Forums

×

Warning

JUser: :_load: Unable to load user with ID: 187411
Resolved
0 votes
As we are working to provide on ClearOS 8 we are looking to see what features and functions that you find lacking with ClearOS, the portals, and this website. What would you like improved and what would you like changed. We are working on building our roadmap for 8 and need to know what is key for you. We also want to allow for greater community involvement and if you have an interest in 'owning' or leading within the community.
Tuesday, January 29 2019, 07:32 PM
Share this post:
Responses (40)
  • Accepted Answer

    Sunday, April 28 2019, 05:41 PM - #Permalink
    Resolved
    0 votes
    I thought that I made that feature request a long time ago! Peter added it to the tracker. :)
    The reply is currently minimized Show
  • Accepted Answer

    Sunday, April 28 2019, 11:06 AM - #Permalink
    Resolved
    0 votes
    Patrick de Brabander wrote:

    Eric Anderson wrote:

    more share options in flexshare: like create mask, browseable and more...

    [edit Nick Howitt] Gitlab https://gitlab.com/clearos/clearfoundation/app-flexshare/issues/9[/edit]

    Not sure this has mentioned.

    Maybe a combination of Flexshare and Store manager
    I woould like the abbility to use flexshares on the 2nd, 3rd drive.
    So when you add a flexshare you can choose on which drive will be (sdb/sdc/....) or maybe even which directory
    I'll link it to Continue work with FlexshareDirCustom implementation which has been created as a Storage Manager issue.
    The reply is currently minimized Show
  • Accepted Answer

    Sunday, April 28 2019, 07:44 AM - #Permalink
    Resolved
    0 votes
    Eric Anderson wrote:

    more share options in flexshare: like create mask, browseable and more...

    [edit Nick Howitt] Gitlab https://gitlab.com/clearos/clearfoundation/app-flexshare/issues/9[/edit]

    Not sure this has mentioned.

    Maybe a combination of Flexshare and Store manager
    I woould like the abbility to use flexshares on the 2nd, 3rd drive.
    So when you add a flexshare you can choose on which drive will be (sdb/sdc/....) or maybe even which directory
    The reply is currently minimized Show
  • Accepted Answer

    Thursday, April 04 2019, 10:25 PM - #Permalink
    Resolved
    0 votes
    We've been taking note of your suggestions and placing them as 'Feature Requests' in Gitlab. That is where we will process such things in the future. If you wish to add a feature, you can report find the app in ClearOS that you want to see an improvement in Gitlab and then report the issue. Be sure to flag the issue with the tag 'Feature Request'.

    If you see feature that you like and want to promote it, be sure to hit the like button, the more likes, the more visible it is to us.

    If the feature isn't part of a project that exists yet, go to the "Feature Requests" project and report your feature request as a 'New Issue'. Don't forget to tag your request and like it. Issues can and will be moved from features when it is assigned a project.
    The reply is currently minimized Show
  • Accepted Answer

    Sunday, March 24 2019, 09:27 PM - #Permalink
    Resolved
    0 votes
    Hello Sandbo,
    Welcome to ClearOS. I will move your requests across but can I just point out that when you port forward, you should **not** also open the port. The incoming firewall is for traffic destined for ClearOS, but port Forwarding is for traffic destined through ClearOS to the LAN behind.
    The reply is currently minimized Show
  • Accepted Answer

    Sunday, March 24 2019, 09:00 PM - #Permalink
    Resolved
    0 votes
    Hi,

    I am new to ClearOS and previously had some experience with pfsense.
    I am switching mostly because of the fact that ClearOS is built on Linux, and so far it works just as well.
    Thanks for the hard work!

    Just a few minor suggestions:
    Ease of use
    -Allow editing of firewall/port-forwarding rules, sometimes it's better if this can just be changed but not remade
    [edit Nick Howitt] Gitlab https://gitlab.com/clearos/clearfoundation/app-port-forwarding/issues/3 [/edit]
    -Allow a drop down list of assigned static ips when selecting which IP the port-forwarding refers to, this makes things easier when there are so many IoT items
    [edit Nick Howitt] Gitlab https://gitlab.com/clearos/clearfoundation/app-port-forwarding/issues/4
    Note this only works with static leases as ClearOS does not know about truly static IP's
    [/edit]

    Default behaviour
    -Default the second NIC to static. I had difficulties understanding how to setup a DHCP server at first, as it turns out I need to set the second NIC (meant for LAN) to static, only then it can work as a DHCP server. It will be easier if this was part of the setup wizard.
    [edit Nick Howitt] Gitlab https://gitlab.com/clearos/clearfoundation/app-network/issues/17 [/edit]
    -When port-forwarding rules are added, automatically open the firewall. Now I have to manually do the same thing twice which is quite redundant. IIRC, pfsense will automatically open the firewall when something is port-forwarded.
    The reply is currently minimized Show
  • Accepted Answer

    Saturday, March 23 2019, 05:23 PM - #Permalink
    Resolved
    0 votes
    Nick Howitt wrote:

    Hello Patrick,
    Please can you elaborate on these?
    1 - Do you mean DHCP such that the DHCP server will not give out IP's to unknown MAC addresses - similar to what you often see in WAP's for WiFi access, or did you mean firewall blocking based on MAC address? Blocking on MAC address is problematic. I think even NetworkManager allows a WiFi interface to randomise its MAC address each time it connects. The reverse would be easier in the firewall, to only allow permitted MAC addresses.
    2 - What do you mean by "Account manager is not completely linked with some extensions/users"? Can you give an example? When requesting a tick box is this to replace the current dropdowns? I will file an issue on the dropdowns on App Policies as I think they are no different from groups in the background. - Gitlab https://gitlab.com/clearos/clearfoundation/app-users/issues/8


    Hi Nick.

    [b]
    1 - Do you mean DHCP such that the DHCP server will not give out IP's to unknown MAC addresses - similar to what you often see in WAP's for WiFi access, or did you mean firewall blocking based on MAC address? Blocking on MAC address is problematic. I think even NetworkManager allows a WiFi interface to randomise its MAC address each time it connects. The reverse would be easier in the firewall, to only allow permitted MAC addresses.


    Correct. This is exactly what i mean.
    One a MAC connect to the DHCP and recieves an IP-adress I want to have the opportunity to block this devices and gets an IP the next time (and connect to the system)

    [edit Nick Howitt] Gitlab https://gitlab.com/clearos/clearfoundation/app-dhcp/issues/4 [/edit]

    [b]
    2 - What do you mean by "Account manager is not completely linked with some extensions/users"? Can you give an example? When requesting a tick box is this to replace the current dropdowns? I will file an issue on the dropdowns on App Policies as I think they are no different from groups in the background. - Gitlab https://gitlab.com/clearos/clearfoundation/app-users/issues/8


    Is it possible to tag the option with a certain users for these packages
    https://i.ibb.co/F5LtZrt/2019-03-23-18-14-44-pdebrabander-nl-Account-Manager.png

    Something like this, but the a row of tags.

    https://i.ibb.co/Dp8bXNb/2019-03-23-18-21-46-pdebrabander-nl-Members.png

    [edit Nick Howitt] Gitlab https://gitlab.com/clearos/clearfoundation/app-accounts/issues/2 [/edit]
    The reply is currently minimized Show
  • Accepted Answer

    Thursday, March 21 2019, 07:02 PM - #Permalink
    Resolved
    0 votes
    Thanks Nick for undertaking these updates...

    Forum issues - it is already decided to move and it looks like to Discourse forums. Lets wait to see what it brings until raising bugs.

    I could accept that if there are concrete plans to implement the replacement within say the next three months, and announced within the next week or two. As yet there hasn't been a single append by anyone from Clear management as to *when* it will happen and *what* the replacement will be. So other than an indication that we *might* move to Discourse , and no indication whatsoever of timing - we are still in much the same situation as 8 1/2 years ago. This change could be two years away or more for all we know...

    Perhaps we should change the bug to something like "no viable procedure or willingness to fix problems, performance issues, bugs etc affecting the Clear Forums". :p If after the move to Discourse. or whatever the replacement, is - we still have the same crappy support and reluctance to fix issues, we will still have the same basic problem as currently experienced. Discourse looks nice, but will there be continuous competent and expeditious support?
    The reply is currently minimized Show
  • Accepted Answer

    Thursday, March 21 2019, 10:20 AM - #Permalink
    Resolved
    0 votes
    All items transferred except where there are specific comments either in the post or in a follow up post.

    Not transferred are any website issues, because the decision has already been made to move to different forum software and I don't see much point in raising bugs against the current site when it is all going to change. Once the new site appears, then, to me it makes sense to start raising issues against the new site.
    The reply is currently minimized Show
  • Accepted Answer

    Thursday, March 21 2019, 09:30 AM - #Permalink
    Resolved
    0 votes
    Patrick de Brabander wrote:

    definitely a way to block a device on MAC number in DHCP.
    Maybe in webconfig more feature to adjust settings. This is very limited now.

    Account manager is not completly linked with some extensions/users. A tickbox would be great to enable features
    Hello Patrick,
    Please can you elaborate on these?
    1 - Do you mean DHCP such that the DHCP server will not give out IP's to unknown MAC addresses - similar to what you often see in WAP's for WiFi access, or did you mean firewall blocking based on MAC address? Blocking on MAC address is problematic. I think even NetworkManager allows a WiFi interface to randomise its MAC address each time it connects. The reverse would be easier in the firewall, to only allow permitted MAC addresses.

    [edit Nick Howitt]After clarification: Gitlab https://gitlab.com/clearos/clearfoundation/app-dhcp/issues/4 [/edit]

    2 - What do you mean by "Account manager is not completely linked with some extensions/users"? Can you give an example? When requesting a tick box is this to replace the current dropdowns? I will file an issue on the dropdowns on App Policies as I think they are no different from groups in the background. - Gitlab https://gitlab.com/clearos/clearfoundation/app-users/issues/8
    The reply is currently minimized Show
  • Accepted Answer

    Wednesday, March 20 2019, 04:59 PM - #Permalink
    Resolved
    0 votes
    @Dirk,
    I've added your requests from this post to Gitlab

    I've not added your Kopano request as it exists already, and you MAC blocking is possible already with both a custom firewall rule and Gateway Management so I've not added that.
    The reply is currently minimized Show
  • Accepted Answer

    Wednesday, March 20 2019, 03:05 PM - #Permalink
    Resolved
    0 votes
    Hi Tony,
    I've moved some of your requests from your post to Gitlab. I have not moved the following:

    Forum issues - it is already decided to move and it looks like to Discourse forums. Lets wait to see what it brings until raising bugs.
    LDAP - I believe it is going to 389 Directory/IPA.
    Certificate Management - There is already a new certificate manager written for 7.6 updates (so not 7.6) and I know it has needed changes to Let's Encrypt so is further reaching than teh current one. Again, lets see what it brings.
    Removed Device Drivers It is the intent to switch to a stock kernel. The background work has been done and QoS can be flipped right now (I've already flipped mine). There was a bug in the update which exposed the parameter to flip in the conf file which is easy to fix. This will also probably happen in 7.6 updates. Once this has happened we should be able to switch to a mainline kernel and (my personal guess) possibly at the next required kernel update. No one liked patching the kernel for IMQ. Then you can have direct access to kmod drivers.
    The reply is currently minimized Show
  • Accepted Answer

    grubs
    grubs
    Offline
    Sunday, March 10 2019, 11:39 PM - #Permalink
    Resolved
    0 votes
    For me, participation is too painful due simply to the poor performance of the website.
    I find the clearOS website and forum to be unbearably slow to the point of being not wanting to engage or participate because its too painful waiting 5-15 seconds after clicking on a link to see the content. There is a lot of great content that is difficult to extract from the forums... This isn't a new thing - has been an issue since the current format was rolled out. That it is still an issue after a few years just adds to the disappointment.
    The reply is currently minimized Show
  • Accepted Answer

    Saturday, March 09 2019, 07:39 PM - #Permalink
    Resolved
    0 votes
    Marc Laporte wrote:

    Rodrigo's list is fantastic:
    https://www.clearos.com/clearfoundation/social/community/my-suggestion-feature-request-list


    Who is going to move these feature request to Gitlab? Of course I want to do it if it's okay by Rodrigo!?
    The reply is currently minimized Show
  • Accepted Answer

    Saturday, March 09 2019, 04:59 AM - #Permalink
    Resolved
    0 votes
    Rodrigo's list is fantastic:
    https://www.clearos.com/clearfoundation/social/community/my-suggestion-feature-request-list

    [edit by Nick Howitt]
    I've put Rodrigo's list on Gitlab as follows:
    Port CDW to ClearOS 7 https://gitlab.com/clearos/feature-requests/issues/56
    Storage App - not added is it is an existing target
    Multiple php versions - Not added as it exists in 7.x and is integrated with the Web Server app.
    NTP - https://gitlab.com/clearos/clearfoundation/app-ntp/issues/1
    DDNS - https://gitlab.com/clearos/feature-requests/issues/57
    Update accelerator - https://gitlab.com/clearos/feature-requests/issues/58
    Web Server - https://gitlab.com/clearos/clearfoundation/app-web-server/issues/5
    Apache Tomcat - https://gitlab.com/clearos/feature-requests/issues/59
    Web file manager - https://gitlab.com/clearos/feature-requests/issues/60
    File permissions - https://gitlab.com/clearos/feature-requests/issues/61.
    Better Wi-Fi support - already requested
    CRON Manager- https://gitlab.com/clearos/feature-requests/issues/62
    Wake on LAN (with scheduling) - https://gitlab.com/clearos/feature-requests/issues/63. Note, if it is just for scripting, there are many packages you can install such as net-tools which includes the "ether-wake" program.
    Apache proxy - Not added. This exists as the ProxyPass app for which there is a small charge for the developer.
    NUT UPS Tools - https://gitlab.com/clearos/feature-requests/issues/64
    VoIP Server - https://gitlab.com/clearos/feature-requests/issues/65
    ZoneMinder - Security camera Server - https://gitlab.com/clearos/feature-requests/issues/66. Note it can be installed from https://zmrepo.zoneminder.com/ and it has its own GUI.

    Other ideas:

    Better comparison between media servers on market
    Right now, I have to research online to decide which to install

    Include network setup suggestions
    One thing that might be helpful is to have some text or image showing different setups of network parameters. I'm thinking specifically of numbers of dhcp clients the subnet will allow, which numbers will be dedicated to remote vpn, static ip. https://gitlab.com/clearos/feature-requests/issues/71
    The reply is currently minimized Show
  • Accepted Answer

    Monday, March 04 2019, 01:28 AM - #Permalink
    Resolved
    0 votes
    more share options in flexshare: like create mask, browseable and more...

    [edit Nick Howitt] Gitlab https://gitlab.com/clearos/clearfoundation/app-flexshare/issues/9[/edit]
    The reply is currently minimized Show
  • Accepted Answer

    Friday, March 01 2019, 02:35 PM - #Permalink
    Resolved
    0 votes
    Hello!

    I would like to see better integration for Docker. IMHO, it should cover

    * port forwarding
    * service discovery
    * internal dns resolution
    * container scaling
    * rest api for some actions (pull, start, stop, run, **upgrade**)

    In another words, it could wrap the `docker-compose` tool.

    I see docker as the only way to deploy modern applications in ClearOS without relying in external Yum repositories and compromising system behavior.

    [edit Nick Howitt] Gitlab https://gitlab.com/clearos/clearfoundation/app-docker/issues/2[/edit]
    The reply is currently minimized Show
  • Accepted Answer

    Friday, March 01 2019, 01:10 AM - #Permalink
    Resolved
    0 votes
    PostgreSQL. I have some apps using pgsql (webmin managed, very limited but more secure than pgadmin), instead maria/mysql. it would be nice have something that could handle this databases

    [edit Nick Howitt] Gitlab https://gitlab.com/clearos/feature-requests/issues/70[/edit]
    The reply is currently minimized Show
  • Accepted Answer

    Tuesday, February 26 2019, 05:05 AM - #Permalink
    Resolved
    0 votes
    Thanks to everyone for putting your suggestions here. I will be giving away Bonanza Tickets to each poster thus far that submits their request here as an Issue in GitLab. After a week, I'll sweep them up and post them all myself but I'll give some tickets away if you do it before I get to it.
    The reply is currently minimized Show
  • Accepted Answer

    Robert
    Robert
    Offline
    Monday, February 11 2019, 08:55 AM - #Permalink
    Resolved
    0 votes
    Hello,

    ClearOS works well for me all those years and I use it since the 5.1 times. What I always missed was a webaccess app to allow easy file sync between ClearOS machines. I know this can be done using rsync and so on, but a "push this button method" would be great. Especially, since ClearOS has a VPN app for site to site connections.

    Thanks.

    Best wishes,

    Robert

    [edit Nick Howitt] Gitlab https://gitlab.com/clearos/feature-requests/issues/69

    @Robert, I am a bit cautious about this request unless you can flesh it out more so it is not just a solution to your personal needs. Are you wanting to list a target machine source folders/files and destination folders? Are you expecting ssh keys to be in place? Is this to be run under cron?
    [/edit]
    The reply is currently minimized Show
  • Accepted Answer

    Sunday, February 10 2019, 07:05 PM - #Permalink
    Resolved
    0 votes
    Hello Dave and all,

    Despite this is my first post, I use ClearOS since nearly 4 years for personal use as an Internet gateway/router and NAS. I am still amazed it is so stable!

    I am glad being able sharing with you my concern: I want being sure my data would be safe in case my server would be stolen. In Ubuntu, before version 18.04, the personal folder was encrypted until we connected at least once. That feature would be great for ClearOS because the server can automatically restart after a power outage and thus leave our data safe until we connect through SSH once (or better, through http/s for example). I don't want to type a password on the physical console (and, by the way, I don't have one for that server!).

    I could implement that manually, but an out of the box solution would be appreciated :-)
    I hope my suggestion would useful or give you some ideas.

    Best Regards,
    Sylvain

    [edit Nick Howitt] - Gitlab https://gitlab.com/clearos/clearfoundation/app-users/issues/9. Filed against app-users but it may not be the best place for it. [/edit]
    The reply is currently minimized Show
  • Accepted Answer

    Saturday, February 09 2019, 08:11 PM - #Permalink
    Resolved
    0 votes
    A dashboard for adding formatting and the removal of drives, including raid etc, under Linux this has allways been an issue, if windoze can make it easy, why not Linux. ?

    [edit Nick Howitt] - Gitlab https://gitlab.com/clearos/clearfoundation/app-storage/issues/3[/edit]
    The reply is currently minimized Show
  • Accepted Answer

    Friday, February 08 2019, 05:05 PM - #Permalink
    Resolved
    1 votes
    The Wireless interface brought back into IP settings and the AP app capable of supporting 802.11n and 802.11ac and multiple radios and NIC's (I believe some NICs declare two radios on a single interface and other declare themselves as 2 NICs when they support both bands simultaneously)

    [edit Nick Howitt]GitLab feature request[/edit]
    The reply is currently minimized Show
  • Accepted Answer

    Friday, February 08 2019, 03:54 PM - #Permalink
    Resolved
    0 votes
    Regular updates of the apps. Keeping a little bit on track with the updates of bought packages, like Kopano,etc...
    The reply is currently minimized Show
  • Accepted Answer

    Wednesday, February 06 2019, 10:50 PM - #Permalink
    Resolved
    0 votes
    Website Improvement - seems like a lot of new users don't get the message that their first post or two is moderated and will not appear immediately - so they try and try again re-posting...

    EDIT: Another one from the "Kernel 7.5" thread...
    People have problems uploading images when the resolution or size exceeds the limits - better feedback to the user that the upload failed and restate those limits... This seems a quite common problem when users upload an image for the first time...
    The reply is currently minimized Show
  • Accepted Answer

    Wednesday, February 06 2019, 05:12 PM - #Permalink
    Resolved
    1 votes
    A top level flexshare so you don't have to map the shares individually. Either optionally or always this should exclude the website shares.

    [edit Nick Howitt]GitLab feature request[/edit]
    The reply is currently minimized Show
  • Accepted Answer

    Monday, February 04 2019, 10:49 PM - #Permalink
    Resolved
    0 votes
    ClearOS Proxy Error Screen could be improved...

    At the moment if you mistype a url it shows you what you typed in the Web Address panel of the error screen - which is good...

    What is bad however, is that there is no means to correct it... If you use the browser back button the url is blank. The error screen doesn't allow you to copy the url. which would allow you to paste it back into the url bar and correct. The only option seems to start again and type the whole over... Even allowing one to copy the url in the Web Address field would be a help. Even better would be a field that shows what you typed with an edit facility to make amendments, and a "Go" button to try again...

    You are actually better off without the web proxy in this situation as you get a message like "This site can’t be reached" from the browser with a reason, and the unreachable url stays in the url address bar so you can amend and try again...

    [edit Nick Howitt] - Gitlab https://gitlab.com/clearos/clearfoundation/app-web-proxy/issues/4[/edit]
    The reply is currently minimized Show
  • Accepted Answer

    Sunday, February 03 2019, 02:41 PM - #Permalink
    Resolved
    1 votes
    definitely a way to block a device on MAC number in DHCP.
    Maybe in webconfig more feature to adjust settings. This is very limited now.

    [edit Nick Howitt] Gitlab https://gitlab.com/clearos/clearfoundation/app-dhcp/issues/4 [/edit]

    Account manager is not completly linked with some extensions/users. A tickbox would be great to enable features

    [edit Nick Howitt] Gitlab https://gitlab.com/clearos/clearfoundation/app-accounts/issues/2 [/edit]
    The reply is currently minimized Show
  • Accepted Answer

    Saturday, February 02 2019, 07:39 AM - #Permalink
    Resolved
    0 votes
    This Youtube video is very interesting @Dave. Also so the way Docker is heading on RHEL 8. Sander van Vugt is a Linux guy he also write books about Linux. I guess he works for RHEL? Thank you for leaving that link @Dave!

    Video about RHEL 8
    The reply is currently minimized Show
  • Accepted Answer

    Saturday, February 02 2019, 07:09 AM - #Permalink
    Resolved
    0 votes
    Can you make the forums password manager compatible?

    I use a password manger (Dashlane) and with the ClearOS forums the password manager doesn't work. In my opinion everyone should use a password manger these days and a forum or website should support / tested on that feature..

    I added this wish to my initial list.
    The reply is currently minimized Show
  • Accepted Answer

    Friday, February 01 2019, 08:53 PM - #Permalink
    Resolved
    0 votes
    Marcel van van Leeuwen wrote:
    Is that not a limitation of Windows 10. If I’m correct Microsoft removed some features. I have to Google regarding this.

    Yes. Win10 queries all DNS servers in parallel then takes the answer from the first to respond. This generally is not the one through the VPN. If you use a different LAN domain from your external domain you are OK. I don't. Mine are the same inside and out. Added to which, Clearcenter DNS (Tucows or Godaddy?) resolves wildcard subdomains, so for anything it does not explicitly know about, it still returns an IP address. There are different way's round but essentially they mean forcing the DNS through the VPN, slowing up your normal browsing or using the local hosts file.
    The reply is currently minimized Show
  • Accepted Answer

    Friday, February 01 2019, 08:38 PM - #Permalink
    Resolved
    0 votes
    Dirk Albring wrote:
    Hey Nick,

    I think we've talked about this SMB issue in a different thread, but the biggest problem I have is when openVPNing into our office's network. I have the rule implemented that you suggested. I am able to connect to the network. I am also able to access computers on the network, but only by entering their IP addresses in File Explorer's address bar (Windows 10). Browsing the network shows no network computers, but entering their IP address in the form of \\192.168.9.xxx will allow access to shared folders. You can alternately enter the computer name in the form of \\Computer_Name. While these methods work, you have to remember IP addresses or exact computer names. I don't have a Windows AD Server in house; just a bunch of Windows computers sharing the network. We do have one Ubuntu server with a mounted drive to store all the folders the office shares internally, i.e. cad files, MS Office files, pics, videos, etc. It is not used as a domain server on the network. Just storage. I would rather not jeopardize the network with down time by trying to implement a Windows server. I don't want to say anymore because Dave's thread was asking for suggested improvements and additions.


    Is that not a limitation of Windows 10. If I’m correct Microsoft removed some features. I have to Google regarding this.
    The reply is currently minimized Show
  • Accepted Answer

    Friday, February 01 2019, 05:25 PM - #Permalink
    Resolved
    0 votes
    Dirk Albring wrote:
    A simpler more concise integration of Samba with a Windows network. It’s horrific trying to get your ClearOS file server to work smoothly on your office’s Windows network...horrific. Especially horrific when trying to VPN into your office’s Windows network. A lot of times there’s a work around, but there’s always a lot of R&D to figure it out. I for one love R&D, but when I’m paying for a business solution I want it working out of the box.


    Can you elaborate on this? What problems have you faced?


    Hey Nick,

    I think we've talked about this SMB issue in a different thread, but the biggest problem I have is when openVPNing into our office's network. I have the rule implemented that you suggested. I am able to connect to the network. I am also able to access computers on the network, but only by entering their IP addresses in File Explorer's address bar (Windows 10). Browsing the network shows no network computers, but entering their IP address in the form of \\192.168.9.xxx will allow access to shared folders. You can alternately enter the computer name in the form of \\Computer_Name. While these methods work, you have to remember IP addresses or exact computer names. I don't have a Windows AD Server in house; just a bunch of Windows computers sharing the network. We do have one Ubuntu server with a mounted drive to store all the folders the office shares internally, i.e. cad files, MS Office files, pics, videos, etc. It is not used as a domain server on the network. Just storage. I would rather not jeopardize the network with down time by trying to implement a Windows server. I don't want to say anymore because Dave's thread was asking for suggested improvements and additions.



    Dirk Albring wrote:
    It would be nice to block all external traffic to MAC addresses (at my choosing) on my office network...I mean all external traffic...with an app designed to prevent any sort of tunneling that bypasses your gateway’s firewall. For example, a protocol filter to block the use of apps like psiphon. I know that’s a big wish.


    Gateway Management can do it - How to block Psiphon


    Your help link is specifically related to psiphon, which is great, but that was just an example. This is not to mention that the business solution of Gateway Management is around $400/year if memory serves me right. That along with all the other portal add-on subscriptions I'm paying for makes it unattractive. I don't feel like having an added office expense of a few grand a year for my gateway server. That would be another suggestion, Dave. Some way to make subscriptions more attractive in pricing.
    The reply is currently minimized Show
  • Accepted Answer

    Thursday, January 31 2019, 08:05 PM - #Permalink
    Resolved
    0 votes
    Dynamic VPN switch to IKEv2 so it can easily be set up to run behind NAT (and use some new features of Libreswan). Also make it compatible with the Static VPN (move the up_down script to the conn)

    [edit Nick Howitt] GitLab feature request (note the old tracker had no target version so was not transferred)[/edit]
    The reply is currently minimized Show
  • Accepted Answer

    Thursday, January 31 2019, 07:02 PM - #Permalink
    Resolved
    0 votes
    Awesome feedback everyone.

    I've compiled your answers here and have given some feedback:

    https://docs.google.com/document/d/14QllNp5OjRTyC9ejlf1gEGme6mmUCCinRJFOaZl6KO4/edit?usp=sharing

    Please give us more.
    The reply is currently minimized Show
  • Accepted Answer

    Thursday, January 31 2019, 11:06 AM - #Permalink
    Resolved
    0 votes
    Dirk Albring wrote:
    A simpler more concise integration of Samba with a Windows network. It’s horrific trying to get your ClearOS file server to work smoothly on your office’s Windows network...horrific. Especially horrific when trying to VPN into your office’s Windows network. A lot of times there’s a work around, but there’s always a lot of R&D to figure it out. I for one love R&D, but when I’m paying for a business solution I want it working out of the box.

    Can you elaborate on this? What problems have you faced?

    Re:VPN, was the solution to open the Windows firewall to the OpenVPN subnet? If so, you could try adding a ClearOS custom firewall rule:
    $IPTABLES -t nat -I POSTROUTING -s 10.8.0.0/24 -j MASQUERADE
    If that fixes the issue so you don't have to change the Windows firewall, I can add an enhancement request for a switch in the OpenVPN webconfig. The disadvantage of this is that if you provide central support to remote workers (VNC or RDP or something like that), it may stop you connecting to them from your work LAN. That would have to be tested and is why I suggest a switch. [edit Nick Howitt] - Gitlab https://gitlab.com/clearos/clearfoundation/app-openvpn/issues/4[/edit]

    Longer term, if you run an AD Domain Controller, I believe you can deploy firewall rules using RSAT/Group Policies and that would be the better way to go. You can't use RSAT with the current domain offering which uses old-style NT4 domains, however, if you see in this post Clearcenter are developing a full AD DC solution to run in a docker container in ClearOS. I have just installed ClearOS and Win10 in a VM. ClearOS is running as an AD DC and I have Win10 joined to its domain. I recently updated the howto and there seems to be only one residual issue from my testing.
    The reply is currently minimized Show
  • Accepted Answer

    Thursday, January 31 2019, 08:55 AM - #Permalink
    Resolved
    0 votes
    Dirk Albring wrote:
    It would be nice to block all external traffic to MAC addresses (at my choosing) on my office network...I mean all external traffic...with an app designed to prevent any sort of tunneling that bypasses your gateway’s firewall. For example, a protocol filter to block the use of apps like psiphon. I know that’s a big wish.

    Gateway Management can do it - How to block Psiphon
    The reply is currently minimized Show
  • Accepted Answer

    Thursday, January 31 2019, 05:31 AM - #Permalink
    Resolved
    1 votes
    ClearOS needs a working mail forwarding method. While Kopano is a beautiful alternative/compliment to Outlook and exceeds Zarafa to some extent, it has it’s bugs when integrated with ClearOS. One that stands out is mail forwarding to external accounts. I think with regard to Kopano, this is a bug in their system, so why not have a method apart from Kopano? The beta hook that you guys experimented with at one time was almost good. Maybe get that working smoothly?

    A simpler more concise integration of Samba with a Windows network. It’s horrific trying to get your ClearOS file server to work smoothly on your office’s Windows network...horrific. Especially horrific when trying to VPN into your office’s Windows network. A lot of times there’s a work around, but there’s always a lot of R&D to figure it out. I for one love R&D, but when I’m paying for a business solution I want it working out of the box. [edit Nick Howitt] - Gitlab feature request filed against OpenVPN https://gitlab.com/clearos/clearfoundation/app-openvpn/issues/4.[/edit]

    It would be nice to block all external traffic to MAC addresses (at my choosing) on my office network...I mean all external traffic...with an app designed to prevent any sort of tunneling that bypasses your gateway’s firewall. For example, a protocol filter to block the use of apps like psiphon. I know that’s a big wish.

    Is there a reason you took Awstats out of the available apps in the Marketplace and ultimately out of the Webconfig? I’m probably behind in the times. You probably removed it back in the Clark Connect days, but it’d be a nice compliment to the web server configuration in the Webconfig. Kinda but not quite like having Mariadb in the Webconfig. [edit Nick Howitt] - Gitlab https://gitlab.com/clearos/feature-requests/issues/68.[/edit]

    I have yet to find a link to my Clear Center account from within the Webconfig. Seems trivial, I know, but it’d be nice. [edit Nick Howitt] - Gitlab https://gitlab.com/clearos/clearfoundation/app-registration/issues/6[/edit]

    I’ll help on the forum as I’m able. It helps when you have a working system or two in place, which I do (knock on wood). It’s hard to help the community some times without a system to try things out on.

    More later...
    The reply is currently minimized Show
  • Accepted Answer

    Tuesday, January 29 2019, 11:30 PM - #Permalink
    Resolved
    0 votes
    Obviously agree Marcel's comments regarding the forum software... additional points...
    1. get a better search function - the existing one is pathetic.
    2. Fix the reported bugs - simple example - we still see emoticons where they should not be - there is an example of this nonsense today in the post about mail at example.com - assuming it is not edited - so will repeat a line just in case
    main.cf:#local_recipient_maps = unix:passwd.byname $alias_maps
    Some sites require emticons to be within square brackets - not sure if this would help these forums - let's try it [:(]
    Edit: Nope - still fails...

    Version 8.x - just a few to start with
    1. ldap - "openldap-servers" is a removed package - what is the replacement? (a welcome loss as ldap was the most unreliable aspect of ClearOS of my systems)...
    2. Multiple ClearOS server environment - name server and dhcpd functionality.With dnsmasq if the one server providing these services is down for whatever reason - they are lost unless another system is manually re-configured, and even then it has no knowledge of existing dhcp leases, and the name servers details have to be manually synchronized between them. [edit Nick Howitt] - Gitlab https://gitlab.com/clearos/feature-requests/issues/67[/edit]
    3. Better certificate management... - 7.x is a hotchpotch of webconfig and manual changes, even with lets-encrypt
    4. IPv6 needs refinement from what is in 7.x [edit Nick Howitt] - Gitlab https://gitlab.com/clearos/clearfoundation/app-network/issues/16[/edit]
    5. Less noise in /var/log/messages [edit Nick Howitt] - Gitlab https://gitlab.com/clearos/clearfoundation/app-base/issues/9 aginst app-base but could be wrongly categorised.[/edit]
    6. Section "8.1.1. Removed device drivers" in the RHEl 8.0 Beta Release Notes shows a large number of older devices no longer supported. If kmod drivers for these old devices appear - it would be nice if ClearOS has finally migrated to the standard kernel to obviate the next for custom kmod compilation...

    [edit Nick Howitt]
    For items not yet added, see comment in later post.
    [/edit]
    The reply is currently minimized Show
  • Accepted Answer

    Tuesday, January 29 2019, 08:47 PM - #Permalink
    Resolved
    0 votes
    Hi Dave, I have no problems with helping this community. I miss the days when we had a little bit more of activity on the forums. I appreciate that Nick is still around. Some point what crossed my mind below. If i have more point I'll let you know.



    Regarding the Forums:



    Faster forums (important!). The ClearOS forums in my country are slow, and with slow forums people will leave!

    Other forum software (not sure which, but after using it awhile I'm not a fan of the current forums).

    Interaction with the developers so they know what is going on in the community.

    More active members.

    A way to do a preview of my post before I post to the forums. This is also very handy for not native English speaking people.

    Can you make the website / forums password manager compatible.



    Regarding ClearOS 8:


    I want Docker!!!! [edit Nick Howitt] - Gitlab https://gitlab.com/clearos/feature-requests/issues/51[/edit]

    A way to make a pool of several drives thus one directory consists of several drives (OverlayFS). [edit Nick Howitt] - Gitlab https://gitlab.com/clearos/feature-requests/issues/50[/edit]

    ZFS is maybe a interesting option for the future now Redhat ditched BTRFS, but only when we can do RAIDZ expansion (This feature is coming). [edit Nick Howitt] - Gitlab https://gitlab.com/clearos/feature-requests/issues/55[/edit]

    ClearSHARE looks interesting... [edit Nick Howitt]- Gitlab https://gitlab.com/clearos/feature-requests/issues/54[/edit]
    The reply is currently minimized Show
Your Reply