Skip to content
Geek is the Way!
Menu
  • Forums
  • Sobre o blog
  • Contato
  • English
    • Português
Menu

Tag: security

Hardening Zabbix Server installation using Apache VirtualHosts and Let’s Encrypt certificates

Posted on December 30, 2022December 30, 2024 by Thiago Crepaldi

In my previous post, we went through the process of installing Zabbix Server on a Debian LXC container. Although it works alright, it doesn’t come with HTTPS support out of the box. It also has an “ugly” /zabbix in the end of the URL. In this short post, we are going through the steps of…

Share this:

  • Tweet
Read more

Deploying a public Vaultwarden instance on a Proxmox LXC container using HAProxy on pfSense

Posted on December 27, 2022December 30, 2024 by Thiago Crepaldi

In crazy times as today’s, having strong and unique passwords are a must to handle threats from Internet. However, keeping track of such passwords is very hard, and this is where password managers come in. There are several password managers out there, but I really enjoy Bitwarden. If you don’t know them, I urge you…

Share this:

  • Tweet
Read more

Setting up VPN client on your pfSense using Private Internet Access (PIA) service with Kill switch

Posted on December 12, 2022December 30, 2024 by Thiago Crepaldi

Private Internet Access (aka PIA) provides a cheap VPN service that allows up to 10 simultaneous devices. Recently I have switched from Surfshark to PIA because although Surfshark allows unlimited devices, having multiple connections in the same device (pfSense router) doesn’t always work. The reason is that different connections to different countries can have the…

Share this:

  • Tweet
Read more

How to create a DMZ network using VLANs on pfSense

Posted on October 16, 2022October 17, 2022 by Thiago Crepaldi

DMZ (aka Demilitarized Zone) network as defined by Wikipedia “is a physical or logical subnetwork that contains and exposes an organization’s external-facing services to an untrusted, usually larger, network such as the Internet”. The purpose is to add an additional layer of security by separating what is exposed a public service in the DMZ, while the rest of…

Share this:

  • Tweet
Read more

How to fix R3 CA/Certificate issue on pfSense (expired on September 29th, 2021)

Posted on October 18, 2021July 28, 2022 by Thiago Crepaldi

On Wednesday, September 29th 2021 a widely used Certificate Authority (CA) from Let’s Encrypt expired and brought the world to its knees. Well, at least my homelab, anyways. The exact message would be something like “The following CA/Certificate entries are expiring: Certificate Authority: Acmecert: O=Let’s Encrypt, CN=Let’s Encrypt Authority R3, C=US” The fix is quite…

Share this:

  • Tweet
Read more

How to fix the X3 CA/Certificate issue after upgrading to pfSense 2.5

Posted on February 26, 2021August 6, 2022 by Thiago Crepaldi

If you recently upgraded to pfSense 2.5, you may have received notifications about some CA/Certificate entries close to expiring. The exact message would be something like “The following CA/Certificate entries are expiring: Certificate Authority: Acmecert: O=Let’s Encrypt, CN=Let’s Encrypt Authority X3, C=US” The fix is quite simple, just visit System >> Cert Manager >> CAs…

Share this:

  • Tweet
Read more

How to configure IPSec Site-to-Site VPN tunnel on your pfSense using dynamic IPs and pre-shared keys in both ends

Posted on December 23, 2020December 30, 2024 by Thiago Crepaldi

Many of us have more than one pfSense (maybe connecting our home and office, our home and our parents, etc) which would benefit with a direct connection between them. In this post I will describe how to create a routed tunnel that connects both ends, in a way that Site A can directly access Site…

Share this:

  • Tweet
Read more

Isolating Wi-Fi networks using VLAN subnets through pfSense + Unifi switch and a little more…

Posted on November 25, 2020October 16, 2022 by Thiago Crepaldi

A typical home network is a simple single network and if any of your devices is compromised or infected with malware, the attacker may be able to spread malware or compromise all of your other devices. You can better protect your home network by separating your home network into sub-networks (aka subnets). Devices in a subnet do…

Share this:

  • Tweet
Read more

Isolating Wi-Fi networks using VLAN subnets through pfSense + UDM-Pro and a little more…

Posted on September 2, 2020August 14, 2022 by Thiago Crepaldi

A typical home network is a composed of a single network and if any of your devices is compromised or infected with malware, the attacker is able to spread malware or compromise all devices. You can better protect your home network by separating your home network into sub-networks (aka subnets). Devices in a subnet do not have…

Share this:

  • Tweet
Read more

Setting up VPN client on your pfSense (Surfshark) with Kill switch

Posted on August 30, 2020December 30, 2024 by Thiago Crepaldi

Surfshark provides a cheap VPN service that allows unlimited number of devices with ad blocking. In this tutorial we are going to configure pfSense with Surfshark and assign an interface to it so that we can route it to other services. Surfshark information The first step is getting your Surfshark credentials. Go to the login…

Share this:

  • Tweet
Read more
  • Previous
  • 1
  • 2
  • 3
  • Next
LIKED? SUPPORT IT :)

Buy Me a Coffee


Search


Categories

  • Cooking (1)
  • Homelab (79)
    • APC UPS (6)
    • pfSense (40)
    • Proxmox (20)
    • Shopping (1)
    • Supermicro (2)
    • Synology NAS (8)
    • Ubiquiti (6)
    • UDM-Pro (4)
  • Random (3)
  • Wordpress (1)

Tags

Agentless monitoring (3) AP9631 (3) Apache2 (3) APC UPS (6) apt-get software (2) Bind9 (3) certificates (5) CloudFlare (2) DDNS (5) debian (3) DNS (7) DSM (6) Dynamic DNS (4) Firewall (9) gmail (3) Let's Encrypt Certificates (7) monitoring (18) networking (21) NMC (2) PBS (3) pfBlockerNG (2) pfsense (43) port forwarding (3) privacy (2) proxmox (17) proxmox backup server (3) proxmox virtual environment (16) pve (5) rev202207eng (76) security (28) SNMP (4) SNMPv1 (3) ssh (4) SSL (6) Synology (7) udm-pro (5) UDR (2) unifi (6) unifi controller (3) UPS (5) VLAN (4) vpn (9) wifi (4) Zabbix (18) Zabbix Agent2 (11)

See also

Privacy policy

Sitemap

©2025 Geek is the Way! | Design by Superb