Linuxmuster-setup läuft nicht durch (SSH-Verbindung zur Firewall)

Hi Fenyo,

unfortunalty the setup, either done by cli or WebGui, does make kind of a fuss to the firewall. You need to reconfigure the UnBoundDNS-Section of the opnSense after you ran linuxmuster-setup (see Murks nach linuxmuster-setup im Setup der opnSense - #18 von Adrian). Otherwise you will probably experiance DNS-Loop-Issues.

Kind regards
Thomas

Hi,
Thanks for the idea, but unfortunately I have set the unbound dns tool to query forward in opnsense, but it does not help, still no name resolution, only ping works after gateway recovery. One more oddity is that the server after websetup becomes read-only in the filesystem, so even if I wanted to I couldn’t poke into the config files.


In parallel, I also started to try another free solution, Linux Schools Server, which is far less painful to install, works for the first time, at least on a basic function level (dhcp, dns, samba, proxy etc), and it can be used to domain a Win10 client without any problems, but it has practically no documentation. In principle it has an exam user and tftp can be enabled, but it seems far from as elaborate as lmn exam mode and linbo.
I know free solutions, don’t want too many.

Hi Feyno,

im very sorry that you experiance such hardship while installing linuxmuster.net.
This is not normal.
Thomas has noticed the Problems some weeks ago and we were not able yet to resolve these.

I made some screenshots for you so you can see, how the unbound should be configured.
Regard the „use system Nameservers“ which has no tick!

Restart the services afterwards or the OPNsense itself and then test again.

I wanted to test the vanilla install this week: but there was no time. I’ll try to do that next week …
Yours
Holger

Yes, that’s exactly what I did, the description Thomas linked to did the same, but it didn’t help. I didn’t restart the opnsense but only the service (I don’t think it matters), next time I’ll be able to try again next week.

I didn’t have time to test it this week, but I did get a router for the opnsense, to see if that was the cause of the agony. So I’ll try again next week, but I see that version 7.3 can be installed from scratch. Then I might try it, as I read the description the main difference is that the domain controller and the fileserver have been separated. On the lmn server physical machine, would this mean that in addition to the separate fileserver package installation, the server gets a second ip address or does it need a second network card too?

Thanks Fenyo

Hi Fenyo,

the Fileserverseparation in 7.3 is optional not obligatory, as far as i know.
If you separate it it runs on a separate machine which can be a second virtual Machine on the same VM-Host. There is no need for a second Networkkard since both are in the same Netwokr, which we call „Grün“ (Green).

yours
Holger

OK, thanks, then I guess the fileserver settings can be ignored, it can only be optionally detached and run on another physical or virtual machine if I understand correctly.

Hi Fenyo,
thats correct.
It is also designed to be migrated in a running environment.
When you notice, after a while, that you would like to move the Fileserver to another Machine: to migrate a two server installation (OPNSense,LMN) to a threeserver Installation (OPNsense, LMN, Fileserver)
Yours
Holger

Hi,
Thanks, tap two done, unfortunately it still messes up after websetup. The router has helped the situation so much that now the gateway stays good after websetup, but web interface is no longer accessible from client machine after successful setup message (I can ping it, but nothing else). A new phenomenon is that the dhcp server does not work after websetup, this worked in 7.2, looking into the dhcpd.conf file it does not include the range in setup.ini only nameserver domain ntp gateway and other static stuff. By default name resolution also doesn’t work after websetup only if I set my own name server in resolv.conf. So I don’t know where things go wrong, I can try 7.2 again with router.

Hi.
Your linuxmuster-server has a different name than simply server– I’m not sure, but I think the name server is highly recommended. However, I’m not sure if it could be causing the issues shown in your screenshots.
Holger (@baumhof) – was meinst Du?
Viele Grüße,
Michael