What do you run; Opnsense, pfsense, Smoothwall, maybe a WAF like wazuh?

Today was update/audit firewall day. I’m running a standalone instance of pFsense on a Protectli Vault FW4B - 4 Port - Intel Quad Core - 8GB RAM - 120GB mSATA SSD with unbound, pfBlockerNG, Suricata, ntopng, and heavily filtered. I did bump the swap to 8 GB as I’ve previously noticed a few ‘out of swap’ errors under load.

Before I signed off, I ran it through a couple porn sites to see if my adblocking strategy was working. Not one intrusive ad. Sweet!

Show me what you got.

    • irmadlad@lemmy.worldOP
      link
      fedilink
      English
      arrow-up
      5
      ·
      22 hours ago

      OpenBSD pf

      I’d never heard of it so I went and checked it out. It seems to have a lot of pFsense/Opnsense features just managed from the cli. Cool.

      • Hobbes_Dent@lemmy.world
        link
        fedilink
        arrow-up
        13
        arrow-down
        1
        ·
        22 hours ago

        It’s the ‘pf’ in pfSense.

        pf is developed as part of the OpenBSD project and is the built in packet filter/firewall.

    • JovialSodium@lemmy.sdf.org
      link
      fedilink
      arrow-up
      4
      ·
      edit-2
      21 hours ago

      Also this. On some unremarkable HP office PC that’s probably about a decade old. No ad filtering or anything as it interferes with others in the house. I’ve thought about trying a second unbound service with adblocking for me, but haven’t gotten around to it.

      • irmadlad@lemmy.worldOP
        link
        fedilink
        English
        arrow-up
        1
        arrow-down
        1
        ·
        7 hours ago

        No ad filtering or anything as it interferes with others in the house

        Ahhh the WAF (Wife Aceptance Factor). I made a seperate Vlan for my lady friend so when she comes over to visit, I don’t have to reinvent the wheel for her. She can have all the ads and slop she can stomach, just keep it on your seperate branch and we’ll both be happy.

      • trailee@sh.itjust.works
        link
        fedilink
        arrow-up
        2
        ·
        16 hours ago

        I run a secondary wifi network with “Ads” in its name, whose vlan doesn’t get forced into pihole DNS. It mostly prevents me from having to hear complaints from others in the house, and they barely ever use it.