bolha.us is one of the many independent Mastodon servers you can use to participate in the fediverse.
We're a Brazilian IT Community. We love IT/DevOps/Cloud, but we also love to talk about life, the universe, and more. | Nós somos uma comunidade de TI Brasileira, gostamos de Dev/DevOps/Cloud e mais!

Server stats:

254
active users

#pfsense

0 posts0 participants0 posts today
Replied in thread

@usuario @TagsBR @manualdousuario pfsense é sistema open source que funciona como firewall e roteador, com recursos avançados como VPN, controle de tráfego, VLAN, IDS/IPS e muito mais.

Ideal para quem quer mais controle sobre a segurança da própria rede.

Site oficial: pfsense.org/

www.pfsense.orgpfSense® - World's Most Trusted Open Source FirewallpfSense is a free and open source firewall and router that also features unified threat management, load balancing, multi WAN, and more
Replied in thread

@fusl @mnalis @0xF21D

I do that with #pfSense & #OPNsense (depending on the exact network in question) and have it merge multiple sources that get cached.

In total, I do may out the 30 DNS servers and whilst I have #IPv4only, I have everything ready for #DualStack (#IPv4 + #IPv6) once my ISP stops keeing it's thumbs um their ass...

GitHublists.d/dns.servers.list.tsv at main · greyhat-academy/lists.dList of useful things. Contribute to greyhat-academy/lists.d development by creating an account on GitHub.

I recently discovered that despite having a business account, my ISP will automatically block #WireGuard traffic if I use a tunnel actively for an extended period, or if there is just a lot of traffic. (Tech support swears they don't do this but the internet suggests otherwise).

The only viable workaround I've found is to somewhat regularly rotate the listen port on the tunnel.

This, it turns out, is a headache with #pfSense.

It's very crude and only supports a single tunnel at the moment, but I just spent an absurd amount of time on a solution - so here it is if anyone is interested:

github.com/sudonem/pfsense-wg-

GitHubGitHub - sudonem/pfsense-wg-rotateContribute to sudonem/pfsense-wg-rotate development by creating an account on GitHub.

Es hat den ganzen verschissenen Tag gedauert, aber VLAN-Config per File und ein Uplink auf Port 22 mit allen #VLAN tagged scheine ich hinbekommen zu haben.

Nächster Schritt: Trunk mit zwei NICs, um das Ding direkt an die #pfSense anzuschliessen. Dann kann ich endlich den uralten und chronisch überfüllten 24x #Switch unterbrechungsfrei ausmustern, der immer noch mein Hauptswitch ist. Dessen Ableben ist ein Damoklesschwert über meiner heimischen IT-Landschaft, dessen Auflösung ich schon seit Jahren vor mir her schiebe. Bin ja kein Netzwerker und #JunOS ist jetzt nicht so intuitiv.

Der #Juniper 3400 ist deutlich jünger und hat einen erheblich geringeren #Stromverbrauch, trotz doppelt so vieler Ports. Danach kann die Serverlandschaft weiter wachsen, die #Weltherrschaft ist nahe...

Hi I'm 90s Script Kiddie, I grew up online. I do #devops and #automation code stuff for my job. My hobbies are #gamedev, #vintageelectronics, #gaming, #repair ing stuff to keep it out of the landfill, old #apple hardware, #linux admin (I run my own mail, web, media etc servers) #network admin especially #pfsense, I love #books, #anime, #manga - reading in general really. #music too! Jazz, alt-rock, pop, folk, chiptunes... I also enjoy #cooking and am trying to get better at it. Beliefs-wise I'm something of an anarchist, yearning for a #solarpunk future I'll probably never live in, but I do what I can to do #mutualaid for the people in my circle. If you're my friend, I will set up all your electronics for you, replace the battery in your phone, give you some free mail or web hosting... whatever! I try to limit my consumption of news media for my own sanity, but I love reading about what people are doing in their own words. That's why I love the Fediverse, and it's why I'm lurking around on #gopher

I don't have a lot of friends. I've always been kind of a loner, and a little awkward. Luckily, I love my own company and have no problem spending time alone. Those few in my circle are people who I think make the world better by being in it.

I'm a #queer #bi #enby and I don't really give a hoot about what pronouns you use for me. Actually, I sort of feel like however you labeled me I'd want to break out of that box somehow. I guess I'm pretty contrary.

New #introduction who dis.

Any #PFSense / #OPNsense wizards out there?

Anyone ever see it where one's WAN interface randomly decides to become a private IP instead of proper public one?

This is like the 3-4th time over 2-3 years and it's really getting on my nerves. Rare enough for me to not dig in and fix, but common enough to where -> this must never happen again.

Maybe fault of AT&T gear? But would love to have pfsense re-check for IP if it ends up with a 192 somehow for WAN interface.

Replied in thread

@snow Maybe consider a provider that allows you to do #Blackholing?

  • In fact that is something #DECIX advocates for: Stopping #DDoS at the #IX level!

#Contabo for example allows to book a dedicaded, managed #pfSense #Firewall woth their #dedicaded #Servers so you can just block entire ASNs aggressively.

I am trying to configure #pfsense #openvpn through alias instead of single CIDR notations, as soon as I make the changes, clients from the outside can't connect, even after restarting the openvpn server. But testing with a machine I have here through a mobile provider hotspot the new openvpn settings work. *scratches head* #sysadmin #IPV6 #ipv4

One for my fellow #FreeBSD and #OpenBSD users. I used to build my own simple firewalls using either OS until I ended up with dual upstream, non-aggregated connections and switch to #pfsense CE for that.

I would much rather prefer to go back to a regular artisanal firewall, but wasn't able to find any configuration examples for an ideally pf-based firewall setup that has the ability to handle routing traffic between two distinct upstream providers without using LAGG or a similar aggregation setup.

Does anyone have such a setup that they're willing to share, or should I just stick with pfSense or OPNSense?

Ich hab uebrigens meine beiden #pfSense CE Firewall im Datacenter auf pfSense+ geupgraded.

Neben dem #Proxmox Mail Gateway ist das das zweite Open Source Produkt, was ich mit einer Subscription supporte.

Mir waere es eigentlich fast lieber, in einen Topf/Fund einzuzahlen und da dann zu sagen, was ich gerne unterstuetzt haben sehen wollen wuerde und der Fund verteilt die Gelder dann halt anteilig weiter.
Aber vielleicht ist das ja auch das Business Modell von OpenCollective... wer weiss...

Looking for a good, easy to follow tutorial on how to setup pfsense HAProxy to route web traffic between 3 different web servers, not a round robin, but 3 independently different pages, haproxy would serve the right pages based on hostname. Also, use the acme certificates manager to manage certs.

I keep screwing this up haha, and then giving up.

Any suggestions?
#pfsense #networking #firewall #haproxy