My Preferred Package Picks for Peak pfSense Performance

Поділитися
Вставка
  • Опубліковано 10 гру 2024

КОМЕНТАРІ • 76

  • @h3415a
    @h3415a 4 місяці тому +36

    Service Watchdog is a useful one to keep service up. Also mail report.

    • @break1146
      @break1146 4 місяці тому +2

      I've had some issues with Tailscale service just stopping and me using that to access the devices behind cgnat that's kind of a problem. I worked around this making a cronjob restarting the service every so often as a quickfix, but this is much better. I must have missed this package whenever going through the list to see if there's something interesting to find.
      Ima try it, thanks!

    • @pepeshopping
      @pepeshopping 4 місяці тому

      Which should NOT be nedded!

  • @npoitevin
    @npoitevin 4 місяці тому +12

    Great to get this update, and glad to realize this matches my experience. I wish you can dig a bit deeper as to why DNSBL is not relevant anymore and what could be used as a replacement especially in a home environment with kids

    • @timezonewall
      @timezonewall 4 місяці тому +1

      It's fairly easy these days to tell a web browser to use a different DNS, so if one uses a block with the DHCP specified DNS, the end user can simply tell the browser to use a different DNS service. It's a little hard to change DNS at the system level, but not too difficult. I still use a local DNS via "Adguard Home", however it's not for parental controls, it's to limit DNS requests going to the internet by doing forced caching, and to re-write certain requests such as keeping NTP requests local.
      For parental controls, you will need to go deeper to really lock down the device, simple DNS blocking is easy to get around.

    • @dyerseve3001
      @dyerseve3001 4 місяці тому +1

      Also DoH in browser bypasses traditional DNS, which is why endpoint DNS is preferred when the device needs to be managed and monitored.

  • @skorpion1298
    @skorpion1298 4 місяці тому +16

    Watching this Channel since.. 2017 or something.. Thanks Lawrence for everything!

  • @HomeBudgetComputing
    @HomeBudgetComputing 4 місяці тому +9

    As always, absolutely awesome alliteration. 😎

  • @zeeventuresph
    @zeeventuresph 4 місяці тому +2

    Thanks for the pfsense pkg update Tom!

  • @mysticsilent
    @mysticsilent 4 місяці тому +3

    Thanks Tom! Nice package review 👍

  • @Zaf9670
    @Zaf9670 4 місяці тому

    Thanks for the update Tom!

  • @mrpops2ko
    @mrpops2ko 4 місяці тому +4

    i dont use it, but the crowsec package is probably something people will want if they host anything externally

  • @walideshtiwi6303
    @walideshtiwi6303 4 місяці тому +1

    I hope they can add support for WAF alongside with HAproxy

  • @RandomTechChannel
    @RandomTechChannel 3 місяці тому

    Cron can be useful if you want to schedule eg. reboot at some certain time.

  • @deadlymarsupial1236
    @deadlymarsupial1236 4 місяці тому

    Cheers from Australia.
    Wish pfSense had a proper supply chain presence here.

    • @worldtravels2763
      @worldtravels2763 2 місяці тому

      What do you mean? Just download it, right?

  • @stevebaillargeon7136
    @stevebaillargeon7136 4 місяці тому

    Great again Lawrence!
    What do you think of Zen Armor solution?

  • @truckerallikatuk
    @truckerallikatuk 4 місяці тому +25

    Dear Netgate, why is the patcher not installed by default?

    • @LAWRENCESYSTEMS
      @LAWRENCESYSTEMS  4 місяці тому +8

      I agree

    • @Mr.Leeroy
      @Mr.Leeroy 4 місяці тому

      the same reason we have a manual updater and not an auto-updater, obviously. Everything in that plugin is opt-in manual administration based and just having a plugin does nothing useful.

    • @yahyoh91
      @yahyoh91 4 місяці тому

      @@Mr.Leeroy That's make no sense! the patches should have been as normal system updates which should been done regularly..same as any operating system in this world. Instead of relying on installing a package to install the updates?? (patches)
      I have been using pfsense on and off for almost 2 years and i never had an idea about the patches packages till seeing this video..and im kinda tech nerd let alone other people who are less nerdy?
      Netgate need to fix this issue and make the patches as a normal system updates IMO.
      Also Thank you Lawrance for the Video.

    • @Mr.Leeroy
      @Mr.Leeroy 4 місяці тому +2

      @@yahyoh91 Patches are not updates. They may contain couple hotfixes until an update comes, but thats only a fraction of their usecases, which are mainly dev or admin tuning functionality.
      If you are hoping for a faster and less attended rolling release, that's not happening since project is built around FreeBSD, which has the opposite in its core philosophy.

  • @yumpizzaness
    @yumpizzaness 4 місяці тому

    I use cron for enabling hardware offloads on passthru NICs in a VM

  • @CoryMT
    @CoryMT 4 місяці тому

    I love Traffic Totals. My only problem with it is that whenever there is an unclean shutdown the data seems to get corrupted and the only way I've found to fix that is to reset graphing data (lose it all).
    That should be easy to avoid if everything goes as expected, but after numerous power outages and brownouts I finally had to get a UPS.
    After that my ssd started dying and caused it to crash numerous times before I realized what was happening.
    Then I virtualized it so I can spin it up on a different physical host just in case, and then had a stick of ram going bad and crashing the system.
    So I now have two PC's running Proxmox, both with mirrored zfs boot pools, both on UPSs, in part to keep my router running through power and equipment failure. 😞
    I have Cron installed to launch the QEMU Guest Agent on boot.

  • @user-lm3ll1jp7f
    @user-lm3ll1jp7f 4 місяці тому

    Thank you for all your information.... It is always very informative... I have a quick question... I was hoping to run by you... Would you happen to have any recommendations for Hyper-v cloud hosting services? Or do you offer hosting of hyper-v servers? Thank you very much

  • @gregoryb.9630
    @gregoryb.9630 3 місяці тому

    Would it be possible to explain package choices between a first-time or home setup, a paranoid setup, and then for a business that wants to put money where it matters, such as an HA or large hardware cost setup?

  • @xgeko2
    @xgeko2 4 місяці тому

    By chance do all of these packages exist and setup the same way in opnsense? I really like all of your content appreciate you!

  • @HisLoveArmy
    @HisLoveArmy 4 місяці тому +2

    I purchased a couple netgates, I wanted to love pfsense but honestly the way they do vlans and interfaces is so confusing to me. I wish it was easier to use.

    • @samsampier7147
      @samsampier7147 4 місяці тому

      Let us know if you have specific questions. I found it straightforward. My job is networking and firewalls related, not PFsense.

    • @danig75
      @danig75 4 місяці тому

      Take a breather, maybe read a bit more about vlans and try again. Once you get the hang of it it's just as easy as any other implementation

    • @AlexKidd4Fun
      @AlexKidd4Fun 3 місяці тому +2

      It seems pretty straightforward to me as well. 🤔

  • @Emerald13
    @Emerald13 4 місяці тому

    Thank you!

  • @jahanson
    @jahanson 4 місяці тому +1

    watched even though I use opnsense :) appreciate the time you put in to this

  • @sku2007
    @sku2007 4 місяці тому

    i'm using pihole and have a firewall rule setup which forwards all outgoing dns to pihole (except pihole itself^^). but i don't know if this is sufficient in all cases, at least it seems to work for me and blocks lots of ads. of course, for forwarded requests the router ip shows up in pihole log.

  • @thegorn
    @thegorn 4 місяці тому

    Hmm "NSFW_LAN". Does that connect to a NSFW directory of photos and videos on the NAS? 🤭

  • @Boatsman99
    @Boatsman99 4 місяці тому +1

    Why the NUT wasn't mentioned?

    • @LAWRENCESYSTEMS
      @LAWRENCESYSTEMS  4 місяці тому +2

      I almost never use it. If you're using ZFS suddenly losing power is not really an issue.

  • @YeOldeTraveller
    @YeOldeTraveller 4 місяці тому

    Is the issue with Zabbix this use case, or Zabbix in general?
    I was evaluating Zabbix for monitoring a large deployment.

    • @LAWRENCESYSTEMS
      @LAWRENCESYSTEMS  4 місяці тому

      Zabbix is great, but I just don't use it anymore.

  • @gjkrisa
    @gjkrisa 2 місяці тому

    can ha proxy work like squid proxy? i use steam cache now and apt cache and has worked pretty well but feel it’s harder to set up then ha proxy probably would be.

  • @LAMBDA34
    @LAMBDA34 4 місяці тому

    I used ntopng a few months back but I found out it was writing a LOT of logs and was killing my NVMe 😰

  • @ssgtlaatz
    @ssgtlaatz 4 місяці тому

    What about zerotier? Is that available on pfSense yet? I keep finding old posts (2+ yrs) all say no official package.

  • @HansVledder
    @HansVledder 4 місяці тому

    Perfect!

  • @KubGov
    @KubGov 4 місяці тому

    What proxy would you suggest one use... now that I have removed Squid from my pfSense? We need a proxy.. not for caching or filtering (although this would be a plus of it did) but we need it for logging....

    • @LAWRENCESYSTEMS
      @LAWRENCESYSTEMS  4 місяці тому +1

      I don't suggest any due to the issues that come with them. We use an endpoint tool on each client machine to monitor and manage web sites.

    • @diegogarriz3857
      @diegogarriz3857 Місяць тому

      @@LAWRENCESYSTEMS Which endpoint tool is it? Does it have a management console? Is it open source? Thanks in advance for the guidance.

    • @LAWRENCESYSTEMS
      @LAWRENCESYSTEMS  Місяць тому

      @@diegogarriz3857 We currently us Zorus and I am not aware of any good open source alternative.

  • @maverick-phillips
    @maverick-phillips 4 місяці тому

    What do you recommend if you don't like Snort?

    • @LAWRENCESYSTEMS
      @LAWRENCESYSTEMS  4 місяці тому +3

      Since most traffic is encrypted IDS systems are much less useful here in 2024

  • @Dfull86
    @Dfull86 4 місяці тому

    What are y'all using outside of Zabbix?

  • @sudeepchakraborty5084
    @sudeepchakraborty5084 4 місяці тому

    Sir i trying to install pfsense on my cyberoam CR-15iNG firewall
    After installation when booting from ssd its giving the error
    bios drive c: is disk 0
    Can any one can help me i am in very much trouble 🙏 pls help

  • @tamasspark7180
    @tamasspark7180 4 місяці тому +4

    Avahi!

  • @ChrisMyers2000
    @ChrisMyers2000 4 місяці тому

    Were these particular packages proposed in order of their propensity to perform? Or just random order? 😂

  • @LackofFaithify
    @LackofFaithify 4 місяці тому

    Anyone else think the little hand icon on the thumbnail was flipping the bird? Thought it was another video about opensense *rim shot*

  • @LA-MJ
    @LA-MJ 4 місяці тому

    What does zabbix have to do with squid?

    • @LAWRENCESYSTEMS
      @LAWRENCESYSTEMS  4 місяці тому

      Nothing, I just don't use zabbix anymore and I don't recommend anyone use squid.

  • @rogermutumba1057
    @rogermutumba1057 4 місяці тому

    Awesome

  • @plebiannn
    @plebiannn 4 місяці тому

    Damn the timing of this video haha

  • @maurochss
    @maurochss 4 місяці тому

    If I want to create a filter for Kids @home, which packages or setup would you recommend?

  • @adminema6116
    @adminema6116 4 місяці тому +1

    freeradius3, wireguard, tailscale, service watchdog, pfblocker, openvpn client export ❤

  • @SamuelViagus
    @SamuelViagus 4 місяці тому

    Wan IP address…

  • @TechySpeaking
    @TechySpeaking 4 місяці тому +1

    First

  • @alk_dl
    @alk_dl 4 місяці тому +1

    you have replaced zabbix with uptime-kuma?

    • @LAWRENCESYSTEMS
      @LAWRENCESYSTEMS  4 місяці тому +1

      Essentially yes but Uptime Kuma does not have near the same features as Zabbix, but I also did not really need all those features.

    • @alk_dl
      @alk_dl 4 місяці тому

      @@LAWRENCESYSTEMS thanks for the reply