<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
	<channel>
		<title>Opnsense on trustserv.de</title>
		<link>https://trustserv.de/en/tags/opnsense/</link>
		<description>Recent content in Opnsense on trustserv.de</description>
		<generator>Hugo</generator>
		<language>en-US</language>
		
		
		
		
			<lastBuildDate>Mon, 17 Aug 2026 11:30:00 +0200</lastBuildDate>
		
			<atom:link href="https://trustserv.de/en/tags/opnsense/index.xml" rel="self" type="application/rss+xml" />
			<item>
				<title>Homelab Rebuild Part 8: Running My Own Certificate Authority</title>
				<link>https://trustserv.de/en/post/homelab-teil-8/</link>
				<pubDate>Mon, 17 Aug 2026 11:30:00 +0200</pubDate>
				<guid>https://trustserv.de/en/post/homelab-teil-8/</guid>
				<description>&lt;h2 id=&#34;the-annoyance&#34;&gt;&#xA;  The annoyance&#xA;  &lt;a class=&#34;heading-link&#34; href=&#34;#the-annoyance&#34;&gt;&#xA;    &lt;i class=&#34;fa-solid fa-link&#34; aria-hidden=&#34;true&#34; title=&#34;Link to heading&#34;&gt;&lt;/i&gt;&#xA;    &lt;span class=&#34;sr-only&#34;&gt;Link to heading&lt;/span&gt;&#xA;  &lt;/a&gt;&#xA;&lt;/h2&gt;&#xA;&lt;p&gt;Every internal service with a web interface greets you with a certificate&#xA;warning. Firewall, NAS, backup server, access point — same picture&#xA;everywhere, one click to dismiss each time.&lt;/p&gt;&#xA;&lt;p&gt;It isn&amp;rsquo;t just tedious. &lt;strong&gt;It trains you to click warnings away&lt;/strong&gt;, and&#xA;eventually you&amp;rsquo;ll dismiss one that mattered. Exactly the reflex you don&amp;rsquo;t&#xA;want to build.&lt;/p&gt;&#xA;&lt;p&gt;The fix is your own certificate authority. One root certificate installed&#xA;on your devices, and from then on the browser trusts everything issued by&#xA;it.&lt;/p&gt;</description>
			</item>
			<item>
				<title>Homelab Rebuild Part 5: The First VLAN</title>
				<link>https://trustserv.de/en/post/homelab-teil-5/</link>
				<pubDate>Sat, 15 Aug 2026 20:40:00 +0200</pubDate>
				<guid>https://trustserv.de/en/post/homelab-teil-5/</guid>
				<description>&lt;h2 id=&#34;why-telephony-of-all-things&#34;&gt;&#xA;  Why telephony of all things&#xA;  &lt;a class=&#34;heading-link&#34; href=&#34;#why-telephony-of-all-things&#34;&gt;&#xA;    &lt;i class=&#34;fa-solid fa-link&#34; aria-hidden=&#34;true&#34; title=&#34;Link to heading&#34;&gt;&lt;/i&gt;&#xA;    &lt;span class=&#34;sr-only&#34;&gt;Link to heading&lt;/span&gt;&#xA;  &lt;/a&gt;&#xA;&lt;/h2&gt;&#xA;&lt;p&gt;After &lt;a href=&#34;https://trustserv.de/en/post/homelab-teil-4/&#34; &gt;part 4&lt;/a&gt; everything is in place: a&#xA;firewall that can enforce rules, and a host for services. Now comes the&#xA;first VLAN of my own — and I deliberately started with the case where the&#xA;least can go wrong.&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;If the landline dies, it doesn&amp;rsquo;t matter.&lt;/strong&gt; I have a Swiss phone and a&#xA;German phone. A networking experiment whose worst outcome is that one&#xA;handset doesn&amp;rsquo;t ring is the ideal first test. That was the selection&#xA;logic: not the most important service first, the most harmless one.&lt;/p&gt;</description>
			</item>
			<item>
				<title>Homelab Rebuild Part 3: Sliding the Firewall In</title>
				<link>https://trustserv.de/en/post/homelab-teil-3/</link>
				<pubDate>Sat, 15 Aug 2026 20:00:00 +0200</pubDate>
				<guid>https://trustserv.de/en/post/homelab-teil-3/</guid>
				<description>&lt;h2 id=&#34;the-awkward-part&#34;&gt;&#xA;  The awkward part&#xA;  &lt;a class=&#34;heading-link&#34; href=&#34;#the-awkward-part&#34;&gt;&#xA;    &lt;i class=&#34;fa-solid fa-link&#34; aria-hidden=&#34;true&#34; title=&#34;Link to heading&#34;&gt;&lt;/i&gt;&#xA;    &lt;span class=&#34;sr-only&#34;&gt;Link to heading&lt;/span&gt;&#xA;  &lt;/a&gt;&#xA;&lt;/h2&gt;&#xA;&lt;p&gt;The hardware from &lt;a href=&#34;https://trustserv.de/en/post/homelab-teil-2/&#34; &gt;part 2&lt;/a&gt; was sitting on the&#xA;desk. The network kept running. And that&amp;rsquo;s exactly the uncomfortable&#xA;spot: the uplink isn&amp;rsquo;t my hobby project, it&amp;rsquo;s the way to the internet. If&#xA;I break it, it&amp;rsquo;s broken.&lt;/p&gt;&#xA;&lt;p&gt;So the task wasn&amp;rsquo;t &amp;ldquo;set up OPNsense&amp;rdquo;, it was &amp;ldquo;set up OPNsense without&#xA;hours of downtime in between&amp;rdquo;.&lt;/p&gt;&#xA;&lt;h2 id=&#34;prepare-before-it-counts&#34;&gt;&#xA;  Prepare before it counts&#xA;  &lt;a class=&#34;heading-link&#34; href=&#34;#prepare-before-it-counts&#34;&gt;&#xA;    &lt;i class=&#34;fa-solid fa-link&#34; aria-hidden=&#34;true&#34; title=&#34;Link to heading&#34;&gt;&lt;/i&gt;&#xA;    &lt;span class=&#34;sr-only&#34;&gt;Link to heading&lt;/span&gt;&#xA;  &lt;/a&gt;&#xA;&lt;/h2&gt;&#xA;&lt;p&gt;The first step had nothing to do with the network: the firewall got&#xA;assembled in my room, hooked up to the workstation, and fully configured.&#xA;LAN on &lt;code&gt;10.0.1.1&lt;/code&gt;, DHCP set up, base rules in place, everything clicked&#xA;through.&lt;/p&gt;</description>
			</item>
			<item>
				<title>Homelab Rebuild Part 2: Hardware for the Firewall</title>
				<link>https://trustserv.de/en/post/homelab-teil-2/</link>
				<pubDate>Sat, 15 Aug 2026 19:28:21 +0200</pubDate>
				<guid>https://trustserv.de/en/post/homelab-teil-2/</guid>
				<description>&lt;h2 id=&#34;the-question&#34;&gt;&#xA;  The question&#xA;  &lt;a class=&#34;heading-link&#34; href=&#34;#the-question&#34;&gt;&#xA;    &lt;i class=&#34;fa-solid fa-link&#34; aria-hidden=&#34;true&#34; title=&#34;Link to heading&#34;&gt;&lt;/i&gt;&#xA;    &lt;span class=&#34;sr-only&#34;&gt;Link to heading&lt;/span&gt;&#xA;  &lt;/a&gt;&#xA;&lt;/h2&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://trustserv.de/en/post/homelab-teil-1/&#34; &gt;Part 1&lt;/a&gt; settled what I wanted: a dedicated&#xA;firewall to take over routing, so the Banana Pi R4 could become a pure&#xA;switch and access point. What wasn&amp;rsquo;t settled was the hardware.&lt;/p&gt;&#xA;&lt;p&gt;My requirement sounded simple at first. Init7 gives me symmetric 10 Gbit&#xA;here, at the same price as 1 Gbit. If I&amp;rsquo;m buying a box anyway, it should&#xA;pass as much of that through as possible. On top of that I wanted to try&#xA;deep packet inspection — mostly because companies run it and I want to&#xA;understand how it behaves.&lt;/p&gt;</description>
			</item>
	</channel>
</rss>
