Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - almodovaris

#1
Yup, I have disabled Turbo, and I still get 1 Gigabit downloads through Zenarmor.
#2
I don't know about multicore, but "Do not pin engine..." helps a lot.
#3
Some cheap Android phones and cheap Android media players come preloaded with malware.
#4
I use cheap miniPCs as firewalls. They can do 1 Gbps Zenarmor without problems. So, for me multicore Zenarmor is not needed.
#5
There is not any solution which blocks 100% of porn.

E.g., OpenDNS does not flag Usenet as porn, while 95% of Usenet servers teem with porn.

Or websites for big files transfers: you could be downloading gigabytes of porn and most firewalls would not even notice it.
#6
General Discussion / Google Drive
March 14, 2025, 03:24:00 PM
The announcement for 25.1.3 says Google Drive will be phased out. Could you provide a source for it?
#7
Yup, don't use mongodb, use SQL.
#8
Zenarmor (Sensei) / Re: Unsatisfactory TLS inspection.
November 05, 2024, 08:45:37 PM
I think that is due to blocking QUIC. Chromium-based  browsers seem not to like that.
#9
Yup, I had that once due to the security settings of my credit card. I had to explicitly allow payments for Zenarmor.
#10
The filters are not all-knowing, they're work in progress.
#11
Zenarmor (Sensei) / Re: zenarmor devices
September 12, 2024, 11:04:27 PM
Try to ping them.
#12
Disabling clients from using their own DoT, DoH, or DoQ is a complicated matter. Against DoT you have Zenarmor. Against DoQ you can block QUIC in Zenarmor. But DoH blocking is a lot more complicated, unless you have an exhaustive list of all DoH servers. The problem is that anyone may start a DoH server, so such list is never foolproof.

Correction: Zenarmor blocks DoH, not DoT. But the problem that anyone may create their own DoH server persists. DoH is indistinguishable from regular HTTPS traffic. Technically, Zenarmor can inspect HTTPS connections, but that breaks much of the internet and smartphone apps.
#13
In the end, I think this is an OPNsense-only problem. I have Zenarmor running of Debian 12, and it does not have such issue.
#14
About pinging hostnames: that was once a problem in Zenarmor, perhaps you are using a similar app.
#15
And, yup, if the bectl with 24.1 cannot see the crash from another bectl, I have no idea why it prompted me to send the crash reports.