Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - muchacha_grande

#1
26.1 Series / Re: Rules [new] Sort order Sequence?
February 04, 2026, 05:21:36 PM
Ok, thank you for your time and work. The new gui is really impressive.

Quote from: Monviech (Cedrik) on February 04, 2026, 04:46:18 PMJust set the sequence to 0 on the WAN rule and it should be before all other WAN rules


By the way, sequence 0 is not allowed on the gui. The input error is "Sequence shall be between 1 and 999999."
#2
26.1 Series / Re: Rules [new] Sort order Sequence?
February 04, 2026, 04:59:54 PM
Quote from: OPNenthu on February 04, 2026, 04:47:18 PMThis doesn't seem right.  Interface rules have priority group 400000, not 300000.  Are you sure you have an interface rule with 300000?  That violates the docs and could be a bug.

You are right, it was a typo, sorry. It is 400000.000001.

Quote from: Monviech (Cedrik) on February 04, 2026, 04:31:18 PMIt gets processed in the way you see it sorted in the GUI.

Quote from: Monviech (Cedrik) on February 04, 2026, 04:46:18 PMJust set the sequence to 0 on the WAN rule and it should be before all other WAN rules?

I know that floating rules should not be needed for my general blacklist case but if the rules are processed in the sorted order on the GUI, I can see the floating rules first, then the group rules and finally the interface rules. And inside each group the rules are ordered by the sequence number, that is only the second part of the sort order. So that is my confusion.
#3
26.1 Series / Re: Rules [new] Sort order Sequence?
February 04, 2026, 04:37:15 PM
So, to get the functionality of the general backlist as I had before with the floating rule. Do I need to modify the interface rule to make it a floating one, e.g. enabling a second interface on the rule? could be a loopback?

Or may be there is a more elegant way of achieving it?
#4
26.1 Series / Re: Rules [new] Sort order Sequence?
February 04, 2026, 04:28:10 PM
Just to be sure, I have a floating rule with sort order 200000.0000011, then a group rule 300000.0000021 and finally an interface rule 300000.000001. Does it mean that the interface rule will be processed before the floating and the group rules?

I have to make sure that the interface rule is processed first because is a general blacklist.

In the old rule system I had the blacklist declared as a floating rule with only the WAN interface selected.
#5
26.1 Series / Re: DNS port forwarding does not work
February 04, 2026, 01:51:23 PM
I'm using 127.0.0.1 as redirection address.
#7
26.1 Series / Re: Nextcloud Backup creates multiple files
February 01, 2026, 05:35:05 PM
+1

Quote from: Patrick M. Hausen on February 01, 2026, 03:57:28 PMAt the very least use readable timestamps for which alphabetical and chronological order is identical like YYYY-MM-dd-hh:mm:ss or similar.

I had to disable the plugin too. Many files with meaningless names.

To me, lock to the previous version as Franco says can't be a long term solution, so I had to stop using it.
#8
26.1 Series / Re: Nextcloud Backup creates multiple files
February 01, 2026, 03:28:15 PM
Ok... thank you

I've closed the request.
#9
26.1 Series / Re: Nextcloud Backup creates multiple files
February 01, 2026, 03:22:00 PM
I have opened a feature request to have an option that allows the user to opt for the previous behavior.

The problem with backing up the conf/backup directory is that when using nginx plugin, it uses the configuration to maintain the list of banned IPs, and this changes the config many times per day generating a huge amount of files.

I don't need to backup every of theses configs. So having the chance to use the original method would be useful in my case.
#10
26.1 Series / Re: Suricata - Divert (IPS)
January 31, 2026, 09:38:57 PM
Quote from: Monviech (Cedrik) on January 31, 2026, 08:59:17 PMNo packet is passed back to the firewall to match another rule on the same interface afterwards.

Does it mean that it doesn't matter the selection of pass, reject or block on the "divert-to" rule?
#11
26.1 Series / Re: Suricata - Divert (IPS)
January 31, 2026, 06:39:26 PM
I have a (maybe dumb) question:

When using "divert-to" the matched packet is sent to Suricata to be inspected. After that, Suricata is responsible for the evaluation of the packet and not pf anymore.

Who is in charged of rejecting, blocking or passing the packet?

I can imagine that Suricata responds to pf with a verdict and is pf who blocks or pass the packet.
#12
26.1 Series / Re: Can't import rules in new rules UI?
January 29, 2026, 04:00:57 PM
The button is the checkbox beside the filename
#13
26.1 Series / Re: 26.1 is out!!!
January 28, 2026, 02:07:46 PM
We are anxious =)
#14
So, the renew process will have to run more regularly but the TXT record will be reused so there will not be the need to create a DNS record on each renewal.
#15
Ok, just take into account that if you are using an alias in your "NAS allow" firewall rule and that alias takes its IP from DNS, that could be the problem because switching to Dnsmasq could make the alias table to not populate anymore with the NAS IP.
That's what I wanted to make sure.