this post was submitted on 30 Mar 2025
-33 points (17.6% liked)

Selfhosted

45382 readers
388 users here now

A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.

Rules:

  1. Be civil: we're here to support and learn from one another. Insults won't be tolerated. Flame wars are frowned upon.

  2. No spam posting.

  3. Posts have to be centered around self-hosting. There are other communities for discussing hardware or home computing. If it's not obvious why your post topic revolves around selfhosting, please include details to make it clear.

  4. Don't duplicate the full text of your blog or github here. Just post the link for folks to click.

  5. Submission headline should match the article title (don’t cherry-pick information from the title to fit your agenda).

  6. No trolling.

Resources:

Any issues on the community? Report it using the report flag.

Questions? DM the mods!

founded 2 years ago
MODERATORS
 

Public Service Announcement:

Have you checked out Sophos XG Firewall for home use lately?

It's basically an enterprise firewall fully licensed for personal use.

  • All the firewall stuff
  • Normal IPS
  • Built-In easy transparent SSL/TLS proxy
  • Web Application Firewall

I like it better than PF/Open Sense right now.

https://youtu.be/Ui8UC8-MeJU

top 6 comments
sorted by: hot top controversial new old
[–] starkzarn@infosec.pub 6 points 2 days ago (1 children)

They place arbitrary limits on home users as well, which is a secondary reason to not use it compared to open source offerings. For instance:

  • you are limited to 1Gbps line speed
  • you are limited to one week of analytics, with no export option, so you can't even ship them elsewhere
  • there are also resource limits that prevent ram and CPU utilization
[–] redfox@infosec.pub 0 points 1 day ago

This is true, the 6 GB RAM limit and four cores.

I run a pretty enterprise home lab, and I haven't ever seen the devices hit the resource limit.

I have around 3k IPS rules and TLS inspection for most categories of sites except the normal stuff like streaming, banking, etc that you'd not want or need to inspect.

For anyone it might help, I use these as inline proxies rather than as the gateway at the moment. So they have more than just internet traffic going through them, they also have segments of my LANs getting evaluated. Performance has been great so far.

[–] SirMaple__@lemmy.ca 23 points 3 days ago (1 children)

Nope. I'll stick with OPNsense which is open source.

[–] redfox@infosec.pub 0 points 1 day ago (1 children)

I like OPN also. I've always appreciated the stability of the BSDs.

My only personal complaint with OPN/PF was the TLS inspection.

I've read about adding the modules to *Sense, but I haven't figured out the configuration pieces.

It just works with Sophos UTM and XG firewall, and the configuration was super easy.

You always use what you like though.

What do you use TLS inspection for?

[–] Dran_Arcana@lemmy.world 8 points 3 days ago

Thank you for letting me know what software not to use; good bot