TheHolm

joined 2 years ago
[–] TheHolm@aussie.zone 3 points 1 year ago (9 children)

using wildcards is really bad security practice. and at age of ACME absolutely unnecessary.

[–] TheHolm@aussie.zone 1 points 1 year ago

No HA. Classic HA is evil, shared control plane is good way to loose both FWs. Need redundancy use 2 independent FW + routing protocols. Losing session states during fail-over is not a big problem these days. I did in-place upgrades, but I'm running LTS and not yet done any major version upgrades. So far no problems.

[–] TheHolm@aussie.zone 1 points 1 year ago (2 children)

Sorry, what do yo want to know? IT just a linux based router pretended to be a juniper FW. NAT/IPv6/PPPoE/VRFs are working as expected.

[–] TheHolm@aussie.zone 1 points 1 year ago* (last edited 1 year ago)

Look to FIIO. They have million models for all budgets. I'm using E10K for last 5? years. Best 100$ I ever spent. I would add physical volume knob on it is extremely convenient. Love it.

[–] TheHolm@aussie.zone 1 points 1 year ago

Can you promise a near 100% uptime? Otherwise, some email might not reach you. Just lol. Mail get queued just fine by everyone. If you really concern , setup second MX.

[–] TheHolm@aussie.zone 3 points 1 year ago (4 children)

VyOS: Debian based router + firewall. Linux makes it easier for people to pick up the CLI but I’ve heard complaints about it being difficult to follow. Currently CLI only, at least without third-party solutions, but is powerful and competes directly with OPNsense for features for the most part. Seems to be just as stable. my mistake, FOSS version is not LTS but a rolling release and needs to be compiled.

Very misleading statement. Both rolling and LTS are FOSS, they just do not provide LTS binaries for free. Want LTS? build it yourself , all tools and guides(bit outdated) is out there. It will took 30 min you your time to setup.

[–] TheHolm@aussie.zone 2 points 1 year ago (1 children)

Stable is not "pay only" . Just build it yourself, all tools are available. it will take 30 minutes of your time if you have docker environment ready.

[–] TheHolm@aussie.zone 0 points 1 year ago (1 children)

Are you running it natively as "jail" ?

[–] TheHolm@aussie.zone 2 points 1 year ago

Nothing can beat bhyve for PFSence.

[–] TheHolm@aussie.zone 3 points 1 year ago (2 children)

I do not understand why everyone calling hosting email difficult? IT is like 5 RFC you need to read and implement. Sofware wise you will need mail agent, something for DKIM ( if it not build in in agent), "local delivery agent" ( probably presenting it as IMAP) + mail reader of your choice. Nothing too complex

[–] TheHolm@aussie.zone 2 points 1 year ago

Do not try to host outbound mail on residential IP blocks, delivery will be really bad. Cheap VPS is same story. You best bet is VPS from some not well know provider, they may be avoid to be in blacklist in M$ and Google. Inbound mail is fine anywhere as so long as you can have port 25 open. DDNS works too.

view more: ‹ prev next ›