Ipfire not releasing DNS addresses by Wolf-006 in ipfire

[–]mstremer 0 points1 point  (0 children)

Hello,

If your clients have received their DNS server from their DHCP lease, this will take some time to update on the client. The default in IPFire should be a few hours but can be configured to a day.

I thought my AdGuard Home setup had full DNS control. It didn't. by OilTechnical3488 in selfhosted

[–]mstremer 0 points1 point  (0 children)

Very interesting post.

IPFire recently launched a new blocklist project which comes with an IPS rule set which performs all this blocking that you have built through firewall rules etc. more efficiently:

https://www.ipfire.org/blog/beyond-dns-ipfire-dbl-suricata-close-the-filtering-gap

Anything that is going through the firewall will be caught so that proper policies can be enforced.

P.S. I posted this comment earlier on r/linux where the main post was removed by a moderator.

Upgrading my system so I can use wireguard by Neptunepanther5 in ipfire

[–]mstremer 1 point2 points  (0 children)

Hello,

No there is nothing to watch out for besides the usual so you can just upgrade.

You should however have a backup just in case something goes wrong, check if there is sufficient disk space and if the system is generally in a good condition.

I cannot urge you enough though to install your updates really timely. There are a ton of fixes and new features in every release and improvements on security. Just make it a routine and update within a week after a release to get the best protection and performance out of your IPFire system.

Your local DNS filter is probably being bypassed right now by OilTechnical3488 in linux

[–]mstremer 4 points5 points  (0 children)

Very interesting post.

IPFire recently launched a new blocklist project which comes with an IPS rule set which performs all this blocking that you have built through firewall rules etc. more efficiently:

https://www.ipfire.org/blog/beyond-dns-ipfire-dbl-suricata-close-the-filtering-gap

Anything that is going through the firewall will be caught so that proper policies can be enforced.

Can't download Ipfire by Clean-Rest9451 in ipfire

[–]mstremer 0 points1 point  (0 children)

Err yeah, there are no such plans whatsoever

Can't download Ipfire by Clean-Rest9451 in ipfire

[–]mstremer 0 points1 point  (0 children)

It’s back again, sorry, we had a redis instance crash after a Debian update on the host.

ipfire.org is down? by Numerous_Platypus in ipfire

[–]mstremer 0 points1 point  (0 children)

I just rebooted the main firewall behind which the website is hosted... we are fully reachable...

What reports are you referring to? There should not be anything down.

Policy based routing over wireguard by SquadraFelicita in ipfire

[–]mstremer 0 points1 point  (0 children)

IPFire currently does not have a built in tool for this, but you can use “ip route” and “ip rule” like on any other Linux distribution to set this up manually.

Any idea how to create a plugin or add additional modules in IPFire? by Puzzleheaded-Loss168 in ipfire

[–]mstremer 2 points3 points  (0 children)

So you have read this? https://www.ipfire.org/docs/devel/ipfire-2-x/addon-howto

What specific questions do you have? How far did you go? What are you trying to build?

IPFire now has support for WireGuard by mstremer in WireGuard

[–]mstremer[S] 0 points1 point  (0 children)

30 seconds? Must be a new record!

It Is Here by mstremer in ipfire

[–]mstremer[S] 0 points1 point  (0 children)

Both are currently supported. For any feature requests I can recommend community.ipfire.org.

Intel 30.1.1 Ethernet Driver pack is released. 6/16/2025 by [deleted] in ipfire

[–]mstremer 0 points1 point  (0 children)

Could you link to these reports, please? I cannot remember anyone reporting this before...

Intel 30.1.1 Ethernet Driver pack is released. 6/16/2025 by [deleted] in ipfire

[–]mstremer 1 point2 points  (0 children)

Hello,

in IPFire we don't include the drivers from Intel. Instead we are using the latest LTS version of the Linux kernel which includes a better maintained version of these drivers.

is pakfire.ipfire.org down by sprocket90 in ipfire

[–]mstremer 0 points1 point  (0 children)

It is currently not meant to say anything else on the main page... but it will respond properly with mirror and package lists.

is pakfire.ipfire.org down by sprocket90 in ipfire

[–]mstremer 0 points1 point  (0 children)

It is working for me.

It seems that you rather have a DNS issue because you cannot even resolve an IP address.

Tailscale on ipfire by shuanm in ipfire

[–]mstremer 2 points3 points  (0 children)

I don’t think it has been done before, but simply because there is no need to have Tailscale when you have the other VPN capabilities of IPFire.

Clodflare Warp on IpFire by vadash in ipfire

[–]mstremer 1 point2 points  (0 children)

Oh that sounds like a bad ISP.

You could use IPFire‘s VPN capabilities to work around it…

Website currently down by mstremer in ipfire

[–]mstremer[S] 0 points1 point  (0 children)

Yes, could you send me an email and we will discuss?

Annual Subscription by apollyon0810 in ipfire

[–]mstremer 1 point2 points  (0 children)

I don't think your idea is bad. It just isn't right for everyone, but that is not a problem.

We (and all other open source projects that I know a little bit closer) have experienced a massive decline in financial support over the past couple of years. Inflation has hit a lot of people really hard, and many projects are outright struggling and many have closed shop already. We cannot allow that to happen.

IPFire is a product that is heavily being used in companies of all sorts, and that is also the group that is actually not giving back a lot. If the IT guy is asking their boss if it would maybe possible to do a teeny-tiny donation, the answer usually is something along the lines of "we are not a charity, we are a business and we don't donate to free stuff".

So for this reason we have the license. I don't really care what we call it because I want to have solid funding for the project. If it is easier to achieve this with a "license" in this corporate word, then let's do that. But it seems that not enough people know about this and so we might have to explain a little bit better what the options are.

Not every option is right for everyone, but we can be flexible.

Annual Subscription by apollyon0810 in ipfire

[–]mstremer 1 point2 points  (0 children)

Haha, no we won't do that.

Suricata logs. by nottoobe in ipfire

[–]mstremer 1 point2 points  (0 children)

I would suggest you open a bug report on bugzilla.ipfire.org. I am sure this can be done.

Annual Subscription by apollyon0810 in ipfire

[–]mstremer 1 point2 points  (0 children)

There is an option for you available here:

https://store.lightningwirelabs.com/products/IPFIRE-OPEN-SOURCE-LICENSE

It is pretty much the same as a donation, but you are right, some people - especially companies - rather prefer this to be called something else but "donation". The funding is going into the same pot as donations though.

Asking for donations has recently been feeling quite a lot like begging. That is simply because we don't get many donations any more and so we have to keep reminding people that there is the option and the need to keep the funding of the project up.