Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - xkpx

#31
Hello gentlemens/ladies, still newbie here.

Configuration:
* Removed all DNS by ISP and cleared all possible places, then i set DoT Quad9 in Unbound.
* DNSBL list - https://raw.githubusercontent.com/dibdot/DoH-IP-blocklists/master/doh-domains.txt
* DNSBL whitelist added dns.quad9.net
* DNSBL blacklist with checked NXDOMAIN option, then applied & restarted Unbound server.

Result:
* DOHs are blocked.

Okey, but when i try to open BraveBrowser and connect to internet website is blocked.
Then try to make NAT Port Forwarding rule for 53,853 and redirect to 127.0.0.1;53;853.
But again didn't worked and all websites was blocked.

Did i missed something, and is it possible or if not, maybe with one of these options?
* Suricata and RuleList,
* Firewall-Alias rule add (if list is domain names they are resolved to ip)
* Unbound Override
* Unbound RPZ - https://forum.netgate.com/topic/171887/unbound-dns-rpz/2
* SSL-Split - https://laskowski-tech.com/2020/03/29/opnsense-and-ssl-decryption-using-sslsplit/

( I'am thinking its way better to block on DNS level instead of rule ?)
( Also even if i manage to somehow bypass and get it working , Is it right that i'am just redirecting the request through quad9 and will still arrive at the doh server used by Brave in example ?

Video for information about "Best New" - loss of visibility by managed private networks : https://www.youtube.com/watch?v=04Wugl7yb-k [ Going Dark: catastrophic security and privacy losses...]
#32
HaProxy is going to receive http3 update i hope : https://github.com/opnsense/plugins/issues/3026
#33
Lovely , Thanks for hard work !
Question: is it possbile to cover somehow  multi domain wildcard (for www.firewall.network.com ) -

I got problem with this settings it covers the subdomains but not www.
Common Name: *.network.com
Multidomain name: network.com

Any idea how to issue one cert for all services with subdomains and 1st level domain and www.
Or what is the right way to do this , or maybe to redirect www -> *.network.com without it?

** So far i issued new cert and added in HaProxy and its working so i guess this is the way
www.dev.network.com
#34
Simple and clean tutorial Thanks!
#35
*mark for deletion* excuse me
#36
General Discussion / [delete thread] thanks!
June 26, 2022, 12:04:47 PM
Excuse me!