• 4 Posts
  • 233 Comments
Joined 3 years ago
cake
Cake day: July 20th, 2023

help-circle
  • Don’t know what to say,

    I maintain a double stack since 5 years and apart of some small nuisance I never had a real problem.

    Ipv6 has been with us for more than 20 years, and It is true that to have that fine grain control in ipv6 you will need to go to a prosumer devices, but those are not that expensive and if you have a home lab you should check on them anyway…

    Things are mature despite your bad experiences




  • The amount of swap used is not a good indicative, you need to check if there is a big exchange of data per second/minute. This is the only indicative of an out of memory system.

    Sometimes, some regions of data memory “age” in ram without any access for a long periods of time, the the kernel here has two options, it could destroy the region knowing it could recreate it when needed (with some cpu overhead) or moved this to a swap file when the ram structure already in the swap file and release than section.

    Which regions are good candidates for this? Buffers, specially in the fs, code region used for processes or even data sections of a long sleeping process…

    Checking your data, if those 5gb are created over a long period of time I would not care a lot about it. Remeber how big the swap is, isn’t that important vs real traffic (in or out) to it













  • My setup is “simple” and all these monitoring functions are performed in my opnsense box with the telegram plugin.

    Most of the alerts are pretty basic and are done into the FW level or the outbound basic logging. So opnsense with the basic tooling is just enough.

    I have in my todo to connect the logging system from opnsense to a proper Prometheus/grafana system to really have proper log of several days without having an impact on the FW but I never find the time to do it (lazyness problem)


  • Segment the network as much as feasible, forbid the communication between the segments via FW rules, and set an alert when those rules are triggered.

    For example: your dmz should never initiate any type of communication with your lan segment, your lan segment should not try to access services outside ports 80/443, your dns should log all resolutions performed and it would be nice to have at least a black list.

    None of them should have dns over tls, and for specific hosts and networks segments, new domains with very looong active but idle connections should trigger an alert.

    My personal opinion is that for a homelab is not realistic to perform a dpi to check that there is not an active attack ongoing, neither from the raw processing power, either from the human effort side, your best chance is to alert when something unusual is happening and then adjust your rules of the are false positives