<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Guide on Andrew's Memory Blog</title><link>https://andrewmemory.acornwall.net/tags/guide/</link><description>Recent content in Guide on Andrew's Memory Blog</description><generator>Hugo -- gohugo.io</generator><image><url>https://andrewmemory.acornwall.net/img/rss_image.png</url><title>Guide on Andrew's Memory Blog</title><link>https://andrewmemory.acornwall.net/</link></image><language>en</language><managingEditor>andrewmemoryblog@gmail.com (Andrew's Memory Blog)</managingEditor><webMaster>andrewmemoryblog@gmail.com (Andrew's Memory Blog)</webMaster><copyright>Copyright 2009--2025</copyright><lastBuildDate>Sun, 15 Oct 2023 23:59:39 -0700</lastBuildDate><atom:link href="https://andrewmemory.acornwall.net/tags/guide/index.xml" rel="self" type="application/rss+xml"/><item><title>Setting up an OpenBSD 7.4 Firewall Device</title><link>https://andrewmemory.acornwall.net/blog/2023-10-15-setting-up-an-openbsd-7-4-firewall-device/</link><pubDate>Sun, 15 Oct 2023 23:59:39 -0700</pubDate><author>andrewmemoryblog@gmail.com (Andrew's Memory Blog)</author><guid>https://andrewmemory.acornwall.net/blog/2023-10-15-setting-up-an-openbsd-7-4-firewall-device/</guid><description>&lt;p&gt;My &lt;a href="https://www.pcengines.ch/alix.htm" target="_blank" rel="noreferrer"&gt;PC Engines ALIX&lt;/a&gt; running the (mumble) version of OpenBSD has been a great firewall. But now that it looks like PC Engines is &lt;a href="https://www.pcengines.ch/eol.htm" target="_blank" rel="noreferrer"&gt;wrapping up&lt;/a&gt;, it&amp;rsquo;s time to find something new. For a while I&amp;rsquo;ve suspected that the ALIX is a little underpowered. It&amp;rsquo;s harder to find 4G CF cards these days. Plus I want something with a HDMI port so I can put it on a KVM switch and don&amp;rsquo;t need to worry about serial port speeds.&lt;/p&gt;
&lt;figure&gt;&lt;img
class="my-0 rounded-md"
loading="lazy"
decoding="async"
fetchpriority="auto"
alt="The OpenBSD Puffy logo"
width="300"
height="300"
src="https://andrewmemory.acornwall.net/blog/2023-10-15-setting-up-an-openbsd-7-4-firewall-device/images/puffy-firewall-sticker.png"
srcset="https://andrewmemory.acornwall.net/blog/2023-10-15-setting-up-an-openbsd-7-4-firewall-device/images/puffy-firewall-sticker.png 800w, https://andrewmemory.acornwall.net/blog/2023-10-15-setting-up-an-openbsd-7-4-firewall-device/images/puffy-firewall-sticker.png 1280w"
sizes="(min-width: 768px) 50vw, 65vw"
data-zoom-src="https://andrewmemory.acornwall.net/blog/2023-10-15-setting-up-an-openbsd-7-4-firewall-device/images/puffy-firewall-sticker.png"&gt;&lt;/figure&gt;
&lt;p&gt;So&amp;hellip; here&amp;rsquo;s the order of operations:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://andrewmemory.acornwall.net/blog/2023-10-15-buying-new-hardware-for-an-openbsd-firewall/" &gt;Buy new hardware&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://andrewmemory.acornwall.net/blog/2023-10-15-installing-openbsd-7-3-for-a-firewall/" &gt;Get OpenBSD running on the new hardware&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://andrewmemory.acornwall.net/blog/2023-10-21-set-up-networking-for-an-openbsd-7-4-firewall-device/" &gt;Reorganize my network while it&amp;rsquo;s running&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://andrewmemory.acornwall.net/blog/2023-10-22-block-ad-sites-and-nasties-on-openbsd-7-4/" &gt;Block ad sites and nasties&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://andrewmemory.acornwall.net/blog/2023-10-22-setting-up-wireguard-on-an-openbsd-7-4-firewall-device/" &gt;Add a Wireguard VPN&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Here goes!&lt;/p&gt;</description></item><item><title>Building an ALIX firewall</title><link>https://andrewmemory.acornwall.net/blog/2012-06-20-building-an-alix-firewall/</link><pubDate>Wed, 20 Jun 2012 23:02:03 -0700</pubDate><author>andrewmemoryblog@gmail.com (Andrew's Memory Blog)</author><guid>https://andrewmemory.acornwall.net/blog/2012-06-20-building-an-alix-firewall/</guid><description>&lt;p&gt;It&amp;rsquo;s been a long time since I updated my firewall. Right now it&amp;rsquo;s a &lt;a href="http://www.pcengines.ch/alix2c2.htm" target="_blank" rel="noreferrer"&gt;PC Engines ALIX 2c2&lt;/a&gt; that I&amp;rsquo;ve been really happy with. I used &lt;a href="http://www.nmedia.net/flashdist/" target="_blank" rel="noreferrer"&gt;flashdist&lt;/a&gt; and put &lt;a href="http://openbsd.org/44.html" target="_blank" rel="noreferrer"&gt;OpenBSD 4.4&lt;/a&gt; on it.&lt;/p&gt;
&lt;p&gt;I think that&amp;rsquo;s a winning combination, but it&amp;rsquo;s time to upgrade. First, I want to go to &lt;a href="http://openbsd.org/51.html" target="_blank" rel="noreferrer"&gt;OpenBSD 5.1&lt;/a&gt;. Next, flashdist has been replaced with &lt;a href="http://www.nmedia.net/flashrd/" target="_blank" rel="noreferrer"&gt;flashrd&lt;/a&gt;, which is easier to install and use, and more appropriate for larger CF cards.&lt;/p&gt;
&lt;p&gt;I started by getting an &lt;a href="http://www.pcengines.ch/alix2d2.htm" target="_blank" rel="noreferrer"&gt;ALIX 2d2&lt;/a&gt; (just one more IDE header than the 2c2, not much change). I bought it from &lt;a href="http://www.mini-box.com/s.nl/sc.8/category.19/.f" target="_blank" rel="noreferrer"&gt;mini-box.com&lt;/a&gt;, and I also picked up the custom enclosure for it and a power supply.&lt;/p&gt;
&lt;p&gt;I already had a 4 GB CF card: a Kingston 4GB elite pro 133X, which was new when I built the original firewall. Make sure you have a good CF writer. I&amp;rsquo;ve had failures with cheapies, but got a Kingston FCR-HS219/1 and that worked.&lt;/p&gt;
&lt;p&gt;There are a number of steps to get a working firewall. They are:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;&lt;a href="https://andrewmemory.acornwall.net/blog/2012-06-20-getting-openbsd-5-1-on-the-alix-firewall/" &gt;Getting OpenBSD 5.1 on the ALIX&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://andrewmemory.acornwall.net/blog/2012-06-25-setting-up-networking-for-the-alix-firewall" &gt;Setting up networking for the ALIX firewall&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://andrewmemory.acornwall.net/blog/2012-06-27-setting-up-pf-for-the-alix-firewall" &gt;Setting up PF for the ALIX firewall&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://andrewmemory.acornwall.net/blog/2012-06-28-setting-up-bind-on-the-alix-firewall" &gt;Setting up BIND on the ALIX firewall&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://andrewmemory.acornwall.net/blog/2012-07-07-final-cleanup-for-the-alix-firewall" &gt;Final cleanup for the ALIX firewall&lt;/a&gt;&lt;/li&gt;
&lt;/ol&gt;</description></item></channel></rss>