home.social

#opnsense — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #opnsense, aggregated by home.social.

fetched live
  1. @tux Hier mal Grafisch die CPU Auslastung (ca 35%) . Habe als #Plugin und Service #Crowdsec #qFeeds #Adguard #Home als größe Position u.a. installiert.

    #OPNsense

  2. @tux Hier mal Grafisch die CPU Auslastung (ca 35%) . Habe als #Plugin und Service #Crowdsec #qFeeds #Adguard #Home als größe Position u.a. installiert.

    #OPNsense

  3. @tux Ich habe dafür "CWWK Mini PC N150 (Upgraded N100) Firewall Appliance" bei Amazon gekauft. Sparsam (Strom) aber Leistungsfähig. Für die gängigen #OPNsense Plugins langt es allemal. Mit einem I5 kann es aber nicht mithalten. Eventuell auf eine stärkere CPU setzen. Alternativ "Protectli"

    Achja, das ist keine Verkaufsberatung^^

  4. @tux Ich habe dafür "CWWK Mini PC N150 (Upgraded N100) Firewall Appliance" bei Amazon gekauft. Sparsam (Strom) aber Leistungsfähig. Für die gängigen #OPNsense Plugins langt es allemal. Mit einem I5 kann es aber nicht mithalten. Eventuell auf eine stärkere CPU setzen. Alternativ "Protectli"

    Achja, das ist keine Verkaufsberatung^^

  5. Hallo Fediverse, ich habe mal eine Frage: Ich suche für OPNsense einen Ersatz für meine defekte IPU 662 (nrg-systems.de/produkte/ipu662…).

    Voraussetzungen sind:
    - 4 x LAN
    - HDMI
    - USB
    - Genug Power für IDS, Crowdsec, ....

    Was könnt ihr mir da empfehlen?
    Gerne kann dieser Beitrag geteilt werden.

    #Followerpower #FragDasFediverse #Hardware #Firewall #OPNsense

  6. Hallo Fediverse, ich habe mal eine Frage: Ich suche für OPNsense einen Ersatz für meine defekte IPU 662 (nrg-systems.de/produkte/ipu662…).

    Voraussetzungen sind:
    - 4 x LAN
    - HDMI
    - USB
    - Genug Power für IDS, Crowdsec, ....

    Was könnt ihr mir da empfehlen?
    Gerne kann dieser Beitrag geteilt werden.

    #Followerpower #FragDasFediverse #Hardware #Firewall #OPNsense

  7. Bin gerade dabei mit den #Shapers unter #OPNsense zu experimentieren. Interessant. Sieht einfacher aus als es ist. Wichtig zu erkennen: was ist IN und was ist OUT.

    #Firewall #Bandbreitenbegrenzung

  8. Bin gerade dabei mit den #Shapers unter #OPNsense zu experimentieren. Interessant. Sieht einfacher aus als es ist. Wichtig zu erkennen: was ist IN und was ist OUT.

    #Firewall #Bandbreitenbegrenzung

  9. Yay. BGP advertisements for a network that was available only on one routeros box to my main router running opnsense is working now :)
    #learning #bgp #routeros #mikrotik #opnsense #homelab

  10. Yay. BGP advertisements for a network that was available only on one routeros box to my main router running opnsense is working now :)
    #learning #bgp #routeros #mikrotik #opnsense #homelab

  11. Yay. BGP advertisements for a network that was available only on one routeros box to my main router running opnsense is working now :)
    #learning #bgp #routeros #mikrotik #opnsense #homelab

  12. Survived the next spike! Seems it is really under control. Eventually I'll have to figure out how much memory this translates to.

    #Tor #Opnsense

  13. Survived the next spike! Seems it is really under control. Eventually I'll have to figure out how much memory this translates to.

    #Tor #Opnsense

  14. Survived the next spike! Seems it is really under control. Eventually I'll have to figure out how much memory this translates to.

    #Tor #Opnsense

  15. 🚀 How to Deploy #OPNsense on a Rad Web Hosting #VPS

    This guide demonstrates how to deploy OPNsense on a Rad Web Hosting VPS. This guide is tailored specifically for Rad Web Hosting VPS infrastructure, including /32 IP addressing, KVM ...
    Continued 👉 #opensource #selfhosting #selfhosted

    🚀 How to Deploy OPNsense on a ...

  16. 🚀 How to Deploy #OPNsense on a Rad Web Hosting #VPS

    This guide demonstrates how to deploy OPNsense on a Rad Web Hosting VPS. This guide is tailored specifically for Rad Web Hosting VPS infrastructure, including /32 IP addressing, KVM ...
    Continued 👉 #opensource #selfhosting #selfhosted

    🚀 How to Deploy OPNsense on a ...

  17. Finally finally I've actually been at home (well, not quite, my wife had to survive 15-20 mins without iwebs) when #OPNsense had another Tor meltdown. The good thing is that there’s a window when the machine is not completely stuck, so I figured out the right max nmbcluster-value, by being able to test it immediately since when I restart Tor, it’d immediately spool up to the full load!

    Observation: after 650.000 clusters it stabilises as Tor’s internal load-balancing kicks in.

    #FreeBSD #Tor

  18. Finally finally I've actually been at home (well, not quite, my wife had to survive 15-20 mins without iwebs) when #OPNsense had another Tor meltdown. The good thing is that there’s a window when the machine is not completely stuck, so I figured out the right max nmbcluster-value, by being able to test it immediately since when I restart Tor, it’d immediately spool up to the full load!

    Observation: after 650.000 clusters it stabilises as Tor’s internal load-balancing kicks in.

    #FreeBSD #Tor

  19. Finally finally I've actually been at home (well, not quite, my wife had to survive 15-20 mins without iwebs) when #OPNsense had another Tor meltdown. The good thing is that there’s a window when the machine is not completely stuck, so I figured out the right max nmbcluster-value, by being able to test it immediately since when I restart Tor, it’d immediately spool up to the full load!

    Observation: after 650.000 clusters it stabilises as Tor’s internal load-balancing kicks in.

    #FreeBSD #Tor

  20. Okay, time for the OPNsense 26.7 update. I will be gone for a while. Hopefully only a little while. 😅

    #HomeLab #OPNsense

  21. Okay, time for the OPNsense 26.7 update. I will be gone for a while. Hopefully only a little while. 😅

    #HomeLab #OPNsense

  22. Okay, time for the OPNsense 26.7 update. I will be gone for a while. Hopefully only a little while. 😅

    #HomeLab #OPNsense

  23. Anyone know how to make file deletion "take" on a RAM mount/tmpfs on FreeBSD?

    OPNsense is set to log to RAM to save SSD write cycles. I've cleared out the offending file but `df` is still showing 100% utilization and processes are still failing to write.

    Edit: seems nginx was holding a file open and disk exhaustion was blocking service restart. A full stop and start of nginx cleared it

    #OPNsense #FreeBSD #BSD

  24. Anyone know how to make file deletion "take" on a RAM mount/tmpfs on FreeBSD?

    OPNsense is set to log to RAM to save SSD write cycles. I've cleared out the offending file but `df` is still showing 100% utilization and processes are still failing to write.

    Edit: seems nginx was holding a file open and disk exhaustion was blocking service restart. A full stop and start of nginx cleared it

    #OPNsense #FreeBSD #BSD

  25. Anyone know how to make file deletion "take" on a RAM mount/tmpfs on FreeBSD?

    OPNsense is set to log to RAM to save SSD write cycles. I've cleared out the offending file but `df` is still showing 100% utilization and processes are still failing to write.

    Edit: seems nginx was holding a file open and disk exhaustion was blocking service restart. A full stop and start of nginx cleared it

    #OPNsense #FreeBSD #BSD

  26. So in my Proxmox cluster, I've been putting off the upgrade from PVE 8 to PVE 9 for awhile, and last weekend I updated one of my lesser-used nodes (just running my Minecraft server) and verified everything is fine. Tonight was my node that's running Home Assistant and other stuff, and afterwards I was planning the host running my OPNsense instance.

    Turns out that last one was already on PVE 9 when I set it up! That's one source of stress out of the way!

    #homelab #proxmox #OPNsense #maintenance

  27. @Viss thanks to their toxic behaviour towards #opnsense a while ago i switched fully to deciso appliances and never looked back ;)

  28. @Viss thanks to their toxic behaviour towards #opnsense a while ago i switched fully to deciso appliances and never looked back ;)

  29. @Viss thanks to their toxic behaviour towards #opnsense a while ago i switched fully to deciso appliances and never looked back ;)

  30. RE: social.stefanberger.net/@stefa

    Looks like I‘m running #OPNsense since 3.5 years now. Before that I was using #pfSense.
    All running on the same #Protectli FW4B box, which replaced my FRITZ!box 5.5 years ago.
    All running fine. Knock on wood

    #homelab

  31. RE: social.stefanberger.net/@stefa

    Looks like I‘m running #OPNsense since 3.5 years now. Before that I was using #pfSense.
    All running on the same #Protectli FW4B box, which replaced my FRITZ!box 5.5 years ago.
    All running fine. Knock on wood

    #homelab

  32. RE: social.stefanberger.net/@stefa

    Looks like I‘m running #OPNsense since 3.5 years now. Before that I was using #pfSense.
    All running on the same #Protectli FW4B box, which replaced my FRITZ!box 5.5 years ago.
    All running fine. Knock on wood

    #homelab

  33. @dbauer
    Congrats!

    /59 still a weird choice but better than /62 by default with their CPE

    #opnsense #ipv6

  34. @dbauer
    Congrats!

    /59 still a weird choice but better than /62 by default with their CPE

    #opnsense #ipv6

  35. It is with great pleasure, that I can announce, that I sucessfully jumped through all the hoops Vodafone provided me.
    Now my #opnsense is finally properly setup with public ipv4 without cgnat & an /59 #ipv6 prefix so that all my clients get ULA & GUA via identity association & router advertisements.

  36. It is with great pleasure, that I can announce, that I sucessfully jumped through all the hoops Vodafone provided me.
    Now my #opnsense is finally properly setup with public ipv4 without cgnat & an /59 #ipv6 prefix so that all my clients get ULA & GUA via identity association & router advertisements.

  37. Durch Zufall bin ich auf Informationen zu den Hagezi-Blocklisten gestoßen. Aktuell gibt es offenbar ein Problem, das auf eine Sperre durch Microsoft auf GitHub zurückzuführen ist. Die Entwickler bauen gerade alternative Pools neu auf.

    #hagezi #filterlisten #opnsense #adguard #Blocklisten #github #ads #dns #Filter #Microsoft #DNSBunker

    forum.opnsense.org/index.php?t

  38. Durch Zufall bin ich auf Informationen zu den Hagezi-Blocklisten gestoßen. Aktuell gibt es offenbar ein Problem, das auf eine Sperre durch Microsoft auf GitHub zurückzuführen ist. Die Entwickler bauen gerade alternative Pools neu auf.

    #hagezi #filterlisten #opnsense #adguard #Blocklisten #github #ads #dns #Filter #Microsoft #DNSBunker

    forum.opnsense.org/index.php?t

  39. 🛡️ Antiphishing is now officially available in @opnsense.org (@suricata IDPS)

    OPNsense 26.7.2, released today, includes:

    `os-intrusion-detection-content-at-antiphishing 1.0`

    The plugin integrates the Antiphishing Suricata ruleset into the OPNsense ecosystem.

    This is another step toward making community-driven Threat Intelligence directly consumable at the network enforcement layer.

    Current ecosystem integration:

    • Suricata / suricata-update
    • OPNsense
    • pfSense PR in progress

    The project also recently added NRD-based threat intelligence for proactive phishing infrastructure detection (Suspect domains).

    📖 OPNsense Quick Guide

    For users who want to enable the ruleset on OPNsense 26.7.2:

    Quick Guide — Installing Antiphishing on OPNsense 26.7.2

    Project:
    github.com/julioliraup/Antiphi

    Vector / CTI dashboard:
    julioliraup.github.io/AT/

    #Suricata #OPNsense #ThreatIntelligence #CTI #DetectionEngineering #IDS #IPS #OpenSource

  40. 🛡️ Antiphishing is now officially available in @opnsense.org (@suricata IDPS)

    OPNsense 26.7.2, released today, includes:

    `os-intrusion-detection-content-at-antiphishing 1.0`

    The plugin integrates the Antiphishing Suricata ruleset into the OPNsense ecosystem.

    This is another step toward making community-driven Threat Intelligence directly consumable at the network enforcement layer.

    Current ecosystem integration:

    • Suricata / suricata-update
    • OPNsense
    • pfSense PR in progress

    The project also recently added NRD-based threat intelligence for proactive phishing infrastructure detection (Suspect domains).

    📖 OPNsense Quick Guide

    For users who want to enable the ruleset on OPNsense 26.7.2:

    Quick Guide — Installing Antiphishing on OPNsense 26.7.2

    Project:
    github.com/julioliraup/Antiphi

    Vector / CTI dashboard:
    julioliraup.github.io/AT/

    #Suricata #OPNsense #ThreatIntelligence #CTI #DetectionEngineering #IDS #IPS #OpenSource

  41. 🛡️ Antiphishing is now officially available in @opnsense.org (@suricata IDPS)

    OPNsense 26.7.2, released today, includes:

    `os-intrusion-detection-content-at-antiphishing 1.0`

    The plugin integrates the Antiphishing Suricata ruleset into the OPNsense ecosystem.

    This is another step toward making community-driven Threat Intelligence directly consumable at the network enforcement layer.

    Current ecosystem integration:

    • Suricata / suricata-update
    • OPNsense
    • pfSense PR in progress

    The project also recently added NRD-based threat intelligence for proactive phishing infrastructure detection (Suspect domains).

    📖 OPNsense Quick Guide

    For users who want to enable the ruleset on OPNsense 26.7.2:

    Quick Guide — Installing Antiphishing on OPNsense 26.7.2

    Project:
    github.com/julioliraup/Antiphi

    Vector / CTI dashboard:
    julioliraup.github.io/AT/

    #Suricata #OPNsense #ThreatIntelligence #CTI #DetectionEngineering #IDS #IPS #OpenSource

  42. PSA, hold off updating to #OPNsense 26.7.2 if your device has Realtek NICs in it, either VM pass-through or bare metal. Lots of people reporting kernel problems and boot loops.

    forum.opnsense.org/index.php?t

  43. PSA, hold off updating to #OPNsense 26.7.2 if your device has Realtek NICs in it, either VM pass-through or bare metal. Lots of people reporting kernel problems and boot loops.

    forum.opnsense.org/index.php?t

  44. PSA, hold off updating to #OPNsense 26.7.2 if your device has Realtek NICs in it, either VM pass-through or bare metal. Lots of people reporting kernel problems and boot loops.

    forum.opnsense.org/index.php?t

  45. 🚀 How to Deploy #OPNsense on a Rad Web Hosting #VPS

    This guide demonstrates how to deploy OPNsense on a Rad Web Hosting VPS. This guide is tailored specifically for Rad Web Hosting VPS infrastructure, including /32 IP addressing, KVM virtualization, and ISO-based installs.
    What is OPNsense?
    OPNsense is a free, open-source firewall and routing platform designed for network security, traffic control, and perimeter ...
    Continued 👉 blog.radwebhosting.com/deploy- #opensource #selfhosting #selfhosted

  46. 🚀 How to Deploy #OPNsense on a Rad Web Hosting #VPS

    This guide demonstrates how to deploy OPNsense on a Rad Web Hosting VPS. This guide is tailored specifically for Rad Web Hosting VPS infrastructure, including /32 IP addressing, KVM virtualization, and ISO-based installs.
    What is OPNsense?
    OPNsense is a free, open-source firewall and routing platform designed for network security, traffic control, and perimeter ...
    Continued 👉 blog.radwebhosting.com/deploy- #opensource #selfhosting #selfhosted

  47. I get 900/100 service from my ISP, Zen, but that's irrelevant, as we're dealing with the layer 2 connection between the proxmox NIC and the ONT.

    If I force the link speed on the proxmox NIC to speed=2500 I get an error about the driver not supporting forced settings, and the link goes down. It only comes back up if I set it to auto again.

    Like I say, I'm only on a 900/100 package from Zen, but I'd still expect the NIC and ONT to negotiate a 2.5Gb/s link 🤔

    #OPNsense #proxmox #openreach

  48. I get 900/100 service from my ISP, Zen, but that's irrelevant, as we're dealing with the layer 2 connection between the proxmox NIC and the ONT.

    If I force the link speed on the proxmox NIC to speed=2500 I get an error about the driver not supporting forced settings, and the link goes down. It only comes back up if I set it to auto again.

    Like I say, I'm only on a 900/100 package from Zen, but I'd still expect the NIC and ONT to negotiate a 2.5Gb/s link 🤔

    #OPNsense #proxmox #openreach

  49. I get 900/100 service from my ISP, Zen, but that's irrelevant, as we're dealing with the layer 2 connection between the proxmox NIC and the ONT.

    If I force the link speed on the proxmox NIC to speed=2500 I get an error about the driver not supporting forced settings, and the link goes down. It only comes back up if I set it to auto again.

    Like I say, I'm only on a 900/100 package from Zen, but I'd still expect the NIC and ONT to negotiate a 2.5Gb/s link 🤔

    #OPNsense #proxmox #openreach

  50. Question for anyone out there running a combination of #OPNsense (26.7.1) as a guest on #proxmox (9.2.10) with #openreach fibre:

    Does your external NIC negotiate 2.5Gb/s with the openreach ONT?

    Mine only negotiates 1Gb/s, even though it's an Intel I225-V (rev 3) NIC that is 2.5GbE capable, as is the ONT.

    The NIC is not passed through to the OPNsense guest, it's on a Linux bridge in proxmox with the guest given a virtual NIC on the bridge. OPNsense sees the vnic as 10Gb/s

  51. Question for anyone out there running a combination of #OPNsense (26.7.1) as a guest on #proxmox (9.2.10) with #openreach fibre:

    Does your external NIC negotiate 2.5Gb/s with the openreach ONT?

    Mine only negotiates 1Gb/s, even though it's an Intel I225-V (rev 3) NIC that is 2.5GbE capable, as is the ONT.

    The NIC is not passed through to the OPNsense guest, it's on a Linux bridge in proxmox with the guest given a virtual NIC on the bridge. OPNsense sees the vnic as 10Gb/s