opnsenseIncrease UFS read-ahead speeds to match the state of hard drives and NCQ.vfs.read_maxdefaultSet the ephemeral port range to be lower.net.inet.ip.portrange.firstdefault115200serialvideonormalOPN1somedomain.yourlocal.mcdadminsSystem Administratorssystem19992000page-allrootSystem Administratorsystemadmins$2y$10$5555555555o8dj21980j1doiOIJDIOASJOID!jidjeue19812y0$2y$11$55555555556D8198uOASIDJaiojdjd1oijdijosaoijdaoidOIASJDoijdoiadOASdoiKusersomeuser/bin/sh200020012000Etc/UTC0.opnsense.pool.ntp.org 1.opnsense.pool.ntp.org 2.opnsense.pool.ntp.org 3.opnsense.pool.ntp.orghttps6155aba4c93751yes111111hadphadphadpmonthlyaesni111admins1enabled11os-ddclient,os-dyndns,os-haproxy,os-wireguard1adminsyesbasicen_USnonenonenonenonenonenonenonenone1pppoe0WAN11pppoe11em1LAN1192.168.20.124track601lo0Loopback1127.0.0.1none18::1128em5backup_sync1110.10.5.1241wireguardWireGuard (Group)1group11openvpnOpenVPN1group11192.168.20.1somedomain.yourlocal.mcdhmac-md5192.168.20.50192.168.20.200192.168.20.155:55:55:55:55:1c192.168.20.160somehost983someservire855:55:55:55:55:1c192.168.20.155somehost89355:55:55:55:55:1c192.168.20.50hostswitch2switch-2 (bottom)public3automatictcpwaninetnat_618812d37b8193.31302503host_3221wanip55555root@192.168.1.118/firewall_nat_edit.php made changesroot@192.168.1.118/firewall_nat_edit.php made changestcpwaninetnat_651ffc35e573d9.09092618192.168.20.140221wanip30140root@172.12.0.11/firewall_nat_edit.php made changesroot@172.12.0.11/firewall_nat_edit.php made changespasswaninetkeep stateallow public connections to vpninwireguard1udp1wanip51820root@192.168.1.118/firewall_rules_edit.php made changesroot@192.168.1.118/firewall_rules_edit.php made changesnat_670979b3279551.73601303waninetkeep stateport forwarding for virtual ip for someservice2 serverstcp1
192.168.20.1
55555root@172.12.0.12/firewall_nat_edit.php made changes1ICMPicmpICMPTCPtcpGeneric TCPHTTPhttpGeneric HTTP/2000.opnsense.pool.ntp.orgsystem_information-container:00000000-col3:show,traffic_graphs-container:00000001-col3:show,thermal_sensors-container:00000002-col3:show,log-container:00000003-col3:show,services_status-container:00000004-col4:show,gateways-container:00000005-col4:show,interface_list-container:00000006-col4:show,carp_status-container:00000007-col4:show,wireguard-container:00000008-col4:show,dyn_dns_status-container:00000009-col4:show,system_log-container:00000010-col4:show2root@172.12.0.12/firewall_nat.php made changesv90180015wireguard11x3690_3host0192.168.1.1361someservice2_viphost0192.168.20.225alias for someservice2 vip000wan192.168.0.0/16,10.0.0.0/8,172.16.0.0/12W0D234acmedium0000120120127.0.0.1250auto1syslog facility log_daemon0rootoiujds9889DSIJSDIJSDIjdj2812510root@localhost.local0101$HOSTsystem30030da6083fd-852c-44af-9ae7-8c9de443bbc9,4f18b847-c2ab-4707-9686-bf656e187ab8,62ea6632-3554-43be-bb0b-ceceab685338,f543f50a-4e52-4afd-85ce-95fe6d61dc54PingNetworkPingfailed pingalertNetworkLinkNetworkInterfacefailed linkalert0opnsense110onstrip110admin@localhost.local0/var/squid/cache256always1001625600020481024102425600usernamepasswordlan31283129004503401public212101080:http,21:ftp,443:https,70:gopher,210:wais,1025-65535:unregistered ports,280:http-mgmt,488:gss-http,591:filemaker,777:multiling http443:https0icap://[::1]:1344/avscanicap://[::1]:1344/avscan100X-Username1102460OPNsense proxy authentication25115311transparent000000000000100.0.0.0/8,10.0.0.0/8,100.64.0.0/10,169.254.0.0/16,172.16.0.0/12,192.0.2.0/24,192.168.0.0/16,198.18.0.0/15,198.51.100.0/24,203.0.113.0/24,233.252.0.0/24,::1/128,2001:db8::/32,fc00::/8,fd00::/8,fe80::/10allow0001apisomeapp.yourdomain.local.mcdA192.168.20.161Some app local1api-intsomeapp.yourdomain.local.mcdA192.168.20.161Some app local1*someapp.yourdomain.local.mcdA192.168.20.161Some app local11publicwg089udsjiuod109jadsSUIDSAUIduhashuiauas/asdkj=eH555555555555555+892jdjiodsjiodsoijsdjiodj=51820172.12.0.1/24003031aec-2e84-462e-9eab-57762dde667a,98e6ca3d-1de9-449b-be80-77022221b509,67c0ace5-e802-4d2b-a536-f8b7a2db6f99,74b60fff-7844-4097-9966-f1c2b1ad29ff,3de82ad5-bc1b-4b91-9598-f906e58ac937,a95e6b5e-24a4-40b5-bb41-b79e784f6f1c,6c9a12c6-c1ca-4c14-866b-975406a30590,c33b308b-7125-4688-9561-989ace8787b5,e43f004a-23bf-4027-8fb0-953fbb40479f1some-laptop95555555555555555555555555555FN2aCHemL3RjA8=172.12.0.8/321user2pJ555555555555555555xiUxuJof78XXugx1KUrrYg8=172.12.0.6/321some-phoneSLQXdM/555555555555555555MWhR2WSEkaSXh1ZpXU=172.12.0.9/32100300ddclient1someddnsprovidersomeusername.com55555555555555555555555555555dsiyourpublic.host.com0if101300wanyourpublic.host.com1060s00101024102401ignore204816384ipv4200030036000prefer-client-ciphersTLSv1.2ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-SHA384:ECDHE-ECDSA-AES128-SHA256TLS_AES_128_GCM_SHA256:TLS_AES_256_GCM_SHA384:TLS_CHACHA20_POLY1305_SHA25630s30s30s3x-1last,libc127.0.0.1local0info08822000*:8404/metrics04600106707fe74642f67.520198991some-ingresspublic service redirecting traffic192.168.20.55:55555tcpf0c76bef-8623-4fa8-a992-61f83d504b8700prefer-client-ciphersTLSv1.2ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-SHA384:ECDHE-ECDSA-AES128-SHA256TLS_AES_128_GCM_SHA256:TLS_AES_256_GCM_SHA384:TLS_CHACHA20_POLY1305_SHA256100157680000required00000030m50k1src10s10s10s10s1m1m00h2,http1100/metricshttp-keep-alive670979396dea69.722994270another-ingresspublic service redirecting traffic with non descriptive description192.168.20.1:55555tcpf0c76bef-8623-4fa8-a992-61f83d504b8700prefer-client-ciphersTLSv1.2ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-SHA384:ECDHE-ECDSA-AES128-SHA256TLS_AES_128_GCM_SHA256:TLS_AES_256_GCM_SHA384:TLS_CHACHA20_POLY1305_SHA256100157680000required00000030m50k1src10s10s10s10s1m1m00h2,http1100/metricshttp-keep-alive6707fa71c3cb99.644516641some_serverstcproundrobin2c0364e69-459d-48b2-a1d1-808324fea9cb,187d8b79-4376-45fc-9fd7-476074a7a57715110db0c-afa9-4bad-bbbe-5bbeb52262bb000h2,http11sticktablepiggybackSRVCOOKIE1sourceipv430m50k10s10s10s10s1m1m00safe06707f9a980b271.592225801server1server running on host
192.168.20.55
55555activeunspecifiedstatic01336707faa46d5f57.143187831server2server running something
192.168.20.155
55555activeunspecifiedstatic0167server-loadbalancer-monitortcp2snopref0options/http10localhost000string0000006155aba4c9375Web GUI TLS certificateLtCg==L22o=wanipalias192.168.20.1553210.11.16.170010virtual ip for service0pppoepppoe0em0someuser@ppoeserver.com5555555555AyNA==someddnsprovider5555555555ee479874398u1298e98u18yourpublic.host.comwanwan0ononononononononononononononononononononononononononononononononopt110.10.5.2root555555555ononon