You should be able to do NPTv6 on the secondary interface. You will probably have to decide which uplink is the primary and use the GUA addresses from that one, then NPTv6 on the other uplink.
This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.
Show posts MenuQuote from: Monviech (Cedrik) on February 23, 2026, 10:52:13 AMDoesn't matter that much. You can use NAT and just bind to random ports no other service uses.
That way you let PF decide which interface can forward traffic to the webserver.
It's always better to bind to the ANY interface since the service will always reliably start.
Quote from: Monviech (Cedrik) on February 21, 2026, 10:34:52 PMJust fyi:
https://docs.opnsense.org/vendor/deciso/opnwaf.html
It's almost the same apache configuration and web application features as in UTM, and we support it fully in business support (if you ever need it).
If you want to stay mostly in community scope HA proxy is also fine.
Quote from: nero355 on February 04, 2026, 06:07:40 PMQuote from: bimbar on February 02, 2026, 10:50:53 AMWe've had terrible experiences with professional Netgear switches regarding port speeds and compatibilities.Any chance you remember the exact models ?
Even if it works, for the homeuser Netgear switches the interface is terrible.
Quote from: OPNenthu on February 01, 2026, 09:13:15 PMQuote from: nero355 on February 01, 2026, 04:57:50 PMIt's one of their weirdest products ever :
- € 200 for the Switch
- € 90 for the adapter
If you can get by with a PoE injector as Patrick suggested, then the non-PoE version of the same switch is the better deal. But at that point the Mikrotik with its 8x 2.5GbE ports is practically begging, even with the fan.QuoteAnd add to that Netgear and HPE switches.
I haven't tried the professional Netgear switches and I do expect better of them, but I had a terrible experience with a cheaper Netgear smart switch and had to return it. It was leaking RAs across the VLANs.