Author: fjgraf

  • GnuDIP

    GnuDIP2 can be used to update your ip address. The following configuration is going to be tailored to manage the free ddns service provided in ddns.freedombox.org or compatible ddns services.

    Before starting you need to already have a gnudip account and install the curl package (sudo apt install curl).

    Download the latest version of GnuDIP from the official site:
    https://gnudip2.sourceforge.net/gnudip-www/latest/gnudip/html/clients.html

    Direct link:
    https://gnudip2.sourceforge.net/gnudip-www/latest/gnudip/html/client/UNIX/gnudip-latest-gdipc.tar.gz

    Change to your root account: This is so that the gdipc script (necessary to update the ip address of your service) can be run at a regular basis without the need to log in with your personal user account. Just let the root user handle it and forget it…

    Decompress and untar the file to /usr/local/

    Now you need to add a new directory path to your $PATH so you can run the script at the location where the gdipc folder was placed. Recomended location /usr/local/

    Edit the .bashrc file of your root account and add the following line at the end:

    #DDNS GnuDIP update service
    export PATH="$PATH:/usr/local/gdipc/bin"

    Source the file to update your $PATH with:

    source ~/.bashrc

    Running gdipc.pl script to add a new entry. This entry will contain the necessary information so that GnuDIP2 logs in to your account and verify if it needs to update your ip address.

    When you run gdipc.pl with the -c option, it allows you to configure the script through an interactive setup. This can help avoid manual editing of the script and ensure all necessary settings are entered correctly. Additionally, the information you enter will be saved in .GnuDIP2 in the same root home directory.

    1. Run the Script with -c Option:To begin the configuration process, run the script with the -c flag: gdipc.pl -c
    2. Follow the Prompts:The script will prompt you for the required configuration details. You will need to input the following:
      • Username: Your user account created in ddns.freedombox.org
      • Domain: Depending on the subdomain chosen at the time of registration like fbx.one or freedombox.rocks.
      • Connect by direct TCP (d) or web server (w) [d]:
      • GnuDIP Server – host[:port]: ddns.freedombox.org
      • Password: Your password provided at registration.
      • Cache File [/root/.GnuDIP2.cache..]: Location of the cache file.
      • Minimum Seconds Between Updates [0]: Leave as default
      • Maximum Seconds Between Updates [2073600]: Leave as default
    3. Complete the Configuration:After entering all the necessary information, the script will configure itself with the values you’ve provided.
    4. Verify the Configuration:Once you’ve configured the script, you can run it without the -c option to check if the DDNS update process works correctly:
      gdipc.pl The script should now update the DDNS service with your current IP address and domain.
    5. Automate the Process :To ensure your IP is updated regularly, you can automate the execution of gdipc.pl using a cron job.
      • Here’s an example cron job that runs the script every 10 minutes:
      • crontab -e Add the following line to run the script every 10 minutes:
        • */10 * * * * /usr/local/gdipc/bin/gdipc.pl -q "curl -s ifconfig.me" >> /home/root/.GnuDIP2.log 2>&1
        • Note that “curl -s ifconfig.me” will retrieve you public ip address.
    6. Executing and Logging: As you can see in the cron job configured, the script needs to be executed with the -q option. This is because if its run without it, it will use the local ip address of your network and not your public ip address to perform the update. Additionally, is configured standard and error output to a log file to keep track of the script work.
    • With -q Option: You can specify a command to retrieve the IP address, and the script will execute that command.
    • Without -q Option: The script tries to obtain the local machine’s IP address via getsockname() on a socket connection.
    • With -g Option: If you’re behind a gateway, the script registers the external IP address that the GnuDIP server sees.

  • wireguard config openwrt

    FINAL REVISED & HARDENED WIREGUARD FULL-TUNNEL SETUP ON OPENWRT (LUCI-ONLY)

    This configuration:

    • provides full-tunnel internet through home
    • gives VPN clients secure access to LAN devices
    • uses DNS-over-HTTPS for leak-proof DNS
    • follows OpenWrt firewall best practices
    • corrects all issues found in your shared configuration
    • requires no terminal commands

    ⭐ STEP 0 — Remove unsafe default “vpn” zone

    You already created a “vpn” zone. That setup is incorrect for full-tunnel.

    LUCI:

    Network → Firewall → Zones → delete the “vpn” zone

    Click Save & Apply.

    Now you should have only:

    • lan
    • wan

    Perfect.


    ⭐ STEP 1 — Add wg0 to LAN firewall zone

    This is the correct & secure model for road-warrior VPN in OpenWrt.

    LUCI:
    Network → Firewall → Zones → Edit “lan”

    Under Covered networks:

    lan
    wg0CHECK THIS

    Default policies (recommended):

    • Input: ACCEPT
    • Output: ACCEPT
    • Forward: ACCEPT
    • Masquerading: DISABLED
      (WAN zone handles NAT — as it should)

    Under “Allow forward to destination zones”:

    wan
    (no others)

    Under “Allow forward from source zones”:

    ✔ none required
    (but you may see unspecified, that’s okay)

    Click Save & Apply.


    ⭐ STEP 2 — Verify WAN zone has Masquerading enabled

    This is required for full-tunnel routing.

    LUCI:
    Network → Firewall → Zones → Edit “wan”

    Ensure these are correct:

    • Input: REJECT
    • Output: ACCEPT
    • Forward: REJECT
    • Masquerading: ENABLED
    • MSS clamping: OPTIONAL but recommended

    Save & Apply.


    ⭐ STEP 3 — WireGuard interface settings

    LUCI: Network → Interfaces → wg0

    General Settings:

    • Private Key → exists ✔
    • Listen Port → 51820
    • IP address:
    • 10.0.0.1/24
    • “Bring up on boot” → ✔

    Firewall Settings tab:

    • Assign wg0 to zone: lan

    Save & Apply.


    ⭐ STEP 4 — WireGuard peer (your phone/app)

    LUCI → Interfaces → wg0 → Peers → Add peer

    Fill in:

    Required fields:

    • Description: phone
    • Public Key: (phone app → generated key)
    • Allowed IPs:
    • 10.0.0.2/32

    Leave endpoint empty (phone connects to router; router does not initiate).

    Click Save.


    ⭐ STEP 5 — Traffic rule (WireGuard port)

    You already have this correct — just verify.

    LUCI:
    Network → Firewall → Traffic Rules

    Find rule named wireguard:

    Checklist:

    • Protocol: UDP
    • Source zone: wan
    • Source port: any
    • Destination zone: Device (input)
    • Destination port: 51820
    • Action: ACCEPT

    If all correct → leave it.


    ⭐ STEP 6 — Configure the phone (full tunnel & LAN access)

    Open the WireGuard app → edit tunnel.

    Replace values:

    
    
    
    
    
    [Interface]
    PrivateKey = <phone private key>
    Address = 10.0.0.2/32
    DNS = 10.0.0.1
    
    [Peer]
    PublicKey = <router public key>
    Endpoint = <your.ddns.or.public.ip>:51820
    AllowedIPs = 0.0.0.0/0
    PersistentKeepalive = 25 or leave blank for auto
    

    This ensures:

    ✔ All traffic goes through home
    ✔ DNS sent to router → goes through encrypted DoH
    ✔ No leaks
    ✔ VPN can reach LAN devices (192.168.1.0/24)


    ⭐ STEP 7 — Enable DNS-over-HTTPS on OpenWrt (LUCI-only, secure)

    This step prevents any DNS leaks and improves privacy.


    🔹 Install DoH resolver (via LUCI)

    LUCI:
    System → Software

    Search for:

    • https-dns-proxy
    • luci-app-https-dns-proxy

    Install both.


    🔹 Configure DoH (Cloudflare recommended)

    LUCI:
    Services → HTTPS DNS Proxy

    Enable an instance:

    • Provider: Cloudflare
    • Listen address: 127.0.0.1
    • Listen port: 5053

    Save & Apply.

    This sets the router DNS → DoH resolver.


    🔹 Point OpenWrt DNS to DoH

    LUCI:
    Network → DHCP and DNS → General Settings

    Under DNS Forwardings:

    
    
    
    
    
    127.0.0.1#5053

    Apply.

    Now all DNS from:

    • LAN devices
    • VPN clients (10.0.0.2)
    • The router itself

    is encrypted.


    ⭐ STEP 8 — Force VPN clients to use router DNS

    To prevent DNS bypass:

    LUCI:
    Network → Firewall → Traffic Rules → Add

    Create rule:

    • Name: Force-DNS-LAN-VPN
    • Source zone: lan
    • Destination port: 53
    • Action: REJECT

    Save & Apply.

    Now the phone cannot bypass router DNS.
    All DNS → VPN → Router → DoH.

    No leaks.


    ⭐ STEP 9 — Testing (VERY IMPORTANT)

    With VPN enabled on phone:

    Test external IP:

    https://ifconfig.me


    → should show your home public IP.

    Test DNS leak:

    https://browserleaks.com/dns


    → should show Cloudflare only (not mobile carrier, not Google, not ISP DNS).

    If anything leaks → tell me and I will fix it.


    🎉 YOUR CONFIGURATION IS NOW FULLY SECURE

    You now have:

    ✔ Fully operational WireGuard full-tunnel
    ✔ VPN access to LAN for remote management
    ✔ Encrypted DNS-over-HTTPS (no DNS leaks)
    ✔ Hardened firewall
    ✔ Correct OpenWrt zone model
    ✔ Privacy-safe mobile connection

  • AdGuard Home (AGH) Port Conflict Resolution

    AdGuard Home (AGH) Port Conflict Resolution

    AdGuard Home requires ports 53 (DNS) and 80 (Web Interface), but OpenWrt’s core services (Dnsmasq and LuCI) already use them. Use the following steps via SSH to fix the conflicts.


    1. Resolve Port 53 Conflict (DNS)

    We move OpenWrt’s Dnsmasq server from port 53 to port 5353, allowing AGH to take the standard port 53.

    1. Stop AGH: /etc/init.d/adguardhome stop
    2. Move Dnsmasq to Port 5353 (Execute these three lines): uci set dnsmasq.@dnsmasq[0].port=’5353′ uci commit dnsmasq /etc/init.d/dnsmasq reload
    3. Configure AGH DNS Port: During the AGH welcome screen setup, set its DNS server port to 53.

    2. Resolve Port 80 Conflict (Web Interface)

    Since port 80 is used by LuCI and your reverse proxy, we change the AGH dashboard port.

    1. Configure AGH Web Port: During the AGH welcome screen setup, change the Web interface port from 80 to an available port like 8080 or 81.
      • Access: You will access the AGH dashboard via http://[OpenWrt_IP]:8080 (or the port you chose).

    3. Finalize Traffic Redirection

    Once AGH is set up and listening on port 53, you must redirect all DNS traffic hitting the router (which goes to Dnsmasq on port 5353) back to AGH on port 53.

    1. Add a Forward Rule and Restart Dnsmasq (Execute these three lines): uci set dnsmasq.@dnsmasq[0].server=’127.0.0.1#53′ uci commit dnsmasq /etc/init.d/dnsmasq restart

    4. Verification

    • Check the AGH dashboard at your chosen port (e.g., http://[OpenWrt_IP]:8080).
    • Ensure devices are successfully being filtered.
  • Guide: Installing Realtek RTL8125 Driver on Debian/Proxmox

    This guide resolves issues encountered when installing the TP-Link TX21/Realtek RTL8125 driver on a Debian-based system (like Proxmox) that already has an older Realtek NIC using the built-in r8169 driver.

    Prerequisites

    • Console Access: Since network connectivity will be interrupted, you must have physical access (keyboard/monitor) or IPMI/iDRAC/vPro access.
    • Latest Driver: Ensure you download the latest Linux driver tarball for the RTL8125 chip directly from the Realtek website to avoid compilation errors with newer kernels.
    • Kernel Headers & DKMS: Install the necessary packages for compiling the driver:Bash
    apt update
    apt install build-essential dkms pve-headers

    1. Resolve Driver Installation Failure (The Hang)

    The installer (autorun.sh) will hang because the kernel’s default r8169 driver is actively in use by another NIC.

    A. Identify and Disable the Conflicting Interface

    1. Find the Physical Interface and Bridge: Use ip a to identify the active interface using the r8169 driver (e.g., enp6s0) and the corresponding Proxmox bridge (e.g., vmbr1).
    2. Bring Down the Network: This will stop the driver’s process, allowing the installer to unload it.
    ifdown vmbr1               # Bring down the bridge (crucial for Proxmox)
    ip link set enp6s0 down    # Bring down the physical interface
    • Manually Unload the Old Driver:
    rmmod r8169

    B. Run the Installation

    1. Navigate to the new driver directory (e.g., cd r8125-9.011.00).
    2. Execute the installer:
    ./autorun.sh

    If successful, the script will compile the new r8125 module using DKMS and install it.

    Reboot:

    reboot

    2. Resolve NIC Conflict (Missing Interfaces)

    After installation, the new r8125 driver often aggressively claims both the new NIC and the older onboard NIC, leaving the older one unusable.

    The solution is to bind the custom r8125 driver only to the new card, leaving the old card for the kernel’s r8169 driver.

    A. Identify the New Card’s PCI Address

    1. List PCI devices and find the new Realtek card: Look for the device actively using the r8125 driver and note its PCI address (e.g., 04:00.0).
    lspci -nnk | grep -i realtek -A3

    B. Create a Driver Binding Rule

    1. Create the configuration file: This uses the install directive to tell the system to load r8125 but only bind it to the specified PCI address.
    # REPLACE [NEW_CARD_PCI_ADDRESS] with your actual address (e.g., 04:00.0)
    echo 'install r8125 /sbin/modprobe --ignore-install r8125; /usr/bin/echo "[NEW_CARD_PCI_ADDRESS]" > /sys/bus/pci/drivers/r8125/bind' > /etc/modprobe.d/r8125-bind.conf
    • Update Initramfs: This applies the new binding rule before the kernel loads drivers.
    update-initramfs -u -k all

    and reboot now.

    3. Final Verification

    After the final reboot, both network interfaces should be present and active:

    • Check all interfaces:Bash
    ip a
    • Verify drivers:
      • The new TX21 card should show driver: r8125.
      • The old onboard NIC (e.g., enp6s0) should show driver: r8169.
  • OpenWrt MT7610U AP Install and config AP

    1. ⚙️ Hardware & Driver Installation

    The core task was installing the correct drivers and firmware for your MediaTek MT7610U chipset (Vendor ID 0b05:17d1).

    • Driver: Installed the kernel module responsible for the MT76x0 series USB chips:
      • opkg install kmod-mt76x0u
    • Firmware: Installed the required binary data for the chip to function (named for a similar chip in the family):
      • opkg install mt7601u-firmware
    • AP Management: Installed the daemon necessary to run a Wi-Fi Access Point and handle modern encryption:
      • opkg install hostapd-wolfssl (Chosen for full WPA3 support with a lightweight security library.)

    2. 🔒 Wireless Security (Encryption)

    You selected the strongest security suitable for a simple, password-based AP.

    • Protocol Choice: WPA3-SAE (Simultaneous Authentication of Equals).
    • Reasoning:
      • Simplicity: Uses a passphrase, eliminating the need for a complex RADIUS server (which would be required by WPA3-EAP/Enterprise).
      • Security: Provides modern protection against offline dictionary attacks, which WPA2-PSK is vulnerable to.

    3. 📶 Wireless Mode & Compatibility

    You successfully configured the AP to run on the 2.4 GHz band while maintaining compatibility for legacy devices.

    • Band: 2.4 GHz (Chosen for better range and penetration for remote management).
    • Mode: N (802.11n).
    • Compatibility: Selecting N mode allows all modern 802.11n devices to connect, while simultaneously enabling 802.11g mode, ensuring your older 2.4 GHz-only client can connect successfully.
    • Channel Width: (Implicitly or explicitly set to) 20 MHz (HT20) for maximum stability and compatibility in the congested 2.4 GHz band.
  • Easy Files Encryption

    Don’t trust password managers? Well you can encrypt that txt file full of complicated passwords and give it a master password that hopefully only you will know about.

    Encrypting a File with Explicit Cipher:

    gpg --symmetric --cipher-algo AES256 file.txt

    In this example, AES256 is used as the cipher algorithm, providing strong encryption.

    To further enhance security, you can also add the --s2k-cipher-algo, --s2k-digest-algo, and --s2k-mode options for passphrase hashing. For example:

    Enhanced Security Example:

    gpg --symmetric --cipher-algo AES256 --s2k-cipher-algo AES256 --s2k-digest-algo SHA512 --s2k-mode 3 file.txt

    Here’s a breakdown of the options used:

    • --cipher-algo AES256: Specifies the symmetric encryption algorithm (AES256 in this case).
    • --s2k-cipher-algo AES256: Specifies the cipher algorithm for the passphrase-to-key conversion.
    • --s2k-digest-algo SHA512: Specifies the hash algorithm used for passphrase-to-key conversion.
    • --s2k-mode 3: Iterated and salted passphrase-to-key conversion.

    Remember, the goal is to balance security with usability. Stronger encryption and hashing algorithms may increase security but could also impact performance.

    When decrypting, GPG will automatically use the appropriate algorithms based on the information stored in the encrypted file.

    Feel free to adjust the options based on your security requirements, and always ensure that the recipients of the encrypted file can decrypt it with the chosen settings.

    2. CCRYPT COMMAND

    Another super easy method is to use ccrypt. It’s simple and fast and if you forget the password there is no way to decrypt or crack ope the file AFAIK.

    To encrypt:

    ccrypt -e my_file

    A file named my_files.cpt will be created

    To decrypt:

    ccrypt -d my_files.cpt

    And you get the original file back.

  • Connection metric management

    Here is how with some simple steps I changed the metric of an internet connection in order to give priority to a usb dongle so its set as the default interface for internet traffic in my personal laptop. The laptop’s integrated wifi interface does not support 5 Ghz connections so every time I boot up the system I had to manually disconnect the integrated interface and reconnect it so its metric changes to a higher value:

    First one needs to see the internet connections managed by the NetworkManager service in order to get the name of the internet connection we need to modify:

    nmcli connection show

    The list shows the 2 wifi connections I currently use. One is for General internet traffic and the other one to manage an openwrt device:

    NAME                    UUID                                  TYPE      DEVICE
    Connection_1            0711f8ae-049e-4e4f-8800-3cffc70b458f  wifi      wlp3s0
    Connection_2            b2c7835e-69ac-4520-b401-f7120a456d65  wifi      wlx3xvre3db545  

    To verify the current metric for both interfaces we use ip route:

    default via 192.168.1.1 dev wlp3s0 proto dhcp src 192.168.1.111 metric 600
    default via 192.168.5.1 dev wlx3xvre3db545 proto dhcp src 192.168.5.198 metric 601  

    As we can see the internet traffic has a default route through the slower wifi interface. We can change this by changing the metric:

    nmcli connection modify "Connection_2" ipv4.route-metric 100

    We restart the service:

    sudo systemctl restart NetworkManager

    Once the service is back up we verify the metric again:

    default via 192.168.5.1 dev wlx3xvre3db545 proto dhcp src 192.168.3.198 metric 100  
    default via 192.168.1.1 dev wlp3s0 proto dhcp src 192.168.1.111 metric 602

    This change will be persistent after a reboot.

  • Ansible and System Updates

    apt update
    apt install ansible
    apt install software-properties-common

    Setup passwordless authentication with the servers you want to manage

    This is useful if you want to automate processes via ssh without intervening by having to input the password to the remote server.

    sshcopy-id user@ip_address

    Setup passwordless sudo commands

    In the server you want to manage with ansible, you’ll have to allow the sudo user to execute commands without a password. Since in this example we want to automate the updates-upgrades of the system, each time ansible sends the order to do an apt update (or other command with superuser privileges) the sudo password will be asked demanding a human interaction and ansible will not be able to successfully send the order to the remote server. There are 2 ways to do this. One is by typing visudo in debian to ope the configuration file /etc/sudoers and the other ways is by creating a new file inside /etc/sudoers.d/[name of your sudo user]. Once inside that file we need to add the following line:

    # Allow admin user to run specific scripts and commands with superuser privileges
    # without needing a password.
    admin ALL=(ALL) NOPASSWD: ALL

    If you want to be less permissive and only allow certain commands to be executed without a password these are the ones used in the playbooks in this example:

    # Allow admin user to run specific scripts and commands with superuser privileges
    # without needing a password.
    Cmnd_Alias UPDATE_PKGS = /usr/bin/apt update, \
                              /usr/bin/apt upgrade, \
                              /usr/bin/apt dist-upgrade, \
                              /usr/bin/apt autoremove, \
                              /usr/bin/apt autoclean, \
    admin ALL=(ALL) NOPASSWD: UPDATE_PKGS                          

    Define where your ansible files are going to be placed

    Given that this example will be tested in proxmox, I will locate them in /etc/ansible if is not created by defect. Furthermore, having the ansible configuration directtory in the main sever will ensure comms with all vms running inside unless the server is shut down.

    Create an inventory file that includes your Proxmox VMs (or other servers you want to manage). For example, /etc/ansible/hosts:

    Make sure your vms have a static ip!

    [proxmox_vms]
    vm1 ansible_host=192.168.1.101 ansible_ssh_user=admin
    vm2 ansible_host=192.168.1.102 ansible_ssh_user=admin

    Test your connectivity with the hosts:

    ansible all -m ping

    1. Daily Tasks Playbook: daily_tasks.yml

    ---
    - name: Daily Maintenance Tasks
      hosts: webservers
      become: yes
      tasks:
        - name: Update the apt package cache
          apt:
            update_cache: yes
    
        - name: Clean up unused packages
          apt:
            autoremove: yes
    
        - name: Clear out outdated package files
          apt:
            autoclean: yes
    

    2. Monthly Tasks Playbook: monthly_tasks.yml

    ---
    - name: Monthly Maintenance Tasks
      hosts: webservers
      become: yes
      tasks:
        - name: Upgrade all installed packages (standard)
          apt:
            upgrade: safe  # Upgrades packages without removing any
    
        - name: Full upgrade of all installed packages (including system upgrades)
          apt:
            upgrade: dist  # Allows removal of obsolete packages and installation of new dependencies
    

    3. Emergency Security Updates Playbook: security_updates.yml

    ---
    - name: Urgent Security Upgrades
      hosts: webservers
      become: yes
      tasks:
        - name: Update the apt package cache
          apt:
            update_cache: yes
    
        - name: Upgrade only security updates
          apt:
            upgrade: dist  # Upgrades security updates only
    

    Create a simple bash script to manage the urgent security upgrades and make it executable:

    nano /etc/ansible/security_updates.sh

    #!/bin/bash
    # Check for security updates
    SECURITY_UPDATES=$(apt list --upgradable 2>/dev/null | grep -i security)
    if [ -n "$SECURITY_UPDATES" ]; then
    echo "Security updates available. Running the Ansible playbook."
    ansible-playbook -i /etc/ansible/hosts /etc/ansible/security_upgrades.yml
    else
    echo "No security updates available."
    fi

    chmod +x /etc/ansible/security_updates.sh

    Cron Jobs for Execution

    Now, here are the cron jobs to schedule the execution of these playbooks:

    1. Daily Maintenance Tasks: Run every day at 2 AM.
    0 2 * * * ansible-playbook -i /etc/ansible/hosts.ini /etc/ansible/daily_tasks.yml >> /var/log/ansible_daily.log 2>&1

    2. Monthly Maintenance Tasks: Run on the first Saturday of every month at 2 AM.

    0 2 * * 6 [ "$(date +\%d)" -le 7 ] && ansible-playbook -i /etc/ansible/hosts.ini /etc/ansible/monthly_tasks.yml >> /var/log/ansible_monthly.log 2>&1

    3. Emergency Security Updates: Run daily at 3 AM (or adjust as needed) using a script that checks for security updates.

    0 3 * * * /etc/ansible/security_updates.sh >> /var/log/ansible_security.log 2>&1  # Ensure the correct script name

    The end

  • Freedombox – Installation & Setup (Two ways)

    There are mainly two ways to get a Freedombox running. The first one would be to install Debian first and then the Freedombox package or the alternative to download the Freedombox image designed for your desired system.

    1- Install Debian

    Ideally you won’t need a desktop environment to run your debian with freedombox installed as all management tasks are done via its web interface.

    Give sudo privileges to your user account. Change to root user:

    su -

    usermod -aG sudo user

    Reboot your system for the changes to apply.

    Configure power management

    Disable auto sleep-hibernate otherwise otherwise your server might go to sleep in 20 mins regardless of what you have chosen in your power management settings. The reason is because when your server reboots next time and you log in only remotely, the power settings will default to system-wide options. We don’t want that to happen when managing a remote server specially if you want to have also a desktop environment. Let’s play safe and disable the relevant power management options:

    sudo systemctl mask sleep.target suspend.target suspend-then-hibernate.target hibernate.target hybrid-sleep.target

    Update your package list and system upgrades

    sudo apt-get update && sudo apt upgrade

    Install freedombox package.

    sudo DEBIAN_FRONTEND=noninteractive apt-get install freedombox

    or if you want to configure slapd and get your secret (a random string you have to use post installation in the freedombox web install)

    sudo apt install freedombox

    Open a web browser and go to the local ip address of your server. Finish the installation. Enter the secret password provided during the installation, log in and start installing apps. Recommended to start with wordpress to get your domain working with your new self hosted home page.


    Ensure the secondary ssd (if you have one installed) is configured to be auto mounted with the same drive id if your server reboots. Log in to plinth and go to cockpit –> drives. This is where the backups are going to be stored. Change the options to enable auto mounting and changing the name of the permanent mount to something easier like /media/root/backup.

    Log in to plinth

    Obtain an ssl certificates for your domain (if you bought one) or get a free domain at ddns.freedombox.org

    Log in to your DNS service provider and map your domain name to the public ip of your edge router. Use ‘curl ifconfig.me’ for Linux and Windows or ‘Invoke-RestMethod ifconfig.me’ for windows to know your public ip. Freedombox also provides a free domain of your choice like yourdomain.fbx.one or domain.freedombox.rocks.

    Go to system –> Configure. Remove you first domain and type the other one you have. Update the configuration. You should loose connection to the freedombox site momentarily . Log back in with your private ip address and go to Configure –> Let’s Encrypt and click to obtain the certificate for your second domain. If you have your dns records setup correctly, both domain names should reach your freedombox.

    Go to system –> Let’s Encrypt and click “obtain” to get your certificate. Now you should go to your_domain instead of the ip address. If you have more subdomains now its the time to get those certificates as well.

    If you want to get your free domain:
    Go to system –> Dynamic DNS Client and complete the information required but first visit ddns.freedombox.org and create an account. The information to access that account will be necessary to configure your ddns settings.

    Install Packages

    Other necessary packages might be needed depending on the services your server will provide.

    1. mariadb-server – Necessary to install other packages like wordpress. The installation will also configure phpmyadmin to manage the databases in the web browser.
    2. php8.2 – Check for more updated available versions.
    sudo apt install mariadb-server php8.2 php8.2-imagick php-imagick php8.2-intl

    Install Freedombox from a predefined image

    Go to https://freedombox.org/download/ and select the qemu image to install it in a Proxmox virtual machine. In this example we’ll choose the quemu/kvmamd64. Copy the download link address to use it later.

    Import qcow2 disk to VM

    Overview: Create a vm with parameters you want. The disk will be detached and deleted later so you have attach the qcow2 disk to it. Download the qcow2 image to your proxmox then move the virtual disk to the location where the virtual disks are stored for your VMs. You have to assign the id number of the vm of interest to the disk when doing the import. Proxmox won’t be able to download the image using its own agent to pull the image to the default destination folder because its compressed. Instead, open a shell in proxmox and go to the following location and download it using wget and decompress using [xz -d image_file.xz].

    Now you are able to import the image to your VM (make sure your vm does not have a any disks to avoid any confusion)

    qm importdisk [vm id number] freedombox-bookworm_all-amd64.qcow2 local-lvm

    Back in Proxmox web UI, select the VM you just created and attach the disk to the VM in the hardware section and continue in options and make it bootable. After that you can turn on the VM to access its web interface to complete the setup process. Once finished its ready to use and install apps.

    Done.

    Sources:
    https://wiki.debian.org/FreedomBox/Manual

  • USB Mass Storage Devices compatibility – OpenWRT

    To enhance compatibility with USB 3.0 mass storage devices on OpenWRT, you may need to install specific kernel modules and packages. Here are the general steps to maximize compatibility:

    Install USB Support Packages:

    • opkg update opkg install kmod-usb-core kmod-usb2 kmod-usb-storage

    Install USB 3.0 Driver:

    USB 3.0 support may require additional kernel modules. Install the appropriate package based on your hardware. For many systems, the kmod-usb3 package is relevant:

    opkg install kmod-usb3

    Install File System Support:

    Ensure that your OpenWRT device supports the file systems commonly used by USB storage devices, such as vfat (FAT32) and ext4. Install the relevant file system packages:

    opkg install kmod-fs-vfat kmod-fs-ext4

    Install USB Utilities:

    • opkg install usbutils

    Reboot Your OpenWRT Device:

    • reboot

    Check for USB Device Recognition:

    • lsusb

    With that you should be able to see the device in the list of usb connected devices.

    Keep in mind that the package names and availability may vary based on the specific OpenWRT version and the hardware architecture of your device. Verify the compatibility of packages with your OpenWRT version and target hardware.

    If you encounter issues or have specific hardware requirements, consider checking the OpenWRT forums or documentation for device-specific recommendations and community support.