Recent posts

#1
German - Deutsch / Re: [SOLVED] DynamicDNS, Hetzn...
Last post by open - Today at 06:02:32 PM
Jetzt wollte ich Dir ein Scrrenschot schicken, auf dem Du siehst, das hier nur Hetzner DNS zu sehen ist.
Naja, keine Ahnung warum, ob es einfach dauert oder ob der zwischenzeitliche Reboot etwas geändert hat, aber jetzt steht hier auch bei mir Hetzner DNS und Hetzer DNS (Legacy). Vielleicht wäre als Name HetznerCloud treffender. Dann ist es eindeutig, das es die Cloud API anspricht.
Egal, Eintrag ist aber da und es funktioniert auch.
Solved stimmt also ;)
Danke
#2
26.1, 26,4 Series / Re: Change WAN based on RTT/Pi...
Last post by meyergru - Today at 05:40:40 PM
You can use gateway groups for that and use specific trigger levels - it is in the official docs.
#3
26.1, 26,4 Series / Change WAN based on RTT/Ping
Last post by inkeliz - Today at 05:35:01 PM
I currently have three WAN connections. My primary goal was to use them for failover and basic load balancing.

However, I've noticed that latency and routing change between ISPs on a weekly or monthly basis. Some ISPs have terrible routes to specific servers, especially international ones (for example, Brazil ↔ Europe). I'd like to know whether OPNsense can automatically switch the WAN based on latency.

Does OPNsense provide a feature that can continuously ping a set of IP addresses and choose the WAN with the lowest latency?

For example, consider three WANs: WAN_A WAN_B, and WAN_C.

The idea would be:

* WAN_A → ServerSaoPaulo = 170 ms
* WAN_B → ServerSaoPaulo = 230 ms
* WAN_C → ServerSaoPaulo = 123 ms

In this case, I would want all connections to ServerSaoPaulo to use WAN_C* OPNsense should only switch to WAN_A or WAN_B if WAN_C experiences high latency or significant packet loss.

For connections to ServerSomewhereElse: any of the WANs can be used.
#4
Quote from: vpx23 on Today at 04:03:41 PMPSU: FSP FlexGURU 300W

€ 69.44
geniuzcom.de

https://preisvergleich.heise.de/fsp-flexguru-300w-fsp300-57fcb-a2203423.html
https://www.fsplifestyle.com/en/product/Flexguru300W.html
Are you 100% sure it's actually a good one ?!

The Power Supply market is one big minefield sadly... :(

QuoteMainboard: Supermicro A2SDi-4C-HLN4F

€ 386.19
Plexcom Hardware For You

https://preisvergleich.heise.de/supermicro-a2sdi-4c-hln4f-bulk-mbd-a2sdi-4c-hln4f-b-a1710120.html
https://www.supermicro.com/en/products/motherboard/A2SDi-4C-HLN4F
Seems expensive for a Firewall and in range of Mini PCs that will do the job just as good ?!

QuoteECC RAM: ATP A4B04QG8BLPBSE (2x 4 GB)

2x 53.12 € = 106.24 EUR (Not in stock, just for reference)
Mouser

https://eu.mouser.com/ProductDetail/ATP-Electronics/A4B04QG8BLPBSE?qs=iLbezkQI%252BsjpkBexVW6rQA%3D%3D
https://www.atpinc.com/products/industrial-dram-module-ddr4
HOLY CRAP BATMAN !!! That's fucking expensive!

RAM prices have really gone INSANE !!! :(

QuoteM.2 SSD: Swissbit SE2600BC020GI-1TB1-1CB-STD (20 GB SLC)

52.65 € (Not in Stock, I know it's only a pure flash module, just for reference)
DigiKey

https://www.digikey.de/en/products/detail/swissbit/SE2600BC020GI-1TB1-1CB-STD/22320996
https://www.swissbit.com/de/produkte/produktsuche?pn=SE2600BC020GI-1TB1-1CB-STD
Didn't know you can still buy SLC stuff! COOL! :)

QuoteOptional: Inter-Tech ST-7238 (4x Intel i350)

€ 89.90
Mindfactory

https://preisvergleich.heise.de/inter-tech-argus-st-7238-lan-adapter-77773010-a2709788.html
https://www.inter-tech.de/produktdetails-198/ST-7238_EN.html
Why not eBay the thing for like € 35 or so ?!

You might get DELL stuff that needs a piece of tape on certain pins, but hey : If it works = Who cares ?! ;)

QuoteOptional: StarTech/Delock Serial port cable with header

3-5 EUR

https://www.delock.de/produkt/89900/merkmale.html?setLanguage=en
https://www.startech.com/en-eu/cables/pnl9m16
I hate DeLock products to be honest!

I have one of these : https://www.aten.com/global/en/products/usb-solutions/converters/uc232a/
And then just a TTY Enabled on it's USB Port at my Raspberry Pi 3B for Serial Console Access :)
#5
A system like that can be had from Quotom (Q20322G9) with passive cooling, plus it has 4x SFP+ ports on top of 5x 2.5 GbE ports instaed of 5x 1 GbE.
#6
Why such a large case and way oversized power supply for a firewall? A Supermicro A2SDi-4C-HLN4F fits nicely into a Supermicro SC101F, power supply already included.

If you need an additional network card you can go with an SCE300 for the case.

I have both cases, SC101F with exactly the suggested mainboard and the SCE300 with an X10SDV-4C-TLN4F.
#7
Hardware and Performance / OPNsense BlackBox Concept (OBB...
Last post by vpx23 - Today at 04:03:41 PM
Just throwing together a little box for OPNsense.

Case: Inter-Tech S31B

€ 61.77
geniuzcom.de

https://preisvergleich.heise.de/4013915216
https://www.inter-tech.de/productdetails-155/S31B_EN.html

PSU: FSP FlexGURU 300W

€ 69.44
geniuzcom.de

https://preisvergleich.heise.de/fsp-flexguru-300w-fsp300-57fcb-a2203423.html
https://www.fsplifestyle.com/en/product/Flexguru300W.html

Mainboard: Supermicro A2SDi-4C-HLN4F

€ 386.19
Plexcom Hardware For You

https://preisvergleich.heise.de/supermicro-a2sdi-4c-hln4f-bulk-mbd-a2sdi-4c-hln4f-b-a1710120.html
https://www.supermicro.com/en/products/motherboard/A2SDi-4C-HLN4F

ECC RAM: ATP A4B04QG8BLPBSE (2x 4 GB)

2x 53.12 € = 106.24 EUR (Not in stock, just for reference)
Mouser

https://eu.mouser.com/ProductDetail/ATP-Electronics/A4B04QG8BLPBSE?qs=iLbezkQI%252BsjpkBexVW6rQA%3D%3D
https://www.atpinc.com/products/industrial-dram-module-ddr4

M.2 SSD: Swissbit SE2600BC020GI-1TB1-1CB-STD (20 GB SLC)

52.65 € (Not in Stock, I know it's only a pure flash module, just for reference)
DigiKey

https://www.digikey.de/en/products/detail/swissbit/SE2600BC020GI-1TB1-1CB-STD/22320996
https://www.swissbit.com/de/produkte/produktsuche?pn=SE2600BC020GI-1TB1-1CB-STD

Optional: Inter-Tech ST-7238 (4x Intel i350)

€ 89.90
Mindfactory

https://preisvergleich.heise.de/inter-tech-argus-st-7238-lan-adapter-77773010-a2709788.html
https://www.inter-tech.de/produktdetails-198/ST-7238_EN.html

Optional: StarTech/Delock Serial port cable with header

3-5 EUR

https://www.delock.de/produkt/89900/merkmale.html?setLanguage=en
https://www.startech.com/en-eu/cables/pnl9m16

Total price: 676.29 EUR (766.19 EUR with optional Add-On NIC)
#8
German - Deutsch / Re: [SOLVED] DynamicDNS, Hetzn...
Last post by meyergru - Today at 03:04:20 PM
Das ist nicht wahr: Ich sehe "Hetzner DNS" und "Hetzner DNS Legacy (deprecated)" als Service in der GUI angeboten (26.1.11_5).
#9
26.1, 26,4 Series / Re: Problem with shutdown/rebo...
Last post by mrzaz - Today at 02:15:36 PM
Just for info.
Upgraded to latest but it still hanged as before not able to shut down unless kill -9 <suricata process>
It is still running suricata   8.0.5_2   59.3MiB   unknown-repository   GPLv2   High Performance Network IDS, IPS and Security Monitoring engine

//Dan Lundqvist
#10
Thanks, that's the solution to my problem. I'm already forwarding the ACME HTTP-01 Challenge redirect to my Proxmox Mail Gateway (PMG), and it's working. I'm not sure if the TLS-ALPN-01 works for Caddy itself, since my internet provider doesn't offer IPv6. However, I'm having an issue with my PMG, which sends a spam report via email and provides a link to the same domain for marking spam emails as such. Here, access is routed through the reverse proxy to the PMG website itself, and a certificate for Caddy itself is required for this.