home.social

#opnsense — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #opnsense, aggregated by home.social.

fetched live
  1. Survived the next spike! Seems it is really under control. Eventually I'll have to figure out how much memory this translates to.

    #Tor #Opnsense

  2. 🚀 How to Deploy #OPNsense on a Rad Web Hosting #VPS

    This guide demonstrates how to deploy OPNsense on a Rad Web Hosting VPS. This guide is tailored specifically for Rad Web Hosting VPS infrastructure, including /32 IP addressing, KVM ...
    Continued 👉 #opensource #selfhosting #selfhosted

    🚀 How to Deploy OPNsense on a ...

  3. Finally finally I've actually been at home (well, not quite, my wife had to survive 15-20 mins without iwebs) when #OPNsense had another Tor meltdown. The good thing is that there’s a window when the machine is not completely stuck, so I figured out the right max nmbcluster-value, by being able to test it immediately since when I restart Tor, it’d immediately spool up to the full load!

    Observation: after 650.000 clusters it stabilises as Tor’s internal load-balancing kicks in.

    #FreeBSD #Tor

  4. Okay, time for the OPNsense 26.7 update. I will be gone for a while. Hopefully only a little while. 😅

    #HomeLab #OPNsense

  5. Anyone know how to make file deletion "take" on a RAM mount/tmpfs on FreeBSD?

    OPNsense is set to log to RAM to save SSD write cycles. I've cleared out the offending file but `df` is still showing 100% utilization and processes are still failing to write.

    Edit: seems nginx was holding a file open and disk exhaustion was blocking service restart. A full stop and start of nginx cleared it

    #OPNsense #FreeBSD #BSD

  6. @Viss thanks to their toxic behaviour towards #opnsense a while ago i switched fully to deciso appliances and never looked back ;)

  7. RE: social.stefanberger.net/@stefa

    Looks like I‘m running #OPNsense since 3.5 years now. Before that I was using #pfSense.
    All running on the same #Protectli FW4B box, which replaced my FRITZ!box 5.5 years ago.
    All running fine. Knock on wood

    #homelab

  8. @dbauer
    Congrats!

    /59 still a weird choice but better than /62 by default with their CPE

    #opnsense #ipv6

  9. It is with great pleasure, that I can announce, that I sucessfully jumped through all the hoops Vodafone provided me.
    Now my #opnsense is finally properly setup with public ipv4 without cgnat & an /59 #ipv6 prefix so that all my clients get ULA & GUA via identity association & router advertisements.

  10. Durch Zufall bin ich auf Informationen zu den Hagezi-Blocklisten gestoßen. Aktuell gibt es offenbar ein Problem, das auf eine Sperre durch Microsoft auf GitHub zurückzuführen ist. Die Entwickler bauen gerade alternative Pools neu auf.

    #hagezi #filterlisten #opnsense #adguard #Blocklisten #github #ads #dns #Filter #Microsoft #DNSBunker

    forum.opnsense.org/index.php?t

  11. 🛡️ Antiphishing is now officially available in @opnsense.org (@suricata IDPS)

    OPNsense 26.7.2, released today, includes:

    `os-intrusion-detection-content-at-antiphishing 1.0`

    The plugin integrates the Antiphishing Suricata ruleset into the OPNsense ecosystem.

    This is another step toward making community-driven Threat Intelligence directly consumable at the network enforcement layer.

    Current ecosystem integration:

    • Suricata / suricata-update
    • OPNsense
    • pfSense PR in progress

    The project also recently added NRD-based threat intelligence for proactive phishing infrastructure detection (Suspect domains).

    📖 OPNsense Quick Guide

    For users who want to enable the ruleset on OPNsense 26.7.2:

    Quick Guide — Installing Antiphishing on OPNsense 26.7.2

    Project:
    github.com/julioliraup/Antiphi

    Vector / CTI dashboard:
    julioliraup.github.io/AT/

    #Suricata #OPNsense #ThreatIntelligence #CTI #DetectionEngineering #IDS #IPS #OpenSource

  12. PSA, hold off updating to #OPNsense 26.7.2 if your device has Realtek NICs in it, either VM pass-through or bare metal. Lots of people reporting kernel problems and boot loops.

    forum.opnsense.org/index.php?t

  13. I get 900/100 service from my ISP, Zen, but that's irrelevant, as we're dealing with the layer 2 connection between the proxmox NIC and the ONT.

    If I force the link speed on the proxmox NIC to speed=2500 I get an error about the driver not supporting forced settings, and the link goes down. It only comes back up if I set it to auto again.

    Like I say, I'm only on a 900/100 package from Zen, but I'd still expect the NIC and ONT to negotiate a 2.5Gb/s link 🤔

    #OPNsense #proxmox #openreach

  14. Question for anyone out there running a combination of #OPNsense (26.7.1) as a guest on #proxmox (9.2.10) with #openreach fibre:

    Does your external NIC negotiate 2.5Gb/s with the openreach ONT?

    Mine only negotiates 1Gb/s, even though it's an Intel I225-V (rev 3) NIC that is 2.5GbE capable, as is the ONT.

    The NIC is not passed through to the OPNsense guest, it's on a Linux bridge in proxmox with the guest given a virtual NIC on the bridge. OPNsense sees the vnic as 10Gb/s

  15. I'm a little disappointed that the #OPNsense crew decided to leave the #Zabbix agent out of their libraries...

    Ok.. Not a little, a LOT

    Just had to configure SNMP on my firewall because someone couldn't be arsed to port the agent to the new version...

    Hey, OPNsense crew, #BringBackZabbixAgent, prettyplease.

  16. My opnsense now deploys valid certs to my Fritzbox too. ✅
    Chrome seems to cache that old selfsigned cert. Vivaldi shows it is valid.
    #opnsense #acmesh #letsencrypt #httpseverywere #fritzbox

  17. 🚀 How to Deploy #OPNsense on a Rad Web Hosting #VPS

    This guide demonstrates how to deploy OPNsense on a Rad Web Hosting VPS. This guide is tailored specifically for Rad Web Hosting VPS infrastructure, including /32 IP addressing, KVM ...
    Continued 👉 #opensource #selfhosting #selfhosted

    🚀 How to Deploy OPNsense on a ...

  18. @happyborg

    Internally. Like a local intranet page only available to the local network.

    Wait, can I do local certificates in #OpnSense? Is that like a local certificate authority? Or is that only for OpnSense itself? Guess I'll look at that a little closer.