(Updated Video In Description) How To Setup ACME, Let's Encrypt, and HAProxy HTTPS on pfsense

  Рет қаралды 178,156

Lawrence Systems

Lawrence Systems

Күн бұрын

Updated Version of this video here:
• How To Guide For HAPro...
lawrence.video...
How To Guide For HAProxy and Let's Encrypt on pfSense: Detailed Steps for Setting Up Reverse Proxy
• How To Guide For HAPro...
Amazon Affiliate Store
➡️ www.amazon.com...
Gear we used on Kit (affiliate Links)
➡️ kit.co/lawrenc...
Try ITProTV free of charge and get 30% off!
➡️ go.itpro.tv/lts
Use OfferCode LTSERVICES to get 5% off your order at
➡️ lawrence.video...
Tesla Referral Program Offer
🚘 www.tesla.com/...
Lawrence Systems Shirts and Swag
👕 teespring.com/...
Digital Ocean Offer Code
➡️ m.do.co/c/85de...
HostiFi UniFi Cloud Hosting Service
➡️ hostifi.net/?v...
Protect you privacy with a VPN from Private Internet Access
➡️ www.privateint...
Google Fi Service Referral Code
📱g.co/fi/r/TA02XR
More Of Our Affiliates that help us out and can get you discounts!
➡️ www.lawrencesy...
Twitter
🐦 / tomlawrencetech
Patreon
🔗 / lawrencesystems
Our Forums
🔗 forums.lawrenc...
GitHub
🔗 github.com/law...
Discord
🔗 / discord
Our Web Site
🔗 www.lawrencesy...
www.haproxy.co...
Netgate Hangout Videos
Let's Encrypt on pfSense
• Let's Encrypt on pfSense
Server Load Balancing on pfSense 2.4
• Server Load Balancing ...
#pfsense #Firewalls

Пікірлер: 188
@LAWRENCESYSTEMS
@LAWRENCESYSTEMS 7 ай бұрын
Updated Video here kzbin.info/www/bejne/mIabZpedfbiVaKc
@jrtapley
@jrtapley 4 жыл бұрын
I’ve spent so many hours getting this running. This is a long overdue video. Thanks for making it!
@WapitiEater
@WapitiEater 2 жыл бұрын
Good help, thanks. PLT: Disable any existing NAT rules that may exist from previous efforts. Lost about half a day for I 'twigged on to that one. Once NAT was out of the way, this worked perfectly. Thanks!
@CookieStealer559
@CookieStealer559 Жыл бұрын
3 years later and this is still great! Thanks a lot!
@bdorr17
@bdorr17 4 жыл бұрын
Aside from pointing out the one config issue (maybe), Thanks for the video, this was absolutely useful and awesome and I love to not have to port forward and open up 80 just to let letsencrypt verify my cert. This is much more secure method and I really appreciate it
@kevinmiddleton6930
@kevinmiddleton6930 2 жыл бұрын
This video provided that "ah-ha" moment that I needed for my wildcard cert to work in haproxy. Now I can move away from my other load balancer / reverse proxy tool that I have been using and centralize on pfSense. Thank you!
@raymondfb
@raymondfb 2 жыл бұрын
great video, head still spinning a little. slick as snot when it gets up and runs. thank you again for taking the time to make your videos. learned so much.
@S3ANZ13
@S3ANZ13 2 жыл бұрын
You know the one bad thing about tutorials that start with things already set up? .... Me not checking the HAProxy "Settings" panel to see if it's even enabled.
@LAWRENCESYSTEMS
@LAWRENCESYSTEMS 2 жыл бұрын
It's always those little details.
@h1lari0
@h1lari0 Жыл бұрын
Increasing the maximum connections help as well. 😊
@heavy1metal
@heavy1metal 4 жыл бұрын
Instead of only using a default backend, you'd just create the ACL > action. Prevents people from just hitting your IP:PORT and successfully getting the service without the FQDN. Generally I would avoid a default backend going to a valid service. An example of a use case, is I'm currently using the default to redirect to a backend that redirects to a TCP frontend for non web-services. TCP front has its own ACL to match against, but you get the idea.
@BorisJohnsonMayor
@BorisJohnsonMayor Жыл бұрын
What about the default certificate for the frontend. It requires one, so is it a problem?
@vicoscugnizzo3154
@vicoscugnizzo3154 9 ай бұрын
Many thanks for many years of contributing to shape a generation of professionals and enthusiasts like me. Pls. do you mind if I make a humble request? IPv6 setups, same videos you made before but emphasizing IPv6 in many forms SLAAC, DHCPv6. Reckon you will be supporting this transition and untangle this complicated setup. I believe many people is avoiding afraid not be able to deliver with quality as the y do in IPv4. Much appreciated.
@Dorff_Meister
@Dorff_Meister 3 жыл бұрын
Thanks! I've been wanting to do this for a long time and now it's all working on my Netgate/pfSense. My biggest mistake in the process was not moving pfSense from 443 before enabling things. Doh.
@Dorff_Meister
@Dorff_Meister Жыл бұрын
I've just setup Nginx Proxy Manager (NPM) in a docker container, have it all working, and am in the process of copying the hosts from my HAProxy config (provided by pfsense) to NPM. I'm finding NPM a lot faster to add and manage the configuration. Hopefully I don't find issues or loss in functionality (I'll run the concurrently at least for a while).
@taylom1980
@taylom1980 3 жыл бұрын
This video is AWESOME! It totally helped me out with redirecting multiple subdomains to different ports on a single server. Thank you so much for showing me how to do this!
@MannyCastilloPage
@MannyCastilloPage 4 жыл бұрын
Didn't see your usual outro where you "and thank you for making it to the end of the video" :) thanks for this video
@LAWRENCESYSTEMS
@LAWRENCESYSTEMS 4 жыл бұрын
Oops, too late now
@memphis2k
@memphis2k 4 жыл бұрын
Great video. I was under the impression that this didn't expose port 443 to the internet. But it does. Still more secure than exposing an server I'm suspecting.
@daniellunateel
@daniellunateel 3 жыл бұрын
This video was super helpful but I really wish you had covered the firewall rules in some more depth. I was having a ton of trouble until I thought to change the firewall rule to allow access to LAN Net instead of to the firewall itself. Maybe this is super obvious to everyone else but I completely missed it for hours.
@michaelmauer1385
@michaelmauer1385 2 жыл бұрын
Thx, the additional certificates (frontend) was key in my search! Thank you
@zoey101dogwablog
@zoey101dogwablog 2 жыл бұрын
love the hl2 reference with nova prospekt
@AaronStuder
@AaronStuder 4 жыл бұрын
33:05 Don't you need to copy the "restart" at the end as well?
@deafno
@deafno 3 жыл бұрын
16:30 The certs in Backend / Server list are not required to get frontend HTTPS offloading to work. I beleive this is for validating backend SSL certs instead.
@CAHOP2401
@CAHOP2401 4 жыл бұрын
This is perfect. Been looking for a video like this
@furfoxsake
@furfoxsake 3 жыл бұрын
Awesome video, I was able to get it working for WAN connections. But for some reason when I try to connect from the LAN side, it redirects me to the pfSense login page. An thoughts on why this is happening?
@Jeancomputech
@Jeancomputech 2 жыл бұрын
Hi Tom i hope you are having a great Saturday. The question i have is do you have have to do port forwarding to the backend server or just added to the proxy backend?
@LAWRENCESYSTEMS
@LAWRENCESYSTEMS 2 жыл бұрын
No, you allow ports to HAProxy, not to the servers behind it.
@alpachino468
@alpachino468 Жыл бұрын
I wasn't able to get through the entire video yet. Is there any mention of how to stop people from outside your network accessing certain proxies? Basically, I don't want to let people outside my local network access TrueNAS.
@NT-zg2hj
@NT-zg2hj 4 жыл бұрын
Hi Lawerance, Hope your well. Thanks for the video. I have a NAS box which I would like to keep local. Would you mind doing another similar video but only for a local network (Private) Thanks
@EduardoReyesDPM
@EduardoReyesDPM 4 жыл бұрын
Literally working on this last night using cloudflare with dns mode.... Ty
@theshuz
@theshuz 4 жыл бұрын
I've used this on pfSense for years!!! Works great!!!👍
@benek9841
@benek9841 2 жыл бұрын
Hi Lawrence, great video as always. Yours videos inspired me to build my Pfsense router. Now I migrated my Nginx to HAproxy. Question: is there a way to do some basic authentication to some back end services?
@LAWRENCESYSTEMS
@LAWRENCESYSTEMS 2 жыл бұрын
Generally auth is taken care of by the app you are running
@Herkullainen
@Herkullainen 4 жыл бұрын
This, Jen, is the Internet.
@fonte935
@fonte935 4 жыл бұрын
Such a cool video, Tom. It's taken me more than a few views to digest it all, and now I am trying it on my server. We'll see how it goes! :)
@alphabanks
@alphabanks 4 жыл бұрын
This was an amazing video however I would like to see more advanced topics such as load balancing. I would also be interested in seeing if HA Proxy can do pre authentication using local passwords on PF or against Active Directory.
@superzeiberman9811
@superzeiberman9811 3 жыл бұрын
Who gives a thumb down for this video? It's a very infomative video and nice structured!
@johnglennan2153
@johnglennan2153 2 жыл бұрын
I'm getting DNS rebinding attack detected after setting up the HA-Proxy Part then testing the domain I registered. (EDIT) I ended up solving this by enabling HA Proxy. Sorry for this comment awesome video. You rock! Also do you need open vpn still if you use HA Proxy?
@LAWRENCESYSTEMS
@LAWRENCESYSTEMS 2 жыл бұрын
Putting things behind a VPN is a more secure method.
@rnovachkov
@rnovachkov 2 жыл бұрын
PLEASE make a video how to setup pfsense with haproxy and synology behind with all the services working.
@stefanmilev1
@stefanmilev1 4 жыл бұрын
Great video Lawrence, I always wanted to setup something like this on my pfsense server as I was annoyed with the certificate message popping up all the time. Now using your guide I will try to set it up and make mi network a bit better.
@misckicirina
@misckicirina 2 жыл бұрын
Great tutorial, thank you. I followed it and HA Proxy works in my PfSense but unfortunately only if I disable pfBlockerNG and DNSBL. Maybe this is caused by the two NAT rules created by pfBlockerNG that forward ports 80 and 443 to 8081 and 8443, respectively. Is there any way to get HA Proxy working with pfBlockerNG enabled? Or should I replace pfBlockerNG with Pinhole?
@godyK
@godyK 2 жыл бұрын
I Have followed the video but I am having one problem whenever I try to access the sites I get redirected to the HAProxy stats page on all the domains
@conrat2000
@conrat2000 2 жыл бұрын
Thank you so much!
@georgelza
@georgelza Жыл бұрын
... hi hi. I have my pfSense setup current to work with CloudFlare and using a lets encrypt cert. due to various reasons I need to change my domain. I already bought the new domain from Google and already created/added it to my CF profile and updated the domain on google's side to use the CF NS's. know this is prob a bit of the beaten track, but any chance you can do a video... showing whats additional to be added or changed to accommodate this use case.
@udbytossen
@udbytossen 3 жыл бұрын
Hi Lawrense system. Great Video - Although I want to use this before our Company Webserver - but how about getting the tracking information. I located a option under frontend - "Use forwardfor" option, for statestic etc on websites - But this guide works fine, and adding this option stills shows the client IP as 192.168.1.1 (PFsense) - so how can I make my marketingguy happy :-) Keep them Videos Coming - like the late evenings with those!
@manutech156
@manutech156 3 жыл бұрын
Are you going to do a video on how to setup Dynamic DNS with digitalOcean and pfSense?
@annoyedbybrother
@annoyedbybrother 2 жыл бұрын
If you are using cloudflair you need to make sure you set Your SSL/TLS encryption mode to "Full". this is under Domian > SSL/TLS > Overview
@saywhat9158
@saywhat9158 4 жыл бұрын
Great timing ... thanks for this info. Now, if pfsense would unify the Captive Portal login/logout window like Opnsense instead of using an archaic method of popup windows that most browsers disable by default due to security issues, then I might actually purchase a licensed Netgate box from them when I upgrade for hardware AES support.
@whatevah666
@whatevah666 3 жыл бұрын
awsome vid, thanks. small nitpicking, you don HAVE TO have a default backend as stated in the fw "If a backend is selected with actions above or in other shared frontends, no default is needed and this can be left to "None"." I prefer not having a default backend in case of scanners etc, that way you don't "leak" info via certificated and such, it just seems better to me :)
@BorisJohnsonMayor
@BorisJohnsonMayor Жыл бұрын
What about the default certificate for the frontend. It requires one, so is it a problem?
@manmustbuild
@manmustbuild 2 жыл бұрын
I've got my front end set to listen on LAN address. Prefer to get that working before I open up the WAN ports. pfsense has a valid ACME wildcard cert and the subdomain resolves and that's all working great. But whenever I try to turn on HAProxy and route to a different internal server, I lose access to the pfsense webGUI.
@LAWRENCESYSTEMS
@LAWRENCESYSTEMS 2 жыл бұрын
Put the Web UI on a different port.
@moondawson2165
@moondawson2165 2 жыл бұрын
Hi Tom, which of digitalocean solutions supports let's encrypt?
@LAWRENCESYSTEMS
@LAWRENCESYSTEMS 2 жыл бұрын
They do have DNS challenge response
@bdorr17
@bdorr17 4 жыл бұрын
Hey, it looks like the correct command would be /usr/local/etc/rc.d/haproxy.sh restart which I think you left out. Just want to confirm that
@LAWRENCESYSTEMS
@LAWRENCESYSTEMS 4 жыл бұрын
Do it's in the documentation not what I say..lol
@bdorr17
@bdorr17 4 жыл бұрын
@@LAWRENCESYSTEMS lol no issues, just in case you use that function though, might want to double check
@ranjithgreen
@ranjithgreen 3 жыл бұрын
Thank you for wonderfully video, i am facing issue i want to use my domain without 'www' i tried but not resolved and shows (503 Service Unavailable No server is available to handle this request.) i need help in this with Haproxy and domain configuration, once again thank you
@NoRogeR
@NoRogeR 3 жыл бұрын
Great video 👍 I would suggest to turn on xforwardedfor as well to reveal real ips to backends
@androbourne
@androbourne 2 жыл бұрын
If you are using certs locally on the host do you still need SSL Offloading? How can that be done without needing 2 certs? Aka cert from PFSense and locally issused cert from Lets Encrypt on local server? I basically just want HAProxy to pass whatever cert is already assigned on the server its self. I don't want HAProxy to manage any certs.
@LAWRENCESYSTEMS
@LAWRENCESYSTEMS 2 жыл бұрын
There might be a way to do that, but I made the tutorial based on the more common way people use it which is having HAProxy handle the certs.
@ramikilany9279
@ramikilany9279 4 жыл бұрын
About the Pure NAT it is not working with me, I did the same configuration but the internal IP does not open the WAN IP, where is the problem in your opinion? Best Regards
@ChrisVogtmann
@ChrisVogtmann 3 жыл бұрын
Are there firewall rules that need to be setup? I have a mail server on the LAN and tried to follow this to add a cert so I could have it behind an ssl but port 80 still works fine but when I go to 443 I get PR_CONNECT_RESET_ERROR When I run the terminal command, it shows it sending the cert for my domain set up in acme Any Ideas?
@emilianocaballero7013
@emilianocaballero7013 Жыл бұрын
Just making sure, can this be used to provide a let's encrypt certificate to an internal PBX server such as FreePBX?
@LAWRENCESYSTEMS
@LAWRENCESYSTEMS Жыл бұрын
It should work for the web interface.
@VioletDragonsProjects
@VioletDragonsProjects 4 жыл бұрын
ive finally got this working on two domains. Cloud and Web Server behind two domains i now have to setup mail. but there is some differences in my lab than in this video. You didnt mention about VIP/Virtual IPs it will work without it just wont be able to have this setup internally only externally but yeah it works took some setting up to do. Web Servers requires some tweaking for http to https redirection Wordpress Servers on the other hand requires a lot of tweaking or web site is broken i.e layout.
@house0795
@house0795 Жыл бұрын
Can I set reverse proxy but only for local use not open to internet with haproxy ?
@fbifido2
@fbifido2 4 жыл бұрын
Would a wildcard domain certificate using ACME DNS auth, work in these case as seen in your video?
@manthing1467
@manthing1467 4 жыл бұрын
I am trying that right now but ive been dealing with 503 errors w the SSL going through.
@garrettdengler7599
@garrettdengler7599 3 жыл бұрын
If I’m using a UniFi router, would this still work for me if I set up a pfsense box internally? Or would there be a better solution for that scenario?
@LAWRENCESYSTEMS
@LAWRENCESYSTEMS 3 жыл бұрын
It would add more complexity that just replacing the UnFi router.
@garrettdengler7599
@garrettdengler7599 3 жыл бұрын
@@LAWRENCESYSTEMS Bummer. I can't justify replacing the udm-pro so I'll have to dig around for a different solution. Great video though. Thanks!
@faizmustofa6369
@faizmustofa6369 2 жыл бұрын
what that all domain is private network ? or public
@simonlock9718
@simonlock9718 4 жыл бұрын
Hi Lawrence. Please could you make a video showing how to use haproxy (HTTPS) for local only servers. E.g. FreeNAS. I have several local only servers and each are configured using certbot to obtain their own certificates (cloudflare dns challenge). I know that you hinted at NAT reflection / Pure NAT but I simply cannot get this to work. Thanks
@LAWRENCESYSTEMS
@LAWRENCESYSTEMS 4 жыл бұрын
Already did kzbin.info/www/bejne/oKHchqBraNyYY7s
@simonlock9718
@simonlock9718 4 жыл бұрын
Thank you Lawrence. I had to use a VIP to get it working.@@LAWRENCESYSTEMS
@Tom-jo8fu
@Tom-jo8fu 8 ай бұрын
How to setup cloudflare localdns? I received constant an ssl error.
@homeassistantiptv8068
@homeassistantiptv8068 3 жыл бұрын
my haProxy has stopped working as soon as i configured LAGG - haproxy sites now only work via WAN and not on the LAN.. WOuld anyone be able to point me in the right direction?
@jeremyrangel8138
@jeremyrangel8138 3 жыл бұрын
is this the same process we could use if we wanted multiple web servers with only one public IP address?
@MrBaracas
@MrBaracas 3 жыл бұрын
Would this work for those origin certs that cloudflare trys like heck to get its people to use?
@RichardBuckerCodes
@RichardBuckerCodes 4 жыл бұрын
what about backend machines that need to generate valid certs
@jim7smith
@jim7smith 3 жыл бұрын
What software are you using at the beginning with the image of the network?
@Sladeofdark
@Sladeofdark 4 жыл бұрын
fuuuuuuuuuuuu...ck. will i ever understand certificates? why am i so facinated with this mess lol. Awesome content sir!
@chris11d7
@chris11d7 3 жыл бұрын
it's like in middle school when you create a secret language with your friends. you and your friends know how to interpret what you're saying because they have the legend, and in order for anyone else to understand, they also need the legend. You distribute the legend to only people who are allowed to know what you are saying. The CA (certificate authority) verifies my identity to make sure I'm not pretending to be someone else.
@ranjithgreen
@ranjithgreen 3 жыл бұрын
i need help in this with Haproxy redirect non-www domains to their www variant once again thank you
@charlie7975
@charlie7975 4 жыл бұрын
Great video. All of yours are great. I want to make sure WAN traffic to my pfSense login and a couple other web servers gets blocked so access is only local/VPN. Can you point me in the right direction?
@LAWRENCESYSTEMS
@LAWRENCESYSTEMS 4 жыл бұрын
the pfsense web configuration page is blocked on WAN by deafult.
@kapurar
@kapurar 2 жыл бұрын
Great video!
@FTLN
@FTLN 2 жыл бұрын
Hi Lawrence, I have a standalone PFSENSE in the cloud with one wan interface, one OPENVPN interface and One IPSEC interface, can you confirm from which interface is used by HA proxy to proxy the request ?
@LAWRENCESYSTEMS
@LAWRENCESYSTEMS 2 жыл бұрын
I have never tried that setup.
@FTLN
@FTLN 2 жыл бұрын
@@LAWRENCESYSTEMS Thanks, but from which interface does HA proxy forward traffic?
@Gillis785
@Gillis785 4 жыл бұрын
Hi there just wondering if there is something you need to add in your nginx conf file to make this work. It works fine when running apache but I get error 503 Service Unavailable when running nginx. Thank you.
@weismichael
@weismichael 4 жыл бұрын
thanks for the video, as ur a professional for unifi products, u can maybe tell me, how to make unifi nvr get working through haproxy. the ui is running on port 7443, but it also needs port 7446 for the video stream. i am not able to get it running. maybe u have an advice.
@gt_masterman
@gt_masterman Жыл бұрын
why exactly is it a bad idea to expose your NAS? wouldn't this be one of the applications as it lets me access my files from anywhere? and since the NAS has its own login, there shouldn't be any way to access data if you aren't authorized right?
@LAWRENCESYSTEMS
@LAWRENCESYSTEMS Жыл бұрын
In theory yes, in reality if there is a security flaw, which has happened many times, then others can access your files, delete them, or encrypt them and charge a ransom.
@vasquezmi
@vasquezmi Жыл бұрын
How are you able to passthrough your public IP to the WAN interface? What I see on the front end is the same public IP that you set in Digital Ocean. For me I only see the IP assigned by my cable modem. Is there an option to set that or pass it through?
@LAWRENCESYSTEMS
@LAWRENCESYSTEMS Жыл бұрын
I think what you are looking for is In the back end settings "Use Client-IP to connect to backend servers."
@vasquezmi
@vasquezmi Жыл бұрын
@@LAWRENCESYSTEMS I think I understand now as I look through the steps. I have a BYOD cable modem that is set to router mode. I believe I need to set it to Bridge mode in order to have the public IP passthrough to the pfSense....or use like you said the Client-IP / 1:1 NAT options that are available.
@Napert
@Napert Жыл бұрын
Where can I find a tutorial for this but with cloudflare and without exposing to public internet?
@LAWRENCESYSTEMS
@LAWRENCESYSTEMS Жыл бұрын
If you are talking about Cloudflare tunnels, that does expose it to the public internet.
@WebbedPete
@WebbedPete 3 жыл бұрын
KEY item missing: to do this on the LAN side, in System->Advanced, set a different TCP port, AND check "Disable webConfigurator redirect rule" Then HAproxy can listen to 443 on the LAN side of pfSense.
@mattparksey
@mattparksey 3 жыл бұрын
Ever tried setting up authelia for 2fa, HaProxy on PFsense?
@LAWRENCESYSTEMS
@LAWRENCESYSTEMS 3 жыл бұрын
Nope
@mattparksey
@mattparksey 3 жыл бұрын
@@LAWRENCESYSTEMS Hmm looks like it works well with Traefik
@tac73
@tac73 3 жыл бұрын
I've got to be honest here. The only thing I know for sure that I've learned is, that your speech is way faster than my brain can process. I've replayed segments over and over, til I'm just worn out. I hope I don't lose interest before it all sinks in! :-)
@LAWRENCESYSTEMS
@LAWRENCESYSTEMS 3 жыл бұрын
Use the KZbin slow speed playback option
@tac73
@tac73 3 жыл бұрын
@@LAWRENCESYSTEMS That's actually a very good idea! Thanks Tom!
@nanabkgyasi
@nanabkgyasi 2 жыл бұрын
Hey Lawrence. Is there a way for me to edit the haproxy config file? My nginx is failing to start because the ssl certificate is not where it expects it although hapxy/acme is issuing it successfully.
@LAWRENCESYSTEMS
@LAWRENCESYSTEMS 2 жыл бұрын
Not something I have tested
@frankihk
@frankihk 4 жыл бұрын
hi Lawrence, how to setup snort protection for each sub domain or acl
@rkbest9783
@rkbest9783 2 жыл бұрын
So, I can use just the back-end without the front-end linked if I just want to use alias for local access instead of IP and still not exposing the service to outside world? Your tut is for all services can be accesses from outside world!
@LAWRENCESYSTEMS
@LAWRENCESYSTEMS 2 жыл бұрын
No, you just tie the front end to an internal IP.
@rkbest9783
@rkbest9783 2 жыл бұрын
@@LAWRENCESYSTEMS thanks, will give it a try.
@rkbest9783
@rkbest9783 2 жыл бұрын
@@LAWRENCESYSTEMS How will the certificate setup be different in HAProxy in such a case. As we wont have a domain linked to it. do we still need to provide a Domain SAN list entry (a domain box exist in there)
@pdoughertyfamily
@pdoughertyfamily Жыл бұрын
I purchased a domain at Namecheap and then tried to activate the api to do the items described in your video. It let me use test in a sandbox but when I tried to go live it said my account was too small to use the api. Any suggestions for a free/super cheap registrar and dns host for a home/lab user? - Thanks.
@pdoughertyfamily
@pdoughertyfamily Жыл бұрын
Update. After an appeal to support and an explanation of what I was using this for, they activated my key.
@PhrozenN
@PhrozenN 4 жыл бұрын
How the hell did you get your terminal looking like that? Thx for the great tutorials :)
@chwaee
@chwaee 4 жыл бұрын
parrot OS
@PhrozenN
@PhrozenN 4 жыл бұрын
@@chwaee what? No. That's pop os
@lepsycho3691
@lepsycho3691 4 жыл бұрын
He asked for the terminal not the distro. If i'm not mistaking this is zsh and you can use it on any distro.
@danielday8828
@danielday8828 4 жыл бұрын
Was wondering if you could elaborate on doing a redirect rule from http to https?
@latenyt7dusk231
@latenyt7dusk231 2 жыл бұрын
If i run PFsense on a vm with haproxy and the webhosts are on the same subnet of PFsense will it work?
@LAWRENCESYSTEMS
@LAWRENCESYSTEMS 2 жыл бұрын
I don't understand the question.
@masterhinz
@masterhinz 3 жыл бұрын
That was so helpfull. Thanks a lot for this great video!
@zyxwvutsrqponmlkh
@zyxwvutsrqponmlkh 4 жыл бұрын
Acme services are not listed in my pfsense, is this not available in community edition?
@LAWRENCESYSTEMS
@LAWRENCESYSTEMS 4 жыл бұрын
You add it via the package manger
@codochi
@codochi 4 жыл бұрын
Hi~ How to configure synology + directadmin same port 443? I tried but it only run synology.
@koenpauwels98
@koenpauwels98 3 жыл бұрын
Great tutorial, sometimes its a little bit over my head.. im not really an IT guy, but i wanted to achieve this. So some stuff you just assume you should know :D but i dont
@royhall4649
@royhall4649 4 жыл бұрын
I have followed this step by step, but none of my web servers are working...
@AntonKristensen
@AntonKristensen 4 жыл бұрын
Any chance you have or could make a video showing how to do this with tls / https mode, to route to servers depending on the certificates sni over tls/https and not the http/https you have there. Best regards!
@LAWRENCESYSTEMS
@LAWRENCESYSTEMS 4 жыл бұрын
Just change the mode, it's a settings option.
@pixel9119
@pixel9119 3 жыл бұрын
what do I have to put in my txt record on the dns server?
@3DProphet
@3DProphet 4 жыл бұрын
Why is NOIP not in the domain scan list method? I have a paid domain there :/
@blainej07
@blainej07 4 жыл бұрын
Hey Tom, have you considered making a Nextcloud VS FileCloud video? Would you consider it? Been hearing a lot about FileCloud lately...
@LAWRENCESYSTEMS
@LAWRENCESYSTEMS 4 жыл бұрын
FileCloud is not open source, NextCloud is
@blainej07
@blainej07 4 жыл бұрын
$10/year to selfhost but good call, good call. Gonna spin it up and give it a whirl for fun though :-)
@frankihk
@frankihk 4 жыл бұрын
it is possible deploy with openvpn?
@joeroback4726
@joeroback4726 4 жыл бұрын
what about renewal? when cert renewal happens, does HAProxy get automatically restarted?
@LAWRENCESYSTEMS
@LAWRENCESYSTEMS 4 жыл бұрын
You have to enable that feature, that's covered towards the end of the video
4 жыл бұрын
One of the best out there how you should enplane for a newbie that have hard time to see the connections for functions. you doing well for add extra information in some impotent points. I have a wish do. Certificate is a brain eater for me to get everything together what exactly every type of file doing and are fore. Some common words when talking certificate. Ca ? Root ? Public cert ? chain ? Generate self sign cert? x509? Validation ? Best way to storing Certificate, root,cert,ca or what they are? Key ?? This is weird thing to understand. sometimes there is Key file with certificate. Dose the Country Code,location,Email Address, city...... importen/or dangerous in some way?
@sicanu1981
@sicanu1981 3 жыл бұрын
Hi Tom Please help me out it's not working for me !
@THEGURU1234556
@THEGURU1234556 3 жыл бұрын
does not work here as well
@BobSmith-wu2ll
@BobSmith-wu2ll 4 жыл бұрын
I've followed the tutorial and everything is working until my ISP changes my IP address. I'm using the Dynamic DNS Service in pfSense to update my IP with Namecheap. But that's not getting over to DO to change the IP in the A Records. I haven't figured out how to use Dynamic DNS to work with DO's A Records. Any advice?
@eldaria
@eldaria 4 жыл бұрын
Not sure what you mean by DNS, but if you mean the inbound rules, then you can pick "This Firewall"
@pdoughertyfamily
@pdoughertyfamily Жыл бұрын
I'm a new user at namecheap when I try to use the api they say I need a higher account balance or $20 in domains for the last two years. Did you see the same thing? - Thanks
@mohsinhassan88
@mohsinhassan88 4 жыл бұрын
Great Video, I have been searching for a video like this forever as i was trying to set this up for myself. i have been watching your videos for a long time and am a huge fan. I do have a comment about the flow of the video, while i was able to understand what you were talking about since i spent a long time reading up on this topic, i feel compared to your previous video on other topics (which are excellent as a follow along and very well structured even for someone completely new) I feel this was not as well structured. I mean the content excellent, it just need a bit more introduction and preface before you got into the meat of things. More along the lines, why one would need this, what alternatives are available out there. Most of your videos before you get started with the topic you explain what the topic is, what alternatives are available (which i love because then i can go out and read up on those topics as well and is a great way of learning new things. Maybe do another video just talking about those points before we start watching this video. Nonetheless this is an excellent video. keep it up.
😜 #aminkavitaminka #aminokka #аминкавитаминка
00:14
Аминка Витаминка
Рет қаралды 919 М.
How it feels when u walk through first class
00:52
Adam W
Рет қаралды 21 МЛН
Good teacher wows kids with practical examples #shorts
00:32
I migliori trucchetti di Fabiosa
Рет қаралды 12 МЛН
pfSense Configuration Guide - Zero to Hero!
1:26:20
Jim's Garage
Рет қаралды 10 М.
HAProxy Crash Course (TLS 1.3, HTTPS, HTTP/2 and more)
1:12:19
Hussein Nasser
Рет қаралды 136 М.
HTTPS, SSL, TLS & Certificate Authority Explained
43:29
Laith Academy
Рет қаралды 121 М.
pfsense HA Proxy Troubleshooting
14:22
Lawrence Systems
Рет қаралды 33 М.
TCP/IP for Programmers
3:03:31
Eli the Computer Guy
Рет қаралды 183 М.
MP3 CDs: a hybrid "format" that never existed, yet was surprisingly common
34:18
Technology Connections
Рет қаралды 195 М.
pfsense + HAProxy + Let's Encrypt Howto
25:04
SystemaD
Рет қаралды 21 М.
😜 #aminkavitaminka #aminokka #аминкавитаминка
00:14
Аминка Витаминка
Рет қаралды 919 М.