This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.
Show posts Menu192.168.128.4 is my OPNsense IP192.168.128.32 is the actual server IP but i should not have duplicate DNS records.fakebizprez@scum-studio: /Users/fakebizprez
➜ curl -v https://unifiserver.******.cloud
* Host unifiserver.******.cloud:443 was resolved.
* IPv6: (none)
* IPv4: 192.168.128.32, 192.168.128.251, 192.168.128.4
* Trying 192.168.128.32:443...
* connect to 192.168.128.32 port 443 from 192.168.128.10 port 54358 failed: Connection refused
* Trying 192.168.128.251:443...
^C
fakebizprez@scum-studio: /Users/fakebizprez
➜ nslookup unifiserver.******.cloud
Server: 192.168.128.4
Address: 192.168.128.4#53
Name: unifiserver.******.cloud
Address: 192.168.128.4
Name: unifiserver.******.cloud
Address: 192.168.128.32
fakebizprez@scum-studio: /Users/fakebizprez
➜ doggo unifiserver.******.cloud
NAME TYPE CLASS TTL ADDRESS NAMESERVER
unifiserver.******.cloud. A IN 3600s 192.168.128.32 192.168.128.4:53
unifiserver.******.cloud. A IN 3600s 192.168.128.4 192.168.128.4:53
Quote from: meyergru on September 17, 2025, 10:27:52 AMObviously, yes.Thank you, but when it comes to networking, nothing is obvious to me anymore 😭
Quote from: meyergru on September 16, 2025, 11:36:09 PMAFAIK, wildcard certificates work only via the ACME plugin, not via Caddy's own certificate mechanism.So I should use the ACME plugin to get a wildcard cert, and then select that cert in the drop down when configuring Caddy?
Quote from: Monviech (Cedrik) on September 16, 2025, 09:35:00 AMOnly if you want automatic certificates.
Name
linehaulVPN
Addresses
10.50.50.6/32
DNS servers
192.168.128.4
Peer
Allowed IPs
0.0.0.0/0, ::/0
Endpoint
XXX.XXX.130.203:51820
Persistent keepalive
every 25 seconds
QuoteCreating a Simple Reverse Proxy:
The domain has to be externally resolvable. Create an A-Record on a public DNS server that points your domain to the external IP address of your OPNsense.
Quote from: Greg_E on June 20, 2025, 03:13:20 PMQuote from: fakebizprez on June 19, 2025, 05:08:57 PMQuote from: Greg_E on June 18, 2025, 03:25:23 PMThat's seems like a lot of power for OPNsense, not sure I would use an MS-A2 for this function unless I had a lot of clients and a lot of filtering setup. Maybe if I had a lot of VPN users I would want that much CPU, but that's a powerful computer for what most of us are doing.👀
And how much power does that consume? My little Xeon (similar to an older i3) shows mostly the same CPU use, but I only have 16GB of ram. It's TDP is much lower as well.
The HP T740 showed very similar results when I was using it, and that would be at around 40 watts during use.
But again, depends on how many things you are trying to do with a firewall, if you have a lot of VPN, that extra power would certainly be justified over an n150.
Quote from: meyergru on June 19, 2025, 06:58:04 PMI think the official CN for Cloudflare DNS is "cloudflare-dns.com", not "dns.cloudflare.com", see: https://developers.cloudflare.com/1.1.1.1/encryption/dns-over-tls/. Thus, your certificate verification could fail, although IDK if Cloudflare uses multi-domain certificates.they have so many it gets confusing but this is from the link you sent me:
Quotekdig -d @1.1.1.1 +tls-ca +tls-host=one.one.one.one example.com