If you want to take it even further a fully virtualized Opnsense with Proxmox is amazing. Your router can float between cluster nodes and each VLAN becomes a virtual interface in the hypervisor. What still blows my mind is how I can migrate the instance to a second server and bring the original server down for maintenance without my users noticing a thing.
Got any documentation on how a setup like this might be implemented? I'm curious how the interfaces float between nodes to keep the network up. Is it relying mostly on switches for the physical connectivity, including upstream?
OPNsense: Open-source security platform
131–140 of 151 posts
Re: OPNsense: Open-source security platform
#132If you want to take it even further a fully virtualized Opnsense with Proxmox is amazing. Your router can float between cluster nodes and each VLAN becomes a virtual interface in the hypervisor. What still blows my mind is how I can migrate the instance to a second server and bring the original server down for maintenance without my users noticing a thing.
As long as your Proxmox Cluster is backed by shared storage (ceph, gluster etc.) and HA is configured for your opnSense VM you can just shutdown the Node. Works flawlessly with pfSense (PVE backed by ceph). Even SIP calls don't get disconnected
Re: OPNsense: Open-source security platform
#133How well does OPNsense deal with bufferbloat in a home networking situation? It appears to implement fq_codel for traffic shaping, but not the newer cake algorithm. Test: https://www.waveform.com/tools/bufferbloat
Huh, TIL about bufferbloat. I run OPNsense (very happy with it) and had a B, so I followed this guide ( https://docs.ibracorp.io/opnsense/ ) and I now have A+. Do you have any information on fq_codel vs cake?
https://www.bufferbloat.net/projects/codel/wiki/
https://www.bufferbloat.net/projects/codel/wiki/CakeTechnica...
Re: OPNsense: Open-source security platform
#134Earlier quoted context omitted.
This and the debacle with Wireguard are the two top reasons that have kept me on OpenWRT.
Debacle with wireguard? Opnsense has wireguard easily available. Also, it's just base wireguard, so you don't have to go through any extra steps of trying to understand / trust other additions on top of it, which is very nice IMO.
[1]: https://www.phoronix.com/news/FreeBSD-WireGuard-Lands-2022
[2]: https://arstechnica.com/gadgets/2021/03/buffer-overruns-lice...
Re: OPNsense: Open-source security platform
#135Earlier quoted context omitted.
I switched to pfSense from EdgeRouter a few years back, and find the firewall rules make _less_ sense. The reason is likely that I understand IPTables pretty well, where as the approach used in pfSense seems "abstract" in comparison. I'd certainly recommend grabbing something like a Protectli box (if power draw is a concern) or building a small server with NICs to install OPNSense on over the Ubiquiti stuff. For me,…
I recently switched to RouterOS. The learning curve was a bit high to me. I'm still tinkering with it but I got my main things working - vlans, default internet access out via vpn, one port (internet accessible server) routed without vpn. I learned a lot in the last 3 weeks it also helped me understand networking a lot more. Sure I had to do a lot of trial and error or figure out why things don't work but in the end…
So far the only one which is never blocked is cloudflare’s WARP but I suspect it’s because it’s newish (the VPN functionality of WARP is at least, originally it was mostly about DNS). But it has severe performance problems when running on a router as far as I can tell, I suspect it has to do with MTU, but I couldn’t solve it so far.
Next I was going to Google One’s VPN, but I don’t think it’s a candidate for me, I want to use a VPN for privacy, so google is probably not the best choice.
The sites which are blocked are mostly enterprise login pages. As I work from home, it’s a no go for me. Secondly, I need to connect via VPN to some company network a couple of times a day and the performance of “VPN over VPN” is currently catastophic, it’s just unusable. Not sure if it’s also related to MTU…
Re: OPNsense: Open-source security platform
#136Earlier quoted context omitted.
The pfsense people are, frankly, fucking clowns. They bought the domain opnsense.com and used it to badmouth the opnsense project[0]. Do not give pfsense time, attention, or money. [0] https://opnsense.org/opnsense-com/
I remember reading this nearer the time, but I never clicked through to see just what was on the site; having just looked at the cache, I'm appalled. That stuff goes beyond petty, to the point that whoever is behind that should not only NOT be doing business with the grown ups, they should be in a facility seriously re-evaluating their life choices. What a disgrace.
Well, you don’t have to wonder, the owner of the domain was revealed by court action to be Jamie Thompson, one of the two founder of Netgate, which sells the commercial version of pfSense. Surprise…
Re: OPNsense: Open-source security platform
#137Pfense is practically no longer open source. OPNsense has come a long way and even has some features pfsense does not
They also like to tell you why you're wrong for wanting wireguard (so it's for your own good they don't support it) instead of letting you make up your own mind. No thanks.
Re: OPNsense: Open-source security platform
#138Earlier quoted context omitted.
I switched to pfSense from EdgeRouter a few years back, and find the firewall rules make _less_ sense. The reason is likely that I understand IPTables pretty well, where as the approach used in pfSense seems "abstract" in comparison. I'd certainly recommend grabbing something like a Protectli box (if power draw is a concern) or building a small server with NICs to install OPNSense on over the Ubiquiti stuff. For me,…
I'm the other way, I find IPTables less intuitive and featureful than PF. The way Netfilter/IPTables works under the hood seems much more over-complicated[1] than it needs to be (which is how I feel about a lot of Linux system stuff these days). The architecture of PF[2] (and thus how the rules get processed) just makes more sense to me. pfSense/OPNsense is just a stripped-down FreeBSD under the hood. If there are th…
I'd love to build a BSD based router/firewall in a declarative manner/source controlled configuration on top of a vanilla OS, I just don't have the time (specifically network downtime for the home, family) to play with it.
I like graphs and charts, but otherwise not a massive fine of GUIs that hide functionality and complexity, would rather know/understand exactly what's going on at the CLI.
Thanks for the links, no time like the present to learn more!
Re: OPNsense: Open-source security platform
#139Recently transitioned from Ubiquit stuff to a OPNSense setup. It was such a good decision. The firewall rules make much more sense. Better functions than the dream machine series. You can also get a lot more for the same price. Ubiquti hardware is very under spec for the money you pay for. Highly recommend this guide to setup your own. It’s very dense and more verbose than you need so skip the irrelevant sections. [1…
I switched to pfSense from EdgeRouter a few years back, and find the firewall rules make _less_ sense. The reason is likely that I understand IPTables pretty well, where as the approach used in pfSense seems "abstract" in comparison. I'd certainly recommend grabbing something like a Protectli box (if power draw is a concern) or building a small server with NICs to install OPNSense on over the Ubiquiti stuff. For me,…
As a bonus I have xcp-ng spin up a ubuntu server with Portainer running things like pihole / unifi controller / plex / a terraria server. I also decided to randomly throw in a cheap nvidia GPU for some extra oomph. Highly recommend it for tinkerers, and the only reason I would spend more for the protectli is if the fan noise of a mini PC might be a nuisance.
Re: OPNsense: Open-source security platform
#140Earlier quoted context omitted.
It looks like the maintain a dhcp6c [0] already. Do they not use it? Edit: I checked the source and they are already utilizing it [1]. 0. https://github.com/opnsense/dhcp6c 1. https://github.com/search?q=repo%3Aopnsense%2Fcore+dhcp6&typ...
I think dhcp6c is the problem? FreeBSD provides a better option, but they aren't using it.