Recent posts

#1
26.1 Series / Re: Destination NAT (port forw...
Last post by meyergru - Today at 05:30:55 PM
What does a redirect IP of "This Firewall" even mean? "This firewall" is the set of all adresses the firewall has.

Use an explicit IP like 127.0.0.1 and it will work.
#2
26.1 Series / Re: unbound bug. DHCP clients ...
Last post by jonny5 - Today at 05:30:10 PM
Not terribly often talked about, but, all FQDNs (even domains) have a period at the end. So, "google.com" is actually "google.com." and we just get to skip the last period because we never had to use it, they have let us skip it since for about forever (in nearly every service, save, Raw/back-end DNS).

At times like this you see the standard show up where you get to see the last period at the end of a name on the network.
#3
25.7, 25.10 Series / Re: Periodic interface reset -...
Last post by clarknova - Today at 05:29:34 PM
So I scheduled the interface reset for a few minutes after midnight, but as it turned out, OPNsense grabbed a new lease with the new IP address 1 or 2 minutes before midnight. I'm not sure what triggered it, but there must have been something on the provider's side that minimised my down time. I ended up deleting the cron job before it ran.
#4
German - Deutsch / Re: Mini PC
Last post by meyergru - Today at 05:22:35 PM
Quote from: k0ns0l3 on Today at 05:01:26 PMBilliger wird nicht mehr

Doch: https://www.amazon.de/HSIPC-Firewall-Appliance-Router-i226-V/dp/B0CP1VZRG7 - dort kostet es mit RAM und Platte soviel wie bei ipu-system ohne.

 
#5
General Discussion / Re: Deutsche Telekom - Glasfer...
Last post by meyergru - Today at 05:04:04 PM
You should talk to them directly, but I would think they want it covered, because when that breaks outside your house for whatever reason (e.g. vandalism), it is their obligation to fix it.

The ballpark for such things is 30-50€, as I already wrote. The Leox LXT-010H-D should work for Telekom, because they use VLANs (I still was unable to get it to work for DG). It costs ~31€. The Telekom Glasfaser Modem 2b is ~40€ and that should work with Telekom for sure...
#6
26.1 Series / Re: unbound bug. DHCP clients ...
Last post by vimage22 - Today at 05:01:44 PM
This was odd to me as well when it first happened. I did a google and it led me to the official documentation on the kea website. I forget the entire explanation, but it had something to do with windows OS, I think. The dot, in kea's world, is a signal to not try and resolve the hostname beyond that trailing dot. Do not know why that concept is important to kea. And I did not see a pattern. Some leases had it, others did not.
unbound did crash when I added the reservation, before I realized I needed to remove the trailing dot.
#7
German - Deutsch / Re: Mini PC
Last post by k0ns0l3 - Today at 05:01:26 PM
Hier kannst auch nachschauen

https://www.ipu-system.de/
 
Billiger wird nicht mehr oder etwas gebrauchtes finden.
Lg
#8
General Discussion / Re: Deutsche Telekom - Glasfer...
Last post by chemlud - Today at 04:57:18 PM
If I buy an ONT: How much (ballpark)?

The old telephone line enters the house to the best of my knowledge in the basement, EAST side. The router would be one level up and to the very WEST. So kind of nightmarish, no matter it CAT6/7 or fiber.

Extra question: How deep does Der Gilb dig outside the house? Still 80cm something at least? No microtrenching or so?

Maybe I should ask for an ONT to be placed direct at my network-equipment, (first floor, so the fiber would be on the OUTSIDE of the house, before entering through the wall? Sounds crazy...)
#9
General Discussion / Re: Deutsche Telekom - Glasfer...
Last post by meyergru - Today at 04:52:46 PM
Really? Interesting. Both M-Net and Deutsche Glasfaser give you one. Either way, they are dirt cheap (30-50€). I just bought an LXT-010H-D from wisp.pl and that also has 2.5 Gbps.
#10
26.1 Series / Re: [SOLVED] NTP Redirect via ...
Last post by meyergru - Today at 04:48:56 PM
I would doubt that - unless you mix tagged and untagged traffic on the same physical interface and the rule somehow applies to you camera VLAN as well. You can look at /tmp/rules.debug to convince yourself of what gets thrown at pf.

P.S.: If you did the same as here, namely to redirect to "This Firewall": try 127.0.0.1 instead. Details matter.