this post was submitted on 31 Jan 2026
275 points (99.6% liked)

Selfhosted

61808 readers
334 users here now

A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.

Rules:

Detailed Rules Post

  1. Be civil.

  2. No spam.

  3. Posts are to be related to self-hosting.

  4. Don't duplicate the full text of your blog or readme if you're providing a link.

  5. Submission headline should match the article title.

  6. No trolling.

  7. Promotion posts require active participation, with an account that is at least 30 days old. F/LOSS without a paywall has exceptions, with requirements. See the rules link for details. Tags [CBH] or [AIP] are required, see the links in Rule 8 for details.

  8. AI-related discussions and AI-involved promotional posts have additional requirements for tagging, as noted in Rule 7 and the AI & Promotional Post Expanded Rules post, and find example disclosures here.

Resources:

Any issues on the community? Report it using the report flag.

Questions? DM the mods!

founded 3 years ago
MODERATORS
 

Finally ditched my ISP’s router and installed my own opnsense firewall with my own Access Point. I have crowdsec running on opnsense to block attacks + adguard to block ads and malicious domains. My network is segmented between my homelab that is exposed and my AP.

Finally feels quite safe in my network πŸ˜…

all 31 comments
sorted by: hot top controversial new old
[–] whimsy@lemmy.zip 35 points 7 months ago (1 children)

Networking isn't my strong suit, so this might be a stupid question. But what exactly is a hardware firewall? Is it the same thing as my Internet facing router blocking incoming packets which haven't been requested from "inside the home" network?

[–] irmadlad@lemmy.world 26 points 7 months ago

A hardware firewall generally indicates a standalone appliance that is dedicated to being a firewall. Not to be confused with a software firewall as you would see with UFW, or Windows Defender. Modern routers do possess some of the same tenets of a hardware firewall, but a dedicated hardware firewall usually gives a broader range of defenses such as IDS/IPS, filtering, etc.

I have a dedicated hardware firewall in the form of pFsense. The 'black box' in OP's picture is the hardware firewall.

[–] Decronym@lemmy.decronym.xyz 21 points 7 months ago* (last edited 6 months ago)

Acronyms, initialisms, abbreviations, contractions, and other phrases which expand to something larger, that I've seen in this thread:

Fewer Letters More Letters
AP WiFi Access Point
DNS Domain Name Service/System
IP Internet Protocol
IoT Internet of Things for device controllers

4 acronyms in this thread; the most compressed thread commented on today has 14 acronyms.

[Thread #47 for this comm, first seen 31st Jan 2026, 16:30] [FAQ] [Full list] [Contact] [Source code]

[–] snekerpimp@lemmy.world 8 points 7 months ago (1 children)

That looks exactly like the box I grabbed. Are you running your opnsense on the bare metal, or are you virtualizing it? My only regret for mine was not picking up more ram.

[–] pimpampoom@lemmy.zip 7 points 7 months ago (1 children)

I’m running on bare metal. I have a physical homelab behind. Can’t you add ram?

[–] snekerpimp@lemmy.world 14 points 7 months ago (3 children)

I could, if it wasn’t so damn expensive for 32gb

[–] kalpol@lemmy.ca 12 points 7 months ago (1 children)

I can't imagine why you need 32gb for opnsense. I can run it on a single core and 1gb, unless I literally want every DNS blacklist loaded in which case 4gb

[–] snekerpimp@lemmy.world 3 points 7 months ago

I’m running a proxmox instance on mine, with opnsense in a vm and plex, Jellyfin pihole and my omada controller on lxc. 16gb is just enough for everything, but I like to future proof and buffer things, so it makes me a bit nervous utilizing 12 of that 16 gb and only leaving 4gb for proxmox.

[–] comrade_twisty@feddit.org 10 points 7 months ago

In some places you can still get 32GB DDR4 for a kidney if youβ€˜re lucky.

[–] irmadlad@lemmy.world 1 points 7 months ago (1 children)
[–] snekerpimp@lemmy.world 1 points 7 months ago

I will get them a look

[–] irmadlad@lemmy.world 7 points 7 months ago (1 children)

OP, you may want to look into ntopng. I think opnsense has a ntopng plugin. I find it very useful for traffic analysis.

[–] pimpampoom@lemmy.zip 3 points 7 months ago

Will have a look, thanks!

[–] Cyber@feddit.uk 3 points 7 months ago* (last edited 7 months ago) (1 children)

Nice.

Running different SSIDs too?

I put all my IoT stuff on a dedicated 2.4-only network, VLANd it to the (pfsense) firewall which allows the VLAN trunk to be split into separate logical NICs that I apply different policies to, like no access to the internet, etc...

[–] pimpampoom@lemmy.zip 2 points 7 months ago

At the moment I only have one WiFi instance, not planning to separate yet but it could be a future upgrade since I have a few IoT devices.

[–] possiblylinux127@lemmy.zip 3 points 7 months ago (1 children)
[–] pimpampoom@lemmy.zip 2 points 7 months ago (1 children)

Personal preference, it’s what I’ve been using since I started my homelab and I think it works well enough.

[–] possiblylinux127@lemmy.zip 1 points 7 months ago (1 children)

Are you exposing things to the internet?

[–] irmadlad@lemmy.world 3 points 7 months ago (1 children)

I have crowdsec running on opnsense to block attacks

Crowdsec is a pretty good package. It does blocking, but is geared more to being an IDS. Opnsense supports Suricata which is a more aggressive, and all encompassing IDS/IPS. I don't think opnsense supports it's cousin Snort.

[–] pimpampoom@lemmy.zip 2 points 7 months ago (1 children)

I considered suricata but for now I think crowdsec works well enough, I’ll see later if I think suricata could be more useful

[–] irmadlad@lemmy.world 2 points 7 months ago

Cool, cool. I was just throwing it out there if you hadn't considered it. It's quite a powerful package.

[–] bytepursuits@programming.dev 3 points 7 months ago (1 children)

Share some pictures and stats of you could. Do u see many probes?

[–] pimpampoom@lemmy.zip 1 points 7 months ago (1 children)

You want pictures and stats of what?

[–] Mist101@lemmy.world 3 points 7 months ago

Cats, if you have them, dogs if not.