Ok I have used Opnsense for 5 years and before that PFSense for many years (10+). I think I am covered. Just commenting on the amount of port scanning. Mine looks like about 30% incoming is dropped.
I think you have it wrong. Port forwarding is letting external traffic into/ through your firewall and directing it to a specific internal ip and port. I'd agree with 'don't port forward'. NAT was invented so that many of your network devices could share the same public IP. Your outbound packets...
I do have NAT, because ..... IPv4, you know. I don't have a static IPv4 connection. But why would that be any different? Every public IP address I get from Afrihost has continuous port scans going on. It's a filthy world out there on internet streets.
I'm using Opnsense. isn't fail2ban a tool to monitor open ports, and then dropping failed attempts on that port? I don't have any ports open at this stage, so it's more just port scans I am seeing
Yes that goes without saying, I just wonder, if there is so much port scanning going on accross the whole of the ISP network, they can probably clear that away? My firewall logs will look much better
This weekend I spent a good couple of hours staring at my live firewall logs. What I saw was constant port scans from IPs all across the world (Bulgaria, America, Netherlands etc.) Not even scanning random ports, just going down the list like 39000, 39001, 39002 etc. I disconnected for a while...
Sheesh I had to look up that BIM term, thought you were talking about something IT. Then I realized what you were talking about :laugh: ... I designed water reticulation and roads on a drafting table.... With a HP41CV. Never used a CAD system, and left civil for IT before it became a real thing...
I've been using desktop linux since 2000 at home, pretty much exclusively. Work is a different issue because most companies insist on MSOffice. In my opinion the last hurdles are the MS office suite and Adobe products. We are seeing the emergence of the Euro Office Project that may make it...
I don't know how they set things up unfortunately. Normally you would get a different Prefix on your lan, than on your wan. And sometimes like on Openserve, you only get a link local on the wan (fe80::10). Test your IPv6 setup by going to https://test-ipv6.run/
Ok, bad idea. I yanked the ipv4 network out of my network management vlan and basically locked myself out of my whole network. I struggled till now to get it back.
So the verdict is: UnifiOS, switches and access points can pass on IPv6 traffic to client devices, but absolutely needs IPv4 to be...
Ok are you talking about the Unifi Cloud gateway/ Unifi Network? I am using Opnsense as my router and selfhosted UnifiOS to manage the switch and AP's only. So a bit of a different story. I can make the VLAN interface IPv6 only, no problem. On my network they are all on a dualstack netowork...
If all NAT64 and DNS64 is present and your device recognizes it, and it has a CLAT, then it will request your DHCP4 server for option 108, if the router replies with 108 (IPv6 prefered) then your device will disable it's own IPv4 stack for a set period of time (this is if it is on a dual stack...