• 1 Post
  • 453 Comments
Joined 2 years ago
cake
Cake day: August 8th, 2023

help-circle




  • I had a double NAT setup like that. Run a firewall like OPNSense as a Proxmox VM, and give it a WAN interface on the ISP router’s IP range; then run everything else on a different subnet, using OPNSense as the gateway. On the ISP router, put OPNSense’s WAN IP in the DMZ. Then, do all your hardening using OPNSense’s firewall rules. Bonus points for setting up a VLAN on a physical switch to isolate the connection.

    The ISP router will send everything to OPNSense’s WAN IP, and it will basically bypass the whole double NAT situation.











  • They spent the last X election cycles pushing back against the sky is falling hyperbole every time a new administration came to power. They’re used to brushing this off. They are following their programming.

    Meanwhile the whole time we were raping and pillaging the world (like actually, literally) and they pretended we weren’t the bad guys on the news and in the books.

    They haven’t snapped out of it yet. They won’t until the pumps run dry and the grocery shelves sit empty, and then they’ll wonder how it got this bad.