astian, to wireguard
@astian@mastodon.social avatar

Our work advances with MidoriVPN, a private and secure system that uses Multiple instances and mesh technology. Soon to be integrated into .

https://astian.org/midori-browser

MidoriVPN

0crash, to sysadmin
@0crash@mastodon.social avatar

Question to #sysadmin and #selfhosted specialists. We are looking for a free and preferably open-source #wireguard solution with MFA for ~200 devices. Closest that I was able to find was #defguard, but it allows people to self-register devices and not so granular access per-user. We need to control access through VLAN so we have to control each device rather than user.

ferki,
@ferki@fosstodon.org avatar

@0crash Hmm, perhaps netbird and/or netmaker fits the bill?

cjk, to wireguard German
@cjk@chaos.social avatar

Just set up for company VPN, to replace OpenVPN 🥳

cjk,
@cjk@chaos.social avatar

@clarity We only have Linux clients, and I plan to distribute the config & keys via ansible. Every user has to bring in their device either way, because of the upgrade to 24.04

clarity,
@clarity@chaos.social avatar

@cjk ah for sure, thats a no-brainer. I also need to support Windows which makes to 1000x trickier...

stefano, to linux
@stefano@bsd.cafe avatar
tara, to wireguard
@tara@hachyderm.io avatar

An excellent solution from @solene 👇 to protect #Wireguard tunnels on #OpenBSD from #TunnelVision attacks.

Have a closer look at the example about rdomain 0 and rdomain 1

https://dataswamp.org/~solene/2021-10-09-openbsd-wireguard-exit.html

#bsd

sesivanyblog, to homeassistant Czech
@sesivanyblog@blog.eischmann.cz avatar

Digitální domácnost pod kontrolou s Home Assistant Green

První zkušenosti s Home Assistant Green a nasazením HA platformy v domácnosti.

(reakce na tento post se zobrazí i na samotném blogu)

https://blog.eischmann.cz/2024/05/03/digitalni-domacnost-pod-kontrolou-s-home-assistant-green/

holm, to android German

https://gnulinux.ch/datensparsames-android-mit-der-android-debug-bridge-teil1-samsung-phablet

wow! geiles verfahren. insbesondere rethink dns kannte ich noch nicht. aber da dieses mehrere wireguard endpunkte parallel verwalten kann wird das nun mal angetestet. happy hacking!

@gnulinux #android #firewall #debloat #wireguard #grapheneos

Lioh,
@Lioh@social.anoxinon.de avatar

@holm @gnulinux da hatte ich schonmal was zu geschrieben: https://gnulinux.ch/android-absichern-mit-rethinkdns

Ich würde heute allerdings personalDNSFilter empfehlen: https://gnulinux.ch/android-adblocking-mit-personaldnsfilter

Das macht genau was es soll. rethinkDNS hat leider ein bisschen die Featureitis befallen.

lme, to wireguard German
@lme@bsd.cafe avatar

Help needed.
I set up on according to @stefano's excellent journal entry at https://freebsdfoundation.org/our-work/journal/browser-based-edition/make-your-own-vpn-freebsd-wireguard-ipv6-and-ad-blocking-included/
While the wireguard connection between my clients (Android and Windows) is established, it is unusable slow. See screenshot.
Speedtest shows latency between 2 and 21 seconds. The server is hosted at @netcup, and both the connection there and my client's connection is of course much faster.
I tinkered with MTU on both server and client but no luck, either.

feld,
@feld@bikeshed.party avatar

@lme @stefano @netcup UDP getting dropped due to too small buffer sizes? Check for queue drops in sysctl. If it's nonzero that's probably an issue

stefano, to linux
@stefano@bsd.cafe avatar
mforester,
@mforester@rollenspiel.social avatar

@stefano great tutorial. 🙂
I do something very similar. My home lab is exposed via IPv6, but sadly IPv6 only is still not a viable option. Too often, I find myself in networks where IPv6 is disabled.
I have a VPS with an IPv4 where I use soccat to proxy ports 443 and 80 to my home lab server (connected via a Wireguard tunnel). The reverse proxy itself is running directly in my home lab.

mikael, to wireguard
@mikael@hachyderm.io avatar

does it right: I configured hosted on my for my and my laptops, and it supports and out of the box without issues.

https://oxcrag.net/blog/2024/04/14/Connecting-to-Home-From-Abroad.html

mikael,
@mikael@hachyderm.io avatar

@vwbusguy sounds really good! I’ll definitely keep this in mind.

vwbusguy,
@vwbusguy@mastodon.online avatar
linuxiac, to RaspberryPi
@linuxiac@mastodon.social avatar
jbzfn, to wireguard
@jbzfn@mastodon.social avatar

🎉 NetBSD 10.0 Released With Much Improved Hardware Support & Faster Performance | Phoronix

#NetBSD 10 provides #WireGuard support, support for many newer #Arm platforms including for #AppleSilicon and newer #RaspberryPi boards, a new Intel Ethernet drive, support for Realtek 2.5GbE network adapters, #SMP performance improvements, automatic swap encryption, and an enormous amount of other hardware support improvements that accumulated over the past 4+ years 」

https://www.phoronix.com/news/NetBSD-10.0-Released

retiolus, (edited ) to Help
@retiolus@mamot.fr avatar

Would someone me configure my server to access my home local network?

I've literally been stuck for 6 hours.

https://forum.yunohost.org/t/cant-access-yunohost-local-network-through-wireguard-server/29127/1

@linuxquestions

mforester, (edited )
@mforester@rollenspiel.social avatar

@retiolus @linuxquestions is the WG server in a container or running on the host system? Not sure if that's relevant, but it might be a starting point.
You'll also need to define a route from 10.10.10.0 to 192.168.2.0.

mforester,
@mforester@rollenspiel.social avatar

@retiolus @linuxquestions and enable IP forwarding. It's a sysctl setting.

foss_android, to android
@foss_android@mstdn.social avatar

Rethink
DNS + Firewall + VPN

is a security app that combines multiple functionalities to protect your device.

Download: https://rethinkdns.com/download

kohelet,
@kohelet@mstdn.social avatar

@foss_android
Just installed
apps looks GREAT from first look.
lots to discover and test.

my only concern is that it'll take lots of battery to use,
but I guess it is what it is.

caos, to linux German

🦉 💻 Freie Router-Firmware für mehr #Datenschutz (#CC2tv Folge 369)

yewtu.be/watch?v=EeKuqHYCNe0

"Die Anzahl der Geräte, die wir in unserem Heimnetz nutzen, ist in den letzten Jahren deutlich gestiegen. Darunter sind auch Geräte, denen wir nicht gerne vollen Zugriff auf das Heimnetz und Internet überlassen wollen. Doch meist ist es kaum möglich, beispielsweise den Internetzugriff zuverlässig zu beschränken. In diesem Video zeigen wir die freie Routersoftware OpenWRT, die solche Funktionen bietet, allerdings auch ein Netzwerk-Grundwissen bei der Einrichtung voraussetzt."

#OpenWRT #FritzBox #Heimnetz #Netzwerk #DMZ #Linux #Tracker #TOR #WireGuard #FOSS @datenschutz

  • All
  • Subscribed
  • Moderated
  • Favorites
  • JUstTest
  • mdbf
  • everett
  • osvaldo12
  • magazineikmin
  • thenastyranch
  • rosin
  • normalnudes
  • Youngstown
  • Durango
  • slotface
  • ngwrru68w68
  • kavyap
  • DreamBathrooms
  • tester
  • InstantRegret
  • ethstaker
  • GTA5RPClips
  • tacticalgear
  • Leos
  • anitta
  • modclub
  • khanakhh
  • cubers
  • cisconetworking
  • provamag3
  • megavids
  • lostlight
  • All magazines