Skip Navigation

Posts
3
Comments
159
Joined
1 yr. ago

Rocket Surgeon

  • Meh. I like things my way. There's a certain satisfaction there.

  • Ok. Then don't use windows. Sounds good.

  • I corrupt the files. I take ownership, remove inheritance, and then deny Trusted Installer and System access. My windows systems generally have several components neutered like this. Major upgrades will sometimes overwrite my changes, but mostly they stick. Absolutely nonfunctional.

  • I'd try slurm. Once. Ain't putting the bottlecap next to my nuts tho.

  • I quit drinking soda years ago as I got older and needed to cut shit that was making me fat.I will (like every other year) occasionally have a Mountain Dew or a Sprite.Soda is lovely stuff, but its definitely radioactive.

  • Nuka-cola is hard to come by here tho.I've wondered ... are the bottlecaps radioactive?How does that work out when you have a pocketful next to your nuts?

  • Yup. I pay about $6/month for Hetzner with my NextCloud. Love it.

  • Cool. Yes, this looks reasonable. It looks logical.

    So, my main recommendation is consider the use of virtual bridges to manage the network instead of passthrough. And I recommend installing and using the OVS style virtual bridge.https://pve.proxmox.com/wiki/Open_vSwitch

    This gives you flexibility going forward. Say you want to run something out in the DMZ instead of behind the firewall, well you just attach that VM to the DMZ bridge instead. And it gives you an easy way to provision network for VMs. You just attach them to the LAN bridge.

    (RoaS is a terrible name. Router on a Stick. It means your router is on the same switch as its clients, and all the communications go up and down that one port. It's a perfectly legit way to manage a network, but sorta ugly and not what you are doing with your fancy 3-port rig. :)

  • I own 2 OpenWRT routers. Fun little things. Love em.But running a virtual firewall is a perfectly reasonable goal. OpenWRT doesn't have the feature set that OPNsense has.They are not the same sort of product. Lot of common ground, but not the same thing.

  • There's a few things we don't know here.

    • Are you hosting more VMs on Proxmox that need network via a virtual switch?
    • Are you providing network to other physical devices as well via a switch, so you need to output to that?
    • Do you want OPNsense to be your gateway and assign IPs, or do you have a router?
    • As you have 3 NICs and sound like you want to use them, let's assume you aren't doing RoaS, but this could all be done on one (very busy) NIC.

    There's nothing wrong with your plan, but that's not how I would do it.I don't pass through NICs. I bond them or I bridge them.In a virtual world, this sort of task is done with virtual switches. OVS switches at my job.OVS is a lot easier to use than oldskool linux bridges that come installed with Proxmox. There's already a dropdown in Network where you can build with OVS objects, but you need to add the package.apt install openvswitch-switch

    • MGT. For your setup, I might consider (the onboard!) eth3 as my mgt NIC. That might be handy some day if you have to remove that card. Your server will still be online.
    • DMZ WAN. I would run the WAN line straight to eth1. Add eth1 to a 'dmz' virtual switch. Add the OPNsense WAN leg to this dmz virtual switch, so the OPNsense (and nothing else) can directly talk to the upstream router.
    • LAN Virtual. Create a 'protected network' virtual switch. Add the OPNsense LAN leg to this virtual switch. VMs can be a member of this downstream protected network and access any services provided by the OPNsense.
    • LAN Local. If you need to share the OPNsense protected network back out to other devices, add eth2 to to the protected network switch, and ethernet cable out from eth2 to a dumb switch. Plug other external devices into the dumb switch, and they will be downstream from and protected by your OPNsense, accessing its services.

    Feel free to ignore me here. I build a lot of big things, so I use enterprise-scale techniques. There's nothing wrong with your pass-through plan.And ... you can do this! I have a somewhat similar setup on my laptop with HyperV, so I can distribute wired (work VPN) and wireless (everything else) internet to guest VMs and the main OS. I made two virtual switches in HyperV.

    • The first switch gets exclusive access to my NIC attached to my VPN device. This is the OPNsense WAN leg.
    • The second switch is the OPNsense LAN leg and VMs are members.

    Good luck!

  • It's interesting that you are not a bot and have some purpose, but I'm blocking you anyway. Crossposts suck.

  • I recently earned the Cisco CCST Cybersecurity cert.Over and above the CCST Network cert, I learned a few things about configuring firewalls, ACLs, and zones.But at least a third of the entire cert was this bullshit.Lingo. Abbreviations. Dumb new ways to not say what you mean.

  • Trust me. You need Plextastic. Its got all the cool new stuff. Just a small fee.You will come around.

  • Please yes. I want this to be a thing.

  • Gotta refresh em sometimes. When ublock stops managing youtube perfectly, I reload all the filters. Sometimes I don't even need to close out the browser, just the filters.

  • Totally off topic, but I drink at a bar called Spaghetti Western!Hillsboro, OR.

  • Ya, that's the really obvious take. That's teh way you do biz these days.Like, that's what's gonna happen to all those 'lifetime' Plex accounts. Sure, you still have access to 'Plex-classic'. But you don't get any of the new Plextastic services ... unless you want to pay the $1,999 upgrade fee ...

  • So much venom. That's weird. Because they are all useful to some degree or another.

    I use Brave. (The free one. Obviously.)

    And I use Vivaldi. And Firefox. And Waterfox.And even Chrome.

    I do a lot of work through browser-based utilities. I like to set one browser up with all my server clusters pinned. This is the Brave/Vivaldi role. It doesn't go online, just server mangement.And I'll set up Chrome with all my work sites. Because that's the standard, and its gonna run all that work shit reliably. Login to my work google here.And I want a dirty actual-browser with uBlock, SuperStop, and kill-sticky. Usually Firefox. Might get my personal gmail here.If I'm on a machine where I need an additional role, or perhaps some extension that I don't want in my main browser, I install another browser to handle it.They are tools, folks. Use em. Don't let them use you. Don't be a tool.:]

  • Technology @lemmy.world

    Replication of Quantum Factorisation Records with an 8-bit Home Computer, an Abacus, and a Dog

    www.zhaw.ch /en/about-us/news/news-releases/news-detail/event-news/replication-of-quantum-factorisation-records-with-an-8-bit-home-computer-an-abacus-and-a-dog
  • Ask Lemmy @lemmy.world

    Is this a spoon or a spatchula?

  • Ask Lemmy @lemmy.world

    Anybody else block Lemmit.Online spambot?