What do you run; Opnsense, pfsense, Smoothwall, maybe a WAF like wazuh?

Today was update/audit firewall day. I’m running a standalone instance of pFsense on a Protectli Vault FW4B - 4 Port - Intel Quad Core - 8GB RAM - 120GB mSATA SSD with unbound, pfBlockerNG, Suricata, ntopng, and heavily filtered. I did bump the swap to 8 GB as I’ve previously noticed a few ‘out of swap’ errors under load.

Before I signed off, I ran it through a couple porn sites to see if my adblocking strategy was working. Not one intrusive ad. Sweet!

Show me what you got.

  • Zoma@sh.itjust.works
    link
    fedilink
    arrow-up
    3
    ·
    17 hours ago

    I’ve been using Ufw but airvpn’s kill switch seems to override it, should i be using something else?

    • irmadlad@lemmy.worldOP
      link
      fedilink
      English
      arrow-up
      2
      ·
      16 hours ago

      I have found that a lot of VPN kill switches interfere with other security measures. For instance, I use tailscale on my VPS. I also run a local VPN. If I have the kill switch on the local VPN engaged, it interferes with tailscale and I cannot ssh in to my VPS. So, a not so elegant solution for me is to disengage the local VPN’s kill switch for that session, and then re-enable it after I am finished administering my VPS. After which I will do a DNS leak check to make sure everything is as it was. Takes a couple of quick steps, but it seems to work.