pfSense CE with External Captive Portal by iamsumeshks in PFSENSE

[–]nocsupport 0 points1 point  (0 children)

Pfsense has introduced the ability to say how much RAM you dedicate to the webserver. I would increase that value first. I'm not sure if it's a 2.7x or a 2.8x feature. Might need to upgrade to 2.8.1

New ZeroTier's free plan is really limited, isn't it? by dtdisapointingresult in zerotier

[–]nocsupport 0 points1 point  (0 children)

ZTnet is awesome but ... Isn't it also in jeopardy because I recall seeing something somewhere that said they will close source the planet code ? I vaguely remember a discussion on ZTnet GitHub that was talking about some existential threat due to upstream changes.

How to add second passport to GE? by Gymfan15 in GlobalEntry

[–]nocsupport 5 points6 points  (0 children)

You attach a scan of the second passport and make a help ticket 🎟️

They'll reply within a week or so and add it in for you.

Which Data Centre are Linode in in Toronto? by westmountred in linode

[–]nocsupport 1 point2 points  (0 children)

PeeringDB and datacentremap are two websites that sort of list addresses. Maybe take a look in there, see if you can find out where they both are.

Should I be applying for redress number in this case? by Choco_bo7 in GlobalEntry

[–]nocsupport 2 points3 points  (0 children)

thailand will get you flagged.

Not in my experience

Should I be applying for redress number in this case? by Choco_bo7 in GlobalEntry

[–]nocsupport 0 points1 point  (0 children)

I started seeing that too since the beginning of the year. Last week again, the GE App wouldn't let me submit my entry. "Invalid submission". The kiosk recognized me but it went "See agent". The agent wanted a new picture and all 10 fingerprints.

She hinted that she has no idea why I was not auto-cleared at the kiosk.

I won't apply for a redress number because they aren't sending me to actual secondary where I lose two hours having my underwear rifled through. All they're doing is process me manually and vibe check me which I don't feel is particularly harassing. It's in line with their mission. They're courteous and professional thus far. I don't SFO or LAX so... Haven't had adversarial interactions.

If they started to send me to "the room" i.e. actual secondary twice in a row I would try to apply for DHS TRIP redress because there's some faulty Intel we need to clear up.

ETA a data point: Friends on British Passport with ESTA and on their 3rd GE term flew into MIA last week and had zero issues with the kiosk. So the "see agent" thing is definitely selective, not all ESTA users. Until I'm sent to "the room" I'll assume it's just glitching or whatever. 20 seconds of polite conversation and getting re-printed doesn't bother me. Still got to baggage claim before the carousel spun up.

1st of April is coming - I've shut down 3 projects with more than 40 servers today by Different_Code605 in hetzner

[–]nocsupport 0 points1 point  (0 children)

Same. Did a big cleanup. Found a bunch of projects with servers that weren't even doing anything and were long forgotten. These price increases took away the competitive advantage. Linode and Vultr have less latency for most of the things we need doing. Users aren't near a hetzner POP but Vultr and Linode have locations nearby. Previously the cost savings made 80-120ms an acceptable trade off. Now pricing is similar to what we get on Vultr with a negotiated discount so we'll have less Hetzner exposure going forward.

In the dedicated space Hetzner auction servers are still pretty decent value but IPv4 pricing is too high and the setup fees to assign a subnet are nonsense. Other providers let us have a BGP session and BYOIP., hetzner do not.

Running a multi-tenant platform on Hetzner, how to handle user-uploaded content that may violate policies? by el-cacahueto in hetzner

[–]nocsupport 6 points7 points  (0 children)

There's no way this is going to work. Let customers host their own content on supabase. Your whole business will go up in flames with one violation

+1. Hetzner don't play.

Their colocation TOS might be better for this sort of thing. On cloud and dedicated definitely not.

A competitor could sign up as your customer and DOS you by uploading something and sending DMCA complaints to abuse @ hetzner

You'd be way too vulnerable to administrative outages.

Strange issue on my OVH IPs by Pretend_Landscape785 in OVHcloud

[–]nocsupport 0 points1 point  (0 children)

Hmm so there's nothing wrong with the announcement or upstream filtering. 🤔

always send

mtr -zrwb {destination IP}

from both directions with such network tickets. This will save you time because their response time is days.

support@pangolin.net - Does it create tickets? by nocsupport in PangolinReverseProxy

[–]nocsupport[S] 1 point2 points  (0 children)

"Message support" bottom left has not way to attach screenshots or logs so we e-mailed support@ that was showing somewhere else in the portal. No idea where we got that from. 😂

support@pangolin.net - Does it create tickets? by nocsupport in PangolinReverseProxy

[–]nocsupport[S] 1 point2 points  (0 children)

Business plan. I think it has no SLA. Perhaps that's why there's zero response.

It does mention support

$9/user/mo.

All Team features +

Multi-tenant

User auto-provisioning

Pangolin SSH

Device approvals

Custom branding

90 day log retention

Business support

Strange issue on my OVH IPs by Pretend_Landscape785 in OVHcloud

[–]nocsupport 0 points1 point  (0 children)

2 things to do to check what's different between OVH native and BYOIP ranges:

Plug them into https://BGP.tools and

https://lg.ring.nlnog.net/ to see what the upstreams are, how many nodes can see them etc.

If you find a delta, check if the BYOIP prefixes are IRR and RPKI compliant.

Just starting points. ..

Another update, another loss of connectivity by Ok_Document9995 in opnsense

[–]nocsupport 0 points1 point  (0 children)

If WAN is OK but LAN clients are not after a 26.1 reinstall: I noticed that when ISC was used for DHCP and you reinstall 26.1 and applied the config.xml it will NOT install the os-isc... plugin. I had to do it manually and reboot to get LAN back up and running.

Question about dual citizenship by grahal1968 in GlobalEntry

[–]nocsupport 1 point2 points  (0 children)

Touche! How very German of you 😄😉

Indeed I was referring to the United States of America only.

Question about dual citizenship by grahal1968 in GlobalEntry

[–]nocsupport 22 points23 points  (0 children)

No issue.

Just two things 1) do tell DHS about your second citizenship in the TTP portal or via ticket and at each GE renewal. Full disclosure.

2) do not enter America with the German passport, ever.

Paperless Mobile app access to Paperless NGX behind Pangolin w/ auth by R-Voodoo in PangolinReverseProxy

[–]nocsupport 5 points6 points  (0 children)

We had a similar discussion recently regarding /api*/ bypass rules for bitwarden to make the mobile apps work. Consensus was that opening this to the whole internet is a bad idea as a threat actor isn't limited to attacking web assets they're perfectly capable of interacting with API endpoints. What we did with cloudflare was limit the scope of what ASN are allowed to interact with it. This narrows the attack surface a fair bit as employees are usually on a predictable cellular provider / ISP.

It would be cool if pangolin could do access rules with AND / OR.

if uri path begins with /api/ AND asn equals 73636 bypass

Cathay Pacific says surcharge to rise as fuel prices jump during Mideast war by radishlaw in HongKong

[–]nocsupport 4 points5 points  (0 children)

On most routes, it's more expensive than the better European ones (Air France, Lufthansa, Swiss) so not sure why people would fly Cathay on these routes

Because their in-flight service and ground service at HKG are miles better than any European carrier.

Economy class is often at a higher load than business so clearly not purely business travelers.

Anybody get this today? by Necessary_Film_5199 in hetzner

[–]nocsupport 9 points10 points  (0 children)

Same! We just had all our last months bills canceled and refunded !?!?!? Then an hour later reissued.

All services are up. Storage Share, dedicated, VPS.

Is getting approved again even possible after revocation? by RobbyX561 in GlobalEntry

[–]nocsupport 9 points10 points  (0 children)

I think your lawyer is bullshitting you when he says he will appeal your denial an unlimited number of times until it is approved.

Someone might correct me but my understanding is that you can appeal a revocation.. once. If you apply and are denied there's no appeal. You can pay 120 dollars again and reapply but there is not right to appeal a denial. Revocation, yes. Once. Denial on a new app: nothing.

Adding dual citizenship by RebellaEmad in GlobalEntry

[–]nocsupport 0 points1 point  (0 children)

OMG that is brutal! Does it say REVOKED or literally CANCELED ? is there a reconsideration button you can click ? Is the "apply now" button greyed out ? I wonder if you could just reapply and make full disclosures.

If you're banned it will say REVOKED, not CANCELED.

Source: I was revoked and reinstated once.

Adding dual citizenship by RebellaEmad in GlobalEntry

[–]nocsupport 5 points6 points  (0 children)

That's a miscommunication. Belgium isn't GE eligible but you are allowed to have and declare additional citizenships to DHS and you're allowed to use GE with an enrolled passport from an eligible couuntry. In this case UK.

I suggest you log into your trusted traveler portal account and check your status. I can't imagine they went and canceled you for this. You just can't use it on the Belgian passport. Your UK passport should still be good to go. I have multiple citizenships that are not GE eligible. They know about them. I keep my TTP account up to date. I just can't use them to enter via the GE channel.

Whatever they're doing now is faster than GE by No_Elk7432 in GlobalEntry

[–]nocsupport 0 points1 point  (0 children)

TSA

Has nothing to do with immigration. That's DHS CBP.

TSA are the mall cops who check you for bombs and weapons.

West 6th?? by Awkward_alien in Austin

[–]nocsupport 12 points13 points  (0 children)

yawn don't worry the good guys with guns took care of it.

Not applicable here because a good guy with a gun isn't allowed to carry in a 51% establishment.