home.social

#pf — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #pf, aggregated by home.social.

  1. New post: FreeBSD resource monitoring and accounting.

    A practical tour of the base-system toolkit for figuring out *what is actually using my server*: top, vmstat, systat, gstat, netstat/sockstat, procstat, pfctl, and per-jail attribution with kern.racct and rctl.

    No ports, no agents. Just FreeBSD.

    blog.hofstede.it/freebsd-resou

    #FreeBSD #BSD #Jails #pf #SysAdmin #DevOps #Unix #BSD #Blog

  2. New post: FreeBSD resource monitoring and accounting.

    A practical tour of the base-system toolkit for figuring out *what is actually using my server*: top, vmstat, systat, gstat, netstat/sockstat, procstat, pfctl, and per-jail attribution with kern.racct and rctl.

    No ports, no agents. Just FreeBSD.

    blog.hofstede.it/freebsd-resou

    #FreeBSD #BSD #Jails #pf #SysAdmin #DevOps #Unix #BSD #Blog

  3. New post: FreeBSD resource monitoring and accounting.

    A practical tour of the base-system toolkit for figuring out *what is actually using my server*: top, vmstat, systat, gstat, netstat/sockstat, procstat, pfctl, and per-jail attribution with kern.racct and rctl.

    No ports, no agents. Just FreeBSD.

    blog.hofstede.it/freebsd-resou

    #FreeBSD #BSD #Jails #pf #SysAdmin #DevOps #Unix #BSD #Blog

  4. New post: FreeBSD resource monitoring and accounting.

    A practical tour of the base-system toolkit for figuring out *what is actually using my server*: top, vmstat, systat, gstat, netstat/sockstat, procstat, pfctl, and per-jail attribution with kern.racct and rctl.

    No ports, no agents. Just FreeBSD.

    blog.hofstede.it/freebsd-resou

    #FreeBSD #BSD #Jails #pf #SysAdmin #DevOps #Unix #BSD #Blog

  5. Trying to figure out networking and (OpenBSD) pf at the same time...

    Basically, I have a secondary IPv4 address on my OpenBSD webserver that I want to forward to my IPv6-only Wii - as if the IPv4 address was the Wii's.

    What forwarding mode is appropriate? nat-to, af-to, rdr-to?

    #OpenBSD #pf #networking

  6. Built an AI agent harness on OpenBSD 7.8, as a test and - because why not(?)
    It's 198 agents. 198 UNIX users. One kernel.

    Each job runs through a setuid C wrapper:
    chroot(2) → unveil(2) → pledge(2) → execve(2)
    PF handles per-department egress. Every syscall is logged.

    Idle agents cost zero RAM. They're just directory entries until the executor calls them up. No containers. No VMs. No orchestrator bloat.
    Just OpenBSD being exactly what it was built to be. ❤️

    More people should know this OS is the ultimate AI harness. 🐡

    #OpenBSD #pledge #unveil #pf #BSD #AI #agenticAI

  7. [Repost for the morning (CEST) crowd]

    Friends, I wrote a book. It's now out in its fourth edition.

    More in "The Book of PF, 4th Edition: It's Here, It's Real" nxdomain.no/~peter/its_real_it

    For background, "Yes, The Book of PF, 4th Edition Is Coming Soon" nxdomain.no/~peter/yes_the_boo

    Get the book: nostarch.com/book-of-pf-4e

    @nostarch #bookofpf #pf #networking #openbsd #freebsd #networktrickery #cybersecurity

  8. BSDCan bsdcan.org/2026/ Tutorial Thursday 2026-06-18: 09:00 - 16:00 DMS 1120
    Network Management with the PF Packet Filter Toolset on OpenBSD and FreeBSD
    Peter Hansteen, Massimiliano Stucchi, Tom Smyth
    bsdcan.org/2026/timetable/time
    To register bsdcan.org/2026/registration.h @bsdcan #openbsd #freebsd #pf #networking

  9. Schrödinger's Honeypot on FreeBSD and nginx

    Every day, bots scan my site for WordPress paths that do not exist. With a small nginx trick, those probes become self-inflicted bans. Here is how I adapted Schrödinger's Honeypot for a FreeBSD, nginx, jail setup.

    blog.giersig.eu/articles/schro

    #pf
  10. Game seeks players! #PF-1e The Harrowing
    Flavour: "A dark fantasy adventure where the characters are trapped inside a living, magical card deck. It focuses on Gothic storytelling, Varisian lore, and navigating the chaotic, sentient ..."
    Read more: rpgcrossing.com/showthread.php
    cdn.bsky.app/img/avatar_thumbn

    Missing content? Check our main feed at bsky.app/profile/rpgcrossing.b

    #pf
  11. The router has been up for 16 days and 11 hours without any incidents—what a milestone!!

    #openbsd #pf

  12. I finally got a @BoxyBSD VM today. The installation using the ISO went smoothly.
    However, writing firewall rules in pf instead of nftables still takes some practice.
    I hope I’ll be able to port and test my crazytrace program on FreeBSD.

    #FreeBSD #BoxyBSD #PF #nftables #BSDNewbie

  13. Running #OpenBSD 7.8 ​:openbsd:​

    DNS:
    #nsd (3 Master Zones), #DNSSEC & #DANE (RFC6698) + #unbound
    Firewall:
    #pf with auto-fed tables (IPS-style), spambot-tarpitting & service rate limits.
    Mail:
    #smtpd (Multi-domain, RFC8461/MTA-STS) + #rspamd (DKIM) + #dovecot (IMAPS-only).
    Spam-Defense:
    #spamd with auto-SPF-walk (no more greylisting issues).
    Web:
    #relayd (TLS-Terminator, HSTS, CSP) + #httpd (NIP-05, Autoconfig, security.txt).
    Performance: Lightweight "Fail2Ban" via 1-liner shell script (No Python crap!).

    #Nostr Relay in Rust building...

    #SelfHosted #SysAdmin #Security #Privacy

  14. Running #OpenBSD 7.8 ​:openbsd:​

    DNS:
    #nsd (3 Master Zones), #DNSSEC & #DANE (RFC6698) + #unbound
    Firewall:
    #pf with auto-fed tables (IPS-style), spambot-tarpitting & service rate limits.
    Mail:
    #smtpd (Multi-domain, RFC8461/MTA-STS) + #rspamd (DKIM) + #dovecot (IMAPS-only).
    Spam-Defense:
    #spamd with auto-SPF-walk (no more greylisting issues).
    Web:
    #relayd (TLS-Terminator, HSTS, CSP) + #httpd (NIP-05, Autoconfig, security.txt).
    Performance: Lightweight "Fail2Ban" via 1-liner shell script (No Python crap!).

    #Nostr Relay in Rust building...

    #SelfHosted #SysAdmin #Security #Privacy

  15. Running #OpenBSD 7.8 ​:openbsd:​

    DNS:
    #nsd (3 Master Zones), #DNSSEC & #DANE (RFC6698) + #unbound
    Firewall:
    #pf with auto-fed tables (IPS-style), spambot-tarpitting & service rate limits.
    Mail:
    #smtpd (Multi-domain, RFC8461/MTA-STS) + #rspamd (DKIM) + #dovecot (IMAPS-only).
    Spam-Defense:
    #spamd with auto-SPF-walk (no more greylisting issues).
    Web:
    #relayd (TLS-Terminator, HSTS, CSP) + #httpd (NIP-05, Autoconfig, security.txt).
    Performance: Lightweight "Fail2Ban" via 1-liner shell script (No Python crap!).

    #Nostr Relay in Rust building...

    #SelfHosted #SysAdmin #Security #Privacy

  16. Running #OpenBSD 7.8 ​:openbsd:​

    DNS:
    #nsd (3 Master Zones), #DNSSEC & #DANE (RFC6698) + #unbound
    Firewall:
    #pf with auto-fed tables (IPS-style), spambot-tarpitting & service rate limits.
    Mail:
    #smtpd (Multi-domain, RFC8461/MTA-STS) + #rspamd (DKIM) + #dovecot (IMAPS-only).
    Spam-Defense:
    #spamd with auto-SPF-walk (no more greylisting issues).
    Web:
    #relayd (TLS-Terminator, HSTS, CSP) + #httpd (NIP-05, Autoconfig, security.txt).
    Performance: Lightweight "Fail2Ban" via 1-liner shell script (No Python crap!).

    #Nostr Relay in Rust building...

    #SelfHosted #SysAdmin #Security #Privacy

  17. Running #OpenBSD 7.8 ​:openbsd:​

    DNS:
    #nsd (3 Master Zones), #DNSSEC & #DANE (RFC6698) + #unbound
    Firewall:
    #pf with auto-fed tables (IPS-style), spambot-tarpitting & service rate limits.
    Mail:
    #smtpd (Multi-domain, RFC8461/MTA-STS) + #rspamd (DKIM) + #dovecot (IMAPS-only).
    Spam-Defense:
    #spamd with auto-SPF-walk (no more greylisting issues).
    Web:
    #relayd (TLS-Terminator, HSTS, CSP) + #httpd (NIP-05, Autoconfig, security.txt).
    Performance: Lightweight "Fail2Ban" via 1-liner shell script (No Python crap!).

    #Nostr Relay in Rust building...

    #SelfHosted #SysAdmin #Security #Privacy

  18. Nice, someone has written an updated #ZFS management module for #Webmin for #FreeBSD which really looks helpful. Its not only offering #ZFS managment, there is also #Samba, #PF #NFS and various other types configuration like #ACL management included, too. Wow!

    With this, #Webmin is nearly feature complete. I'm only missing #Bastille or #Bhyve modules.

    github.com/karmantyu/ZFSgame

  19. Nice, someone has written an updated #ZFS management module for #Webmin for #FreeBSD which really looks helpful. Its not only offering #ZFS managment, there is also #Samba, #PF #NFS and various other types configuration like #ACL management included, too. Wow!

    With this, #Webmin is nearly feature complete. I'm only missing #Bastille or #Bhyve modules.

    github.com/karmantyu/ZFSgame

  20. Nice, someone has written an updated #ZFS management module for #Webmin for #FreeBSD which really looks helpful. Its not only offering #ZFS managment, there is also #Samba, #PF #NFS and various other types configuration like #ACL management included, too. Wow!

    With this, #Webmin is nearly feature complete. I'm only missing #Bastille or #Bhyve modules.

    github.com/karmantyu/ZFSgame

  21. Nice, someone has written an updated #ZFS management module for #Webmin for #FreeBSD which really looks helpful. Its not only offering #ZFS managment, there is also #Samba, #PF #NFS and various other types configuration like #ACL management included, too. Wow!

    With this, #Webmin is nearly feature complete. I'm only missing #Bastille or #Bhyve modules.

    github.com/karmantyu/ZFSgame

  22. Крастерский маршрутизатор на FreeBSD из старого компа

    Доброго свободного времени, товарищи! в этой своей первой статье хотел бы вам рассказать как я будучи далёк от сетевых технологий перешел с роутера мыльницы на старый комп из-под дивана.

    habr.com/ru/articles/1012524/

    #freebsd #unbound #mpd5 #pf #dhcpd

  23. Yes, You Too Can Be An Evil Network Overlord - On The Cheap With OpenBSD, pflow And nfsen nxdomain.no/~peter/yes_you_too

    A story about network metadata and #openbsd, originally from 2014, good for reprising. See The Book of PF for more #nfsen #netflow #pflow #monitoring #networking #security #pf #packetfilter #bookofPF @nostarch

  24. Budget 2026-27 simplifies PF trusts & employer contributions. Discover how PF trust rationalisation benefits employers and employees. Click for details on tax clarity & compliance! english.mathrubhumi.com/news/m #EPFO #PF #UnionBudget2026 #Tax