Skip to content
Geek is the Way!
Menu
  • Forums
  • Sobre o blog
  • Contato
  • English
    • Português
Menu

Tag: pfsense

How to fix R3 CA/Certificate issue on pfSense (expired on September 29th, 2021)

Posted on October 18, 2021July 28, 2022 by Thiago Crepaldi

On Wednesday, September 29th 2021 a widely used Certificate Authority (CA) from Let’s Encrypt expired and brought the world to its knees. Well, at least my homelab, anyways. The exact message would be something like “The following CA/Certificate entries are expiring: Certificate Authority: Acmecert: O=Let’s Encrypt, CN=Let’s Encrypt Authority R3, C=US” The fix is quite…

Share this:

  • Tweet
Read more

Routing specific devices through your VPN gateway using pfSense

Posted on April 21, 2021August 4, 2022 by Thiago Crepaldi

While I was writing a post on how to route specific WEB traffic through VPN, I’ve got inspired and decided to write another post on how to route specific DEVICES (your NAS server, laptop, iPhone, etc) through VPN while the rest of your house still uses the default ISP gateway. This kind of approach might…

Share this:

  • Tweet
Read more

Routing specific websites through your VPN gateway using pfSense

Posted on April 21, 2021August 4, 2022 by Thiago Crepaldi

For those who followed my previous post on how to configure a VPN client on pfSense, one cool application for it is to route only specific websites through the VPN while the rest of the traffic goes through the default ISP gateway, as usual. That is interesting when you want to use an IP from…

Share this:

  • Tweet
Read more

How to fix the X3 CA/Certificate issue after upgrading to pfSense 2.5

Posted on February 26, 2021August 6, 2022 by Thiago Crepaldi

If you recently upgraded to pfSense 2.5, you may have received notifications about some CA/Certificate entries close to expiring. The exact message would be something like “The following CA/Certificate entries are expiring: Certificate Authority: Acmecert: O=Let’s Encrypt, CN=Let’s Encrypt Authority X3, C=US” The fix is quite simple, just visit System >> Cert Manager >> CAs…

Share this:

  • Tweet
Read more

Install Let’s Encrypt SSL certificates on your Supermicro X10 from Synology on a schedule

Posted on February 15, 2021December 30, 2024 by Thiago Crepaldi

Recently I have added a Supermicro X10DRi-T4+ to my homelab and a natural idea was to install a Let’s Encrypt SSL certificate and replace the original self-signed one. For such, I had to adapt a couple python scripts [1] [2] first published by Jari Turkia. None of them worked for Supermicro X10DRi-T4+, but it wasn’t…

Share this:

  • Tweet
Read more

Fix your BufferBloat and speed your Internet on your pfSense

Posted on February 13, 2021December 30, 2024 by Thiago Crepaldi

As bufferbloat.net defines it, “Bufferbloat is the undesirable latency that comes from a router or other network equipment buffering too much data. It is a huge drag on Internet performance created, ironically, by previous attempts to make it work better. The one-sentence summary is “Bloated buffers lead to network-crippling latency spikes. The bad news is…

Share this:

  • Tweet
Read more

Routing Internet Traffic Through a Site-to-Site IPsec VPN on a specific Wi-fi over VLAN

Posted on January 20, 2021August 9, 2022 by Thiago Crepaldi

Yeah, I know, I need to work on shorter titles 😀 By reading a previous post, you may have created an IPSec tunnel to connect your home and office (or something like that). That is useful on its own, but it can be the case that you also want that all internet traffic to go…

Share this:

  • Tweet
Read more

Setup VLAN subnets on pfSense

Posted on December 23, 2020October 16, 2022 by Thiago Crepaldi

This is another topic that I have referenced so many times that I decided to dedicate a post just for it and save some typing. The goal is to configure a VLAN subnet that has DHCP server and basic firewall rules to allow any traffic on your pfSense. This VLAN will be created from the…

Share this:

  • Tweet
Read more

How to configure IPSec Site-to-Site VPN tunnel on your pfSense using dynamic IPs and pre-shared keys in both ends

Posted on December 23, 2020December 30, 2024 by Thiago Crepaldi

Many of us have more than one pfSense (maybe connecting our home and office, our home and our parents, etc) which would benefit with a direct connection between them. In this post I will describe how to create a routed tunnel that connects both ends, in a way that Site A can directly access Site…

Share this:

  • Tweet
Read more

Creating RFC1918 alias for Firewall rules

Posted on December 23, 2020August 11, 2022 by Thiago Crepaldi

From time to time, I need to reference the use of a IP alias called RFC1918 to separate traffic from local network from other (aka “Internet”) traffic. RFC 1918 was published to “Address Allocation for Private Internets”, which is our local network. There is nobody on internet using any IP in the range described by…

Share this:

  • Tweet
Read more
  • Previous
  • 1
  • 2
  • 3
  • 4
  • 5
  • Next
LIKED? SUPPORT IT :)

Buy Me a Coffee


Search


Categories

  • Cooking (1)
  • Homelab (79)
    • APC UPS (6)
    • pfSense (40)
    • Proxmox (20)
    • Shopping (1)
    • Supermicro (2)
    • Synology NAS (8)
    • Ubiquiti (6)
    • UDM-Pro (4)
  • Random (3)
  • Wordpress (1)

Tags

Agentless monitoring (3) AP9631 (3) Apache2 (3) APC UPS (6) apt-get software (2) Bind9 (3) certificates (5) CloudFlare (2) DDNS (5) debian (3) DNS (7) DSM (6) Dynamic DNS (4) Firewall (9) gmail (3) Let's Encrypt Certificates (7) monitoring (18) networking (21) NMC (2) PBS (3) pfBlockerNG (2) pfsense (43) port forwarding (3) privacy (2) proxmox (17) proxmox backup server (3) proxmox virtual environment (16) pve (5) rev202207eng (76) security (28) SNMP (4) SNMPv1 (3) ssh (4) SSL (6) Synology (7) udm-pro (5) UDR (2) unifi (6) unifi controller (3) UPS (5) VLAN (4) vpn (9) wifi (4) Zabbix (18) Zabbix Agent2 (11)

See also

Privacy policy

Sitemap

©2025 Geek is the Way! | Design by Superb