MadaMada

@madamada@snac.void.my

SysAdmin with a simple life..interested in FOSS, FreeBSD, Linux, IPv6, cloud stuff and whatever things that come along the way I find interesting..
JabberIDmadamada@xpath.my
Matrix@madamada:matrix.org
Emailmada@void.my
Webhttps://buster.xpath.my
Geminigemini://warlock.xpath.my
TheFediPeoplehttps://fediverse.info/explore/people
Yggdrasilhttps://yggdrasil-network.github.io/
silverpill boosted

[?]deutrino »
@deutrino@mstdn.io

please list and/or tell me about every ActivityPub software which is excellent for running a single-user instance!

boosts desired! :awoo:

    ...
    1 ★ 0 ↺

    [?]MadaMada »
    @madamada@snac.void.my

    ...

    [?]deutrino »
    @deutrino@mstdn.io

    @madamada I was pleased to see this is in Debian testing (and maybe stable, I haven't looked)

      #freebsd boosted

      [?]gino »
      @colman@ieji.de

      Installing xorg on

      Thinkpad laptop

      Alt...Thinkpad laptop

        ...
        1 ★ 0 ↺

        [?]MadaMada »
        @madamada@snac.void.my

        pkg install py311-fastest_pkg to get the fastest pkg mirror :>

          [?]dch :flantifa: :flan_hacker: »
          @dch@bsd.network

          has an updated blocklistd daemon thanks to efforts from jlduran@ with help from emaste@ & myself, imported from NetBSD github.com/zoulasc/blocklist

          Blocklistd is an additional hook into sshd from OpenBSD, that tracks failed attempts. It now blocks on failed usernames as well.

          I added a small notification :flan_hacker: to the script and get a very satisfying notification every time one of my servers bans a crawler.

          I should also extend this so that it handles more than just ssh, but also links into our web crawler detection tooling.

          I also want to extend this script so that getting a ban one on server gets you a block on all of them :)

            ...
            #freebsd boosted

            [?]dch :flantifa: :flan_hacker: »
            @dch@bsd.network

            I block these spammers for a week atm.

            blocklistd allows you to specify the number of failures before you block (I set this to zero for immediate block) and the duration before the firewall rule is cleared.

            As there is also an allowlist for my trusted networks, I’m never at risk of being locked out.

            As I roll out 15.0-BETA3 I am also enabling this too. At some point the notifications will be annoying but right now it’s a great deal of satisfaction, hearing them trickle in every couple of hours.

            a list of notifications from servers of blocked IP ranges.

            Alt...a list of notifications from servers of blocked IP ranges.

              ...

              [?]F. ⭐⭐⭐⭐⭐ »
              @derherrfreitag@bonn.social

              @dch Good thing to have an easy integration for that. Does it allow to block ranges as well? For IPv6, I usually block the whole /64, as these v6 is assigned in these blocks and even for v4 I am blocking /24 because most (=almost any) of this traffic comes from poorly managed hosters/cloud ranges or dial-up ISP ranges...

                ...

                [?]dch :flantifa: :flan_hacker: »
                @dch@bsd.network

                @derherrfreitag it would be a trivial charge in cgit.freebsd.org/src/tree/libe to use a larger mask. But by default it blocks bad IPs not networks.

                  ...

                  [?]F. ⭐⭐⭐⭐⭐ »
                  @derherrfreitag@bonn.social

                  @dch Yeah, easy to adapt. Thanks for pointing out.

                    Older...

                    [?]kaveman »
                    @kaveman@mastodon.bsd.cafe

                    @dch @jeffpc the updated libblocklist API has an open2 which takes a custom logger. Would that help with your nginx use-case?

                    context: mastodon.radio/@jeffpc/1153561

                      [?]the esoteric programmer »
                      @esoteric_programmer@social.stealthy.club

                      @dch doesn't crowdsec have modules for blocking both web traffic and ssh stuff?

                      ...

                      [?]dch :flantifa: :flan_hacker: »
                      @dch@bsd.network

                      @esoteric_programmer yes they do also but you are required to trust their systems and share your data with them, it’s not always a win for privacy vs security.

                        [?]meka »
                        @meka@bsd.network

                        @dch I know postfix is supporting blocklist but what else? I could extend blocklist from only ssh to a wider set of services

                          ...

                          [?]dch :flantifa: :flan_hacker: »
                          @dch@bsd.network

                          @meka ideally I would be able to use blocklistd from external tools, specifically haproxy.

                          As haproxy has our TLS private keys, it can see inside the URL and query parameters to see what HTTP agents are used, or if we're being probed for SQL injections or wordpress vulns (we don't run WP so thats definitely malicious), and hand that over to blocklistd to perma-ban them.

                          atm blocklistd has a hard requirement on having access to the incoming file descriptor, and it would be a generally much more useful tool if it had some functionality to at least be able to add & remove externally supplied IP addresses into its database, perhaps extending blocklistctl in some way, or allowing some /dev/blocklist where members of the appropriate UNIX group could insert, query, or remove entries.

                            ...

                            [?]meka »
                            @meka@bsd.network

                            @dch I wanted to do the management commands for it years ago. I will have to check my GitHub, maybe I did something. I know I have some dummynet integration from few years back.

                              0 ★ 0 ↺

                              [?]MadaMada »
                              @madamada@snac.void.my

                              Does Blocklistd replace the already available Blacklistd ?

                              What's the difference between this and the existing UseBlacklist in SSH ?

                              Also, does blocklistd have a retention period before clearing the lists ?

                                ...

                                [?]dch :flantifa: :flan_hacker: »
                                @dch@bsd.network

                                @madamada yep it was renamed upstream in between last FreeBSD releases. jlduran has added the necessary plumbing and release notes so that it should work without config changes but also remind you to update to the new names.

                                  ...
                                  0 ★ 0 ↺

                                  [?]MadaMada »
                                  @madamada@snac.void.my

                                  Ah cool thanks.

                                    [?]dch :flantifa: :flan_hacker: »
                                    @dch@bsd.network

                                    @madamada and yes it has a little DB to track when entries need to be retired from the firewall

                                      [?]ltning »
                                      @ltning@pleroma.anduin.net

                                      @dch could I inject IPs to block from lua code in nginx? Does it space out the changes in pf (assuming pf is supported) so we don't spend all our time in pf locks when thousands of IPs are added in a split second? Asking for a friend ;)

                                        ...

                                        [?]dch :flantifa: :flan_hacker: »
                                        @dch@bsd.network

                                        @ltning atm no and no.

                                        blocklistd‘s current api requires passing the FD in and blocklistd uses that to find the culprit src IP directly.

                                        its a standard pf table insert via shell script cgit.freebsd.org/src/tree/libe

                                          [?]Eugen »
                                          @ieugen@mas.to

                                          hello lazy web, I'm looking for solutions / DNS providers that support hosting Reverse IPV6 DNS zones . I would like to take control over my IPV6 hosting for hosting my own server over IPV6.

                                          Not keen on hosting my own primary DNS service yet.

                                            ...

                                            [?]Albrecht »
                                            @albrecht@masto.a0s.de

                                            @ieugen You mean for your own IPv6 prefix?

                                              ...

                                              [?]Eugen »
                                              @ieugen@mas.to

                                              @albrecht yes, my very own IPv6 prefix . A full /56 :)

                                                ...
                                                #freebsd boosted

                                                [?]Larvitz »
                                                @Larvitz@mastodon.bsd.cafe

                                                Made my FreeBSD server at Netcup ready to host multiple isolated applications with automatic https via Let's Encrypt.

                                                Internet → Server → PF firewall → Caddy jail (reverse proxy) → Individual application jails

                                                Each app gets its own isolated jail for security, while Caddy handles all the routing and https. PF keeps the front door locked.

                                                All of course with IPv6 first, where every Jail has it's own public IP address and using NAT for legacy IPv4.

                                                Love how FreeBSD jails make this kind of segmentation so elegant.

                                                Traffic flow diagram

                                                Alt...Traffic flow diagram

                                                  ...

                                                  [?]Børge »
                                                  @noexec@mastodon.bsd.cafe

                                                  @Larvitz how did you get public IPv6 in the jails? Were you able to get that working with the /64 you were assigned or did you need to get more? I've struggled with IPv6 and Netcup, and it seems others have too so I'm just curious

                                                    ...

                                                    [?]Larvitz »
                                                    @Larvitz@mastodon.bsd.cafe

                                                    @noexec I did carve out a /80 subnet from the /64 and use that for jails. Not elegant but it works.

                                                    For some older Jails, I still use ULA addresses (fdXX) and NAT

                                                      0 ★ 0 ↺

                                                      [?]MadaMada »
                                                      @madamada@snac.void.my

                                                      On Contabo, I have my /64 split into 2 x /72's, one for the host and one for Wireguard clients. Not pretty but it works.

                                                      CC: @Larvitz@bsd.cafe

                                                        [?]Daniel Gultsch »
                                                        @daniel@gultsch.social

                                                        I want to move away from YouTube Music.

                                                        What open source music player are you using on Android?

                                                        ...
                                                        Older...

                                                        [?]Arnav Kumar »
                                                        @arnav@fosstodon.org

                                                        @daniel I use the good ol' VLC with local FLAC files.

                                                          [?]pixelschubsi »
                                                          @pixelschubsi@troet.cafe

                                                          @daniel Not exactly moving away from YouTube Music, but with OpenTune you at least don't need to pay them or have an account.

                                                            [?]Ulrich Popp :jf: »
                                                            @HoSnoopy@m.efg-ober-ramstadt.de

                                                            @daniel I dont have Android or iOS, but I installed Jellyfin/Sailfin. ;-)
                                                            Works good, if you have your own mp3s at home stored.

                                                              [?]Marcus Adams »
                                                              @gerowen@mastodon.social

                                                              @daniel I use Ultrasonic which streams from the with the "Music" app on my Nextcloud server. The Nextcloud music app supports both Subsonic and Ampache protocols.

                                                              Link: f-droid.org/packages/org.moire

                                                                [?]Andrea Mazzilli »
                                                                @andreamazzilli@mastodon.social

                                                                @daniel I'm currently using Auxio

                                                                  [?]phylax »
                                                                  @phylax@social.anoxinon.de

                                                                  @daniel I use Fossify Music Player

                                                                    [?]poeschel »
                                                                    @poeschel@jit.social

                                                                    @daniel Not sure if that counts as a music player in your sense. I use
                                                                    Tempo
                                                                    f-droid.org/packages/com.cappi

                                                                      [?]sb arms & legs »
                                                                      @sb@metroholografix.ca

                                                                      @daniel
                                                                      I use for android, and as a server. It's fantastic!

                                                                        [?]Martina Neumayer »
                                                                        @MartinaNeumayer@mastodon.social

                                                                        @daniel None. I don't use any streaming junk. My music is on vinyls, 8-tracks, tapes, bands, CDs and similar things instead of being online. Yes, it may be old-fashioned and at times less practical, but my music played that way has something that the online "high-quality-umpa-umpa" lacks: soul.

                                                                          [?]CryptGoat »
                                                                          @cryptgoat@fedifreu.de

                                                                          @daniel
                                                                          is an excellent and sleek local audio player.
                                                                          beta for Jellyfin music streaming.
                                                                          or for YouTube Music.

                                                                            [?]Marko »
                                                                            @decorum@kanoa.de

                                                                            @daniel NewPipe 👍

                                                                              [?]Uwe Caspari »
                                                                              @ucas@dudo.social

                                                                              @daniel I use Pi Music Player. A really simple Player, I like it that way.

                                                                                1 ★ 0 ↺

                                                                                [?]MadaMada »
                                                                                @madamada@snac.void.my

                                                                                [?]SimpleX Chat »
                                                                                @simplex@mastodon.social

                                                                                Join & create SimpleX groups!

                                                                                The directory can now be viewed on our website: simplex.chat/directory

                                                                                ...

                                                                                [?]waffles »
                                                                                @wafflesies@infosec.exchange

                                                                                @simplex is it supposed to be empty though

                                                                                  ...
                                                                                  2 ★ 0 ↺

                                                                                  [?]MadaMada »
                                                                                  @madamada@snac.void.my

                                                                                  Yeah the link the new site is empty. The link to https://simplex.chat/directory isn't though..

                                                                                  CC: @simplex@mastodon.social

                                                                                    [?]Martina Neumayer »
                                                                                    @MartinaNeumayer@mastodon.social

                                                                                    @simplex Gladly but I can't. I can't even chat with people because there's a nasty bug with the latest 6.4.5 app version on android.
                                                                                    The keyboard is popping up and hiding constantly on its own like a crazy. There's no way to stop that from happening else than fully reboot the phone. Tested on few different keyboards, few different devices with same results. The app is unusable in such state. Often I can't even login in. That's not good at all! Please fix the issue ASAP!
                                                                                    V.6.5 still had the bug.👎

                                                                                      [?]ejim »
                                                                                      @ejim@muenster.im

                                                                                      @simplex you got the link wrong in your post

                                                                                        #freebsd boosted

                                                                                        [?]Tom »
                                                                                        @pertho@mastodon.bsd.cafe

                                                                                        Well.. got working on . Not sure how to solve the /compat/linux/dev/shm thing automatically but it's downloading the games.

                                                                                        A picture of my i3 desktop running Valve's Steam client on the left-hand side of the screen which is downloading Portal 2 and Skyrim. On the right-hand side is a terminal window with fastfetch text showing the system is running FreeBSD 14.3-RELEASE-p3.

                                                                                        Alt...A picture of my i3 desktop running Valve's Steam client on the left-hand side of the screen which is downloading Portal 2 and Skyrim. On the right-hand side is a terminal window with fastfetch text showing the system is running FreeBSD 14.3-RELEASE-p3.

                                                                                          ...
                                                                                          #freebsd boosted

                                                                                          [?]Tom »
                                                                                          @pertho@mastodon.bsd.cafe

                                                                                          Outcome of testing on :

                                                                                          1. Downloading and installing games was painful. Steam would crash with some monitor file descriptor assert error. I had to start Steam multiple times to install a game

                                                                                          2. Running games is impossible:
                                                                                          "lsu-bwrap-stub.rb: Bubblewrap doesn't work on FreeBSD. Select LSU chroot or Legacy Runtime in the game compatibility settings"

                                                                                          Selecting Legacy Runtime made Portal 2 run but the graphics are all messed up and stuttery.. setting graphics to 1920x1080 made the game and Steam crash out. Why back in and getting loads of graphics corruption.

                                                                                          Skyrim didn't run at all no matter what I tried.

                                                                                          Sadly this experiment didn't go well.

                                                                                            ...
                                                                                            0 ★ 0 ↺

                                                                                            [?]MadaMada »
                                                                                            @madamada@snac.void.my

                                                                                            Hate to break it to you..if you are coming from Windows, most of the stuff you run there will hardly run on FreeBSD..and if you manage to get it to run at all, they aren't stable..will often crash, leave artifacts, etc etc..also hardware dependent..

                                                                                            It's not quite there yet..but it's getting there bit by bit..

                                                                                            Hopefully FreeBSD 15-RELEASE will be an upgrade to all that..

                                                                                              ...

                                                                                              [?]Tom »
                                                                                              @pertho@mastodon.bsd.cafe

                                                                                              @madamada I'm definitely not coming from Windows. I haven't used Windows personally since 2003.

                                                                                                #freebsd boosted

                                                                                                [?]Tom »
                                                                                                @pertho@mastodon.bsd.cafe

                                                                                                Hey friends: Is there some kind of severe rate/connection throttling in base sshd? I was able to connect once and then since then, it hangs. Off I telnet to port 22 I do get a banner but the key exchange just hangs and I get a connection reset after a while.

                                                                                                Am I better off disabling the base sshd and install openssh server?

                                                                                                  ...
                                                                                                  1 ★ 0 ↺

                                                                                                  [?]MadaMada »
                                                                                                  @madamada@snac.void.my

                                                                                                  Try disabling the following in sshd_config

                                                                                                  • UseDNS no
                                                                                                  • UsePAM no (optional)
                                                                                                  Then restart SSHD

                                                                                                    ...

                                                                                                    [?]Tom »
                                                                                                    @pertho@mastodon.bsd.cafe

                                                                                                    @madamada I had usedns set to no already. I'll try usepam no as well.

                                                                                                      #freebsd boosted

                                                                                                      [?]heise online English » 🤖
                                                                                                      @heiseonlineenglish@social.heise.de

                                                                                                      Netgate sponsors the modernisation of the FreeBSD variant of pf(4)

                                                                                                      FreeBSD 15.0 is expected to bring noticeable improvements to its pf(4) variant. This will also benefit pfSense and OPNsense.

                                                                                                      heise.de/en/news/Netgate-spons

                                                                                                        ...
                                                                                                        1 ★ 1 ↺
                                                                                                        :runbsdBg: sysop :runbsdBg: boosted

                                                                                                        [?]MadaMada »
                                                                                                        @madamada@snac.void.my

                                                                                                        I hope they also include af-to into it..


                                                                                                          #freebsd boosted

                                                                                                          [?]Stefano Marinelli »
                                                                                                          @stefano@mastodon.bsd.cafe

                                                                                                          ...
                                                                                                          Older...

                                                                                                          [?]Nux »
                                                                                                          @Nux@fosstodon.org

                                                                                                          @stefano 5 days to go until what?

                                                                                                          Re Zimbra, I think it lives on as Carbonio developed by your own paesani at Zextras. There's commercial support available, too.

                                                                                                          zextras.com/carbonio-community

                                                                                                            ...

                                                                                                            [?]Stefano Marinelli »
                                                                                                            @stefano@mastodon.bsd.cafe

                                                                                                            @Nux It's the EuroBSDConAdvent calendar, so 5 days to EuroBSDCon 🙂
                                                                                                            Zimbra is still Open Source, they just don't provide the builds anymore - but you can build it yourself.
                                                                                                            Carbonio is another software - a Zimbra fork.

                                                                                                              ...

                                                                                                              [?]Nux »
                                                                                                              @Nux@fosstodon.org

                                                                                                              @stefano Oh, how lovely, have a nice time there! Hope to catch up with the slides and recordings, would love to come in person at some point.

                                                                                                              Re Zimbra, I think it lost a lot of credibility when exchanging so many hands. My gut prefers Zextras atm.

                                                                                                                ...

                                                                                                                [?]Stefano Marinelli »
                                                                                                                @stefano@mastodon.bsd.cafe

                                                                                                                @Nux I agree, all those ownership changes didn't look good at all. More, they seem more oriented towards providing software and services to "the big cloud players" so they're not focused on self-hosting anymore. And it's a shame.
                                                                                                                About Zextras - I've very good reasons to avoid dealing with them. This could be one of the future horror stories on my blog...

                                                                                                                  ...

                                                                                                                  [?]Holger Hessdorfer »
                                                                                                                  @drheho@mastodon.social

                                                                                                                  @stefano what about fail2ban for your mailserver setup to prevent constant mailserver requests with different passwords?

                                                                                                                    ...

                                                                                                                    [?]Stefano Marinelli »
                                                                                                                    @stefano@mastodon.bsd.cafe

                                                                                                                    @drheho This article just covers the basics - of course, the server should be hardened, both at firewall level (limiting the requests, connections, etc.) and using solutions like fail2ban. But I didn't want to go too deep.

                                                                                                                      ...

                                                                                                                      [?]Holger Hessdorfer »
                                                                                                                      @drheho@mastodon.social

                                                                                                                      @stefano would it be possible to maybe see an advanced server tutorial/dokumentation sometime which addresses this

                                                                                                                        3 ★ 3 ↺

                                                                                                                        [?]MadaMada »
                                                                                                                        @madamada@snac.void.my

                                                                                                                        Great guide as usual 🙂

                                                                                                                        An alternative for those that want the heavy lifting done automatically can checkout iRedMail

                                                                                                                          ...
                                                                                                                          8 ★ 1 ↺
                                                                                                                          Mynacol boosted

                                                                                                                          [?]MadaMada »
                                                                                                                          @madamada@snac.void.my

                                                                                                                          Found this badge on my desk when I was cleaning up..I can't recall where I got it from.. oh well.. rocks 🙂

                                                                                                                            [?]Ryan Barrett »
                                                                                                                            @snarfed.org@fed.brid.gy

                                                                                                                            I don’t understand the value of consumer VPNs. Can someone explain it to me?

                                                                                                                            We do pretty much everything over SSL these days. Definitely everything that matters. That provides confidentiality, so network intermediaries can’t see the data, and server authentication, so they can’t impersonate the server.

                                                                                                                            Yes, DNS is the exception, it’s not encrypted, but more and more browsers and other user agents are building in DoH and DoT, and even enabling it by default.

                                                                                                                            So, given all that, what do general purpose VPNs add? What am I missing? Are they just security theater marketing? Or do they bundle other security features like anti-malware etc, and the term “VPN” now means a bundle of miscellaneous endpoint security features, like (shudder) anti-virus used to?

                                                                                                                            ...

                                                                                                                            [?]silverpill »
                                                                                                                            @silverpill@mitra.social

                                                                                                                            @snarfed.org They are used for censorship circumvention and for privacy (to hide IP address).

                                                                                                                              1 ★ 0 ↺

                                                                                                                              [?]MadaMada »
                                                                                                                              @madamada@snac.void.my

                                                                                                                              Think public networks, airport/hotel wifi, public cafe wifi..would you trust using them ? That's where a VPN comes in..

                                                                                                                              Want to watch a streaming tv series but it's not available in your region, a VPN can help..

                                                                                                                              In countries like China where most things are blocked, how do you access say, Youtube ? A VPN..

                                                                                                                              And the lists goes on..

                                                                                                                              A VPN used to be a thing that links two or more networks together..oh how much it has grown..

                                                                                                                              I use it all the time when I am on a public network..simply because I trust my own network more..

                                                                                                                                ...

                                                                                                                                [?]Ryan Barrett »
                                                                                                                                @snarfed.org@fed.brid.gy

                                                                                                                                the point of SSL is that you don't need to trust the underlying network, for either confidentiality or endpoint authentication.

                                                                                                                                circumventing censorship and region blocking are definitely good points though!

                                                                                                                                  4 ★ 2 ↺
                                                                                                                                  :runbsdBg: sysop :runbsdBg: boosted

                                                                                                                                  [?]MadaMada »
                                                                                                                                  @madamada@snac.void.my

                                                                                                                                  Hm so the livecd of GhostBSD 25.02-R14.3p2 loads and runs on my Thinkpad T480..typing this from Firefox from the livecd 🙂

                                                                                                                                  For the FN Keys, it seems only the volume keys work 😞

                                                                                                                                  For Wifi, 2.4G works, associates quickly.. but for 5G with the same passphrase, it tries to associate and fails 😞

                                                                                                                                  But no worries, just trying this out to see what works and what doesn't..

                                                                                                                                  ...

                                                                                                                                  [?]radhitya 🇵🇸 🇮🇩 »
                                                                                                                                  @al1r4d@pegelinux.top

                                                                                                                                  @madamada when xlibre?

                                                                                                                                    ...
                                                                                                                                    0 ★ 0 ↺

                                                                                                                                    [?]MadaMada »
                                                                                                                                    @madamada@snac.void.my

                                                                                                                                    @al1r4d@pegelinux.top No idea.. probably less than a year from now since it is still new..

                                                                                                                                      [?]bsdtv_personal »
                                                                                                                                      @bsdtv@mastodon.bsd.cafe

                                                                                                                                      @madamada here is the NYC*BUG dmesgd page for your laptop. Perhaps you may find helpful information among the entries:
                                                                                                                                      dmesgd.nycbug.org/dmesgd?do=in

                                                                                                                                        ...
                                                                                                                                        1 ★ 0 ↺

                                                                                                                                        [?]MadaMada »
                                                                                                                                        @madamada@snac.void.my

                                                                                                                                        Thanks...took a look..most of the stuff works, the stock wifi driver still displays the code ce error which is related to the wifi firmware..

                                                                                                                                          4 ★ 1 ↺

                                                                                                                                          [?]MadaMada »
                                                                                                                                          @madamada@snac.void.my

                                                                                                                                          So I was testing CLAT in a VirtualBox running Porteus Linux. The VM is IPv6-only and it seems to be working. Here's the following requirements..
                                                                                                                                          git
                                                                                                                                          tayga
                                                                                                                                          make/gcc compiler
                                                                                                                                          a NAT64 service running on your local network (Tayga/Jool)

                                                                                                                                          Build the source

                                                                                                                                          mkdir staging
                                                                                                                                          cd staging
                                                                                                                                          git clone https://github.com/apalrd/tayga.git
                                                                                                                                          cd tayga
                                                                                                                                          make
                                                                                                                                          make install

                                                                                                                                          Configuration file

                                                                                                                                          cat /etc/tayga.conf
                                                                                                                                          tun-device clat
                                                                                                                                          ipv4-addr 192.0.0.2
                                                                                                                                          ipv6-addr 2001:db8:feed::65
                                                                                                                                          map 192.0.0.1 2001:db8:feed::64
                                                                                                                                          prefix 64:ff9b::/96 # NAT64 prefix
                                                                                                                                          Replace 2001:db8:feed with your /64 GUA prefix.
                                                                                                                                          You can use Cloudflare's 2606:4700:4700::64 as the DNS4 resolver.

                                                                                                                                          Configure Tayga

                                                                                                                                          #!/usr/bin/env bash

                                                                                                                                          echo 1 > /proc/sys/net/ipv6/conf/all/forwarding
                                                                                                                                          echo 2 > /proc/sys/net/ipv6/conf/eth0/accept_ra
                                                                                                                                          echo 1 > /proc/sys/net/ipv6/conf/eth0/proxy_ndp

                                                                                                                                          ip neigh add proxy 2001:db8:feed::64 dev eth0
                                                                                                                                          ip neigh add proxy 2001:db8:feed::65 dev eth0

                                                                                                                                          tayga -c /etc/tayga.conf --mktun

                                                                                                                                          ip link set dev clat up
                                                                                                                                          ip addr add 192.0.0.1/29 dev clat
                                                                                                                                          ip route add default dev clat mtu 1260
                                                                                                                                          ip route add 2001:db8:feed::64/127 dev clat

                                                                                                                                          tayga -c /etc/tayga.conf

                                                                                                                                          Example output should look like this:
                                                                                                                                          root@skully:~# ip a s dev clat
                                                                                                                                          5: clat: <POINTOPOINT,MULTICAST,NOARP,UP,LOWER_UP> mtu 1500 qdisc pfifo_fast state UP group default qlen 500
                                                                                                                                          link/none
                                                                                                                                          inet 192.0.0.1/29 scope global clat
                                                                                                                                          valid_lft forever preferred_lft forever
                                                                                                                                          inet6 fe80::cbdf:afeb:7379:bd0a/64 scope link stable-privacy
                                                                                                                                          valid_lft forever preferred_lft forever
                                                                                                                                          root@skully:~# ping -c 3 1.1.1.1
                                                                                                                                          PING 1.1.1.1 (1.1.1.1) 56(84) bytes of data.
                                                                                                                                          64 bytes from 1.1.1.1: icmp_seq=1 ttl=52 time=13.0 ms
                                                                                                                                          64 bytes from 1.1.1.1: icmp_seq=2 ttl=52 time=16.6 ms
                                                                                                                                          64 bytes from 1.1.1.1: icmp_seq=3 ttl=52 time=13.7 ms

                                                                                                                                          --- 1.1.1.1 ping statistics ---
                                                                                                                                          3 packets transmitted, 3 received, 0% packet loss, time 2004ms
                                                                                                                                          rtt min/avg/max/mdev = 13.008/14.429/16.557/1.532 ms

                                                                                                                                          Enjoy 🙂

                                                                                                                                          -only

                                                                                                                                            #freebsd boosted

                                                                                                                                            [?]rvstaveren »
                                                                                                                                            @rvstaveren@mastodon.online

                                                                                                                                            Trying out (4) in a separate fib… but that doesn’t work at all: I’m seeing ARP requests but they’re all stay unanswered... Does that mean the address used for vxlanlocal also needs to be in that fib? Trying to segregate my jail traffic using its own gateway

                                                                                                                                              ...
                                                                                                                                              0 ★ 0 ↺

                                                                                                                                              [?]MadaMada »
                                                                                                                                              @madamada@snac.void.my

                                                                                                                                              @rvstaveren@mastodon.online As I understand it, the networking part + jail needs to be executed under that FIB..

                                                                                                                                                #freebsd boosted

                                                                                                                                                [?]kaveman »
                                                                                                                                                @kaveman@mastodon.bsd.cafe

                                                                                                                                                Plasma 6 on simply reboots the machine after an hour or so. Nothing heavy running on the machine. Sadly no logs, core files etc. just reboots. Don't have the energy to look into this now. Sadly, the desktops are all Linux first and bring in a lot of Linuxisms. I used to use i3 earlier but these days I don't want to tweak config files. GNUstep? Lumina?

                                                                                                                                                  ...
                                                                                                                                                  #freebsd boosted

                                                                                                                                                  [?]EF »
                                                                                                                                                  @EF@mastodon.bsd.cafe

                                                                                                                                                  @kaveman Mate seems decent on or xfce.

                                                                                                                                                    1 ★ 0 ↺

                                                                                                                                                    [?]MadaMada »
                                                                                                                                                    @madamada@snac.void.my

                                                                                                                                                    My 2 cents..

                                                                                                                                                    My choices are XFCE or LXDE. Both are lightweight and serves my needs. For me, I look at the programs that are must have's regardless of either DE or WM, which are quite minimal..

                                                                                                                                                    A terminal, browser, media player, torrent client, pdf reader, file manager, editor, and a screenshot program.

                                                                                                                                                    Most of my time is spent in the terminal..

                                                                                                                                                    The perfect DE/WM for me are the one's where you rarely have to mess around with that much. It should just work and not get in the way of you spending that time on productive/leisure things that matter most.

                                                                                                                                                      ...

                                                                                                                                                      [?]kaveman »
                                                                                                                                                      @kaveman@mastodon.bsd.cafe

                                                                                                                                                      @madamada agreed. I wouldn't call xfce lightweight though. last I checked, a fresh empty plasma desktop weighs only slightly more.

                                                                                                                                                        #freebsd boosted

                                                                                                                                                        [?]Santiago, né ? :amiga: 👾 »
                                                                                                                                                        @santi@gone.lema.org

                                                                                                                                                        Unlike VMs my #FreeBSD #jails don’t need a ssh server. I just connect to the host and pass tmuxjail.sh <jailname> to log into each one.

                                                                                                                                                        https://gist.lema.org/santiago/6384991f0ad447cca4327af6935e469c

                                                                                                                                                          ...
                                                                                                                                                          0 ★ 0 ↺

                                                                                                                                                          [?]MadaMada »
                                                                                                                                                          @madamada@snac.void.my

                                                                                                                                                          @santi@gone.lema.org I normally have sshd and cron(selectively) turned off in my jail(s) by default..unless I need them for some reason..

                                                                                                                                                            ...

                                                                                                                                                            [?]Santiago, né ? :amiga: 👾 »
                                                                                                                                                            @santi@gone.lema.org

                                                                                                                                                            @madamada Yeah it’s not necessary most of the time unless you have to give access to someone who doesn’t also own the host machine.

                                                                                                                                                            It’s one case where the default influenced my behavior. My default LXCs in proxmox come with sshd by default and jails did not so I adapted.

                                                                                                                                                            In my case all VMs are in a VLAN at home and only the remote frontend can hit them with http(s) via a tunnel so having a ssh service or not doesn’t matter much as it’s not reachable from the outside.

                                                                                                                                                            🗳
                                                                                                                                                            #ipv6 boosted

                                                                                                                                                            [?]Edwin G. Spooks 👻 🍁 »
                                                                                                                                                            @EdwinG@mstdn.moimeme.ca

                                                                                                                                                            I’m going to be running an experiment… I’ll turn off the archaic IPv4 stack on my home network.

                                                                                                                                                            No NAT64.

                                                                                                                                                            How long will I last?
                                                                                                                                                            - - -
                                                                                                                                                            Je vais faire une petite expérience… je vais désactiver l’archaïque pile IPv4 sur mon réseau domestique.

                                                                                                                                                            Pas de NAT64!

                                                                                                                                                            Combien de temps je vais l’endurer?

                                                                                                                                                            <1 day/jour:0
                                                                                                                                                            1 day/jour – 1 week/semaine:0
                                                                                                                                                            1-2 weeks/semaines:0
                                                                                                                                                            >2 weeks/semaines:0
                                                                                                                                                              ...
                                                                                                                                                              #ipv6 boosted

                                                                                                                                                              [?]Edwin G. Spooks 👻 🍁 »
                                                                                                                                                              @EdwinG@mstdn.moimeme.ca

                                                                                                                                                              So, the answer: 1 day and 8 minutes.

                                                                                                                                                              Things got progressively worse as the day went on. This morning, I still had bidirectional messaging (SMS/MMS). Now, I can only receive messages, not send any (mobile service is unreliable at my place).

                                                                                                                                                              Also, I don’t have email anymore.
                                                                                                                                                              - - -
                                                                                                                                                              Donc, la réponse: 1 jour et 8 minutes.

                                                                                                                                                              Ça s’est détérioré au cours de la journée. Ce matin, j’avais encore les textos bidirectionnels. Maintenant, je ne pense que les recevoir, pas en envoyer.

                                                                                                                                                                ...
                                                                                                                                                                #ipv6 boosted

                                                                                                                                                                [?]Edwin G. Spooks 👻 🍁 »
                                                                                                                                                                @EdwinG@mstdn.moimeme.ca

                                                                                                                                                                I will note that some news services like CBC are unavailable unless you know French.

                                                                                                                                                                It felt zen not to read news 😁
                                                                                                                                                                - - -
                                                                                                                                                                Je noterai que certains services de nouvelles comme Radio-Canada étaient indisponibles à moins de connaître le français.

                                                                                                                                                                C’était très zen de ne pas lire l’actualité 😁

                                                                                                                                                                  ...

                                                                                                                                                                  [?]Miyuru Sankalpa »
                                                                                                                                                                  @miyuru@ipv6.social

                                                                                                                                                                  ...
                                                                                                                                                                  1 ★ 0 ↺

                                                                                                                                                                  [?]MadaMada »
                                                                                                                                                                  @madamada@snac.void.my

                                                                                                                                                                  @miyuru@ipv6.social Hm..looks interesting..I will have to try this out :>

                                                                                                                                                                  So this binds to [::]:53 ? I would like to use this along side Unbound if possible..

                                                                                                                                                                    ...

                                                                                                                                                                    [?]Miyuru Sankalpa »
                                                                                                                                                                    @miyuru@ipv6.social

                                                                                                                                                                    @madamada you can, set self_resolver and self_port to what ever you like.

                                                                                                                                                                      #freebsd boosted

                                                                                                                                                                      [?]Walter »
                                                                                                                                                                      @glassnerves@mastodon.sdf.org

                                                                                                                                                                      I don’t usually promote personal projects here, but I’ll give it a try.
                                                                                                                                                                      Meet Tocaia, a minimalist, cross-platform TUI Gopher client written in C89 for POSIX systems.
                                                                                                                                                                      It even supports Haiku.
                                                                                                                                                                      Pull requests and bug reports are welcome! =)
                                                                                                                                                                      github.com/manipuladordedados/

                                                                                                                                                                        ...
                                                                                                                                                                        1 ★ 0 ↺

                                                                                                                                                                        [?]MadaMada »
                                                                                                                                                                        @madamada@snac.void.my

                                                                                                                                                                        @glassnerves@mastodon.sdf.org Does it support gemini:// ?

                                                                                                                                                                          ...
                                                                                                                                                                          #freebsd boosted

                                                                                                                                                                          [?]xinqu »
                                                                                                                                                                          @xinqu@mastodon.bsd.cafe

                                                                                                                                                                          Short on Laptops story
                                                                                                                                                                          T15: Don't

                                                                                                                                                                          You know, I really like . I also appreciate the efforts and progress that is currently made. But it felt like installing on most Laptops in the early 90s. There's a lot we can learn from when it comes to this.

                                                                                                                                                                            ...

                                                                                                                                                                            [?]EF »
                                                                                                                                                                            @EF@mastodon.bsd.cafe

                                                                                                                                                                            @xinqu it would be helpful if it was explain why not and what were the problems encountered.

                                                                                                                                                                              ...
                                                                                                                                                                              #freebsd boosted

                                                                                                                                                                              [?]xinqu »
                                                                                                                                                                              @xinqu@mastodon.bsd.cafe

                                                                                                                                                                              @EF Of course, and I really wish I had more time for that. But at the moment, I need a laptop that "just works" so I didn't spend much time troubleshooting.

                                                                                                                                                                              What I remember: WiFi works, but only occasionally - one time the WiFi-Interface is "UP" but has "no link" (according to dhclient). After the next reboot, everything is fine.

                                                                                                                                                                              X works (I tried to no-Wayland variant)! But when I close the lid and open it again, the Laptop is 'bricked' Blank screen, does not react to anything (CTRL-ALT-Fx e.g.). This was the main reason I gave up.

                                                                                                                                                                              I choose xfce: No battery indicator, no backlight control (although the cli command `backlight` worked!). Maybe there were just a few xfce-packages missing - but I had no experience with xfce so I didn't know where to look for solutions.

                                                                                                                                                                              I'll buy the same laptop again soon, because I can get them very inexpensive at the moment and it works perfectly with Fedora. Then I have a backup and I can try again with

                                                                                                                                                                                ...
                                                                                                                                                                                0 ★ 0 ↺

                                                                                                                                                                                [?]MadaMada »
                                                                                                                                                                                @madamada@snac.void.my

                                                                                                                                                                                @xinqu@bsd.cafe @EF@bsd.cafe FreeBSD is late to the game in laptop support.. had FreeBSD focused on it in the 90's like Linux did, it would be close to or on par with Linux in laptop support..

                                                                                                                                                                                The FreeBSD Foundation has allocated efforts to improve this now, so time will tell..

                                                                                                                                                                                I'll probably wait for the next 2-3 years and come back to check on things again.. Until then, I'll stick to what I use now or I'll probably just install some flavor of Linux and be done..

                                                                                                                                                                                  #freebsd boosted

                                                                                                                                                                                  [?]Joel Carnat ♑ 🤪 »
                                                                                                                                                                                  @joel@gts.tumfatig.net

                                                                                                                                                                                  FreeBSD tiny shit post, because hey! [SENSITIVE CONTENT]

                                                                                                                                                                                  So as a "normal" #FreeBSD user, you can't run pw user mod -s /usr/local/bin/bash yourself but you can chsh -s /usr/local/bin/bash yourself. I don't see the coherance here.
                                                                                                                                                                                  Yes, chpass is '+s' when pw is not. But I still have difficulty understanding -1- the reason for pw to exist when other commands already do and -2- why not applying the same kind of permission to both command(s set).

                                                                                                                                                                                  ...
                                                                                                                                                                                  0 ★ 0 ↺

                                                                                                                                                                                  [?]MadaMada »
                                                                                                                                                                                  @madamada@snac.void.my

                                                                                                                                                                                  FreeBSD tiny shit post, because hey! [SENSITIVE CONTENT]pw(8) is meant to be used by the superuser account, root in this case. chsh(1) can be used by root and a regular user, tho a regular user has limited usage of it..for example changing to use a different shell.

                                                                                                                                                                                  See man pw(8), chsh(1) for more details.

                                                                                                                                                                                    [?]Didier Legrand »
                                                                                                                                                                                    @dal@mastodon.bsd.cafe

                                                                                                                                                                                    OVH VPS is limited with only one IPv6 so I can't run FreeBSD jails with each an IPv6. Too sad.

                                                                                                                                                                                    Contabo VPS have an IPv6 /64 but I can't get it to work with FreeBSD (Linux works). Too sad.

                                                                                                                                                                                    I have to find a VPS provider with similar cost than OVH or Contabo which works with FreeBSD.

                                                                                                                                                                                    ...

                                                                                                                                                                                    [?]Stefano Marinelli »
                                                                                                                                                                                    @stefano@mastodon.bsd.cafe

                                                                                                                                                                                    @dal the only one I'm aware of (and has similar prices) is Hetzner.

                                                                                                                                                                                      ...

                                                                                                                                                                                      [?]Didier Legrand »
                                                                                                                                                                                      @dal@mastodon.bsd.cafe

                                                                                                                                                                                      @stefano Thank you. I'll look at what they offer.

                                                                                                                                                                                        0 ★ 0 ↺

                                                                                                                                                                                        [?]MadaMada »
                                                                                                                                                                                        @madamada@snac.void.my

                                                                                                                                                                                        Or split the /64 into 2 /72's, the latter 00ff::/72 you could assign to the bridge interface connecting the epair's.

                                                                                                                                                                                          ...

                                                                                                                                                                                          [?]Didier Legrand »
                                                                                                                                                                                          @dal@mastodon.bsd.cafe

                                                                                                                                                                                          @madamada Currently without any jail, IPv6/64 on Contabo VPS does not work with default router address in /etc/rc.conf: ipv6_defaultrouter="fe80::1%vtnet0"
                                                                                                                                                                                          (See forums.freebsd.org/threads/can for further information)

                                                                                                                                                                                            0 ★ 0 ↺

                                                                                                                                                                                            [?]MadaMada »
                                                                                                                                                                                            @madamada@snac.void.my

                                                                                                                                                                                            @delta@chaos.social Hey, check this out.. the foreground text color is the same as the background :


                                                                                                                                                                                            v2.10.0 Desktop = Windows 10

                                                                                                                                                                                              History

                                                                                                                                                                                              Back to top - More...