Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - sorano

#1
25.7, 25.10 Series / Re: HAProxy - what did i do?
November 05, 2025, 10:40:35 AM
Quote from: erbmur on November 03, 2025, 07:51:35 PMHi all,

I setup haproxy a long time ago and through blood and sweat I managed to get it to work.
I now want to make some changes and I can't remember what I did!

The main problem I am having is I want to change my front end authenticator from authelia to tinyauth.
looking at the config file, I have a bunch of stuff I somehow managed to manually add to the file, under my public facing services I have a line in the config saying  # WARNING: pass through options below this line, with a bunch of stuff I somehow managed to stick underneath it, but I don't remember where or how I did it, and I need to make some changes to these.

if it helps, whenever I test syntax, I get a soft warning message with a bunch of "[WARNING] (33030) : config : parsing [/usr/local/etc/haproxy.conf.staging:132] : a 'http-request' rule placed after a 'use_backend' rule will still be processed before."

That warning is just a warning and depending on how complex your HAProxy rules are it can be something you just you have to live with. I've been having it for as long as I can remember.
#2
May I suggest tunable replacing realteak with Intel NIC.
#3
You could take a look at LNAV:

https://lnav.org/
#4
Yeah it's that zenarmor crap doing it.

My OPNsense installation have been alot more "Zen" since I just stopped using that piece of trash software.
#5
Then don't lol.

Current DHCPB is not going away (yet).


I'm very happy to see them implement KEA as it's the way.
#6
Cloudflares WAF is a god compared to Zenarmor.

You cannot even compare them feature wise.
#7
Quote from: athurdent on August 09, 2023, 09:28:15 AM
Oh boy, I used to be a big fan of Zenarmor. Now I'm actually considering cancelling my subscription.

Yeah, I canceled my home subscription. Not really worth it anymore, poor QA along with nerfing features was enough for me.

Who cares about a fancy webui when the core features gets broken.
#8
I've never added whitelisted entries from the reporting tab so I wouldn't know.

I add my whitelisted domain in:

Services --> Unbound DNS --> Blocklist
Whitelist Domains: Input FQDN or use regexp.
#9
Does the gateway reply to ICMP?

Try pinging it from your PC.
#10
It works for me, what is the FQDN and how does your whitelist entry look?
#11
General Discussion / Re: Alert for new DHCP client
August 03, 2023, 10:54:44 AM
I guess you could use something to parse the DHCP-log.

However, if you are not explicitly bound to DHCP you could use https://virtualize.link/opnarp/ to be alerted of new ARP entries.
#12
General Discussion / Re: opnsense are crooks
August 03, 2023, 10:32:44 AM
Lol...

You call them crooks yet they deliver one of the best open source firewalls for free.

How about you keep better track on your subscriptions next time?
#13
Haven't used the API so cannot comment on that but the txt lists from here works great:

https://www.cloudflare.com/ips/
#14
I've not used pi-hole for years but you should be able to select a custom server and input your OPNsense IP somewhere  :)
#15
23.1 Legacy Series / Re: ddclient and Dynu DNS
July 18, 2023, 10:41:50 PM
Quote from: skydiver on July 15, 2023, 05:17:34 PM
I am on my third DNS provider trying to find a provider that will work with both the new ddclient and also the new ACME client.

Cloudflare works wonderfully.