chiefgyk3d, to pfSense
@chiefgyk3d@social.chiefgyk3d.com avatar

I'm currently learning about #Zscaler Deception, and I really wish Zscaler would allow you to get a setup for homelabs but they want a minimum of 50 seats when I spoke to them. Because I would love to roll a proper SME homelab to tie Zscaler, #Crowdstrike, #Pfsense, and more and then pipe all that to a #SIEM such as Datadog or another one.

I think it would benefit Zscaler to allow professionals to have access to do this on homelabs as we implement what we are familiar with.

#Infosec

qlp, to pfSense
@qlp@linh.social avatar

With the deprecation of the armv7 architecture in pfSense's upstream operating system, FreeBSD, it looks like pfSense+ 24.03 will probably be the one of the last major releases that I'll be seeing for my Netgate 3100 firewall.

I'm debating on replacing it with one of their newer appliances (either a 4200 or a 6100, as the 2100 doesn't have any 2.5 GbE ports) or getting a cheap-ish N100 or N300 passively-cooled system and pay for a pfSense+ subscription.

Netgate: 24.03 New Features and Changes

https://docs.netgate.com/pfsense/en/latest/releases/24-03.html

josephholsten, to pfSense
Yahiko, to pfSense French
@Yahiko@framapiaf.org avatar

Je me sens débile. On est d'accord qu'avec on peut faire du routage inter-VLANs ?

J'ai un port trunk / tag (comme tu veux, ça dépend des marques) avec tous mes VLANs sur mon commutateur et un port avec tous mes VLANs sur mon pfSense.

Normalement en mettant une règle sur mon VLAN source vers mon VLAN destination, ça devrait fonctionner ou je m'y prends comme un manche ?

Merci !

douglasvb, to Ubiquiti
@douglasvb@mastodon.social avatar

I'm thinking about switching from a #Ubiquiti #EdgeRouter to something with #OPNsense on it. My home Internet can do 1gbps/45mbps although this fall I'll probably end up with symmetric 1.2gbps. I'm upgrading my access points to WiFi 7 (the new Ubiquiti APs) so the WiFi will support the throughput even if our devices don't yet.

The frustrating thing with the EdgeRouter is that it's basically been abandoned the last few years by its manufacturer. They are still selling plenty of them but... 1/n

douglasvb,
@douglasvb@mastodon.social avatar

... the software updates have been very sparse. And it seems the company is focusing on other product lines.

I was looking at #pfSense but it seems that the company became jerks a few years ago. I used the software about a decade ago to setup a fraternity house network with about 300 concurrent devices and with four cable modems to supply the Internet. It worked surprisingly well to bond those connections together and shape network traffic. But since the company seems to be jerks now... (2/n)

Yahiko, to pfSense French
@Yahiko@framapiaf.org avatar

Le LTE sur c'est de la merde ou c'est mon équipement ?

bradj, to random

might tell you that DHCP is EOL soon and that you should change to Kea DHCP. I switched this morning, which is just a checkbox in the UI, and it brought down my guest network. Unable to resolve DNS within Guest. Devices were getting IPs.

Dug in more after work and saw Guest DNS Servers were misconfigured. Fixed DNS, restarted DHCP, DNS, and interfaces but kept getting intermittent connectivity issues between networks.

Main network was fine. Ended up reverting back to ISC.

pete_wright, to pfSense
@pete_wright@nlogic.systems avatar

Just got my 4200 today for . This thing is pretty sweet and big upgrade from my older 1100 which was a really good device. Finally got a fiber connection so needed some hardware with a bit more power. Especially appreciated the easy-peazy backup/restore between devices so all my DNS and firewall rules showed up right way.

fatuus, to pfSense French
@fatuus@mstdn.fr avatar

Dis :mastodon: Tu aurais une solution facile pour faire un MitM 🚨 (SSL donc) avec du ?
(C'est pour intercepter tout ce qui passe dans mon VLAN et à quel point le 'S' dans cet acronyme est pour sécurité 🔒 )

Toute réponses étudiée, surtout les :blobnomcookie:

D'la bonne journée sur vous
:boost_requested:

gregdosh, to homelab
@gregdosh@auengun.net avatar

Homelab TODO:
There is an existing pfSense guide to automatically renew an OpenVPN connection to PIA on some cadence. It also handles port forwarding for applications.

I've created a more modern idea with their Wireguard servers along with renewing the tunnel every 15 minutes and adapted to work with qBittorrent. I need to document and get this into version control somewhere.

https://github.com/fm407/PIA-NextGen-PortForwarding

Yahiko, to pfSense French
@Yahiko@framapiaf.org avatar

Question technique sur . J'ai un commercial qui a eu l'idée (avec mon aval) de vendre un lien avec pool d'IP publiques. Le problème c'est que je n'ai pas pu maquetter.
L'idée c'est une IP pour notre matos, la seconde pour le firewall d'un autre prestataire. L'idéal s'était que ce firewall soit sur une des interface du pfSense et fasse sa vie.
1/2

gyptazy, to FreeBSD
@gyptazy@gyptazy.ch avatar

You’re a fan? It doesn’t matter if you’re a beginner, pro or developer - everyone is welcome to participate in the .

Focussing on , , , and in the discussions, also all other flavors like , ()) are welcome! You’re a fan (, , , , ,…) - just jump in: :bsd.cafe

More on my blog:
https://gyptazy.ch/blog/bsd-cafe-the-community-for-bsd-systems-freebsd-openbsd-netbsd/

hobbsc, to home
@hobbsc@social.sdf.org avatar

I'm still mulling over my project of connecting three buildings. Currently two of the buildings are connected with a bridge but I'm not happy with the weird subnetting.

Anyone have strong opinions on equipment if starting fresh? I'm considering gear as I've used it with some success in the past. Also considering or for the routers.

I could, in theory, bury a cable for it but that's real effort so I'm going wireless.

nixCraft, to random
@nixCraft@mastodon.social avatar

The article talks about using poor password attack vectors. just clickbait. And What do you mean again? The bots never stopped. The scanning never stopped. Here is a guide to protect your openssh https://www.cyberciti.biz/tips/linux-unix-bsd-openssh-server-best-practices.html

kkarhan,

@nixCraft #pfSense...

Because I've got a complete /29 and I don't want to spent 4-5 digits for some overpriced "Enterprise" bs.

For servers offsite, I use #ufw as built-in option in @ubuntu because I just restrict SSH access to my IP range...

wagesj45, to pfSense
@wagesj45@mastodon.jordanwages.com avatar

Does the automatic update for #pfsense work for anyone else? I've never had it work successfully and it bricks the system, and I always have to take the configuration backup and restore it on a fresh install every time.

What's the deal? Is it something I'm doing wrong?

gspapp, to random

Can any OpenBSD person help me with this error? I am trying to install OpenBSD 7.4 and it always fails to install the bootloader. I could install OpenBSD 7.3 (when it was released) but now I can't install 7.4. Should I email misc@? I'd appreciate if somebody could help me.

kkarhan,
kkarhan,

@gspapp yeah, I kept default on too until it broke...

Granted I upgraded from like 2.4 onwards...

chiefgyk3d, to Twitch
@chiefgyk3d@social.chiefgyk3d.com avatar

Doing a bandwidth test on #Twitch right now to see if I resolved my issues, I may have to reformat my #Pfsense firewall tomorrow as well

philpem, to opnsense
@philpem@digipres.club avatar

Either I'm an idiot or (and too?) can't filter devices into DHCP pools based on their DHCP vendorclass.
That's annoying if true, because it'll make it pretty hard to use for the IP Phone VLAN.
Someone please prove me wrong... I like just about everything else about it, including being able to use it as an nginx reverse-proxy.

0x58, to Cybersecurity

📨 Latest issue of my curated and list of resources for week /2023 is out! It includes the following and much more:

➝ 🔓 🇺🇸 U.S. nuclear research lab impacts 45,000 people
➝ 🇩🇪 Germany Says Customer Data Stolen in Attack
➝ 🔓 🏧 ATM company Coin Cloud got hacked. Even its new owners don’t know how
➝ 🔓 🇺🇸 Norton discloses data breach after May ransomware attack
➝ 🇷🇺 Russian SVR-Linked Targets TeamCity Servers in Ongoing Attacks
➝ 👥 ransomware now poaching , NoEscape affiliates
➝ 🇻🇳 💻 seizes domains used to sell fraudulent accounts
➝ 🇫🇷 💸 French police arrests Russian suspect linked to ransomware
➝ 🇨🇳 Chinese APT Volt Typhoon Linked to Unkillable SOHO Router
➝ 🇺🇦 🇷🇺 Ukrainian military says it hacked 's federal tax agency
➝ 🇨🇳 🚪 Researchers Unmask Sandman APT's Hidden Link to China-Based Backdoor
➝ 🇺🇦 📡 ’s largest mobile communications provider down after apparent
➝ 🇪🇸 Kelvin Security hacking group leader arrested in
➝ 🔻 👮🏻‍♂️ ransomware site outage rumored to be caused by law enforcement
➝ 📹 🕵🏻‍♂️ devices broadcasted private video to other users’ accounts
➝ 🇷🇺 🇪🇺 Russian Diplomat Expelled Amid EU Spy Purge Is Now An OSCE Election Observer In Serbia
➝ 🇺🇸 Harry Coker confirmed to be the next National Cyber Director
➝ 🇪🇸 🇺🇸 Spain expels two US spies for infiltrating secret service
➝ 📝 Unveils EMB3D Threat Model for Embedded Devices Used in Critical Infrastructure
➝ 🩹 Patch Tuesday: Electromagnetic Fault Injection, Critical Redis Vulnerability
➝ 🦠 🇵🇸 New Pierogi++ by Cyber Gang Targeting Palestinian Entities
➝ 🦠 🇮🇷 Iranian State-Sponsored Group Deploys 3 New Malware Downloaders
➝ 🦠 🇩🇪 New MrAnon Stealer Malware Targeting German Users via Booking-Themed
➝ 🍪 's New Tracking Protection in Chrome Blocks Third-Party
➝ 🐛 👨🏻‍💻 Unveils Open Source Vulnerability Impact Scoring System
➝ 🩹 🧱 backports RCE fix after attacks on unsupported
➝ 🔓 🧱 Over 1,450 servers exposed to RCE attacks via bug chain
➝ 🩹 🍏 Ships iOS 17.2 With Urgent Security
➝ 🐛 Over 30% of apps use a vulnerable version of the library

📚 This week's recommended reading is: "Black Hat Python, 2nd Edition: Python Programming for Hackers and Pentesters (2nd Edition)" by Justin Seitz and Tim Arnold

Subscribe to the newsletter to have it piping hot in your inbox every week-end ⬇️

https://infosec-mashup.santolaria.net/p/infosec-mashup-week-502023

mja, to random
kkarhan,

@mja or you could just use a #pfSense or #OPNsense instead...

stefano, to pfSense
@stefano@bsd.cafe avatar
SonarResearch, to pfSense

Critical vulnerabilities in pfSense firewall: RCE via XSS and Command Injection!
Find out how SonarCloud discovered these vulnerabilities in our newest blog post:
https://www.sonarsource.com/blog/pfsense-vulnerabilities-sonarcloud?utm_medium=social&utm_source=mastodon&utm_campaign=&utm_content=blog-pfsense-vulnerabilities-sonarcloud-231212-p1&utm_term=ww_en_all_x
(CVE-2023-42325, CVE-2023-42326, CVE-2023-42327)

qlp, to pfSense
@qlp@linh.social avatar

For anyone who has any devices running pfSense Plus or pfSense CE, a new version has been released to fix some really important security and ZFS issues.

https://www.netgate.com/blog/netgate-releases-pfsense-plus-software-version-23.09.1-and-pfsense-ce-software-version-2.7.2

josh, to pfSense

is just great.

  • All
  • Subscribed
  • Moderated
  • Favorites
  • JUstTest
  • mdbf
  • everett
  • osvaldo12
  • magazineikmin
  • thenastyranch
  • rosin
  • normalnudes
  • Youngstown
  • Durango
  • slotface
  • ngwrru68w68
  • kavyap
  • DreamBathrooms
  • tester
  • InstantRegret
  • ethstaker
  • GTA5RPClips
  • tacticalgear
  • Leos
  • anitta
  • modclub
  • khanakhh
  • cubers
  • cisconetworking
  • megavids
  • provamag3
  • lostlight
  • All magazines