home.social

#netgate — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #netgate, aggregated by home.social.

fetched live
  1. I've decided to take the leap and update my #NetGate #pfSense box to 26.03-RELEASE. Here's hoping it's stable and doesn't do all the random lockups I was seeing that kept me on 24.0x

  2. I've decided to take the leap and update my #NetGate #pfSense box to 26.03-RELEASE. Here's hoping it's stable and doesn't do all the random lockups I was seeing that kept me on 24.0x

  3. pfSense Plus 26.03 (still a Relase Candidate) adds a “Certificate Profile” field to the Certificate Services interface. If you’re using Let’s Encrypt you can put in “shortlived” to switch to six-day certs on your web UI, HAProxy, etc. #pfSense #pfSensePlus #Netgate

  4. pfSense Plus 26.03 (still a Relase Candidate) adds a “Certificate Profile” field to the Certificate Services interface. If you’re using Let’s Encrypt you can put in “shortlived” to switch to six-day certs on your web UI, HAProxy, etc. #pfSense #pfSensePlus #Netgate

  5. @ij
    Was mich bei #pfSense zunehmends mehr stört, ist der kontinuierlich steigende Druck zur #Monetarisierung seitens #netgate. Als Nutzer der CE biste immer mehr benachteiligt, und das wird so auch bewusst weiter voran getrieben. An Images kommt man nur noch mit einem Login und auch Supportinformationen im öffentlichen Forum sind nicht mehr uneingeschränkt einsehbar.

    Auch der Zwang zur Online-Installation ist dadurch motiviert und schafft für den Nutzer erhebliche Problemfälle. Beispielsweise, wenn man per #Terraform eine ganze Systemlandschaft hinter einer Firewall aufbauen möchte. Das wird dann echt zum Krampf.

  6. @ij
    Was mich bei #pfSense zunehmends mehr stört, ist der kontinuierlich steigende Druck zur #Monetarisierung seitens #netgate. Als Nutzer der CE biste immer mehr benachteiligt, und das wird so auch bewusst weiter voran getrieben. An Images kommt man nur noch mit einem Login und auch Supportinformationen im öffentlichen Forum sind nicht mehr uneingeschränkt einsehbar.

    Auch der Zwang zur Online-Installation ist dadurch motiviert und schafft für den Nutzer erhebliche Problemfälle. Beispielsweise, wenn man per #Terraform eine ganze Systemlandschaft hinter einer Firewall aufbauen möchte. Das wird dann echt zum Krampf.

  7. Kaum macht man es richtig, schon funktioniert's. Wer hätte das ahnen können!?!

    In Ruhe vorbereitet auf einem Testsystem, habe ich jetzt die exportierte config.xml überarbeitet und dabei die Einträge für openvpn, ipsec und outbound NAT entfernt. Das ließ sich auf einer frisch installierten #pfSense 2.8.1 importieren und ich bin wieder im Rennen.

    Trotzdem werde ich mir mittelfristig ansehen, ob ich nicht besser zu #opnSense migriere. In den letzten Jahren hat Firma #netgate einiges in eine Richtung gelenkt, die mir nicht gefällt.

  8. Kaum macht man es richtig, schon funktioniert's. Wer hätte das ahnen können!?!

    In Ruhe vorbereitet auf einem Testsystem, habe ich jetzt die exportierte config.xml überarbeitet und dabei die Einträge für openvpn, ipsec und outbound NAT entfernt. Das ließ sich auf einer frisch installierten #pfSense 2.8.1 importieren und ich bin wieder im Rennen.

    Trotzdem werde ich mir mittelfristig ansehen, ob ich nicht besser zu #opnSense migriere. In den letzten Jahren hat Firma #netgate einiges in eine Richtung gelenkt, die mir nicht gefällt.

  9. pfSense Plus 2025.11.1 is out with some bug fixes and changes including reduced TLS certificate lifetime. I had no issues remotely updating my 2100. #pfSense #pfSensePlus #Netgate docs.netgate.com/pfsense/relea

  10. pfSense Plus 2025.11.1 is out with some bug fixes and changes including reduced TLS certificate lifetime. I had no issues remotely updating my 2100. #pfSense #pfSensePlus #Netgate docs.netgate.com/pfsense/relea

  11. For anyone using #pfsense, I wrote this little converter [1] that takes the xml and generates a #Markdown file for each interface and its firewall rules. It also generates an alias.md file that has flags of whether that alias is dead/ unused or not.

    At $DAYJOB, we have to audit our firewall rules on a recurring basis, and this is a good way for us to update our docs quicker.

    [1] gitlab.com/jeremygonyea/pfsens

    #netgate #pfsese #exporters #audit #sysadmin

  12. For anyone using #pfsense, I wrote this little converter [1] that takes the xml and generates a #Markdown file for each interface and its firewall rules. It also generates an alias.md file that has flags of whether that alias is dead/ unused or not.

    At $DAYJOB, we have to audit our firewall rules on a recurring basis, and this is a good way for us to update our docs quicker.

    [1] gitlab.com/jeremygonyea/pfsens

    #netgate #pfsese #exporters #audit #sysadmin

  13. After another major change to my #NetGate setup, I finally remembered to save another damned local backup. I'm still a little amused at the 4ish whole megabytes it's worried about when I back up RRD data as well.

  14. After another major change to my #NetGate setup, I finally remembered to save another damned local backup. I'm still a little amused at the 4ish whole megabytes it's worried about when I back up RRD data as well.

  15. The beta cycle has started for pfSense Plus 25.11. There don’t seem to be any release notes yet but here are the open bugs. redmine.pfsense.org/versions/82 #Netgate #pfSense #pfSensePlus

  16. The beta cycle has started for pfSense Plus 25.11. There don’t seem to be any release notes yet but here are the open bugs. redmine.pfsense.org/versions/82 #Netgate #pfSense #pfSensePlus

  17. pfSense Plus 25.07 release candidate is out! I updated my Negate 2100 and everything seems good so far. #Netgate #pfSense #pfSensePlus docs.netgate.com/pfsense/relea

  18. pfSense Plus 25.07 release candidate is out! I updated my Negate 2100 and everything seems good so far. #Netgate #pfSense #pfSensePlus docs.netgate.com/pfsense/relea

  19. 🦾 Why I use OPNsense over pfSense, and why I don't trust Netgate at all • Adam Conway

    「 From domain disputes, licensing changes, security issues, and more, there's a lot that simply doesn't sit right with me. That's not to say that OPNsense is perfect, but the company's negatively perceived actions have not been anywhere near as controversial 」

    xda-developers.com/why-use-opn

    #OPNsense #pfSense #freebsd #netgate

  20. 🦾 Why I use OPNsense over pfSense, and why I don't trust Netgate at all • Adam Conway

    「 From domain disputes, licensing changes, security issues, and more, there's a lot that simply doesn't sit right with me. That's not to say that OPNsense is perfect, but the company's negatively perceived actions have not been anywhere near as controversial 」

    xda-developers.com/why-use-opn

    #OPNsense #pfSense #freebsd #netgate

  21. Hey Fedi, was ist denn Deine Meinung zu #Netgate Firewalls? Ich würde gerne mein Heimnetz etwas besser unter Kontrolle bringen und unnötige Trackingkommunikation von "smarten" Geräten unterbinden und am liebsten auch die ganzen anderen Privacy-feindlichen Vorgänge, denen man täglich so ausgesetzt ist, schon auf Netzwerkebene blockieren. Taugen die Geräte von Netgate was oder ist das überteuert? Wie geht Ihr mit dieser Sache um? Ist-Zustand ist sehr basic: Bislang habe ich nur eine Fritzbox, AVM-Mesh-APs und ein paar unmanaged Switches für die Ethernetkabel.

    #followerpower #firewall #privacy #fragfedi #boost

  22. Hey Fedi, was ist denn Deine Meinung zu #Netgate Firewalls? Ich würde gerne mein Heimnetz etwas besser unter Kontrolle bringen und unnötige Trackingkommunikation von "smarten" Geräten unterbinden und am liebsten auch die ganzen anderen Privacy-feindlichen Vorgänge, denen man täglich so ausgesetzt ist, schon auf Netzwerkebene blockieren. Taugen die Geräte von Netgate was oder ist das überteuert? Wie geht Ihr mit dieser Sache um? Ist-Zustand ist sehr basic: Bislang habe ich nur eine Fritzbox, AVM-Mesh-APs und ein paar unmanaged Switches für die Ethernetkabel.

    #followerpower #firewall #privacy #fragfedi #boost

  23. #Netgate #pfSense CE 2.8.0 is here! I knew it was on the way, but wouldn’t have placed any bets on it beating 25.03 out the gate. netgate.com/blog/netgate-relea

  24. #Netgate #pfSense CE 2.8.0 is here! I knew it was on the way, but wouldn’t have placed any bets on it beating 25.03 out the gate. netgate.com/blog/netgate-relea

  25. Something strange with my #Unifi gear...

    Recently replaced my UDM Pro with a CloudKey Gen2 Plus (because I don't need the gateway function as my #Netgate #pfSense is taking care of this).

    According to the screenshot, my WiFi APs are offline as well as the Protect cameras.
    But: both are working.

    Maybe that's because of the "management" VLAN 31 instead of default VLAN 1?

  26. Something strange with my #Unifi gear...

    Recently replaced my UDM Pro with a CloudKey Gen2 Plus (because I don't need the gateway function as my #Netgate #pfSense is taking care of this).

    According to the screenshot, my WiFi APs are offline as well as the Protect cameras.
    But: both are working.

    Maybe that's because of the "management" VLAN 31 instead of default VLAN 1?

  27. Just realized that my #pfSense #Netgate 6100 has 4x 2.5 GbE ports. At least my #Unifi switch reports 2.5 GbE now... before connecting to the switch those ports were connected to the UDM Pro, which only has 1 GbE...

  28. Just realized that my #pfSense #Netgate 6100 has 4x 2.5 GbE ports. At least my #Unifi switch reports 2.5 GbE now... before connecting to the switch those ports were connected to the UDM Pro, which only has 1 GbE...

  29. Ok so you're telling me i have to run beta code on my production appliance to get a *security fix*??? Fuck all the way off with that. #pfsense #netgate

  30. Ok so you're telling me i have to run beta code on my production appliance to get a *security fix*??? Fuck all the way off with that. #pfsense #netgate

  31. I‘m reworking my #homelab rack setup. First two pics are before (from last year), the other two pics are the result of todays work. Alas, some cables need to be exchanged, though…

    Lately I replaced the # Unifi Standard 24 PoE switch with Pro HD 24 PoE with Etherlighting. And the #Netgate 6100 #pfsense has replaced the UDM Pro as gateway and Firewall…

    EDIT:
    the A1000 and the Indy were removed from the rack. The UPS and the server moved some RUs higher. The purpose of the upper patch panel is to be able to use the short cables from above/below. In the back the connection goes hidden from the Pfsense to the UDM Pro ports.

    Only annoyance: Why is are the port of the Unifi patch panel not labeled?! Hmpf...

  32. I‘m reworking my #homelab rack setup. First two pics are before (from last year), the other two pics are the result of todays work. Alas, some cables need to be exchanged, though…

    Lately I replaced the # Unifi Standard 24 PoE switch with Pro HD 24 PoE with Etherlighting. And the #Netgate 6100 #pfsense has replaced the UDM Pro as gateway and Firewall…

    EDIT:
    the A1000 and the Indy were removed from the rack. The UPS and the server moved some RUs higher. The purpose of the upper patch panel is to be able to use the short cables from above/below. In the back the connection goes hidden from the Pfsense to the UDM Pro ports.

    Only annoyance: Why is are the port of the Unifi patch panel not labeled?! Hmpf...

  33. #pfsense service toot:

    Using #ACME certificates on your #freeradius for wifi authentication and things stop working after 60 days when the cert renews?

    in the acme configuration add the follwing php-command to the actions list:

    require_once('/usr/local/pkg/freeradius.inc'); freeradius_eapconf_resync(true);

    (Long time lingering bug in pfsense, #netgate is not willing to fix)

  34. #pfsense service toot:

    Using #ACME certificates on your #freeradius for wifi authentication and things stop working after 60 days when the cert renews?

    in the acme configuration add the follwing php-command to the actions list:

    require_once('/usr/local/pkg/freeradius.inc'); freeradius_eapconf_resync(true);

    (Long time lingering bug in pfsense, #netgate is not willing to fix)

  35. I'm coming into the #pfsense vs #opnsense debate way late, and I'm too ignorant to take a side right now. I did get a #netgate box on a recommendation, that's currently sitting in my desk only hooked up to a serial console.

    But otherwise, no skin in the game currently.