Basics
pfSense 2.9.0 on Proxmox
Installing pfSense 2.9.0 on Proxmox. An update for 2026. Including how to setup the GEMU Guest Agent. And Unbound 1.26.0 security issue fix for older installs.
After moving to an apartment, I downsize from 14 servers, many Enterprise grade machines. To VPS, NUC, mini and SFF machines. I will create a series of posts how I create my new lab. As I need to do a lot of travelling this year, this will take a long time to get ready. This is my story #proxmox #zfs #docker #vlan #samba #pve #pbs
Basics
Installing pfSense 2.9.0 on Proxmox. An update for 2026. Including how to setup the GEMU Guest Agent. And Unbound 1.26.0 security issue fix for older installs.
Docker
Anyone using computers knows how important the DNS is. For a homelab we need more, things like blocking bad sites. Without a working DNS you are lost and nothing will work. Technitium is a DNS Server for Privacy and Security including site blocking and syncronication. We set it up using Docker.
MyNewLab
I took my old MacBook Pro (Intel) and upgraded it with a version of Arch Linux, Omarchy. It's beautiful, easy to use, and all based on Arch. It's also a system designed to be the system to use when moving from Windows or Mac to Linux. In two weeks you will learn to love Omarchy 4.0.
DNS
To use friendly names instead of IPs. Set up a Private Domain with Technitium. We set up a Domain Name Server ns1 and configure it to handle our domain, example.com or mylab.lan. Options for later: DHCP, a cluster with at least ns1 and ns2 for redundancy, and add ad-blocking if that's needed.
Docker
This post will show the use of the Docker Socket Proxy with Portainer. It allows controlled and secure automation while still maintaining security. It's a reverse proxy that allows you to control what Docker API endpoints can be accessed by Docker clients such as Portainer, DIUN and Watchtower.
Docker
Container orchestration the easy way. Swarm mode is an advanced feature for container orchestration. Use Swarm mode if you intend to use Swarm as a production runtime environment. Docker Swarm mode is built into the Docker Engine. Docker Swarm mode is similar to K3s or even K8s, but it's lighter.
MyNewLab
Sometimes it's a better to have an easy-to-use system rather than one with everything. We need a secure VM and that's why we run Proton OS. Using the recommendations of the KSPP (Kernel Self-Protection Project), the Photon OS Linux Kernel is secure from the start.
Build
One of the supporting pillars of virtualization is the use of Cloud-Init and Cloud Images. Setting up VMs is easy and fast. The process is easy to automate and adapt to CI/CD.
MyNewLab
SmokePing is a deluxe latency measurement tool. It can measure, store and display latency, latency distribution and packet loss. SmokePing uses the RRDtool to maintain a long term data-store. It draws informative graphs of the state of each network connection to express up-to-the-minute information.
MyNewLab
TrueCommand is a ZFS-aware solution, allowing you to set custom alerts on statistics like ARC usage or pool capacity, ensuring storage uptime and future planning. TrueCommand also identifies and pinpoints errors on drives or vdevs, saving valuable time when troubleshooting and resolving issues.
Networking
Running services on a PVE node is a perfect place to simulate networking. For the basic setup, we are to use SDN and OPNsense. Setting up a virtual or dedicated NIC as WAN and set up an SDN network for our VM/CT to use.
Build
Proxmox Backup Server is flexible and can be installed on any device running Debian, a VM or a LXC. Here I show my Proxmox LXC setup. Having PBS on the PVE is making use of the large and fast SSD ZFS RAID 10 storage.