest way.
@hottroddinn
@hottroddinn 6 күн бұрын
I don't see tailscale under VPN section. I've reinstalled this thrice and it's still the same. Any tip would be appreciated.
@sheridans
@sheridans 6 күн бұрын
Install the plugin as you would any other, refresh the browser page for it to appear in the interface. Haven't had any reports of it not even appearing after install
@bartje885
@bartje885 6 күн бұрын
Any way to use the CRON build-in scheduler to make a snapshot before auto update the firmware?
@sheridans
@sheridans 6 күн бұрын
Sorry, no. They decided against auto feature as coupd cause people to run out of disk space if they didn't clean them up.
@bartje885
@bartje885 6 күн бұрын
@@sheridans Well that makes perfectly sense, thanks. I will create a cron job for myself and a script that keeps the latest x snapshots. Thanks
@sheridans
@sheridans 6 күн бұрын
@bartje885 don't give up hope, you never know what's around the corner 😀
@mattsmolinski
@mattsmolinski 8 күн бұрын
thought the day would never come lol thank you so much!
@sheridans
@sheridans 8 күн бұрын
Someone had to do it, had an outstanding request on Tailscale Github page for 2 years: 😀
@Froggie92
@Froggie92 8 күн бұрын
i saw someone talking about it on reddit the other day, didnt know you wrote it, kudos! ive been running it in a container for months bc the upgrade in opnsense was so involved and broke often, once again, gods work truly
@sheridans
@sheridans 8 күн бұрын
Thank you for that. It was much appreciated to know it was worth the effort! They'll probably be an update or two as that was the first draft, seems to be fine for most people.
@oxygenkiosk
@oxygenkiosk 8 күн бұрын
Handy tip, thank you. Every day's a school day.
@sheridans
@sheridans 8 күн бұрын
For you and me both 😉
@Felix-ve9hs
@Felix-ve9hs 8 күн бұрын
Very cool, never knew this was a thing, and I use windows for 20 years now 😂
@sheridans
@sheridans 8 күн бұрын
I've only used it recently myself 😀
@kpv123
@kpv123 9 сағат бұрын
It was not in previous versions of windows. Sandboxie was the go to program for a sandbox.
@minigpracing3068
@minigpracing3068 8 күн бұрын
Thanks. I'll have to install this on my laptop. WSL would be another good choice to build a sandbox.
@sheridans
@sheridans 8 күн бұрын
Works well,obviously wsl is Linux based, Sandbox is Windows. Appreciate feedback 🙏
@ojumooladaniel5467
@ojumooladaniel5467 8 күн бұрын
The only method that worked for me. Thanks.
@sheridans
@sheridans 8 күн бұрын
Appreciate you taking the time to say so!
@mndphaser
@mndphaser 9 күн бұрын
freebsd-version -kru. pkg intall bectl -y && man bectl to read about it.
@sheridans
@sheridans 8 күн бұрын
I'm assuming you mean "pkg install beadm"? bectl is part of the base, which is based on beadm but has some lacking functionality
@SyedHuzaifaFazal
@SyedHuzaifaFazal 9 күн бұрын
Hi Sam, we have a CISCO router and a switch configured with DHCP and DNS and all office traffic going through it. Please let me know how I can forward all my current traffic so that it will pass through OPNsense firewall which I have installed in a dedicated server
@sheridans
@sheridans 8 күн бұрын
How is the internet connection provided? I replaced our ISP provided Cisco router completely with OPNsense
@TheNorliss
@TheNorliss 9 күн бұрын
Nice one, mate. How do you find the performance when you use one of these boxes in lieu of the supplied ISP router? There seems to be some conflicting information about this insofar as many pointing out the FreeBSD issue with downstream traffic being bottlenecked and pegging one CPU core, whilst I've also read that this issue has been resolved?
@sheridans
@sheridans 9 күн бұрын
It is single thread bound, so faster cpu is usually recommended. You can try setting some system tuneables: net.isr.dispatch: deferred net.isr.maxthreads: -1 net.isr.bindthreads: 1 And reboot after changing
@sheridans
@sheridans 9 күн бұрын
@@TheNorliss see this thread github.com/opnsense/core/issues/5415
@TheNorliss
@TheNorliss 9 күн бұрын
@@sheridans Thanks, mate. It's a shame this hasn't been sorted in Free BSD as from what I understand it doesn't seem to affect upstream traffic, only downstream?
@sheridans
@sheridans 9 күн бұрын
@@TheNorliss apparently the settings in that thread solved it for someone. Haven't tried it myself yet
@TheNorliss
@TheNorliss 9 күн бұрын
@@sheridans Yeah thanks, mate. Will give this a try when I actually get my OPNsense gear set up. Your content's great, btw. Another sub here.
9 күн бұрын
Thank you very much! Is it possible to use another tailscale node as exit node? So that i could register another tailscale node (remote node) as gateway in opnsense? So that the opnsense traffic gets routed through an external tailscale exit node?
@sheridans
@sheridans 9 күн бұрын
Haven't tried it, you could possibly try natting. OPNsense forums may be best place to ask, awkward on yt
@tristinbutz7244
@tristinbutz7244 9 күн бұрын
You made a comment about the key expiring in 90 days, and said you would come back to that topic later in the video. Unless I missed it, you never went over how to make this not expire. How do I do so? Thanks.
@sheridans
@sheridans 9 күн бұрын
that's a setting within tailscale panel, login go to machines, 3 dots and click do not expire
@toady0013
@toady0013 9 күн бұрын
Just installed to make my rpi node redundant. Plugin connects fine but am not able to connect to any devices on the other side of my tail net. Is routing etc still manually required or should this all be handled by default
@sheridans
@sheridans 9 күн бұрын
Have you assigned the interface, and added allow firewall rules as shown in the video?
@ecn78
@ecn78 8 күн бұрын
@@sheridans I think I know what the problem is here, I had the same with the mimugmail install. I could ping my OPNsense but not get the Web GUI. You need to enable the web GUI listening interfaces. System > Settings > Administration > Listen Interfaces - this probably just says 'LAN', use the drop down to tick TLSC (or whatever you called the interface) too. @toady0013 try this.
@ecn78
@ecn78 8 күн бұрын
@@sheridansI think I know what the issue is here. The web UI listen interfaces need updating once the TLSC interface is added. I ran into the same thing before. System > Settings > Administration > Listen Interfaces- probably only has LAN selected. Select TLSC as well to enable web UI over tailnet. Edit: actually I may have misread the above - looks like connections from OPNsense to the rest of the network. Regardless, in my case the above needed configuring for the rest of the tailnet to access the web UI.
@sheridans
@sheridans 8 күн бұрын
Thank you for sharing! Didn't even cross my mind 😞
@imissyy
@imissyy 9 күн бұрын
Thank you so much. Well done.
@sheridans
@sheridans 9 күн бұрын
Appreciate that, thanks 😊
@sheridans
@sheridans 9 күн бұрын
OPNsense 24.7.11 released. "a minor update all things considered, but it does bring you the long sought after Tailscale plugin courtesy of Sheridan Computers. Suricata is also updated to its latest version to fix a couple of CVEs."
@Pommster
@Pommster 6 күн бұрын
I installed the Tailscale plugin, generated an auth key and filled in the pre-authentication key in the plugin and it just doesn't work after I enabled it. Machine never appears on the list and I never get an IP address. Could it be because I sign in using Apple? Status shows NeedLogin. Wonder if I can change login method.
@sheridans
@sheridans 6 күн бұрын
No, should be fine. As long as you put in a valid preauth key
@Pommster
@Pommster 6 күн бұрын
@@sheridans Okay, I worked it out. After I filled in the key in OPNsense I have to go to the AuthURL listed and login again. Then I can authorise my machine.
@over-there
@over-there 10 күн бұрын
Thanks for all your work on opnsense
@sheridans
@sheridans 9 күн бұрын
Thank you, 24.7.11 has just been released which includes the plugin. It also addresses some CVE's with Suricata
@talsstudio2939
@talsstudio2939 10 күн бұрын
Stay a way from them The problem With Synology is the technical support one of the worst I ever experience now I'm afraid should I use this drive because if I ever need a tech-support and I'm not gonna find it on KZbin, I have no where to go should I just return the unit and buy something else because I don't trust Synology
@sheridans
@sheridans 10 күн бұрын
Owning an IT support company, we sell alot. What's the problem? Drives fail
@timwasyliw5920
@timwasyliw5920 10 күн бұрын
what do i do if i get this error [0x7E]?
@sheridans
@sheridans 9 күн бұрын
I try downloading again, sounds like file corruption
@Stigman101
@Stigman101 10 күн бұрын
Thanks really good..
@sheridans
@sheridans 10 күн бұрын
Appreciated, thanks 👍
@pegatube
@pegatube 10 күн бұрын
Dear channel, Thanks for your sharing and video. I confirm that your solution help me to upgrade my PC from Windows 10 to Windows 11 without TPM 2.0 Hope you are doing well and produce more and more videos
@sheridans
@sheridans 10 күн бұрын
Thanks for sharing 👍
@roboguys-r5u
@roboguys-r5u 11 күн бұрын
it doesn't let me choose keep files, settings and apps so i just did keep personal stuff
@sheridans
@sheridans 10 күн бұрын
Many people had similar issues in the comments, it was related to not using the same language iso as installed on the system