Finally ditched my ISP’s router and installed my own opnsense firewall with my own Access Point. I have crowdsec running on opnsense to block attacks + adguard to block ads and malicious domains. My network is segmented between my homelab that is exposed and my AP.

Finally feels quite safe in my network 😅

  • ☂️-@lemmy.ml
    link
    fedilink
    English
    arrow-up
    3
    ·
    edit-2
    38 minutes ago

    i recommend getting a fan blowing on that box. these get really hot at the slightest hint of some load.

    • utjebe@reddthat.com
      link
      fedilink
      English
      arrow-up
      4
      ·
      2 hours ago

      I bought a topton router with Intel N150. I was and still am disappointed with how much it heats up. Enev at idle it’s not really comfortable to touch it.

      • ☂️-@lemmy.ml
        link
        fedilink
        English
        arrow-up
        2
        ·
        39 minutes ago

        check thermal paste and get a fan attached to it. computer 120mm fans fit just right.

        • utjebe@reddthat.com
          link
          fedilink
          English
          arrow-up
          1
          ·
          15 minutes ago

          I don’t think thermal paste is the problem here, the whole box is god damn hot, so it conducts heat well. At wall it measures 14-15w consumption, got it there from like 20-22w that was on defaults. Given that N150 is 6W TDP, the whole system just runs hot.

          A fan would help, but I wanted fanless for a reason.

      • irmadlad@lemmy.world
        link
        fedilink
        English
        arrow-up
        2
        ·
        53 minutes ago

        A muffin fan with 4 stand offs would to the trick. Must be this particular model that gets hot.

    • irmadlad@lemmy.world
      link
      fedilink
      English
      arrow-up
      2
      ·
      2 hours ago

      It wouldn’t be a bad idea. Right at this moment my temps are as such:

      • dev.cpu.0.temperature: 103 °F
      • dev.cpu.1.temperature: 103 °F
      • dev.cpu.2.temperature: 105 °F
      • dev.cpu.3.temperature: 109 °F
      • hw.acpi.thermal.tz0.temperature: 81 °F

      IIRC, the case temp is like 194 freedom units. I’ve never really seen it get much higher than it is now.

  • v321@lemmy.ml
    link
    fedilink
    English
    arrow-up
    1
    ·
    2 hours ago

    What do you think of Keenetic? Security-wise, do you trust it?

    • pimpampoom@lemmy.zipOP
      link
      fedilink
      English
      arrow-up
      1
      ·
      29 minutes ago

      I just got it, it’s only being used as an access point so can’t really say about all their features.

      • v321@lemmy.ml
        link
        fedilink
        English
        arrow-up
        1
        ·
        18 minutes ago

        The reason I ask is that Keenetic has substantial ties with Russia. And there is a big chance the firmware development is still done in Russia.

  • peskypry@lemmy.ml
    link
    fedilink
    English
    arrow-up
    7
    ·
    5 hours ago

    Good for you. I use OpenWrt on a decent router yet it’s so flexible. I can create multiple VLANs with different firewall rules, multiple APs, Ad and IP blocking etc.

    Honestly I can’t imagine going back to a shitty ISP router ever.

    • Buffy@libretechni.ca
      link
      fedilink
      English
      arrow-up
      3
      ·
      3 hours ago

      Even the wrong non-isp routers are ridiculous compared to OpenWrt capable ones. You’re telling me I’m paying a huge premium to get a cutting edge Nighthawk, and then they shove a subscription service in my face to use any of these features? Let alone the security implications of having all your traffic routed through proprietary software. No thank you.

      • Snot Flickerman@lemmy.blahaj.zone
        link
        fedilink
        English
        arrow-up
        1
        ·
        55 minutes ago

        I don’t think we are the target audience for those, though, as weird as that sounds. More likely intended to be sold to less tech savvy people who are willing to pay for the convenience of some company handling their security.

  • irmadlad@lemmy.world
    link
    fedilink
    English
    arrow-up
    3
    ·
    4 hours ago

    I have crowdsec running on opnsense to block attacks

    Crowdsec is a pretty good package. It does blocking, but is geared more to being an IDS. Opnsense supports Suricata which is a more aggressive, and all encompassing IDS/IPS. I don’t think opnsense supports it’s cousin Snort.

  • DecronymB
    link
    fedilink
    English
    arrow-up
    5
    ·
    edit-2
    7 minutes ago

    Acronyms, initialisms, abbreviations, contractions, and other phrases which expand to something larger, that I’ve seen in this thread:

    Fewer Letters More Letters
    AP WiFi Access Point
    DNS Domain Name Service/System
    IP Internet Protocol
    IoT Internet of Things for device controllers

    4 acronyms in this thread; the most compressed thread commented on today has 7 acronyms.

    [Thread #47 for this comm, first seen 31st Jan 2026, 16:30] [FAQ] [Full list] [Contact] [Source code]

    • pimpampoom@lemmy.zipOP
      link
      fedilink
      English
      arrow-up
      1
      ·
      32 minutes ago

      Personal preference, it’s what I’ve been using since I started my homelab and I think it works well enough.

  • whimsy@lemmy.zip
    link
    fedilink
    English
    arrow-up
    21
    ·
    8 hours ago

    Networking isn’t my strong suit, so this might be a stupid question. But what exactly is a hardware firewall? Is it the same thing as my Internet facing router blocking incoming packets which haven’t been requested from “inside the home” network?

    • irmadlad@lemmy.world
      link
      fedilink
      English
      arrow-up
      12
      ·
      8 hours ago

      A hardware firewall generally indicates a standalone appliance that is dedicated to being a firewall. Not to be confused with a software firewall as you would see with UFW, or Windows Defender. Modern routers do possess some of the same tenets of a hardware firewall, but a dedicated hardware firewall usually gives a broader range of defenses such as IDS/IPS, filtering, etc.

      I have a dedicated hardware firewall in the form of pFsense. The ‘black box’ in OP’s picture is the hardware firewall.

  • SayCyberOnceMore@feddit.uk
    link
    fedilink
    English
    arrow-up
    1
    ·
    5 hours ago

    Nice.

    Running different SSIDs too?

    I put all my IoT stuff on a dedicated 2.4-only network, VLANd it to the (pfsense) firewall which allows the VLAN trunk to be split into separate logical NICs that I apply different policies to, like no access to the internet, etc…

    • pimpampoom@lemmy.zipOP
      link
      fedilink
      English
      arrow-up
      2
      ·
      4 hours ago

      At the moment I only have one WiFi instance, not planning to separate yet but it could be a future upgrade since I have a few IoT devices.

  • irmadlad@lemmy.world
    link
    fedilink
    English
    arrow-up
    5
    ·
    7 hours ago

    OP, you may want to look into ntopng. I think opnsense has a ntopng plugin. I find it very useful for traffic analysis.

  • snekerpimp@lemmy.world
    link
    fedilink
    English
    arrow-up
    7
    ·
    9 hours ago

    That looks exactly like the box I grabbed. Are you running your opnsense on the bare metal, or are you virtualizing it? My only regret for mine was not picking up more ram.

    • Shabby4582@lemmy.world
      link
      fedilink
      English
      arrow-up
      6
      ·
      9 hours ago

      Looks like one of the qotom/topton boxes you can find on aliexpress.

      Can also pick them up with preinstalled *sense from Protectli (which I did I regretted nothing, totally great experience.)

      • pimpampoom@lemmy.zipOP
        link
        fedilink
        English
        arrow-up
        6
        ·
        9 hours ago

        Indeed it’s a topton mini pc/firewall. It’s costs 300€ on AliExpress :) I removed Pfsense and installed opnsense