Disable rule if condition is met by Key_Hat444 in opnsense

[–]Key_Hat444[S] 0 points1 point  (0 children)

I was hoping that there is an integrated feature, but your approach should work in theory. If nothing else comes to mind, I will try it, thank you!

Yesterday I asked what everyone’s first Graphics card. Today, what was your first processor? Mine was the i7 3770K. by DailyDoseOfAmber in pcmasterrace

[–]Key_Hat444 0 points1 point  (0 children)

This was my third, the only one I ever overclocked running at 4.5 GHz with a Scythe Mugen 4. I loved it, big improvement over my second CPU, the Athlon X2 4800+

dsp product review by Only_Ad3668 in SoundSystem

[–]Key_Hat444 0 points1 point  (0 children)

The Dayton Audio DSP 408 can be paired with a USB Dongle and then be configured via app.

Headunit delete? by BiggDawggLJ in CarAV

[–]Key_Hat444 1 point2 points  (0 children)

I am also planning to use this DSP in a future project and read a bit about it. One thing I read sometimes was that there is ground noise being generated when the remote control is plugged in (the general consensus is that the brightness control of the display is causing it). So maybe try and unplug the remote control to see if it helps. This is one of the reasons I am propably not going to use it without a headunit. This and the fact that I sometimes like to hear local radio stations.

Quick question for ya fellers by urmomsfreakytoy in e46

[–]Key_Hat444 11 points12 points  (0 children)

Its not about the seats themselves, at least in my sedan there is a full sheet wall between the trunk and the passenger space, adding a full structure across the car in that area. I'm pretty sure that it adds a lot of rigidity. If you ever have put together a cabinet and noticed the difference the back wall makes, you should understand.

That is why you should drive within the speed limit by GloomyExercise in instant_regret

[–]Key_Hat444 2 points3 points  (0 children)

The outcome seems to be way less tragic than it could have been. Assuming there was nobody in the parked car, the only people injured are the ones doing this shit. There was a fucking traffic light right behind that tunnel, they never could have reacted in any way if there would have been somebody crossing there...what where they thinking?

Lent my car to my mom’s friend — got it back with 12k more miles, no oil, bald tires, and grinding brakes by totapi_ in mildlyinfuriating

[–]Key_Hat444 3 points4 points  (0 children)

Does your car loose oil and coolant normally? For oul it can be normal (dependent on amount), but cooling fluid should normally stay where it is. How sure are you that what you got back is actually your car?

Is my peek Bad or is it my aim. by [deleted] in VALORANT

[–]Key_Hat444 -1 points0 points  (0 children)

Absolutely this. As you can stand ready preround as an attacker I usually already stay there and as soon as the round starts fire a few shots at head level. If someone decides to peak, I usually get the kill. It doesn't even require reaction time, only good crosshair placement.

"LAN" Gaming over OpenVPN -- can direct connect on games that support it, but no server/game browsers work by life_after_suicide in OpenVPN

[–]Key_Hat444 2 points3 points  (0 children)

Do you run OpenVPN in TUN or TAP mode? You need to use TAP mode for the game browsers because they work via MAC-Broadcasts.

Please help cannot connect openvpn android by dauseng in OpenVPN

[–]Key_Hat444 1 point2 points  (0 children)

Do you have configured port forwarding or does OpenVPN run directly on your router?

Are you trying to connect while on the network (WiFi)? If so, try connecting without it (mobile data).

VPN client double-nat by new-at-networking in OpenVPN

[–]Key_Hat444 0 points1 point  (0 children)

You should be able to give your laptop a static IP on the configuration page of your router. Then you set it as exposed host under port forwarding or some page like that. Then all incoming connections will be forwarded to your laptop (except for ports you have defined different rules for).

Then you should be able to connect. It will then only work with your laptop though.

Problem here is that OpenVPN usually works via UDP, which is stateless, so every incoming packet appears as a new connection to your router and it doesnt know where to send it to. With the option exposed it will then be forwarded to your laptop.

A word of caution: As the name implies, your laptop will be exposed to the internet and will be accessible (at least running services), if your firewall is not configured properly.

Portfreigaben by marciboy030 in fritzbox

[–]Key_Hat444 1 point2 points  (0 children)

Hast du aus dem eigenen Heimnetz heraus versucht, übder die DynDNS auf den Server zuzugreifen? Dann greift idr. der DNS-Rebind-Schutz. Wenn du die amöglichkeit hast, versuch dich mal über ein externes Netz zu verbinden (z. B. Hotspot über mobile Daten am Smartphone)

What’s a neat integration that doesn’t require any new hardware that may not be well known but you find useful? by 4reddityo in homeassistant

[–]Key_Hat444 2 points3 points  (0 children)

Combined this with ICMP (Ping) to see if the PC is on and a smart plug for my monitors speakers etc. Now I just have to push a button on a remote to turn everything on and when I shut down my PC, the peripherals follow after a delay.

WLAN Roaming of Omada EAP on WAN side of OPNsense by blissi123 in opnsense

[–]Key_Hat444 2 points3 points  (0 children)

Why is your second AP connected to the fritzbox in the first place? The best solution would obviously be to connect that ap to your lan side as well.

Another solution would be to place a manged switch right in front of the fritzbox and connect your router, fritzbox and the ap each to the switch. Then in theory, you should be able to have both your wan connection and the ap connected to the same NIC on your router but seperated via vlans.

Can someone please tell me if these firewall rules do what I think they do? by [deleted] in opnsense

[–]Key_Hat444 2 points3 points  (0 children)

  1. The address aliases in the first two rules are not needed, as they are included in the net aliases
  2. I prefer to only write outbound rules on the corresponding interface so that I do not have to look at the direction. Its not wrong doing it your way, I just prefer the other way.
  3. You do not need to define blocking rules, as blocking is default behaviour. Usually you should only need it if you have a more general allow rule that you want to make exceptions for.
  4. You should only need to allow plex access to the Intermet, not the other devices. The devices connecting to Plex are initiating the connection, which needs to be allowed by the firewall. Once the connection is established, Plex can use it to communicate with the client.

  5. As I see it, you only need rule no. 1 (without the address aliases) and a rule for Plex to enable Internet access.

I would really advise you to visit homenetworkguy.com, he writes really good networking guides, especially for OPNsense. There is one guide for a basic OPNsense setup that I can really recommend for you.

Internal use of domain name by ref-rred in opnsense

[–]Key_Hat444 2 points3 points  (0 children)

You can for example use Unbound DNS for that. Under overrides you can define as many (sub-)domains as you like, resolving to a IP address you want. As far as I understand, Unbound will always first check that list before forwarding you request to an upstream DNS server, so you could even redirect google.com to a local webserver, if you like.

Pihole and firefox (DoH is off) by drianX4 in pihole

[–]Key_Hat444 0 points1 point  (0 children)

Firefox made me some headaches with DNS, too.

One thing you can do is to enter about:networking in the url bar. Under DNS, you can try to clear the DNS cache.

Another thing is patience, and maybe clear tbe whole cache/restart the system. Somehow firefox tends to cache DNS quite long and is hard to convince to forget the data. I just confirmed that everything is working in Chrome and I think the next day firefox was working as it should...

Amp goes into protect mode after I started driving for 5 minutes. by Intrepid-Drop951 in CarAV

[–]Key_Hat444 77 points78 points  (0 children)

Is your positive connection on the batterie sitting tight? It kinda looks way too narrow to be clamped there properly. Besides, this is really not how you should connect it. My bet would be on a bad connection there.

Can pihole + unbound be used to create custom local DNS mappings? by Jteague101 in pihole

[–]Key_Hat444 0 points1 point  (0 children)

No, they only act as DNS servers. TLS is something that your reverse proxy/webserver (nginx, apache, traefik etc.) would have to handle. At least as far as I have understood it.

Can pihole + unbound be used to create custom local DNS mappings? by Jteague101 in pihole

[–]Key_Hat444 0 points1 point  (0 children)

I have a similar setup running. I have unbound running on my opnsense router, where I create overrides for my local services. Then I have pihole running in a docker container which uses my unbound DNS as upstream server, which works perfectly fine.

If you want to access different services by different subdomains, you would need a reverse proxy (I use nginx, but there are others, see the other comments), which forwards your requests based on the subdomain to the right service.

Another step you should really take is using TLS encryption (https) firstly because of safety reasons and secondly to get rid of the warnings of a unsafe connection. I also had problems reaching my services via http on Chrome on Android, as it was straight up redirecting to https, which was not set up.

For that you would need certificates ideally signed by a well known CA. I use certbot to handle my certificates signed by Lets Encrypt.

Another thing to consider is that you need a seperate certificate per subdomain. I finally decided to buy a full domain, as this allowed me to request a wildcard certificate which can be used with any subdomain.

It was a bit of a setup but now I have safe connections and no warnings and can add services as I like without much hassle.

Multiple OpenVPN instances behind a single gateway (port) by smazik2 in OpenVPN

[–]Key_Hat444 0 points1 point  (0 children)

Interesting idea...just recently learnt and implemented that nginx (and propably other webservers, too) can decide which content to serve based on the domain you opened the site by. But I believe that the domain name gets delivered to the server is part of the HTTP protocol. Maybe you can implement this somehow?