<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://mediawiki.comfac.net/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Justinaquino</id>
	<title>MediawikiCIT - User contributions [en]</title>
	<link rel="self" type="application/atom+xml" href="https://mediawiki.comfac.net/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Justinaquino"/>
	<link rel="alternate" type="text/html" href="https://mediawiki.comfac.net/index.php/Special:Contributions/Justinaquino"/>
	<updated>2026-10-03T08:08:41Z</updated>
	<subtitle>User contributions</subtitle>
	<generator>MediaWiki 1.45.1</generator>
	<entry>
		<id>https://mediawiki.comfac.net/index.php?title=Main_Page&amp;diff=284</id>
		<title>Main Page</title>
		<link rel="alternate" type="text/html" href="https://mediawiki.comfac.net/index.php?title=Main_Page&amp;diff=284"/>
		<updated>2026-08-28T15:42:51Z</updated>

		<summary type="html">&lt;p&gt;Justinaquino: Move Nextcloud workshop link to System Administration &amp;amp; Self-Hosting section&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__NOTOC__&lt;br /&gt;
&amp;lt;div style=&amp;quot;background:#f8f9fa; border:1px solid #ddd; border-radius:4px; padding:12px 16px; margin-bottom:20px;&amp;quot;&amp;gt;&lt;br /&gt;
Welcome to the &#039;&#039;&#039;Comfac IT Knowledge Base&#039;&#039;&#039;. Use the sections below to find guides, SOPs, and references organized by topic.&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== New Articles ==&lt;br /&gt;
&lt;br /&gt;
Recent additions to this wiki, newest first — each is also filed in its permanent topic section below. &#039;&#039;&#039;Keep this list to the 10 most recent&#039;&#039;&#039; and prune as new pages are added; nothing is deleted, entries just roll off the feed.&lt;br /&gt;
* 2026-08-28 — &#039;&#039;&#039;[[Nextcloud App Development Workshop 260825]]&#039;&#039;&#039; — Beginner workshop (Anna Larch, Nextcloud DevRel): OCP vs OC, request lifecycle, entities/migrations/indices, events, background jobs, app-store submission — &#039;&#039;Filed under: System Administration &amp;amp; Self-Hosting&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* 2026-08-09 — &#039;&#039;&#039;[[SOP: Third-Party Software Security Review]]&#039;&#039;&#039; — due-diligence workflow for GitHub/OSS code (data-leak focus) + first review result: offline-browser-translate, CLEAN WITH CONDITIONS — &#039;&#039;Filed under: IT Operations &amp;amp; SOPs&#039;&#039;&lt;br /&gt;
* 2026-08-02 — &#039;&#039;&#039;[[Hugging Face Practical Guide 260802]]&#039;&#039;&#039; — Spaces, local app builds, the Model Hub / dataset viewer, and the enterprise compute tier; the route from stock models to tailored ones and to training on our own data — &#039;&#039;Filed under: AI &amp;amp; Machine Learning&#039;&#039;&lt;br /&gt;
* 2026-08-01 — &#039;&#039;&#039;[[Audio Learning]]&#039;&#039;&#039; — Converting research and study material into scripts written to be listened to rather than read; shared Comfac tool — &#039;&#039;Filed under: Tools &amp;amp; Productivity&#039;&#039;&lt;br /&gt;
* 2026-07-31 — &#039;&#039;&#039;[[Resume CV Renamer Pipeline]]&#039;&#039;&#039; — CV intake → OCR / vision-OCR → AI field extraction → date-stamped rename + VCF export — &#039;&#039;Filed under: Tools &amp;amp; Productivity&#039;&#039;&lt;br /&gt;
* 2026-07-15 — &#039;&#039;&#039;[[De-Risk: Sovereign Training Data v0.1]]&#039;&#039;&#039; — Frontier-Token Quarantine and the ToS-clean path to owned model weights, prompted by the June 2026 Fable 5 export-control suspension — &#039;&#039;Filed under: AI &amp;amp; Machine Learning&#039;&#039;&lt;br /&gt;
* 2026-07-15 — &#039;&#039;&#039;[[Directed Execution: Token-Efficient Agent Development Process]]&#039;&#039;&#039; — Director/Executor/Checker loop and skill distillation for token-efficient agent development — &#039;&#039;Filed under: AI &amp;amp; Machine Learning&#039;&#039;&lt;br /&gt;
* 2026-07-11 — &#039;&#039;&#039;[[Tutorial: Exposing a Dockerized Web App via NPM Direct DB Config]]&#039;&#039;&#039; — Expose a Dockerized web app by editing Nginx Proxy Manager&#039;s database directly — &#039;&#039;Filed under: System Administration &amp;amp; Self-Hosting&#039;&#039;&lt;br /&gt;
* 2026-05-02 — &#039;&#039;&#039;[[Organizing Coder Terminals]]&#039;&#039;&#039; — Tmux + dynamic titles for managing multiple AI agent terminals — &#039;&#039;Filed under: System Administration &amp;amp; Self-Hosting&#039;&#039;&lt;br /&gt;
* 2026-04-28 — &#039;&#039;&#039;[[Forgejo Pages]]&#039;&#039;&#039;&lt;br /&gt;
* 2026-04-24 — &#039;&#039;&#039;[[Buzz Transcription]]&#039;&#039;&#039; — Offline audio/meeting transcription via Whisper (whisper.cpp), Flatpak + Vulkan GPU acceleration — &#039;&#039;Filed under: Tools &amp;amp; Productivity&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== Newest Pages (auto) ==&lt;br /&gt;
&lt;br /&gt;
The 10 most recently created pages — maintains itself.&lt;br /&gt;
&lt;br /&gt;
{{Special:NewPages/10}}&lt;br /&gt;
&lt;br /&gt;
== ERPNext / Frappe ==&lt;br /&gt;
&amp;lt;div style=&amp;quot;column-count:2; column-gap:2em;&amp;quot;&amp;gt;&lt;br /&gt;
* [[Frappe HRMS]] — &#039;&#039;&#039;HR &amp;amp; Payroll&#039;&#039;&#039; (with Philippine Localization)&lt;br /&gt;
* [[Frappe ERPNext/Webshop]] — &#039;&#039;&#039;E-Commerce Webshop&#039;&#039;&#039; (setup, architecture, chapters)&lt;br /&gt;
* [[Manufacturing v16 260125]]&lt;br /&gt;
* [[ERpnext Asset Management Procedure 260113]]&lt;br /&gt;
* [[ERPNext HR Module Outline]]&lt;br /&gt;
* [[ERPNEXT Payroll POC 251212]]&lt;br /&gt;
* [[Comfac ERPNext Strategy Canvas (Expanded)]]&lt;br /&gt;
* [[PAD-Driven ERPNext Strategy 260303]] — PAD/AI-agentic implementation strategy for Frappe ERPNext&lt;br /&gt;
* [[ERPNext v15 Docker Setup Guide]] — Local Docker setup for evaluation, testing, and student use&lt;br /&gt;
* [[Frappe Links and References]]&lt;br /&gt;
* [[Using Frappe Wiki]]&lt;br /&gt;
* [https://docs.frappe.io/cloud/guidelines-for-contributing-regional-compliance-app Guidelines for Contributing Regional Compliance App]&lt;br /&gt;
* [https://docs.frappe.io/cloud/what-are-benches-and-bench-groups What are Benches?]&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== System Administration &amp;amp; Self-Hosting ==&lt;br /&gt;
&amp;lt;div style=&amp;quot;column-count:2; column-gap:2em;&amp;quot;&amp;gt;&lt;br /&gt;
* [[Nextcloud App Development Workshop 260825]] — Beginner workshop (Anna Larch, Nextcloud DevRel, 2026-08-25)&lt;br /&gt;
* [[Networking PfSense Index]] — Consolidated index of all networking, pfSense, DNS, and infrastructure guides&lt;br /&gt;
* [[System Hardening Strategy: Win2Lin Migration &amp;amp; Infrastructure 251129]]&lt;br /&gt;
* [[Controller Systems 251213-01]]&lt;br /&gt;
* [[Power Distribution Tree 251213]]&lt;br /&gt;
* [[Introduction: Why Self-Host Your Email?]]&lt;br /&gt;
* [[Mailcow + Thunderbird Setup Guide (Email + Calendar)]]&lt;br /&gt;
* [[Mailcow SOGo: Creating Filters for Events, Approvals, and Organizational Emails]]&lt;br /&gt;
* [[Spoof Timezone Extension – Setup Guide for Comfac Staff]]&lt;br /&gt;
* [[Viber Focus-Stealing]]&lt;br /&gt;
* [[🌐 WordPress Website — *You Own Everything, Learn Everything*]]&lt;br /&gt;
* [[Portainer to Docker Compose Migration Guide]]&lt;br /&gt;
* [[Organizing Coder Terminals]] — Tmux + dynamic titles for managing multiple AI agent terminals&lt;br /&gt;
* [[Editing Mastodon Docker Deployment Guide 260402]]&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Storage &amp;amp; Hardware ==&lt;br /&gt;
&amp;lt;div style=&amp;quot;column-count:2; column-gap:2em;&amp;quot;&amp;gt;&lt;br /&gt;
* [[TrueNAS Configuration Options &amp;amp; Scale Options 251130]]&lt;br /&gt;
* [[TrueNAS Business Plan: Project 251212]]&lt;br /&gt;
* [[Comparison: TrueNAS Mini X+ vs Dell Precision 3680 Tower (2025)]]&lt;br /&gt;
* [[Backblaze Drive Stats for Server and Storage Qualification]]&lt;br /&gt;
* [[Industrial Controllers and Water Utilities 251011]]&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== AI &amp;amp; Machine Learning ==&lt;br /&gt;
&amp;lt;div style=&amp;quot;column-count:2; column-gap:2em;&amp;quot;&amp;gt;&lt;br /&gt;
* [[OpenWebUI - 251128-justin]]&lt;br /&gt;
* [[Comfac GPU Scaling and AI Research Goals]]&lt;br /&gt;
* [[🧠 Process: Selecting and Installing the Right Ollama Model for Your Hardware]]&lt;br /&gt;
* [[Ollama GNOME System Tray Panel 260401]] — GNOME system tray toggle to start/stop Ollama and reclaim VRAM&lt;br /&gt;
* [[Proceedural Agentic Development Methodology 260304]] — Methodology for systematic agent use&lt;br /&gt;
* [[Project OpenCoder: AI Independence Initiative]] — Strategic roadmap for manufacturing intelligence&lt;br /&gt;
* [[OpenCoder Qwen35 Agentic Setup 260330]] — Qwen3.5 Modelfile fix for tool calling in OpenCode; thinking mode suppression; HDD vs SSD findings&lt;br /&gt;
* [[OpenCode Multi-Provider Configuration Guide 260401]] — Dual-mode AI coding setup with Kimi cloud + Ollama local models via Distrobox&lt;br /&gt;
* [[PAD-Driven ERPNext Strategy 260303]] — Procedural Agentic Development for Frappe/ERPNext configuration and deployment&lt;br /&gt;
* [[Directed Execution: Token-Efficient Agent Development Process]] — Director/Executor/Checker loop and skill distillation for token-efficient agent development (v0.1, 2026-07-15)&lt;br /&gt;
* [[De-Risk: Sovereign Training Data v0.1]] — Frontier-Token Quarantine and the ToS-clean path to owned model weights, prompted by the June 2026 Fable 5 export-control suspension (v0.1, 2026-07-15)&lt;br /&gt;
* [[Hugging Face Practical Guide 260802]] — Spaces, local app builds, the Model Hub / dataset viewer, and the enterprise compute tier; the route from stock models to tailored ones and to training on our own data (2026-08-02)&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Job Descriptions ==&lt;br /&gt;
&amp;lt;div style=&amp;quot;column-count:2; column-gap:2em;&amp;quot;&amp;gt;&lt;br /&gt;
* [[Job Descriptions]] — Index of all official job descriptions (IT, Engineering, Sales)&lt;br /&gt;
* [[JD IT Project Staff]] — IT Project Staff&lt;br /&gt;
* [[JD Security Compliance Assistant 260224]] — Security and Compliance Assistant (SCA)&lt;br /&gt;
* [[JD Engineering Designer 260108]] — Engineering Designer&lt;br /&gt;
* [[JD Engineering Supervisor 260109]] — Engineering Supervisor&lt;br /&gt;
* [[JD Technical Sales 260112]] — Technical Sales Engineer&lt;br /&gt;
* [[JD Marketing Assistant 251119]] — Marketing Assistant&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== IT Operations &amp;amp; SOPs ==&lt;br /&gt;
&amp;lt;div style=&amp;quot;column-count:2; column-gap:2em;&amp;quot;&amp;gt;&lt;br /&gt;
* [[SOP: Third-Party Software Security Review]] — vet GitHub/OSS code for data leakage and exploits before install; workflow, criteria, and review log&lt;br /&gt;
* [[SCA Program Plan 260320]] — Security &amp;amp; Compliance Assistant Program Plan v3 (ISO 9001/27001, PDCA, distributed audit model)&lt;br /&gt;
* [[SOP: Inter-Company Ordering and Production Process 260203]] — Ordering and production workflow between Sister Companies and the Cabuyao Plant&lt;br /&gt;
* [[Memo: Team Roles &amp;amp; Reporting Process Clarification 260320]] — Role boundaries, data ownership, and the new ERPNext-driven reporting paradigm&lt;br /&gt;
* [[Standard Operating Procedure: Distributed Minute Taking &amp;amp; Task Ownership 251208]]&lt;br /&gt;
* [[Business Continuity]]&lt;br /&gt;
* [[Procedure: CC-Blast Data Breach Prevention]]&lt;br /&gt;
* [[8D (Eight Discipline) Problem Solving Procedure]]&lt;br /&gt;
* [[Offline Malware Remediation &amp;amp; Data Recovery]]&lt;br /&gt;
* [[Troubleshooting: Access &amp;amp; Permission Issues]]&lt;br /&gt;
* [[Steps to Repair and OCR a Scanned or Corrupted PDF in Ubuntu]]&lt;br /&gt;
* [[IT IMPORTS PROCESSES]]&lt;br /&gt;
* [[IT Purchase Requests 241126]]&lt;br /&gt;
* [[IT REQUEST (OP-ERP-ITR) - EDITED 250801]]&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Sales &amp;amp; Business ==&lt;br /&gt;
&amp;lt;div style=&amp;quot;column-count:2; column-gap:2em;&amp;quot;&amp;gt;&lt;br /&gt;
* [[Comfac Sales Knowledge Base]]&lt;br /&gt;
* [[Comfac CRM – Customer Qualification &amp;amp; Conversion Process]]&lt;br /&gt;
* [[Partner Reseller Pricing 251109]]&lt;br /&gt;
* [[Biz Analysis Methodology 251109]]&lt;br /&gt;
* [[2026 MIS IT KRA KPI Biz Plan]]&lt;br /&gt;
* [[SALES INVOICE TAX OUTPUT 250829]]&lt;br /&gt;
* [[Projects in Process Report 251023]]&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Tools &amp;amp; Productivity ==&lt;br /&gt;
&amp;lt;div style=&amp;quot;column-count:2; column-gap:2em;&amp;quot;&amp;gt;&lt;br /&gt;
* [[Excel Description Filler Tool 📝]]&lt;br /&gt;
* [[Resume CV Renamer Pipeline|Resume / CV Renamer Pipeline]] — CV intake → OCR / vision-OCR → AI field extraction → date-stamped rename + VCF export&lt;br /&gt;
* [https://github.com/Comfac-Global-Group/comfac-studies Comfac Studies - Spaced Repetiton Active Recall]&lt;br /&gt;
* [[LibreOffice / Nextcloud Office – &amp;quot;Due Tasks&amp;quot; Conditional Formatting]]&lt;br /&gt;
* [[Google Drive and Shared Drive Training]]&lt;br /&gt;
* [[260108 CGG- GitHub Administration Guide]]&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Wiki &amp;amp; Documentation ==&lt;br /&gt;
&amp;lt;div style=&amp;quot;column-count:2; column-gap:2em;&amp;quot;&amp;gt;&lt;br /&gt;
* [[Mediawiki Setting Up Guide]]&lt;br /&gt;
* [[Contributing to Only Office 260307]]&lt;br /&gt;
* [[Mediawiki Additional Configuration]]&lt;br /&gt;
* [[Mediawiki Docker Migration Guide]]&lt;br /&gt;
* [[Home]]&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Tutorials ==&lt;br /&gt;
&amp;lt;div style=&amp;quot;column-count:2; column-gap:2em;&amp;quot;&amp;gt;&lt;br /&gt;
* [[Claude Code Isolation and Burner Workflow 260211]] — Secure AI development environment setup&lt;br /&gt;
* [[Opencode isolation and burner workflow 260216]] — OpenCode CLI isolation procedures&lt;br /&gt;
* [[LibreOffice Calc NumToWords Extension Complete Guide]] — Extension development&lt;br /&gt;
* [[ERPNext v15 Docker Setup Guide]] — ERPNext v15 local Docker setup (students, evaluators, thin-client demos)&lt;br /&gt;
* [[Erpnextv15-SSH-setup-241111]] — ERPNext v15 SSH/Portainer production setup&lt;br /&gt;
* [[Git-Mediawiki Local Editing 260223]] — Wiki editing with Git&lt;br /&gt;
* [[Understanding &amp;amp; Fixing Kernel Panics 260212]] — System debugging&lt;br /&gt;
* [[OpenCode in Android Termux 260303]] — OpenCode in Android&lt;br /&gt;
* [[OpenCoder Qwen35 Agentic Setup 260330]] — Qwen3.5 agentic setup: Modelfile, tool calling fix, storage impact&lt;br /&gt;
* [[Lora Basics 260304]] — LORA research&lt;br /&gt;
* [https://github.com/anomalyco/opencode/issues/4283#issuecomment-4083399210 Opencode Copy-paste Clipboard doesnt Work - Solution]   https://github.com/anomalyco/opencode/issues/4283#issuecomment-4083399210&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Research ==&lt;br /&gt;
&amp;lt;div style=&amp;quot;column-count:2; column-gap:2em;&amp;quot;&amp;gt;&lt;br /&gt;
* [[Ladybird Browser]] — Browser engine development&lt;br /&gt;
* [[Computing Architecture]] — System design principles&lt;br /&gt;
* [[Backblaze Drive Stats for Server and Storage Qualification 260219]] — Drive reliability analysis&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== For Users Only ==&lt;br /&gt;
* [[Private:Private Ngani]]&lt;br /&gt;
* [[Private:Private Nganipart2]]&lt;br /&gt;
&lt;br /&gt;
== CIT-OJT Project Documentations ==&lt;br /&gt;
* [[OJTDocs: For OJTs only]]&lt;br /&gt;
&lt;br /&gt;
== Need Help? ==&lt;br /&gt;
&amp;lt;div style=&amp;quot;column-count:2; column-gap:2em;&amp;quot;&amp;gt;&lt;br /&gt;
* [[Troubleshooting: Access &amp;amp; Permission Issues]]&lt;br /&gt;
* [https://www.mediawiki.org/wiki/Special:MyLanguage/Help:Contents MediaWiki User&#039;s Guide]&lt;br /&gt;
* [https://www.mediawiki.org/wiki/Special:MyLanguage/Manual:Configuration_settings Configuration settings]&lt;br /&gt;
* [https://www.mediawiki.org/wiki/Special:MyLanguage/Manual:FAQ MediaWiki FAQ]&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;/div&gt;</summary>
		<author><name>Justinaquino</name></author>
	</entry>
	<entry>
		<id>https://mediawiki.comfac.net/index.php?title=Main_Page&amp;diff=283</id>
		<title>Main Page</title>
		<link rel="alternate" type="text/html" href="https://mediawiki.comfac.net/index.php?title=Main_Page&amp;diff=283"/>
		<updated>2026-08-28T15:42:34Z</updated>

		<summary type="html">&lt;p&gt;Justinaquino: Topic link: Nextcloud App Development Workshop 260825&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__NOTOC__&lt;br /&gt;
&amp;lt;div style=&amp;quot;background:#f8f9fa; border:1px solid #ddd; border-radius:4px; padding:12px 16px; margin-bottom:20px;&amp;quot;&amp;gt;&lt;br /&gt;
Welcome to the &#039;&#039;&#039;Comfac IT Knowledge Base&#039;&#039;&#039;. Use the sections below to find guides, SOPs, and references organized by topic.&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== New Articles ==&lt;br /&gt;
&lt;br /&gt;
Recent additions to this wiki, newest first — each is also filed in its permanent topic section below. &#039;&#039;&#039;Keep this list to the 10 most recent&#039;&#039;&#039; and prune as new pages are added; nothing is deleted, entries just roll off the feed.&lt;br /&gt;
* 2026-08-28 — &#039;&#039;&#039;[[Nextcloud App Development Workshop 260825]]&#039;&#039;&#039; — Beginner workshop (Anna Larch, Nextcloud DevRel): OCP vs OC, request lifecycle, entities/migrations/indices, events, background jobs, app-store submission — &#039;&#039;Filed under: System Administration &amp;amp; Self-Hosting&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* 2026-08-09 — &#039;&#039;&#039;[[SOP: Third-Party Software Security Review]]&#039;&#039;&#039; — due-diligence workflow for GitHub/OSS code (data-leak focus) + first review result: offline-browser-translate, CLEAN WITH CONDITIONS — &#039;&#039;Filed under: IT Operations &amp;amp; SOPs&#039;&#039;&lt;br /&gt;
* 2026-08-02 — &#039;&#039;&#039;[[Hugging Face Practical Guide 260802]]&#039;&#039;&#039; — Spaces, local app builds, the Model Hub / dataset viewer, and the enterprise compute tier; the route from stock models to tailored ones and to training on our own data — &#039;&#039;Filed under: AI &amp;amp; Machine Learning&#039;&#039;&lt;br /&gt;
* 2026-08-01 — &#039;&#039;&#039;[[Audio Learning]]&#039;&#039;&#039; — Converting research and study material into scripts written to be listened to rather than read; shared Comfac tool — &#039;&#039;Filed under: Tools &amp;amp; Productivity&#039;&#039;&lt;br /&gt;
* 2026-07-31 — &#039;&#039;&#039;[[Resume CV Renamer Pipeline]]&#039;&#039;&#039; — CV intake → OCR / vision-OCR → AI field extraction → date-stamped rename + VCF export — &#039;&#039;Filed under: Tools &amp;amp; Productivity&#039;&#039;&lt;br /&gt;
* 2026-07-15 — &#039;&#039;&#039;[[De-Risk: Sovereign Training Data v0.1]]&#039;&#039;&#039; — Frontier-Token Quarantine and the ToS-clean path to owned model weights, prompted by the June 2026 Fable 5 export-control suspension — &#039;&#039;Filed under: AI &amp;amp; Machine Learning&#039;&#039;&lt;br /&gt;
* 2026-07-15 — &#039;&#039;&#039;[[Directed Execution: Token-Efficient Agent Development Process]]&#039;&#039;&#039; — Director/Executor/Checker loop and skill distillation for token-efficient agent development — &#039;&#039;Filed under: AI &amp;amp; Machine Learning&#039;&#039;&lt;br /&gt;
* 2026-07-11 — &#039;&#039;&#039;[[Tutorial: Exposing a Dockerized Web App via NPM Direct DB Config]]&#039;&#039;&#039; — Expose a Dockerized web app by editing Nginx Proxy Manager&#039;s database directly — &#039;&#039;Filed under: System Administration &amp;amp; Self-Hosting&#039;&#039;&lt;br /&gt;
* 2026-05-02 — &#039;&#039;&#039;[[Organizing Coder Terminals]]&#039;&#039;&#039; — Tmux + dynamic titles for managing multiple AI agent terminals — &#039;&#039;Filed under: System Administration &amp;amp; Self-Hosting&#039;&#039;&lt;br /&gt;
* 2026-04-28 — &#039;&#039;&#039;[[Forgejo Pages]]&#039;&#039;&#039;&lt;br /&gt;
* 2026-04-24 — &#039;&#039;&#039;[[Buzz Transcription]]&#039;&#039;&#039; — Offline audio/meeting transcription via Whisper (whisper.cpp), Flatpak + Vulkan GPU acceleration — &#039;&#039;Filed under: Tools &amp;amp; Productivity&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== Newest Pages (auto) ==&lt;br /&gt;
&lt;br /&gt;
The 10 most recently created pages — maintains itself.&lt;br /&gt;
&lt;br /&gt;
{{Special:NewPages/10}}&lt;br /&gt;
&lt;br /&gt;
== ERPNext / Frappe ==&lt;br /&gt;
&amp;lt;div style=&amp;quot;column-count:2; column-gap:2em;&amp;quot;&amp;gt;&lt;br /&gt;
* [[Nextcloud App Development Workshop 260825]] — Beginner workshop (Anna Larch, Nextcloud DevRel, 2026-08-25)&lt;br /&gt;
* [[Frappe HRMS]] — &#039;&#039;&#039;HR &amp;amp; Payroll&#039;&#039;&#039; (with Philippine Localization)&lt;br /&gt;
* [[Frappe ERPNext/Webshop]] — &#039;&#039;&#039;E-Commerce Webshop&#039;&#039;&#039; (setup, architecture, chapters)&lt;br /&gt;
* [[Manufacturing v16 260125]]&lt;br /&gt;
* [[ERpnext Asset Management Procedure 260113]]&lt;br /&gt;
* [[ERPNext HR Module Outline]]&lt;br /&gt;
* [[ERPNEXT Payroll POC 251212]]&lt;br /&gt;
* [[Comfac ERPNext Strategy Canvas (Expanded)]]&lt;br /&gt;
* [[PAD-Driven ERPNext Strategy 260303]] — PAD/AI-agentic implementation strategy for Frappe ERPNext&lt;br /&gt;
* [[ERPNext v15 Docker Setup Guide]] — Local Docker setup for evaluation, testing, and student use&lt;br /&gt;
* [[Frappe Links and References]]&lt;br /&gt;
* [[Using Frappe Wiki]]&lt;br /&gt;
* [https://docs.frappe.io/cloud/guidelines-for-contributing-regional-compliance-app Guidelines for Contributing Regional Compliance App]&lt;br /&gt;
* [https://docs.frappe.io/cloud/what-are-benches-and-bench-groups What are Benches?]&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== System Administration &amp;amp; Self-Hosting ==&lt;br /&gt;
&amp;lt;div style=&amp;quot;column-count:2; column-gap:2em;&amp;quot;&amp;gt;&lt;br /&gt;
* [[Networking PfSense Index]] — Consolidated index of all networking, pfSense, DNS, and infrastructure guides&lt;br /&gt;
* [[System Hardening Strategy: Win2Lin Migration &amp;amp; Infrastructure 251129]]&lt;br /&gt;
* [[Controller Systems 251213-01]]&lt;br /&gt;
* [[Power Distribution Tree 251213]]&lt;br /&gt;
* [[Introduction: Why Self-Host Your Email?]]&lt;br /&gt;
* [[Mailcow + Thunderbird Setup Guide (Email + Calendar)]]&lt;br /&gt;
* [[Mailcow SOGo: Creating Filters for Events, Approvals, and Organizational Emails]]&lt;br /&gt;
* [[Spoof Timezone Extension – Setup Guide for Comfac Staff]]&lt;br /&gt;
* [[Viber Focus-Stealing]]&lt;br /&gt;
* [[🌐 WordPress Website — *You Own Everything, Learn Everything*]]&lt;br /&gt;
* [[Portainer to Docker Compose Migration Guide]]&lt;br /&gt;
* [[Organizing Coder Terminals]] — Tmux + dynamic titles for managing multiple AI agent terminals&lt;br /&gt;
* [[Editing Mastodon Docker Deployment Guide 260402]]&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Storage &amp;amp; Hardware ==&lt;br /&gt;
&amp;lt;div style=&amp;quot;column-count:2; column-gap:2em;&amp;quot;&amp;gt;&lt;br /&gt;
* [[TrueNAS Configuration Options &amp;amp; Scale Options 251130]]&lt;br /&gt;
* [[TrueNAS Business Plan: Project 251212]]&lt;br /&gt;
* [[Comparison: TrueNAS Mini X+ vs Dell Precision 3680 Tower (2025)]]&lt;br /&gt;
* [[Backblaze Drive Stats for Server and Storage Qualification]]&lt;br /&gt;
* [[Industrial Controllers and Water Utilities 251011]]&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== AI &amp;amp; Machine Learning ==&lt;br /&gt;
&amp;lt;div style=&amp;quot;column-count:2; column-gap:2em;&amp;quot;&amp;gt;&lt;br /&gt;
* [[OpenWebUI - 251128-justin]]&lt;br /&gt;
* [[Comfac GPU Scaling and AI Research Goals]]&lt;br /&gt;
* [[🧠 Process: Selecting and Installing the Right Ollama Model for Your Hardware]]&lt;br /&gt;
* [[Ollama GNOME System Tray Panel 260401]] — GNOME system tray toggle to start/stop Ollama and reclaim VRAM&lt;br /&gt;
* [[Proceedural Agentic Development Methodology 260304]] — Methodology for systematic agent use&lt;br /&gt;
* [[Project OpenCoder: AI Independence Initiative]] — Strategic roadmap for manufacturing intelligence&lt;br /&gt;
* [[OpenCoder Qwen35 Agentic Setup 260330]] — Qwen3.5 Modelfile fix for tool calling in OpenCode; thinking mode suppression; HDD vs SSD findings&lt;br /&gt;
* [[OpenCode Multi-Provider Configuration Guide 260401]] — Dual-mode AI coding setup with Kimi cloud + Ollama local models via Distrobox&lt;br /&gt;
* [[PAD-Driven ERPNext Strategy 260303]] — Procedural Agentic Development for Frappe/ERPNext configuration and deployment&lt;br /&gt;
* [[Directed Execution: Token-Efficient Agent Development Process]] — Director/Executor/Checker loop and skill distillation for token-efficient agent development (v0.1, 2026-07-15)&lt;br /&gt;
* [[De-Risk: Sovereign Training Data v0.1]] — Frontier-Token Quarantine and the ToS-clean path to owned model weights, prompted by the June 2026 Fable 5 export-control suspension (v0.1, 2026-07-15)&lt;br /&gt;
* [[Hugging Face Practical Guide 260802]] — Spaces, local app builds, the Model Hub / dataset viewer, and the enterprise compute tier; the route from stock models to tailored ones and to training on our own data (2026-08-02)&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Job Descriptions ==&lt;br /&gt;
&amp;lt;div style=&amp;quot;column-count:2; column-gap:2em;&amp;quot;&amp;gt;&lt;br /&gt;
* [[Job Descriptions]] — Index of all official job descriptions (IT, Engineering, Sales)&lt;br /&gt;
* [[JD IT Project Staff]] — IT Project Staff&lt;br /&gt;
* [[JD Security Compliance Assistant 260224]] — Security and Compliance Assistant (SCA)&lt;br /&gt;
* [[JD Engineering Designer 260108]] — Engineering Designer&lt;br /&gt;
* [[JD Engineering Supervisor 260109]] — Engineering Supervisor&lt;br /&gt;
* [[JD Technical Sales 260112]] — Technical Sales Engineer&lt;br /&gt;
* [[JD Marketing Assistant 251119]] — Marketing Assistant&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== IT Operations &amp;amp; SOPs ==&lt;br /&gt;
&amp;lt;div style=&amp;quot;column-count:2; column-gap:2em;&amp;quot;&amp;gt;&lt;br /&gt;
* [[SOP: Third-Party Software Security Review]] — vet GitHub/OSS code for data leakage and exploits before install; workflow, criteria, and review log&lt;br /&gt;
* [[SCA Program Plan 260320]] — Security &amp;amp; Compliance Assistant Program Plan v3 (ISO 9001/27001, PDCA, distributed audit model)&lt;br /&gt;
* [[SOP: Inter-Company Ordering and Production Process 260203]] — Ordering and production workflow between Sister Companies and the Cabuyao Plant&lt;br /&gt;
* [[Memo: Team Roles &amp;amp; Reporting Process Clarification 260320]] — Role boundaries, data ownership, and the new ERPNext-driven reporting paradigm&lt;br /&gt;
* [[Standard Operating Procedure: Distributed Minute Taking &amp;amp; Task Ownership 251208]]&lt;br /&gt;
* [[Business Continuity]]&lt;br /&gt;
* [[Procedure: CC-Blast Data Breach Prevention]]&lt;br /&gt;
* [[8D (Eight Discipline) Problem Solving Procedure]]&lt;br /&gt;
* [[Offline Malware Remediation &amp;amp; Data Recovery]]&lt;br /&gt;
* [[Troubleshooting: Access &amp;amp; Permission Issues]]&lt;br /&gt;
* [[Steps to Repair and OCR a Scanned or Corrupted PDF in Ubuntu]]&lt;br /&gt;
* [[IT IMPORTS PROCESSES]]&lt;br /&gt;
* [[IT Purchase Requests 241126]]&lt;br /&gt;
* [[IT REQUEST (OP-ERP-ITR) - EDITED 250801]]&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Sales &amp;amp; Business ==&lt;br /&gt;
&amp;lt;div style=&amp;quot;column-count:2; column-gap:2em;&amp;quot;&amp;gt;&lt;br /&gt;
* [[Comfac Sales Knowledge Base]]&lt;br /&gt;
* [[Comfac CRM – Customer Qualification &amp;amp; Conversion Process]]&lt;br /&gt;
* [[Partner Reseller Pricing 251109]]&lt;br /&gt;
* [[Biz Analysis Methodology 251109]]&lt;br /&gt;
* [[2026 MIS IT KRA KPI Biz Plan]]&lt;br /&gt;
* [[SALES INVOICE TAX OUTPUT 250829]]&lt;br /&gt;
* [[Projects in Process Report 251023]]&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Tools &amp;amp; Productivity ==&lt;br /&gt;
&amp;lt;div style=&amp;quot;column-count:2; column-gap:2em;&amp;quot;&amp;gt;&lt;br /&gt;
* [[Excel Description Filler Tool 📝]]&lt;br /&gt;
* [[Resume CV Renamer Pipeline|Resume / CV Renamer Pipeline]] — CV intake → OCR / vision-OCR → AI field extraction → date-stamped rename + VCF export&lt;br /&gt;
* [https://github.com/Comfac-Global-Group/comfac-studies Comfac Studies - Spaced Repetiton Active Recall]&lt;br /&gt;
* [[LibreOffice / Nextcloud Office – &amp;quot;Due Tasks&amp;quot; Conditional Formatting]]&lt;br /&gt;
* [[Google Drive and Shared Drive Training]]&lt;br /&gt;
* [[260108 CGG- GitHub Administration Guide]]&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Wiki &amp;amp; Documentation ==&lt;br /&gt;
&amp;lt;div style=&amp;quot;column-count:2; column-gap:2em;&amp;quot;&amp;gt;&lt;br /&gt;
* [[Mediawiki Setting Up Guide]]&lt;br /&gt;
* [[Contributing to Only Office 260307]]&lt;br /&gt;
* [[Mediawiki Additional Configuration]]&lt;br /&gt;
* [[Mediawiki Docker Migration Guide]]&lt;br /&gt;
* [[Home]]&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Tutorials ==&lt;br /&gt;
&amp;lt;div style=&amp;quot;column-count:2; column-gap:2em;&amp;quot;&amp;gt;&lt;br /&gt;
* [[Claude Code Isolation and Burner Workflow 260211]] — Secure AI development environment setup&lt;br /&gt;
* [[Opencode isolation and burner workflow 260216]] — OpenCode CLI isolation procedures&lt;br /&gt;
* [[LibreOffice Calc NumToWords Extension Complete Guide]] — Extension development&lt;br /&gt;
* [[ERPNext v15 Docker Setup Guide]] — ERPNext v15 local Docker setup (students, evaluators, thin-client demos)&lt;br /&gt;
* [[Erpnextv15-SSH-setup-241111]] — ERPNext v15 SSH/Portainer production setup&lt;br /&gt;
* [[Git-Mediawiki Local Editing 260223]] — Wiki editing with Git&lt;br /&gt;
* [[Understanding &amp;amp; Fixing Kernel Panics 260212]] — System debugging&lt;br /&gt;
* [[OpenCode in Android Termux 260303]] — OpenCode in Android&lt;br /&gt;
* [[OpenCoder Qwen35 Agentic Setup 260330]] — Qwen3.5 agentic setup: Modelfile, tool calling fix, storage impact&lt;br /&gt;
* [[Lora Basics 260304]] — LORA research&lt;br /&gt;
* [https://github.com/anomalyco/opencode/issues/4283#issuecomment-4083399210 Opencode Copy-paste Clipboard doesnt Work - Solution]   https://github.com/anomalyco/opencode/issues/4283#issuecomment-4083399210&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Research ==&lt;br /&gt;
&amp;lt;div style=&amp;quot;column-count:2; column-gap:2em;&amp;quot;&amp;gt;&lt;br /&gt;
* [[Ladybird Browser]] — Browser engine development&lt;br /&gt;
* [[Computing Architecture]] — System design principles&lt;br /&gt;
* [[Backblaze Drive Stats for Server and Storage Qualification 260219]] — Drive reliability analysis&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== For Users Only ==&lt;br /&gt;
* [[Private:Private Ngani]]&lt;br /&gt;
* [[Private:Private Nganipart2]]&lt;br /&gt;
&lt;br /&gt;
== CIT-OJT Project Documentations ==&lt;br /&gt;
* [[OJTDocs: For OJTs only]]&lt;br /&gt;
&lt;br /&gt;
== Need Help? ==&lt;br /&gt;
&amp;lt;div style=&amp;quot;column-count:2; column-gap:2em;&amp;quot;&amp;gt;&lt;br /&gt;
* [[Troubleshooting: Access &amp;amp; Permission Issues]]&lt;br /&gt;
* [https://www.mediawiki.org/wiki/Special:MyLanguage/Help:Contents MediaWiki User&#039;s Guide]&lt;br /&gt;
* [https://www.mediawiki.org/wiki/Special:MyLanguage/Manual:Configuration_settings Configuration settings]&lt;br /&gt;
* [https://www.mediawiki.org/wiki/Special:MyLanguage/Manual:FAQ MediaWiki FAQ]&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;/div&gt;</summary>
		<author><name>Justinaquino</name></author>
	</entry>
	<entry>
		<id>https://mediawiki.comfac.net/index.php?title=Main_Page&amp;diff=282</id>
		<title>Main Page</title>
		<link rel="alternate" type="text/html" href="https://mediawiki.comfac.net/index.php?title=Main_Page&amp;diff=282"/>
		<updated>2026-08-28T15:42:29Z</updated>

		<summary type="html">&lt;p&gt;Justinaquino: Feed: Nextcloud App Development Workshop 260825&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__NOTOC__&lt;br /&gt;
&amp;lt;div style=&amp;quot;background:#f8f9fa; border:1px solid #ddd; border-radius:4px; padding:12px 16px; margin-bottom:20px;&amp;quot;&amp;gt;&lt;br /&gt;
Welcome to the &#039;&#039;&#039;Comfac IT Knowledge Base&#039;&#039;&#039;. Use the sections below to find guides, SOPs, and references organized by topic.&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== New Articles ==&lt;br /&gt;
&lt;br /&gt;
Recent additions to this wiki, newest first — each is also filed in its permanent topic section below. &#039;&#039;&#039;Keep this list to the 10 most recent&#039;&#039;&#039; and prune as new pages are added; nothing is deleted, entries just roll off the feed.&lt;br /&gt;
* 2026-08-28 — &#039;&#039;&#039;[[Nextcloud App Development Workshop 260825]]&#039;&#039;&#039; — Beginner workshop (Anna Larch, Nextcloud DevRel): OCP vs OC, request lifecycle, entities/migrations/indices, events, background jobs, app-store submission — &#039;&#039;Filed under: System Administration &amp;amp; Self-Hosting&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* 2026-08-09 — &#039;&#039;&#039;[[SOP: Third-Party Software Security Review]]&#039;&#039;&#039; — due-diligence workflow for GitHub/OSS code (data-leak focus) + first review result: offline-browser-translate, CLEAN WITH CONDITIONS — &#039;&#039;Filed under: IT Operations &amp;amp; SOPs&#039;&#039;&lt;br /&gt;
* 2026-08-02 — &#039;&#039;&#039;[[Hugging Face Practical Guide 260802]]&#039;&#039;&#039; — Spaces, local app builds, the Model Hub / dataset viewer, and the enterprise compute tier; the route from stock models to tailored ones and to training on our own data — &#039;&#039;Filed under: AI &amp;amp; Machine Learning&#039;&#039;&lt;br /&gt;
* 2026-08-01 — &#039;&#039;&#039;[[Audio Learning]]&#039;&#039;&#039; — Converting research and study material into scripts written to be listened to rather than read; shared Comfac tool — &#039;&#039;Filed under: Tools &amp;amp; Productivity&#039;&#039;&lt;br /&gt;
* 2026-07-31 — &#039;&#039;&#039;[[Resume CV Renamer Pipeline]]&#039;&#039;&#039; — CV intake → OCR / vision-OCR → AI field extraction → date-stamped rename + VCF export — &#039;&#039;Filed under: Tools &amp;amp; Productivity&#039;&#039;&lt;br /&gt;
* 2026-07-15 — &#039;&#039;&#039;[[De-Risk: Sovereign Training Data v0.1]]&#039;&#039;&#039; — Frontier-Token Quarantine and the ToS-clean path to owned model weights, prompted by the June 2026 Fable 5 export-control suspension — &#039;&#039;Filed under: AI &amp;amp; Machine Learning&#039;&#039;&lt;br /&gt;
* 2026-07-15 — &#039;&#039;&#039;[[Directed Execution: Token-Efficient Agent Development Process]]&#039;&#039;&#039; — Director/Executor/Checker loop and skill distillation for token-efficient agent development — &#039;&#039;Filed under: AI &amp;amp; Machine Learning&#039;&#039;&lt;br /&gt;
* 2026-07-11 — &#039;&#039;&#039;[[Tutorial: Exposing a Dockerized Web App via NPM Direct DB Config]]&#039;&#039;&#039; — Expose a Dockerized web app by editing Nginx Proxy Manager&#039;s database directly — &#039;&#039;Filed under: System Administration &amp;amp; Self-Hosting&#039;&#039;&lt;br /&gt;
* 2026-05-02 — &#039;&#039;&#039;[[Organizing Coder Terminals]]&#039;&#039;&#039; — Tmux + dynamic titles for managing multiple AI agent terminals — &#039;&#039;Filed under: System Administration &amp;amp; Self-Hosting&#039;&#039;&lt;br /&gt;
* 2026-04-28 — &#039;&#039;&#039;[[Forgejo Pages]]&#039;&#039;&#039;&lt;br /&gt;
* 2026-04-24 — &#039;&#039;&#039;[[Buzz Transcription]]&#039;&#039;&#039; — Offline audio/meeting transcription via Whisper (whisper.cpp), Flatpak + Vulkan GPU acceleration — &#039;&#039;Filed under: Tools &amp;amp; Productivity&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== Newest Pages (auto) ==&lt;br /&gt;
&lt;br /&gt;
The 10 most recently created pages — maintains itself.&lt;br /&gt;
&lt;br /&gt;
{{Special:NewPages/10}}&lt;br /&gt;
&lt;br /&gt;
== ERPNext / Frappe ==&lt;br /&gt;
&amp;lt;div style=&amp;quot;column-count:2; column-gap:2em;&amp;quot;&amp;gt;&lt;br /&gt;
* [[Frappe HRMS]] — &#039;&#039;&#039;HR &amp;amp; Payroll&#039;&#039;&#039; (with Philippine Localization)&lt;br /&gt;
* [[Frappe ERPNext/Webshop]] — &#039;&#039;&#039;E-Commerce Webshop&#039;&#039;&#039; (setup, architecture, chapters)&lt;br /&gt;
* [[Manufacturing v16 260125]]&lt;br /&gt;
* [[ERpnext Asset Management Procedure 260113]]&lt;br /&gt;
* [[ERPNext HR Module Outline]]&lt;br /&gt;
* [[ERPNEXT Payroll POC 251212]]&lt;br /&gt;
* [[Comfac ERPNext Strategy Canvas (Expanded)]]&lt;br /&gt;
* [[PAD-Driven ERPNext Strategy 260303]] — PAD/AI-agentic implementation strategy for Frappe ERPNext&lt;br /&gt;
* [[ERPNext v15 Docker Setup Guide]] — Local Docker setup for evaluation, testing, and student use&lt;br /&gt;
* [[Frappe Links and References]]&lt;br /&gt;
* [[Using Frappe Wiki]]&lt;br /&gt;
* [https://docs.frappe.io/cloud/guidelines-for-contributing-regional-compliance-app Guidelines for Contributing Regional Compliance App]&lt;br /&gt;
* [https://docs.frappe.io/cloud/what-are-benches-and-bench-groups What are Benches?]&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== System Administration &amp;amp; Self-Hosting ==&lt;br /&gt;
&amp;lt;div style=&amp;quot;column-count:2; column-gap:2em;&amp;quot;&amp;gt;&lt;br /&gt;
* [[Networking PfSense Index]] — Consolidated index of all networking, pfSense, DNS, and infrastructure guides&lt;br /&gt;
* [[System Hardening Strategy: Win2Lin Migration &amp;amp; Infrastructure 251129]]&lt;br /&gt;
* [[Controller Systems 251213-01]]&lt;br /&gt;
* [[Power Distribution Tree 251213]]&lt;br /&gt;
* [[Introduction: Why Self-Host Your Email?]]&lt;br /&gt;
* [[Mailcow + Thunderbird Setup Guide (Email + Calendar)]]&lt;br /&gt;
* [[Mailcow SOGo: Creating Filters for Events, Approvals, and Organizational Emails]]&lt;br /&gt;
* [[Spoof Timezone Extension – Setup Guide for Comfac Staff]]&lt;br /&gt;
* [[Viber Focus-Stealing]]&lt;br /&gt;
* [[🌐 WordPress Website — *You Own Everything, Learn Everything*]]&lt;br /&gt;
* [[Portainer to Docker Compose Migration Guide]]&lt;br /&gt;
* [[Organizing Coder Terminals]] — Tmux + dynamic titles for managing multiple AI agent terminals&lt;br /&gt;
* [[Editing Mastodon Docker Deployment Guide 260402]]&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Storage &amp;amp; Hardware ==&lt;br /&gt;
&amp;lt;div style=&amp;quot;column-count:2; column-gap:2em;&amp;quot;&amp;gt;&lt;br /&gt;
* [[TrueNAS Configuration Options &amp;amp; Scale Options 251130]]&lt;br /&gt;
* [[TrueNAS Business Plan: Project 251212]]&lt;br /&gt;
* [[Comparison: TrueNAS Mini X+ vs Dell Precision 3680 Tower (2025)]]&lt;br /&gt;
* [[Backblaze Drive Stats for Server and Storage Qualification]]&lt;br /&gt;
* [[Industrial Controllers and Water Utilities 251011]]&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== AI &amp;amp; Machine Learning ==&lt;br /&gt;
&amp;lt;div style=&amp;quot;column-count:2; column-gap:2em;&amp;quot;&amp;gt;&lt;br /&gt;
* [[OpenWebUI - 251128-justin]]&lt;br /&gt;
* [[Comfac GPU Scaling and AI Research Goals]]&lt;br /&gt;
* [[🧠 Process: Selecting and Installing the Right Ollama Model for Your Hardware]]&lt;br /&gt;
* [[Ollama GNOME System Tray Panel 260401]] — GNOME system tray toggle to start/stop Ollama and reclaim VRAM&lt;br /&gt;
* [[Proceedural Agentic Development Methodology 260304]] — Methodology for systematic agent use&lt;br /&gt;
* [[Project OpenCoder: AI Independence Initiative]] — Strategic roadmap for manufacturing intelligence&lt;br /&gt;
* [[OpenCoder Qwen35 Agentic Setup 260330]] — Qwen3.5 Modelfile fix for tool calling in OpenCode; thinking mode suppression; HDD vs SSD findings&lt;br /&gt;
* [[OpenCode Multi-Provider Configuration Guide 260401]] — Dual-mode AI coding setup with Kimi cloud + Ollama local models via Distrobox&lt;br /&gt;
* [[PAD-Driven ERPNext Strategy 260303]] — Procedural Agentic Development for Frappe/ERPNext configuration and deployment&lt;br /&gt;
* [[Directed Execution: Token-Efficient Agent Development Process]] — Director/Executor/Checker loop and skill distillation for token-efficient agent development (v0.1, 2026-07-15)&lt;br /&gt;
* [[De-Risk: Sovereign Training Data v0.1]] — Frontier-Token Quarantine and the ToS-clean path to owned model weights, prompted by the June 2026 Fable 5 export-control suspension (v0.1, 2026-07-15)&lt;br /&gt;
* [[Hugging Face Practical Guide 260802]] — Spaces, local app builds, the Model Hub / dataset viewer, and the enterprise compute tier; the route from stock models to tailored ones and to training on our own data (2026-08-02)&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Job Descriptions ==&lt;br /&gt;
&amp;lt;div style=&amp;quot;column-count:2; column-gap:2em;&amp;quot;&amp;gt;&lt;br /&gt;
* [[Job Descriptions]] — Index of all official job descriptions (IT, Engineering, Sales)&lt;br /&gt;
* [[JD IT Project Staff]] — IT Project Staff&lt;br /&gt;
* [[JD Security Compliance Assistant 260224]] — Security and Compliance Assistant (SCA)&lt;br /&gt;
* [[JD Engineering Designer 260108]] — Engineering Designer&lt;br /&gt;
* [[JD Engineering Supervisor 260109]] — Engineering Supervisor&lt;br /&gt;
* [[JD Technical Sales 260112]] — Technical Sales Engineer&lt;br /&gt;
* [[JD Marketing Assistant 251119]] — Marketing Assistant&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== IT Operations &amp;amp; SOPs ==&lt;br /&gt;
&amp;lt;div style=&amp;quot;column-count:2; column-gap:2em;&amp;quot;&amp;gt;&lt;br /&gt;
* [[SOP: Third-Party Software Security Review]] — vet GitHub/OSS code for data leakage and exploits before install; workflow, criteria, and review log&lt;br /&gt;
* [[SCA Program Plan 260320]] — Security &amp;amp; Compliance Assistant Program Plan v3 (ISO 9001/27001, PDCA, distributed audit model)&lt;br /&gt;
* [[SOP: Inter-Company Ordering and Production Process 260203]] — Ordering and production workflow between Sister Companies and the Cabuyao Plant&lt;br /&gt;
* [[Memo: Team Roles &amp;amp; Reporting Process Clarification 260320]] — Role boundaries, data ownership, and the new ERPNext-driven reporting paradigm&lt;br /&gt;
* [[Standard Operating Procedure: Distributed Minute Taking &amp;amp; Task Ownership 251208]]&lt;br /&gt;
* [[Business Continuity]]&lt;br /&gt;
* [[Procedure: CC-Blast Data Breach Prevention]]&lt;br /&gt;
* [[8D (Eight Discipline) Problem Solving Procedure]]&lt;br /&gt;
* [[Offline Malware Remediation &amp;amp; Data Recovery]]&lt;br /&gt;
* [[Troubleshooting: Access &amp;amp; Permission Issues]]&lt;br /&gt;
* [[Steps to Repair and OCR a Scanned or Corrupted PDF in Ubuntu]]&lt;br /&gt;
* [[IT IMPORTS PROCESSES]]&lt;br /&gt;
* [[IT Purchase Requests 241126]]&lt;br /&gt;
* [[IT REQUEST (OP-ERP-ITR) - EDITED 250801]]&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Sales &amp;amp; Business ==&lt;br /&gt;
&amp;lt;div style=&amp;quot;column-count:2; column-gap:2em;&amp;quot;&amp;gt;&lt;br /&gt;
* [[Comfac Sales Knowledge Base]]&lt;br /&gt;
* [[Comfac CRM – Customer Qualification &amp;amp; Conversion Process]]&lt;br /&gt;
* [[Partner Reseller Pricing 251109]]&lt;br /&gt;
* [[Biz Analysis Methodology 251109]]&lt;br /&gt;
* [[2026 MIS IT KRA KPI Biz Plan]]&lt;br /&gt;
* [[SALES INVOICE TAX OUTPUT 250829]]&lt;br /&gt;
* [[Projects in Process Report 251023]]&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Tools &amp;amp; Productivity ==&lt;br /&gt;
&amp;lt;div style=&amp;quot;column-count:2; column-gap:2em;&amp;quot;&amp;gt;&lt;br /&gt;
* [[Excel Description Filler Tool 📝]]&lt;br /&gt;
* [[Resume CV Renamer Pipeline|Resume / CV Renamer Pipeline]] — CV intake → OCR / vision-OCR → AI field extraction → date-stamped rename + VCF export&lt;br /&gt;
* [https://github.com/Comfac-Global-Group/comfac-studies Comfac Studies - Spaced Repetiton Active Recall]&lt;br /&gt;
* [[LibreOffice / Nextcloud Office – &amp;quot;Due Tasks&amp;quot; Conditional Formatting]]&lt;br /&gt;
* [[Google Drive and Shared Drive Training]]&lt;br /&gt;
* [[260108 CGG- GitHub Administration Guide]]&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Wiki &amp;amp; Documentation ==&lt;br /&gt;
&amp;lt;div style=&amp;quot;column-count:2; column-gap:2em;&amp;quot;&amp;gt;&lt;br /&gt;
* [[Mediawiki Setting Up Guide]]&lt;br /&gt;
* [[Contributing to Only Office 260307]]&lt;br /&gt;
* [[Mediawiki Additional Configuration]]&lt;br /&gt;
* [[Mediawiki Docker Migration Guide]]&lt;br /&gt;
* [[Home]]&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Tutorials ==&lt;br /&gt;
&amp;lt;div style=&amp;quot;column-count:2; column-gap:2em;&amp;quot;&amp;gt;&lt;br /&gt;
* [[Claude Code Isolation and Burner Workflow 260211]] — Secure AI development environment setup&lt;br /&gt;
* [[Opencode isolation and burner workflow 260216]] — OpenCode CLI isolation procedures&lt;br /&gt;
* [[LibreOffice Calc NumToWords Extension Complete Guide]] — Extension development&lt;br /&gt;
* [[ERPNext v15 Docker Setup Guide]] — ERPNext v15 local Docker setup (students, evaluators, thin-client demos)&lt;br /&gt;
* [[Erpnextv15-SSH-setup-241111]] — ERPNext v15 SSH/Portainer production setup&lt;br /&gt;
* [[Git-Mediawiki Local Editing 260223]] — Wiki editing with Git&lt;br /&gt;
* [[Understanding &amp;amp; Fixing Kernel Panics 260212]] — System debugging&lt;br /&gt;
* [[OpenCode in Android Termux 260303]] — OpenCode in Android&lt;br /&gt;
* [[OpenCoder Qwen35 Agentic Setup 260330]] — Qwen3.5 agentic setup: Modelfile, tool calling fix, storage impact&lt;br /&gt;
* [[Lora Basics 260304]] — LORA research&lt;br /&gt;
* [https://github.com/anomalyco/opencode/issues/4283#issuecomment-4083399210 Opencode Copy-paste Clipboard doesnt Work - Solution]   https://github.com/anomalyco/opencode/issues/4283#issuecomment-4083399210&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Research ==&lt;br /&gt;
&amp;lt;div style=&amp;quot;column-count:2; column-gap:2em;&amp;quot;&amp;gt;&lt;br /&gt;
* [[Ladybird Browser]] — Browser engine development&lt;br /&gt;
* [[Computing Architecture]] — System design principles&lt;br /&gt;
* [[Backblaze Drive Stats for Server and Storage Qualification 260219]] — Drive reliability analysis&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== For Users Only ==&lt;br /&gt;
* [[Private:Private Ngani]]&lt;br /&gt;
* [[Private:Private Nganipart2]]&lt;br /&gt;
&lt;br /&gt;
== CIT-OJT Project Documentations ==&lt;br /&gt;
* [[OJTDocs: For OJTs only]]&lt;br /&gt;
&lt;br /&gt;
== Need Help? ==&lt;br /&gt;
&amp;lt;div style=&amp;quot;column-count:2; column-gap:2em;&amp;quot;&amp;gt;&lt;br /&gt;
* [[Troubleshooting: Access &amp;amp; Permission Issues]]&lt;br /&gt;
* [https://www.mediawiki.org/wiki/Special:MyLanguage/Help:Contents MediaWiki User&#039;s Guide]&lt;br /&gt;
* [https://www.mediawiki.org/wiki/Special:MyLanguage/Manual:Configuration_settings Configuration settings]&lt;br /&gt;
* [https://www.mediawiki.org/wiki/Special:MyLanguage/Manual:FAQ MediaWiki FAQ]&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;/div&gt;</summary>
		<author><name>Justinaquino</name></author>
	</entry>
	<entry>
		<id>https://mediawiki.comfac.net/index.php?title=Nextcloud_App_Development_Workshop_260825&amp;diff=281</id>
		<title>Nextcloud App Development Workshop 260825</title>
		<link rel="alternate" type="text/html" href="https://mediawiki.comfac.net/index.php?title=Nextcloud_App_Development_Workshop_260825&amp;diff=281"/>
		<updated>2026-08-28T15:41:38Z</updated>

		<summary type="html">&lt;p&gt;Justinaquino: Create: Nextcloud app dev beginner workshop 260825 (video BQlm71K1AVM)&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[https://youtu.be/BQlm71K1AVM &#039;&#039;&#039;Building your first Nextcloud app (beginner workshop)&#039;&#039;&#039; — watch on YouTube] (Nextcloud channel, 2026-08-25, 56 min)&lt;br /&gt;
&lt;br /&gt;
Presented by Anna Larch (Nextcloud Developer Relations, ex-Talk developer; security team), with Marcel Müller answering chat. Foundations of Nextcloud app development: where your code sits, what it may call, and how it talks to the rest of the server. Every example comes from a real app — Nextcloud Talk, Dashboard, Theming, and Files reminders.&lt;br /&gt;
&lt;br /&gt;
== Summary ==&lt;br /&gt;
* &#039;&#039;&#039;Public vs private API&#039;&#039;&#039; — build against &amp;lt;code&amp;gt;OCP\&amp;lt;/code&amp;gt; (stable, documented); &amp;lt;code&amp;gt;OC\&amp;lt;/code&amp;gt; is internal/legacy and can be removed between versions. Breaking changes to public APIs are announced ~5 major versions ahead. If it isn&#039;t in the developer manual, assume it can change.&lt;br /&gt;
* &#039;&#039;&#039;Request lifecycle&#039;&#039;&#039; — &amp;lt;code&amp;gt;index.php → routes → controller → service → mapper/DB → response&amp;lt;/code&amp;gt;. Auth, CSRF, and rate limiting run before the controller; brute-force throttling runs inside it. Controllers translate HTTP; business logic belongs in services.&lt;br /&gt;
* &#039;&#039;&#039;Dependency injection&#039;&#039;&#039; — type-hint interfaces (&amp;lt;code&amp;gt;private IStorage $storage&amp;lt;/code&amp;gt;); the container resolves what the instance actually uses. The &amp;lt;code&amp;gt;?string $userId&amp;lt;/code&amp;gt; pattern is a nullable, immutable, cheap-to-filter user identifier resolved from the login.&lt;br /&gt;
* &#039;&#039;&#039;Entities &amp;amp; type casting&#039;&#039;&#039; — cast entity fields explicitly (bool, DateTime) because MariaDB/MySQL/Oracle/PostgreSQL disagree on tinyint/boolean and datetime handling.&lt;br /&gt;
* &#039;&#039;&#039;Migrations&#039;&#039;&#039; — &amp;lt;code&amp;gt;preSchemaChange&amp;lt;/code&amp;gt; / &amp;lt;code&amp;gt;changeSchema&amp;lt;/code&amp;gt; / &amp;lt;code&amp;gt;postSchemaChange&amp;lt;/code&amp;gt;. Heavy data work goes into a one-time background job, never inline in an upgrade (her example: a 6–7 hour system-address-book update).&lt;br /&gt;
* &#039;&#039;&#039;Indices&#039;&#039;&#039; — add at table creation when possible; for existing large tables register a missing-index listener so the admin applies it via &amp;lt;code&amp;gt;occ&amp;lt;/code&amp;gt; in a maintenance window. Debug slow queries with &amp;lt;code&amp;gt;EXPLAIN&amp;lt;/code&amp;gt;.&lt;br /&gt;
* &#039;&#039;&#039;Event system&#039;&#039;&#039; — apps integrate by listening to core events (file created/modified/deleted, node updated), never by calling another app&#039;s code. Files reminders has no dependency on the Files app.&lt;br /&gt;
* &#039;&#039;&#039;Background jobs&#039;&#039;&#039; — extend &amp;lt;code&amp;gt;TimedJob&amp;lt;/code&amp;gt;; cron flavors are cron / webcron / ajax (ajax gives no time guarantee). Use the maintenance window with time-insensitive jobs for heavy syncs.&lt;br /&gt;
* &#039;&#039;&#039;Scale traps&#039;&#039;&#039; — use folder search with limit/offset instead of full tree loads; chunk &amp;lt;code&amp;gt;IN&amp;lt;/code&amp;gt; queries to 1,000 items (Oracle&#039;s limit); avoid N+1 queries; test on current + previous majors; profile with Blackfire.&lt;br /&gt;
* &#039;&#039;&#039;App store&#039;&#039;&#039; — validate info.xml, sign last, tarball = one top-level folder named the app ID, certificate request takes 2–4 days. Common rejections: CN/app-ID mismatch, bad archive structure, files changed after signing, invalid category.&lt;br /&gt;
&lt;br /&gt;
== Key takeaways ==&lt;br /&gt;
# Use only &amp;lt;code&amp;gt;OCP\&amp;lt;/code&amp;gt;; anything not in the developer manual can change.&lt;br /&gt;
# Controllers translate HTTP; services do the work; entities/mappers own the data — with type casting.&lt;br /&gt;
# Heavy work (migrations, tree walks, per-user loops) belongs in background jobs.&lt;br /&gt;
# Integrate via events, never by calling another app&#039;s code.&lt;br /&gt;
# Chunk &amp;lt;code&amp;gt;IN&amp;lt;/code&amp;gt; queries to 1,000 for Oracle; test against the previous major too.&lt;br /&gt;
# Sign last; the tarball must contain exactly one top-level folder named the app ID.&lt;br /&gt;
&lt;br /&gt;
== Resources ==&lt;br /&gt;
* Video: https://youtu.be/BQlm71K1AVM&lt;br /&gt;
* Nextcloud developer program and resources: https://nextcloud.com/developer/&lt;br /&gt;
* Developer documentation: https://docs.nextcloud.com&lt;br /&gt;
* Local transcript + study notes: &amp;lt;code&amp;gt;work/comfac-nextcloud/Audio Video/&amp;lt;/code&amp;gt; — &amp;lt;code&amp;gt;BQlm71K1AVM-structured.md&amp;lt;/code&amp;gt;, &amp;lt;code&amp;gt;BQlm71K1AVM-questions-details-needed.md&amp;lt;/code&amp;gt;&lt;/div&gt;</summary>
		<author><name>Justinaquino</name></author>
	</entry>
	<entry>
		<id>https://mediawiki.comfac.net/index.php?title=Main_Page&amp;diff=280</id>
		<title>Main Page</title>
		<link rel="alternate" type="text/html" href="https://mediawiki.comfac.net/index.php?title=Main_Page&amp;diff=280"/>
		<updated>2026-08-09T06:23:58Z</updated>

		<summary type="html">&lt;p&gt;Justinaquino: Feature SOP: Third-Party Software Security Review in New Articles and IT Operations &amp;amp; SOPs&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__NOTOC__&lt;br /&gt;
&amp;lt;div style=&amp;quot;background:#f8f9fa; border:1px solid #ddd; border-radius:4px; padding:12px 16px; margin-bottom:20px;&amp;quot;&amp;gt;&lt;br /&gt;
Welcome to the &#039;&#039;&#039;Comfac IT Knowledge Base&#039;&#039;&#039;. Use the sections below to find guides, SOPs, and references organized by topic.&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== New Articles ==&lt;br /&gt;
&lt;br /&gt;
Recent additions to this wiki, newest first — each is also filed in its permanent topic section below. &#039;&#039;&#039;Keep this list to the 10 most recent&#039;&#039;&#039; and prune as new pages are added; nothing is deleted, entries just roll off the feed.&lt;br /&gt;
&lt;br /&gt;
* 2026-08-09 — &#039;&#039;&#039;[[SOP: Third-Party Software Security Review]]&#039;&#039;&#039; — due-diligence workflow for GitHub/OSS code (data-leak focus) + first review result: offline-browser-translate, CLEAN WITH CONDITIONS — &#039;&#039;Filed under: IT Operations &amp;amp; SOPs&#039;&#039;&lt;br /&gt;
* 2026-08-02 — &#039;&#039;&#039;[[Hugging Face Practical Guide 260802]]&#039;&#039;&#039; — Spaces, local app builds, the Model Hub / dataset viewer, and the enterprise compute tier; the route from stock models to tailored ones and to training on our own data — &#039;&#039;Filed under: AI &amp;amp; Machine Learning&#039;&#039;&lt;br /&gt;
* 2026-08-01 — &#039;&#039;&#039;[[Audio Learning]]&#039;&#039;&#039; — Converting research and study material into scripts written to be listened to rather than read; shared Comfac tool — &#039;&#039;Filed under: Tools &amp;amp; Productivity&#039;&#039;&lt;br /&gt;
* 2026-07-31 — &#039;&#039;&#039;[[Resume CV Renamer Pipeline]]&#039;&#039;&#039; — CV intake → OCR / vision-OCR → AI field extraction → date-stamped rename + VCF export — &#039;&#039;Filed under: Tools &amp;amp; Productivity&#039;&#039;&lt;br /&gt;
* 2026-07-15 — &#039;&#039;&#039;[[De-Risk: Sovereign Training Data v0.1]]&#039;&#039;&#039; — Frontier-Token Quarantine and the ToS-clean path to owned model weights, prompted by the June 2026 Fable 5 export-control suspension — &#039;&#039;Filed under: AI &amp;amp; Machine Learning&#039;&#039;&lt;br /&gt;
* 2026-07-15 — &#039;&#039;&#039;[[Directed Execution: Token-Efficient Agent Development Process]]&#039;&#039;&#039; — Director/Executor/Checker loop and skill distillation for token-efficient agent development — &#039;&#039;Filed under: AI &amp;amp; Machine Learning&#039;&#039;&lt;br /&gt;
* 2026-07-11 — &#039;&#039;&#039;[[Tutorial: Exposing a Dockerized Web App via NPM Direct DB Config]]&#039;&#039;&#039; — Expose a Dockerized web app by editing Nginx Proxy Manager&#039;s database directly — &#039;&#039;Filed under: System Administration &amp;amp; Self-Hosting&#039;&#039;&lt;br /&gt;
* 2026-05-02 — &#039;&#039;&#039;[[Organizing Coder Terminals]]&#039;&#039;&#039; — Tmux + dynamic titles for managing multiple AI agent terminals — &#039;&#039;Filed under: System Administration &amp;amp; Self-Hosting&#039;&#039;&lt;br /&gt;
* 2026-04-28 — &#039;&#039;&#039;[[Forgejo Pages]]&#039;&#039;&#039;&lt;br /&gt;
* 2026-04-24 — &#039;&#039;&#039;[[Buzz Transcription]]&#039;&#039;&#039; — Offline audio/meeting transcription via Whisper (whisper.cpp), Flatpak + Vulkan GPU acceleration — &#039;&#039;Filed under: Tools &amp;amp; Productivity&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== Newest Pages (auto) ==&lt;br /&gt;
&lt;br /&gt;
The 10 most recently created pages — maintains itself.&lt;br /&gt;
&lt;br /&gt;
{{Special:NewPages/10}}&lt;br /&gt;
&lt;br /&gt;
== ERPNext / Frappe ==&lt;br /&gt;
&amp;lt;div style=&amp;quot;column-count:2; column-gap:2em;&amp;quot;&amp;gt;&lt;br /&gt;
* [[Frappe HRMS]] — &#039;&#039;&#039;HR &amp;amp; Payroll&#039;&#039;&#039; (with Philippine Localization)&lt;br /&gt;
* [[Frappe ERPNext/Webshop]] — &#039;&#039;&#039;E-Commerce Webshop&#039;&#039;&#039; (setup, architecture, chapters)&lt;br /&gt;
* [[Manufacturing v16 260125]]&lt;br /&gt;
* [[ERpnext Asset Management Procedure 260113]]&lt;br /&gt;
* [[ERPNext HR Module Outline]]&lt;br /&gt;
* [[ERPNEXT Payroll POC 251212]]&lt;br /&gt;
* [[Comfac ERPNext Strategy Canvas (Expanded)]]&lt;br /&gt;
* [[PAD-Driven ERPNext Strategy 260303]] — PAD/AI-agentic implementation strategy for Frappe ERPNext&lt;br /&gt;
* [[ERPNext v15 Docker Setup Guide]] — Local Docker setup for evaluation, testing, and student use&lt;br /&gt;
* [[Frappe Links and References]]&lt;br /&gt;
* [[Using Frappe Wiki]]&lt;br /&gt;
* [https://docs.frappe.io/cloud/guidelines-for-contributing-regional-compliance-app Guidelines for Contributing Regional Compliance App]&lt;br /&gt;
* [https://docs.frappe.io/cloud/what-are-benches-and-bench-groups What are Benches?]&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== System Administration &amp;amp; Self-Hosting ==&lt;br /&gt;
&amp;lt;div style=&amp;quot;column-count:2; column-gap:2em;&amp;quot;&amp;gt;&lt;br /&gt;
* [[Networking PfSense Index]] — Consolidated index of all networking, pfSense, DNS, and infrastructure guides&lt;br /&gt;
* [[System Hardening Strategy: Win2Lin Migration &amp;amp; Infrastructure 251129]]&lt;br /&gt;
* [[Controller Systems 251213-01]]&lt;br /&gt;
* [[Power Distribution Tree 251213]]&lt;br /&gt;
* [[Introduction: Why Self-Host Your Email?]]&lt;br /&gt;
* [[Mailcow + Thunderbird Setup Guide (Email + Calendar)]]&lt;br /&gt;
* [[Mailcow SOGo: Creating Filters for Events, Approvals, and Organizational Emails]]&lt;br /&gt;
* [[Spoof Timezone Extension – Setup Guide for Comfac Staff]]&lt;br /&gt;
* [[Viber Focus-Stealing]]&lt;br /&gt;
* [[🌐 WordPress Website — *You Own Everything, Learn Everything*]]&lt;br /&gt;
* [[Portainer to Docker Compose Migration Guide]]&lt;br /&gt;
* [[Organizing Coder Terminals]] — Tmux + dynamic titles for managing multiple AI agent terminals&lt;br /&gt;
* [[Editing Mastodon Docker Deployment Guide 260402]]&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Storage &amp;amp; Hardware ==&lt;br /&gt;
&amp;lt;div style=&amp;quot;column-count:2; column-gap:2em;&amp;quot;&amp;gt;&lt;br /&gt;
* [[TrueNAS Configuration Options &amp;amp; Scale Options 251130]]&lt;br /&gt;
* [[TrueNAS Business Plan: Project 251212]]&lt;br /&gt;
* [[Comparison: TrueNAS Mini X+ vs Dell Precision 3680 Tower (2025)]]&lt;br /&gt;
* [[Backblaze Drive Stats for Server and Storage Qualification]]&lt;br /&gt;
* [[Industrial Controllers and Water Utilities 251011]]&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== AI &amp;amp; Machine Learning ==&lt;br /&gt;
&amp;lt;div style=&amp;quot;column-count:2; column-gap:2em;&amp;quot;&amp;gt;&lt;br /&gt;
* [[OpenWebUI - 251128-justin]]&lt;br /&gt;
* [[Comfac GPU Scaling and AI Research Goals]]&lt;br /&gt;
* [[🧠 Process: Selecting and Installing the Right Ollama Model for Your Hardware]]&lt;br /&gt;
* [[Ollama GNOME System Tray Panel 260401]] — GNOME system tray toggle to start/stop Ollama and reclaim VRAM&lt;br /&gt;
* [[Proceedural Agentic Development Methodology 260304]] — Methodology for systematic agent use&lt;br /&gt;
* [[Project OpenCoder: AI Independence Initiative]] — Strategic roadmap for manufacturing intelligence&lt;br /&gt;
* [[OpenCoder Qwen35 Agentic Setup 260330]] — Qwen3.5 Modelfile fix for tool calling in OpenCode; thinking mode suppression; HDD vs SSD findings&lt;br /&gt;
* [[OpenCode Multi-Provider Configuration Guide 260401]] — Dual-mode AI coding setup with Kimi cloud + Ollama local models via Distrobox&lt;br /&gt;
* [[PAD-Driven ERPNext Strategy 260303]] — Procedural Agentic Development for Frappe/ERPNext configuration and deployment&lt;br /&gt;
* [[Directed Execution: Token-Efficient Agent Development Process]] — Director/Executor/Checker loop and skill distillation for token-efficient agent development (v0.1, 2026-07-15)&lt;br /&gt;
* [[De-Risk: Sovereign Training Data v0.1]] — Frontier-Token Quarantine and the ToS-clean path to owned model weights, prompted by the June 2026 Fable 5 export-control suspension (v0.1, 2026-07-15)&lt;br /&gt;
* [[Hugging Face Practical Guide 260802]] — Spaces, local app builds, the Model Hub / dataset viewer, and the enterprise compute tier; the route from stock models to tailored ones and to training on our own data (2026-08-02)&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Job Descriptions ==&lt;br /&gt;
&amp;lt;div style=&amp;quot;column-count:2; column-gap:2em;&amp;quot;&amp;gt;&lt;br /&gt;
* [[Job Descriptions]] — Index of all official job descriptions (IT, Engineering, Sales)&lt;br /&gt;
* [[JD IT Project Staff]] — IT Project Staff&lt;br /&gt;
* [[JD Security Compliance Assistant 260224]] — Security and Compliance Assistant (SCA)&lt;br /&gt;
* [[JD Engineering Designer 260108]] — Engineering Designer&lt;br /&gt;
* [[JD Engineering Supervisor 260109]] — Engineering Supervisor&lt;br /&gt;
* [[JD Technical Sales 260112]] — Technical Sales Engineer&lt;br /&gt;
* [[JD Marketing Assistant 251119]] — Marketing Assistant&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== IT Operations &amp;amp; SOPs ==&lt;br /&gt;
&amp;lt;div style=&amp;quot;column-count:2; column-gap:2em;&amp;quot;&amp;gt;&lt;br /&gt;
* [[SOP: Third-Party Software Security Review]] — vet GitHub/OSS code for data leakage and exploits before install; workflow, criteria, and review log&lt;br /&gt;
* [[SCA Program Plan 260320]] — Security &amp;amp; Compliance Assistant Program Plan v3 (ISO 9001/27001, PDCA, distributed audit model)&lt;br /&gt;
* [[SOP: Inter-Company Ordering and Production Process 260203]] — Ordering and production workflow between Sister Companies and the Cabuyao Plant&lt;br /&gt;
* [[Memo: Team Roles &amp;amp; Reporting Process Clarification 260320]] — Role boundaries, data ownership, and the new ERPNext-driven reporting paradigm&lt;br /&gt;
* [[Standard Operating Procedure: Distributed Minute Taking &amp;amp; Task Ownership 251208]]&lt;br /&gt;
* [[Business Continuity]]&lt;br /&gt;
* [[Procedure: CC-Blast Data Breach Prevention]]&lt;br /&gt;
* [[8D (Eight Discipline) Problem Solving Procedure]]&lt;br /&gt;
* [[Offline Malware Remediation &amp;amp; Data Recovery]]&lt;br /&gt;
* [[Troubleshooting: Access &amp;amp; Permission Issues]]&lt;br /&gt;
* [[Steps to Repair and OCR a Scanned or Corrupted PDF in Ubuntu]]&lt;br /&gt;
* [[IT IMPORTS PROCESSES]]&lt;br /&gt;
* [[IT Purchase Requests 241126]]&lt;br /&gt;
* [[IT REQUEST (OP-ERP-ITR) - EDITED 250801]]&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Sales &amp;amp; Business ==&lt;br /&gt;
&amp;lt;div style=&amp;quot;column-count:2; column-gap:2em;&amp;quot;&amp;gt;&lt;br /&gt;
* [[Comfac Sales Knowledge Base]]&lt;br /&gt;
* [[Comfac CRM – Customer Qualification &amp;amp; Conversion Process]]&lt;br /&gt;
* [[Partner Reseller Pricing 251109]]&lt;br /&gt;
* [[Biz Analysis Methodology 251109]]&lt;br /&gt;
* [[2026 MIS IT KRA KPI Biz Plan]]&lt;br /&gt;
* [[SALES INVOICE TAX OUTPUT 250829]]&lt;br /&gt;
* [[Projects in Process Report 251023]]&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Tools &amp;amp; Productivity ==&lt;br /&gt;
&amp;lt;div style=&amp;quot;column-count:2; column-gap:2em;&amp;quot;&amp;gt;&lt;br /&gt;
* [[Excel Description Filler Tool 📝]]&lt;br /&gt;
* [[Resume CV Renamer Pipeline|Resume / CV Renamer Pipeline]] — CV intake → OCR / vision-OCR → AI field extraction → date-stamped rename + VCF export&lt;br /&gt;
* [https://github.com/Comfac-Global-Group/comfac-studies Comfac Studies - Spaced Repetiton Active Recall]&lt;br /&gt;
* [[LibreOffice / Nextcloud Office – &amp;quot;Due Tasks&amp;quot; Conditional Formatting]]&lt;br /&gt;
* [[Google Drive and Shared Drive Training]]&lt;br /&gt;
* [[260108 CGG- GitHub Administration Guide]]&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Wiki &amp;amp; Documentation ==&lt;br /&gt;
&amp;lt;div style=&amp;quot;column-count:2; column-gap:2em;&amp;quot;&amp;gt;&lt;br /&gt;
* [[Mediawiki Setting Up Guide]]&lt;br /&gt;
* [[Contributing to Only Office 260307]]&lt;br /&gt;
* [[Mediawiki Additional Configuration]]&lt;br /&gt;
* [[Mediawiki Docker Migration Guide]]&lt;br /&gt;
* [[Home]]&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Tutorials ==&lt;br /&gt;
&amp;lt;div style=&amp;quot;column-count:2; column-gap:2em;&amp;quot;&amp;gt;&lt;br /&gt;
* [[Claude Code Isolation and Burner Workflow 260211]] — Secure AI development environment setup&lt;br /&gt;
* [[Opencode isolation and burner workflow 260216]] — OpenCode CLI isolation procedures&lt;br /&gt;
* [[LibreOffice Calc NumToWords Extension Complete Guide]] — Extension development&lt;br /&gt;
* [[ERPNext v15 Docker Setup Guide]] — ERPNext v15 local Docker setup (students, evaluators, thin-client demos)&lt;br /&gt;
* [[Erpnextv15-SSH-setup-241111]] — ERPNext v15 SSH/Portainer production setup&lt;br /&gt;
* [[Git-Mediawiki Local Editing 260223]] — Wiki editing with Git&lt;br /&gt;
* [[Understanding &amp;amp; Fixing Kernel Panics 260212]] — System debugging&lt;br /&gt;
* [[OpenCode in Android Termux 260303]] — OpenCode in Android&lt;br /&gt;
* [[OpenCoder Qwen35 Agentic Setup 260330]] — Qwen3.5 agentic setup: Modelfile, tool calling fix, storage impact&lt;br /&gt;
* [[Lora Basics 260304]] — LORA research&lt;br /&gt;
* [https://github.com/anomalyco/opencode/issues/4283#issuecomment-4083399210 Opencode Copy-paste Clipboard doesnt Work - Solution]   https://github.com/anomalyco/opencode/issues/4283#issuecomment-4083399210&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Research ==&lt;br /&gt;
&amp;lt;div style=&amp;quot;column-count:2; column-gap:2em;&amp;quot;&amp;gt;&lt;br /&gt;
* [[Ladybird Browser]] — Browser engine development&lt;br /&gt;
* [[Computing Architecture]] — System design principles&lt;br /&gt;
* [[Backblaze Drive Stats for Server and Storage Qualification 260219]] — Drive reliability analysis&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== For Users Only ==&lt;br /&gt;
* [[Private:Private Ngani]]&lt;br /&gt;
* [[Private:Private Nganipart2]]&lt;br /&gt;
&lt;br /&gt;
== CIT-OJT Project Documentations ==&lt;br /&gt;
* [[OJTDocs: For OJTs only]]&lt;br /&gt;
&lt;br /&gt;
== Need Help? ==&lt;br /&gt;
&amp;lt;div style=&amp;quot;column-count:2; column-gap:2em;&amp;quot;&amp;gt;&lt;br /&gt;
* [[Troubleshooting: Access &amp;amp; Permission Issues]]&lt;br /&gt;
* [https://www.mediawiki.org/wiki/Special:MyLanguage/Help:Contents MediaWiki User&#039;s Guide]&lt;br /&gt;
* [https://www.mediawiki.org/wiki/Special:MyLanguage/Manual:Configuration_settings Configuration settings]&lt;br /&gt;
* [https://www.mediawiki.org/wiki/Special:MyLanguage/Manual:FAQ MediaWiki FAQ]&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;/div&gt;</summary>
		<author><name>Justinaquino</name></author>
	</entry>
	<entry>
		<id>https://mediawiki.comfac.net/index.php?title=SOP:_Third-Party_Software_Security_Review&amp;diff=279</id>
		<title>SOP: Third-Party Software Security Review</title>
		<link rel="alternate" type="text/html" href="https://mediawiki.comfac.net/index.php?title=SOP:_Third-Party_Software_Security_Review&amp;diff=279"/>
		<updated>2026-08-09T06:23:57Z</updated>

		<summary type="html">&lt;p&gt;Justinaquino: Create SOP: third-party software security review workflow + first due-diligence result (offline-browser-translate)&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= SOP: Third-Party Software Security Review (Due Diligence) =&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Purpose:&#039;&#039;&#039; No third-party code — GitHub repos, browser extensions, open-source tools — is installed or run on Comfac machines without a security review first. The review emphasis is &#039;&#039;&#039;data leakage / exfiltration risk&#039;&#039;&#039;, then permissions vs. purpose, obfuscation, supply chain, and repository history.&lt;br /&gt;
&lt;br /&gt;
The full workflow, criteria, and triage script live in the IT-knowledge repo: &amp;lt;code&amp;gt;IT-knowledge/skills/repo-security-review/&amp;lt;/code&amp;gt; (git.gi7b.org). Finished review reports are filed in &amp;lt;code&amp;gt;IT-knowledge/skills/repo-security-review/reports/&amp;lt;/code&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
== Workflow ==&lt;br /&gt;
&lt;br /&gt;
# &#039;&#039;&#039;Acquire and pin.&#039;&#039;&#039; Clone full history into a scratch area (never a synced project folder). Record the exact commit (&amp;lt;code&amp;gt;git rev-parse HEAD&amp;lt;/code&amp;gt;) — the verdict covers that commit only.&lt;br /&gt;
# &#039;&#039;&#039;Automated triage.&#039;&#039;&#039; Run the pattern pack:&lt;br /&gt;
#: &amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;bash IT-knowledge/skills/repo-security-review/scripts/triage-scan.sh &amp;amp;lt;git-url&amp;amp;gt; agent260222/repo-scans&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
#: It scans for hardcoded endpoints, network calls, telemetry keywords, obfuscation/dynamic exec, remote code loading, dangerous extension APIs, data-at-rest, injection sinks, IPC/message surfaces, committed secrets, install/CI hooks, binaries, and contributor history. &#039;&#039;&#039;A clean triage is not a verdict&#039;&#039;&#039; — it finds where to look.&lt;br /&gt;
# &#039;&#039;&#039;Manual review.&#039;&#039;&#039; Read every triage hit in context; read the manifest/permissions and trace the data flow: what user data is read, where does every network call send, what persists. Every egress destination must be user-configured or justified by the feature — anything else is a finding.&lt;br /&gt;
# &#039;&#039;&#039;Verdict and report.&#039;&#039;&#039; File the report under &amp;lt;code&amp;gt;reports/YYMMDD-&amp;amp;lt;repo&amp;amp;gt;.md&amp;lt;/code&amp;gt; with target + commit, verdict, data-flow map, findings table (with file:line evidence), and caveats.&lt;br /&gt;
# &#039;&#039;&#039;Re-review on change.&#039;&#039;&#039; A verdict expires on update, permission/manifest change, ownership change, or a dependency adding a binary blob. Diff from the reviewed commit and re-triage the delta.&lt;br /&gt;
&lt;br /&gt;
== Criteria Checklist ==&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! # !! Question !! Fail closed when&lt;br /&gt;
|-&lt;br /&gt;
| 1 || Can you enumerate every network destination? || Hidden/encoded endpoints&lt;br /&gt;
|-&lt;br /&gt;
| 2 || Does every egress match the stated purpose? || Data leaves to a party the user didn&#039;t configure&lt;br /&gt;
|-&lt;br /&gt;
| 3 || Is the permission set minimal for the purpose? || Broad grants (&amp;amp;lt;all_urls&amp;amp;gt;, filesystem, exec) without justification&lt;br /&gt;
|-&lt;br /&gt;
| 4 || Is all executed code readable? || Obfuscation, blobs without source, remote code loading&lt;br /&gt;
|-&lt;br /&gt;
| 5 || Does anything run before you consent? || postinstall hooks, curl&amp;amp;#124;sh installs, unpinned self-update&lt;br /&gt;
|-&lt;br /&gt;
| 6 || What user data is read and where is it stored? || Silent persistence of content/credentials&lt;br /&gt;
|-&lt;br /&gt;
| 7 || Are IPC/message boundaries validated? || Privileged handlers trusting unverified senders&lt;br /&gt;
|-&lt;br /&gt;
| 8 || Is the supply chain pinned? || Unpinned deps, unsigned release binaries&lt;br /&gt;
|-&lt;br /&gt;
| 9 || Does history/metadata support trust? || New owner + permission bump, throwaway account&lt;br /&gt;
|-&lt;br /&gt;
| 10 || Would you notice if an update turned evil? || Auto-update with no hash check&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Verdicts ==&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;CLEAN&#039;&#039;&#039; — install OK.&lt;br /&gt;
* &#039;&#039;&#039;CLEAN WITH CONDITIONS&#039;&#039;&#039; — install OK if the listed configuration conditions are met.&lt;br /&gt;
* &#039;&#039;&#039;SUSPICIOUS&#039;&#039;&#039; — do not install; the report lists what would change the verdict.&lt;br /&gt;
* &#039;&#039;&#039;MALICIOUS&#039;&#039;&#039; — do not install; consider reporting upstream.&lt;br /&gt;
&lt;br /&gt;
Severity: &#039;&#039;&#039;Critical&#039;&#039;&#039; (exfiltration, RCE, credential theft) · &#039;&#039;&#039;High&#039;&#039;&#039; (exfiltration capability gated only by config/obscurity, obfuscated payload) · &#039;&#039;&#039;Medium&#039;&#039;&#039; (over-broad permissions, cleartext transport of user content, missing origin checks) · &#039;&#039;&#039;Low&#039;&#039;&#039; (privacy footguns, hygiene) · &#039;&#039;&#039;Info&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
== Review Log ==&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Date !! Target !! Commit !! Verdict !! Report&lt;br /&gt;
|-&lt;br /&gt;
| 2026-08-09 || [https://github.com/Eldoprano/offline-browser-translate offline-browser-translate] (Firefox extension, local-LLM page translation) || d2b0907 || &#039;&#039;&#039;CLEAN WITH CONDITIONS&#039;&#039;&#039; || IT-knowledge: &amp;lt;code&amp;gt;skills/repo-security-review/reports/260809-offline-browser-translate.md&amp;lt;/code&amp;gt;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== 2026-08-09 — offline-browser-translate (Local LLM Translator) ===&lt;br /&gt;
&lt;br /&gt;
Static review of all source (60 commits, full history) at commit &amp;lt;code&amp;gt;d2b0907&amp;lt;/code&amp;gt;. No exfiltration, no telemetry, no obfuscation, no remote code loading, no dependencies or install hooks. The extension&#039;s &amp;quot;your data never leaves your machine&amp;quot; claim is accurate &#039;&#039;&#039;for the default configuration&#039;&#039;&#039;:&lt;br /&gt;
&lt;br /&gt;
* All 7 &amp;lt;code&amp;gt;fetch()&amp;lt;/code&amp;gt; call sites send page text only to the user-configured LLM server URL (default &amp;lt;code&amp;gt;localhost:11434/1234&amp;lt;/code&amp;gt;). Non-localhost URLs require an explicit per-origin browser permission prompt.&lt;br /&gt;
* No third-party endpoints anywhere; declared Firefox data-collection permission is &amp;quot;none&amp;quot;, consistent with the code.&lt;br /&gt;
* Translations are inserted via &amp;lt;code&amp;gt;textContent&amp;lt;/code&amp;gt; only (no XSS sink); all &amp;lt;code&amp;gt;innerHTML&amp;lt;/code&amp;gt; uses are static template strings.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Conditions (configuration risks, not code defects):&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
# Point it only at localhost or a trusted machine — page text goes to whatever server URL is configured.&lt;br /&gt;
# Remote (LAN) server URLs are plain HTTP — translated page content is cleartext on the wire.&lt;br /&gt;
# Leave the translation cache at its default (&amp;lt;code&amp;gt;off&amp;lt;/code&amp;gt;) for sensitive pages; &amp;lt;code&amp;gt;persistent&amp;lt;/code&amp;gt; mode stores translated page text in IndexedDB.&lt;br /&gt;
# The optional &amp;lt;code&amp;gt;&amp;amp;lt;all_urls&amp;amp;gt;&amp;lt;/code&amp;gt; permission (floating button) runs the content script on every page — broad, but user-initiated, and data still flows only to the configured endpoint.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Caveats:&#039;&#039;&#039; static review only (no runtime network capture); the AMO store artifact was not diffed against the repo; verdict covers commit d2b0907 only — updates require a delta re-review.&lt;br /&gt;
&lt;br /&gt;
== Related ==&lt;br /&gt;
&lt;br /&gt;
* [[Open Source Software Analysis]] — architecture/contribution analysis of OSS projects (complementary, not a security review)&lt;br /&gt;
* [[Procedure: CC-Blast Data Breach Prevention]]&lt;br /&gt;
* [[SCA Program Plan 260320]]&lt;br /&gt;
&lt;br /&gt;
[[Category:Security]]&lt;br /&gt;
[[Category:SOP]]&lt;br /&gt;
[[Category:IT Operations]]&lt;br /&gt;
[[Category:Open Source]]&lt;/div&gt;</summary>
		<author><name>Justinaquino</name></author>
	</entry>
	<entry>
		<id>https://mediawiki.comfac.net/index.php?title=Buzz_Transcription&amp;diff=278</id>
		<title>Buzz Transcription</title>
		<link rel="alternate" type="text/html" href="https://mediawiki.comfac.net/index.php?title=Buzz_Transcription&amp;diff=278"/>
		<updated>2026-08-09T06:20:05Z</updated>

		<summary type="html">&lt;p&gt;Justinaquino: Point Taglish audio + report to wiki.gi7b.org copies (mp3 not allowed here; 2 MB upload cap)&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Buzz is an open-source, offline-capable audio/meeting transcription tool powered by OpenAI Whisper (via whisper.cpp). On this system it is installed as a Flatpak and runs with Vulkan GPU acceleration on the AMD RX 7600.&lt;br /&gt;
&lt;br /&gt;
== How to Transcribe a Meeting ==&lt;br /&gt;
&lt;br /&gt;
=== Prerequisites ===&lt;br /&gt;
* Buzz installed (Flatpak: &amp;lt;code&amp;gt;io.github.chidiwilliams.Buzz&amp;lt;/code&amp;gt;)&lt;br /&gt;
* A model downloaded — recommended: &amp;lt;code&amp;gt;ggml-large-v3-turbo&amp;lt;/code&amp;gt; for quality, &amp;lt;code&amp;gt;ggml-tiny&amp;lt;/code&amp;gt; for speed&lt;br /&gt;
* Models are stored at &amp;lt;code&amp;gt;~/.var/app/io.github.chidiwilliams.Buzz/cache/Buzz/models/&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== File Transcription (Meeting Recording) ===&lt;br /&gt;
# Launch Buzz from the application menu or run: &amp;lt;code&amp;gt;flatpak run io.github.chidiwilliams.Buzz&amp;lt;/code&amp;gt;&lt;br /&gt;
# Go to &#039;&#039;&#039;File → Import Media&#039;&#039;&#039; and select your meeting recording (MP3, WAV, M4A, etc.)&lt;br /&gt;
# In the transcription dialog:&lt;br /&gt;
#* &#039;&#039;&#039;Model&#039;&#039;&#039;: Select &amp;lt;code&amp;gt;large-v3-turbo&amp;lt;/code&amp;gt; (best quality for meetings)&lt;br /&gt;
#* &#039;&#039;&#039;Task&#039;&#039;&#039;: Transcribe&lt;br /&gt;
#* &#039;&#039;&#039;Language&#039;&#039;&#039;: Select your language or leave on Auto&lt;br /&gt;
#* &#039;&#039;&#039;Extract Speech&#039;&#039;&#039;: &#039;&#039;&#039;Leave unchecked&#039;&#039;&#039; for files longer than ~30 minutes (see [[#OOM Crash with Large Files|OOM Crash]] below)&lt;br /&gt;
#* &#039;&#039;&#039;Output&#039;&#039;&#039;: SRT, VTT, or TXT depending on your need&lt;br /&gt;
# Click &#039;&#039;&#039;Transcribe&#039;&#039;&#039;&lt;br /&gt;
# When complete, the transcript appears in the main window and is saved alongside the source file&lt;br /&gt;
&lt;br /&gt;
=== Live Transcription (Real-Time) ===&lt;br /&gt;
# Go to &#039;&#039;&#039;File → Record and Transcribe&#039;&#039;&#039;&lt;br /&gt;
# Select your microphone input&lt;br /&gt;
# Choose model and language&lt;br /&gt;
# Click &#039;&#039;&#039;Record&#039;&#039;&#039; — transcription appears live on screen&lt;br /&gt;
# Stop recording when done; export via &#039;&#039;&#039;File → Export&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
=== Recommended Settings for Meetings ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Setting !! Value !! Reason&lt;br /&gt;
|-&lt;br /&gt;
| Model || large-v3-turbo || Best accuracy; 1.6 GB VRAM, runs on RX 7600&lt;br /&gt;
|-&lt;br /&gt;
| Extract Speech || &#039;&#039;&#039;Off&#039;&#039;&#039; for files &amp;amp;gt;30 min || Demucs uses 8–15 GB RAM for long files (OOM risk)&lt;br /&gt;
|-&lt;br /&gt;
| Language || Set explicitly || Faster than auto-detect&lt;br /&gt;
|-&lt;br /&gt;
| Task || Transcribe || Use Translate only if you need English output from another language&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Before Each Session: Clear Swap ===&lt;br /&gt;
Prior transcription sessions can leave stale pages in swap. Run this before starting a long transcription:&lt;br /&gt;
&amp;lt;pre&amp;gt;sudo swapoff -a &amp;amp;&amp;amp; sudo swapon -a&amp;lt;/pre&amp;gt;&lt;br /&gt;
This is safe when free RAM exceeds swap used (typical on this system: 15+ GB free, 8 GB swap).&lt;br /&gt;
&lt;br /&gt;
== GPU Acceleration ==&lt;br /&gt;
&lt;br /&gt;
Buzz&#039;s Flatpak installation includes a Vulkan-enabled &amp;lt;code&amp;gt;whisper-cli&amp;lt;/code&amp;gt;. On this system, GPU inference is automatically active — no configuration needed.&lt;br /&gt;
&lt;br /&gt;
* GPU in use: &#039;&#039;&#039;AMD RX 7600 (RDNA3, RADV NAVI33)&#039;&#039;&#039;&lt;br /&gt;
* Confirmed by: &amp;lt;code&amp;gt;whisper_backend_init_gpu: using Vulkan0 backend&amp;lt;/code&amp;gt; in runtime output&lt;br /&gt;
* Buzz checks for Vulkan at startup (&amp;lt;code&amp;gt;IS_VULKAN_SUPPORTED&amp;lt;/code&amp;gt;) and omits the &amp;lt;code&amp;gt;--no-gpu&amp;lt;/code&amp;gt; flag when found&lt;br /&gt;
&lt;br /&gt;
To force CPU inference (for debugging):&lt;br /&gt;
&amp;lt;pre&amp;gt;flatpak override --user io.github.chidiwilliams.Buzz --env=BUZZ_FORCE_CPU=true&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
To revert:&lt;br /&gt;
&amp;lt;pre&amp;gt;flatpak override --user --reset io.github.chidiwilliams.Buzz&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== OOM Crash with Large Files ==&lt;br /&gt;
&lt;br /&gt;
=== Symptom ===&lt;br /&gt;
When selecting &amp;lt;code&amp;gt;ggml-large-v3-turbo&amp;lt;/code&amp;gt; in Buzz and starting a transcription on a long file, the application crashes. VRAM usage never visibly climbs before the crash.&lt;br /&gt;
&lt;br /&gt;
=== Root Cause ===&lt;br /&gt;
The crash is caused by the &#039;&#039;&#039;Extract Speech (Demucs)&#039;&#039;&#039; pre-processing step, not the large model.&lt;br /&gt;
&lt;br /&gt;
Demucs is a PyTorch-based music source separation model that strips background noise from audio before passing it to the transcription engine. It processes raw PCM audio at full float32 precision entirely in RAM:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Audio Duration !! Compressed Size !! RAM Required (Demucs)&lt;br /&gt;
|-&lt;br /&gt;
| 1 hour MP3 || ~60 MB || 500 MB – 1 GB&lt;br /&gt;
|-&lt;br /&gt;
| 3–4 hour session || ~220 MB || 8–15 GB peak&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
The combination that caused the crash:&lt;br /&gt;
# Swap already exhausted from previous sessions&lt;br /&gt;
# Extract Speech (Demucs) triggered on a ~220 MB MP3 (~3–4 hours of audio)&lt;br /&gt;
# Python RAM usage exceeded available RAM + swap ceiling&lt;br /&gt;
# OOM killer terminated the process at 22 GB RSS&lt;br /&gt;
# &amp;lt;code&amp;gt;whisper-cli&amp;lt;/code&amp;gt; was never launched → no VRAM activity observed&lt;br /&gt;
&lt;br /&gt;
=== Why VRAM Never Climbed ===&lt;br /&gt;
&amp;lt;code&amp;gt;whisper-cli&amp;lt;/code&amp;gt; runs as a subprocess of the Python GUI. The OOM kill happened during Demucs pre-processing — &amp;lt;code&amp;gt;whisper-cli&amp;lt;/code&amp;gt; was never started, so no VRAM allocation occurred.&lt;br /&gt;
&lt;br /&gt;
From the Buzz log at crash time:&lt;br /&gt;
&amp;lt;pre&amp;gt;~/.var/app/io.github.chidiwilliams.Buzz/.local/state/Buzz/log/logs.txt&amp;lt;/pre&amp;gt;&lt;br /&gt;
The last entry was &amp;lt;code&amp;gt;Will extract speech&amp;lt;/code&amp;gt; — the log never reached &amp;lt;code&amp;gt;Starting whisper file transcription&amp;lt;/code&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
=== Fix ===&lt;br /&gt;
&#039;&#039;&#039;Uncheck &amp;quot;Extract Speech&amp;quot;&#039;&#039;&#039; in the Buzz transcription dialog for any file longer than ~30 minutes. The &amp;lt;code&amp;gt;large-v3-turbo&amp;lt;/code&amp;gt; model has built-in noise tolerance that makes Demucs pre-processing unnecessary in most cases.&lt;br /&gt;
&lt;br /&gt;
Optionally, grow the swapfile if you need Extract Speech for shorter files:&lt;br /&gt;
&amp;lt;pre&amp;gt;sudo swapoff /swap.img&lt;br /&gt;
sudo fallocate -l 16G /swap.img&lt;br /&gt;
sudo mkswap /swap.img&lt;br /&gt;
sudo swapon /swap.img&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Environment Variables ==&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Variable !! Default !! Effect&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;BUZZ_FORCE_CPU&amp;lt;/code&amp;gt; || false || Set to &amp;lt;code&amp;gt;true&amp;lt;/code&amp;gt; to disable GPU inference&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;BUZZ_WHISPERCPP_N_THREADS&amp;lt;/code&amp;gt; || cpu_count / 2 || Override thread count for whisper-cli&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
Set via: &amp;lt;code&amp;gt;flatpak override --user io.github.chidiwilliams.Buzz --env=VAR=value&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Key File Paths ==&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Path !! Description&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;/var/lib/flatpak/app/io.github.chidiwilliams.Buzz/.../buzz/whisper_cpp/whisper-cli&amp;lt;/code&amp;gt; || Bundled Vulkan whisper-cli (libwhisper 1.8.3)&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;~/.var/app/io.github.chidiwilliams.Buzz/cache/Buzz/models/&amp;lt;/code&amp;gt; || Buzz model cache (ggml binaries)&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;~/.var/app/io.github.chidiwilliams.Buzz/.local/state/Buzz/log/logs.txt&amp;lt;/code&amp;gt; || Buzz application log&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;~/.var/app/io.github.chidiwilliams.Buzz/config/Buzz.conf&amp;lt;/code&amp;gt; || Buzz settings&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;~/whisper.cpp/build/bin/whisper-cli&amp;lt;/code&amp;gt; || Custom Vulkan-enabled whisper.cpp build&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;~/bin/whisper-cli-vulkan&amp;lt;/code&amp;gt; || Wrapper script for custom build (sets &amp;lt;code&amp;gt;LD_LIBRARY_PATH&amp;lt;/code&amp;gt;)&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;~/.local/share/pipx/venvs/buzz-captions/lib/python3.12/site-packages/buzz/whisper_cpp/&amp;lt;/code&amp;gt; || pipx install whisper_cpp directory (directly modifiable)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Investigation Summary ==&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Question !! Finding&lt;br /&gt;
|-&lt;br /&gt;
| Is Buzz using the RX 7600? || &#039;&#039;&#039;Yes.&#039;&#039;&#039; &amp;lt;code&amp;gt;using Vulkan0 backend&amp;lt;/code&amp;gt; confirmed inside the Flatpak sandbox.&lt;br /&gt;
|-&lt;br /&gt;
| Was &amp;lt;code&amp;gt;--no-gpu&amp;lt;/code&amp;gt; being added? || &#039;&#039;&#039;No.&#039;&#039;&#039; &amp;lt;code&amp;gt;IS_VULKAN_SUPPORTED = True&amp;lt;/code&amp;gt; in the sandbox; flag is never appended.&lt;br /&gt;
|-&lt;br /&gt;
| Does the large model load correctly? || &#039;&#039;&#039;Yes.&#039;&#039;&#039; 1.6 GB to VRAM, transcribes in ~1.25s on a short clip.&lt;br /&gt;
|-&lt;br /&gt;
| What caused the crash? || &#039;&#039;&#039;Extract Speech (Demucs) OOM.&#039;&#039;&#039; Python killed at 22 GB RSS before whisper-cli launched.&lt;br /&gt;
|-&lt;br /&gt;
| Why was VRAM not climbing? || &amp;lt;code&amp;gt;whisper-cli&amp;lt;/code&amp;gt; was never started — process died during Demucs pre-processing.&lt;br /&gt;
|-&lt;br /&gt;
| Fix? || &#039;&#039;&#039;Uncheck Extract Speech&#039;&#039;&#039; for long files. Clear swap before sessions.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Investigation date: 2026-04-25. System: Ubuntu 24.04, AMD RX 7600, Buzz 1.4.4 (Flatpak).&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== Folder Watch (Automatic Transcription) ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;border:1px solid #a00;background:#fee;padding:0.5em 1em;&amp;quot;&amp;gt;&#039;&#039;&#039;Do not use Folder Watch.&#039;&#039;&#039; It is disruptive at default settings: every audio file dropped into the watched folder is transcribed automatically without asking, silently occupying the GPU/CPU and flooding the folder with output files — and with &#039;&#039;Delete processed files&#039;&#039; ticked, the source audio is deleted afterwards. It is disabled by default and should stay that way. Use [[#File Transcription (Meeting Recording)|File → Import Media]] instead. The settings below are documented for reference only (as configured during testing on 2026-08-09).&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[File:Buzz Folder Watch tab.png|thumb|400px|right|Folder Watch tab: whisper.cpp backend, Large-V3, advanced options unchecked]]&lt;br /&gt;
[[File:Buzz Folder Watch tab full.png|thumb|400px|right|Folder Watch tab — Enable folder watch with input/output folders set to /home/justin/Music]]&lt;br /&gt;
&lt;br /&gt;
=== Settings ===&lt;br /&gt;
&lt;br /&gt;
In &#039;&#039;&#039;Preferences → Folder Watch&#039;&#039;&#039;:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Setting !! Value !! Notes&lt;br /&gt;
|-&lt;br /&gt;
| Enable folder watch || &#039;&#039;&#039;leave unticked&#039;&#039;&#039; || ticking it starts auto-transcribing everything dropped into the input folder&lt;br /&gt;
|-&lt;br /&gt;
| Input folder || &amp;lt;code&amp;gt;/home/justin/Music&amp;lt;/code&amp;gt; || drop recordings here&lt;br /&gt;
|-&lt;br /&gt;
| Output folder || &amp;lt;code&amp;gt;/home/justin/Music&amp;lt;/code&amp;gt; || same folder — files stay put&lt;br /&gt;
|-&lt;br /&gt;
| Delete processed files || &#039;&#039;&#039;unchecked&#039;&#039;&#039; || &#039;&#039;&#039;ticking this deletes the source audio after transcription&#039;&#039;&#039; — keep it unticked&lt;br /&gt;
|-&lt;br /&gt;
| Model || whisper.cpp — Large-V3 || engine choice matters, see below&lt;br /&gt;
|-&lt;br /&gt;
| Task || Transcribe ||&lt;br /&gt;
|-&lt;br /&gt;
| Language || Detect Language ||&lt;br /&gt;
|-&lt;br /&gt;
| Export || TXT || SRT / VTT also available&lt;br /&gt;
|-&lt;br /&gt;
| Word-level timings || &#039;&#039;&#039;unchecked&#039;&#039;&#039; ||&lt;br /&gt;
|-&lt;br /&gt;
| Extract speech || &#039;&#039;&#039;unchecked&#039;&#039;&#039; || &#039;&#039;&#039;do not check — crashes on long files&#039;&#039;&#039; (see [[#OOM Crash with Large Files|OOM Crash with Large Files]])&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Use whisper.cpp instead of the default engine ===&lt;br /&gt;
&lt;br /&gt;
[[File:Buzz model dropdown.png|thumb|400px|right|Model dropdown: whisper.cpp and Faster Whisper]]&lt;br /&gt;
&lt;br /&gt;
The model picker lists two engines: &#039;&#039;&#039;whisper.cpp&#039;&#039;&#039; and &#039;&#039;&#039;Faster Whisper&#039;&#039;&#039;. Faster Whisper is the default — switch to &#039;&#039;&#039;whisper.cpp&#039;&#039;&#039;:&lt;br /&gt;
&lt;br /&gt;
* whisper.cpp uses the &amp;lt;code&amp;gt;ggml-*.bin&amp;lt;/code&amp;gt; models already cached under &amp;lt;code&amp;gt;~/.var/app/io.github.chidiwilliams.Buzz/cache/Buzz/models/&amp;lt;/code&amp;gt; (Flatpak path; &amp;lt;code&amp;gt;~/snap/buzz/…&amp;lt;/code&amp;gt; on snap installs) — no extra download&lt;br /&gt;
* it runs through the bundled Vulkan &amp;lt;code&amp;gt;whisper-cli&amp;lt;/code&amp;gt;, so GPU acceleration applies (see [[#GPU Acceleration|GPU Acceleration]])&lt;br /&gt;
&lt;br /&gt;
[[File:Buzz Models tab whisper.cpp.png|thumb|400px|right|Models tab, whisper.cpp group: Large-V3, Large-V3-Turbo, Medium.en, Large and Large-v2 downloaded]]&lt;br /&gt;
&lt;br /&gt;
In the Models tab, the whisper.cpp group shows the downloaded sizes — Large-V3 and Large-V3-Turbo are the useful ones for meetings (Large-V3-Turbo: best quality/speed trade-off, see [[#How to Transcribe a Meeting|Recommended Settings]]).&lt;br /&gt;
&lt;br /&gt;
=== Leave the advanced options unchecked ===&lt;br /&gt;
&lt;br /&gt;
[[File:Buzz transcription dialog unchecked.png|thumb|400px|right|Transcription dialog: neither Word-level timings nor Extract speech checked]]&lt;br /&gt;
&lt;br /&gt;
In the transcription dialog (shown when folder watch picks up a file) both &#039;&#039;&#039;Word-level timings&#039;&#039;&#039; and &#039;&#039;&#039;Extract speech&#039;&#039;&#039; are left unchecked. Checking &#039;&#039;&#039;Extract speech&#039;&#039;&#039; — the obvious option for a meeting recording — triggers the Demucs pre-processing step that OOM-crashes the app on long files (22 GB RSS kill, [[#OOM Crash with Large Files|see above]]). Keep both unchecked.&lt;br /&gt;
&lt;br /&gt;
=== Result ===&lt;br /&gt;
&lt;br /&gt;
Transcriptions are written next to the source as &amp;lt;code&amp;gt;&amp;amp;lt;original name&amp;amp;gt; (transcribed on &amp;amp;lt;date&amp;amp;gt;).txt&amp;lt;/code&amp;gt;, e.g. &amp;lt;code&amp;gt;2026-08-08 20-56-20 3rd Apocalypse Bob&#039;s ADND1E (transcribed on 09-Aug-2026 01-50-32).txt&amp;lt;/code&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
Config verified 2026-08-09 in &amp;lt;code&amp;gt;~/snap/buzz/570/.config/Buzz.conf&amp;lt;/code&amp;gt; (snap install): &amp;lt;code&amp;gt;folder_watch\enabled&amp;lt;/code&amp;gt; = &amp;lt;code&amp;gt;false&amp;lt;/code&amp;gt; (off — recommended), &amp;lt;code&amp;gt;folder_watch\input_folder&amp;lt;/code&amp;gt; = &amp;lt;code&amp;gt;/home/justin/Music&amp;lt;/code&amp;gt;, &amp;lt;code&amp;gt;folder_watch\output_directory&amp;lt;/code&amp;gt; = &amp;lt;code&amp;gt;/home/justin/Music&amp;lt;/code&amp;gt;, model Whisper.cpp / large-v3, and &amp;lt;code&amp;gt;delete_processed_files&amp;lt;/code&amp;gt;, &amp;lt;code&amp;gt;extract_speech&amp;lt;/code&amp;gt;, &amp;lt;code&amp;gt;word_level_timings&amp;lt;/code&amp;gt; all &amp;lt;code&amp;gt;false&amp;lt;/code&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
== Example: Taglish Test (2026-08-09) ==&lt;br /&gt;
&lt;br /&gt;
A Taglish (Tagalog + English code-switching) test recording, transcribed automatically by Buzz&#039;s Folder Watch during testing (now disabled — see the [[#Folder Watch (Automatic Transcription)|Folder Watch]] warning above):&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;Audio:&#039;&#039;&#039; [https://wiki.gi7b.org/index.php/Special:FilePath/Taglish_Test_260809.mp3 Taglish Test 260809.mp3] — hosted on wiki.gi7b.org (this wiki does not allow audio uploads)&lt;br /&gt;
* &#039;&#039;&#039;Evaluation report:&#039;&#039;&#039; [https://wiki.gi7b.org/index.php/Special:FilePath/Taglish_Transcription_and_Evaluation_Report_260809.docx Taglish Transcription and Evaluation Report 260809.docx] — hosted on wiki.gi7b.org (this wiki caps uploads at 2 MB)&lt;br /&gt;
&lt;br /&gt;
The report grades the result &#039;&#039;&#039;95/100 (Excellent)&#039;&#039;&#039; at ~96 % word accuracy. Code-switching between Filipino and English (EDSA, client, project, presentation, brain cells, lunch, work) is handled seamlessly. Noted deviations are typical ASR behavior: punctuation is collapsed into sentence breaks, &amp;quot;Almost two hours&amp;quot; became &amp;quot;Almost 2 hours&amp;quot;, &amp;quot;na-stuck&amp;quot; → &amp;quot;nakastuck&amp;quot;, &amp;quot;kailangan nating&amp;quot; → &amp;quot;kailan nating&amp;quot;.&lt;/div&gt;</summary>
		<author><name>Justinaquino</name></author>
	</entry>
	<entry>
		<id>https://mediawiki.comfac.net/index.php?title=Buzz_Transcription&amp;diff=277</id>
		<title>Buzz Transcription</title>
		<link rel="alternate" type="text/html" href="https://mediawiki.comfac.net/index.php?title=Buzz_Transcription&amp;diff=277"/>
		<updated>2026-08-09T06:10:18Z</updated>

		<summary type="html">&lt;p&gt;Justinaquino: Mirror from wiki.gi7b.org rev 4963 (2026-08-09): Folder Watch warning, Taglish example, screenshots&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Buzz is an open-source, offline-capable audio/meeting transcription tool powered by OpenAI Whisper (via whisper.cpp). On this system it is installed as a Flatpak and runs with Vulkan GPU acceleration on the AMD RX 7600.&lt;br /&gt;
&lt;br /&gt;
== How to Transcribe a Meeting ==&lt;br /&gt;
&lt;br /&gt;
=== Prerequisites ===&lt;br /&gt;
* Buzz installed (Flatpak: &amp;lt;code&amp;gt;io.github.chidiwilliams.Buzz&amp;lt;/code&amp;gt;)&lt;br /&gt;
* A model downloaded — recommended: &amp;lt;code&amp;gt;ggml-large-v3-turbo&amp;lt;/code&amp;gt; for quality, &amp;lt;code&amp;gt;ggml-tiny&amp;lt;/code&amp;gt; for speed&lt;br /&gt;
* Models are stored at &amp;lt;code&amp;gt;~/.var/app/io.github.chidiwilliams.Buzz/cache/Buzz/models/&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== File Transcription (Meeting Recording) ===&lt;br /&gt;
# Launch Buzz from the application menu or run: &amp;lt;code&amp;gt;flatpak run io.github.chidiwilliams.Buzz&amp;lt;/code&amp;gt;&lt;br /&gt;
# Go to &#039;&#039;&#039;File → Import Media&#039;&#039;&#039; and select your meeting recording (MP3, WAV, M4A, etc.)&lt;br /&gt;
# In the transcription dialog:&lt;br /&gt;
#* &#039;&#039;&#039;Model&#039;&#039;&#039;: Select &amp;lt;code&amp;gt;large-v3-turbo&amp;lt;/code&amp;gt; (best quality for meetings)&lt;br /&gt;
#* &#039;&#039;&#039;Task&#039;&#039;&#039;: Transcribe&lt;br /&gt;
#* &#039;&#039;&#039;Language&#039;&#039;&#039;: Select your language or leave on Auto&lt;br /&gt;
#* &#039;&#039;&#039;Extract Speech&#039;&#039;&#039;: &#039;&#039;&#039;Leave unchecked&#039;&#039;&#039; for files longer than ~30 minutes (see [[#OOM Crash with Large Files|OOM Crash]] below)&lt;br /&gt;
#* &#039;&#039;&#039;Output&#039;&#039;&#039;: SRT, VTT, or TXT depending on your need&lt;br /&gt;
# Click &#039;&#039;&#039;Transcribe&#039;&#039;&#039;&lt;br /&gt;
# When complete, the transcript appears in the main window and is saved alongside the source file&lt;br /&gt;
&lt;br /&gt;
=== Live Transcription (Real-Time) ===&lt;br /&gt;
# Go to &#039;&#039;&#039;File → Record and Transcribe&#039;&#039;&#039;&lt;br /&gt;
# Select your microphone input&lt;br /&gt;
# Choose model and language&lt;br /&gt;
# Click &#039;&#039;&#039;Record&#039;&#039;&#039; — transcription appears live on screen&lt;br /&gt;
# Stop recording when done; export via &#039;&#039;&#039;File → Export&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
=== Recommended Settings for Meetings ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Setting !! Value !! Reason&lt;br /&gt;
|-&lt;br /&gt;
| Model || large-v3-turbo || Best accuracy; 1.6 GB VRAM, runs on RX 7600&lt;br /&gt;
|-&lt;br /&gt;
| Extract Speech || &#039;&#039;&#039;Off&#039;&#039;&#039; for files &amp;amp;gt;30 min || Demucs uses 8–15 GB RAM for long files (OOM risk)&lt;br /&gt;
|-&lt;br /&gt;
| Language || Set explicitly || Faster than auto-detect&lt;br /&gt;
|-&lt;br /&gt;
| Task || Transcribe || Use Translate only if you need English output from another language&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Before Each Session: Clear Swap ===&lt;br /&gt;
Prior transcription sessions can leave stale pages in swap. Run this before starting a long transcription:&lt;br /&gt;
&amp;lt;pre&amp;gt;sudo swapoff -a &amp;amp;&amp;amp; sudo swapon -a&amp;lt;/pre&amp;gt;&lt;br /&gt;
This is safe when free RAM exceeds swap used (typical on this system: 15+ GB free, 8 GB swap).&lt;br /&gt;
&lt;br /&gt;
== GPU Acceleration ==&lt;br /&gt;
&lt;br /&gt;
Buzz&#039;s Flatpak installation includes a Vulkan-enabled &amp;lt;code&amp;gt;whisper-cli&amp;lt;/code&amp;gt;. On this system, GPU inference is automatically active — no configuration needed.&lt;br /&gt;
&lt;br /&gt;
* GPU in use: &#039;&#039;&#039;AMD RX 7600 (RDNA3, RADV NAVI33)&#039;&#039;&#039;&lt;br /&gt;
* Confirmed by: &amp;lt;code&amp;gt;whisper_backend_init_gpu: using Vulkan0 backend&amp;lt;/code&amp;gt; in runtime output&lt;br /&gt;
* Buzz checks for Vulkan at startup (&amp;lt;code&amp;gt;IS_VULKAN_SUPPORTED&amp;lt;/code&amp;gt;) and omits the &amp;lt;code&amp;gt;--no-gpu&amp;lt;/code&amp;gt; flag when found&lt;br /&gt;
&lt;br /&gt;
To force CPU inference (for debugging):&lt;br /&gt;
&amp;lt;pre&amp;gt;flatpak override --user io.github.chidiwilliams.Buzz --env=BUZZ_FORCE_CPU=true&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
To revert:&lt;br /&gt;
&amp;lt;pre&amp;gt;flatpak override --user --reset io.github.chidiwilliams.Buzz&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== OOM Crash with Large Files ==&lt;br /&gt;
&lt;br /&gt;
=== Symptom ===&lt;br /&gt;
When selecting &amp;lt;code&amp;gt;ggml-large-v3-turbo&amp;lt;/code&amp;gt; in Buzz and starting a transcription on a long file, the application crashes. VRAM usage never visibly climbs before the crash.&lt;br /&gt;
&lt;br /&gt;
=== Root Cause ===&lt;br /&gt;
The crash is caused by the &#039;&#039;&#039;Extract Speech (Demucs)&#039;&#039;&#039; pre-processing step, not the large model.&lt;br /&gt;
&lt;br /&gt;
Demucs is a PyTorch-based music source separation model that strips background noise from audio before passing it to the transcription engine. It processes raw PCM audio at full float32 precision entirely in RAM:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Audio Duration !! Compressed Size !! RAM Required (Demucs)&lt;br /&gt;
|-&lt;br /&gt;
| 1 hour MP3 || ~60 MB || 500 MB – 1 GB&lt;br /&gt;
|-&lt;br /&gt;
| 3–4 hour session || ~220 MB || 8–15 GB peak&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
The combination that caused the crash:&lt;br /&gt;
# Swap already exhausted from previous sessions&lt;br /&gt;
# Extract Speech (Demucs) triggered on a ~220 MB MP3 (~3–4 hours of audio)&lt;br /&gt;
# Python RAM usage exceeded available RAM + swap ceiling&lt;br /&gt;
# OOM killer terminated the process at 22 GB RSS&lt;br /&gt;
# &amp;lt;code&amp;gt;whisper-cli&amp;lt;/code&amp;gt; was never launched → no VRAM activity observed&lt;br /&gt;
&lt;br /&gt;
=== Why VRAM Never Climbed ===&lt;br /&gt;
&amp;lt;code&amp;gt;whisper-cli&amp;lt;/code&amp;gt; runs as a subprocess of the Python GUI. The OOM kill happened during Demucs pre-processing — &amp;lt;code&amp;gt;whisper-cli&amp;lt;/code&amp;gt; was never started, so no VRAM allocation occurred.&lt;br /&gt;
&lt;br /&gt;
From the Buzz log at crash time:&lt;br /&gt;
&amp;lt;pre&amp;gt;~/.var/app/io.github.chidiwilliams.Buzz/.local/state/Buzz/log/logs.txt&amp;lt;/pre&amp;gt;&lt;br /&gt;
The last entry was &amp;lt;code&amp;gt;Will extract speech&amp;lt;/code&amp;gt; — the log never reached &amp;lt;code&amp;gt;Starting whisper file transcription&amp;lt;/code&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
=== Fix ===&lt;br /&gt;
&#039;&#039;&#039;Uncheck &amp;quot;Extract Speech&amp;quot;&#039;&#039;&#039; in the Buzz transcription dialog for any file longer than ~30 minutes. The &amp;lt;code&amp;gt;large-v3-turbo&amp;lt;/code&amp;gt; model has built-in noise tolerance that makes Demucs pre-processing unnecessary in most cases.&lt;br /&gt;
&lt;br /&gt;
Optionally, grow the swapfile if you need Extract Speech for shorter files:&lt;br /&gt;
&amp;lt;pre&amp;gt;sudo swapoff /swap.img&lt;br /&gt;
sudo fallocate -l 16G /swap.img&lt;br /&gt;
sudo mkswap /swap.img&lt;br /&gt;
sudo swapon /swap.img&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Environment Variables ==&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Variable !! Default !! Effect&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;BUZZ_FORCE_CPU&amp;lt;/code&amp;gt; || false || Set to &amp;lt;code&amp;gt;true&amp;lt;/code&amp;gt; to disable GPU inference&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;BUZZ_WHISPERCPP_N_THREADS&amp;lt;/code&amp;gt; || cpu_count / 2 || Override thread count for whisper-cli&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
Set via: &amp;lt;code&amp;gt;flatpak override --user io.github.chidiwilliams.Buzz --env=VAR=value&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Key File Paths ==&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Path !! Description&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;/var/lib/flatpak/app/io.github.chidiwilliams.Buzz/.../buzz/whisper_cpp/whisper-cli&amp;lt;/code&amp;gt; || Bundled Vulkan whisper-cli (libwhisper 1.8.3)&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;~/.var/app/io.github.chidiwilliams.Buzz/cache/Buzz/models/&amp;lt;/code&amp;gt; || Buzz model cache (ggml binaries)&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;~/.var/app/io.github.chidiwilliams.Buzz/.local/state/Buzz/log/logs.txt&amp;lt;/code&amp;gt; || Buzz application log&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;~/.var/app/io.github.chidiwilliams.Buzz/config/Buzz.conf&amp;lt;/code&amp;gt; || Buzz settings&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;~/whisper.cpp/build/bin/whisper-cli&amp;lt;/code&amp;gt; || Custom Vulkan-enabled whisper.cpp build&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;~/bin/whisper-cli-vulkan&amp;lt;/code&amp;gt; || Wrapper script for custom build (sets &amp;lt;code&amp;gt;LD_LIBRARY_PATH&amp;lt;/code&amp;gt;)&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;~/.local/share/pipx/venvs/buzz-captions/lib/python3.12/site-packages/buzz/whisper_cpp/&amp;lt;/code&amp;gt; || pipx install whisper_cpp directory (directly modifiable)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Investigation Summary ==&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Question !! Finding&lt;br /&gt;
|-&lt;br /&gt;
| Is Buzz using the RX 7600? || &#039;&#039;&#039;Yes.&#039;&#039;&#039; &amp;lt;code&amp;gt;using Vulkan0 backend&amp;lt;/code&amp;gt; confirmed inside the Flatpak sandbox.&lt;br /&gt;
|-&lt;br /&gt;
| Was &amp;lt;code&amp;gt;--no-gpu&amp;lt;/code&amp;gt; being added? || &#039;&#039;&#039;No.&#039;&#039;&#039; &amp;lt;code&amp;gt;IS_VULKAN_SUPPORTED = True&amp;lt;/code&amp;gt; in the sandbox; flag is never appended.&lt;br /&gt;
|-&lt;br /&gt;
| Does the large model load correctly? || &#039;&#039;&#039;Yes.&#039;&#039;&#039; 1.6 GB to VRAM, transcribes in ~1.25s on a short clip.&lt;br /&gt;
|-&lt;br /&gt;
| What caused the crash? || &#039;&#039;&#039;Extract Speech (Demucs) OOM.&#039;&#039;&#039; Python killed at 22 GB RSS before whisper-cli launched.&lt;br /&gt;
|-&lt;br /&gt;
| Why was VRAM not climbing? || &amp;lt;code&amp;gt;whisper-cli&amp;lt;/code&amp;gt; was never started — process died during Demucs pre-processing.&lt;br /&gt;
|-&lt;br /&gt;
| Fix? || &#039;&#039;&#039;Uncheck Extract Speech&#039;&#039;&#039; for long files. Clear swap before sessions.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Investigation date: 2026-04-25. System: Ubuntu 24.04, AMD RX 7600, Buzz 1.4.4 (Flatpak).&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== Folder Watch (Automatic Transcription) ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;border:1px solid #a00;background:#fee;padding:0.5em 1em;&amp;quot;&amp;gt;&#039;&#039;&#039;Do not use Folder Watch.&#039;&#039;&#039; It is disruptive at default settings: every audio file dropped into the watched folder is transcribed automatically without asking, silently occupying the GPU/CPU and flooding the folder with output files — and with &#039;&#039;Delete processed files&#039;&#039; ticked, the source audio is deleted afterwards. It is disabled by default and should stay that way. Use [[#File Transcription (Meeting Recording)|File → Import Media]] instead. The settings below are documented for reference only (as configured during testing on 2026-08-09).&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[File:Buzz Folder Watch tab.png|thumb|400px|right|Folder Watch tab: whisper.cpp backend, Large-V3, advanced options unchecked]]&lt;br /&gt;
[[File:Buzz Folder Watch tab full.png|thumb|400px|right|Folder Watch tab — Enable folder watch with input/output folders set to /home/justin/Music]]&lt;br /&gt;
&lt;br /&gt;
=== Settings ===&lt;br /&gt;
&lt;br /&gt;
In &#039;&#039;&#039;Preferences → Folder Watch&#039;&#039;&#039;:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Setting !! Value !! Notes&lt;br /&gt;
|-&lt;br /&gt;
| Enable folder watch || &#039;&#039;&#039;leave unticked&#039;&#039;&#039; || ticking it starts auto-transcribing everything dropped into the input folder&lt;br /&gt;
|-&lt;br /&gt;
| Input folder || &amp;lt;code&amp;gt;/home/justin/Music&amp;lt;/code&amp;gt; || drop recordings here&lt;br /&gt;
|-&lt;br /&gt;
| Output folder || &amp;lt;code&amp;gt;/home/justin/Music&amp;lt;/code&amp;gt; || same folder — files stay put&lt;br /&gt;
|-&lt;br /&gt;
| Delete processed files || &#039;&#039;&#039;unchecked&#039;&#039;&#039; || &#039;&#039;&#039;ticking this deletes the source audio after transcription&#039;&#039;&#039; — keep it unticked&lt;br /&gt;
|-&lt;br /&gt;
| Model || whisper.cpp — Large-V3 || engine choice matters, see below&lt;br /&gt;
|-&lt;br /&gt;
| Task || Transcribe ||&lt;br /&gt;
|-&lt;br /&gt;
| Language || Detect Language ||&lt;br /&gt;
|-&lt;br /&gt;
| Export || TXT || SRT / VTT also available&lt;br /&gt;
|-&lt;br /&gt;
| Word-level timings || &#039;&#039;&#039;unchecked&#039;&#039;&#039; ||&lt;br /&gt;
|-&lt;br /&gt;
| Extract speech || &#039;&#039;&#039;unchecked&#039;&#039;&#039; || &#039;&#039;&#039;do not check — crashes on long files&#039;&#039;&#039; (see [[#OOM Crash with Large Files|OOM Crash with Large Files]])&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Use whisper.cpp instead of the default engine ===&lt;br /&gt;
&lt;br /&gt;
[[File:Buzz model dropdown.png|thumb|400px|right|Model dropdown: whisper.cpp and Faster Whisper]]&lt;br /&gt;
&lt;br /&gt;
The model picker lists two engines: &#039;&#039;&#039;whisper.cpp&#039;&#039;&#039; and &#039;&#039;&#039;Faster Whisper&#039;&#039;&#039;. Faster Whisper is the default — switch to &#039;&#039;&#039;whisper.cpp&#039;&#039;&#039;:&lt;br /&gt;
&lt;br /&gt;
* whisper.cpp uses the &amp;lt;code&amp;gt;ggml-*.bin&amp;lt;/code&amp;gt; models already cached under &amp;lt;code&amp;gt;~/.var/app/io.github.chidiwilliams.Buzz/cache/Buzz/models/&amp;lt;/code&amp;gt; (Flatpak path; &amp;lt;code&amp;gt;~/snap/buzz/…&amp;lt;/code&amp;gt; on snap installs) — no extra download&lt;br /&gt;
* it runs through the bundled Vulkan &amp;lt;code&amp;gt;whisper-cli&amp;lt;/code&amp;gt;, so GPU acceleration applies (see [[#GPU Acceleration|GPU Acceleration]])&lt;br /&gt;
&lt;br /&gt;
[[File:Buzz Models tab whisper.cpp.png|thumb|400px|right|Models tab, whisper.cpp group: Large-V3, Large-V3-Turbo, Medium.en, Large and Large-v2 downloaded]]&lt;br /&gt;
&lt;br /&gt;
In the Models tab, the whisper.cpp group shows the downloaded sizes — Large-V3 and Large-V3-Turbo are the useful ones for meetings (Large-V3-Turbo: best quality/speed trade-off, see [[#How to Transcribe a Meeting|Recommended Settings]]).&lt;br /&gt;
&lt;br /&gt;
=== Leave the advanced options unchecked ===&lt;br /&gt;
&lt;br /&gt;
[[File:Buzz transcription dialog unchecked.png|thumb|400px|right|Transcription dialog: neither Word-level timings nor Extract speech checked]]&lt;br /&gt;
&lt;br /&gt;
In the transcription dialog (shown when folder watch picks up a file) both &#039;&#039;&#039;Word-level timings&#039;&#039;&#039; and &#039;&#039;&#039;Extract speech&#039;&#039;&#039; are left unchecked. Checking &#039;&#039;&#039;Extract speech&#039;&#039;&#039; — the obvious option for a meeting recording — triggers the Demucs pre-processing step that OOM-crashes the app on long files (22 GB RSS kill, [[#OOM Crash with Large Files|see above]]). Keep both unchecked.&lt;br /&gt;
&lt;br /&gt;
=== Result ===&lt;br /&gt;
&lt;br /&gt;
Transcriptions are written next to the source as &amp;lt;code&amp;gt;&amp;amp;lt;original name&amp;amp;gt; (transcribed on &amp;amp;lt;date&amp;amp;gt;).txt&amp;lt;/code&amp;gt;, e.g. &amp;lt;code&amp;gt;2026-08-08 20-56-20 3rd Apocalypse Bob&#039;s ADND1E (transcribed on 09-Aug-2026 01-50-32).txt&amp;lt;/code&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
Config verified 2026-08-09 in &amp;lt;code&amp;gt;~/snap/buzz/570/.config/Buzz.conf&amp;lt;/code&amp;gt; (snap install): &amp;lt;code&amp;gt;folder_watch\enabled&amp;lt;/code&amp;gt; = &amp;lt;code&amp;gt;false&amp;lt;/code&amp;gt; (off — recommended), &amp;lt;code&amp;gt;folder_watch\input_folder&amp;lt;/code&amp;gt; = &amp;lt;code&amp;gt;/home/justin/Music&amp;lt;/code&amp;gt;, &amp;lt;code&amp;gt;folder_watch\output_directory&amp;lt;/code&amp;gt; = &amp;lt;code&amp;gt;/home/justin/Music&amp;lt;/code&amp;gt;, model Whisper.cpp / large-v3, and &amp;lt;code&amp;gt;delete_processed_files&amp;lt;/code&amp;gt;, &amp;lt;code&amp;gt;extract_speech&amp;lt;/code&amp;gt;, &amp;lt;code&amp;gt;word_level_timings&amp;lt;/code&amp;gt; all &amp;lt;code&amp;gt;false&amp;lt;/code&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
== Example: Taglish Test (2026-08-09) ==&lt;br /&gt;
&lt;br /&gt;
A Taglish (Tagalog + English code-switching) test recording, transcribed automatically by Buzz&#039;s Folder Watch during testing (now disabled — see the [[#Folder Watch (Automatic Transcription)|Folder Watch]] warning above):&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;Audio:&#039;&#039;&#039; [[:File:Taglish Test 260809.mp3|Taglish Test 260809.mp3]]&lt;br /&gt;
* &#039;&#039;&#039;Evaluation report:&#039;&#039;&#039; [[:File:Taglish Transcription and Evaluation Report 260809.docx|Taglish Transcription and Evaluation Report 260809.docx]]&lt;br /&gt;
&lt;br /&gt;
The report grades the result &#039;&#039;&#039;95/100 (Excellent)&#039;&#039;&#039; at ~96 % word accuracy. Code-switching between Filipino and English (EDSA, client, project, presentation, brain cells, lunch, work) is handled seamlessly. Noted deviations are typical ASR behavior: punctuation is collapsed into sentence breaks, &amp;quot;Almost two hours&amp;quot; became &amp;quot;Almost 2 hours&amp;quot;, &amp;quot;na-stuck&amp;quot; → &amp;quot;nakastuck&amp;quot;, &amp;quot;kailangan nating&amp;quot; → &amp;quot;kailan nating&amp;quot;.&lt;/div&gt;</summary>
		<author><name>Justinaquino</name></author>
	</entry>
	<entry>
		<id>https://mediawiki.comfac.net/index.php?title=File:Buzz_Folder_Watch_tab.png&amp;diff=276</id>
		<title>File:Buzz Folder Watch tab.png</title>
		<link rel="alternate" type="text/html" href="https://mediawiki.comfac.net/index.php?title=File:Buzz_Folder_Watch_tab.png&amp;diff=276"/>
		<updated>2026-08-09T06:10:17Z</updated>

		<summary type="html">&lt;p&gt;Justinaquino: Mirrored from wiki.gi7b.org (2026-08-09)&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Mirrored from wiki.gi7b.org (2026-08-09)&lt;/div&gt;</summary>
		<author><name>Justinaquino</name></author>
	</entry>
	<entry>
		<id>https://mediawiki.comfac.net/index.php?title=File:Buzz_Models_tab_whisper.cpp.png&amp;diff=275</id>
		<title>File:Buzz Models tab whisper.cpp.png</title>
		<link rel="alternate" type="text/html" href="https://mediawiki.comfac.net/index.php?title=File:Buzz_Models_tab_whisper.cpp.png&amp;diff=275"/>
		<updated>2026-08-09T06:10:16Z</updated>

		<summary type="html">&lt;p&gt;Justinaquino: Mirrored from wiki.gi7b.org (2026-08-09)&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Mirrored from wiki.gi7b.org (2026-08-09)&lt;/div&gt;</summary>
		<author><name>Justinaquino</name></author>
	</entry>
	<entry>
		<id>https://mediawiki.comfac.net/index.php?title=File:Buzz_model_dropdown.png&amp;diff=274</id>
		<title>File:Buzz model dropdown.png</title>
		<link rel="alternate" type="text/html" href="https://mediawiki.comfac.net/index.php?title=File:Buzz_model_dropdown.png&amp;diff=274"/>
		<updated>2026-08-09T06:10:15Z</updated>

		<summary type="html">&lt;p&gt;Justinaquino: Mirrored from wiki.gi7b.org (2026-08-09)&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Mirrored from wiki.gi7b.org (2026-08-09)&lt;/div&gt;</summary>
		<author><name>Justinaquino</name></author>
	</entry>
	<entry>
		<id>https://mediawiki.comfac.net/index.php?title=File:Buzz_Folder_Watch_tab_full.png&amp;diff=273</id>
		<title>File:Buzz Folder Watch tab full.png</title>
		<link rel="alternate" type="text/html" href="https://mediawiki.comfac.net/index.php?title=File:Buzz_Folder_Watch_tab_full.png&amp;diff=273"/>
		<updated>2026-08-09T06:10:14Z</updated>

		<summary type="html">&lt;p&gt;Justinaquino: Mirrored from wiki.gi7b.org (2026-08-09)&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Mirrored from wiki.gi7b.org (2026-08-09)&lt;/div&gt;</summary>
		<author><name>Justinaquino</name></author>
	</entry>
	<entry>
		<id>https://mediawiki.comfac.net/index.php?title=File:Buzz_transcription_dialog_unchecked.png&amp;diff=272</id>
		<title>File:Buzz transcription dialog unchecked.png</title>
		<link rel="alternate" type="text/html" href="https://mediawiki.comfac.net/index.php?title=File:Buzz_transcription_dialog_unchecked.png&amp;diff=272"/>
		<updated>2026-08-09T06:10:13Z</updated>

		<summary type="html">&lt;p&gt;Justinaquino: Mirrored from wiki.gi7b.org (2026-08-09)&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Mirrored from wiki.gi7b.org (2026-08-09)&lt;/div&gt;</summary>
		<author><name>Justinaquino</name></author>
	</entry>
	<entry>
		<id>https://mediawiki.comfac.net/index.php?title=Main_Page&amp;diff=271</id>
		<title>Main Page</title>
		<link rel="alternate" type="text/html" href="https://mediawiki.comfac.net/index.php?title=Main_Page&amp;diff=271"/>
		<updated>2026-08-02T06:05:55Z</updated>

		<summary type="html">&lt;p&gt;Justinaquino: Add New Articles feed (10 most recent, pruned) + auto Newest Pages section, per the hub-and-spoke publishing protocol&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__NOTOC__&lt;br /&gt;
&amp;lt;div style=&amp;quot;background:#f8f9fa; border:1px solid #ddd; border-radius:4px; padding:12px 16px; margin-bottom:20px;&amp;quot;&amp;gt;&lt;br /&gt;
Welcome to the &#039;&#039;&#039;Comfac IT Knowledge Base&#039;&#039;&#039;. Use the sections below to find guides, SOPs, and references organized by topic.&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== New Articles ==&lt;br /&gt;
&lt;br /&gt;
Recent additions to this wiki, newest first — each is also filed in its permanent topic section below. &#039;&#039;&#039;Keep this list to the 10 most recent&#039;&#039;&#039; and prune as new pages are added; nothing is deleted, entries just roll off the feed.&lt;br /&gt;
&lt;br /&gt;
* 2026-08-02 — &#039;&#039;&#039;[[Hugging Face Practical Guide 260802]]&#039;&#039;&#039; — Spaces, local app builds, the Model Hub / dataset viewer, and the enterprise compute tier; the route from stock models to tailored ones and to training on our own data — &#039;&#039;Filed under: AI &amp;amp; Machine Learning&#039;&#039;&lt;br /&gt;
* 2026-08-01 — &#039;&#039;&#039;[[Audio Learning]]&#039;&#039;&#039; — Converting research and study material into scripts written to be listened to rather than read; shared Comfac tool — &#039;&#039;Filed under: Tools &amp;amp; Productivity&#039;&#039;&lt;br /&gt;
* 2026-07-31 — &#039;&#039;&#039;[[Resume CV Renamer Pipeline]]&#039;&#039;&#039; — CV intake → OCR / vision-OCR → AI field extraction → date-stamped rename + VCF export — &#039;&#039;Filed under: Tools &amp;amp; Productivity&#039;&#039;&lt;br /&gt;
* 2026-07-15 — &#039;&#039;&#039;[[De-Risk: Sovereign Training Data v0.1]]&#039;&#039;&#039; — Frontier-Token Quarantine and the ToS-clean path to owned model weights, prompted by the June 2026 Fable 5 export-control suspension — &#039;&#039;Filed under: AI &amp;amp; Machine Learning&#039;&#039;&lt;br /&gt;
* 2026-07-15 — &#039;&#039;&#039;[[Directed Execution: Token-Efficient Agent Development Process]]&#039;&#039;&#039; — Director/Executor/Checker loop and skill distillation for token-efficient agent development — &#039;&#039;Filed under: AI &amp;amp; Machine Learning&#039;&#039;&lt;br /&gt;
* 2026-07-11 — &#039;&#039;&#039;[[Tutorial: Exposing a Dockerized Web App via NPM Direct DB Config]]&#039;&#039;&#039; — Expose a Dockerized web app by editing Nginx Proxy Manager&#039;s database directly — &#039;&#039;Filed under: System Administration &amp;amp; Self-Hosting&#039;&#039;&lt;br /&gt;
* 2026-05-02 — &#039;&#039;&#039;[[Organizing Coder Terminals]]&#039;&#039;&#039; — Tmux + dynamic titles for managing multiple AI agent terminals — &#039;&#039;Filed under: System Administration &amp;amp; Self-Hosting&#039;&#039;&lt;br /&gt;
* 2026-04-28 — &#039;&#039;&#039;[[Forgejo Pages]]&#039;&#039;&#039;&lt;br /&gt;
* 2026-04-24 — &#039;&#039;&#039;[[Buzz Transcription]]&#039;&#039;&#039; — Offline audio/meeting transcription via Whisper (whisper.cpp), Flatpak + Vulkan GPU acceleration — &#039;&#039;Filed under: Tools &amp;amp; Productivity&#039;&#039;&lt;br /&gt;
* 2026-04-23 — &#039;&#039;&#039;[[Training: Setting Up a Firewall for Yourself]]&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== Newest Pages (auto) ==&lt;br /&gt;
&lt;br /&gt;
The 10 most recently created pages — maintains itself.&lt;br /&gt;
&lt;br /&gt;
{{Special:NewPages/10}}&lt;br /&gt;
&lt;br /&gt;
== ERPNext / Frappe ==&lt;br /&gt;
&amp;lt;div style=&amp;quot;column-count:2; column-gap:2em;&amp;quot;&amp;gt;&lt;br /&gt;
* [[Frappe HRMS]] — &#039;&#039;&#039;HR &amp;amp; Payroll&#039;&#039;&#039; (with Philippine Localization)&lt;br /&gt;
* [[Frappe ERPNext/Webshop]] — &#039;&#039;&#039;E-Commerce Webshop&#039;&#039;&#039; (setup, architecture, chapters)&lt;br /&gt;
* [[Manufacturing v16 260125]]&lt;br /&gt;
* [[ERpnext Asset Management Procedure 260113]]&lt;br /&gt;
* [[ERPNext HR Module Outline]]&lt;br /&gt;
* [[ERPNEXT Payroll POC 251212]]&lt;br /&gt;
* [[Comfac ERPNext Strategy Canvas (Expanded)]]&lt;br /&gt;
* [[PAD-Driven ERPNext Strategy 260303]] — PAD/AI-agentic implementation strategy for Frappe ERPNext&lt;br /&gt;
* [[ERPNext v15 Docker Setup Guide]] — Local Docker setup for evaluation, testing, and student use&lt;br /&gt;
* [[Frappe Links and References]]&lt;br /&gt;
* [[Using Frappe Wiki]]&lt;br /&gt;
* [https://docs.frappe.io/cloud/guidelines-for-contributing-regional-compliance-app Guidelines for Contributing Regional Compliance App]&lt;br /&gt;
* [https://docs.frappe.io/cloud/what-are-benches-and-bench-groups What are Benches?]&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== System Administration &amp;amp; Self-Hosting ==&lt;br /&gt;
&amp;lt;div style=&amp;quot;column-count:2; column-gap:2em;&amp;quot;&amp;gt;&lt;br /&gt;
* [[Networking PfSense Index]] — Consolidated index of all networking, pfSense, DNS, and infrastructure guides&lt;br /&gt;
* [[System Hardening Strategy: Win2Lin Migration &amp;amp; Infrastructure 251129]]&lt;br /&gt;
* [[Controller Systems 251213-01]]&lt;br /&gt;
* [[Power Distribution Tree 251213]]&lt;br /&gt;
* [[Introduction: Why Self-Host Your Email?]]&lt;br /&gt;
* [[Mailcow + Thunderbird Setup Guide (Email + Calendar)]]&lt;br /&gt;
* [[Mailcow SOGo: Creating Filters for Events, Approvals, and Organizational Emails]]&lt;br /&gt;
* [[Spoof Timezone Extension – Setup Guide for Comfac Staff]]&lt;br /&gt;
* [[Viber Focus-Stealing]]&lt;br /&gt;
* [[🌐 WordPress Website — *You Own Everything, Learn Everything*]]&lt;br /&gt;
* [[Portainer to Docker Compose Migration Guide]]&lt;br /&gt;
* [[Organizing Coder Terminals]] — Tmux + dynamic titles for managing multiple AI agent terminals&lt;br /&gt;
* [[Editing Mastodon Docker Deployment Guide 260402]]&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Storage &amp;amp; Hardware ==&lt;br /&gt;
&amp;lt;div style=&amp;quot;column-count:2; column-gap:2em;&amp;quot;&amp;gt;&lt;br /&gt;
* [[TrueNAS Configuration Options &amp;amp; Scale Options 251130]]&lt;br /&gt;
* [[TrueNAS Business Plan: Project 251212]]&lt;br /&gt;
* [[Comparison: TrueNAS Mini X+ vs Dell Precision 3680 Tower (2025)]]&lt;br /&gt;
* [[Backblaze Drive Stats for Server and Storage Qualification]]&lt;br /&gt;
* [[Industrial Controllers and Water Utilities 251011]]&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== AI &amp;amp; Machine Learning ==&lt;br /&gt;
&amp;lt;div style=&amp;quot;column-count:2; column-gap:2em;&amp;quot;&amp;gt;&lt;br /&gt;
* [[OpenWebUI - 251128-justin]]&lt;br /&gt;
* [[Comfac GPU Scaling and AI Research Goals]]&lt;br /&gt;
* [[🧠 Process: Selecting and Installing the Right Ollama Model for Your Hardware]]&lt;br /&gt;
* [[Ollama GNOME System Tray Panel 260401]] — GNOME system tray toggle to start/stop Ollama and reclaim VRAM&lt;br /&gt;
* [[Proceedural Agentic Development Methodology 260304]] — Methodology for systematic agent use&lt;br /&gt;
* [[Project OpenCoder: AI Independence Initiative]] — Strategic roadmap for manufacturing intelligence&lt;br /&gt;
* [[OpenCoder Qwen35 Agentic Setup 260330]] — Qwen3.5 Modelfile fix for tool calling in OpenCode; thinking mode suppression; HDD vs SSD findings&lt;br /&gt;
* [[OpenCode Multi-Provider Configuration Guide 260401]] — Dual-mode AI coding setup with Kimi cloud + Ollama local models via Distrobox&lt;br /&gt;
* [[PAD-Driven ERPNext Strategy 260303]] — Procedural Agentic Development for Frappe/ERPNext configuration and deployment&lt;br /&gt;
* [[Directed Execution: Token-Efficient Agent Development Process]] — Director/Executor/Checker loop and skill distillation for token-efficient agent development (v0.1, 2026-07-15)&lt;br /&gt;
* [[De-Risk: Sovereign Training Data v0.1]] — Frontier-Token Quarantine and the ToS-clean path to owned model weights, prompted by the June 2026 Fable 5 export-control suspension (v0.1, 2026-07-15)&lt;br /&gt;
* [[Hugging Face Practical Guide 260802]] — Spaces, local app builds, the Model Hub / dataset viewer, and the enterprise compute tier; the route from stock models to tailored ones and to training on our own data (2026-08-02)&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Job Descriptions ==&lt;br /&gt;
&amp;lt;div style=&amp;quot;column-count:2; column-gap:2em;&amp;quot;&amp;gt;&lt;br /&gt;
* [[Job Descriptions]] — Index of all official job descriptions (IT, Engineering, Sales)&lt;br /&gt;
* [[JD IT Project Staff]] — IT Project Staff&lt;br /&gt;
* [[JD Security Compliance Assistant 260224]] — Security and Compliance Assistant (SCA)&lt;br /&gt;
* [[JD Engineering Designer 260108]] — Engineering Designer&lt;br /&gt;
* [[JD Engineering Supervisor 260109]] — Engineering Supervisor&lt;br /&gt;
* [[JD Technical Sales 260112]] — Technical Sales Engineer&lt;br /&gt;
* [[JD Marketing Assistant 251119]] — Marketing Assistant&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== IT Operations &amp;amp; SOPs ==&lt;br /&gt;
&amp;lt;div style=&amp;quot;column-count:2; column-gap:2em;&amp;quot;&amp;gt;&lt;br /&gt;
* [[SCA Program Plan 260320]] — Security &amp;amp; Compliance Assistant Program Plan v3 (ISO 9001/27001, PDCA, distributed audit model)&lt;br /&gt;
* [[SOP: Inter-Company Ordering and Production Process 260203]] — Ordering and production workflow between Sister Companies and the Cabuyao Plant&lt;br /&gt;
* [[Memo: Team Roles &amp;amp; Reporting Process Clarification 260320]] — Role boundaries, data ownership, and the new ERPNext-driven reporting paradigm&lt;br /&gt;
* [[Standard Operating Procedure: Distributed Minute Taking &amp;amp; Task Ownership 251208]]&lt;br /&gt;
* [[Business Continuity]]&lt;br /&gt;
* [[Procedure: CC-Blast Data Breach Prevention]]&lt;br /&gt;
* [[8D (Eight Discipline) Problem Solving Procedure]]&lt;br /&gt;
* [[Offline Malware Remediation &amp;amp; Data Recovery]]&lt;br /&gt;
* [[Troubleshooting: Access &amp;amp; Permission Issues]]&lt;br /&gt;
* [[Steps to Repair and OCR a Scanned or Corrupted PDF in Ubuntu]]&lt;br /&gt;
* [[IT IMPORTS PROCESSES]]&lt;br /&gt;
* [[IT Purchase Requests 241126]]&lt;br /&gt;
* [[IT REQUEST (OP-ERP-ITR) - EDITED 250801]]&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Sales &amp;amp; Business ==&lt;br /&gt;
&amp;lt;div style=&amp;quot;column-count:2; column-gap:2em;&amp;quot;&amp;gt;&lt;br /&gt;
* [[Comfac Sales Knowledge Base]]&lt;br /&gt;
* [[Comfac CRM – Customer Qualification &amp;amp; Conversion Process]]&lt;br /&gt;
* [[Partner Reseller Pricing 251109]]&lt;br /&gt;
* [[Biz Analysis Methodology 251109]]&lt;br /&gt;
* [[2026 MIS IT KRA KPI Biz Plan]]&lt;br /&gt;
* [[SALES INVOICE TAX OUTPUT 250829]]&lt;br /&gt;
* [[Projects in Process Report 251023]]&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Tools &amp;amp; Productivity ==&lt;br /&gt;
&amp;lt;div style=&amp;quot;column-count:2; column-gap:2em;&amp;quot;&amp;gt;&lt;br /&gt;
* [[Excel Description Filler Tool 📝]]&lt;br /&gt;
* [[Resume CV Renamer Pipeline|Resume / CV Renamer Pipeline]] — CV intake → OCR / vision-OCR → AI field extraction → date-stamped rename + VCF export&lt;br /&gt;
* [https://github.com/Comfac-Global-Group/comfac-studies Comfac Studies - Spaced Repetiton Active Recall]&lt;br /&gt;
* [[LibreOffice / Nextcloud Office – &amp;quot;Due Tasks&amp;quot; Conditional Formatting]]&lt;br /&gt;
* [[Google Drive and Shared Drive Training]]&lt;br /&gt;
* [[260108 CGG- GitHub Administration Guide]]&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Wiki &amp;amp; Documentation ==&lt;br /&gt;
&amp;lt;div style=&amp;quot;column-count:2; column-gap:2em;&amp;quot;&amp;gt;&lt;br /&gt;
* [[Mediawiki Setting Up Guide]]&lt;br /&gt;
* [[Contributing to Only Office 260307]]&lt;br /&gt;
* [[Mediawiki Additional Configuration]]&lt;br /&gt;
* [[Mediawiki Docker Migration Guide]]&lt;br /&gt;
* [[Home]]&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Tutorials ==&lt;br /&gt;
&amp;lt;div style=&amp;quot;column-count:2; column-gap:2em;&amp;quot;&amp;gt;&lt;br /&gt;
* [[Claude Code Isolation and Burner Workflow 260211]] — Secure AI development environment setup&lt;br /&gt;
* [[Opencode isolation and burner workflow 260216]] — OpenCode CLI isolation procedures&lt;br /&gt;
* [[LibreOffice Calc NumToWords Extension Complete Guide]] — Extension development&lt;br /&gt;
* [[ERPNext v15 Docker Setup Guide]] — ERPNext v15 local Docker setup (students, evaluators, thin-client demos)&lt;br /&gt;
* [[Erpnextv15-SSH-setup-241111]] — ERPNext v15 SSH/Portainer production setup&lt;br /&gt;
* [[Git-Mediawiki Local Editing 260223]] — Wiki editing with Git&lt;br /&gt;
* [[Understanding &amp;amp; Fixing Kernel Panics 260212]] — System debugging&lt;br /&gt;
* [[OpenCode in Android Termux 260303]] — OpenCode in Android&lt;br /&gt;
* [[OpenCoder Qwen35 Agentic Setup 260330]] — Qwen3.5 agentic setup: Modelfile, tool calling fix, storage impact&lt;br /&gt;
* [[Lora Basics 260304]] — LORA research&lt;br /&gt;
* [https://github.com/anomalyco/opencode/issues/4283#issuecomment-4083399210 Opencode Copy-paste Clipboard doesnt Work - Solution]   https://github.com/anomalyco/opencode/issues/4283#issuecomment-4083399210&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Research ==&lt;br /&gt;
&amp;lt;div style=&amp;quot;column-count:2; column-gap:2em;&amp;quot;&amp;gt;&lt;br /&gt;
* [[Ladybird Browser]] — Browser engine development&lt;br /&gt;
* [[Computing Architecture]] — System design principles&lt;br /&gt;
* [[Backblaze Drive Stats for Server and Storage Qualification 260219]] — Drive reliability analysis&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== For Users Only ==&lt;br /&gt;
* [[Private:Private Ngani]]&lt;br /&gt;
* [[Private:Private Nganipart2]]&lt;br /&gt;
&lt;br /&gt;
== CIT-OJT Project Documentations ==&lt;br /&gt;
* [[OJTDocs: For OJTs only]]&lt;br /&gt;
&lt;br /&gt;
== Need Help? ==&lt;br /&gt;
&amp;lt;div style=&amp;quot;column-count:2; column-gap:2em;&amp;quot;&amp;gt;&lt;br /&gt;
* [[Troubleshooting: Access &amp;amp; Permission Issues]]&lt;br /&gt;
* [https://www.mediawiki.org/wiki/Special:MyLanguage/Help:Contents MediaWiki User&#039;s Guide]&lt;br /&gt;
* [https://www.mediawiki.org/wiki/Special:MyLanguage/Manual:Configuration_settings Configuration settings]&lt;br /&gt;
* [https://www.mediawiki.org/wiki/Special:MyLanguage/Manual:FAQ MediaWiki FAQ]&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;/div&gt;</summary>
		<author><name>Justinaquino</name></author>
	</entry>
	<entry>
		<id>https://mediawiki.comfac.net/index.php?title=Main_Page&amp;diff=270</id>
		<title>Main Page</title>
		<link rel="alternate" type="text/html" href="https://mediawiki.comfac.net/index.php?title=Main_Page&amp;diff=270"/>
		<updated>2026-08-02T05:03:29Z</updated>

		<summary type="html">&lt;p&gt;Justinaquino: File Hugging Face Practical Guide 260802 in the index&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__NOTOC__&lt;br /&gt;
&amp;lt;div style=&amp;quot;background:#f8f9fa; border:1px solid #ddd; border-radius:4px; padding:12px 16px; margin-bottom:20px;&amp;quot;&amp;gt;&lt;br /&gt;
Welcome to the &#039;&#039;&#039;Comfac IT Knowledge Base&#039;&#039;&#039;. Use the sections below to find guides, SOPs, and references organized by topic.&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== ERPNext / Frappe ==&lt;br /&gt;
&amp;lt;div style=&amp;quot;column-count:2; column-gap:2em;&amp;quot;&amp;gt;&lt;br /&gt;
* [[Frappe HRMS]] — &#039;&#039;&#039;HR &amp;amp; Payroll&#039;&#039;&#039; (with Philippine Localization)&lt;br /&gt;
* [[Frappe ERPNext/Webshop]] — &#039;&#039;&#039;E-Commerce Webshop&#039;&#039;&#039; (setup, architecture, chapters)&lt;br /&gt;
* [[Manufacturing v16 260125]]&lt;br /&gt;
* [[ERpnext Asset Management Procedure 260113]]&lt;br /&gt;
* [[ERPNext HR Module Outline]]&lt;br /&gt;
* [[ERPNEXT Payroll POC 251212]]&lt;br /&gt;
* [[Comfac ERPNext Strategy Canvas (Expanded)]]&lt;br /&gt;
* [[PAD-Driven ERPNext Strategy 260303]] — PAD/AI-agentic implementation strategy for Frappe ERPNext&lt;br /&gt;
* [[ERPNext v15 Docker Setup Guide]] — Local Docker setup for evaluation, testing, and student use&lt;br /&gt;
* [[Frappe Links and References]]&lt;br /&gt;
* [[Using Frappe Wiki]]&lt;br /&gt;
* [https://docs.frappe.io/cloud/guidelines-for-contributing-regional-compliance-app Guidelines for Contributing Regional Compliance App]&lt;br /&gt;
* [https://docs.frappe.io/cloud/what-are-benches-and-bench-groups What are Benches?]&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== System Administration &amp;amp; Self-Hosting ==&lt;br /&gt;
&amp;lt;div style=&amp;quot;column-count:2; column-gap:2em;&amp;quot;&amp;gt;&lt;br /&gt;
* [[Networking PfSense Index]] — Consolidated index of all networking, pfSense, DNS, and infrastructure guides&lt;br /&gt;
* [[System Hardening Strategy: Win2Lin Migration &amp;amp; Infrastructure 251129]]&lt;br /&gt;
* [[Controller Systems 251213-01]]&lt;br /&gt;
* [[Power Distribution Tree 251213]]&lt;br /&gt;
* [[Introduction: Why Self-Host Your Email?]]&lt;br /&gt;
* [[Mailcow + Thunderbird Setup Guide (Email + Calendar)]]&lt;br /&gt;
* [[Mailcow SOGo: Creating Filters for Events, Approvals, and Organizational Emails]]&lt;br /&gt;
* [[Spoof Timezone Extension – Setup Guide for Comfac Staff]]&lt;br /&gt;
* [[Viber Focus-Stealing]]&lt;br /&gt;
* [[🌐 WordPress Website — *You Own Everything, Learn Everything*]]&lt;br /&gt;
* [[Portainer to Docker Compose Migration Guide]]&lt;br /&gt;
* [[Organizing Coder Terminals]] — Tmux + dynamic titles for managing multiple AI agent terminals&lt;br /&gt;
* [[Editing Mastodon Docker Deployment Guide 260402]]&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Storage &amp;amp; Hardware ==&lt;br /&gt;
&amp;lt;div style=&amp;quot;column-count:2; column-gap:2em;&amp;quot;&amp;gt;&lt;br /&gt;
* [[TrueNAS Configuration Options &amp;amp; Scale Options 251130]]&lt;br /&gt;
* [[TrueNAS Business Plan: Project 251212]]&lt;br /&gt;
* [[Comparison: TrueNAS Mini X+ vs Dell Precision 3680 Tower (2025)]]&lt;br /&gt;
* [[Backblaze Drive Stats for Server and Storage Qualification]]&lt;br /&gt;
* [[Industrial Controllers and Water Utilities 251011]]&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== AI &amp;amp; Machine Learning ==&lt;br /&gt;
&amp;lt;div style=&amp;quot;column-count:2; column-gap:2em;&amp;quot;&amp;gt;&lt;br /&gt;
* [[OpenWebUI - 251128-justin]]&lt;br /&gt;
* [[Comfac GPU Scaling and AI Research Goals]]&lt;br /&gt;
* [[🧠 Process: Selecting and Installing the Right Ollama Model for Your Hardware]]&lt;br /&gt;
* [[Ollama GNOME System Tray Panel 260401]] — GNOME system tray toggle to start/stop Ollama and reclaim VRAM&lt;br /&gt;
* [[Proceedural Agentic Development Methodology 260304]] — Methodology for systematic agent use&lt;br /&gt;
* [[Project OpenCoder: AI Independence Initiative]] — Strategic roadmap for manufacturing intelligence&lt;br /&gt;
* [[OpenCoder Qwen35 Agentic Setup 260330]] — Qwen3.5 Modelfile fix for tool calling in OpenCode; thinking mode suppression; HDD vs SSD findings&lt;br /&gt;
* [[OpenCode Multi-Provider Configuration Guide 260401]] — Dual-mode AI coding setup with Kimi cloud + Ollama local models via Distrobox&lt;br /&gt;
* [[PAD-Driven ERPNext Strategy 260303]] — Procedural Agentic Development for Frappe/ERPNext configuration and deployment&lt;br /&gt;
* [[Directed Execution: Token-Efficient Agent Development Process]] — Director/Executor/Checker loop and skill distillation for token-efficient agent development (v0.1, 2026-07-15)&lt;br /&gt;
* [[De-Risk: Sovereign Training Data v0.1]] — Frontier-Token Quarantine and the ToS-clean path to owned model weights, prompted by the June 2026 Fable 5 export-control suspension (v0.1, 2026-07-15)&lt;br /&gt;
* [[Hugging Face Practical Guide 260802]] — Spaces, local app builds, the Model Hub / dataset viewer, and the enterprise compute tier; the route from stock models to tailored ones and to training on our own data (2026-08-02)&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Job Descriptions ==&lt;br /&gt;
&amp;lt;div style=&amp;quot;column-count:2; column-gap:2em;&amp;quot;&amp;gt;&lt;br /&gt;
* [[Job Descriptions]] — Index of all official job descriptions (IT, Engineering, Sales)&lt;br /&gt;
* [[JD IT Project Staff]] — IT Project Staff&lt;br /&gt;
* [[JD Security Compliance Assistant 260224]] — Security and Compliance Assistant (SCA)&lt;br /&gt;
* [[JD Engineering Designer 260108]] — Engineering Designer&lt;br /&gt;
* [[JD Engineering Supervisor 260109]] — Engineering Supervisor&lt;br /&gt;
* [[JD Technical Sales 260112]] — Technical Sales Engineer&lt;br /&gt;
* [[JD Marketing Assistant 251119]] — Marketing Assistant&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== IT Operations &amp;amp; SOPs ==&lt;br /&gt;
&amp;lt;div style=&amp;quot;column-count:2; column-gap:2em;&amp;quot;&amp;gt;&lt;br /&gt;
* [[SCA Program Plan 260320]] — Security &amp;amp; Compliance Assistant Program Plan v3 (ISO 9001/27001, PDCA, distributed audit model)&lt;br /&gt;
* [[SOP: Inter-Company Ordering and Production Process 260203]] — Ordering and production workflow between Sister Companies and the Cabuyao Plant&lt;br /&gt;
* [[Memo: Team Roles &amp;amp; Reporting Process Clarification 260320]] — Role boundaries, data ownership, and the new ERPNext-driven reporting paradigm&lt;br /&gt;
* [[Standard Operating Procedure: Distributed Minute Taking &amp;amp; Task Ownership 251208]]&lt;br /&gt;
* [[Business Continuity]]&lt;br /&gt;
* [[Procedure: CC-Blast Data Breach Prevention]]&lt;br /&gt;
* [[8D (Eight Discipline) Problem Solving Procedure]]&lt;br /&gt;
* [[Offline Malware Remediation &amp;amp; Data Recovery]]&lt;br /&gt;
* [[Troubleshooting: Access &amp;amp; Permission Issues]]&lt;br /&gt;
* [[Steps to Repair and OCR a Scanned or Corrupted PDF in Ubuntu]]&lt;br /&gt;
* [[IT IMPORTS PROCESSES]]&lt;br /&gt;
* [[IT Purchase Requests 241126]]&lt;br /&gt;
* [[IT REQUEST (OP-ERP-ITR) - EDITED 250801]]&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Sales &amp;amp; Business ==&lt;br /&gt;
&amp;lt;div style=&amp;quot;column-count:2; column-gap:2em;&amp;quot;&amp;gt;&lt;br /&gt;
* [[Comfac Sales Knowledge Base]]&lt;br /&gt;
* [[Comfac CRM – Customer Qualification &amp;amp; Conversion Process]]&lt;br /&gt;
* [[Partner Reseller Pricing 251109]]&lt;br /&gt;
* [[Biz Analysis Methodology 251109]]&lt;br /&gt;
* [[2026 MIS IT KRA KPI Biz Plan]]&lt;br /&gt;
* [[SALES INVOICE TAX OUTPUT 250829]]&lt;br /&gt;
* [[Projects in Process Report 251023]]&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Tools &amp;amp; Productivity ==&lt;br /&gt;
&amp;lt;div style=&amp;quot;column-count:2; column-gap:2em;&amp;quot;&amp;gt;&lt;br /&gt;
* [[Excel Description Filler Tool 📝]]&lt;br /&gt;
* [[Resume CV Renamer Pipeline|Resume / CV Renamer Pipeline]] — CV intake → OCR / vision-OCR → AI field extraction → date-stamped rename + VCF export&lt;br /&gt;
* [https://github.com/Comfac-Global-Group/comfac-studies Comfac Studies - Spaced Repetiton Active Recall]&lt;br /&gt;
* [[LibreOffice / Nextcloud Office – &amp;quot;Due Tasks&amp;quot; Conditional Formatting]]&lt;br /&gt;
* [[Google Drive and Shared Drive Training]]&lt;br /&gt;
* [[260108 CGG- GitHub Administration Guide]]&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Wiki &amp;amp; Documentation ==&lt;br /&gt;
&amp;lt;div style=&amp;quot;column-count:2; column-gap:2em;&amp;quot;&amp;gt;&lt;br /&gt;
* [[Mediawiki Setting Up Guide]]&lt;br /&gt;
* [[Contributing to Only Office 260307]]&lt;br /&gt;
* [[Mediawiki Additional Configuration]]&lt;br /&gt;
* [[Mediawiki Docker Migration Guide]]&lt;br /&gt;
* [[Home]]&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Tutorials ==&lt;br /&gt;
&amp;lt;div style=&amp;quot;column-count:2; column-gap:2em;&amp;quot;&amp;gt;&lt;br /&gt;
* [[Claude Code Isolation and Burner Workflow 260211]] — Secure AI development environment setup&lt;br /&gt;
* [[Opencode isolation and burner workflow 260216]] — OpenCode CLI isolation procedures&lt;br /&gt;
* [[LibreOffice Calc NumToWords Extension Complete Guide]] — Extension development&lt;br /&gt;
* [[ERPNext v15 Docker Setup Guide]] — ERPNext v15 local Docker setup (students, evaluators, thin-client demos)&lt;br /&gt;
* [[Erpnextv15-SSH-setup-241111]] — ERPNext v15 SSH/Portainer production setup&lt;br /&gt;
* [[Git-Mediawiki Local Editing 260223]] — Wiki editing with Git&lt;br /&gt;
* [[Understanding &amp;amp; Fixing Kernel Panics 260212]] — System debugging&lt;br /&gt;
* [[OpenCode in Android Termux 260303]] — OpenCode in Android&lt;br /&gt;
* [[OpenCoder Qwen35 Agentic Setup 260330]] — Qwen3.5 agentic setup: Modelfile, tool calling fix, storage impact&lt;br /&gt;
* [[Lora Basics 260304]] — LORA research&lt;br /&gt;
* [https://github.com/anomalyco/opencode/issues/4283#issuecomment-4083399210 Opencode Copy-paste Clipboard doesnt Work - Solution]   https://github.com/anomalyco/opencode/issues/4283#issuecomment-4083399210&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Research ==&lt;br /&gt;
&amp;lt;div style=&amp;quot;column-count:2; column-gap:2em;&amp;quot;&amp;gt;&lt;br /&gt;
* [[Ladybird Browser]] — Browser engine development&lt;br /&gt;
* [[Computing Architecture]] — System design principles&lt;br /&gt;
* [[Backblaze Drive Stats for Server and Storage Qualification 260219]] — Drive reliability analysis&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== For Users Only ==&lt;br /&gt;
* [[Private:Private Ngani]]&lt;br /&gt;
* [[Private:Private Nganipart2]]&lt;br /&gt;
&lt;br /&gt;
== CIT-OJT Project Documentations ==&lt;br /&gt;
* [[OJTDocs: For OJTs only]]&lt;br /&gt;
&lt;br /&gt;
== Need Help? ==&lt;br /&gt;
&amp;lt;div style=&amp;quot;column-count:2; column-gap:2em;&amp;quot;&amp;gt;&lt;br /&gt;
* [[Troubleshooting: Access &amp;amp; Permission Issues]]&lt;br /&gt;
* [https://www.mediawiki.org/wiki/Special:MyLanguage/Help:Contents MediaWiki User&#039;s Guide]&lt;br /&gt;
* [https://www.mediawiki.org/wiki/Special:MyLanguage/Manual:Configuration_settings Configuration settings]&lt;br /&gt;
* [https://www.mediawiki.org/wiki/Special:MyLanguage/Manual:FAQ MediaWiki FAQ]&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;/div&gt;</summary>
		<author><name>Justinaquino</name></author>
	</entry>
	<entry>
		<id>https://mediawiki.comfac.net/index.php?title=Hugging_Face_Practical_Guide_260802&amp;diff=269</id>
		<title>Hugging Face Practical Guide 260802</title>
		<link rel="alternate" type="text/html" href="https://mediawiki.comfac.net/index.php?title=Hugging_Face_Practical_Guide_260802&amp;diff=269"/>
		<updated>2026-08-02T05:03:29Z</updated>

		<summary type="html">&lt;p&gt;Justinaquino: New article: Hugging Face practical guide (Spaces, local builds, Model Hub/datasets, enterprise + hf jobs) - lae/HF backlog&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Hugging Face — Practical Guide =&lt;br /&gt;
&lt;br /&gt;
&amp;lt;blockquote&amp;gt;&#039;&#039;&#039;Compiled:&#039;&#039;&#039; 2026-08-02 · &#039;&#039;&#039;Status:&#039;&#039;&#039; Living page — open for deeper research&amp;lt;/blockquote&amp;gt;&lt;br /&gt;
&amp;lt;blockquote&amp;gt;&#039;&#039;&#039;Why it is here:&#039;&#039;&#039; Hugging Face is currently used at Comfac as a download endpoint for stock model files. It is four things, and the other three are the ones we under-use.&amp;lt;/blockquote&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The goal behind this page: access to free open-source models that are &#039;&#039;&#039;better than the stock ones&#039;&#039;&#039; and more tailored to a specific job, the &#039;&#039;&#039;harnesses&#039;&#039;&#039; built around them, and the &#039;&#039;&#039;training resources&#039;&#039;&#039; that take a corpus of a few hundred owned data points and work it up toward thousands.&lt;br /&gt;
&lt;br /&gt;
That last one is the unclosed loop in [[De-Risk: Sovereign Training Data v0.1]] — we have clean, owned process knowledge and no mechanism yet for turning it into &#039;&#039;&#039;weights we own&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
Each section below ends with &#039;&#039;&#039;search keywords&#039;&#039;&#039; for going deeper on that one bucket.&lt;br /&gt;
&lt;br /&gt;
== Source videos ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;blockquote&amp;gt;&#039;&#039;&#039;Note:&#039;&#039;&#039; this wiki does not have the &amp;lt;code&amp;gt;EmbedVideo&amp;lt;/code&amp;gt; extension installed (verified 2026-08-02 via &amp;lt;code&amp;gt;api.php ... siprop=extensions&amp;lt;/code&amp;gt;), so videos are listed as preview cards rather than embedded players. The [https://wiki.gi7b.org/index.php/Hugging_Face_Practical_Guide_260802 gwiki copy of this page] has EmbedVideo and shows them inline. Installing the extension here is an administrator action.&amp;lt;/blockquote&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width:100%;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width:34%;&amp;quot; | Video !! What it covers !! Use it for&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;[https://www.youtube.com/watch?v=3kRB2TXewus What Is Hugging Face and How To Use It]&#039;&#039;&#039;&lt;br /&gt;
| The general tour — Spaces, the Model Hub, the Datasets section, and how they relate.&lt;br /&gt;
| Sections 1–3 below. Start here if Hugging Face has only ever been a download link.&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;[https://www.youtube.com/watch?v=wUzfRBi9wZ0 The Hugging Face Hub for Enterprise &amp;amp; Academia]&#039;&#039;&#039;&lt;br /&gt;
| Private workspaces, SSO, access control, separated compute/storage billing, SSH onto Spaces hardware, and remote training with &amp;lt;code&amp;gt;hf jobs&amp;lt;/code&amp;gt;.&lt;br /&gt;
| Section 4. This is the one that matters for training on our own data.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== 1. Exploring and using pre-built AI (Spaces) ==&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Spaces&#039;&#039;&#039; are ready-to-use, browser-based applications built by the AI community — image and video generators, voice synthesis, transcription, live demos of new papers. All runnable without writing code.&lt;br /&gt;
&lt;br /&gt;
If a Space is useful, click &#039;&#039;&#039;Duplicate Space&#039;&#039;&#039;. That forks it into your own account as your own copy, public or private, on hardware you select.&lt;br /&gt;
&lt;br /&gt;
Two things worth internalising:&lt;br /&gt;
&lt;br /&gt;
* A Space is a &#039;&#039;&#039;real repository&#039;&#039;&#039;, not a demo sandbox. Duplicating gives you the source.&lt;br /&gt;
* Most Spaces are &#039;&#039;&#039;Gradio&#039;&#039;&#039; apps. Learn Gradio once and the whole catalogue becomes editable.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Search keywords:&#039;&#039;&#039; &#039;&#039;&amp;quot;Hugging Face Spaces tutorial&amp;quot;&#039;&#039; · &#039;&#039;&amp;quot;How to build and deploy Gradio apps on Hugging Face&amp;quot;&#039;&#039; · &#039;&#039;&amp;quot;Duplicating Hugging Face Spaces&amp;quot;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== 2. Building custom apps locally ==&lt;br /&gt;
&lt;br /&gt;
Because Spaces are open source, the code comes to your machine. Clone the repository, open it in an AI-assisted IDE, run it locally, and connect your own API keys instead of the demo&#039;s. From there the IDE can help you change colours, fonts, or actual behaviour.&lt;br /&gt;
&lt;br /&gt;
This is the cheapest route to &#039;&#039;&#039;a harness we control&#039;&#039;&#039; — instead of writing scaffolding from scratch, start from a working app and cut it down.&lt;br /&gt;
&lt;br /&gt;
Practical notes:&lt;br /&gt;
* Expect the first local run to fail on dependencies or a missing key. That failure, written down, is the reusable knowledge — not the happy path.&lt;br /&gt;
* Check the licence before adapting anything. &#039;&#039;&#039;Open-source and permissively-licensed are not the same thing&#039;&#039;&#039;, and licence direction is one-way once code is borrowed.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Search keywords:&#039;&#039;&#039; &#039;&#039;&amp;quot;Clone Hugging Face Space locally&amp;quot;&#039;&#039; · &#039;&#039;&amp;quot;Build AI apps with Cursor and Hugging Face&amp;quot;&#039;&#039; · &#039;&#039;&amp;quot;Integrate LLM API keys in Hugging Face local apps&amp;quot;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== 3. Finding models and datasets ==&lt;br /&gt;
&lt;br /&gt;
The &#039;&#039;&#039;Model Hub&#039;&#039;&#039; is the core: over 1.5 million open-source models categorised &#039;&#039;&#039;by task&#039;&#039;&#039; — computer vision, NLP, audio, robotics. The &#039;&#039;&#039;Datasets&#039;&#039;&#039; section holds the data that trained them.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Navigate by task tag, not by keyword.&#039;&#039;&#039; Searching an acronym returns papers; filtering by task returns weights:&lt;br /&gt;
&lt;br /&gt;
: &amp;lt;code&amp;gt;https://huggingface.co/models?pipeline_tag=robotics&amp;lt;/code&amp;gt;&lt;br /&gt;
: &amp;lt;code&amp;gt;https://huggingface.co/api/models?pipeline_tag=robotics&amp;lt;/code&amp;gt; &#039;&#039;(API form, for scripting)&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
The advanced feature almost nobody touches is the &#039;&#039;&#039;dataset viewer&#039;&#039;&#039;: chat with a dataset through an AI agent and &#039;&#039;&#039;run SQL queries in the browser&#039;&#039;&#039; to analyse it &#039;&#039;before&#039;&#039; downloading a single gigabyte. For evaluating training data this is the highest-value habit on the page.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Our standing admission rule applies here:&#039;&#039;&#039; a model card is a &#039;&#039;&#039;claim, not a measurement&#039;&#039;&#039;. Nothing enters the local model roster on a card alone — it enters on a real API call, the same gate used for the Synopsis model-selection slate. See [[Comfac GPU Scaling and AI Research Goals]] §Applied Model Evaluation and [[🧠 Process: Selecting and Installing the Right Ollama Model for Your Hardware]].&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Search keywords:&#039;&#039;&#039; &#039;&#039;&amp;quot;How to choose and run Hugging Face models&amp;quot;&#039;&#039; · &#039;&#039;&amp;quot;Hugging Face dataset viewer SQL tutorial&amp;quot;&#039;&#039; · &#039;&#039;&amp;quot;Fine-tuning open source models Hugging Face&amp;quot;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== 4. Scaling for teams and enterprise ==&lt;br /&gt;
&lt;br /&gt;
For organisations and academic teams the paid tiers add private workspaces, single sign-on (SSO), and granular access control.&lt;br /&gt;
&lt;br /&gt;
The structural benefit is that &#039;&#039;&#039;compute and storage are billed separately&#039;&#039;&#039; — no paying for idle hardware. Two working modes follow:&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;SSH directly onto Spaces hardware&#039;&#039;&#039; and develop there, as if it were a remote box.&lt;br /&gt;
* &#039;&#039;&#039;&amp;lt;code&amp;gt;hf jobs&amp;lt;/code&amp;gt;&#039;&#039;&#039; — fire a heavy training workload at remote hardware and collect the result.&lt;br /&gt;
&lt;br /&gt;
The second is what makes a fine-tune possible without owning the GPU it would need.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Search keywords:&#039;&#039;&#039; &#039;&#039;&amp;quot;Hugging Face Enterprise setup guide&amp;quot;&#039;&#039; · &#039;&#039;&amp;quot;Running hf jobs on zero GPU Hugging Face&amp;quot;&#039;&#039; · &#039;&#039;&amp;quot;Hugging Face private workspaces and security&amp;quot;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Open problem — where this is going ==&lt;br /&gt;
&lt;br /&gt;
Three goals, none closed. Tracked in &amp;lt;code&amp;gt;work/comfac-operations/BACKLOG-huggingface-model-sourcing-and-training.md&amp;lt;/code&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
# &#039;&#039;&#039;Better than stock.&#039;&#039;&#039; The models we run locally today are stock bases. Tuned community models in the same size band may follow instructions better for a specific task, at no cost — but only a run against a gate written &#039;&#039;&#039;beforehand&#039;&#039;&#039; counts as evidence.&lt;br /&gt;
# &#039;&#039;&#039;Harnesses instead of rebuilds.&#039;&#039;&#039; Identify the Spaces that overlap tooling we would otherwise write ourselves.&lt;br /&gt;
# &#039;&#039;&#039;Training on owned data.&#039;&#039;&#039; Start at a few hundred data points and work toward thousands.&lt;br /&gt;
&lt;br /&gt;
=== The constraint on goal 3 ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Frontier-Token Quarantine is binding.&#039;&#039;&#039; Per [[De-Risk: Sovereign Training Data v0.1]], distilling commercial frontier-model outputs into our own weights trades a regulatory dependency for a &#039;&#039;&#039;contractual liability&#039;&#039;&#039; — in writing, with discoverable provenance logs. Any training corpus must be &#039;&#039;&#039;clean by construction&#039;&#039;&#039;. Tooling cannot launder provenance; that was named as the weakest claim in the source report.&lt;br /&gt;
&lt;br /&gt;
=== Hardware reality check ===&lt;br /&gt;
&lt;br /&gt;
Anything meant to run on a normal workstation has to fit the VRAM actually available, &#039;&#039;&#039;alongside whatever else is already resident&#039;&#039;&#039; — a vision model kept loaded for a document pipeline is not free. Size band and quantisation are a filter applied &#039;&#039;&#039;first&#039;&#039;&#039;, not a compromise made afterwards. A related finding already measured here: 4-bit quantisation degrades digit reading, so anything touching numbers on a form runs at 8-bit.&lt;br /&gt;
&lt;br /&gt;
== See also ==&lt;br /&gt;
&lt;br /&gt;
* [[De-Risk: Sovereign Training Data v0.1]] — why owned weights matter and what may not go in the corpus&lt;br /&gt;
* [[Comfac GPU Scaling and AI Research Goals]] — GPU capacity and the applied model-evaluation method&lt;br /&gt;
* [[🧠 Process: Selecting and Installing the Right Ollama Model for Your Hardware]]&lt;br /&gt;
* [[Project OpenCoder: AI Independence Initiative]]&lt;br /&gt;
* [[Directed Execution: Token-Efficient Agent Development Process]]&lt;br /&gt;
&lt;br /&gt;
[[Category:AI]]&lt;br /&gt;
[[Category:Research]]&lt;br /&gt;
[[Category:Open Source]]&lt;br /&gt;
[[Category:Comfac]]&lt;/div&gt;</summary>
		<author><name>Justinaquino</name></author>
	</entry>
	<entry>
		<id>https://mediawiki.comfac.net/index.php?title=Audio_Learning&amp;diff=268</id>
		<title>Audio Learning</title>
		<link rel="alternate" type="text/html" href="https://mediawiki.comfac.net/index.php?title=Audio_Learning&amp;diff=268"/>
		<updated>2026-08-01T06:15:16Z</updated>

		<summary type="html">&lt;p&gt;Justinaquino: Created: Audio Learning research-to-TTS tool article with link to citfj repo&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{New article banner|date=2026-08-01}}&lt;br /&gt;
&#039;&#039;&#039;Audio Learning&#039;&#039;&#039; is the practice of converting research, articles, notes, and study material into scripts written to be &#039;&#039;&#039;listened to&#039;&#039;&#039; rather than read. It is a shared Comfac tool maintained as a private Forgejo repository and designed for staff who consume technical material hands-free — commuting, walking, between machines on the plant floor.&lt;br /&gt;
&lt;br /&gt;
== What it is ==&lt;br /&gt;
&lt;br /&gt;
Written prose and spoken prose are different mediums. A reader can re-read a sentence, skim a heading, and hold structure visually. A listener gets one linear pass with no backtracking. Audio Learning provides the discipline to re-compose research for the ear.&lt;br /&gt;
&lt;br /&gt;
The repository contains a &#039;&#039;&#039;skill for AI agents&#039;&#039;&#039; (&#039;&#039;&#039;research-to-tts&#039;&#039;&#039;) that converts knowledge into one of two house formats:&lt;br /&gt;
&lt;br /&gt;
; Lecture format (Great Courses style)&lt;br /&gt;
: For technical study — networking, protocols, CISM/CISSP, security architecture, governance frameworks, systems engineering, ISO standards. The listener walks away understanding a mechanism they did not understand before. Useful for Comfac training material: Network+ basics, pfSense operations, BIR compliance, ERPNext workflows.&lt;br /&gt;
&lt;br /&gt;
; Analyst format (thesis-and-evidence style)&lt;br /&gt;
: For contested material — energy markets, housing policy, supply-chain economics, regulatory analysis, industry studies. The listener walks away able to make or defend a decision. Useful for bid analysis, feasibility studies, vendor evaluations, and competitive intelligence.&lt;br /&gt;
&lt;br /&gt;
== What it contains ==&lt;br /&gt;
&lt;br /&gt;
* Concrete prose mechanics — how to speak numbers, acronyms, symbols, citations, code, and homographs so a text-to-speech engine renders them correctly&lt;br /&gt;
* Format templates — cold-open structures, spine metaphors, prerequisite ordering, decision frames, thesis stacking, approach ladders, and tripwire indicators&lt;br /&gt;
* Visual description protocols — a two-pass method for turning charts, diagrams, tables, and maps into something a listener can build a mental model of&lt;br /&gt;
* A pre-delivery audit — ten checks every script must pass before it is spoken&lt;br /&gt;
&lt;br /&gt;
== Where it lives ==&lt;br /&gt;
&lt;br /&gt;
The source repository is private on the Comfac Forgejo:&lt;br /&gt;
&lt;br /&gt;
[https://git.comfac-it.net/cgg/audio-learning cgg/audio-learning]&lt;br /&gt;
&lt;br /&gt;
== How to use it ==&lt;br /&gt;
&lt;br /&gt;
An AI agent loads the skill, reads the reference files, picks a format, plans an outline from the source material, drafts a script with spoken prose only (no markdown, no symbols, no parentheticals), and audits the result before delivering it. The output is a plain-text script with a non-spoken production header and a clean spoken body — ready to be fed into any text-to-speech engine.&lt;br /&gt;
&lt;br /&gt;
== Related ==&lt;br /&gt;
&lt;br /&gt;
* [[GPU Scaling and AI Research|GPU Scaling and AI Research Goals]] — Comfac&#039;s model-evaluation infrastructure&lt;br /&gt;
* [[Open Source Software Analysis]] — tool evaluation methodology&lt;br /&gt;
* [[Resume / CV Renamer Pipeline]] — OCR-to-searchable pipeline (same ingestion-to-structured-output pattern)&lt;br /&gt;
&lt;br /&gt;
[[Category:Tools]]&lt;br /&gt;
[[Category:AI Agents]]&lt;br /&gt;
[[Category:Training]]&lt;/div&gt;</summary>
		<author><name>Justinaquino</name></author>
	</entry>
	<entry>
		<id>https://mediawiki.comfac.net/index.php?title=Main_Page&amp;diff=267</id>
		<title>Main Page</title>
		<link rel="alternate" type="text/html" href="https://mediawiki.comfac.net/index.php?title=Main_Page&amp;diff=267"/>
		<updated>2026-07-31T14:25:42Z</updated>

		<summary type="html">&lt;p&gt;Justinaquino: Tools &amp;amp; Productivity: add Resume / CV Renamer Pipeline&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__NOTOC__&lt;br /&gt;
&amp;lt;div style=&amp;quot;background:#f8f9fa; border:1px solid #ddd; border-radius:4px; padding:12px 16px; margin-bottom:20px;&amp;quot;&amp;gt;&lt;br /&gt;
Welcome to the &#039;&#039;&#039;Comfac IT Knowledge Base&#039;&#039;&#039;. Use the sections below to find guides, SOPs, and references organized by topic.&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== ERPNext / Frappe ==&lt;br /&gt;
&amp;lt;div style=&amp;quot;column-count:2; column-gap:2em;&amp;quot;&amp;gt;&lt;br /&gt;
* [[Frappe HRMS]] — &#039;&#039;&#039;HR &amp;amp; Payroll&#039;&#039;&#039; (with Philippine Localization)&lt;br /&gt;
* [[Frappe ERPNext/Webshop]] — &#039;&#039;&#039;E-Commerce Webshop&#039;&#039;&#039; (setup, architecture, chapters)&lt;br /&gt;
* [[Manufacturing v16 260125]]&lt;br /&gt;
* [[ERpnext Asset Management Procedure 260113]]&lt;br /&gt;
* [[ERPNext HR Module Outline]]&lt;br /&gt;
* [[ERPNEXT Payroll POC 251212]]&lt;br /&gt;
* [[Comfac ERPNext Strategy Canvas (Expanded)]]&lt;br /&gt;
* [[PAD-Driven ERPNext Strategy 260303]] — PAD/AI-agentic implementation strategy for Frappe ERPNext&lt;br /&gt;
* [[ERPNext v15 Docker Setup Guide]] — Local Docker setup for evaluation, testing, and student use&lt;br /&gt;
* [[Frappe Links and References]]&lt;br /&gt;
* [[Using Frappe Wiki]]&lt;br /&gt;
* [https://docs.frappe.io/cloud/guidelines-for-contributing-regional-compliance-app Guidelines for Contributing Regional Compliance App]&lt;br /&gt;
* [https://docs.frappe.io/cloud/what-are-benches-and-bench-groups What are Benches?]&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== System Administration &amp;amp; Self-Hosting ==&lt;br /&gt;
&amp;lt;div style=&amp;quot;column-count:2; column-gap:2em;&amp;quot;&amp;gt;&lt;br /&gt;
* [[Networking PfSense Index]] — Consolidated index of all networking, pfSense, DNS, and infrastructure guides&lt;br /&gt;
* [[System Hardening Strategy: Win2Lin Migration &amp;amp; Infrastructure 251129]]&lt;br /&gt;
* [[Controller Systems 251213-01]]&lt;br /&gt;
* [[Power Distribution Tree 251213]]&lt;br /&gt;
* [[Introduction: Why Self-Host Your Email?]]&lt;br /&gt;
* [[Mailcow + Thunderbird Setup Guide (Email + Calendar)]]&lt;br /&gt;
* [[Mailcow SOGo: Creating Filters for Events, Approvals, and Organizational Emails]]&lt;br /&gt;
* [[Spoof Timezone Extension – Setup Guide for Comfac Staff]]&lt;br /&gt;
* [[Viber Focus-Stealing]]&lt;br /&gt;
* [[🌐 WordPress Website — *You Own Everything, Learn Everything*]]&lt;br /&gt;
* [[Portainer to Docker Compose Migration Guide]]&lt;br /&gt;
* [[Organizing Coder Terminals]] — Tmux + dynamic titles for managing multiple AI agent terminals&lt;br /&gt;
* [[Editing Mastodon Docker Deployment Guide 260402]]&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Storage &amp;amp; Hardware ==&lt;br /&gt;
&amp;lt;div style=&amp;quot;column-count:2; column-gap:2em;&amp;quot;&amp;gt;&lt;br /&gt;
* [[TrueNAS Configuration Options &amp;amp; Scale Options 251130]]&lt;br /&gt;
* [[TrueNAS Business Plan: Project 251212]]&lt;br /&gt;
* [[Comparison: TrueNAS Mini X+ vs Dell Precision 3680 Tower (2025)]]&lt;br /&gt;
* [[Backblaze Drive Stats for Server and Storage Qualification]]&lt;br /&gt;
* [[Industrial Controllers and Water Utilities 251011]]&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== AI &amp;amp; Machine Learning ==&lt;br /&gt;
&amp;lt;div style=&amp;quot;column-count:2; column-gap:2em;&amp;quot;&amp;gt;&lt;br /&gt;
* [[OpenWebUI - 251128-justin]]&lt;br /&gt;
* [[Comfac GPU Scaling and AI Research Goals]]&lt;br /&gt;
* [[🧠 Process: Selecting and Installing the Right Ollama Model for Your Hardware]]&lt;br /&gt;
* [[Ollama GNOME System Tray Panel 260401]] — GNOME system tray toggle to start/stop Ollama and reclaim VRAM&lt;br /&gt;
* [[Proceedural Agentic Development Methodology 260304]] — Methodology for systematic agent use&lt;br /&gt;
* [[Project OpenCoder: AI Independence Initiative]] — Strategic roadmap for manufacturing intelligence&lt;br /&gt;
* [[OpenCoder Qwen35 Agentic Setup 260330]] — Qwen3.5 Modelfile fix for tool calling in OpenCode; thinking mode suppression; HDD vs SSD findings&lt;br /&gt;
* [[OpenCode Multi-Provider Configuration Guide 260401]] — Dual-mode AI coding setup with Kimi cloud + Ollama local models via Distrobox&lt;br /&gt;
* [[PAD-Driven ERPNext Strategy 260303]] — Procedural Agentic Development for Frappe/ERPNext configuration and deployment&lt;br /&gt;
* [[Directed Execution: Token-Efficient Agent Development Process]] — Director/Executor/Checker loop and skill distillation for token-efficient agent development (v0.1, 2026-07-15)&lt;br /&gt;
* [[De-Risk: Sovereign Training Data v0.1]] — Frontier-Token Quarantine and the ToS-clean path to owned model weights, prompted by the June 2026 Fable 5 export-control suspension (v0.1, 2026-07-15)&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Job Descriptions ==&lt;br /&gt;
&amp;lt;div style=&amp;quot;column-count:2; column-gap:2em;&amp;quot;&amp;gt;&lt;br /&gt;
* [[Job Descriptions]] — Index of all official job descriptions (IT, Engineering, Sales)&lt;br /&gt;
* [[JD IT Project Staff]] — IT Project Staff&lt;br /&gt;
* [[JD Security Compliance Assistant 260224]] — Security and Compliance Assistant (SCA)&lt;br /&gt;
* [[JD Engineering Designer 260108]] — Engineering Designer&lt;br /&gt;
* [[JD Engineering Supervisor 260109]] — Engineering Supervisor&lt;br /&gt;
* [[JD Technical Sales 260112]] — Technical Sales Engineer&lt;br /&gt;
* [[JD Marketing Assistant 251119]] — Marketing Assistant&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== IT Operations &amp;amp; SOPs ==&lt;br /&gt;
&amp;lt;div style=&amp;quot;column-count:2; column-gap:2em;&amp;quot;&amp;gt;&lt;br /&gt;
* [[SCA Program Plan 260320]] — Security &amp;amp; Compliance Assistant Program Plan v3 (ISO 9001/27001, PDCA, distributed audit model)&lt;br /&gt;
* [[SOP: Inter-Company Ordering and Production Process 260203]] — Ordering and production workflow between Sister Companies and the Cabuyao Plant&lt;br /&gt;
* [[Memo: Team Roles &amp;amp; Reporting Process Clarification 260320]] — Role boundaries, data ownership, and the new ERPNext-driven reporting paradigm&lt;br /&gt;
* [[Standard Operating Procedure: Distributed Minute Taking &amp;amp; Task Ownership 251208]]&lt;br /&gt;
* [[Business Continuity]]&lt;br /&gt;
* [[Procedure: CC-Blast Data Breach Prevention]]&lt;br /&gt;
* [[8D (Eight Discipline) Problem Solving Procedure]]&lt;br /&gt;
* [[Offline Malware Remediation &amp;amp; Data Recovery]]&lt;br /&gt;
* [[Troubleshooting: Access &amp;amp; Permission Issues]]&lt;br /&gt;
* [[Steps to Repair and OCR a Scanned or Corrupted PDF in Ubuntu]]&lt;br /&gt;
* [[IT IMPORTS PROCESSES]]&lt;br /&gt;
* [[IT Purchase Requests 241126]]&lt;br /&gt;
* [[IT REQUEST (OP-ERP-ITR) - EDITED 250801]]&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Sales &amp;amp; Business ==&lt;br /&gt;
&amp;lt;div style=&amp;quot;column-count:2; column-gap:2em;&amp;quot;&amp;gt;&lt;br /&gt;
* [[Comfac Sales Knowledge Base]]&lt;br /&gt;
* [[Comfac CRM – Customer Qualification &amp;amp; Conversion Process]]&lt;br /&gt;
* [[Partner Reseller Pricing 251109]]&lt;br /&gt;
* [[Biz Analysis Methodology 251109]]&lt;br /&gt;
* [[2026 MIS IT KRA KPI Biz Plan]]&lt;br /&gt;
* [[SALES INVOICE TAX OUTPUT 250829]]&lt;br /&gt;
* [[Projects in Process Report 251023]]&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Tools &amp;amp; Productivity ==&lt;br /&gt;
&amp;lt;div style=&amp;quot;column-count:2; column-gap:2em;&amp;quot;&amp;gt;&lt;br /&gt;
* [[Excel Description Filler Tool 📝]]&lt;br /&gt;
* [[Resume CV Renamer Pipeline|Resume / CV Renamer Pipeline]] — CV intake → OCR / vision-OCR → AI field extraction → date-stamped rename + VCF export&lt;br /&gt;
* [https://github.com/Comfac-Global-Group/comfac-studies Comfac Studies - Spaced Repetiton Active Recall]&lt;br /&gt;
* [[LibreOffice / Nextcloud Office – &amp;quot;Due Tasks&amp;quot; Conditional Formatting]]&lt;br /&gt;
* [[Google Drive and Shared Drive Training]]&lt;br /&gt;
* [[260108 CGG- GitHub Administration Guide]]&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Wiki &amp;amp; Documentation ==&lt;br /&gt;
&amp;lt;div style=&amp;quot;column-count:2; column-gap:2em;&amp;quot;&amp;gt;&lt;br /&gt;
* [[Mediawiki Setting Up Guide]]&lt;br /&gt;
* [[Contributing to Only Office 260307]]&lt;br /&gt;
* [[Mediawiki Additional Configuration]]&lt;br /&gt;
* [[Mediawiki Docker Migration Guide]]&lt;br /&gt;
* [[Home]]&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Tutorials ==&lt;br /&gt;
&amp;lt;div style=&amp;quot;column-count:2; column-gap:2em;&amp;quot;&amp;gt;&lt;br /&gt;
* [[Claude Code Isolation and Burner Workflow 260211]] — Secure AI development environment setup&lt;br /&gt;
* [[Opencode isolation and burner workflow 260216]] — OpenCode CLI isolation procedures&lt;br /&gt;
* [[LibreOffice Calc NumToWords Extension Complete Guide]] — Extension development&lt;br /&gt;
* [[ERPNext v15 Docker Setup Guide]] — ERPNext v15 local Docker setup (students, evaluators, thin-client demos)&lt;br /&gt;
* [[Erpnextv15-SSH-setup-241111]] — ERPNext v15 SSH/Portainer production setup&lt;br /&gt;
* [[Git-Mediawiki Local Editing 260223]] — Wiki editing with Git&lt;br /&gt;
* [[Understanding &amp;amp; Fixing Kernel Panics 260212]] — System debugging&lt;br /&gt;
* [[OpenCode in Android Termux 260303]] — OpenCode in Android&lt;br /&gt;
* [[OpenCoder Qwen35 Agentic Setup 260330]] — Qwen3.5 agentic setup: Modelfile, tool calling fix, storage impact&lt;br /&gt;
* [[Lora Basics 260304]] — LORA research&lt;br /&gt;
* [https://github.com/anomalyco/opencode/issues/4283#issuecomment-4083399210 Opencode Copy-paste Clipboard doesnt Work - Solution]   https://github.com/anomalyco/opencode/issues/4283#issuecomment-4083399210&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Research ==&lt;br /&gt;
&amp;lt;div style=&amp;quot;column-count:2; column-gap:2em;&amp;quot;&amp;gt;&lt;br /&gt;
* [[Ladybird Browser]] — Browser engine development&lt;br /&gt;
* [[Computing Architecture]] — System design principles&lt;br /&gt;
* [[Backblaze Drive Stats for Server and Storage Qualification 260219]] — Drive reliability analysis&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== For Users Only ==&lt;br /&gt;
* [[Private:Private Ngani]]&lt;br /&gt;
* [[Private:Private Nganipart2]]&lt;br /&gt;
&lt;br /&gt;
== CIT-OJT Project Documentations ==&lt;br /&gt;
* [[OJTDocs: For OJTs only]]&lt;br /&gt;
&lt;br /&gt;
== Need Help? ==&lt;br /&gt;
&amp;lt;div style=&amp;quot;column-count:2; column-gap:2em;&amp;quot;&amp;gt;&lt;br /&gt;
* [[Troubleshooting: Access &amp;amp; Permission Issues]]&lt;br /&gt;
* [https://www.mediawiki.org/wiki/Special:MyLanguage/Help:Contents MediaWiki User&#039;s Guide]&lt;br /&gt;
* [https://www.mediawiki.org/wiki/Special:MyLanguage/Manual:Configuration_settings Configuration settings]&lt;br /&gt;
* [https://www.mediawiki.org/wiki/Special:MyLanguage/Manual:FAQ MediaWiki FAQ]&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;/div&gt;</summary>
		<author><name>Justinaquino</name></author>
	</entry>
	<entry>
		<id>https://mediawiki.comfac.net/index.php?title=Resume_CV_Renamer_Pipeline&amp;diff=266</id>
		<title>Resume CV Renamer Pipeline</title>
		<link rel="alternate" type="text/html" href="https://mediawiki.comfac.net/index.php?title=Resume_CV_Renamer_Pipeline&amp;diff=266"/>
		<updated>2026-07-31T14:25:40Z</updated>

		<summary type="html">&lt;p&gt;Justinaquino: Add Resume / CV Renamer Pipeline tool article (intake, OCR/vision-OCR, AI extraction, rename, VCF export)&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Resume / CV Renamer Pipeline =&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;background:#f8f9fa; border:1px solid #ddd; border-radius:4px; padding:10px 16px; margin-bottom:16px;&amp;quot;&amp;gt;&lt;br /&gt;
Automated resume ingestion, OCR, AI extraction, file renaming, and VCF contact export for recruitment workflows.&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Location:&#039;&#039;&#039; &amp;lt;code&amp;gt;/path/to/resume-renamer/&amp;lt;/code&amp;gt; (configure to your local HR/resume folder)&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Upstream docs:&#039;&#039;&#039; [[Frappe HRMS - Ch01 Recruitment]]&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== What It Does ==&lt;br /&gt;
&lt;br /&gt;
# Drop a resume file (PDF, DOCX, JPG, PNG) into the folder.&lt;br /&gt;
# The scanner detects the new file and extracts text with &amp;lt;code&amp;gt;pdftotext&amp;lt;/code&amp;gt;.&lt;br /&gt;
# Image files or image-based PDFs are converted with &amp;lt;code&amp;gt;img2pdf&amp;lt;/code&amp;gt; and OCR&#039;d with &amp;lt;code&amp;gt;ocrmypdf&amp;lt;/code&amp;gt; if available.&lt;br /&gt;
# If OCR fails or is unavailable, the scanner falls back to &#039;&#039;&#039;vision OCR&#039;&#039;&#039; using a local VLM (e.g. &amp;lt;code&amp;gt;glm-ocr:bf16&amp;lt;/code&amp;gt;).&lt;br /&gt;
# A local LLM extracts structured candidate data.&lt;br /&gt;
# The file is renamed to: &amp;lt;code&amp;gt;YYMMDD Full Name Degree.pdf&amp;lt;/code&amp;gt;&lt;br /&gt;
# A &amp;lt;code&amp;gt;YYMMDD-HHMMSS_Bulk_Import.vcf&amp;lt;/code&amp;gt; file is generated for contact import.&lt;br /&gt;
&lt;br /&gt;
The single source of truth is the SQLite database &amp;lt;code&amp;gt;resumes.db&amp;lt;/code&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Supported Inputs ==&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Format !! Handling&lt;br /&gt;
|-&lt;br /&gt;
| PDF with text || Direct extraction&lt;br /&gt;
|-&lt;br /&gt;
| Image-based PDF || &amp;lt;code&amp;gt;ocrmypdf&amp;lt;/code&amp;gt; → vision OCR fallback&lt;br /&gt;
|-&lt;br /&gt;
| JPG / PNG || &amp;lt;code&amp;gt;img2pdf&amp;lt;/code&amp;gt; → vision OCR fallback&lt;br /&gt;
|-&lt;br /&gt;
| DOCX || Detected; convert to PDF manually if needed&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Quick Start ==&lt;br /&gt;
&lt;br /&gt;
=== Run once manually ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
cd /path/to/resume-renamer&lt;br /&gt;
source ./venv/bin/activate&lt;br /&gt;
python cv_auto_scanner.py --once&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Dry-run preview ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
python cv_auto_scanner.py --once --dry-run&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Daemon mode ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
python cv_auto_scanner.py --daemon --interval 900  # 15 minutes&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Force a full re-scan ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
rm -f .scanner_state.json&lt;br /&gt;
python cv_auto_scanner.py --once&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Common Issues ==&lt;br /&gt;
&lt;br /&gt;
=== Degree shows &amp;quot;General&amp;quot; or is empty ===&lt;br /&gt;
&lt;br /&gt;
The scanner now explicitly accepts diplomas and certificates in the &amp;lt;code&amp;gt;degree&amp;lt;/code&amp;gt; field. If an older file still shows &amp;quot;General&amp;quot;, reset it and reprocess:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
source ./venv/bin/activate&lt;br /&gt;
python3 -c &amp;quot;&lt;br /&gt;
import resume_db&lt;br /&gt;
resume_db.init_db()&lt;br /&gt;
resume_db.upsert_candidate(&#039;ORIGINAL_FILENAME.pdf&#039;, status=&#039;pending&#039;, retry_count=0, last_error=None)&lt;br /&gt;
&amp;quot;&lt;br /&gt;
rm -f .scanner_state.json&lt;br /&gt;
python cv_auto_scanner.py --once&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== &amp;quot;Text too short / unreadable&amp;quot; ===&lt;br /&gt;
&lt;br /&gt;
The scanner automatically tries OCR and vision OCR. If it still fails:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
source ./venv/bin/activate&lt;br /&gt;
python /path/to/rpdf-skills/vision_ocr.py FAILED_FILE.pdf --model glm-ocr:bf16 --format text -o extracted.txt&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Then rebuild a searchable PDF and re-run the scanner.&lt;br /&gt;
&lt;br /&gt;
=== venv broken after Python upgrade ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
sudo apt install python3.14-venv python3-pip&lt;br /&gt;
cd /path/to/resume-renamer&lt;br /&gt;
rm -rf venv&lt;br /&gt;
python3.14 -m venv venv&lt;br /&gt;
source ./venv/bin/activate&lt;br /&gt;
pip install --upgrade pip&lt;br /&gt;
pip install img2pdf requests pdfplumber psycopg2-binary fpdf2&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== VCF Import ==&lt;br /&gt;
&lt;br /&gt;
New &amp;lt;code&amp;gt;*_Bulk_Import.vcf&amp;lt;/code&amp;gt; files are generated automatically. Import them into your contacts app:&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;Google Contacts:&#039;&#039;&#039; contacts.google.com → Import → Select VCF&lt;br /&gt;
* &#039;&#039;&#039;Android:&#039;&#039;&#039; Copy VCF to phone → Contacts → Settings → Import&lt;br /&gt;
* &#039;&#039;&#039;Thunderbird:&#039;&#039;&#039; &amp;lt;code&amp;gt;thunderbird -compose &amp;quot;to=hr@example.com,subject=Contact Card,attachment=/path/to/YYMMDD-HHMMSS_Bulk_Import.vcf&amp;quot;&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The VCF uses a non-standard layout for multi-part names:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! vCard Field !! Value&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;N&amp;lt;/code&amp;gt; (Last Name) || Role context, e.g. &amp;lt;code&amp;gt;Electrical Applicant 260616&amp;lt;/code&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;N&amp;lt;/code&amp;gt; (First Name) || Candidate&#039;s full name&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;FN&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;{Full Name} - {Context}&amp;lt;/code&amp;gt;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
To specify the context for a batch:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
python cv_auto_scanner.py --vcf-context &amp;quot;Electrical Applicant 260616&amp;quot;&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Related Pages ==&lt;br /&gt;
&lt;br /&gt;
* [[Frappe HRMS]]&lt;br /&gt;
* [[Frappe HRMS - Ch01 Recruitment]]&lt;br /&gt;
* [[Steps to Repair and OCR a Scanned or Corrupted PDF in Ubuntu]]&lt;br /&gt;
* [[🧠 Process: Selecting and Installing the Right Ollama Model for Your Hardware]]&lt;br /&gt;
&lt;br /&gt;
[[Category:HR]]&lt;br /&gt;
[[Category:Recruitment]]&lt;br /&gt;
[[Category:Automation]]&lt;br /&gt;
[[Category:Comfac]]&lt;br /&gt;
[[Category:IT Operations]]&lt;/div&gt;</summary>
		<author><name>Justinaquino</name></author>
	</entry>
	<entry>
		<id>https://mediawiki.comfac.net/index.php?title=Comfac_GPU_Scaling_and_AI_Research_Goals&amp;diff=265</id>
		<title>Comfac GPU Scaling and AI Research Goals</title>
		<link rel="alternate" type="text/html" href="https://mediawiki.comfac.net/index.php?title=Comfac_GPU_Scaling_and_AI_Research_Goals&amp;diff=265"/>
		<updated>2026-07-31T13:02:32Z</updated>

		<summary type="html">&lt;p&gt;Justinaquino: Add Applied Model Evaluation - Synopsis mail-agent model-selection test (2026-07-31)&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Comfac GPU Scaling and AI Research Goals =&lt;br /&gt;
&lt;br /&gt;
== Objective ==&lt;br /&gt;
&lt;br /&gt;
To develop and scale a high-performance AMD-based AI compute cluster, capable of running large-scale models (e.g., Qwen 2.5 235B) and supporting educational and R&amp;amp;D initiatives through open collaboration with partner schools.&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Goals and Steps ==&lt;br /&gt;
&lt;br /&gt;
=== 1. Platform and Motherboard Selection ===&lt;br /&gt;
* Identify and procure a motherboard or server platform that supports extensive GPU scaling and PCIe bifurcation (similar to the setup demonstrated by PewDiePie).&lt;br /&gt;
* Ensure compatibility with ROCm and vLLM for distributed inference and multi-GPU coordination.&lt;br /&gt;
&lt;br /&gt;
=== 2. Initial Scaling (Pilot Models) ===&lt;br /&gt;
* Begin with &#039;&#039;&#039;well-known, stable models&#039;&#039;&#039; to validate infrastructure performance and reliability.&lt;br /&gt;
* &#039;&#039;&#039;Pilot hardware:&#039;&#039;&#039; AMD &#039;&#039;&#039;Radeon PRO R9700 AI&#039;&#039;&#039; or equivalent AI-focused GPU.&lt;br /&gt;
* Validate thermal performance, power delivery, and driver stability for continuous inference workloads.&lt;br /&gt;
&lt;br /&gt;
=== 3. Progressive Hardware Replication ===&lt;br /&gt;
* Once stable results are achieved with R9700 PRO, replicate the same environment using &#039;&#039;&#039;RX 7900 XTX&#039;&#039;&#039; and other AMD GPUs to benchmark performance scaling.&lt;br /&gt;
* Document compatibility issues, driver updates, and quantization performance metrics.&lt;br /&gt;
&lt;br /&gt;
=== 4. Cluster and Swarm Development ===&lt;br /&gt;
* Establish a &#039;&#039;&#039;Cluster System&#039;&#039;&#039; for large-model distributed inference and training.&lt;br /&gt;
* Build a &#039;&#039;&#039;Swarm System&#039;&#039;&#039; capable of parallelizing smaller AI instances (e.g., 7700 and lower-end GPU nodes) for local and academic deployment.&lt;br /&gt;
* Optimize inter-node communication, synchronization, and monitoring tools for mixed hardware setups.&lt;br /&gt;
&lt;br /&gt;
=== 5. Funding and Laboratory Deployment ===&lt;br /&gt;
* Fund the creation of a &#039;&#039;&#039;dedicated AI Lab&#039;&#039;&#039; focused on testing, documentation, and educational use.&lt;br /&gt;
* Provide access to partner schools for research, benchmarking, and AI model fine-tuning.&lt;br /&gt;
&lt;br /&gt;
=== 6. Open Compute and Tokenization Participation ===&lt;br /&gt;
* Study and participate in open-source projects that allow community-based compute contributions (similar to Folding@home).&lt;br /&gt;
* Learn and experiment with decentralized compute-sharing models that enable contributors to sell &#039;&#039;&#039;tokens or compute time&#039;&#039;&#039; securely and transparently.&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Applied Model Evaluation — Synopsis Mail-Agent Test (2026-07-31) ==&lt;br /&gt;
&lt;br /&gt;
First concrete output under the AI research program: an empirical model-selection harness, built for the Synopsis &amp;quot;talk to your email&amp;quot; agent but reusable for CSAMA and 2B evaluation.&lt;br /&gt;
&lt;br /&gt;
&amp;gt; Evaluator: Kimi Code CLI / k1.6 · Methodology: live infra checks + real API tool-call sweeps + mailbox-anchored question verification. Full detail: &amp;lt;code&amp;gt;work/comfac-synopsys/docs/260731-eod-model-selection-session.md&amp;lt;/code&amp;gt; and &amp;lt;code&amp;gt;plans/260731-115026-model-selection-test.md&amp;lt;/code&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;Method over benchmarks:&#039;&#039;&#039; candidates are gated on &#039;&#039;tool-calling fidelity, citation honesty, and admitting absence&#039;&#039; — not prose quality or public benchmark scores. A single fabricated citation fails a candidate outright; every failure carries a failure-mode tag (fabrication / no-search / false-absence / wrong-args / shallow-search / misread / multi-hop-fail) so &amp;quot;failed&amp;quot; distinguishes untrustworthy from merely fixable.&lt;br /&gt;
* &#039;&#039;&#039;Slate (7 candidates, all tools-gated on real calls):&#039;&#039;&#039; qwen3-vl:8b-instruct-q8_0 (control), qwen3-vl:8b-instruct, qwen3.5:9b (thinking on/off arm), gemma4:12b, qwen3:14b, ibm/granite4.1:8b, fablevibes:14b-a3b (community MoE prune — provenance caveat).&lt;br /&gt;
* &#039;&#039;&#039;Hardware finding:&#039;&#039;&#039; 15 GiB usable VRAM (RX 9060 XT class) excludes 27B-class models at Q4 (17 GB+) — concrete evidence for the &#039;&#039;&#039;20 GB+ procurement path&#039;&#039;&#039; (RX 7900 XT / Radeon PRO R9700) in the scaling goals above.&lt;br /&gt;
* &#039;&#039;&#039;Small-model finding:&#039;&#039;&#039; sub-4B models mostly cannot run a tool loop (granite3.3:2b, phi4-mini failed to emit tool calls at all; llama3.2:3b marginal). For CPU/micro-model (CSAMA) roles, plan non-tool architectures (extractive prefilter → small-model polish).&lt;br /&gt;
* &#039;&#039;&#039;Infra prerequisites proven:&#039;&#039;&#039; Ollama as an enabled systemd service, VPN-reachable from the batch host, no auto-sleep, 100% GPU placement — the pattern any &amp;quot;chief model host&amp;quot; in the cluster must replicate.&lt;br /&gt;
* &#039;&#039;&#039;Status:&#039;&#039;&#039; gated run blocked on one human step (Justin&#039;s 20 verified questions). Harness + scorer + golden-set format in &amp;lt;code&amp;gt;work/comfac-synopsys/harness/&amp;lt;/code&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Reference ==&lt;br /&gt;
&lt;br /&gt;
* Inspirational video: [https://youtube.com/qw4fDU18RcU?si=TJ8hYQPIjuQuiORk Watch on YouTube]&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== End Goal ==&lt;br /&gt;
&lt;br /&gt;
To make Comfac and its academic partners a recognized hub for open, scalable, and sustainable AI research using AMD technologies.&lt;/div&gt;</summary>
		<author><name>Justinaquino</name></author>
	</entry>
	<entry>
		<id>https://mediawiki.comfac.net/index.php?title=Main_Page&amp;diff=264</id>
		<title>Main Page</title>
		<link rel="alternate" type="text/html" href="https://mediawiki.comfac.net/index.php?title=Main_Page&amp;diff=264"/>
		<updated>2026-07-15T15:21:51Z</updated>

		<summary type="html">&lt;p&gt;Justinaquino: Add De-Risk article link&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__NOTOC__&lt;br /&gt;
&amp;lt;div style=&amp;quot;background:#f8f9fa; border:1px solid #ddd; border-radius:4px; padding:12px 16px; margin-bottom:20px;&amp;quot;&amp;gt;&lt;br /&gt;
Welcome to the &#039;&#039;&#039;Comfac IT Knowledge Base&#039;&#039;&#039;. Use the sections below to find guides, SOPs, and references organized by topic.&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== ERPNext / Frappe ==&lt;br /&gt;
&amp;lt;div style=&amp;quot;column-count:2; column-gap:2em;&amp;quot;&amp;gt;&lt;br /&gt;
* [[Frappe HRMS]] — &#039;&#039;&#039;HR &amp;amp; Payroll&#039;&#039;&#039; (with Philippine Localization)&lt;br /&gt;
* [[Frappe ERPNext/Webshop]] — &#039;&#039;&#039;E-Commerce Webshop&#039;&#039;&#039; (setup, architecture, chapters)&lt;br /&gt;
* [[Manufacturing v16 260125]]&lt;br /&gt;
* [[ERpnext Asset Management Procedure 260113]]&lt;br /&gt;
* [[ERPNext HR Module Outline]]&lt;br /&gt;
* [[ERPNEXT Payroll POC 251212]]&lt;br /&gt;
* [[Comfac ERPNext Strategy Canvas (Expanded)]]&lt;br /&gt;
* [[PAD-Driven ERPNext Strategy 260303]] — PAD/AI-agentic implementation strategy for Frappe ERPNext&lt;br /&gt;
* [[ERPNext v15 Docker Setup Guide]] — Local Docker setup for evaluation, testing, and student use&lt;br /&gt;
* [[Frappe Links and References]]&lt;br /&gt;
* [[Using Frappe Wiki]]&lt;br /&gt;
* [https://docs.frappe.io/cloud/guidelines-for-contributing-regional-compliance-app Guidelines for Contributing Regional Compliance App]&lt;br /&gt;
* [https://docs.frappe.io/cloud/what-are-benches-and-bench-groups What are Benches?]&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== System Administration &amp;amp; Self-Hosting ==&lt;br /&gt;
&amp;lt;div style=&amp;quot;column-count:2; column-gap:2em;&amp;quot;&amp;gt;&lt;br /&gt;
* [[Networking PfSense Index]] — Consolidated index of all networking, pfSense, DNS, and infrastructure guides&lt;br /&gt;
* [[System Hardening Strategy: Win2Lin Migration &amp;amp; Infrastructure 251129]]&lt;br /&gt;
* [[Controller Systems 251213-01]]&lt;br /&gt;
* [[Power Distribution Tree 251213]]&lt;br /&gt;
* [[Introduction: Why Self-Host Your Email?]]&lt;br /&gt;
* [[Mailcow + Thunderbird Setup Guide (Email + Calendar)]]&lt;br /&gt;
* [[Mailcow SOGo: Creating Filters for Events, Approvals, and Organizational Emails]]&lt;br /&gt;
* [[Spoof Timezone Extension – Setup Guide for Comfac Staff]]&lt;br /&gt;
* [[Viber Focus-Stealing]]&lt;br /&gt;
* [[🌐 WordPress Website — *You Own Everything, Learn Everything*]]&lt;br /&gt;
* [[Portainer to Docker Compose Migration Guide]]&lt;br /&gt;
* [[Organizing Coder Terminals]] — Tmux + dynamic titles for managing multiple AI agent terminals&lt;br /&gt;
* [[Editing Mastodon Docker Deployment Guide 260402]]&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Storage &amp;amp; Hardware ==&lt;br /&gt;
&amp;lt;div style=&amp;quot;column-count:2; column-gap:2em;&amp;quot;&amp;gt;&lt;br /&gt;
* [[TrueNAS Configuration Options &amp;amp; Scale Options 251130]]&lt;br /&gt;
* [[TrueNAS Business Plan: Project 251212]]&lt;br /&gt;
* [[Comparison: TrueNAS Mini X+ vs Dell Precision 3680 Tower (2025)]]&lt;br /&gt;
* [[Backblaze Drive Stats for Server and Storage Qualification]]&lt;br /&gt;
* [[Industrial Controllers and Water Utilities 251011]]&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== AI &amp;amp; Machine Learning ==&lt;br /&gt;
&amp;lt;div style=&amp;quot;column-count:2; column-gap:2em;&amp;quot;&amp;gt;&lt;br /&gt;
* [[OpenWebUI - 251128-justin]]&lt;br /&gt;
* [[Comfac GPU Scaling and AI Research Goals]]&lt;br /&gt;
* [[🧠 Process: Selecting and Installing the Right Ollama Model for Your Hardware]]&lt;br /&gt;
* [[Ollama GNOME System Tray Panel 260401]] — GNOME system tray toggle to start/stop Ollama and reclaim VRAM&lt;br /&gt;
* [[Proceedural Agentic Development Methodology 260304]] — Methodology for systematic agent use&lt;br /&gt;
* [[Project OpenCoder: AI Independence Initiative]] — Strategic roadmap for manufacturing intelligence&lt;br /&gt;
* [[OpenCoder Qwen35 Agentic Setup 260330]] — Qwen3.5 Modelfile fix for tool calling in OpenCode; thinking mode suppression; HDD vs SSD findings&lt;br /&gt;
* [[OpenCode Multi-Provider Configuration Guide 260401]] — Dual-mode AI coding setup with Kimi cloud + Ollama local models via Distrobox&lt;br /&gt;
* [[PAD-Driven ERPNext Strategy 260303]] — Procedural Agentic Development for Frappe/ERPNext configuration and deployment&lt;br /&gt;
* [[Directed Execution: Token-Efficient Agent Development Process]] — Director/Executor/Checker loop and skill distillation for token-efficient agent development (v0.1, 2026-07-15)&lt;br /&gt;
* [[De-Risk: Sovereign Training Data v0.1]] — Frontier-Token Quarantine and the ToS-clean path to owned model weights, prompted by the June 2026 Fable 5 export-control suspension (v0.1, 2026-07-15)&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Job Descriptions ==&lt;br /&gt;
&amp;lt;div style=&amp;quot;column-count:2; column-gap:2em;&amp;quot;&amp;gt;&lt;br /&gt;
* [[Job Descriptions]] — Index of all official job descriptions (IT, Engineering, Sales)&lt;br /&gt;
* [[JD IT Project Staff]] — IT Project Staff&lt;br /&gt;
* [[JD Security Compliance Assistant 260224]] — Security and Compliance Assistant (SCA)&lt;br /&gt;
* [[JD Engineering Designer 260108]] — Engineering Designer&lt;br /&gt;
* [[JD Engineering Supervisor 260109]] — Engineering Supervisor&lt;br /&gt;
* [[JD Technical Sales 260112]] — Technical Sales Engineer&lt;br /&gt;
* [[JD Marketing Assistant 251119]] — Marketing Assistant&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== IT Operations &amp;amp; SOPs ==&lt;br /&gt;
&amp;lt;div style=&amp;quot;column-count:2; column-gap:2em;&amp;quot;&amp;gt;&lt;br /&gt;
* [[SCA Program Plan 260320]] — Security &amp;amp; Compliance Assistant Program Plan v3 (ISO 9001/27001, PDCA, distributed audit model)&lt;br /&gt;
* [[SOP: Inter-Company Ordering and Production Process 260203]] — Ordering and production workflow between Sister Companies and the Cabuyao Plant&lt;br /&gt;
* [[Memo: Team Roles &amp;amp; Reporting Process Clarification 260320]] — Role boundaries, data ownership, and the new ERPNext-driven reporting paradigm&lt;br /&gt;
* [[Standard Operating Procedure: Distributed Minute Taking &amp;amp; Task Ownership 251208]]&lt;br /&gt;
* [[Business Continuity]]&lt;br /&gt;
* [[Procedure: CC-Blast Data Breach Prevention]]&lt;br /&gt;
* [[8D (Eight Discipline) Problem Solving Procedure]]&lt;br /&gt;
* [[Offline Malware Remediation &amp;amp; Data Recovery]]&lt;br /&gt;
* [[Troubleshooting: Access &amp;amp; Permission Issues]]&lt;br /&gt;
* [[Steps to Repair and OCR a Scanned or Corrupted PDF in Ubuntu]]&lt;br /&gt;
* [[IT IMPORTS PROCESSES]]&lt;br /&gt;
* [[IT Purchase Requests 241126]]&lt;br /&gt;
* [[IT REQUEST (OP-ERP-ITR) - EDITED 250801]]&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Sales &amp;amp; Business ==&lt;br /&gt;
&amp;lt;div style=&amp;quot;column-count:2; column-gap:2em;&amp;quot;&amp;gt;&lt;br /&gt;
* [[Comfac Sales Knowledge Base]]&lt;br /&gt;
* [[Comfac CRM – Customer Qualification &amp;amp; Conversion Process]]&lt;br /&gt;
* [[Partner Reseller Pricing 251109]]&lt;br /&gt;
* [[Biz Analysis Methodology 251109]]&lt;br /&gt;
* [[2026 MIS IT KRA KPI Biz Plan]]&lt;br /&gt;
* [[SALES INVOICE TAX OUTPUT 250829]]&lt;br /&gt;
* [[Projects in Process Report 251023]]&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Tools &amp;amp; Productivity ==&lt;br /&gt;
&amp;lt;div style=&amp;quot;column-count:2; column-gap:2em;&amp;quot;&amp;gt;&lt;br /&gt;
* [[Excel Description Filler Tool 📝]]&lt;br /&gt;
* [https://github.com/Comfac-Global-Group/comfac-studies Comfac Studies - Spaced Repetiton Active Recall]&lt;br /&gt;
* [[LibreOffice / Nextcloud Office – &amp;quot;Due Tasks&amp;quot; Conditional Formatting]]&lt;br /&gt;
* [[Google Drive and Shared Drive Training]]&lt;br /&gt;
* [[260108 CGG- GitHub Administration Guide]]&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Wiki &amp;amp; Documentation ==&lt;br /&gt;
&amp;lt;div style=&amp;quot;column-count:2; column-gap:2em;&amp;quot;&amp;gt;&lt;br /&gt;
* [[Mediawiki Setting Up Guide]]&lt;br /&gt;
* [[Contributing to Only Office 260307]]&lt;br /&gt;
* [[Mediawiki Additional Configuration]]&lt;br /&gt;
* [[Mediawiki Docker Migration Guide]]&lt;br /&gt;
* [[Home]]&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Tutorials ==&lt;br /&gt;
&amp;lt;div style=&amp;quot;column-count:2; column-gap:2em;&amp;quot;&amp;gt;&lt;br /&gt;
* [[Claude Code Isolation and Burner Workflow 260211]] — Secure AI development environment setup&lt;br /&gt;
* [[Opencode isolation and burner workflow 260216]] — OpenCode CLI isolation procedures&lt;br /&gt;
* [[LibreOffice Calc NumToWords Extension Complete Guide]] — Extension development&lt;br /&gt;
* [[ERPNext v15 Docker Setup Guide]] — ERPNext v15 local Docker setup (students, evaluators, thin-client demos)&lt;br /&gt;
* [[Erpnextv15-SSH-setup-241111]] — ERPNext v15 SSH/Portainer production setup&lt;br /&gt;
* [[Git-Mediawiki Local Editing 260223]] — Wiki editing with Git&lt;br /&gt;
* [[Understanding &amp;amp; Fixing Kernel Panics 260212]] — System debugging&lt;br /&gt;
* [[OpenCode in Android Termux 260303]] — OpenCode in Android&lt;br /&gt;
* [[OpenCoder Qwen35 Agentic Setup 260330]] — Qwen3.5 agentic setup: Modelfile, tool calling fix, storage impact&lt;br /&gt;
* [[Lora Basics 260304]] — LORA research&lt;br /&gt;
* [https://github.com/anomalyco/opencode/issues/4283#issuecomment-4083399210 Opencode Copy-paste Clipboard doesnt Work - Solution]   https://github.com/anomalyco/opencode/issues/4283#issuecomment-4083399210&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Research ==&lt;br /&gt;
&amp;lt;div style=&amp;quot;column-count:2; column-gap:2em;&amp;quot;&amp;gt;&lt;br /&gt;
* [[Ladybird Browser]] — Browser engine development&lt;br /&gt;
* [[Computing Architecture]] — System design principles&lt;br /&gt;
* [[Backblaze Drive Stats for Server and Storage Qualification 260219]] — Drive reliability analysis&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== For Users Only ==&lt;br /&gt;
* [[Private:Private Ngani]]&lt;br /&gt;
* [[Private:Private Nganipart2]]&lt;br /&gt;
&lt;br /&gt;
== CIT-OJT Project Documentations ==&lt;br /&gt;
* [[OJTDocs: For OJTs only]]&lt;br /&gt;
&lt;br /&gt;
== Need Help? ==&lt;br /&gt;
&amp;lt;div style=&amp;quot;column-count:2; column-gap:2em;&amp;quot;&amp;gt;&lt;br /&gt;
* [[Troubleshooting: Access &amp;amp; Permission Issues]]&lt;br /&gt;
* [https://www.mediawiki.org/wiki/Special:MyLanguage/Help:Contents MediaWiki User&#039;s Guide]&lt;br /&gt;
* [https://www.mediawiki.org/wiki/Special:MyLanguage/Manual:Configuration_settings Configuration settings]&lt;br /&gt;
* [https://www.mediawiki.org/wiki/Special:MyLanguage/Manual:FAQ MediaWiki FAQ]&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;/div&gt;</summary>
		<author><name>Justinaquino</name></author>
	</entry>
	<entry>
		<id>https://mediawiki.comfac.net/index.php?title=De-Risk:_Sovereign_Training_Data_v0.1&amp;diff=263</id>
		<title>De-Risk: Sovereign Training Data v0.1</title>
		<link rel="alternate" type="text/html" href="https://mediawiki.comfac.net/index.php?title=De-Risk:_Sovereign_Training_Data_v0.1&amp;diff=263"/>
		<updated>2026-07-15T15:21:51Z</updated>

		<summary type="html">&lt;p&gt;Justinaquino: Add De-Risk: Sovereign Training Data v0.1&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= De-Risk: Sovereign Training Data v0.1 =&lt;br /&gt;
== Building Model Intelligence Without Frontier Tokens in the Corpus ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;blockquote&amp;gt;&#039;&#039;&#039;Evaluator:&#039;&#039;&#039; Justin Aquino (CEO / CISO-DPO), authored as JCA&amp;lt;/blockquote&amp;gt;&lt;br /&gt;
&amp;lt;blockquote&amp;gt;&#039;&#039;&#039;Evaluation Date:&#039;&#039;&#039; 2026-07-15&amp;lt;/blockquote&amp;gt;&lt;br /&gt;
&amp;lt;blockquote&amp;gt;&#039;&#039;&#039;Methodology:&#039;&#039;&#039; Strategy document — synthesis of the Fable 5 export-control incident, Anthropic/OpenAI commercial-terms analysis, and the Directed Execution Process economics. Companion to &amp;lt;code&amp;gt;2026-07-15-fable-ban-sovereign-ai-and-local-model-strategy.md&amp;lt;/code&amp;gt; (source report, veracity-reviewed) and &amp;lt;code&amp;gt;2026-07-15-fable-fact-check-and-csama-legal-qa-conversation.md&amp;lt;/code&amp;gt; (full Q&amp;amp;A transcript).&amp;lt;/blockquote&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Owner:&#039;&#039;&#039; JCNA (CEO / CISO-DPO) · &#039;&#039;&#039;Status:&#039;&#039;&#039; Draft for review · &#039;&#039;&#039;Date:&#039;&#039;&#039; 2026-07-15&lt;br /&gt;
&#039;&#039;&#039;Companion documents:&#039;&#039;&#039; Directed Execution Process v0.1 · Fable Ban &amp;amp; Local AI (veracity-reviewed 2026-07)&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== 1. Context — What the Fable Episode Actually Proved ==&lt;br /&gt;
&lt;br /&gt;
Three facts from June–July 2026 matter to us. Everything else in the source document was dramatization.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;1.1 Frontier access is now a policy variable, not an infrastructure constant.&#039;&#039;&#039; A Mythos-class model went from launch to worldwide suspension in three days on a single Commerce directive, and stayed dark for 19 days. The trigger was external (a reported jailbreak escalated to Treasury), the scope was blunt (all foreign nationals, unverifiable, therefore everyone), and the reversal was equally abrupt. No SLA, no contract, no self-hosted deployment would have protected a workflow hard-wired to that model. The lesson is not &amp;quot;Anthropic is unreliable&amp;quot; — the lesson is that &#039;&#039;any&#039;&#039; frontier vendor now sits downstream of national-security discretion, and OpenAI&#039;s government-coordinated GPT-5.6 rollout confirms the pattern applies industry-wide.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;1.2 The naive response — distill frontier outputs into your own weights — is a legal trap.&#039;&#039;&#039; Anthropic&#039;s and OpenAI&#039;s terms broadly prohibit using model outputs to train competing models. A pipeline that harvests Fable or Sol completions into a fine-tuning corpus trades a &#039;&#039;regulatory&#039;&#039; dependency for a &#039;&#039;contractual&#039;&#039; liability, and does so in writing, with provenance logs that would be discoverable. For an organization whose CISO-DPO signs the compliance posture, this is not a gray area we can occupy. The source document&#039;s &amp;quot;Distilabel ensures ToS compliance&amp;quot; claim was its weakest section precisely because tooling cannot launder provenance.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;1.3 The clean asset class already exists in our practice.&#039;&#039;&#039; Skills, specs, checklists, and QA-derived process knowledge — instructions authored by our people, versioned in our Forgejo — transferred capability across the blackout at zero legal risk. The Directed Execution Process doc formalized this. What it did &#039;&#039;not&#039;&#039; yet do is close the loop from process knowledge to &#039;&#039;&#039;model weights we own&#039;&#039;&#039;. This document closes that loop, cleanly.&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== 2. The De-Risk Principle: Frontier-Token Quarantine ==&lt;br /&gt;
&lt;br /&gt;
One rule, enforced architecturally, resolves the entire ToS exposure:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;blockquote&amp;gt;&#039;&#039;&#039;No frontier-model-generated token ever enters the training corpus. Frontier models may shape the process; they may never author the data.&#039;&#039;&#039;&amp;lt;/blockquote&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This splits our AI estate into two zones:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Zone !! Contents !! Frontier models (Claude/Fable, Sol)... !! Legal character&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;Process zone&#039;&#039;&#039; || Plans, specs, QA verdicts, RCAs, skill drafts, test designs || ...operate freely here || Ordinary licensed use — Claude helping our team work&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;Corpus zone&#039;&#039;&#039; || Prompts, completions, error traces, corrections, preference pairs destined for fine-tuning || ...are architecturally excluded || 100% owned: our people, our machines, open-weight models, permissive licenses&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
The subtle failure mode to guard against: a Claude-written QA verdict or RCA is still a frontier token. If that text is pasted verbatim into a training sample, the quarantine is breached. Therefore:&lt;br /&gt;
&lt;br /&gt;
* **Claude&#039;s judgments become &#039;&#039;signals&#039;&#039;, not &#039;&#039;text&#039;&#039;.** Pass/fail, severity, &amp;quot;principle violated&amp;quot; tags — structured fields a human confirms — may drive &#039;&#039;selection and labeling&#039;&#039; of corpus samples. Claude&#039;s prose stays in the process zone.&lt;br /&gt;
* &#039;&#039;&#039;The strongest labels don&#039;t come from Claude at all.&#039;&#039;&#039; They come from deterministic verifiers — tests pass, lint clean, build succeeds, output matches oracle. Claude helps &#039;&#039;design&#039;&#039; the tests; the CI system &#039;&#039;issues&#039;&#039; the labels. A label emitted by pytest has no author to have a ToS with.&lt;br /&gt;
* &#039;&#039;&#039;Skills remain process-zone artifacts.&#039;&#039;&#039; Instructions and context engineering are not model training; the Directed Execution loop continues unchanged. This document adds a parallel track, it does not replace that one.&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== 3. The Error Foundry — Why the Error Is the Gold ==&lt;br /&gt;
&lt;br /&gt;
Commodity training data is worthless: every lab has scraped the same internet, and open models are already trained on it. What no one else has — what cannot be scraped, bought, or distilled — is &#039;&#039;&#039;the distribution of failures our specific models make on our specific work, paired with verified corrections.&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
A failure trajectory is the single most valuable sample type because it encodes three things at once:&lt;br /&gt;
&lt;br /&gt;
# &#039;&#039;&#039;Where the model&#039;s capability boundary actually is&#039;&#039;&#039; (not where benchmarks claim it is — recall that ~30% of SWE-bench Pro tasks are broken; our CI is not).&lt;br /&gt;
# &#039;&#039;&#039;A hard negative&#039;&#039;&#039; — a plausible-looking wrong answer, which is exactly what preference-optimization methods (DPO/KTO) need and exactly what synthetic &amp;quot;textbook&amp;quot; data lacks.&lt;br /&gt;
# &#039;&#039;&#039;A verified positive twin&#039;&#039;&#039; — once the correction lands and the verifier goes green, we hold a (failed attempt, working attempt) pair on identical context. That pair is a gradient pointing from &amp;quot;what our model does&amp;quot; to &amp;quot;what our work requires.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
This also sidesteps the model-collapse problem the source document correctly cited: collapse comes from training on unfiltered synthetic output. Our corpus is synthetic &#039;&#039;attempts&#039;&#039; filtered by &#039;&#039;non-synthetic ground truth&#039;&#039; (executing code, real acceptance criteria, human confirmation). The verifier anchors the distribution to reality.&lt;br /&gt;
&lt;br /&gt;
We already run this pattern. &#039;&#039;&#039;Team C at Cabuyao logs negative information from AGV runs for model training&#039;&#039;&#039; — this document generalizes Team C&#039;s discipline to the entire software and knowledge-work estate.&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== 4. Pipeline Architecture ==&lt;br /&gt;
&lt;br /&gt;
=== 4.1 Roles ===&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Layer !! Actor !! Produces !! Zone&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;Direction&#039;&#039;&#039; || Claude (Director session) || FRD-style spec, acceptance criteria, test design, ≤2K-token plan || Process&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;Execution&#039;&#039;&#039; || DeepSeek / Kimi / local Qwen &amp;amp; DeepSeek on OpenCode (vLLM, dual RX 7900 XT) || All code, drafts, attempts — every token of it || &#039;&#039;&#039;Corpus&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;Verification&#039;&#039;&#039; || CI: pytest/lint/type-check/build via n8n or pre-commit || Deterministic pass/fail labels || &#039;&#039;&#039;Corpus&#039;&#039;&#039; (labels)&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;QA&#039;&#039;&#039; || Claude (Checker session, separate from Director) || Verdict as structured fields; prose stays out of corpus || Process&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;RCA&#039;&#039;&#039; || Claude + human || Root-cause analysis → feeds &#039;&#039;skill drafts&#039;&#039; and &#039;&#039;new test cases&#039;&#039;, never sample text || Process&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;Correction&#039;&#039;&#039; || Open model (re-attempt with hint) or human dev || The corrected trajectory — corpus-eligible because its author is ours || &#039;&#039;&#039;Corpus&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;Curation&#039;&#039;&#039; || Interns + devs || Provenance manifest, dedup, pair assembly, PR to dataset repo || Corpus&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
The critical asymmetry: &#039;&#039;&#039;Claude reads everything and authors nothing that trains.&#039;&#039;&#039; Its intelligence is spent on specs, test oracles, verdict signals, and RCA insight — all of which make the &#039;&#039;open&#039;&#039; models&#039; next attempts better, and make the &#039;&#039;corpus&#039;&#039; labels sharper, without ever contributing a training token.&lt;br /&gt;
&lt;br /&gt;
=== 4.2 The loop, end to end ===&lt;br /&gt;
&lt;br /&gt;
# &#039;&#039;&#039;Objective in.&#039;&#039;&#039; Real ticket or deliberately challenging intern objective. Director-Claude produces spec + machine-checkable acceptance criteria. Spec is stored in Forgejo (process repo).&lt;br /&gt;
# &#039;&#039;&#039;Open model executes.&#039;&#039;&#039; Full trajectory logged: prompt, context, every attempt, tool calls, outputs. This logging is non-negotiable — the exhaust &#039;&#039;is&#039;&#039; the product.&lt;br /&gt;
# &#039;&#039;&#039;Verifier fires.&#039;&#039;&#039; Fail → the failure trace is tagged and banked (this is the gold, not discarded). Pass → candidate positive.&lt;br /&gt;
# &#039;&#039;&#039;On failure:&#039;&#039;&#039; RCA (Claude + human) identifies the principle violated → two outputs: (a) a &#039;&#039;skill draft&#039;&#039; or new test case (process zone), (b) a &#039;&#039;hint&#039;&#039; given to the open model for a re-attempt. The re-attempt that passes becomes the positive twin.&lt;br /&gt;
# &#039;&#039;&#039;Pair assembly.&#039;&#039;&#039; (context, failed, passed, verifier evidence, provenance manifest) → PR into the dataset repo. Intern authors it; dev reviews it; Forgejo history is the audit trail and the intern&#039;s portfolio.&lt;br /&gt;
# &#039;&#039;&#039;Periodic fine-tune.&#039;&#039;&#039; When a domain accumulates enough pairs (target: 500–1,000 verified pairs before first run), fine-tune Qwen/DeepSeek variants on the 7900 XT rig (LoRA/QLoRA first — full fine-tunes are not needed to capture correction patterns). Evaluate against a held-out set of &#039;&#039;our own&#039;&#039; past failures.&lt;br /&gt;
# &#039;&#039;&#039;Promotion.&#039;&#039;&#039; A tuned model earns executor duty only by beating the base model on the held-out failure set and on live first-pass acceptance rate — the same metric already in the Directed Execution scoreboard.&lt;br /&gt;
&lt;br /&gt;
=== 4.3 Provenance manifest (per sample, mandatory) ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;text&amp;quot;&amp;gt;&lt;br /&gt;
sample_id: uuid&lt;br /&gt;
generator: {model: qwen2.5-coder-32b, host: PC00-vllm, license: apache-2.0}&lt;br /&gt;
context_source: {ticket: FORGEJO-####, spec_hash: ..., spec_author: human|claude-process-zone}&lt;br /&gt;
label: {verifier: pytest@ci, result: fail|pass, evidence: run_url}&lt;br /&gt;
frontier_tokens_present: false        # hard gate; CI rejects true&lt;br /&gt;
human_touch: {curated_by: intern_id, reviewed_by: dev_id}&lt;br /&gt;
correction_lineage: failed_sample_id  # for positive twins&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;frontier_tokens_present: false&amp;lt;/code&amp;gt; is enforced by a pre-merge check on the dataset repo: samples whose context includes Claude-session exports are rejected mechanically, not by policy memo. Same philosophy as Synopsis — deterministic rules first.&lt;br /&gt;
&lt;br /&gt;
=== 4.4 Storage &amp;amp; plumbing ===&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;Trajectory log:&#039;&#039;&#039; SQLite first (Synopsis pattern), one DB per domain, schema versioned in Forgejo. Graduate to ERPNext DocTypes only when the team needs commission-model-style visibility.&lt;br /&gt;
* &#039;&#039;&#039;Dataset repo:&#039;&#039;&#039; dedicated Forgejo org, one repo per domain (&amp;lt;code&amp;gt;ds-coding&amp;lt;/code&amp;gt;, &amp;lt;code&amp;gt;ds-erpnext&amp;lt;/code&amp;gt;, &amp;lt;code&amp;gt;ds-docs&amp;lt;/code&amp;gt;), PR-gated, LFS for traces.&lt;br /&gt;
* &#039;&#039;&#039;Orchestration:&#039;&#039;&#039; n8n handles verifier dispatch and label writes; no human copies test results by hand.&lt;br /&gt;
* &#039;&#039;&#039;Compute:&#039;&#039;&#039; existing dual RX 7900 XT / vLLM stack for both inference and LoRA training; no new capex required for Phase 1–2.&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== 5. Risk Register — What This De-Risks and What It Doesn&#039;t ==&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Risk !! Naive distillation !! This architecture&lt;br /&gt;
|-&lt;br /&gt;
| Frontier ToS breach (training competing models) || High — corpus is frontier tokens || &#039;&#039;&#039;Eliminated&#039;&#039;&#039; — corpus is 100% own/open provenance, mechanically enforced&lt;br /&gt;
|-&lt;br /&gt;
| Frontier blackout (Fable-type event) || Capability frozen at last distill || Skills + tuned weights both survive; Claude roles degrade gracefully to human plan/QA (slower, not broken)&lt;br /&gt;
|-&lt;br /&gt;
| Model collapse from synthetic data || High — unfiltered frontier outputs || Low — every sample anchored by deterministic verifier; failures kept as hard negatives&lt;br /&gt;
|-&lt;br /&gt;
| Vendor lock-in of process knowledge || N/A || Skills in model-portable SKILL.md format; dataset in open formats; weights are Apache/MIT-base&lt;br /&gt;
|-&lt;br /&gt;
| Data privacy (RA 10173) || Frontier API sees raw work product || Secrets/prod data → &#039;&#039;&#039;local agents only&#039;&#039;&#039; (existing hard rule, unchanged); corpus lives on-prem; CISO-DPO sign-off on any sample class containing personal data&lt;br /&gt;
|-&lt;br /&gt;
| Benchmark self-deception || Marketing benchmarks || Held-out set of our own historical failures — unfakeable, directly relevant&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Residual risks, stated honestly:&#039;&#039;&#039;&lt;br /&gt;
* &#039;&#039;Judge-influence gray zone.&#039;&#039; Even using Claude&#039;s pass/fail &#039;&#039;signals&#039;&#039; to select samples arguably &amp;quot;assists&amp;quot; model development. Our mitigation is that the load-bearing labels are deterministic-verifier labels, humans confirm every Claude-derived tag, and no frontier text enters the corpus. This is a defensible posture, not a court-tested one; counsel (BBLAW) should sanity-check the framing once, briefly.&lt;br /&gt;
* &#039;&#039;LoRA ceiling.&#039;&#039; Correction-pattern LoRAs will not make a 32B model a Mythos-class reasoner. That is fine — the Directed Execution economics never asked it to. The 5% burst path to frontier APIs remains for genuinely hard problems, in the process zone where it belongs.&lt;br /&gt;
* &#039;&#039;Curation labor.&#039;&#039; The pipeline lives or dies on logging discipline and intern throughput. Hence §6.&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== 6. Call to Action ==&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;This week&#039;&#039;&#039;&lt;br /&gt;
# &#039;&#039;&#039;CEO/CISO-DPO:&#039;&#039;&#039; ratify the Frontier-Token Quarantine as policy (one page, references the transcription-tool memo as precedent for &amp;quot;approved-tool&amp;quot; governance style).&lt;br /&gt;
# &#039;&#039;&#039;Sysadmin + Carl:&#039;&#039;&#039; stand up the dataset Forgejo org, SQLite trajectory schema, and the &amp;lt;code&amp;gt;frontier_tokens_present&amp;lt;/code&amp;gt; pre-merge check. Half a day of work; it makes the policy mechanical.&lt;br /&gt;
# &#039;&#039;&#039;Devs:&#039;&#039;&#039; switch OpenCode local-agent sessions to full trajectory logging &#039;&#039;now&#039;&#039;, even before curation starts. Every unlogged failure this month is discarded gold.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Weeks 2–4&#039;&#039;&#039;&lt;br /&gt;
# &#039;&#039;&#039;Interns (all, not just dev interns):&#039;&#039;&#039; first curation objectives issued — assemble 50 verified pairs each from live failure logs, PR&#039;d to the dataset repo. The curriculum &#039;&#039;is&#039;&#039; the loop: they learn spec-reading, verifier evidence, and provenance hygiene simultaneously. Scoreboard: pairs merged, review-pass rate.&lt;br /&gt;
# &#039;&#039;&#039;Team C liaison:&#039;&#039;&#039; map the AGV negative-information logging schema onto the manifest in §4.3 so robotics and software share one provenance convention.&lt;br /&gt;
# &#039;&#039;&#039;BBLAW (existing engagement):&#039;&#039;&#039; 30-minute review of the quarantine framing and the judge-signal question. Not a new engagement — an agenda item.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Month 2–3&#039;&#039;&#039;&lt;br /&gt;
# First LoRA run on the coding domain once ≥500 pairs verified. Evaluate on held-out failure set. Publish results internally — win or lose, the eval harness itself is a durable asset.&lt;br /&gt;
# &#039;&#039;&#039;Decision gate:&#039;&#039;&#039; if tuned executor beats base on first-pass acceptance, promote it in the Directed Execution rotation and begin domain #2 (ERPNext customization is the obvious candidate — our failure data there is uniquely ours).&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== 7. The Strategic Frame ==&lt;br /&gt;
&lt;br /&gt;
Two tracks, different clock speeds, one direction:&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;Skills (fast, instant transfer):&#039;&#039;&#039; capability as &#039;&#039;instructions&#039;&#039;, portable across any executor, already running. Survives blackouts by construction.&lt;br /&gt;
* &#039;&#039;&#039;Weights (slow, compounding):&#039;&#039;&#039; capability as &#039;&#039;parameters we own&#039;&#039;, grown exclusively from our own error distribution, legally unencumbered because the corpus never contained a frontier token.&lt;br /&gt;
&lt;br /&gt;
Claude&#039;s highest-value role in both is the same: not as the source of answers to memorize, but as the intelligence that designs the tests, reads the failures, and sharpens the questions — while our models, our people, and our verifiers author every byte we will ever train on.&lt;br /&gt;
&lt;br /&gt;
The Fable ban gave us the precedent. The error logs give us the data. The quarantine gives us the clean title.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;The error is the gold. Log everything.&#039;&#039;&lt;/div&gt;</summary>
		<author><name>Justinaquino</name></author>
	</entry>
	<entry>
		<id>https://mediawiki.comfac.net/index.php?title=Main_Page&amp;diff=262</id>
		<title>Main Page</title>
		<link rel="alternate" type="text/html" href="https://mediawiki.comfac.net/index.php?title=Main_Page&amp;diff=262"/>
		<updated>2026-07-15T11:02:55Z</updated>

		<summary type="html">&lt;p&gt;Justinaquino: Add Directed Execution article link&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__NOTOC__&lt;br /&gt;
&amp;lt;div style=&amp;quot;background:#f8f9fa; border:1px solid #ddd; border-radius:4px; padding:12px 16px; margin-bottom:20px;&amp;quot;&amp;gt;&lt;br /&gt;
Welcome to the &#039;&#039;&#039;Comfac IT Knowledge Base&#039;&#039;&#039;. Use the sections below to find guides, SOPs, and references organized by topic.&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== ERPNext / Frappe ==&lt;br /&gt;
&amp;lt;div style=&amp;quot;column-count:2; column-gap:2em;&amp;quot;&amp;gt;&lt;br /&gt;
* [[Frappe HRMS]] — &#039;&#039;&#039;HR &amp;amp; Payroll&#039;&#039;&#039; (with Philippine Localization)&lt;br /&gt;
* [[Frappe ERPNext/Webshop]] — &#039;&#039;&#039;E-Commerce Webshop&#039;&#039;&#039; (setup, architecture, chapters)&lt;br /&gt;
* [[Manufacturing v16 260125]]&lt;br /&gt;
* [[ERpnext Asset Management Procedure 260113]]&lt;br /&gt;
* [[ERPNext HR Module Outline]]&lt;br /&gt;
* [[ERPNEXT Payroll POC 251212]]&lt;br /&gt;
* [[Comfac ERPNext Strategy Canvas (Expanded)]]&lt;br /&gt;
* [[PAD-Driven ERPNext Strategy 260303]] — PAD/AI-agentic implementation strategy for Frappe ERPNext&lt;br /&gt;
* [[ERPNext v15 Docker Setup Guide]] — Local Docker setup for evaluation, testing, and student use&lt;br /&gt;
* [[Frappe Links and References]]&lt;br /&gt;
* [[Using Frappe Wiki]]&lt;br /&gt;
* [https://docs.frappe.io/cloud/guidelines-for-contributing-regional-compliance-app Guidelines for Contributing Regional Compliance App]&lt;br /&gt;
* [https://docs.frappe.io/cloud/what-are-benches-and-bench-groups What are Benches?]&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== System Administration &amp;amp; Self-Hosting ==&lt;br /&gt;
&amp;lt;div style=&amp;quot;column-count:2; column-gap:2em;&amp;quot;&amp;gt;&lt;br /&gt;
* [[Networking PfSense Index]] — Consolidated index of all networking, pfSense, DNS, and infrastructure guides&lt;br /&gt;
* [[System Hardening Strategy: Win2Lin Migration &amp;amp; Infrastructure 251129]]&lt;br /&gt;
* [[Controller Systems 251213-01]]&lt;br /&gt;
* [[Power Distribution Tree 251213]]&lt;br /&gt;
* [[Introduction: Why Self-Host Your Email?]]&lt;br /&gt;
* [[Mailcow + Thunderbird Setup Guide (Email + Calendar)]]&lt;br /&gt;
* [[Mailcow SOGo: Creating Filters for Events, Approvals, and Organizational Emails]]&lt;br /&gt;
* [[Spoof Timezone Extension – Setup Guide for Comfac Staff]]&lt;br /&gt;
* [[Viber Focus-Stealing]]&lt;br /&gt;
* [[🌐 WordPress Website — *You Own Everything, Learn Everything*]]&lt;br /&gt;
* [[Portainer to Docker Compose Migration Guide]]&lt;br /&gt;
* [[Organizing Coder Terminals]] — Tmux + dynamic titles for managing multiple AI agent terminals&lt;br /&gt;
* [[Editing Mastodon Docker Deployment Guide 260402]]&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Storage &amp;amp; Hardware ==&lt;br /&gt;
&amp;lt;div style=&amp;quot;column-count:2; column-gap:2em;&amp;quot;&amp;gt;&lt;br /&gt;
* [[TrueNAS Configuration Options &amp;amp; Scale Options 251130]]&lt;br /&gt;
* [[TrueNAS Business Plan: Project 251212]]&lt;br /&gt;
* [[Comparison: TrueNAS Mini X+ vs Dell Precision 3680 Tower (2025)]]&lt;br /&gt;
* [[Backblaze Drive Stats for Server and Storage Qualification]]&lt;br /&gt;
* [[Industrial Controllers and Water Utilities 251011]]&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== AI &amp;amp; Machine Learning ==&lt;br /&gt;
&amp;lt;div style=&amp;quot;column-count:2; column-gap:2em;&amp;quot;&amp;gt;&lt;br /&gt;
* [[OpenWebUI - 251128-justin]]&lt;br /&gt;
* [[Comfac GPU Scaling and AI Research Goals]]&lt;br /&gt;
* [[🧠 Process: Selecting and Installing the Right Ollama Model for Your Hardware]]&lt;br /&gt;
* [[Ollama GNOME System Tray Panel 260401]] — GNOME system tray toggle to start/stop Ollama and reclaim VRAM&lt;br /&gt;
* [[Proceedural Agentic Development Methodology 260304]] — Methodology for systematic agent use&lt;br /&gt;
* [[Project OpenCoder: AI Independence Initiative]] — Strategic roadmap for manufacturing intelligence&lt;br /&gt;
* [[OpenCoder Qwen35 Agentic Setup 260330]] — Qwen3.5 Modelfile fix for tool calling in OpenCode; thinking mode suppression; HDD vs SSD findings&lt;br /&gt;
* [[OpenCode Multi-Provider Configuration Guide 260401]] — Dual-mode AI coding setup with Kimi cloud + Ollama local models via Distrobox&lt;br /&gt;
* [[PAD-Driven ERPNext Strategy 260303]] — Procedural Agentic Development for Frappe/ERPNext configuration and deployment&lt;br /&gt;
* [[Directed Execution: Token-Efficient Agent Development Process]] — Director/Executor/Checker loop and skill distillation for token-efficient agent development (v0.1, 2026-07-15)&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Job Descriptions ==&lt;br /&gt;
&amp;lt;div style=&amp;quot;column-count:2; column-gap:2em;&amp;quot;&amp;gt;&lt;br /&gt;
* [[Job Descriptions]] — Index of all official job descriptions (IT, Engineering, Sales)&lt;br /&gt;
* [[JD IT Project Staff]] — IT Project Staff&lt;br /&gt;
* [[JD Security Compliance Assistant 260224]] — Security and Compliance Assistant (SCA)&lt;br /&gt;
* [[JD Engineering Designer 260108]] — Engineering Designer&lt;br /&gt;
* [[JD Engineering Supervisor 260109]] — Engineering Supervisor&lt;br /&gt;
* [[JD Technical Sales 260112]] — Technical Sales Engineer&lt;br /&gt;
* [[JD Marketing Assistant 251119]] — Marketing Assistant&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== IT Operations &amp;amp; SOPs ==&lt;br /&gt;
&amp;lt;div style=&amp;quot;column-count:2; column-gap:2em;&amp;quot;&amp;gt;&lt;br /&gt;
* [[SCA Program Plan 260320]] — Security &amp;amp; Compliance Assistant Program Plan v3 (ISO 9001/27001, PDCA, distributed audit model)&lt;br /&gt;
* [[SOP: Inter-Company Ordering and Production Process 260203]] — Ordering and production workflow between Sister Companies and the Cabuyao Plant&lt;br /&gt;
* [[Memo: Team Roles &amp;amp; Reporting Process Clarification 260320]] — Role boundaries, data ownership, and the new ERPNext-driven reporting paradigm&lt;br /&gt;
* [[Standard Operating Procedure: Distributed Minute Taking &amp;amp; Task Ownership 251208]]&lt;br /&gt;
* [[Business Continuity]]&lt;br /&gt;
* [[Procedure: CC-Blast Data Breach Prevention]]&lt;br /&gt;
* [[8D (Eight Discipline) Problem Solving Procedure]]&lt;br /&gt;
* [[Offline Malware Remediation &amp;amp; Data Recovery]]&lt;br /&gt;
* [[Troubleshooting: Access &amp;amp; Permission Issues]]&lt;br /&gt;
* [[Steps to Repair and OCR a Scanned or Corrupted PDF in Ubuntu]]&lt;br /&gt;
* [[IT IMPORTS PROCESSES]]&lt;br /&gt;
* [[IT Purchase Requests 241126]]&lt;br /&gt;
* [[IT REQUEST (OP-ERP-ITR) - EDITED 250801]]&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Sales &amp;amp; Business ==&lt;br /&gt;
&amp;lt;div style=&amp;quot;column-count:2; column-gap:2em;&amp;quot;&amp;gt;&lt;br /&gt;
* [[Comfac Sales Knowledge Base]]&lt;br /&gt;
* [[Comfac CRM – Customer Qualification &amp;amp; Conversion Process]]&lt;br /&gt;
* [[Partner Reseller Pricing 251109]]&lt;br /&gt;
* [[Biz Analysis Methodology 251109]]&lt;br /&gt;
* [[2026 MIS IT KRA KPI Biz Plan]]&lt;br /&gt;
* [[SALES INVOICE TAX OUTPUT 250829]]&lt;br /&gt;
* [[Projects in Process Report 251023]]&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Tools &amp;amp; Productivity ==&lt;br /&gt;
&amp;lt;div style=&amp;quot;column-count:2; column-gap:2em;&amp;quot;&amp;gt;&lt;br /&gt;
* [[Excel Description Filler Tool 📝]]&lt;br /&gt;
* [https://github.com/Comfac-Global-Group/comfac-studies Comfac Studies - Spaced Repetiton Active Recall]&lt;br /&gt;
* [[LibreOffice / Nextcloud Office – &amp;quot;Due Tasks&amp;quot; Conditional Formatting]]&lt;br /&gt;
* [[Google Drive and Shared Drive Training]]&lt;br /&gt;
* [[260108 CGG- GitHub Administration Guide]]&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Wiki &amp;amp; Documentation ==&lt;br /&gt;
&amp;lt;div style=&amp;quot;column-count:2; column-gap:2em;&amp;quot;&amp;gt;&lt;br /&gt;
* [[Mediawiki Setting Up Guide]]&lt;br /&gt;
* [[Contributing to Only Office 260307]]&lt;br /&gt;
* [[Mediawiki Additional Configuration]]&lt;br /&gt;
* [[Mediawiki Docker Migration Guide]]&lt;br /&gt;
* [[Home]]&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Tutorials ==&lt;br /&gt;
&amp;lt;div style=&amp;quot;column-count:2; column-gap:2em;&amp;quot;&amp;gt;&lt;br /&gt;
* [[Claude Code Isolation and Burner Workflow 260211]] — Secure AI development environment setup&lt;br /&gt;
* [[Opencode isolation and burner workflow 260216]] — OpenCode CLI isolation procedures&lt;br /&gt;
* [[LibreOffice Calc NumToWords Extension Complete Guide]] — Extension development&lt;br /&gt;
* [[ERPNext v15 Docker Setup Guide]] — ERPNext v15 local Docker setup (students, evaluators, thin-client demos)&lt;br /&gt;
* [[Erpnextv15-SSH-setup-241111]] — ERPNext v15 SSH/Portainer production setup&lt;br /&gt;
* [[Git-Mediawiki Local Editing 260223]] — Wiki editing with Git&lt;br /&gt;
* [[Understanding &amp;amp; Fixing Kernel Panics 260212]] — System debugging&lt;br /&gt;
* [[OpenCode in Android Termux 260303]] — OpenCode in Android&lt;br /&gt;
* [[OpenCoder Qwen35 Agentic Setup 260330]] — Qwen3.5 agentic setup: Modelfile, tool calling fix, storage impact&lt;br /&gt;
* [[Lora Basics 260304]] — LORA research&lt;br /&gt;
* [https://github.com/anomalyco/opencode/issues/4283#issuecomment-4083399210 Opencode Copy-paste Clipboard doesnt Work - Solution]   https://github.com/anomalyco/opencode/issues/4283#issuecomment-4083399210&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Research ==&lt;br /&gt;
&amp;lt;div style=&amp;quot;column-count:2; column-gap:2em;&amp;quot;&amp;gt;&lt;br /&gt;
* [[Ladybird Browser]] — Browser engine development&lt;br /&gt;
* [[Computing Architecture]] — System design principles&lt;br /&gt;
* [[Backblaze Drive Stats for Server and Storage Qualification 260219]] — Drive reliability analysis&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== For Users Only ==&lt;br /&gt;
* [[Private:Private Ngani]]&lt;br /&gt;
* [[Private:Private Nganipart2]]&lt;br /&gt;
&lt;br /&gt;
== CIT-OJT Project Documentations ==&lt;br /&gt;
* [[OJTDocs: For OJTs only]]&lt;br /&gt;
&lt;br /&gt;
== Need Help? ==&lt;br /&gt;
&amp;lt;div style=&amp;quot;column-count:2; column-gap:2em;&amp;quot;&amp;gt;&lt;br /&gt;
* [[Troubleshooting: Access &amp;amp; Permission Issues]]&lt;br /&gt;
* [https://www.mediawiki.org/wiki/Special:MyLanguage/Help:Contents MediaWiki User&#039;s Guide]&lt;br /&gt;
* [https://www.mediawiki.org/wiki/Special:MyLanguage/Manual:Configuration_settings Configuration settings]&lt;br /&gt;
* [https://www.mediawiki.org/wiki/Special:MyLanguage/Manual:FAQ MediaWiki FAQ]&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;/div&gt;</summary>
		<author><name>Justinaquino</name></author>
	</entry>
	<entry>
		<id>https://mediawiki.comfac.net/index.php?title=Directed_Execution:_Token-Efficient_Agent_Development_Process&amp;diff=261</id>
		<title>Directed Execution: Token-Efficient Agent Development Process</title>
		<link rel="alternate" type="text/html" href="https://mediawiki.comfac.net/index.php?title=Directed_Execution:_Token-Efficient_Agent_Development_Process&amp;diff=261"/>
		<updated>2026-07-15T11:02:54Z</updated>

		<summary type="html">&lt;p&gt;Justinaquino: Add Directed Execution: Token-Efficient Agent Development Process v0.1&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Directed Execution: Token-Efficient Agent Development Process =&lt;br /&gt;
&#039;&#039;&#039;CGG IT — Process &amp;amp; Skillset Definition v0.1&#039;&#039;&#039;&lt;br /&gt;
Owner: JCA · Status: Draft for team review · Date: 2026-07-15&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== 1. Problem Statement ==&lt;br /&gt;
&lt;br /&gt;
Developers are consuming Claude Sonnet and Opus tokens for raw code generation. This inverts the economics of the model market. Frontier-model output tokens are the single most expensive resource in the stack (Opus 4.8 output: ₱1,450/M; Fable 5: ₱2,900/M), while commodity-model output is nearly free by comparison (DeepSeek V4 Flash: ₱16/M — a 90× to 180× spread). Meanwhile, frontier-model &#039;&#039;input&#039;&#039; tokens are roughly 5× cheaper than their own output tokens, and cache hits cheaper still.&lt;br /&gt;
&lt;br /&gt;
The consequence is a simple design rule that the current workflow violates:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;blockquote&amp;gt;&#039;&#039;&#039;Expensive models should read a lot and write a little. Cheap models should write a lot and be corrected.&#039;&#039;&#039;&amp;lt;/blockquote&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Nobody has directed the developers to work this way, and there is no shared mechanism for making the cheap models better over time. Both gaps are addressed here: a role-separated loop for day-to-day work, and a skill system that converts QA corrections into reusable capability for the cheap agents.&lt;br /&gt;
&lt;br /&gt;
== 2. Economic Rationale (worked example) ==&lt;br /&gt;
&lt;br /&gt;
Assume a typical feature task: ~30K tokens of relevant context, ~50K tokens of generated code and tests.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Current pattern — Opus does everything:&#039;&#039;&#039;&lt;br /&gt;
30K in (₱8.70) + 50K out (₱72.50), plus one revision cycle of similar size ≈ &#039;&#039;&#039;₱150–160 per task&#039;&#039;&#039;, with no independent QA gate.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Directed pattern:&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Step !! Model !! Tokens !! Cost&lt;br /&gt;
|-&lt;br /&gt;
| Plan + FRD || Opus 4.8 || 30K in / 2K out || ₱11.60&lt;br /&gt;
|-&lt;br /&gt;
| Execute || DS V4 Flash || 35K in / 50K out || ₱1.08&lt;br /&gt;
|-&lt;br /&gt;
| QA review || Opus 4.8 || 60K in / 1K out || ₱18.85&lt;br /&gt;
|-&lt;br /&gt;
| Correction || DS V4 Flash || 40K in / 20K out || ₱0.64&lt;br /&gt;
|-&lt;br /&gt;
| Re-check || Opus 4.8 (cached ctx) || 25K in / 0.5K out || ~₱8&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;Total&#039;&#039;&#039; || &#039;&#039;&#039;≈ ₱40&#039;&#039;&#039;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
Roughly a 70–75% cost reduction &#039;&#039;while adding a QA gate that did not previously exist&#039;&#039;. The QA read is the largest line item, which is correct — that is where the intelligence is actually needed. Substituting Sonnet as the checker for routine tasks pushes the total under ₱20. As skills accumulate and first-pass acceptance rises, the correction cycle amortizes toward zero.&lt;br /&gt;
&lt;br /&gt;
The point is not merely savings. It is that &#039;&#039;&#039;judgment and volume are different products&#039;&#039;&#039;, and we have been buying volume at judgment prices.&lt;br /&gt;
&lt;br /&gt;
== 3. Principles ==&lt;br /&gt;
&lt;br /&gt;
# &#039;&#039;&#039;Direction is the deliverable of intelligence.&#039;&#039;&#039; The frontier model&#039;s job is decomposition, constraints, acceptance criteria, and verdicts — all short, dense outputs. If Claude is emitting more than ~2K tokens on a task, something is misrouted.&lt;br /&gt;
# &#039;&#039;&#039;Deterministic-first, same as Synopsis.&#039;&#039;&#039; Anything checkable by a linter, test suite, type checker, or script never reaches a paid model. Machine checks run before Claude sees the diff.&lt;br /&gt;
# &#039;&#039;&#039;Every correction is an asset.&#039;&#039;&#039; A QA correction consumed once is an expense; distilled into a skill, it is capital. The loop is not complete until the correction is either distilled or explicitly judged one-off.&lt;br /&gt;
# &#039;&#039;&#039;Cheap agents are pushed, not babysat.&#039;&#039;&#039; Executors get hard objectives with clear acceptance criteria and their accumulated skill library — not hand-holding. Failures are information for the skill system.&lt;br /&gt;
# &#039;&#039;&#039;The loop is the curriculum.&#039;&#039;&#039; Interns learn the same process the agents run: plan, execute, check, correct, distill. Team-wide token efficiency is a literacy goal, not a dev-only optimization.&lt;br /&gt;
&lt;br /&gt;
== 4. Roles ==&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Role !! Model tier !! Reads !! Writes !! Output budget&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;Director&#039;&#039;&#039; || Claude Opus / Fable || Objective, codebase context, skill index || FRD: decomposition, interfaces, acceptance criteria, risks || ≤ 2K tokens&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;Executor&#039;&#039;&#039; || DS V4 Flash, Kimi K2.6; later local Qwen/DeepSeek via OpenCode || FRD + relevant skills + code context || Code, tests, migration scripts — full volume || Unbounded&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;Checker&#039;&#039;&#039; || Claude Opus (critical) / Sonnet (routine) || Full diff + FRD + machine-check results || Verdict: PASS/FAIL per acceptance criterion, itemized corrections anchored to lines || ≤ 1K tokens&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;Skill Librarian&#039;&#039;&#039; || Human (rotating dev/intern) + cheap model drafting || QA correction logs || Skill drafts, skill index maintenance || —&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
Director and Checker should be &#039;&#039;&#039;separate sessions&#039;&#039;&#039; even when the same model — the Checker must evaluate against the FRD, not defend its own plan.&lt;br /&gt;
&lt;br /&gt;
Model routing within tiers: DeepSeek V4 Flash is the default executor. Kimi K2.6 when the task needs multimodal input (screenshots, UI review) or its larger instant-mode quality helps. Local agents take over as the vLLM/Ollama stack proves out on benchmarked task classes — the skill library transfers with them, which is the strategic payoff: skills are model-portable capability, not vendor lock-in.&lt;br /&gt;
&lt;br /&gt;
== 5. The Loop ==&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Plan → Execute → Machine-check → QA → Correct → Distill → Reuse&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Plan.&#039;&#039;&#039; Director receives the objective and produces an FRD-lite (template below). No code beyond interface signatures and test-case &#039;&#039;descriptions&#039;&#039;. The FRD is the contract; ambiguity discovered later is a planning defect and goes back to the Director, not patched silently by the Executor.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Execute.&#039;&#039;&#039; Executor works in OpenCode with the FRD and the relevant skills loaded (skills prepended as a stable prefix — this also maximizes cache hits). It generates code and tests to satisfy the acceptance criteria. It may burn tokens freely; that is what it is for.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Machine-check.&#039;&#039;&#039; Lint, type-check, test run, formatter. Automated (n8n or a pre-commit script). Failures loop back to the Executor without any paid QA read. Claude never reviews code that fails machine checks.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;QA.&#039;&#039;&#039; Checker reads FRD + diff + machine-check results and returns a structured verdict. It does not rewrite code. Each FAIL item states &#039;&#039;what is wrong, why, and the principle violated&#039;&#039; — the &amp;quot;why&amp;quot; is raw material for distillation.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Correct.&#039;&#039;&#039; Executor applies corrections. Two correction cycles maximum; a third failure escalates to a human plus a mandatory skill-gap review (&amp;quot;what skill would have prevented this?&amp;quot;).&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Distill.&#039;&#039;&#039; Weekly, the Skill Librarian reviews the QA correction log. Any correction pattern appearing &#039;&#039;&#039;twice or more&#039;&#039;&#039; becomes a skill candidate. A cheap model drafts the skill from the correction transcripts; a human reviews and merges it into the Forgejo skill repo.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Reuse.&#039;&#039;&#039; Skills are indexed by trigger. The Director&#039;s FRD names which skills apply; the Executor loads them. Cheap agents therefore climb: yesterday&#039;s correction is today&#039;s default behavior.&lt;br /&gt;
&lt;br /&gt;
== 6. Deliverable Contracts ==&lt;br /&gt;
&lt;br /&gt;
=== FRD-lite (Director output) ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;text&amp;quot;&amp;gt;&lt;br /&gt;
FRD-&amp;lt;seq&amp;gt;: &amp;lt;title&amp;gt;&lt;br /&gt;
Objective: one sentence.&lt;br /&gt;
Scope in / Scope out: explicit exclusions.&lt;br /&gt;
Interfaces: function/API signatures the Executor must implement.&lt;br /&gt;
Acceptance criteria: numbered, each machine- or QA-checkable.&lt;br /&gt;
Constraints: security, style, dependency, and performance rules that apply.&lt;br /&gt;
Skills to load: skill IDs from the index.&lt;br /&gt;
Risk notes: where the Executor is most likely to go wrong.&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== QA Verdict (Checker output) ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;text&amp;quot;&amp;gt;&lt;br /&gt;
VERDICT: PASS | FAIL&lt;br /&gt;
AC-1: PASS/FAIL — &amp;lt;one line&amp;gt;&lt;br /&gt;
AC-n: ...&lt;br /&gt;
Corrections (if FAIL):&lt;br /&gt;
  C1 [file:line] What / Why / Principle violated&lt;br /&gt;
Distill flags: corrections likely to recur → candidate skill name&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The &amp;quot;Principle violated&amp;quot; field is deliberately mandatory. It is what makes the verdict distillable rather than a one-off patch instruction.&lt;br /&gt;
&lt;br /&gt;
== 7. The Skill System ==&lt;br /&gt;
&lt;br /&gt;
A skill is a short markdown file teaching a cheap model a specific competence, in the same shape Anthropic uses for Claude skills — which means skills built here also work when the executor &#039;&#039;is&#039;&#039; Claude, or a local model, or whatever comes next.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Format&#039;&#039;&#039; (&amp;lt;code&amp;gt;SKILL.md&amp;lt;/code&amp;gt; per skill, one directory per skill in the Forgejo repo, e.g. &amp;lt;code&amp;gt;skills/erpnext-patch-migrations/&amp;lt;/code&amp;gt;):&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;text&amp;quot;&amp;gt;&lt;br /&gt;
name: &amp;lt;kebab-case&amp;gt;&lt;br /&gt;
trigger: when this skill applies (used by Director for routing)&lt;br /&gt;
procedure: numbered steps / rules&lt;br /&gt;
examples: one good, one bad (drawn from real QA corrections)&lt;br /&gt;
anti-patterns: the specific failures that birthed this skill&lt;br /&gt;
provenance: FRD/QA references, author, date&lt;br /&gt;
status: draft | reviewed | adopted | deprecated&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Lifecycle.&#039;&#039;&#039; Draft (from correction log, cheap-model-written) → Reviewed (human, PR in Forgejo) → Adopted (in the index, loadable) → Deprecated (superseded or model-obsoleted). Skills are versioned like code because they are code — for the agents.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Ownership.&#039;&#039;&#039; Devs are consumers and reviewers, not the bottleneck. Interns, working with the local DS agents in OpenCode, author most drafts as part of their objectives. The repo&#039;s PR history doubles as an intern portfolio.&lt;br /&gt;
&lt;br /&gt;
== 8. Escalation Rules ==&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Situation !! Route&lt;br /&gt;
|-&lt;br /&gt;
| Routine feature/bugfix, skills exist || Flash executes, Sonnet checks&lt;br /&gt;
|-&lt;br /&gt;
| Novel architecture, security-sensitive, cross-system design || Opus/Fable plans and checks&lt;br /&gt;
|-&lt;br /&gt;
| Executor fails 2 correction cycles || Human review + skill-gap analysis&lt;br /&gt;
|-&lt;br /&gt;
| Executor requests clarification || Back to Director (cheap→expensive calls are Director-mediated, never ad hoc)&lt;br /&gt;
|-&lt;br /&gt;
| Anything touching secrets, credentials, prod data || Local agents only; no external API&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
The last row is a hard rule and aligns with the transcription-tool memo posture: sensitive context stays on the ZeroTier overlay.&lt;br /&gt;
&lt;br /&gt;
== 9. Metrics &amp;amp; Token Ledger ==&lt;br /&gt;
&lt;br /&gt;
Per task, logged (SQLite to start, consistent with the Synopsis MVP philosophy; ERPNext later if it earns its keep):&lt;br /&gt;
&lt;br /&gt;
* Tokens and ₱ by role (Director / Executor / Checker), per task and per week.&lt;br /&gt;
* &#039;&#039;&#039;First-pass acceptance rate&#039;&#039;&#039; — the headline metric. Rising FPA means skills are working.&lt;br /&gt;
* &#039;&#039;&#039;Correction cycles per task&#039;&#039;&#039; and &#039;&#039;&#039;escalation rate&#039;&#039;&#039;.&lt;br /&gt;
* &#039;&#039;&#039;Skill reuse count&#039;&#039;&#039; and &#039;&#039;&#039;skills authored&#039;&#039;&#039; per person — the intern scoreboard.&lt;br /&gt;
* &#039;&#039;&#039;Cost per merged deliverable&#039;&#039;&#039;, trended. Target: sustained &amp;lt;30% of the all-frontier baseline within one quarter.&lt;br /&gt;
&lt;br /&gt;
The ledger is not surveillance; it is the feedback signal that tells us when a task class is ready to move from Flash to a local model, and when a checker can be downgraded from Opus to Sonnet.&lt;br /&gt;
&lt;br /&gt;
== 10. Rollout ==&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Week 1 — Instrument and declare.&#039;&#039;&#039; Stand up the skill repo in Forgejo, the token ledger, and the machine-check gate. Short directive to the team: no frontier-model code generation for tasks with an FRD path; frontier models plan and check.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Week 2 — Seed skills.&#039;&#039;&#039; Mine the last month of Claude chat history for recurring correction patterns; interns draft the first 5–10 skills (likely candidates: ERPNext patch conventions, Frappe API idioms, our lint/commit standards, test scaffolding).&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Week 3 — First directed sprints.&#039;&#039;&#039; Each intern gets one challenging objective run fully through the loop with a local DS agent in OpenCode. Devs act as Skill Librarian reviewers. Every completed objective must ship at least one skill PR.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Week 4 — Review.&#039;&#039;&#039; FPA, cost per deliverable, and skill count reviewed against baseline. Decide the first task class to pilot on fully local models.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Steady state.&#039;&#039;&#039; The loop is the standard operating rhythm. Quarterly, revisit model routing (the pricing table this document was built from will be stale in months) and prune deprecated skills.&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Reasoning summary: the spread between frontier output pricing and commodity output pricing (90×+) makes &amp;quot;smart model writes code&amp;quot; the single most expensive habit in the workflow, while the input/output asymmetry (5×) makes &amp;quot;smart model reads everything, writes verdicts&amp;quot; nearly free by comparison. The skill system converts the residual cost — QA corrections — into permanent, model-portable capability, so the cheap tier&#039;s quality compounds and the expensive tier&#039;s involvement shrinks over time. Interns are the labor force and the beneficiaries of the same loop.&#039;&#039;&lt;/div&gt;</summary>
		<author><name>Justinaquino</name></author>
	</entry>
	<entry>
		<id>https://mediawiki.comfac.net/index.php?title=Tutorial:_Exposing_a_Dockerized_Web_App_via_NPM_Direct_DB_Config&amp;diff=260</id>
		<title>Tutorial: Exposing a Dockerized Web App via NPM Direct DB Config</title>
		<link rel="alternate" type="text/html" href="https://mediawiki.comfac.net/index.php?title=Tutorial:_Exposing_a_Dockerized_Web_App_via_NPM_Direct_DB_Config&amp;diff=260"/>
		<updated>2026-07-11T12:56:50Z</updated>

		<summary type="html">&lt;p&gt;Justinaquino: Uploaded tutorial&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__NOTOC__&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;background-color: #e7f3fe; border-left: 6px solid #2196F3; padding: 15px; margin-bottom: 20px;&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;strong&amp;gt;Tutorial:&amp;lt;/strong&amp;gt; Exposing a Dockerized Web App via NPM Direct DB Config&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;strong&amp;gt;Audience:&amp;lt;/strong&amp;gt; Self-hosters who need to publish a Dockerized service through Nginx Proxy Manager without admin-panel credentials.&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;strong&amp;gt;Last updated:&amp;lt;/strong&amp;gt; 2026-07-11&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= My Dockerized Web App — NPM Proxy Host Setup (Direct DB Method) =&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Scope:&#039;&#039;&#039; Expose a Dockerized internal web application through Nginx Proxy Manager (NPM) on &amp;lt;docker-host&amp;gt; without using the NPM Admin UI, because NPM admin-panel credentials are not stored in the BRC credential store.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Outcome:&#039;&#039;&#039; &amp;lt;code&amp;gt;http://app.example.org&amp;lt;/code&amp;gt; resolves to the analyzer on &amp;lt;docker-host&amp;gt; (&amp;lt;code&amp;gt;&amp;lt;npm-host-zerotier-ip&amp;gt;:&amp;lt;app-port&amp;gt;&amp;lt;/code&amp;gt;) via NPM proxy host &amp;lt;code&amp;gt;&amp;lt;proxy-host-id&amp;gt;&amp;lt;/code&amp;gt;. HTTPS is pending the manual SSL-certificate step in the NPM UI.&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== What You Need ==&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Item&lt;br /&gt;
! Value / Location&lt;br /&gt;
|-&lt;br /&gt;
| Target domain&lt;br /&gt;
| &amp;lt;code&amp;gt;app.example.org&amp;lt;/code&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| Backing service&lt;br /&gt;
| &amp;lt;code&amp;gt;&amp;lt;npm-host-zerotier-ip&amp;gt;:&amp;lt;app-port&amp;gt;&amp;lt;/code&amp;gt; (&amp;lt;docker-host&amp;gt; ZeroTier, &amp;lt;code&amp;gt;myapp&amp;lt;/code&amp;gt; container)&lt;br /&gt;
|-&lt;br /&gt;
| NPM host&lt;br /&gt;
| &amp;lt;docker-host&amp;gt; (&amp;lt;code&amp;gt;&amp;lt;npm-host-local-ip&amp;gt;&amp;lt;/code&amp;gt; local / &amp;lt;code&amp;gt;&amp;lt;npm-host-zerotier-ip&amp;gt;&amp;lt;/code&amp;gt; ZeroTier)&lt;br /&gt;
|-&lt;br /&gt;
| NPM DB container&lt;br /&gt;
| &amp;lt;code&amp;gt;nginx-proxy-manager-db&amp;lt;/code&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| NPM app container&lt;br /&gt;
| &amp;lt;code&amp;gt;nginx-proxy-manager-app&amp;lt;/code&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| NPM DB credentials&lt;br /&gt;
| &amp;lt;code&amp;gt;npm&amp;lt;/code&amp;gt; / &amp;lt;code&amp;gt;npm&amp;lt;/code&amp;gt; (hardcoded in NPM stack)&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;docker-host&amp;gt; SSH credentials&lt;br /&gt;
| &amp;lt;code&amp;gt;&amp;lt;credential-store&amp;gt;/&amp;lt;docker-host&amp;gt;&amp;lt;/code&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| Tooling on the agent side&lt;br /&gt;
| &amp;lt;code&amp;gt;sshpass&amp;lt;/code&amp;gt; (&amp;lt;code&amp;gt;command -v sshpass&amp;lt;/code&amp;gt; to verify)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Step 1 — Deploy the Application ==&lt;br /&gt;
&lt;br /&gt;
The analyzer runs as a Docker Compose stack on &amp;lt;docker-host&amp;gt;:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# On &amp;lt;docker-host&amp;gt;&lt;br /&gt;
/opt/myapp/docker compose up -d&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
It exposes host port &amp;lt;code&amp;gt;&amp;lt;app-port&amp;gt;&amp;lt;/code&amp;gt; and has a one-minute cron sync that pulls &amp;lt;code&amp;gt;main&amp;lt;/code&amp;gt; and restarts the container when the repo changes.&lt;br /&gt;
&lt;br /&gt;
Verify it responds locally:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
curl http://127.0.0.1:&amp;lt;app-port&amp;gt;/api/health&lt;br /&gt;
# expected: {&amp;quot;status&amp;quot;:&amp;quot;ok&amp;quot;,&amp;quot;authenticated&amp;quot;:false}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Step 2 — Set Up the SSH Helper ==&lt;br /&gt;
&lt;br /&gt;
From the workspace, load &amp;lt;docker-host&amp;gt; credentials from BRC and define a one-line SSH wrapper:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
WORKDIR=$(git rev-parse --show-toplevel 2&amp;gt;/dev/null || pwd)&lt;br /&gt;
BRC=&amp;quot;$WORKDIR/&amp;lt;credential-store&amp;gt;/&amp;lt;docker-host&amp;gt;&amp;quot;&lt;br /&gt;
PASS=$(grep &#039;password:&#039; &amp;quot;$BRC&amp;quot; | awk &#039;{print $NF}&#039;)&lt;br /&gt;
HOST=$(grep &#039;zerotier_ip:&#039; &amp;quot;$BRC&amp;quot; | awk &#039;{print $NF}&#039;)&lt;br /&gt;
&amp;lt;docker-host&amp;gt;_USER=$(grep -m1 &#039;user:&#039; &amp;quot;$BRC&amp;quot; | awk &#039;{print $NF}&#039;)&lt;br /&gt;
&lt;br /&gt;
&amp;lt;docker-host&amp;gt;_SSH() {&lt;br /&gt;
  sshpass -p &amp;quot;$PASS&amp;quot; ssh \&lt;br /&gt;
    -o StrictHostKeyChecking=no -o UserKnownHostsFile=/dev/null \&lt;br /&gt;
    &amp;quot;$&amp;lt;docker-host&amp;gt;_USER@$HOST&amp;quot; &amp;quot;$@&amp;quot;&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
If &amp;lt;code&amp;gt;sshpass&amp;lt;/code&amp;gt; is missing, install it first (&amp;lt;code&amp;gt;apt-get install -y sshpass&amp;lt;/code&amp;gt; or equivalent). Do &#039;&#039;&#039;not&#039;&#039;&#039; treat a missing &amp;lt;code&amp;gt;sshpass&amp;lt;/code&amp;gt; as &amp;quot;no SSH access.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Step 3 — Check for Existing Hosts ==&lt;br /&gt;
&lt;br /&gt;
List any existing proxy host that uses the target domain:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
&amp;lt;docker-host&amp;gt;_SSH &amp;quot;docker exec nginx-proxy-manager-db mysql -unpm -pnpm -h127.0.0.1 npm -e \\&amp;quot;&lt;br /&gt;
  SELECT id, domain_names, forward_host, forward_port, enabled&lt;br /&gt;
  FROM proxy_host&lt;br /&gt;
  WHERE domain_names LIKE &#039;%app.example.org%&#039; AND is_deleted=0;&lt;br /&gt;
\\&amp;quot;&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
If a row exists but points to the wrong target, update it or delete it before inserting a duplicate.&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Step 4 — Back Up the &amp;lt;code&amp;gt;proxy_host&amp;lt;/code&amp;gt; Table ==&lt;br /&gt;
&lt;br /&gt;
Always backup before writing:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
&amp;lt;docker-host&amp;gt;_SSH &amp;quot;docker exec nginx-proxy-manager-db mysqldump -unpm -pnpm -h127.0.0.1 npm proxy_host&amp;quot; \&lt;br /&gt;
  &amp;gt; &amp;quot;/tmp/npm-proxy-host-backup-$(date +%Y%m%d-%H%M%S).sql&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;blockquote&amp;gt;&#039;&#039;&#039;Note:&#039;&#039;&#039; Use &amp;lt;code&amp;gt;-h127.0.0.1&amp;lt;/code&amp;gt;; the default socket connection may reject the &amp;lt;code&amp;gt;npm&amp;lt;/code&amp;gt; user.&amp;lt;/blockquote&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Step 5 — Insert the Proxy Host Row ==&lt;br /&gt;
&lt;br /&gt;
Insert an HTTP-only row (&amp;lt;code&amp;gt;certificate_id=0&amp;lt;/code&amp;gt;, &amp;lt;code&amp;gt;ssl_forced=0&amp;lt;/code&amp;gt;). SSL is requested later from the NPM UI.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
DOMAIN=&amp;quot;app.example.org&amp;quot;&lt;br /&gt;
TARGET_IP=&amp;quot;&amp;lt;npm-host-zerotier-ip&amp;gt;&amp;quot;&lt;br /&gt;
TARGET_PORT=&amp;quot;&amp;lt;app-port&amp;gt;&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;docker-host&amp;gt;_SSH &amp;quot;docker exec nginx-proxy-manager-db mysql -unpm -pnpm -h127.0.0.1 npm -e \\&amp;quot;&lt;br /&gt;
INSERT INTO proxy_host&lt;br /&gt;
  (created_on, modified_on, owner_user_id, domain_names, forward_host, forward_port,&lt;br /&gt;
   access_list_id, certificate_id, ssl_forced, caching_enabled, block_exploits,&lt;br /&gt;
   advanced_config, meta, allow_websocket_upgrade, http2_support, forward_scheme, enabled, locations,&lt;br /&gt;
   hsts_enabled, hsts_subdomains, trust_forwarded_proto)&lt;br /&gt;
VALUES&lt;br /&gt;
  (NOW(), NOW(), 1, &#039;[\\\\\&amp;quot;${DOMAIN}\\\\\&amp;quot;]&#039;, &#039;${TARGET_IP}&#039;, ${TARGET_PORT},&lt;br /&gt;
   0, 0, 0, 0, 0,&lt;br /&gt;
   &#039;&#039;,&lt;br /&gt;
   &#039;{\\\\\&amp;quot;nginx_online\\\\\&amp;quot;:true,\\\\\&amp;quot;nginx_err\\\\\&amp;quot;:null}&#039;,&lt;br /&gt;
   0, 0, &#039;http&#039;, 1, &#039;[]&#039;,&lt;br /&gt;
   0, 0, 0);&lt;br /&gt;
\\&amp;quot;&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Record the &amp;lt;code&amp;gt;id&amp;lt;/code&amp;gt; returned by the next SELECT; for this host it is &amp;lt;code&amp;gt;&amp;lt;proxy-host-id&amp;gt;&amp;lt;/code&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Step 6 — Archive Any Manual Config File ==&lt;br /&gt;
&lt;br /&gt;
If a previous workaround created a hand-edited &amp;lt;code&amp;gt;.conf&amp;lt;/code&amp;gt; file in &amp;lt;code&amp;gt;/data/compose/3/data/nginx/proxy_host/&amp;lt;/code&amp;gt;, move it out of nginx&#039;s include path so it does not conflict with the DB-generated config. The proxy_host directory is owned by root, so use a privileged throwaway container:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
&amp;lt;docker-host&amp;gt;_SSH &amp;quot;docker run --rm \&lt;br /&gt;
  -v /data/compose/3/data/nginx/proxy_host:/proxy \&lt;br /&gt;
  alpine sh -c &#039;test -f /proxy/&amp;lt;manual-config&amp;gt;.conf &amp;amp;&amp;amp; mv /proxy/&amp;lt;manual-config&amp;gt;.conf /proxy/&amp;lt;manual-config&amp;gt;.conf.manual-backup-$(date +%Y%m%d-%H%M%S) || true&#039;&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Step 7 — Restart the NPM App Container ==&lt;br /&gt;
&lt;br /&gt;
Restarting regenerates the nginx configs from the DB:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
&amp;lt;docker-host&amp;gt;_SSH &amp;quot;docker restart nginx-proxy-manager-app&amp;quot;&lt;br /&gt;
sleep 5&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Step 8 — Force Config Generation If Needed ==&lt;br /&gt;
&lt;br /&gt;
Direct DB inserts create the row, but NPM&#039;s internal config generator may not write &amp;lt;code&amp;gt;proxy_host/&amp;lt;id&amp;gt;.conf&amp;lt;/code&amp;gt; until the host is created or updated through the app. If the config file is missing, force it from inside the app container:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
HOST_ID=&amp;lt;proxy-host-id&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;docker-host&amp;gt;_SSH &amp;quot;docker exec nginx-proxy-manager-app sh -c &#039;cat &amp;gt; /tmp/regen-proxy-host.mjs &amp;lt;&amp;lt;EOF&lt;br /&gt;
import proxyHostModel from \\&amp;quot;/app/models/proxy_host.js\\&amp;quot;;&lt;br /&gt;
import internalNginx from \\&amp;quot;/app/internal/nginx.js\\&amp;quot;;&lt;br /&gt;
&lt;br /&gt;
const host = await proxyHostModel.query().where(\\&amp;quot;id\\&amp;quot;, ${HOST_ID}).first();&lt;br /&gt;
if (!host) {&lt;br /&gt;
  console.error(\\&amp;quot;proxy_host ${HOST_ID} not found\\&amp;quot;);&lt;br /&gt;
  process.exit(1);&lt;br /&gt;
}&lt;br /&gt;
await internalNginx.configure(proxyHostModel, \\&amp;quot;proxy_host\\&amp;quot;, host);&lt;br /&gt;
console.log(\\&amp;quot;Regenerated config for\\&amp;quot;, host.domain_names);&lt;br /&gt;
EOF&lt;br /&gt;
node /tmp/regen-proxy-host.mjs&#039;&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This writes the config file, tests nginx, updates the row&#039;s &amp;lt;code&amp;gt;meta&amp;lt;/code&amp;gt;, and reloads nginx.&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Step 9 — Verify ==&lt;br /&gt;
&lt;br /&gt;
Check the generated config:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
&amp;lt;docker-host&amp;gt;_SSH &amp;quot;ls -la /data/compose/3/data/nginx/proxy_host/&amp;lt;proxy-host-id&amp;gt;.conf&amp;quot;&lt;br /&gt;
&amp;lt;docker-host&amp;gt;_SSH &amp;quot;cat /data/compose/3/data/nginx/proxy_host/&amp;lt;proxy-host-id&amp;gt;.conf&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Test nginx syntax:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
&amp;lt;docker-host&amp;gt;_SSH &amp;quot;docker exec nginx-proxy-manager-app nginx -t&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Test end-to-end HTTP (from &amp;lt;docker-host&amp;gt;, because public DNS may not be live yet):&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
&amp;lt;docker-host&amp;gt;_SSH &amp;quot;curl -fsS -H &#039;Host: app.example.org&#039; http://127.0.0.1:80/api/health&amp;quot;&lt;br /&gt;
# expected: {&amp;quot;status&amp;quot;:&amp;quot;ok&amp;quot;,&amp;quot;authenticated&amp;quot;:false}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Once Cloudflare DNS points &amp;lt;code&amp;gt;app.example.org&amp;lt;/code&amp;gt; at the &amp;lt;vps-relay&amp;gt; VPS relay, &amp;lt;code&amp;gt;http://app.example.org/&amp;lt;/code&amp;gt; will work publicly.&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Step 10 — Request the SSL Certificate (Manual NPM UI Step) ==&lt;br /&gt;
&lt;br /&gt;
A DB insert cannot complete an ACME DNS-01 challenge. The final certificate step must be done in the NPM Admin UI:&lt;br /&gt;
&lt;br /&gt;
# Open &amp;lt;code&amp;gt;http://&amp;lt;npm-host-zerotier-ip&amp;gt;:81&amp;lt;/code&amp;gt; (&amp;lt;docker-host&amp;gt; ZeroTier) or your NPM admin URL.&lt;br /&gt;
# &#039;&#039;&#039;Hosts → Proxy Hosts&#039;&#039;&#039; → click &amp;lt;code&amp;gt;app.example.org&amp;lt;/code&amp;gt;.&lt;br /&gt;
# Go to the &#039;&#039;&#039;SSL&#039;&#039;&#039; tab.&lt;br /&gt;
# &#039;&#039;&#039;SSL Certificate → Request a new SSL Certificate&#039;&#039;&#039;.&lt;br /&gt;
# Enable &#039;&#039;&#039;Force SSL&#039;&#039;&#039;, &#039;&#039;&#039;HTTP/2 Support&#039;&#039;&#039;, and &#039;&#039;&#039;HSTS&#039;&#039;&#039; as desired.&lt;br /&gt;
# Agree to the Let&#039;s Encrypt ToS and request the certificate.&lt;br /&gt;
&lt;br /&gt;
After the certificate issues, NPM updates &amp;lt;code&amp;gt;proxy_host.certificate_id&amp;lt;/code&amp;gt; and &amp;lt;code&amp;gt;ssl_forced&amp;lt;/code&amp;gt; automatically and regenerates &amp;lt;code&amp;gt;&amp;lt;proxy-host-id&amp;gt;.conf&amp;lt;/code&amp;gt; with HTTPS listeners.&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Troubleshooting ==&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Symptom&lt;br /&gt;
! Cause&lt;br /&gt;
! Fix&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;Access denied for user &#039;npm&#039;@&#039;localhost&#039;&amp;lt;/code&amp;gt; during backup&lt;br /&gt;
| &amp;lt;code&amp;gt;mysqldump&amp;lt;/code&amp;gt; used socket instead of TCP&lt;br /&gt;
| Add &amp;lt;code&amp;gt;-h127.0.0.1&amp;lt;/code&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| Row exists but no &amp;lt;code&amp;gt;&amp;lt;id&amp;gt;.conf&amp;lt;/code&amp;gt; after restart&lt;br /&gt;
| Direct DB insert did not trigger config generator&lt;br /&gt;
| Run the Node force-regeneration script in Step 8&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;nginx: [emerg] duplicate server_name&amp;lt;/code&amp;gt;&lt;br /&gt;
| Old manual &amp;lt;code&amp;gt;.conf&amp;lt;/code&amp;gt; still in &amp;lt;code&amp;gt;proxy_host/&amp;lt;/code&amp;gt;&lt;br /&gt;
| Archive/remove it with a privileged container (Step 6)&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;curl&amp;lt;/code&amp;gt; returns 404 or no response&lt;br /&gt;
| DNS not pointing at NPM yet, or wrong &amp;lt;code&amp;gt;forward_host&amp;lt;/code&amp;gt; / &amp;lt;code&amp;gt;forward_port&amp;lt;/code&amp;gt;&lt;br /&gt;
| Verify DNS A record and the &amp;lt;code&amp;gt;proxy_host&amp;lt;/code&amp;gt; row&lt;br /&gt;
|-&lt;br /&gt;
| Cert request fails&lt;br /&gt;
| Let&#039;s Encrypt rate limit or Cloudflare API token missing&lt;br /&gt;
| Check NPM SSL logs; use the unpause link if rate-limited&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* Reusable NPM direct-DB skill: &amp;lt;code&amp;gt;tools/IT-knowledge/skills/npm-direct-db-modification/SKILL.md&amp;lt;/code&amp;gt;&lt;br /&gt;
* Analyzer repo: &amp;lt;code&amp;gt;&amp;lt;your-app-repo&amp;gt;&amp;lt;/code&amp;gt;&lt;br /&gt;
* NPM Proxy Map in orientation: &amp;lt;code&amp;gt;&amp;lt;orientation-doc&amp;gt;.md&amp;lt;/code&amp;gt; § Published Sites&lt;br /&gt;
* Cloudflare/VPS relay notes: &amp;lt;code&amp;gt;tools/IT-knowledge/networking/NPM_Migration_to_Homelab_VPS_Relay_260401.mw&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:Tutorial]]&lt;br /&gt;
[[Category:Nginx Proxy Manager]]&lt;br /&gt;
[[Category:Docker]]&lt;br /&gt;
[[Category:DevOps]]&lt;/div&gt;</summary>
		<author><name>Justinaquino</name></author>
	</entry>
	<entry>
		<id>https://mediawiki.comfac.net/index.php?title=Organizing_Coder_Terminals&amp;diff=259</id>
		<title>Organizing Coder Terminals</title>
		<link rel="alternate" type="text/html" href="https://mediawiki.comfac.net/index.php?title=Organizing_Coder_Terminals&amp;diff=259"/>
		<updated>2026-05-02T08:13:26Z</updated>

		<summary type="html">&lt;p&gt;Justinaquino: Added RCA: tmux send-keys broke launchers, fixed with direct exec; ce-char-gen troubleshooting&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Problem ==&lt;br /&gt;
&lt;br /&gt;
When running multiple AI coding agents (Claude, Kimi, Qwen, OpenCode) in separate GNOME Terminal windows, every tab looks identical — usually titled by the running process name (e.g., &amp;quot;Kimi Code&amp;quot;). After opening 3–4 terminals, it becomes impossible to tell at a glance which terminal belongs to which project without clicking into each one.&lt;br /&gt;
&lt;br /&gt;
GNOME Terminal 3.44+ removed the &amp;quot;Set Title&amp;quot; option from the tab right-click menu, eliminating the old manual workaround.&lt;br /&gt;
&lt;br /&gt;
== Solution ==&lt;br /&gt;
&lt;br /&gt;
Use &#039;&#039;&#039;tmux&#039;&#039;&#039; inside every terminal:&lt;br /&gt;
* One named tmux session per project (e.g., &amp;lt;code&amp;gt;claude&amp;lt;/code&amp;gt;, &amp;lt;code&amp;gt;kimi&amp;lt;/code&amp;gt;, &amp;lt;code&amp;gt;qwen&amp;lt;/code&amp;gt;)&lt;br /&gt;
* A &amp;lt;code&amp;gt;title&amp;lt;/code&amp;gt; bash command that renames both the tmux window and the terminal title&lt;br /&gt;
* Persistent panes — if an AI agent crashes, the pane stays alive and can be respawned&lt;br /&gt;
&lt;br /&gt;
== Quick Start ==&lt;br /&gt;
&lt;br /&gt;
=== Launch All Agents at Once ===&lt;br /&gt;
&lt;br /&gt;
Run on the Ubuntu desktop:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
~/start_dev_env.sh&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This opens 5 GNOME Terminal windows:&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! # !! Window Title !! Tmux Session !! Purpose&lt;br /&gt;
|-&lt;br /&gt;
| 1 || Claude Code — tmux || claude || Claude Code AI agent&lt;br /&gt;
|-&lt;br /&gt;
| 2 || OpenCode Claude — tmux || opencode-claude || OpenCode (Claude provider)&lt;br /&gt;
|-&lt;br /&gt;
| 3 || OpenCode Kimi — tmux || kimi || OpenCode (Kimi provider)&lt;br /&gt;
|-&lt;br /&gt;
| 4 || OpenCode Qwen — tmux || qwen || OpenCode (Qwen provider)&lt;br /&gt;
|-&lt;br /&gt;
| 5 || Tmux — General || general || Plain bash for git, docker, file ops&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
Each session survives even if the GNOME Terminal window is closed.&lt;br /&gt;
&lt;br /&gt;
=== Launch Individual Agents ===&lt;br /&gt;
&lt;br /&gt;
Double-click any desktop launcher:&lt;br /&gt;
* &amp;lt;code&amp;gt;~/Desktop/claude.sh&amp;lt;/code&amp;gt;&lt;br /&gt;
* &amp;lt;code&amp;gt;~/Desktop/kimi.sh&amp;lt;/code&amp;gt;&lt;br /&gt;
* &amp;lt;code&amp;gt;~/Desktop/opencode.sh&amp;lt;/code&amp;gt;&lt;br /&gt;
* &amp;lt;code&amp;gt;~/Desktop/Qwen.sh&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Each launcher auto-creates or reattaches to its tmux session.&lt;br /&gt;
&lt;br /&gt;
== How to Title Your Session ==&lt;br /&gt;
&lt;br /&gt;
=== The Default Title Is the Command Itself ===&lt;br /&gt;
&lt;br /&gt;
Every new terminal opens with the title:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
title &amp;quot;project&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This is intentional — the &#039;&#039;&#039;default title is the command reminder&#039;&#039;&#039;. You never forget the syntax because it&#039;s staring at you from the tab.&lt;br /&gt;
&lt;br /&gt;
=== Change It ===&lt;br /&gt;
&lt;br /&gt;
Inside any terminal, type:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
title &amp;quot;ce char gen&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This does two things:&lt;br /&gt;
# Renames the tmux window (visible in the green status bar at the bottom)&lt;br /&gt;
# Sets the GNOME Terminal tab/window title&lt;br /&gt;
&lt;br /&gt;
Change it anytime:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
title &amp;quot;mneme shipgen&amp;quot;&lt;br /&gt;
title &amp;quot;IT-knowledge docs&amp;quot;&lt;br /&gt;
title &amp;quot;$(hostname)&amp;quot;   # reset to hostname&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The title auto-resets after every shell prompt, so AI agents cannot overwrite it.&lt;br /&gt;
&lt;br /&gt;
=== Tmux-Only Renaming ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
tmux rename-window &amp;quot;my project&amp;quot;     # rename current window&lt;br /&gt;
tmux rename-session &amp;quot;newname&amp;quot;       # rename entire session&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Key Shortcuts ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Key !! Action&lt;br /&gt;
|-&lt;br /&gt;
| Ctrl+b , || Rename current window (interactive prompt)&lt;br /&gt;
|-&lt;br /&gt;
| Ctrl+b r || Respawn pane (restart AI agent if it crashed)&lt;br /&gt;
|-&lt;br /&gt;
| Ctrl+b d || Detach session (keeps it running in background)&lt;br /&gt;
|-&lt;br /&gt;
| Ctrl+b | || Split pane horizontally&lt;br /&gt;
|-&lt;br /&gt;
| Ctrl+b - || Split pane vertically&lt;br /&gt;
|-&lt;br /&gt;
| Alt+Arrow || Switch panes&lt;br /&gt;
|-&lt;br /&gt;
| Ctrl+b R || Reload tmux config&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Reattaching to Sessions ==&lt;br /&gt;
&lt;br /&gt;
If a terminal window is closed, the tmux session keeps running:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
tmux list-sessions&lt;br /&gt;
tmux attach-session -t claude&lt;br /&gt;
tmux attach-session -t kimi&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Aliases added to &amp;lt;code&amp;gt;~/.bashrc&amp;lt;/code&amp;gt;:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
tls     # list sessions&lt;br /&gt;
tas claude    # attach to claude session&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Configuration Files ==&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! File !! Purpose&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;~/.tmux.conf&amp;lt;/code&amp;gt; || Tmux settings (status bar, mouse, key bindings)&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;~/.bashrc&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;title()&amp;lt;/code&amp;gt; function + auto-reset + tmux aliases&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;~/.config/tmux-launcher.sh&amp;lt;/code&amp;gt; || Helper script for desktop launchers&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Troubleshooting ==&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Symptom !! Cause !! Fix&lt;br /&gt;
|-&lt;br /&gt;
| Title shows &amp;quot;Kimi Code&amp;quot; instead of custom || AI resets it via escape sequences || &amp;lt;code&amp;gt;PROMPT_COMMAND&amp;lt;/code&amp;gt; auto-resets after every prompt&lt;br /&gt;
|-&lt;br /&gt;
| Tab right-click has no &amp;quot;Set Title&amp;quot; || GNOME Terminal 3.44+ removed it || Use &amp;lt;code&amp;gt;title&amp;lt;/code&amp;gt; bash command or &amp;lt;code&amp;gt;Ctrl+b ,&amp;lt;/code&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;title&amp;lt;/code&amp;gt; command not found || &amp;lt;code&amp;gt;.bashrc&amp;lt;/code&amp;gt; not loaded || Start an interactive shell, or run &amp;lt;code&amp;gt;source ~/.bashrc&amp;lt;/code&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| Default title shows &amp;lt;code&amp;gt;title &amp;quot;project&amp;quot;&amp;lt;/code&amp;gt; || Working as designed — syntax reminder || Type &amp;lt;code&amp;gt;title &amp;quot;your real project&amp;quot;&amp;lt;/code&amp;gt; to replace it&lt;br /&gt;
|-&lt;br /&gt;
| Tmux status bar shows &amp;lt;b&amp;gt;&amp;quot;ce char gen&amp;quot;&amp;lt;/b&amp;gt; || Old &amp;lt;code&amp;gt;~/.tmux.conf&amp;lt;/code&amp;gt; on host hardcoded the title || Replace host &amp;lt;code&amp;gt;~/.tmux.conf&amp;lt;/code&amp;gt; with container&#039;s clean version&lt;br /&gt;
|-&lt;br /&gt;
| AI agent crashed and pane is dead || Process exited || Press &amp;lt;code&amp;gt;Ctrl+b r&amp;lt;/code&amp;gt; to respawn&lt;br /&gt;
|-&lt;br /&gt;
| Session already exists || Previous session still running || &amp;lt;code&amp;gt;tmux attach -t &amp;amp;lt;name&amp;amp;gt;&amp;lt;/code&amp;gt; or &amp;lt;code&amp;gt;tmux kill-session -t &amp;amp;lt;name&amp;amp;gt;&amp;lt;/code&amp;gt;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== RCA: Why Tmux Broke the Original Launch Scripts ==&lt;br /&gt;
&lt;br /&gt;
=== What Worked Before (No Tmux) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
distrobox enter agent260411 -- bash -c &#039;cd /home/justin/opencode260220 &amp;amp;&amp;amp; ./csb.sh; exec bash&#039;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&amp;lt;code&amp;gt;./csb.sh&amp;lt;/code&amp;gt; does &amp;lt;code&amp;gt;exec claude&amp;lt;/code&amp;gt;, which replaces the shell with the interactive AI agent. Claude owns the TTY and runs until the user exits.&lt;br /&gt;
&lt;br /&gt;
=== What Broke (First Tmux Attempt) ===&lt;br /&gt;
The initial &amp;lt;code&amp;gt;tmux-launcher.sh&amp;lt;/code&amp;gt; used &amp;lt;code&amp;gt;tmux send-keys&amp;lt;/code&amp;gt; to type commands into a detached session:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
tmux new-session -s &amp;quot;$SESSION&amp;quot; -n &amp;quot;$WINDOW&amp;quot; -d&lt;br /&gt;
tmux send-keys -t &amp;quot;$SESSION:$WINDOW&amp;quot; &amp;quot;./csb.sh&amp;quot; C-m&lt;br /&gt;
tmux attach-session -t &amp;quot;$SESSION&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Why This Failed ===&lt;br /&gt;
# &#039;&#039;&#039;Race condition&#039;&#039;&#039;: &amp;lt;code&amp;gt;send-keys&amp;lt;/code&amp;gt; types faster than the shell initializes. The command often arrived before bash was ready, causing &amp;quot;command not found&amp;quot; or silent failure.&lt;br /&gt;
# &#039;&#039;&#039;No TTY guarantee&#039;&#039;&#039;: Interactive apps (Claude, Kimi) need a controlling terminal. &amp;lt;code&amp;gt;send-keys&amp;lt;/code&amp;gt; provides a pane but doesn&#039;t guarantee the app receives proper TTY initialization before the keystrokes land.&lt;br /&gt;
# &#039;&#039;&#039;Exit timing&#039;&#039;&#039;: If the app started before attach, the user attached to a pane that was already dead or mid-execution.&lt;br /&gt;
&lt;br /&gt;
=== The Fix ===&lt;br /&gt;
Replace &amp;lt;code&amp;gt;send-keys&amp;lt;/code&amp;gt; with direct command execution via a wrapper script. This gives tmux the full command upfront, so it initializes the TTY properly before the app starts — exactly like the original scripts, just wrapped in tmux.&lt;br /&gt;
&lt;br /&gt;
== See Also ==&lt;br /&gt;
&lt;br /&gt;
* [[IT Knowledge Base]]&lt;br /&gt;
* [[Forgejo]]&lt;br /&gt;
* [[Docker Stacks]]&lt;br /&gt;
&lt;br /&gt;
[[Category:System Administration]]&lt;br /&gt;
[[Category:Development Environment]]&lt;br /&gt;
[[Category:AI Agents]]&lt;/div&gt;</summary>
		<author><name>Justinaquino</name></author>
	</entry>
	<entry>
		<id>https://mediawiki.comfac.net/index.php?title=Main_Page&amp;diff=258</id>
		<title>Main Page</title>
		<link rel="alternate" type="text/html" href="https://mediawiki.comfac.net/index.php?title=Main_Page&amp;diff=258"/>
		<updated>2026-05-02T07:31:02Z</updated>

		<summary type="html">&lt;p&gt;Justinaquino: Added Organizing Coder Terminals to IT index&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__NOTOC__&lt;br /&gt;
&amp;lt;div style=&amp;quot;background:#f8f9fa; border:1px solid #ddd; border-radius:4px; padding:12px 16px; margin-bottom:20px;&amp;quot;&amp;gt;&lt;br /&gt;
Welcome to the &#039;&#039;&#039;Comfac IT Knowledge Base&#039;&#039;&#039;. Use the sections below to find guides, SOPs, and references organized by topic.&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== ERPNext / Frappe ==&lt;br /&gt;
&amp;lt;div style=&amp;quot;column-count:2; column-gap:2em;&amp;quot;&amp;gt;&lt;br /&gt;
* [[Frappe HRMS]] — &#039;&#039;&#039;HR &amp;amp; Payroll&#039;&#039;&#039; (with Philippine Localization)&lt;br /&gt;
* [[Frappe ERPNext/Webshop]] — &#039;&#039;&#039;E-Commerce Webshop&#039;&#039;&#039; (setup, architecture, chapters)&lt;br /&gt;
* [[Manufacturing v16 260125]]&lt;br /&gt;
* [[ERpnext Asset Management Procedure 260113]]&lt;br /&gt;
* [[ERPNext HR Module Outline]]&lt;br /&gt;
* [[ERPNEXT Payroll POC 251212]]&lt;br /&gt;
* [[Comfac ERPNext Strategy Canvas (Expanded)]]&lt;br /&gt;
* [[PAD-Driven ERPNext Strategy 260303]] — PAD/AI-agentic implementation strategy for Frappe ERPNext&lt;br /&gt;
* [[ERPNext v15 Docker Setup Guide]] — Local Docker setup for evaluation, testing, and student use&lt;br /&gt;
* [[Frappe Links and References]]&lt;br /&gt;
* [[Using Frappe Wiki]]&lt;br /&gt;
* [https://docs.frappe.io/cloud/guidelines-for-contributing-regional-compliance-app Guidelines for Contributing Regional Compliance App]&lt;br /&gt;
* [https://docs.frappe.io/cloud/what-are-benches-and-bench-groups What are Benches?]&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== System Administration &amp;amp; Self-Hosting ==&lt;br /&gt;
&amp;lt;div style=&amp;quot;column-count:2; column-gap:2em;&amp;quot;&amp;gt;&lt;br /&gt;
* [[Networking PfSense Index]] — Consolidated index of all networking, pfSense, DNS, and infrastructure guides&lt;br /&gt;
* [[System Hardening Strategy: Win2Lin Migration &amp;amp; Infrastructure 251129]]&lt;br /&gt;
* [[Controller Systems 251213-01]]&lt;br /&gt;
* [[Power Distribution Tree 251213]]&lt;br /&gt;
* [[Introduction: Why Self-Host Your Email?]]&lt;br /&gt;
* [[Mailcow + Thunderbird Setup Guide (Email + Calendar)]]&lt;br /&gt;
* [[Mailcow SOGo: Creating Filters for Events, Approvals, and Organizational Emails]]&lt;br /&gt;
* [[Spoof Timezone Extension – Setup Guide for Comfac Staff]]&lt;br /&gt;
* [[Viber Focus-Stealing]]&lt;br /&gt;
* [[🌐 WordPress Website — *You Own Everything, Learn Everything*]]&lt;br /&gt;
* [[Portainer to Docker Compose Migration Guide]]&lt;br /&gt;
* [[Organizing Coder Terminals]] — Tmux + dynamic titles for managing multiple AI agent terminals&lt;br /&gt;
* [[Editing Mastodon Docker Deployment Guide 260402]]&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Storage &amp;amp; Hardware ==&lt;br /&gt;
&amp;lt;div style=&amp;quot;column-count:2; column-gap:2em;&amp;quot;&amp;gt;&lt;br /&gt;
* [[TrueNAS Configuration Options &amp;amp; Scale Options 251130]]&lt;br /&gt;
* [[TrueNAS Business Plan: Project 251212]]&lt;br /&gt;
* [[Comparison: TrueNAS Mini X+ vs Dell Precision 3680 Tower (2025)]]&lt;br /&gt;
* [[Backblaze Drive Stats for Server and Storage Qualification]]&lt;br /&gt;
* [[Industrial Controllers and Water Utilities 251011]]&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== AI &amp;amp; Machine Learning ==&lt;br /&gt;
&amp;lt;div style=&amp;quot;column-count:2; column-gap:2em;&amp;quot;&amp;gt;&lt;br /&gt;
* [[OpenWebUI - 251128-justin]]&lt;br /&gt;
* [[Comfac GPU Scaling and AI Research Goals]]&lt;br /&gt;
* [[🧠 Process: Selecting and Installing the Right Ollama Model for Your Hardware]]&lt;br /&gt;
* [[Ollama GNOME System Tray Panel 260401]] — GNOME system tray toggle to start/stop Ollama and reclaim VRAM&lt;br /&gt;
* [[Proceedural Agentic Development Methodology 260304]] — Methodology for systematic agent use&lt;br /&gt;
* [[Project OpenCoder: AI Independence Initiative]] — Strategic roadmap for manufacturing intelligence&lt;br /&gt;
* [[OpenCoder Qwen35 Agentic Setup 260330]] — Qwen3.5 Modelfile fix for tool calling in OpenCode; thinking mode suppression; HDD vs SSD findings&lt;br /&gt;
* [[OpenCode Multi-Provider Configuration Guide 260401]] — Dual-mode AI coding setup with Kimi cloud + Ollama local models via Distrobox&lt;br /&gt;
* [[PAD-Driven ERPNext Strategy 260303]] — Procedural Agentic Development for Frappe/ERPNext configuration and deployment&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Job Descriptions ==&lt;br /&gt;
&amp;lt;div style=&amp;quot;column-count:2; column-gap:2em;&amp;quot;&amp;gt;&lt;br /&gt;
* [[Job Descriptions]] — Index of all official job descriptions (IT, Engineering, Sales)&lt;br /&gt;
* [[JD IT Project Staff]] — IT Project Staff&lt;br /&gt;
* [[JD Security Compliance Assistant 260224]] — Security and Compliance Assistant (SCA)&lt;br /&gt;
* [[JD Engineering Designer 260108]] — Engineering Designer&lt;br /&gt;
* [[JD Engineering Supervisor 260109]] — Engineering Supervisor&lt;br /&gt;
* [[JD Technical Sales 260112]] — Technical Sales Engineer&lt;br /&gt;
* [[JD Marketing Assistant 251119]] — Marketing Assistant&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== IT Operations &amp;amp; SOPs ==&lt;br /&gt;
&amp;lt;div style=&amp;quot;column-count:2; column-gap:2em;&amp;quot;&amp;gt;&lt;br /&gt;
* [[SCA Program Plan 260320]] — Security &amp;amp; Compliance Assistant Program Plan v3 (ISO 9001/27001, PDCA, distributed audit model)&lt;br /&gt;
* [[SOP: Inter-Company Ordering and Production Process 260203]] — Ordering and production workflow between Sister Companies and the Cabuyao Plant&lt;br /&gt;
* [[Memo: Team Roles &amp;amp; Reporting Process Clarification 260320]] — Role boundaries, data ownership, and the new ERPNext-driven reporting paradigm&lt;br /&gt;
* [[Standard Operating Procedure: Distributed Minute Taking &amp;amp; Task Ownership 251208]]&lt;br /&gt;
* [[Business Continuity]]&lt;br /&gt;
* [[Procedure: CC-Blast Data Breach Prevention]]&lt;br /&gt;
* [[8D (Eight Discipline) Problem Solving Procedure]]&lt;br /&gt;
* [[Offline Malware Remediation &amp;amp; Data Recovery]]&lt;br /&gt;
* [[Troubleshooting: Access &amp;amp; Permission Issues]]&lt;br /&gt;
* [[Steps to Repair and OCR a Scanned or Corrupted PDF in Ubuntu]]&lt;br /&gt;
* [[IT IMPORTS PROCESSES]]&lt;br /&gt;
* [[IT Purchase Requests 241126]]&lt;br /&gt;
* [[IT REQUEST (OP-ERP-ITR) - EDITED 250801]]&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Sales &amp;amp; Business ==&lt;br /&gt;
&amp;lt;div style=&amp;quot;column-count:2; column-gap:2em;&amp;quot;&amp;gt;&lt;br /&gt;
* [[Comfac Sales Knowledge Base]]&lt;br /&gt;
* [[Comfac CRM – Customer Qualification &amp;amp; Conversion Process]]&lt;br /&gt;
* [[Partner Reseller Pricing 251109]]&lt;br /&gt;
* [[Biz Analysis Methodology 251109]]&lt;br /&gt;
* [[2026 MIS IT KRA KPI Biz Plan]]&lt;br /&gt;
* [[SALES INVOICE TAX OUTPUT 250829]]&lt;br /&gt;
* [[Projects in Process Report 251023]]&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Tools &amp;amp; Productivity ==&lt;br /&gt;
&amp;lt;div style=&amp;quot;column-count:2; column-gap:2em;&amp;quot;&amp;gt;&lt;br /&gt;
* [[Excel Description Filler Tool 📝]]&lt;br /&gt;
* [https://github.com/Comfac-Global-Group/comfac-studies Comfac Studies - Spaced Repetiton Active Recall]&lt;br /&gt;
* [[LibreOffice / Nextcloud Office – &amp;quot;Due Tasks&amp;quot; Conditional Formatting]]&lt;br /&gt;
* [[Google Drive and Shared Drive Training]]&lt;br /&gt;
* [[260108 CGG- GitHub Administration Guide]]&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Wiki &amp;amp; Documentation ==&lt;br /&gt;
&amp;lt;div style=&amp;quot;column-count:2; column-gap:2em;&amp;quot;&amp;gt;&lt;br /&gt;
* [[Mediawiki Setting Up Guide]]&lt;br /&gt;
* [[Contributing to Only Office 260307]]&lt;br /&gt;
* [[Mediawiki Additional Configuration]]&lt;br /&gt;
* [[Mediawiki Docker Migration Guide]]&lt;br /&gt;
* [[Home]]&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Tutorials ==&lt;br /&gt;
&amp;lt;div style=&amp;quot;column-count:2; column-gap:2em;&amp;quot;&amp;gt;&lt;br /&gt;
* [[Claude Code Isolation and Burner Workflow 260211]] — Secure AI development environment setup&lt;br /&gt;
* [[Opencode isolation and burner workflow 260216]] — OpenCode CLI isolation procedures&lt;br /&gt;
* [[LibreOffice Calc NumToWords Extension Complete Guide]] — Extension development&lt;br /&gt;
* [[ERPNext v15 Docker Setup Guide]] — ERPNext v15 local Docker setup (students, evaluators, thin-client demos)&lt;br /&gt;
* [[Erpnextv15-SSH-setup-241111]] — ERPNext v15 SSH/Portainer production setup&lt;br /&gt;
* [[Git-Mediawiki Local Editing 260223]] — Wiki editing with Git&lt;br /&gt;
* [[Understanding &amp;amp; Fixing Kernel Panics 260212]] — System debugging&lt;br /&gt;
* [[OpenCode in Android Termux 260303]] — OpenCode in Android&lt;br /&gt;
* [[OpenCoder Qwen35 Agentic Setup 260330]] — Qwen3.5 agentic setup: Modelfile, tool calling fix, storage impact&lt;br /&gt;
* [[Lora Basics 260304]] — LORA research&lt;br /&gt;
* [https://github.com/anomalyco/opencode/issues/4283#issuecomment-4083399210 Opencode Copy-paste Clipboard doesnt Work - Solution]   https://github.com/anomalyco/opencode/issues/4283#issuecomment-4083399210&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Research ==&lt;br /&gt;
&amp;lt;div style=&amp;quot;column-count:2; column-gap:2em;&amp;quot;&amp;gt;&lt;br /&gt;
* [[Ladybird Browser]] — Browser engine development&lt;br /&gt;
* [[Computing Architecture]] — System design principles&lt;br /&gt;
* [[Backblaze Drive Stats for Server and Storage Qualification 260219]] — Drive reliability analysis&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== For Users Only ==&lt;br /&gt;
* [[Private:Private Ngani]]&lt;br /&gt;
* [[Private:Private Nganipart2]]&lt;br /&gt;
&lt;br /&gt;
== CIT-OJT Project Documentations ==&lt;br /&gt;
* [[OJTDocs: For OJTs only]]&lt;br /&gt;
&lt;br /&gt;
== Need Help? ==&lt;br /&gt;
&amp;lt;div style=&amp;quot;column-count:2; column-gap:2em;&amp;quot;&amp;gt;&lt;br /&gt;
* [[Troubleshooting: Access &amp;amp; Permission Issues]]&lt;br /&gt;
* [https://www.mediawiki.org/wiki/Special:MyLanguage/Help:Contents MediaWiki User&#039;s Guide]&lt;br /&gt;
* [https://www.mediawiki.org/wiki/Special:MyLanguage/Manual:Configuration_settings Configuration settings]&lt;br /&gt;
* [https://www.mediawiki.org/wiki/Special:MyLanguage/Manual:FAQ MediaWiki FAQ]&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;/div&gt;</summary>
		<author><name>Justinaquino</name></author>
	</entry>
	<entry>
		<id>https://mediawiki.comfac.net/index.php?title=Organizing_Coder_Terminals&amp;diff=257</id>
		<title>Organizing Coder Terminals</title>
		<link rel="alternate" type="text/html" href="https://mediawiki.comfac.net/index.php?title=Organizing_Coder_Terminals&amp;diff=257"/>
		<updated>2026-05-02T07:27:04Z</updated>

		<summary type="html">&lt;p&gt;Justinaquino: Updated: default title is now the command reminder &amp;#039;title &amp;quot;project&amp;quot;&amp;#039; (2026-05-02)&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Problem ==&lt;br /&gt;
&lt;br /&gt;
When running multiple AI coding agents (Claude, Kimi, Qwen, OpenCode) in separate GNOME Terminal windows, every tab looks identical — usually titled by the running process name (e.g., &amp;quot;Kimi Code&amp;quot;). After opening 3–4 terminals, it becomes impossible to tell at a glance which terminal belongs to which project without clicking into each one.&lt;br /&gt;
&lt;br /&gt;
GNOME Terminal 3.44+ removed the &amp;quot;Set Title&amp;quot; option from the tab right-click menu, eliminating the old manual workaround.&lt;br /&gt;
&lt;br /&gt;
== Solution ==&lt;br /&gt;
&lt;br /&gt;
Use &#039;&#039;&#039;tmux&#039;&#039;&#039; inside every terminal:&lt;br /&gt;
* One named tmux session per project (e.g., &amp;lt;code&amp;gt;claude&amp;lt;/code&amp;gt;, &amp;lt;code&amp;gt;kimi&amp;lt;/code&amp;gt;, &amp;lt;code&amp;gt;qwen&amp;lt;/code&amp;gt;)&lt;br /&gt;
* A &amp;lt;code&amp;gt;title&amp;lt;/code&amp;gt; bash command that renames both the tmux window and the terminal title&lt;br /&gt;
* Persistent panes — if an AI agent crashes, the pane stays alive and can be respawned&lt;br /&gt;
&lt;br /&gt;
== Quick Start ==&lt;br /&gt;
&lt;br /&gt;
=== Launch All Agents at Once ===&lt;br /&gt;
&lt;br /&gt;
Run on the Ubuntu desktop:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
~/start_dev_env.sh&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This opens 5 GNOME Terminal windows:&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! # !! Window Title !! Tmux Session !! Purpose&lt;br /&gt;
|-&lt;br /&gt;
| 1 || Claude Code — tmux || claude || Claude Code AI agent&lt;br /&gt;
|-&lt;br /&gt;
| 2 || OpenCode Claude — tmux || opencode-claude || OpenCode (Claude provider)&lt;br /&gt;
|-&lt;br /&gt;
| 3 || OpenCode Kimi — tmux || kimi || OpenCode (Kimi provider)&lt;br /&gt;
|-&lt;br /&gt;
| 4 || OpenCode Qwen — tmux || qwen || OpenCode (Qwen provider)&lt;br /&gt;
|-&lt;br /&gt;
| 5 || Tmux — General || general || Plain bash for git, docker, file ops&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
Each session survives even if the GNOME Terminal window is closed.&lt;br /&gt;
&lt;br /&gt;
=== Launch Individual Agents ===&lt;br /&gt;
&lt;br /&gt;
Double-click any desktop launcher:&lt;br /&gt;
* &amp;lt;code&amp;gt;~/Desktop/claude.sh&amp;lt;/code&amp;gt;&lt;br /&gt;
* &amp;lt;code&amp;gt;~/Desktop/kimi.sh&amp;lt;/code&amp;gt;&lt;br /&gt;
* &amp;lt;code&amp;gt;~/Desktop/opencode.sh&amp;lt;/code&amp;gt;&lt;br /&gt;
* &amp;lt;code&amp;gt;~/Desktop/Qwen.sh&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Each launcher auto-creates or reattaches to its tmux session.&lt;br /&gt;
&lt;br /&gt;
== How to Title Your Session ==&lt;br /&gt;
&lt;br /&gt;
=== The Default Title Is the Command Itself ===&lt;br /&gt;
&lt;br /&gt;
Every new terminal opens with the title:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
title &amp;quot;project&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This is intentional — the &#039;&#039;&#039;default title is the command reminder&#039;&#039;&#039;. You never forget the syntax because it&#039;s staring at you from the tab.&lt;br /&gt;
&lt;br /&gt;
=== Change It ===&lt;br /&gt;
&lt;br /&gt;
Inside any terminal, type:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
title &amp;quot;ce char gen&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This does two things:&lt;br /&gt;
# Renames the tmux window (visible in the green status bar at the bottom)&lt;br /&gt;
# Sets the GNOME Terminal tab/window title&lt;br /&gt;
&lt;br /&gt;
Change it anytime:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
title &amp;quot;mneme shipgen&amp;quot;&lt;br /&gt;
title &amp;quot;IT-knowledge docs&amp;quot;&lt;br /&gt;
title &amp;quot;$(hostname)&amp;quot;   # reset to hostname&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The title auto-resets after every shell prompt, so AI agents cannot overwrite it.&lt;br /&gt;
&lt;br /&gt;
=== Tmux-Only Renaming ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
tmux rename-window &amp;quot;my project&amp;quot;     # rename current window&lt;br /&gt;
tmux rename-session &amp;quot;newname&amp;quot;       # rename entire session&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Key Shortcuts ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Key !! Action&lt;br /&gt;
|-&lt;br /&gt;
| Ctrl+b , || Rename current window (interactive prompt)&lt;br /&gt;
|-&lt;br /&gt;
| Ctrl+b r || Respawn pane (restart AI agent if it crashed)&lt;br /&gt;
|-&lt;br /&gt;
| Ctrl+b d || Detach session (keeps it running in background)&lt;br /&gt;
|-&lt;br /&gt;
| Ctrl+b | || Split pane horizontally&lt;br /&gt;
|-&lt;br /&gt;
| Ctrl+b - || Split pane vertically&lt;br /&gt;
|-&lt;br /&gt;
| Alt+Arrow || Switch panes&lt;br /&gt;
|-&lt;br /&gt;
| Ctrl+b R || Reload tmux config&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Reattaching to Sessions ==&lt;br /&gt;
&lt;br /&gt;
If a terminal window is closed, the tmux session keeps running:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
tmux list-sessions&lt;br /&gt;
tmux attach-session -t claude&lt;br /&gt;
tmux attach-session -t kimi&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Aliases added to &amp;lt;code&amp;gt;~/.bashrc&amp;lt;/code&amp;gt;:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
tls     # list sessions&lt;br /&gt;
tas claude    # attach to claude session&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Configuration Files ==&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! File !! Purpose&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;~/.tmux.conf&amp;lt;/code&amp;gt; || Tmux settings (status bar, mouse, key bindings)&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;~/.bashrc&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;title()&amp;lt;/code&amp;gt; function + auto-reset + tmux aliases&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;~/.config/tmux-launcher.sh&amp;lt;/code&amp;gt; || Helper script for desktop launchers&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Troubleshooting ==&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Symptom !! Cause !! Fix&lt;br /&gt;
|-&lt;br /&gt;
| Title shows &amp;quot;Kimi Code&amp;quot; instead of custom || AI resets it via escape sequences || &amp;lt;code&amp;gt;PROMPT_COMMAND&amp;lt;/code&amp;gt; auto-resets after every prompt&lt;br /&gt;
|-&lt;br /&gt;
| Tab right-click has no &amp;quot;Set Title&amp;quot; || GNOME Terminal 3.44+ removed it || Use &amp;lt;code&amp;gt;title&amp;lt;/code&amp;gt; bash command or &amp;lt;code&amp;gt;Ctrl+b ,&amp;lt;/code&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;title&amp;lt;/code&amp;gt; command not found || &amp;lt;code&amp;gt;.bashrc&amp;lt;/code&amp;gt; not loaded || Start an interactive shell, or run &amp;lt;code&amp;gt;source ~/.bashrc&amp;lt;/code&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| Default title shows &amp;lt;code&amp;gt;title &amp;quot;project&amp;quot;&amp;lt;/code&amp;gt; || Working as designed — it&#039;s the syntax reminder || Type &amp;lt;code&amp;gt;title &amp;quot;your real project&amp;quot;&amp;lt;/code&amp;gt; to replace it&lt;br /&gt;
|-&lt;br /&gt;
| AI agent crashed and pane is dead || Process exited || Press &amp;lt;code&amp;gt;Ctrl+b r&amp;lt;/code&amp;gt; to respawn&lt;br /&gt;
|-&lt;br /&gt;
| Session already exists || Previous session still running || &amp;lt;code&amp;gt;tmux attach -t &amp;amp;lt;name&amp;amp;gt;&amp;lt;/code&amp;gt; or &amp;lt;code&amp;gt;tmux kill-session -t &amp;amp;lt;name&amp;amp;gt;&amp;lt;/code&amp;gt;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== See Also ==&lt;br /&gt;
&lt;br /&gt;
* [[IT Knowledge Base]]&lt;br /&gt;
* [[Forgejo]]&lt;br /&gt;
* [[Docker Stacks]]&lt;br /&gt;
&lt;br /&gt;
[[Category:System Administration]]&lt;br /&gt;
[[Category:Development Environment]]&lt;br /&gt;
[[Category:AI Agents]]&lt;/div&gt;</summary>
		<author><name>Justinaquino</name></author>
	</entry>
	<entry>
		<id>https://mediawiki.comfac.net/index.php?title=Organizing_Coder_Terminals&amp;diff=256</id>
		<title>Organizing Coder Terminals</title>
		<link rel="alternate" type="text/html" href="https://mediawiki.comfac.net/index.php?title=Organizing_Coder_Terminals&amp;diff=256"/>
		<updated>2026-05-02T07:09:30Z</updated>

		<summary type="html">&lt;p&gt;Justinaquino: Created article on organizing coder terminals with tmux (2026-05-02)&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Problem ==&lt;br /&gt;
&lt;br /&gt;
When running multiple AI coding agents (Claude, Kimi, Qwen, OpenCode) in separate GNOME Terminal windows, every tab looks identical — usually titled by the running process name (e.g., &amp;quot;Kimi Code&amp;quot;). After opening 3–4 terminals, it becomes impossible to tell at a glance which terminal belongs to which project without clicking into each one.&lt;br /&gt;
&lt;br /&gt;
GNOME Terminal 3.44+ removed the &amp;quot;Set Title&amp;quot; option from the tab right-click menu, eliminating the old manual workaround.&lt;br /&gt;
&lt;br /&gt;
== Solution ==&lt;br /&gt;
&lt;br /&gt;
Use &#039;&#039;&#039;tmux&#039;&#039;&#039; inside every terminal:&lt;br /&gt;
* One named tmux session per project (e.g., &amp;lt;code&amp;gt;claude&amp;lt;/code&amp;gt;, &amp;lt;code&amp;gt;kimi&amp;lt;/code&amp;gt;, &amp;lt;code&amp;gt;qwen&amp;lt;/code&amp;gt;)&lt;br /&gt;
* A &amp;lt;code&amp;gt;title&amp;lt;/code&amp;gt; bash command that renames both the tmux window and the terminal title&lt;br /&gt;
* Persistent panes — if an AI agent crashes, the pane stays alive and can be respawned&lt;br /&gt;
&lt;br /&gt;
== Quick Start ==&lt;br /&gt;
&lt;br /&gt;
=== Launch All Agents at Once ===&lt;br /&gt;
&lt;br /&gt;
Run on the Ubuntu desktop:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
~/start_dev_env.sh&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This opens 5 GNOME Terminal windows:&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! # !! Window Title !! Tmux Session !! Purpose&lt;br /&gt;
|-&lt;br /&gt;
| 1 || Claude Code — tmux || claude || Claude Code AI agent&lt;br /&gt;
|-&lt;br /&gt;
| 2 || OpenCode Claude — tmux || opencode-claude || OpenCode (Claude provider)&lt;br /&gt;
|-&lt;br /&gt;
| 3 || OpenCode Kimi — tmux || kimi || OpenCode (Kimi provider)&lt;br /&gt;
|-&lt;br /&gt;
| 4 || OpenCode Qwen — tmux || qwen || OpenCode (Qwen provider)&lt;br /&gt;
|-&lt;br /&gt;
| 5 || Tmux — General || general || Plain bash for git, docker, file ops&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
Each session survives even if the GNOME Terminal window is closed.&lt;br /&gt;
&lt;br /&gt;
=== Launch Individual Agents ===&lt;br /&gt;
&lt;br /&gt;
Double-click any desktop launcher:&lt;br /&gt;
* &amp;lt;code&amp;gt;~/Desktop/claude.sh&amp;lt;/code&amp;gt;&lt;br /&gt;
* &amp;lt;code&amp;gt;~/Desktop/kimi.sh&amp;lt;/code&amp;gt;&lt;br /&gt;
* &amp;lt;code&amp;gt;~/Desktop/opencode.sh&amp;lt;/code&amp;gt;&lt;br /&gt;
* &amp;lt;code&amp;gt;~/Desktop/Qwen.sh&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Each launcher auto-creates or reattaches to its tmux session.&lt;br /&gt;
&lt;br /&gt;
== How to Title Your Session ==&lt;br /&gt;
&lt;br /&gt;
Inside any terminal, type:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
title &amp;quot;ce char gen&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This does two things:&lt;br /&gt;
# Renames the tmux window (visible in the green status bar at the bottom)&lt;br /&gt;
# Sets the GNOME Terminal tab/window title&lt;br /&gt;
&lt;br /&gt;
Change it anytime:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
title &amp;quot;mneme shipgen&amp;quot;&lt;br /&gt;
title &amp;quot;IT-knowledge docs&amp;quot;&lt;br /&gt;
title &amp;quot;$(hostname)&amp;quot;   # reset to hostname&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The title auto-resets after every shell prompt, so AI agents cannot overwrite it.&lt;br /&gt;
&lt;br /&gt;
=== Tmux-Only Renaming ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
tmux rename-window &amp;quot;my project&amp;quot;     # rename current window&lt;br /&gt;
tmux rename-session &amp;quot;newname&amp;quot;       # rename entire session&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Key Shortcuts ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Key !! Action&lt;br /&gt;
|-&lt;br /&gt;
| Ctrl+b , || Rename current window (interactive prompt)&lt;br /&gt;
|-&lt;br /&gt;
| Ctrl+b r || Respawn pane (restart AI agent if it crashed)&lt;br /&gt;
|-&lt;br /&gt;
| Ctrl+b d || Detach session (keeps it running in background)&lt;br /&gt;
|-&lt;br /&gt;
| Ctrl+b | || Split pane horizontally&lt;br /&gt;
|-&lt;br /&gt;
| Ctrl+b - || Split pane vertically&lt;br /&gt;
|-&lt;br /&gt;
| Alt+Arrow || Switch panes&lt;br /&gt;
|-&lt;br /&gt;
| Ctrl+b R || Reload tmux config&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Reattaching to Sessions ==&lt;br /&gt;
&lt;br /&gt;
If a terminal window is closed, the tmux session keeps running:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
tmux list-sessions&lt;br /&gt;
tmux attach-session -t claude&lt;br /&gt;
tmux attach-session -t kimi&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Aliases added to &amp;lt;code&amp;gt;~/.bashrc&amp;lt;/code&amp;gt;:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
tls     # list sessions&lt;br /&gt;
tas claude    # attach to claude session&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Configuration Files ==&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! File !! Purpose&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;~/.tmux.conf&amp;lt;/code&amp;gt; || Tmux settings (status bar, mouse, key bindings)&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;~/.bashrc&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;title()&amp;lt;/code&amp;gt; function + auto-reset + tmux aliases&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;~/.config/tmux-launcher.sh&amp;lt;/code&amp;gt; || Helper script for desktop launchers&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Troubleshooting ==&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Symptom !! Cause !! Fix&lt;br /&gt;
|-&lt;br /&gt;
| Title shows &amp;quot;Kimi Code&amp;quot; instead of custom || AI resets it via escape sequences || &amp;lt;code&amp;gt;PROMPT_COMMAND&amp;lt;/code&amp;gt; auto-resets after every prompt&lt;br /&gt;
|-&lt;br /&gt;
| Tab right-click has no &amp;quot;Set Title&amp;quot; || GNOME Terminal 3.44+ removed it || Use &amp;lt;code&amp;gt;title&amp;lt;/code&amp;gt; bash command or &amp;lt;code&amp;gt;Ctrl+b ,&amp;lt;/code&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| AI agent crashed and pane is dead || Process exited || Press &amp;lt;code&amp;gt;Ctrl+b r&amp;lt;/code&amp;gt; to respawn&lt;br /&gt;
|-&lt;br /&gt;
| Session already exists || Previous session still running || &amp;lt;code&amp;gt;tmux attach -t &amp;amp;lt;name&amp;amp;gt;&amp;lt;/code&amp;gt; or &amp;lt;code&amp;gt;tmux kill-session -t &amp;amp;lt;name&amp;amp;gt;&amp;lt;/code&amp;gt;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== See Also ==&lt;br /&gt;
&lt;br /&gt;
* [[IT Knowledge Base]]&lt;br /&gt;
* [[Forgejo]]&lt;br /&gt;
* [[Docker Stacks]]&lt;br /&gt;
&lt;br /&gt;
[[Category:System Administration]]&lt;br /&gt;
[[Category:Development Environment]]&lt;br /&gt;
[[Category:AI Agents]]&lt;/div&gt;</summary>
		<author><name>Justinaquino</name></author>
	</entry>
	<entry>
		<id>https://mediawiki.comfac.net/index.php?title=Forgejo_Pages&amp;diff=255</id>
		<title>Forgejo Pages</title>
		<link rel="alternate" type="text/html" href="https://mediawiki.comfac.net/index.php?title=Forgejo_Pages&amp;diff=255"/>
		<updated>2026-04-28T13:24:36Z</updated>

		<summary type="html">&lt;p&gt;Justinaquino: Added Forgejo Pages setup guide&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Forgejo Pages — Complete Setup Guide =&lt;br /&gt;
&lt;br /&gt;
&amp;lt;blockquote&amp;gt;**Wiki:** wiki.gi7b.org | **Last updated:** 2026-04-28&amp;lt;/blockquote&amp;gt;&lt;br /&gt;
&amp;lt;blockquote&amp;gt;**Status:** Production — `pages.gi7b.org` live on PC03&amp;lt;/blockquote&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Overview ==&lt;br /&gt;
&lt;br /&gt;
Forgejo does &#039;&#039;&#039;not&#039;&#039;&#039; have a built-in static site server. To serve Pages, you run a&lt;br /&gt;
separate &amp;lt;code&amp;gt;ronmi/forgejo-pages&amp;lt;/code&amp;gt; container alongside Forgejo. It reads files from a&lt;br /&gt;
special branch in each repo via the Forgejo API and serves them over HTTP.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight&amp;gt;&lt;br /&gt;
Browser → Cloudflare DNS → NPM (SSL) → forgejo-pages:8080 → Forgejo API → repo branch&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* **Forgejo:** `https://git.gi7b.org` (container: `forgejo`, internal port 3000)&lt;br /&gt;
* **Pages server:** `https://pages.gi7b.org` (container: `forgejo-pages`, internal port 8080)&lt;br /&gt;
* **Routing:** path-based — `https://pages.gi7b.org/{owner}/{repo}/`&lt;br /&gt;
* **Branch name:** `static-pages` (exact, hardcoded default in this image)&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Gotchas — Read This First ==&lt;br /&gt;
&lt;br /&gt;
=== 1. There is no built-in Pages in Forgejo ===&lt;br /&gt;
&amp;lt;code&amp;gt;ENABLE_FORGEJO_PAGES = true&amp;lt;/code&amp;gt; in &amp;lt;code&amp;gt;app.ini&amp;lt;/code&amp;gt; does nothing. It is not a real setting.&lt;br /&gt;
You need the external &amp;lt;code&amp;gt;ronmi/forgejo-pages&amp;lt;/code&amp;gt; container.&lt;br /&gt;
&lt;br /&gt;
=== 2. Branch must be named exactly `static-pages` ===&lt;br /&gt;
Not &amp;lt;code&amp;gt;gh-pages&amp;lt;/code&amp;gt;, not &amp;lt;code&amp;gt;pages&amp;lt;/code&amp;gt;, not &amp;lt;code&amp;gt;static_pages&amp;lt;/code&amp;gt;. The image default is &amp;lt;code&amp;gt;static-pages&amp;lt;/code&amp;gt;.&lt;br /&gt;
If the branch doesn&#039;t exist in the repo, the server returns 404.&lt;br /&gt;
&lt;br /&gt;
=== 3. Use two separate tokens ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Token !! Scope !! Used by&lt;br /&gt;
|-&lt;br /&gt;
| `forgejo-pages` service token | `repository: read` | Docker container reads repo files via API&lt;br /&gt;
|-&lt;br /&gt;
| `git-push` personal token | `repository: read+write` + `user: read` | You/AI push code via git CLI&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
Never use your account password for git CLI over HTTPS — it will be rejected.&lt;br /&gt;
&lt;br /&gt;
=== 4. NPM forward port is the internal container port ===&lt;br /&gt;
When NPM uses the container DNS name (&amp;lt;code&amp;gt;forgejo-pages&amp;lt;/code&amp;gt;), forward to port &amp;lt;code&amp;gt;8080&amp;lt;/code&amp;gt; (internal).&lt;br /&gt;
If using the host IP (&amp;lt;code&amp;gt;192.168.196.76&amp;lt;/code&amp;gt;), forward to port &amp;lt;code&amp;gt;8585&amp;lt;/code&amp;gt; (exposed host port).&lt;br /&gt;
Mixing these up causes 502 Bad Gateway.&lt;br /&gt;
&lt;br /&gt;
=== 5. Remove NPM Access List from git.gi7b.org ===&lt;br /&gt;
HTTP Basic Auth at the NPM layer blocks git CLI, API calls, and webhooks.&lt;br /&gt;
Forgejo&#039;s own auth (tokens, SSH keys, 2FA) is the correct security layer for a git host.&lt;br /&gt;
&lt;br /&gt;
=== 6. SSH is more reliable than HTTPS for git push ===&lt;br /&gt;
HTTPS git auth has multiple failure modes (token scopes, credential helpers, NPM layers).&lt;br /&gt;
SSH just works. Set it up once per machine and never deal with tokens for pushing again.&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Docker Compose Setup ==&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;File:&#039;&#039;&#039; &amp;lt;code&amp;gt;/home/user/forgejo/compose.yml&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;yaml&amp;quot;&amp;gt;&lt;br /&gt;
services:&lt;br /&gt;
  server:&lt;br /&gt;
    image: codeberg.org/forgejo/forgejo:13&lt;br /&gt;
    container_name: forgejo&lt;br /&gt;
    restart: unless-stopped&lt;br /&gt;
    environment:&lt;br /&gt;
      - USER_UID=1000&lt;br /&gt;
      - USER_GID=1000&lt;br /&gt;
    volumes:&lt;br /&gt;
      - ./data:/data&lt;br /&gt;
      - /etc/localtime:/etc/localtime:ro&lt;br /&gt;
    ports:&lt;br /&gt;
      - &amp;quot;3001:3000&amp;quot;&lt;br /&gt;
      - &amp;quot;223:22&amp;quot;&lt;br /&gt;
    networks:&lt;br /&gt;
      - internal&lt;br /&gt;
      - proxy&lt;br /&gt;
&lt;br /&gt;
  pages:&lt;br /&gt;
    image: ronmi/forgejo-pages&lt;br /&gt;
    container_name: forgejo-pages&lt;br /&gt;
    restart: unless-stopped&lt;br /&gt;
    command: serve --server http://forgejo:3000 --token ${FORGEJO_PAGES_TOKEN} --bind :8080&lt;br /&gt;
    ports:&lt;br /&gt;
      - &amp;quot;8585:8080&amp;quot;&lt;br /&gt;
    networks:&lt;br /&gt;
      - internal&lt;br /&gt;
      - proxy&lt;br /&gt;
    depends_on:&lt;br /&gt;
      - server&lt;br /&gt;
&lt;br /&gt;
networks:&lt;br /&gt;
  internal:&lt;br /&gt;
    driver: bridge&lt;br /&gt;
  proxy:&lt;br /&gt;
    external: true&lt;br /&gt;
    name: npm_proxy&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;File:&#039;&#039;&#039; &amp;lt;code&amp;gt;/home/user/forgejo/.env&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight&amp;gt;&lt;br /&gt;
FORGEJO_PAGES_TOKEN=your_read_only_repository_token_here&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Tokens ==&lt;br /&gt;
&lt;br /&gt;
=== Service Token (for forgejo-pages container) ===&lt;br /&gt;
Generated in Forgejo → Settings → Applications:&lt;br /&gt;
* **Name:** `forgejo-pages-service`&lt;br /&gt;
* **Repository and Organization Access:** All&lt;br /&gt;
* **Permissions:** `repository: Read` only, everything else No access&lt;br /&gt;
* Goes in `/home/user/forgejo/.env` as `FORGEJO_PAGES_TOKEN`&lt;br /&gt;
&lt;br /&gt;
=== Personal Push Token (for git CLI / AI agents) ===&lt;br /&gt;
Generated in Forgejo → Settings → Applications:&lt;br /&gt;
* **Name:** `git-push-{machinename}`&lt;br /&gt;
* **Repository and Organization Access:** All&lt;br /&gt;
* **Permissions:** `repository: Read and Write`, `user: Read`, everything else No access&lt;br /&gt;
* Used as the **password** when git prompts, or embedded in SSH-less workflows&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== NPM Proxy Host — pages.gi7b.org ==&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Details tab:&#039;&#039;&#039;&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Field !! Value&lt;br /&gt;
|-&lt;br /&gt;
| Domain Names | `pages.gi7b.org`&lt;br /&gt;
|-&lt;br /&gt;
| Scheme | `http`&lt;br /&gt;
|-&lt;br /&gt;
| Forward Hostname / IP | `forgejo-pages` (container name) OR `192.168.196.76` (host IP)&lt;br /&gt;
|-&lt;br /&gt;
| Forward Port | `8080` if using container name / `8585` if using host IP&lt;br /&gt;
|-&lt;br /&gt;
| Cache Assets | ✅ On&lt;br /&gt;
|-&lt;br /&gt;
| Block Common Exploits | ✅ On&lt;br /&gt;
|-&lt;br /&gt;
| Websockets Support | Off&lt;br /&gt;
|-&lt;br /&gt;
| Access List | **Publicly Accessible** (no HTTP Basic Auth)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;SSL tab:&#039;&#039;&#039;&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Field !! Value&lt;br /&gt;
|-&lt;br /&gt;
| SSL Certificate | `pages.gi7b.org` (Let&#039;s Encrypt)&lt;br /&gt;
|-&lt;br /&gt;
| Force SSL | ✅ On&lt;br /&gt;
|-&lt;br /&gt;
| HTTP/2 Support | ✅ On&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== SSH Setup for Git Push (per machine) ==&lt;br /&gt;
&lt;br /&gt;
Run once on each machine that needs to push to Forgejo:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
# Generate key&lt;br /&gt;
ssh-keygen -t ed25519 -C &amp;quot;{machinename}-git&amp;quot; -f ~/.ssh/id_ed25519 -N &amp;quot;&amp;quot;&lt;br /&gt;
&lt;br /&gt;
# Show public key to add to Forgejo&lt;br /&gt;
cat ~/.ssh/id_ed25519.pub&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Add the public key in Forgejo → Settings → SSH / GPG Keys → Add Key.&lt;br /&gt;
&lt;br /&gt;
Set remote URL to SSH (note custom port 223):&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
git remote set-url origin ssh://git@192.168.196.76:223/{owner}/{repo}.git&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;blockquote&amp;gt;Use the ZeroTier IP `192.168.196.76` directly — port 223 is not forwarded through&amp;lt;/blockquote&amp;gt;&lt;br /&gt;
&amp;lt;blockquote&amp;gt;the public relay (PC06). SSH over ZeroTier is reliable for internal machines.&amp;lt;/blockquote&amp;gt;&lt;br /&gt;
&amp;lt;blockquote&amp;gt;For external machines, either forward port 223 through PC06 or use HTTPS with a token.&amp;lt;/blockquote&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Publishing a Page (Repeatable Workflow) ==&lt;br /&gt;
&lt;br /&gt;
=== New repo — first time ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
git clone ssh://git@192.168.196.76:223/{owner}/{repo}.git&lt;br /&gt;
cd {repo}&lt;br /&gt;
&lt;br /&gt;
# Create orphan branch (no shared history with main)&lt;br /&gt;
git checkout --orphan static-pages&lt;br /&gt;
git rm -rf . 2&amp;gt;/dev/null || true&lt;br /&gt;
&lt;br /&gt;
# Create your site&lt;br /&gt;
mkdir -p .&lt;br /&gt;
cat &amp;gt; index.html &amp;lt;&amp;lt;&#039;EOF&#039;&lt;br /&gt;
&amp;lt;!DOCTYPE html&amp;gt;&lt;br /&gt;
&amp;lt;html lang=&amp;quot;en&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;head&amp;gt;&amp;lt;meta charset=&amp;quot;UTF-8&amp;quot;&amp;gt;&amp;lt;title&amp;gt;My Page&amp;lt;/title&amp;gt;&amp;lt;/head&amp;gt;&lt;br /&gt;
&amp;lt;body&amp;gt;&lt;br /&gt;
  &amp;lt;h1&amp;gt;Hello from Forgejo Pages&amp;lt;/h1&amp;gt;&lt;br /&gt;
&amp;lt;/body&amp;gt;&lt;br /&gt;
&amp;lt;/html&amp;gt;&lt;br /&gt;
EOF&lt;br /&gt;
&lt;br /&gt;
git add .&lt;br /&gt;
git commit -m &amp;quot;Initial pages content&amp;quot;&lt;br /&gt;
git push -u origin static-pages&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Live immediately at: &amp;lt;code&amp;gt;https://pages.gi7b.org/{owner}/{repo}/&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Update existing pages ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
git checkout static-pages&lt;br /&gt;
# edit files&lt;br /&gt;
git add .&lt;br /&gt;
git commit -m &amp;quot;Update pages&amp;quot;&lt;br /&gt;
git push&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Via Forgejo Web UI (no git needed) ===&lt;br /&gt;
&lt;br /&gt;
1. Open repo → click &#039;&#039;&#039;New File&#039;&#039;&#039;&lt;br /&gt;
2. Filename: &amp;lt;code&amp;gt;index.html&amp;lt;/code&amp;gt;, add content&lt;br /&gt;
3. In commit section: select &#039;&#039;&#039;&amp;quot;Create a new branch&amp;quot;&#039;&#039;&#039;&lt;br /&gt;
4. Branch name: &amp;lt;code&amp;gt;static-pages&amp;lt;/code&amp;gt;&lt;br /&gt;
5. Commit&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Verification ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
# Local test (on PC03)&lt;br /&gt;
curl -i http://localhost:8585/{owner}/{repo}/&lt;br /&gt;
&lt;br /&gt;
# Expected: HTTP/1.1 200 OK + your HTML&lt;br /&gt;
&lt;br /&gt;
# Check pages server logs&lt;br /&gt;
docker logs forgejo-pages --tail 20&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Browser: &amp;lt;code&amp;gt;https://pages.gi7b.org/{owner}/{repo}/&amp;lt;/code&amp;gt; (trailing slash matters)&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Troubleshooting ==&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Symptom !! Cause !! Fix&lt;br /&gt;
|-&lt;br /&gt;
| 400 Bad Request | No valid owner/repo path in URL | URL must be `/{owner}/{repo}/`&lt;br /&gt;
|-&lt;br /&gt;
| 404 Not Found | `static-pages` branch missing or no `index.html` at root | Create branch, push `index.html` to root&lt;br /&gt;
|-&lt;br /&gt;
| 502 Bad Gateway | NPM port mismatch or container not on `npm_proxy` network | Check forward port (8080 internal / 8585 host). Verify: `docker network inspect npm_proxy \ | grep forgejo`&lt;br /&gt;
|-&lt;br /&gt;
| Auth failed (git push) | Wrong token scope or using account password | Use personal push token with `repository: write`. Use SSH instead.&lt;br /&gt;
|-&lt;br /&gt;
| SSH connection refused | Port 223 not reachable from external machine | Use ZeroTier IP for internal machines. Forward port via PC06 for external.&lt;br /&gt;
|-&lt;br /&gt;
| Pages container crash-looping | Missing `serve` command or bad token | Check `docker logs forgejo-pages`. Verify `.env` token is correct.&lt;br /&gt;
|-&lt;br /&gt;
| Stale content | Browser cache | Hard refresh (Ctrl+Shift+R) or test with `curl`&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Justinaquino</name></author>
	</entry>
	<entry>
		<id>https://mediawiki.comfac.net/index.php?title=Buzz_Transcription&amp;diff=254</id>
		<title>Buzz Transcription</title>
		<link rel="alternate" type="text/html" href="https://mediawiki.comfac.net/index.php?title=Buzz_Transcription&amp;diff=254"/>
		<updated>2026-04-24T18:43:50Z</updated>

		<summary type="html">&lt;p&gt;Justinaquino: Add Buzz meeting transcription guide + Vulkan GPU &amp;amp; OOM investigation (2026-04-25)&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Buzz is an open-source, offline-capable audio/meeting transcription tool powered by OpenAI Whisper (via whisper.cpp). On this system it is installed as a Flatpak and runs with Vulkan GPU acceleration on the AMD RX 7600.&lt;br /&gt;
&lt;br /&gt;
== How to Transcribe a Meeting ==&lt;br /&gt;
&lt;br /&gt;
=== Prerequisites ===&lt;br /&gt;
* Buzz installed (Flatpak: &amp;lt;code&amp;gt;io.github.chidiwilliams.Buzz&amp;lt;/code&amp;gt;)&lt;br /&gt;
* A model downloaded — recommended: &amp;lt;code&amp;gt;ggml-large-v3-turbo&amp;lt;/code&amp;gt; for quality, &amp;lt;code&amp;gt;ggml-tiny&amp;lt;/code&amp;gt; for speed&lt;br /&gt;
* Models are stored at &amp;lt;code&amp;gt;~/.var/app/io.github.chidiwilliams.Buzz/cache/Buzz/models/&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== File Transcription (Meeting Recording) ===&lt;br /&gt;
# Launch Buzz from the application menu or run: &amp;lt;code&amp;gt;flatpak run io.github.chidiwilliams.Buzz&amp;lt;/code&amp;gt;&lt;br /&gt;
# Go to &#039;&#039;&#039;File → Import Media&#039;&#039;&#039; and select your meeting recording (MP3, WAV, M4A, etc.)&lt;br /&gt;
# In the transcription dialog:&lt;br /&gt;
#* &#039;&#039;&#039;Model&#039;&#039;&#039;: Select &amp;lt;code&amp;gt;large-v3-turbo&amp;lt;/code&amp;gt; (best quality for meetings)&lt;br /&gt;
#* &#039;&#039;&#039;Task&#039;&#039;&#039;: Transcribe&lt;br /&gt;
#* &#039;&#039;&#039;Language&#039;&#039;&#039;: Select your language or leave on Auto&lt;br /&gt;
#* &#039;&#039;&#039;Extract Speech&#039;&#039;&#039;: &#039;&#039;&#039;Leave unchecked&#039;&#039;&#039; for files longer than ~30 minutes (see [[#OOM Crash with Large Files|OOM Crash]] below)&lt;br /&gt;
#* &#039;&#039;&#039;Output&#039;&#039;&#039;: SRT, VTT, or TXT depending on your need&lt;br /&gt;
# Click &#039;&#039;&#039;Transcribe&#039;&#039;&#039;&lt;br /&gt;
# When complete, the transcript appears in the main window and is saved alongside the source file&lt;br /&gt;
&lt;br /&gt;
=== Live Transcription (Real-Time) ===&lt;br /&gt;
# Go to &#039;&#039;&#039;File → Record and Transcribe&#039;&#039;&#039;&lt;br /&gt;
# Select your microphone input&lt;br /&gt;
# Choose model and language&lt;br /&gt;
# Click &#039;&#039;&#039;Record&#039;&#039;&#039; — transcription appears live on screen&lt;br /&gt;
# Stop recording when done; export via &#039;&#039;&#039;File → Export&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
=== Recommended Settings for Meetings ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Setting !! Value !! Reason&lt;br /&gt;
|-&lt;br /&gt;
| Model || large-v3-turbo || Best accuracy; 1.6 GB VRAM, runs on RX 7600&lt;br /&gt;
|-&lt;br /&gt;
| Extract Speech || &#039;&#039;&#039;Off&#039;&#039;&#039; for files &amp;amp;gt;30 min || Demucs uses 8–15 GB RAM for long files (OOM risk)&lt;br /&gt;
|-&lt;br /&gt;
| Language || Set explicitly || Faster than auto-detect&lt;br /&gt;
|-&lt;br /&gt;
| Task || Transcribe || Use Translate only if you need English output from another language&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Before Each Session: Clear Swap ===&lt;br /&gt;
Prior transcription sessions can leave stale pages in swap. Run this before starting a long transcription:&lt;br /&gt;
&amp;lt;pre&amp;gt;sudo swapoff -a &amp;amp;&amp;amp; sudo swapon -a&amp;lt;/pre&amp;gt;&lt;br /&gt;
This is safe when free RAM exceeds swap used (typical on this system: 15+ GB free, 8 GB swap).&lt;br /&gt;
&lt;br /&gt;
== GPU Acceleration ==&lt;br /&gt;
&lt;br /&gt;
Buzz&#039;s Flatpak installation includes a Vulkan-enabled &amp;lt;code&amp;gt;whisper-cli&amp;lt;/code&amp;gt;. On this system, GPU inference is automatically active — no configuration needed.&lt;br /&gt;
&lt;br /&gt;
* GPU in use: &#039;&#039;&#039;AMD RX 7600 (RDNA3, RADV NAVI33)&#039;&#039;&#039;&lt;br /&gt;
* Confirmed by: &amp;lt;code&amp;gt;whisper_backend_init_gpu: using Vulkan0 backend&amp;lt;/code&amp;gt; in runtime output&lt;br /&gt;
* Buzz checks for Vulkan at startup (&amp;lt;code&amp;gt;IS_VULKAN_SUPPORTED&amp;lt;/code&amp;gt;) and omits the &amp;lt;code&amp;gt;--no-gpu&amp;lt;/code&amp;gt; flag when found&lt;br /&gt;
&lt;br /&gt;
To force CPU inference (for debugging):&lt;br /&gt;
&amp;lt;pre&amp;gt;flatpak override --user io.github.chidiwilliams.Buzz --env=BUZZ_FORCE_CPU=true&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
To revert:&lt;br /&gt;
&amp;lt;pre&amp;gt;flatpak override --user --reset io.github.chidiwilliams.Buzz&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== OOM Crash with Large Files ==&lt;br /&gt;
&lt;br /&gt;
=== Symptom ===&lt;br /&gt;
When selecting &amp;lt;code&amp;gt;ggml-large-v3-turbo&amp;lt;/code&amp;gt; in Buzz and starting a transcription on a long file, the application crashes. VRAM usage never visibly climbs before the crash.&lt;br /&gt;
&lt;br /&gt;
=== Root Cause ===&lt;br /&gt;
The crash is caused by the &#039;&#039;&#039;Extract Speech (Demucs)&#039;&#039;&#039; pre-processing step, not the large model.&lt;br /&gt;
&lt;br /&gt;
Demucs is a PyTorch-based music source separation model that strips background noise from audio before passing it to the transcription engine. It processes raw PCM audio at full float32 precision entirely in RAM:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Audio Duration !! Compressed Size !! RAM Required (Demucs)&lt;br /&gt;
|-&lt;br /&gt;
| 1 hour MP3 || ~60 MB || 500 MB – 1 GB&lt;br /&gt;
|-&lt;br /&gt;
| 3–4 hour session || ~220 MB || 8–15 GB peak&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
The combination that caused the crash:&lt;br /&gt;
# Swap already exhausted from previous sessions&lt;br /&gt;
# Extract Speech (Demucs) triggered on a ~220 MB MP3 (~3–4 hours of audio)&lt;br /&gt;
# Python RAM usage exceeded available RAM + swap ceiling&lt;br /&gt;
# OOM killer terminated the process at 22 GB RSS&lt;br /&gt;
# &amp;lt;code&amp;gt;whisper-cli&amp;lt;/code&amp;gt; was never launched → no VRAM activity observed&lt;br /&gt;
&lt;br /&gt;
=== Why VRAM Never Climbed ===&lt;br /&gt;
&amp;lt;code&amp;gt;whisper-cli&amp;lt;/code&amp;gt; runs as a subprocess of the Python GUI. The OOM kill happened during Demucs pre-processing — &amp;lt;code&amp;gt;whisper-cli&amp;lt;/code&amp;gt; was never started, so no VRAM allocation occurred.&lt;br /&gt;
&lt;br /&gt;
From the Buzz log at crash time:&lt;br /&gt;
&amp;lt;pre&amp;gt;~/.var/app/io.github.chidiwilliams.Buzz/.local/state/Buzz/log/logs.txt&amp;lt;/pre&amp;gt;&lt;br /&gt;
The last entry was &amp;lt;code&amp;gt;Will extract speech&amp;lt;/code&amp;gt; — the log never reached &amp;lt;code&amp;gt;Starting whisper file transcription&amp;lt;/code&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
=== Fix ===&lt;br /&gt;
&#039;&#039;&#039;Uncheck &amp;quot;Extract Speech&amp;quot;&#039;&#039;&#039; in the Buzz transcription dialog for any file longer than ~30 minutes. The &amp;lt;code&amp;gt;large-v3-turbo&amp;lt;/code&amp;gt; model has built-in noise tolerance that makes Demucs pre-processing unnecessary in most cases.&lt;br /&gt;
&lt;br /&gt;
Optionally, grow the swapfile if you need Extract Speech for shorter files:&lt;br /&gt;
&amp;lt;pre&amp;gt;sudo swapoff /swap.img&lt;br /&gt;
sudo fallocate -l 16G /swap.img&lt;br /&gt;
sudo mkswap /swap.img&lt;br /&gt;
sudo swapon /swap.img&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Environment Variables ==&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Variable !! Default !! Effect&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;BUZZ_FORCE_CPU&amp;lt;/code&amp;gt; || false || Set to &amp;lt;code&amp;gt;true&amp;lt;/code&amp;gt; to disable GPU inference&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;BUZZ_WHISPERCPP_N_THREADS&amp;lt;/code&amp;gt; || cpu_count / 2 || Override thread count for whisper-cli&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
Set via: &amp;lt;code&amp;gt;flatpak override --user io.github.chidiwilliams.Buzz --env=VAR=value&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Key File Paths ==&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Path !! Description&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;/var/lib/flatpak/app/io.github.chidiwilliams.Buzz/.../buzz/whisper_cpp/whisper-cli&amp;lt;/code&amp;gt; || Bundled Vulkan whisper-cli (libwhisper 1.8.3)&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;~/.var/app/io.github.chidiwilliams.Buzz/cache/Buzz/models/&amp;lt;/code&amp;gt; || Buzz model cache (ggml binaries)&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;~/.var/app/io.github.chidiwilliams.Buzz/.local/state/Buzz/log/logs.txt&amp;lt;/code&amp;gt; || Buzz application log&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;~/.var/app/io.github.chidiwilliams.Buzz/config/Buzz.conf&amp;lt;/code&amp;gt; || Buzz settings&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;~/whisper.cpp/build/bin/whisper-cli&amp;lt;/code&amp;gt; || Custom Vulkan-enabled whisper.cpp build&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;~/bin/whisper-cli-vulkan&amp;lt;/code&amp;gt; || Wrapper script for custom build (sets &amp;lt;code&amp;gt;LD_LIBRARY_PATH&amp;lt;/code&amp;gt;)&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;~/.local/share/pipx/venvs/buzz-captions/lib/python3.12/site-packages/buzz/whisper_cpp/&amp;lt;/code&amp;gt; || pipx install whisper_cpp directory (directly modifiable)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Investigation Summary ==&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Question !! Finding&lt;br /&gt;
|-&lt;br /&gt;
| Is Buzz using the RX 7600? || &#039;&#039;&#039;Yes.&#039;&#039;&#039; &amp;lt;code&amp;gt;using Vulkan0 backend&amp;lt;/code&amp;gt; confirmed inside the Flatpak sandbox.&lt;br /&gt;
|-&lt;br /&gt;
| Was &amp;lt;code&amp;gt;--no-gpu&amp;lt;/code&amp;gt; being added? || &#039;&#039;&#039;No.&#039;&#039;&#039; &amp;lt;code&amp;gt;IS_VULKAN_SUPPORTED = True&amp;lt;/code&amp;gt; in the sandbox; flag is never appended.&lt;br /&gt;
|-&lt;br /&gt;
| Does the large model load correctly? || &#039;&#039;&#039;Yes.&#039;&#039;&#039; 1.6 GB to VRAM, transcribes in ~1.25s on a short clip.&lt;br /&gt;
|-&lt;br /&gt;
| What caused the crash? || &#039;&#039;&#039;Extract Speech (Demucs) OOM.&#039;&#039;&#039; Python killed at 22 GB RSS before whisper-cli launched.&lt;br /&gt;
|-&lt;br /&gt;
| Why was VRAM not climbing? || &amp;lt;code&amp;gt;whisper-cli&amp;lt;/code&amp;gt; was never started — process died during Demucs pre-processing.&lt;br /&gt;
|-&lt;br /&gt;
| Fix? || &#039;&#039;&#039;Uncheck Extract Speech&#039;&#039;&#039; for long files. Clear swap before sessions.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Investigation date: 2026-04-25. System: Ubuntu 24.04, AMD RX 7600, Buzz 1.4.4 (Flatpak).&#039;&#039;&lt;/div&gt;</summary>
		<author><name>Justinaquino</name></author>
	</entry>
	<entry>
		<id>https://mediawiki.comfac.net/index.php?title=PfSense_Sales_Training_Material&amp;diff=253</id>
		<title>PfSense Sales Training Material</title>
		<link rel="alternate" type="text/html" href="https://mediawiki.comfac.net/index.php?title=PfSense_Sales_Training_Material&amp;diff=253"/>
		<updated>2026-04-23T11:59:49Z</updated>

		<summary type="html">&lt;p&gt;Justinaquino: Restructure: client-friendly networking table, expand myths section, add 5-Pillar Scoping Framework&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= pfSense Sales Training Material =&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Reference:&#039;&#039;&#039; [https://chatgpt.com/share/67c82515-7074-800e-b29c-0df75f5492f3 Full Session Log]&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== 1. Introduction ==&lt;br /&gt;
&lt;br /&gt;
; Objective&lt;br /&gt;
: Provide a clear, layman-friendly explanation of what a firewall is, why pfSense is a powerful solution, and how its key features protect networks.&lt;br /&gt;
&lt;br /&gt;
; Audience&lt;br /&gt;
: Sales teams, marketing, and non-technical staff who need to explain the technology to potential customers — non-technical decision-makers, IT managers, and SMB owners.&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== 2. Network Basics ==&lt;br /&gt;
&lt;br /&gt;
; Definition&lt;br /&gt;
: Networking is the ability to connect computers and systems together. It occurs when more than one device communicates with another device or group of devices.&lt;br /&gt;
&lt;br /&gt;
=== Networking Disciplines ===&lt;br /&gt;
&lt;br /&gt;
==== ECE (Electronics and Communication Engineering) ====&lt;br /&gt;
* Focuses on how electronic devices work and on designing/building network hardware from basic components.&lt;br /&gt;
* In the Philippines, a PRC ECE license is required to sign off plans for CCTV installations — the only legally mandated network designs (CCTV and phone lines).&lt;br /&gt;
* &#039;&#039;&#039;Sales Note:&#039;&#039;&#039; Clients needing custom electronic solutions (for automation or high-security requirements) will require ECE expertise.&lt;br /&gt;
&lt;br /&gt;
==== IT (Information Technology) ====&lt;br /&gt;
* Specializes in deploying and integrating off-the-shelf networking equipment.&lt;br /&gt;
* Advanced configurations improve reliability, scalability (hundreds to thousands of users), and automation for convenience.&lt;br /&gt;
* &#039;&#039;&#039;Sales Note:&#039;&#039;&#039; Larger-scale deployments and convenience features command higher-level IT skills and corresponding investment.&lt;br /&gt;
&lt;br /&gt;
=== Networking Functions ===&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Function&lt;br /&gt;
! What This Means for Your Business&lt;br /&gt;
! Technical Role&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;Connecting to the Internet&#039;&#039;&#039;&amp;lt;br/&amp;gt;(WAN — Wide Area Network)&lt;br /&gt;
| Your business&#039;s door to the outside world — controls what comes in and what goes out.&lt;br /&gt;
| Connects the facility to external networks (Internet or other sites).&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;Connecting Your Devices Together&#039;&#039;&#039;&amp;lt;br/&amp;gt;(LAN — Local Area Network)&lt;br /&gt;
| Lets computers, printers, servers, and phones talk to each other inside your office.&lt;br /&gt;
| Connects devices within the facility for internal communications.&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;Staying Online Even When Hardware Fails&#039;&#039;&#039;&amp;lt;br/&amp;gt;(High Availability)&lt;br /&gt;
| Prevents downtime — if one device fails, another takes over automatically.&lt;br /&gt;
| Builds redundancy and resilience so services stay online despite failures.&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;Controlling Who Can Access What&#039;&#039;&#039;&amp;lt;br/&amp;gt;(User Management)&lt;br /&gt;
| Staff, guests, and contractors each see only what they&#039;re supposed to see.&lt;br /&gt;
| Implements captive portals, LDAP, RADIUS to organize users by roles and privileges.&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;Protecting Against Attacks and Breaches&#039;&#039;&#039;&amp;lt;br/&amp;gt;(Security)&lt;br /&gt;
| Keeps threats out and sensitive data in — separates risky zones from critical systems.&lt;br /&gt;
| Establishes hardened systems using DMZs (buffer zones) and proxy servers.&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;Wireless Connectivity&#039;&#039;&#039;&amp;lt;br/&amp;gt;(Wi-Fi)&lt;br /&gt;
| Lets staff and devices connect without cables — can be segmented by department or role.&lt;br /&gt;
| Deploys mesh or enterprise Wi-Fi for convenient, flexible connectivity.&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;Wired Connectivity&#039;&#039;&#039;&amp;lt;br/&amp;gt;(Ethernet/LAN Cabling)&lt;br /&gt;
| High-speed, reliable connections for servers, workstations, and critical equipment.&lt;br /&gt;
| Provides high-bandwidth, low-latency connections for critical systems.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== 3. Key Myths &amp;amp; Objections ==&lt;br /&gt;
&lt;br /&gt;
Understanding and countering these objections is critical in every sales conversation.&lt;br /&gt;
&lt;br /&gt;
=== Myth 1: &amp;quot;We&#039;re too small — we don&#039;t need a firewall&amp;quot; ===&lt;br /&gt;
; Reality&lt;br /&gt;
: Small and medium businesses are the most targeted precisely because attackers know they have weak defenses. Anyone hosting a web server, NAS, ERP system, or remote workers needs a firewall. Size is not protection.&lt;br /&gt;
&lt;br /&gt;
=== Myth 2: &amp;quot;Our ISP router/modem is enough&amp;quot; ===&lt;br /&gt;
; Reality&lt;br /&gt;
: ISP-provided routers are consumer-grade equipment with no intrusion detection, no network segmentation, no VPN capability, and no traffic monitoring. They are designed for convenience, not security.&lt;br /&gt;
&lt;br /&gt;
=== Myth 3: &amp;quot;Firewalls only block traffic&amp;quot; ===&lt;br /&gt;
; Reality&lt;br /&gt;
: Modern firewalls do far more — they segment your network into zones, prioritize critical traffic (e.g., video calls over casual browsing), detect intrusions in real time, and enable secure VPN access for remote workers.&lt;br /&gt;
&lt;br /&gt;
=== Myth 4: &amp;quot;A VPN is all the security I need&amp;quot; ===&lt;br /&gt;
; Reality&lt;br /&gt;
: A VPN only encrypts traffic between two points. It does nothing to protect your internal network from threats already inside, compromised devices, or unauthorized users on-site.&lt;br /&gt;
&lt;br /&gt;
=== Myth 5: &amp;quot;The cloud handles our security&amp;quot; ===&lt;br /&gt;
; Reality&lt;br /&gt;
: Cloud providers secure their own infrastructure. Your office network, on-site devices, servers, and traffic between locations remain entirely your responsibility.&lt;br /&gt;
&lt;br /&gt;
=== Myth 6: &amp;quot;Hardware firewalls are different from software firewalls&amp;quot; ===&lt;br /&gt;
; Reality&lt;br /&gt;
: All firewalls are computers running software. A &amp;quot;hardware firewall&amp;quot; is simply dedicated hardware optimized to run firewall software. Performance scales by upgrading network interface cards: 100 Mbps → 1 Gbps → 10 Gbps → 100 Gbps.&lt;br /&gt;
&lt;br /&gt;
=== Myth 7: &amp;quot;Competitor products are better out-of-the-box&amp;quot; ===&lt;br /&gt;
; Reality&lt;br /&gt;
: Competitors like Fortinet and Cisco lock key features behind annual licenses that expire. When you stop paying, features stop working. pfSense delivers enterprise-grade features permanently — only updates and support require payment.&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== 4. Why pfSense? ==&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;Open Source:&#039;&#039;&#039; No recurring feature licenses; you pay only for support and updates. When support lapses, pfSense continues to work — only security updates stop.&lt;br /&gt;
* &#039;&#039;&#039;Enterprise Features:&#039;&#039;&#039;&lt;br /&gt;
** LAN/WAN routing and segmentation&lt;br /&gt;
** VPN (remote access and site-to-site)&lt;br /&gt;
** IDS/IPS (intrusion detection and prevention)&lt;br /&gt;
** High Availability &amp;amp; Load Balancing&lt;br /&gt;
** DHCP, DNS, and user Authentication&lt;br /&gt;
* &#039;&#039;&#039;No License Lock-in:&#039;&#039;&#039; Other vendors &amp;quot;rent&amp;quot; features that expire with licenses. pfSense features remain available indefinitely.&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== 5. Core Functions &amp;amp; Features ==&lt;br /&gt;
&lt;br /&gt;
=== Primary Functions ===&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Function&lt;br /&gt;
! Explanation&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;LAN&#039;&#039;&#039;&lt;br /&gt;
| Segments and protects internal network traffic to enforce security zones.&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;WAN&#039;&#039;&#039;&lt;br /&gt;
| Controls access to the Internet; filters inbound/outbound traffic.&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;VPN&#039;&#039;&#039;&lt;br /&gt;
| Creates encrypted tunnels for secure remote access or site-to-site links.&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;IDS/IPS&#039;&#039;&#039;&lt;br /&gt;
| Monitors traffic for threats and automatically blocks or alerts on intrusions.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Secondary Features ===&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;Authentication:&#039;&#039;&#039; Integrates with Active Directory, LDAP, RADIUS for user-based firewall policies.&lt;br /&gt;
* &#039;&#039;&#039;DHCP:&#039;&#039;&#039; Assigns IP addresses automatically to devices on the network.&lt;br /&gt;
* &#039;&#039;&#039;DNS:&#039;&#039;&#039; Acts as resolver or forwarder to improve name lookup speed and security.&lt;br /&gt;
* &#039;&#039;&#039;Load Balancer / HA:&#039;&#039;&#039; Distributes traffic across multiple WAN links or appliances and provides failover.&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== 6. The 5-Pillar Scoping Framework ==&lt;br /&gt;
&lt;br /&gt;
Use this framework on every prospect conversation. Work through each pillar in order — each answer builds context for the next. The goal is to understand the client&#039;s situation before recommending any hardware or solution.&lt;br /&gt;
&lt;br /&gt;
=== Pillar 1: Stakes ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Budget equals stakes. Before pricing anything, establish what is at risk.&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
; Key Questions&lt;br /&gt;
: &amp;quot;What happens to your business if the network goes down for a full day?&amp;quot;&lt;br /&gt;
: &amp;quot;What data do you store or process — customer records, financial data, health information?&amp;quot;&lt;br /&gt;
: &amp;quot;Have you experienced a breach or outage before? What did it cost you?&amp;quot;&lt;br /&gt;
&lt;br /&gt;
; What It Tells You&lt;br /&gt;
: The client&#039;s tolerance for risk and the true value of the protection being sold. A business that loses 50,000 PHP per hour of downtime has very different stakes than one running a small shared drive.&lt;br /&gt;
&lt;br /&gt;
; How It Maps to pfSense&lt;br /&gt;
: &#039;&#039;&#039;High stakes&#039;&#039;&#039; → High Availability setup, IDS/IPS, VLAN segmentation, full TAC support.&lt;br /&gt;
: &#039;&#039;&#039;Lower stakes&#039;&#039;&#039; → Single appliance, basic firewall rules, standard support.&lt;br /&gt;
&lt;br /&gt;
; Sales Note&lt;br /&gt;
: This pillar justifies the budget. Never skip it — without establishing stakes, you are selling on price alone and will always lose to the cheapest option.&lt;br /&gt;
&lt;br /&gt;
=== Pillar 2: Devices &amp;amp; Users ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Knowing the scale determines the hardware tier.&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
; Key Questions&lt;br /&gt;
: &amp;quot;How many staff members use the network daily?&amp;quot;&lt;br /&gt;
: &amp;quot;What devices are connected — computers, phones, tablets, IP cameras, printers, servers, POS terminals?&amp;quot;&lt;br /&gt;
: &amp;quot;Do you have remote workers or multiple office locations?&amp;quot;&lt;br /&gt;
&lt;br /&gt;
; What It Tells You&lt;br /&gt;
: Scale of deployment, number of network interfaces needed, and whether user management features (captive portal, RADIUS) are required.&lt;br /&gt;
&lt;br /&gt;
; How It Maps to pfSense&lt;br /&gt;
: &amp;lt;10 users → Entry-level appliance.&lt;br /&gt;
: 10–100 users → Mid-range (Netgate 4200 series).&lt;br /&gt;
: 100–500 users → HA pair (2× Netgate 4200 MAX, ~120k PHP one-time).&lt;br /&gt;
: 500+ users or ISP → Netgate 6100 series or higher.&lt;br /&gt;
&lt;br /&gt;
=== Pillar 3: Bandwidth &amp;amp; Traffic ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Traffic type matters as much as raw speed.&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
; Key Questions&lt;br /&gt;
: &amp;quot;What is your current internet plan speed (download/upload)?&amp;quot;&lt;br /&gt;
: &amp;quot;What do people do on the network — video calls, large file transfers, cloud apps, IP cameras streaming 24/7?&amp;quot;&lt;br /&gt;
: &amp;quot;Do you have peak hours where the network slows down noticeably?&amp;quot;&lt;br /&gt;
&lt;br /&gt;
; What It Tells You&lt;br /&gt;
: WAN capacity requirements, whether QoS (Quality of Service) is needed to prioritize traffic types, and the processing load for IDS/IPS inspection.&lt;br /&gt;
&lt;br /&gt;
; How It Maps to pfSense&lt;br /&gt;
: Heavy video/VoIP usage → QoS rules to prioritize real-time traffic.&lt;br /&gt;
: Heavy cloud usage → WAN load balancing for redundancy and speed.&lt;br /&gt;
: Many IP cameras → Dedicated VLAN and allocated bandwidth.&lt;br /&gt;
&lt;br /&gt;
=== Pillar 4: Hardware Compatibility ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Existing infrastructure must integrate — not be replaced.&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
; Key Questions&lt;br /&gt;
: &amp;quot;What servers do you have on-site — web servers, NAS, ERP, database?&amp;quot;&lt;br /&gt;
: &amp;quot;Do you have CCTV systems, POS terminals, VoIP phones, or other specialty devices?&amp;quot;&lt;br /&gt;
: &amp;quot;What network switches and access points are currently deployed?&amp;quot;&lt;br /&gt;
&lt;br /&gt;
; What It Tells You&lt;br /&gt;
: VLAN design requirements, potential conflicts with existing devices, number of network interfaces needed, and whether any equipment requires a DMZ or special firewall rules.&lt;br /&gt;
&lt;br /&gt;
; How It Maps to pfSense&lt;br /&gt;
: &#039;&#039;&#039;NAS or web server&#039;&#039;&#039; → DMZ or isolated VLAN with strict inbound rules.&lt;br /&gt;
: &#039;&#039;&#039;CCTV system&#039;&#039;&#039; → Isolated VLAN with no internet access (security best practice).&lt;br /&gt;
: &#039;&#039;&#039;POS terminals&#039;&#039;&#039; → Segmented from general office traffic (PCI-DSS compliance).&lt;br /&gt;
: &#039;&#039;&#039;VoIP phones&#039;&#039;&#039; → Dedicated VLAN with QoS priority to prevent call drops.&lt;br /&gt;
&lt;br /&gt;
=== Pillar 5: Features &amp;amp; Functions Needed ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Match the pfSense feature set to the client&#039;s actual workflow.&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
; Key Questions&lt;br /&gt;
: &amp;quot;Do staff work remotely and need secure access to office systems?&amp;quot;&lt;br /&gt;
: &amp;quot;Do you have a second office location that needs to connect to the main office?&amp;quot;&lt;br /&gt;
: &amp;quot;Do guests or contractors need network access, separate from staff?&amp;quot;&lt;br /&gt;
: &amp;quot;Are there compliance requirements — PCI, HIPAA, data privacy laws?&amp;quot;&lt;br /&gt;
&lt;br /&gt;
; What It Tells You&lt;br /&gt;
: Which pfSense features to highlight in the proposal and configure in the deployment.&lt;br /&gt;
&lt;br /&gt;
; How It Maps to pfSense&lt;br /&gt;
: Remote workers → VPN (OpenVPN or WireGuard).&lt;br /&gt;
: Multiple sites → Site-to-site VPN.&lt;br /&gt;
: Guest or contractor access → Captive portal with time or bandwidth limits.&lt;br /&gt;
: Compliance requirements → IDS/IPS, logging, VLAN segmentation, audit trails.&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== 7. Sizing &amp;amp; Total Cost of Ownership (TCO) ==&lt;br /&gt;
&lt;br /&gt;
=== Sizing Guidelines ===&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Company Size / Bandwidth&lt;br /&gt;
! Recommended Model&lt;br /&gt;
! Notes&lt;br /&gt;
|-&lt;br /&gt;
| Under 1 Gbps Internet&lt;br /&gt;
| Netgate 6100 Series&lt;br /&gt;
| Fits most small-to-medium offices&lt;br /&gt;
|-&lt;br /&gt;
| Up to 500 Users&lt;br /&gt;
| 2× Netgate 4200 MAX (HA setup)&lt;br /&gt;
| ~120k PHP one-time cost for both appliances&lt;br /&gt;
|-&lt;br /&gt;
| Large Networks / ISPs (&amp;gt;1 Gbps)&lt;br /&gt;
| Netgate 6100+ or higher&lt;br /&gt;
| Only ISPs or large enterprises need these models&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Example: Makati Office (200 Users) ===&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;Hardware Cost:&#039;&#039;&#039; 2×4200 MAX for HA → &#039;&#039;&#039;120,000 PHP&#039;&#039;&#039; (one-time)&lt;br /&gt;
* &#039;&#039;&#039;Annual Costs:&#039;&#039;&#039;&lt;br /&gt;
** License Renewal: 7,500 PHP × 2 = &#039;&#039;&#039;15,000 PHP/year&#039;&#039;&#039;&lt;br /&gt;
** TAC Support: &#039;&#039;&#039;45,000 PHP/year&#039;&#039;&#039; (one needed in HA)&lt;br /&gt;
** Snort Subscription: 24,000 PHP × 2 = &#039;&#039;&#039;48,000 PHP/year&#039;&#039;&#039;&lt;br /&gt;
** &#039;&#039;&#039;Total Annual: ~84,000 PHP/year&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
{{Note|&#039;&#039;&#039;Competitor Comparison:&#039;&#039;&#039; Fortinet equivalent: 150k PHP hardware + 200k PHP/year support → pfSense is more cost-effective.}}&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== 8. Next Steps for Sales ==&lt;br /&gt;
&lt;br /&gt;
# Work through the [[#The 5-Pillar Scoping Framework|5-Pillar Scoping Framework]] with the client before recommending any hardware.&lt;br /&gt;
# Select the right appliance based on scoping output (6100 vs 4200 MAX vs higher models).&lt;br /&gt;
# Prepare TCO comparison (pfSense vs competitor).&lt;br /&gt;
# Send proposal template and service brochure.&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Resources &amp;amp; References ==&lt;br /&gt;
&lt;br /&gt;
* [https://www.comfac-it.com/services/netgate-pfsense-setup Setup Services]&lt;br /&gt;
* [https://www.comfac-it.com/blog-post/making-sense-of-unified-threat-management-utm UTM Deep Dive]&lt;br /&gt;
* [https://www.pfsense.org/products/ Netgate Product Info]&lt;/div&gt;</summary>
		<author><name>Justinaquino</name></author>
	</entry>
	<entry>
		<id>https://mediawiki.comfac.net/index.php?title=PfSense_Training_Project_Tracker&amp;diff=252</id>
		<title>PfSense Training Project Tracker</title>
		<link rel="alternate" type="text/html" href="https://mediawiki.comfac.net/index.php?title=PfSense_Training_Project_Tracker&amp;diff=252"/>
		<updated>2026-04-23T10:43:07Z</updated>

		<summary type="html">&lt;p&gt;Justinaquino: Update Phase 1: Decision made to use dedicated training machine instead of 200-core server; add hardware selection tasks&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__NOTOC__&lt;br /&gt;
&amp;lt;div style=&amp;quot;background:#fff8e1; border:1px solid #ffcc80; border-radius:4px; padding:12px 16px; margin-bottom:20px;&amp;quot;&amp;gt;&lt;br /&gt;
&#039;&#039;&#039;Project Tracker&#039;&#039;&#039; for Comfac&#039;s pfSense Practical Training System implementation. This page tracks all tasks from material conversion to infrastructure deployment and course delivery.&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Phase 0: Material Conversion (FUND001 → Wiki) ==&lt;br /&gt;
Convert all Netgate FUND001 training PDFs into CITWiki pages with detailed summaries. Each wiki page should include: learning objectives, key concepts, step-by-step lab instructions adapted for virtual environment, and troubleshooting tips.&lt;br /&gt;
&lt;br /&gt;
=== Slide Decks ===&lt;br /&gt;
* [x] &#039;&#039;&#039;SEG1 — Introduction to pfSense&#039;&#039;&#039; → [[Training: pfSense Introduction]]&lt;br /&gt;
* [x] &#039;&#039;&#039;SEG2 — Interfaces, VIPs, and Rules&#039;&#039;&#039; → [[Training: Interfaces and Firewall Rules]]&lt;br /&gt;
* [x] &#039;&#039;&#039;SEG3 — NAT and VIPs&#039;&#039;&#039; → [[Training: NAT and Virtual IPs]]&lt;br /&gt;
* [x] &#039;&#039;&#039;SEG4 — pfSense Services&#039;&#039;&#039; → [[Training: pfSense Services]]&lt;br /&gt;
* [x] &#039;&#039;&#039;SEG5 — VPNs and IPsec&#039;&#039;&#039; → [[Training: IPsec VPN]]&lt;br /&gt;
* [x] &#039;&#039;&#039;SEG6 — OpenVPN&#039;&#039;&#039; → [[Training: OpenVPN]]&lt;br /&gt;
* [x] &#039;&#039;&#039;SEG7 — WireGuard&#039;&#039;&#039; → [[Training: WireGuard]]&lt;br /&gt;
* [x] &#039;&#039;&#039;SEG8 — Multi-WAN&#039;&#039;&#039; → [[Training: Multi-WAN]]&lt;br /&gt;
* [x] &#039;&#039;&#039;SEG9 — Traffic Shaping&#039;&#039;&#039; → [[Training: Traffic Shaping]]&lt;br /&gt;
* [x] &#039;&#039;&#039;SEG10 — High Availability&#039;&#039;&#039; → [[Training: High Availability]]&lt;br /&gt;
* [x] &#039;&#039;&#039;SEG11 — Other Features&#039;&#039;&#039; → [[Training: Monitoring and Packages]]&lt;br /&gt;
&lt;br /&gt;
=== Labs ===&lt;br /&gt;
* [x] &#039;&#039;&#039;Lab 1 — Intro, Getting Started, Backup/Restore&#039;&#039;&#039; → [[Training Lab 1: Introduction and Backup Restore]]&lt;br /&gt;
* [x] &#039;&#039;&#039;Lab 2 — Interfaces, Firewall Rules, Aliases&#039;&#039;&#039; → [[Training Lab 2: Firewall Rules and Aliases]]&lt;br /&gt;
* [x] &#039;&#039;&#039;Lab 3 — Virtual IPs and NAT&#039;&#039;&#039; → [[Training Lab 3: NAT and Virtual IPs]]&lt;br /&gt;
* [x] &#039;&#039;&#039;Lab 4 — Services and Branch Network Setup&#039;&#039;&#039; → [[Training Lab 4: Services and Branch Network]]&lt;br /&gt;
* [x] &#039;&#039;&#039;Lab 5 — IPsec&#039;&#039;&#039; → [[Training Lab 5: IPsec VPN]]&lt;br /&gt;
* [x] &#039;&#039;&#039;Lab 6 — OpenVPN&#039;&#039;&#039; → [[Training Lab 6: OpenVPN]]&lt;br /&gt;
* [x] &#039;&#039;&#039;Lab 7 — WireGuard&#039;&#039;&#039; → [[Training Lab 7: WireGuard]]&lt;br /&gt;
* [x] &#039;&#039;&#039;Lab 8 — Multi-WAN&#039;&#039;&#039; → [[Training Lab 8: Multi-WAN]]&lt;br /&gt;
* [x] &#039;&#039;&#039;Lab 9 — Traffic Shaping&#039;&#039;&#039; → [[Training Lab 9: Traffic Shaping]]&lt;br /&gt;
* [x] &#039;&#039;&#039;Lab 10 — High Availability&#039;&#039;&#039; → [[Training Lab 10: High Availability]]&lt;br /&gt;
&lt;br /&gt;
=== Comfac Original Content ===&lt;br /&gt;
* [x] &#039;&#039;&#039;Introduction Training (Module 0)&#039;&#039;&#039; → [[Training: Setting Up a Firewall for Yourself]] — Personal/small business firewall&lt;br /&gt;
* [ ] &#039;&#039;&#039;the-pfsense-documentation.pdf&#039;&#039;&#039; → Summarize into [[Training: pfSense Complete Reference]] or link as external reference&lt;br /&gt;
* [ ] &#039;&#039;&#039;WindowsTrainingSupportFiles.zip&#039;&#039;&#039; → Extract and document client software requirements ([[Training: Client Software Requirements]])&lt;br /&gt;
* [ ] &#039;&#039;&#039;Training Videos (4× .mkv)&#039;&#039;&#039; → Catalog timestamps and link from relevant wiki pages&lt;br /&gt;
&lt;br /&gt;
== Phase 1: Infrastructure Setup ==&lt;br /&gt;
Build the virtual training environment on a &#039;&#039;&#039;dedicated training machine&#039;&#039;&#039; — NOT the 200-core / 1TB RAM production server. The 200-core machine should remain fully available for ERPNext, AI workloads, and production services.&lt;br /&gt;
&lt;br /&gt;
=== Resource Analysis (Completed) ===&lt;br /&gt;
* [x] &#039;&#039;&#039;R.1&#039;&#039;&#039; Compare Pure Linux (FOSS) vs Windows stacks -&amp;gt; [[Networking PfSense Index#Resource Estimates Per Student]]&lt;br /&gt;
* [x] &#039;&#039;&#039;R.2&#039;&#039;&#039; Calculate 20% server utilization targets -&amp;gt; 13 students (Linux), 6 students (Windows)&lt;br /&gt;
* [x] &#039;&#039;&#039;R.3&#039;&#039;&#039; Analyze container-based alternatives -&amp;gt; LXC for Linux routers; KVM still required for pfSense&lt;br /&gt;
* [x] &#039;&#039;&#039;R.4&#039;&#039;&#039; Define exercise-limited deployment model -&amp;gt; Right-size per lab; 0-4 vCPUs per student&lt;br /&gt;
* [x] &#039;&#039;&#039;R.5&#039;&#039;&#039; Specify smaller server options for 10 students -&amp;gt; Dell R630 (Linux) / R740 (Windows)&lt;br /&gt;
* [x] &#039;&#039;&#039;R.6&#039;&#039;&#039; Design AI evaluation pipeline -&amp;gt; Qwen 3.5 Coder 9GB + DeepSeek + OpenCode for automated readiness&lt;br /&gt;
* [x] &#039;&#039;&#039;R.7&#039;&#039;&#039; Decide against using 200-core server -&amp;gt; Training will run on dedicated used server or repurposed desktop&lt;br /&gt;
&lt;br /&gt;
=== Hardware Selection ===&lt;br /&gt;
* [ ] &#039;&#039;&#039;H.1&#039;&#039;&#039; Audit retiring desktops from Win2Lin migration for reuse as training server&lt;br /&gt;
* [ ] &#039;&#039;&#039;H.2&#039;&#039;&#039; If no suitable desktop: procure used Dell R630/R640 (32c/64GB) or HP DL360 Gen9&lt;br /&gt;
* [ ] &#039;&#039;&#039;H.3&#039;&#039;&#039; If rack space/noise is issue: procure 3x Intel N100 mini-PCs for silent cluster&lt;br /&gt;
* [ ] &#039;&#039;&#039;H.4&#039;&#039;&#039; Install Intel i350-T4 quad-port NIC if machine only has 1 Ethernet port&lt;br /&gt;
* [ ] &#039;&#039;&#039;H.5&#039;&#039;&#039; Label machine as CIT-TRAINING-01; document in asset inventory&lt;br /&gt;
&lt;br /&gt;
=== Host Preparation ===&lt;br /&gt;
* [ ] &#039;&#039;&#039;A.1&#039;&#039;&#039; Install Ubuntu Server LTS 22.04/24.04 on training hardware&lt;br /&gt;
* [ ] &#039;&#039;&#039;A.2&#039;&#039;&#039; Configure KVM/libvirt with storage pools (NVMe for golden images, SSD for ephemeral clones)&lt;br /&gt;
* [ ] &#039;&#039;&#039;A.3&#039;&#039;&#039; Set up network bridges: br-mgmt, br-lan, br-wan, br-dmz, br-internet&lt;br /&gt;
* [ ] &#039;&#039;&#039;A.4&#039;&#039;&#039; Configure VLANs for student isolation (one VLAN per student or per lab)&lt;br /&gt;
* [ ] &#039;&#039;&#039;A.5&#039;&#039;&#039; Install and configure Ansible controller (host or Docker container)&lt;br /&gt;
* [ ] &#039;&#039;&#039;A.6&#039;&#039;&#039; Verify training machine has no dependency on 200-core server (standalone)&lt;br /&gt;
&lt;br /&gt;
=== Base Images ===&lt;br /&gt;
* [ ] &#039;&#039;&#039;B.1&#039;&#039;&#039; Download pfSense CE ISO and create qcow2 golden image (1 vCPU, 512 MB RAM, 4 GB disk - microVM)&lt;br /&gt;
* [ ] &#039;&#039;&#039;B.2&#039;&#039;&#039; Create Alpine Linux LXC golden image (0.5 vCPU, 256 MB RAM, 1 GB disk)&lt;br /&gt;
* [ ] &#039;&#039;&#039;B.3&#039;&#039;&#039; Create Debian XFCE LXC golden image for NoVNC client (0.5 vCPU, 256 MB RAM, 2 GB disk)&lt;br /&gt;
* [ ] &#039;&#039;&#039;B.4&#039;&#039;&#039; Create Ubuntu Server LXC golden image (0.5 vCPU, 256 MB RAM, 1 GB disk)&lt;br /&gt;
* [ ] &#039;&#039;&#039;B.5&#039;&#039;&#039; Create &amp;quot;Internet Router&amp;quot; LXC golden image (0.5 vCPU, 128 MB RAM, 0.5 GB disk)&lt;br /&gt;
* [ ] &#039;&#039;&#039;B.6&#039;&#039;&#039; Test each golden image boots and functions correctly&lt;br /&gt;
&lt;br /&gt;
=== Automation ===&lt;br /&gt;
* [ ] &#039;&#039;&#039;C.1&#039;&#039;&#039; Write Ansible playbook: lab1-student-env.yml (1 pfSense microVM + 1 LXC client)&lt;br /&gt;
* [ ] &#039;&#039;&#039;C.2&#039;&#039;&#039; Write Ansible playbook: lab2-student-env.yml (1 pfSense + 1 client + 1 server LXC)&lt;br /&gt;
* [ ] &#039;&#039;&#039;C.3&#039;&#039;&#039; Write Ansible playbook: lab3-student-env.yml (1 pfSense + 1 server + internet router LXC)&lt;br /&gt;
* [ ] &#039;&#039;&#039;C.4&#039;&#039;&#039; Write Ansible playbook: lab4-student-env.yml (2 pfSense + 2 clients + 1 server)&lt;br /&gt;
* [ ] &#039;&#039;&#039;C.5&#039;&#039;&#039; Write Ansible playbooks for Labs 5-10 (VPNs, Multi-WAN, Shaping, HA)&lt;br /&gt;
* [ ] &#039;&#039;&#039;C.6&#039;&#039;&#039; Write Ansible playbook: cleanup-student-env.yml (destroy VMs/LXCs, free resources)&lt;br /&gt;
* [ ] &#039;&#039;&#039;C.7&#039;&#039;&#039; Write Ansible playbook: reset-student-env.yml (revert to snapshot/linked clone base)&lt;br /&gt;
* [ ] &#039;&#039;&#039;C.8&#039;&#039;&#039; Test all playbooks end-to-end with a single student ID&lt;br /&gt;
&lt;br /&gt;
=== NoVNC Portal ===&lt;br /&gt;
* [ ] &#039;&#039;&#039;D.1&#039;&#039;&#039; Evaluate Kimchi vs Apache Guacamole vs custom NoVNC proxy&lt;br /&gt;
* [ ] &#039;&#039;&#039;D.2&#039;&#039;&#039; Install and configure chosen NoVNC solution&lt;br /&gt;
* [ ] &#039;&#039;&#039;D.3&#039;&#039;&#039; Integrate NoVNC with student authentication (LDAP, local wiki accounts, or simple token-based)&lt;br /&gt;
* [ ] &#039;&#039;&#039;D.4&#039;&#039;&#039; Build student dashboard: list of phases/labs, &amp;quot;Launch Lab&amp;quot; button, countdown timer&lt;br /&gt;
* [ ] &#039;&#039;&#039;D.5&#039;&#039;&#039; Test 5 concurrent NoVNC sessions for stability&lt;br /&gt;
* [ ] &#039;&#039;&#039;D.6&#039;&#039;&#039; Test 20 concurrent NoVNC sessions for performance&lt;br /&gt;
&lt;br /&gt;
=== AI Evaluation Pipeline ===&lt;br /&gt;
* [ ] &#039;&#039;&#039;E.1&#039;&#039;&#039; Deploy Qwen 3.5 Instruct Coder 9GB on GPU box or 200-core host&lt;br /&gt;
* [ ] &#039;&#039;&#039;E.2&#039;&#039;&#039; Build pytest + Selenium test suite for pfSense GUI validation&lt;br /&gt;
* [ ] &#039;&#039;&#039;E.3&#039;&#039;&#039; Build SSH-based health check suite for VM/LXC connectivity&lt;br /&gt;
* [ ] &#039;&#039;&#039;E.4&#039;&#039;&#039; Integrate DeepSeek or OpenCode for playbook syntax validation&lt;br /&gt;
* [ ] &#039;&#039;&#039;E.5&#039;&#039;&#039; Create readiness dashboard (pass/fail per lab, resource usage graphs)&lt;br /&gt;
* [ ] &#039;&#039;&#039;E.6&#039;&#039;&#039; Schedule automated nightly tests of all lab environments&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Phase 2: Curriculum Development ==&lt;br /&gt;
Design the student-facing training program.&lt;br /&gt;
&lt;br /&gt;
=== Introduction Course (Most Common Use Case) ===&lt;br /&gt;
* [x] &#039;&#039;&#039;E.1&#039;&#039;&#039; Define &amp;quot;Setting Up a Firewall for Yourself&amp;quot; scope: home office / small business&lt;br /&gt;
* [x] &#039;&#039;&#039;E.2&#039;&#039;&#039; Write Module 0: Why You Need a Firewall (threats, NAT basics, basic topology)&lt;br /&gt;
* [x] &#039;&#039;&#039;E.3&#039;&#039;&#039; Write Module 1: Install pfSense on Old PC or VM (hardware requirements, USB install, first boot wizard)&lt;br /&gt;
* [x] &#039;&#039;&#039;E.4&#039;&#039;&#039; Write Module 2: Basic WAN + LAN Setup (DHCP, DNS, first internet connection)&lt;br /&gt;
* [x] &#039;&#039;&#039;E.5&#039;&#039;&#039; Write Module 3: Essential Firewall Rules (block incoming, allow outgoing, ICMP)&lt;br /&gt;
* [x] &#039;&#039;&#039;E.6&#039;&#039;&#039; Write Module 4: Port Forwarding for Common Services (game server, camera, NAS)&lt;br /&gt;
* [x] &#039;&#039;&#039;E.7&#039;&#039;&#039; Write Module 5: VPN for Remote Access (WireGuard road warrior setup)&lt;br /&gt;
* [x] &#039;&#039;&#039;E.8&#039;&#039;&#039; Write Module 6: Backup and Updates (config.xml backup, update schedule)&lt;br /&gt;
* [x] &#039;&#039;&#039;E.9&#039;&#039;&#039; Create hands-on lab for Introduction Course (single pfSense + 1 client VM)&lt;br /&gt;
* [ ] &#039;&#039;&#039;E.10&#039;&#039;&#039; Record or source video walkthroughs for each module&lt;br /&gt;
&lt;br /&gt;
=== Full FUND001 Adaptation ===&lt;br /&gt;
* [x] &#039;&#039;&#039;F.1&#039;&#039;&#039; Map each SEG slide deck to a wiki training page with summary + key takeaways&lt;br /&gt;
* [x] &#039;&#039;&#039;F.2&#039;&#039;&#039; Adapt Netgate labs from physical/virtualbox environment to KVM/Ansible environment&lt;br /&gt;
* [ ] &#039;&#039;&#039;F.3&#039;&#039;&#039; Update IP addressing schema for Comfac virtual lab (avoid conflicts with production)&lt;br /&gt;
* [ ] &#039;&#039;&#039;F.4&#039;&#039;&#039; Write pre-lab briefing pages (what you&#039;ll learn, expected outcomes)&lt;br /&gt;
* [ ] &#039;&#039;&#039;F.5&#039;&#039;&#039; Write post-lab review pages (common mistakes, verification steps, &amp;quot;show me&amp;quot; checklist)&lt;br /&gt;
* [ ] &#039;&#039;&#039;F.6&#039;&#039;&#039; Create quiz questions for each phase (5–10 questions, auto-graded if possible)&lt;br /&gt;
&lt;br /&gt;
== Phase 3: Pilot &amp;amp; Refinement ==&lt;br /&gt;
Run the training with a small group before full rollout.&lt;br /&gt;
&lt;br /&gt;
=== Internal Pilot ===&lt;br /&gt;
* [ ] &#039;&#039;&#039;G.1&#039;&#039;&#039; Recruit 3–5 internal Comfac IT staff as pilot students&lt;br /&gt;
* [ ] &#039;&#039;&#039;G.2&#039;&#039;&#039; Run Phase 1 (Foundations) with pilot group — collect feedback&lt;br /&gt;
* [ ] &#039;&#039;&#039;G.3&#039;&#039;&#039; Run Phase 2 (NAT &amp;amp; Services) with pilot group — collect feedback&lt;br /&gt;
* [ ] &#039;&#039;&#039;G.4&#039;&#039;&#039; Run one VPN lab (IPsec or OpenVPN) with pilot group — test resource limits&lt;br /&gt;
* [ ] &#039;&#039;&#039;G.5&#039;&#039;&#039; Document all bugs, confusion points, and timeouts&lt;br /&gt;
* [ ] &#039;&#039;&#039;G.6&#039;&#039;&#039; Refine playbooks and wiki pages based on pilot feedback&lt;br /&gt;
&lt;br /&gt;
=== Resource Tuning ===&lt;br /&gt;
* [ ] &#039;&#039;&#039;H.1&#039;&#039;&#039; Measure actual CPU/RAM/disk usage per student during pilot&lt;br /&gt;
* [ ] &#039;&#039;&#039;H.2&#039;&#039;&#039; Adjust VM specs if over- or under-provisioned&lt;br /&gt;
* [ ] &#039;&#039;&#039;H.3&#039;&#039;&#039; Test memory overcommit ratios for safe concurrency scaling&lt;br /&gt;
* [ ] &#039;&#039;&#039;H.4&#039;&#039;&#039; Document maximum safe concurrent student count&lt;br /&gt;
&lt;br /&gt;
== Phase 4: Deployment &amp;amp; Operations ==&lt;br /&gt;
Prepare for regular training delivery.&lt;br /&gt;
&lt;br /&gt;
=== Student Onboarding ===&lt;br /&gt;
* [ ] &#039;&#039;&#039;I.1&#039;&#039;&#039; Create student onboarding guide (how to access portal, use NoVNC, reset lab)&lt;br /&gt;
* [ ] &#039;&#039;&#039;I.2&#039;&#039;&#039; Create instructor guide (how to monitor progress, assist students, grade labs)&lt;br /&gt;
* [ ] &#039;&#039;&#039;I.3&#039;&#039;&#039; Set up scheduling system (book lab time slots, prevent over-allocation)&lt;br /&gt;
* [ ] &#039;&#039;&#039;I.4&#039;&#039;&#039; Create completion certificates or badges&lt;br /&gt;
&lt;br /&gt;
=== Monitoring &amp;amp; Maintenance ===&lt;br /&gt;
* [ ] &#039;&#039;&#039;J.1&#039;&#039;&#039; Set up host monitoring (Prometheus/Grafana or simple `libvirt` stats)&lt;br /&gt;
* [ ] &#039;&#039;&#039;J.2&#039;&#039;&#039; Configure alerts for host resource exhaustion&lt;br /&gt;
* [ ] &#039;&#039;&#039;J.3&#039;&#039;&#039; Schedule weekly base image updates (pfSense patches, OS updates)&lt;br /&gt;
* [ ] &#039;&#039;&#039;J.4&#039;&#039;&#039; Document disaster recovery (rebuild host from Ansible, restore golden images)&lt;br /&gt;
&lt;br /&gt;
== Quick Status Dashboard ==&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Phase !! Status !! % Complete !! Blockers&lt;br /&gt;
|-&lt;br /&gt;
| Phase 0: Material Conversion || 🟢 Done (22/23) || 96% || Pending: reference PDF, support files, videos&lt;br /&gt;
|-&lt;br /&gt;
| Phase 1: Infrastructure Setup || 🟡 In Progress || 20% || Hardware decision made; acquire dedicated training machine&lt;br /&gt;
|-&lt;br /&gt;
| Phase 2: Curriculum Development || 🟡 In Progress || 65% || Need video recordings, quizzes, pre/post lab pages&lt;br /&gt;
|-&lt;br /&gt;
| Phase 3: Pilot &amp;amp; Refinement || 🔴 Not Started || 0% || Waiting on Phase 1 + 2&lt;br /&gt;
|-&lt;br /&gt;
| Phase 4: Deployment &amp;amp; Operations || 🔴 Not Started || 0% || Waiting on Phase 3&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Resource Summary ==&lt;br /&gt;
&#039;&#039;&#039;Per-student minimum:&#039;&#039;&#039; 6 vCPUs, 6.5 GB RAM, 62 GB disk&lt;br /&gt;
&#039;&#039;&#039;Per-student full lab:&#039;&#039;&#039; 10 vCPUs, 10.5 GB RAM, 110 GB disk&lt;br /&gt;
&#039;&#039;&#039;200-core / 1TB capacity:&#039;&#039;&#039; 20–40 concurrent students (conservative to optimized)&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Next Actions (This Week):&#039;&#039;&#039;&lt;br /&gt;
# Summarize the-pfsense-documentation.pdf into a reference page&lt;br /&gt;
# Document WindowsTrainingSupportFiles.zip contents&lt;br /&gt;
# Catalog training video timestamps&lt;br /&gt;
# Begin Ansible playbook drafting for Lab 1 environment&lt;br /&gt;
# Evaluate Kimchi vs Guacamole for NoVNC portal&lt;/div&gt;</summary>
		<author><name>Justinaquino</name></author>
	</entry>
	<entry>
		<id>https://mediawiki.comfac.net/index.php?title=Networking_PfSense_Index&amp;diff=251</id>
		<title>Networking PfSense Index</title>
		<link rel="alternate" type="text/html" href="https://mediawiki.comfac.net/index.php?title=Networking_PfSense_Index&amp;diff=251"/>
		<updated>2026-04-23T10:42:09Z</updated>

		<summary type="html">&lt;p&gt;Justinaquino: Add Dedicated Training Server Strategy: recommend separate machine instead of 200-core server; include mini-PC cluster, used server, desktop repurpose, ARM SBC options; cost-benefit analysis&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__NOTOC__&lt;br /&gt;
&amp;lt;div style=&amp;quot;background:#f0f7ff; border:1px solid #b8d4f0; border-radius:4px; padding:12px 16px; margin-bottom:20px;&amp;quot;&amp;gt;&lt;br /&gt;
&#039;&#039;&#039;Consolidated index&#039;&#039;&#039; for all networking infrastructure guides, pfSense documentation, DNS/ad-blocking resources, and network equipment references at Comfac IT.&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== pfSense Core Guides ==&lt;br /&gt;
* [[pfSense Sales Training Material]] — Product knowledge and sales positioning for Netgate/pfSense hardware and software&lt;br /&gt;
* [[Modern Guide: pfSense Captive Portal with FreeRADIUS &amp;amp; ACME]] — Enterprise Wi-Fi captive portal with RADIUS authentication and Let&#039;s Encrypt SSL&lt;br /&gt;
* [[pfSense CE → pfSense Plus Upgrade Guide]] — Step-by-step migration from Community Edition to pfSense Plus&lt;br /&gt;
* [[SOP: Network Troubleshooting &amp;amp; pfSense Monitoring 251130]] — Standard operating procedures for network diagnostics and pfSense health monitoring&lt;br /&gt;
&lt;br /&gt;
== Network Infrastructure &amp;amp; Equipment ==&lt;br /&gt;
* [[Tplink Mikrotik Equivalent]] — Cross-reference of TP-Link and MikroTik models for network deployments&lt;br /&gt;
* [[Controller Systems 251213-01]] — Network and infrastructure controller systems&lt;br /&gt;
* [[Power Distribution Tree 251213]] — Power architecture for network and server racks&lt;br /&gt;
* [[NPM Migration to Homelab VPS Relay 260401]] — Nginx Proxy Manager migration; VPS as iptables/ZeroTier relay with homelab redundancy&lt;br /&gt;
&lt;br /&gt;
== DNS, Ad Blocking &amp;amp; Pi-hole ==&lt;br /&gt;
* [https://github.com/Comfac-Global-Group/pi-hole Comfac Pi-hole Repository] — GitHub repository for Pi-hole DNS sinkhole deployment&lt;br /&gt;
* [https://github.com/Comfac-Global-Group/pi-hole/blob/master/How%20this%20Works.md How Pi-hole Works] — Technical overview of the Pi-hole DNS filtering architecture&lt;br /&gt;
&lt;br /&gt;
== Training &amp;amp; Skills ==&lt;br /&gt;
* [[Skills and Competencies for IT Staff Trained in pfSense]] — Required competencies and certification path for pfSense-administering staff&lt;br /&gt;
* [[PfSense Training Project Tracker]] — &#039;&#039;&#039;Implementation tracker&#039;&#039;&#039; for the NoVNC virtual lab, material conversion, and curriculum development&lt;br /&gt;
&lt;br /&gt;
== Practical Training System (NoVNC Virtual Lab) ==&lt;br /&gt;
&#039;&#039;&#039;Goal:&#039;&#039;&#039; Build a self-hosted, virtualized pfSense training environment where Comfac trainees can learn hands-on without physical hardware. All labs run via NoVNC in a browser, orchestrated on Comfac&#039;s 200-core / 1TB RAM machine.&lt;br /&gt;
&lt;br /&gt;
=== Training Architecture Vision ===&lt;br /&gt;
Each student gets an isolated virtual network sandbox containing:&lt;br /&gt;
* 2× pfSense VMs (HQ HA pair or HQ + Branch)&lt;br /&gt;
* 1–2× Client VMs (Windows/Linux desktop)&lt;br /&gt;
* 1× Server VM (web/DNS/target)&lt;br /&gt;
* 1× Simulated &amp;quot;Internet&amp;quot; router VM&lt;br /&gt;
&lt;br /&gt;
Access is through a NoVNC web portal. Students click a lab, and their environment is provisioned automatically via Ansible/Terraform or Docker/KVM.&lt;br /&gt;
&lt;br /&gt;
=== Resource Estimates Per Student ===&lt;br /&gt;
&lt;br /&gt;
==== Stack A: Pure Linux / FOSS (Recommended for Comfac) ====&lt;br /&gt;
All components run on open-source software. Clients are lightweight Linux VMs or LXC containers. No Windows licensing required.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Component !! vCPUs !! RAM !! Disk !! Virtualization !! Notes&lt;br /&gt;
|-&lt;br /&gt;
| pfSense VM || 1 || 512 MB || 4 GB || KVM microVM || FreeBSD requires KVM; use tiny QEMU args&lt;br /&gt;
|-&lt;br /&gt;
| Linux Client (LXC) || 0.5 || 256 MB || 1 GB || LXC container || Alpine or Debian with XFCE; NoVNC access&lt;br /&gt;
|-&lt;br /&gt;
| Linux Server (LXC) || 0.5 || 256 MB || 1 GB || LXC container || nginx, BIND, or simple Python HTTP&lt;br /&gt;
|-&lt;br /&gt;
| Internet Router (LXC) || 0.5 || 128 MB || 0.5 GB || LXC container || Static routes only; FRR optional&lt;br /&gt;
|-&lt;br /&gt;
| NoVNC Proxy (Docker) || 0.5 || 256 MB || 0.5 GB || Docker container || websockify + nginx&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;Total per student&#039;&#039;&#039; || &#039;&#039;&#039;3&#039;&#039;&#039; || &#039;&#039;&#039;1.4 GB&#039;&#039;&#039; || &#039;&#039;&#039;7 GB&#039;&#039;&#039; || — || Thin-provisioned; linked clones&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== Stack B: Windows Client (Full Desktop Experience) ====&lt;br /&gt;
For trainees who need a Windows desktop for browser-based management or specific client software.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Component !! vCPUs !! RAM !! Disk !! Virtualization !! Notes&lt;br /&gt;
|-&lt;br /&gt;
| pfSense VM || 2 || 1 GB || 8 GB || KVM || Standard qcow2 image&lt;br /&gt;
|-&lt;br /&gt;
| Windows Client || 2 || 4 GB || 40 GB || KVM || Windows 10/11 thin client; needs GPU if GUI-heavy&lt;br /&gt;
|-&lt;br /&gt;
| Ubuntu Server || 1 || 1 GB || 10 GB || KVM || Full VM for compatibility&lt;br /&gt;
|-&lt;br /&gt;
| Internet Router || 1 || 512 MB || 4 GB || KVM || Ubuntu with static routes&lt;br /&gt;
|-&lt;br /&gt;
| NoVNC Proxy || 0.5 || 256 MB || 0.5 GB || Docker || Shared across students&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;Total per student&#039;&#039;&#039; || &#039;&#039;&#039;6.5&#039;&#039;&#039; || &#039;&#039;&#039;6.8 GB&#039;&#039;&#039; || &#039;&#039;&#039;63 GB&#039;&#039;&#039; || — || Higher resource cost&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== Stack C: Hybrid — Containers for Linux Router Exercises ====&lt;br /&gt;
For basic routing/firewall concept labs only (not pfSense-specific), replace pfSense with Linux routers in containers.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Component !! vCPUs !! RAM !! Disk !! Virtualization !! Notes&lt;br /&gt;
|-&lt;br /&gt;
| Linux Router (LXC) || 0.5 || 128 MB || 0.5 GB || LXC || Alpine + iptables/nftables + WireGuard&lt;br /&gt;
|-&lt;br /&gt;
| Linux Client (LXC) || 0.5 || 256 MB || 1 GB || LXC || Alpine or Debian&lt;br /&gt;
|-&lt;br /&gt;
| Linux Server (LXC) || 0.5 || 256 MB || 1 GB || LXC || nginx, BIND&lt;br /&gt;
|-&lt;br /&gt;
| Internet Router (LXC) || 0.5 || 128 MB || 0.5 GB || LXC || Static routes&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;Total per student&#039;&#039;&#039; || &#039;&#039;&#039;2&#039;&#039;&#039; || &#039;&#039;&#039;768 MB&#039;&#039;&#039; || &#039;&#039;&#039;3 GB&#039;&#039;&#039; || — || Cannot teach pfSense GUI; teaches concepts only&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Important:&#039;&#039;&#039; pfSense is FreeBSD-based and cannot run in Linux containers (Docker/LXC). Stack C is suitable for teaching routing/VPN concepts using Linux tools (iptables, nftables, WireGuard, strongSwan), but not for teaching the pfSense web interface. For pfSense GUI training, use Stack A or B.&lt;br /&gt;
&lt;br /&gt;
=== Server Capacity: 20% Utilization Target ===&lt;br /&gt;
The goal is to run the training environment using only 20% of the 200-core / 1TB RAM server, leaving 80% for other Comfac workloads (ERPNext, AI models, file services).&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;20% of available resources:&#039;&#039;&#039;&lt;br /&gt;
* 40 vCPUs (20% of 200)&lt;br /&gt;
* 200 GB RAM (20% of 1 TB)&lt;br /&gt;
* ~2 TB SSD (assuming 10 TB array, 20% = 2 TB)&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Concurrent student capacity at 20% utilization:&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Stack !! Per-Student Resources !! Students at 20% CPU !! Students at 20% RAM !! Limiting Factor&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;A: Pure Linux&#039;&#039;&#039; || 3 vCPU / 1.4 GB || 13 || 142 || &#039;&#039;&#039;CPU: 13 students&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;B: Windows&#039;&#039;&#039; || 6.5 vCPU / 6.8 GB || 6 || 29 || &#039;&#039;&#039;CPU: 6 students&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;C: Containers&#039;&#039;&#039; || 2 vCPU / 0.8 GB || 20 || 250 || &#039;&#039;&#039;CPU: 20 students&#039;&#039;&#039;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Recommendation:&#039;&#039;&#039; Use Stack A (Pure Linux) for all labs. This yields ~13 concurrent students within the 20% budget, or up to ~30 students if spread across time slots (not everyone needs a lab simultaneously).&lt;br /&gt;
&lt;br /&gt;
=== Smaller Server: What Hardware for 10 Students? ===&lt;br /&gt;
If buying a dedicated training server instead of using the 200-core machine:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Stack !! CPU !! RAM !! Storage !! NICs !! Example Hardware&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;A: Pure Linux&#039;&#039;&#039; || 32 cores || 32 GB || 500 GB NVMe || 2x 1GbE || Used Dell R630/R640 (~$300-500)&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;B: Windows&#039;&#039;&#039; || 64 cores || 96 GB || 1 TB NVMe || 2x 1GbE || Used Dell R740 / HP DL360 (~$600-900)&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;C: Containers&#039;&#039;&#039; || 16 cores || 16 GB || 250 GB NVMe || 2x 1GbE || Old desktop + Intel NIC (~$100-200)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Dedicated Training Server Strategy (Recommended) ===&lt;br /&gt;
The 200-core / 1TB RAM machine is Comfac&#039;s primary production server (ERPNext, AI models, file services, build pipelines). Running training labs on it consumes resources that could be used for revenue-generating workloads.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Recommendation: Do NOT run training on the 200-core server.&#039;&#039;&#039; Instead, deploy training on a dedicated, smaller machine.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Option !! Hardware !! Cost (Used) !! Capacity (Stack A) !! Power !! Notes&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;A. Mini-PC Cluster&#039;&#039;&#039; || 3× Intel N100/N305 mini-PCs (4c/8t, 16GB RAM, 512GB SSD each) || ~$450 total || 12 students || ~45W total || Silent, no rack needed. One PC fails = 4 students affected.&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;B. Single Used Server&#039;&#039;&#039; || Dell R630 / HP DL360 Gen9 (2× E5-2680v4, 64GB RAM, 1TB NVMe) || ~$400-600 || 15-20 students || ~150W || Rackmount, redundant PSU, IPMI.&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;C. Desktop Repurpose&#039;&#039;&#039; || Old Comfac desktop (i5-8400, 32GB RAM, 500GB SSD) + Intel i350-T4 NIC || $0 + $50 NIC || 6-8 students || ~65W || Free if you have spare desktops.&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;D. ARM SBC Cluster&#039;&#039;&#039; || 4× Raspberry Pi 5 (4GB) + 1× Pi 5 (8GB as controller) || ~$300 total || 4-6 students || ~25W total || Cannot run x86 pfSense; must use Linux routers (Stack C only).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Best choice for Comfac: Option B (Single Used Server) or Option C (Repurpose Desktop).&#039;&#039;&#039;&lt;br /&gt;
* Option B gives headroom for growth to 20 students&lt;br /&gt;
* Option C is free if you have retiring desktops from the Win2Lin migration&lt;br /&gt;
* Both keep the 200-core server 100% free for production&lt;br /&gt;
&lt;br /&gt;
=== Cost-Benefit: 200-Core Server vs Dedicated Training Box ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Factor !! Training on 200-Core Server !! Dedicated Training Server&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;Hardware Cost&#039;&#039;&#039; || $0 (already owned) || $0-$600&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;Power Cost&#039;&#039;&#039; || Already running || +$10-30/month&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;Opportunity Cost&#039;&#039;&#039; || &#039;&#039;&#039;High&#039;&#039;&#039; — 20% of server unavailable for ERPNext/AI/builds || &#039;&#039;&#039;Zero&#039;&#039;&#039; — production server untouched&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;Risk&#039;&#039;&#039; || Training crashes could affect production VMs || Isolated; training issues contained&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;Noise/Location&#039;&#039;&#039; || Must stay in server room || Mini-PC or desktop can sit in training room&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;Maintenance Window&#039;&#039;&#039; || Must coordinate with production || Anytime; reboot freely&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Verdict:&#039;&#039;&#039; A $400 used server or a $0 repurposed desktop pays for itself in 1-2 months by keeping the 200-core machine fully available for production workloads.&lt;br /&gt;
&lt;br /&gt;
=== Cluster-in-a-Box: Old PC + Proxmox VE ===&lt;br /&gt;
For the absolute lowest cost (repurposed old PC):&lt;br /&gt;
# Install Proxmox VE (Debian-based hypervisor with web GUI)&lt;br /&gt;
# Create LXC templates for Alpine/Debian clients&lt;br /&gt;
# Create KVM VMs for pfSense microVMs&lt;br /&gt;
# Install NoVNC via Proxmox built-in console or add Kimchi/Guacamole&lt;br /&gt;
# Students access via browser to the Proxmox web UI&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Specs needed for 8 students (Stack A):&#039;&#039;&#039;&lt;br /&gt;
* CPU: 6-core / 12-thread (Intel 6th-gen i5 or better; AMD Ryzen 5)&lt;br /&gt;
* RAM: 32 GB DDR4&lt;br /&gt;
* Storage: 500 GB NVMe or SSD&lt;br /&gt;
* NIC: Intel i350-T4 quad-port (for VLANs and bridges)&lt;br /&gt;
* Cost: $0 (old PC) + $50 (NIC) if you already have the PC&lt;br /&gt;
&lt;br /&gt;
This is the path of least resistance for Comfac given the Win2Lin migration will free up desktops.&lt;br /&gt;
&lt;br /&gt;
=== Exercise-Limited Deployment (Right-Sizing per Lab) ===&lt;br /&gt;
Not every lab needs the full sandbox. Deploy only what is needed:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Lab !! Stack A Deployed !! vCPUs Used !! RAM Used !! Disk Used&lt;br /&gt;
|-&lt;br /&gt;
| Day 1 — Theory only || None (wiki only) || 0 || 0 || 0&lt;br /&gt;
|-&lt;br /&gt;
| Lab 1 (Intro/Backup) || 1 pfSense + 1 client || 1.5 || 768 MB || 5 GB&lt;br /&gt;
|-&lt;br /&gt;
| Lab 2 (Rules) || 1 pfSense + 1 client + 1 server || 2 || 1 GB || 6 GB&lt;br /&gt;
|-&lt;br /&gt;
| Lab 3 (NAT) || 1 pfSense + 1 server + router || 2 || 900 MB || 5.5 GB&lt;br /&gt;
|-&lt;br /&gt;
| Lab 4 (Services) || 2 pfSense + 2 clients + 1 server || 4 || 2.1 GB || 11 GB&lt;br /&gt;
|-&lt;br /&gt;
| Lab 5-7 (VPNs) || 2 pfSense + 2 clients || 3 || 1.5 GB || 10 GB&lt;br /&gt;
|-&lt;br /&gt;
| Lab 8 (Multi-WAN) || 1 pfSense + 1 client + router || 2 || 900 MB || 5.5 GB&lt;br /&gt;
|-&lt;br /&gt;
| Lab 9 (Shaping) || 1 pfSense + 2 clients || 2.5 || 1.3 GB || 6 GB&lt;br /&gt;
|-&lt;br /&gt;
| Lab 10 (HA) || 2 pfSense + 1 client || 2.5 || 1.3 GB || 9 GB&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Scheduling strategy:&#039;&#039;&#039; If students are scheduled in 1-hour slots and labs are provisioned on-demand, the same 40 vCPUs / 200 GB RAM can serve 40-60 student-slots per day (not concurrently, but sequentially).&lt;br /&gt;
&lt;br /&gt;
=== Phase 1: Resource Setup Validation ===&lt;br /&gt;
Before full student rollout, validate the resource model with these tests:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Test !! Purpose !! Command / Method !! Pass Criteria&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;T1: MicroVM Boot&#039;&#039;&#039; || Verify pfSense runs in 512MB/1vCPU || qemu-system-x86_64 -m 512 -smp 1 -drive file=pfsense.qcow2 || Boots to login in &amp;lt; 120s&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;T2: LXC Container Spawn&#039;&#039;&#039; || Verify sub-1GB containers work || lxc launch images:alpine/3.19 client || Starts in &amp;lt; 10s; SSH reachable&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;T3: NoVNC Session&#039;&#039;&#039; || Verify one student can access console || websockify + TigerVNC || 640x480 responsive; &amp;lt; 500ms latency&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;T4: 5 Concurrent Students&#039;&#039;&#039; || Validate 20% CPU/RAM budget || Ansible: deploy 5x Stack A || Total &amp;lt; 8 vCPU, &amp;lt; 7 GB RAM&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;T5: Lab 4 Full Deploy&#039;&#039;&#039; || Heaviest lab (2 pfSense + 2 clients + server) || ansible-playbook lab4.yml || Deploys in &amp;lt; 5 min; all VMs pingable&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;T6: Snapshot Reset Speed&#039;&#039;&#039; || Time to reset between students || virsh snapshot-revert + virsh start || &amp;lt; 60 seconds total&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;T7: AI Evaluation Readiness&#039;&#039;&#039; || Validate environment for automated testing || See AI Evaluation section below || All labs pass synthetic health checks&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AI Evaluation: Automated Readiness Testing ===&lt;br /&gt;
Before students arrive, AI agents will validate that each lab environment is functional. This replaces manual smoke-testing.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Evaluation Stack:&#039;&#039;&#039;&lt;br /&gt;
* &#039;&#039;&#039;Qwen 3.5 Instruct Coder (9GB)&#039;&#039;&#039; — Runs locally on the 200-core server or a dedicated GPU box. Evaluates: pfSense GUI accessibility, rule syntax, VPN handshake status, config.xml validity.&lt;br /&gt;
* &#039;&#039;&#039;DeepSeek Coder (optional)&#039;&#039;&#039; — Cloud or local. Validates Ansible playbook correctness, network topology logic, resource allocation math.&lt;br /&gt;
* &#039;&#039;&#039;OpenCode (local agent)&#039;&#039;&#039; — Executes shell commands inside VMs/containers via SSH/API. Performs end-to-end tests: ping, curl, ipsec status, wg show, etc.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Automated Test Sequence (per lab):&#039;&#039;&#039;&lt;br /&gt;
# Deploy lab environment via Ansible&lt;br /&gt;
# AI agent logs into pfSense (admin credentials)&lt;br /&gt;
# Screenshot/check each configured page matches expected state&lt;br /&gt;
# Run connectivity tests from client VMs&lt;br /&gt;
# Verify services are listening on correct ports&lt;br /&gt;
# Generate pass/fail report with specific error details&lt;br /&gt;
# Destroy lab environment&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Benefits:&#039;&#039;&#039;&lt;br /&gt;
* Catch broken base images before students arrive&lt;br /&gt;
* Validate that config.xml injections work correctly&lt;br /&gt;
* Ensure network isolation between students&lt;br /&gt;
* Measure actual resource usage vs. estimates&lt;br /&gt;
* Generate readiness dashboard for instructors&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Implementation:&#039;&#039;&#039;&lt;br /&gt;
* Python + Selenium/Playwright for pfSense GUI testing&lt;br /&gt;
* Paramiko/fabric for SSH-based VM tests&lt;br /&gt;
* pytest framework for test organization&lt;br /&gt;
* GitHub Actions or local Cron for scheduled runs&lt;br /&gt;
* Output: Markdown report posted to wiki or sent via Matrix/Email&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Related Infrastructure ==&lt;br /&gt;
* [[System Hardening Strategy: Win2Lin Migration &amp;amp; Infrastructure 251129]] — Server migration and infrastructure hardening&lt;br /&gt;
* [[Introduction: Why Self-Host Your Email?]] — Self-hosted email infrastructure context&lt;br /&gt;
* [[Mailcow + Thunderbird Setup Guide (Email + Calendar)]] — Email server deployment&lt;br /&gt;
* [[Portainer to Docker Compose Migration Guide]] — Container orchestration for network services&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&#039;&#039;This index consolidates networking resources previously scattered across the [[Main Page]]. Last updated: 260423.&#039;&#039;&lt;/div&gt;</summary>
		<author><name>Justinaquino</name></author>
	</entry>
	<entry>
		<id>https://mediawiki.comfac.net/index.php?title=PfSense_Training_Project_Tracker&amp;diff=250</id>
		<title>PfSense Training Project Tracker</title>
		<link rel="alternate" type="text/html" href="https://mediawiki.comfac.net/index.php?title=PfSense_Training_Project_Tracker&amp;diff=250"/>
		<updated>2026-04-23T10:14:45Z</updated>

		<summary type="html">&lt;p&gt;Justinaquino: Update Phase 1: Resource analysis completed (R.1-R.6), add AI evaluation pipeline tasks, update status dashboard&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__NOTOC__&lt;br /&gt;
&amp;lt;div style=&amp;quot;background:#fff8e1; border:1px solid #ffcc80; border-radius:4px; padding:12px 16px; margin-bottom:20px;&amp;quot;&amp;gt;&lt;br /&gt;
&#039;&#039;&#039;Project Tracker&#039;&#039;&#039; for Comfac&#039;s pfSense Practical Training System implementation. This page tracks all tasks from material conversion to infrastructure deployment and course delivery.&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Phase 0: Material Conversion (FUND001 → Wiki) ==&lt;br /&gt;
Convert all Netgate FUND001 training PDFs into CITWiki pages with detailed summaries. Each wiki page should include: learning objectives, key concepts, step-by-step lab instructions adapted for virtual environment, and troubleshooting tips.&lt;br /&gt;
&lt;br /&gt;
=== Slide Decks ===&lt;br /&gt;
* [x] &#039;&#039;&#039;SEG1 — Introduction to pfSense&#039;&#039;&#039; → [[Training: pfSense Introduction]]&lt;br /&gt;
* [x] &#039;&#039;&#039;SEG2 — Interfaces, VIPs, and Rules&#039;&#039;&#039; → [[Training: Interfaces and Firewall Rules]]&lt;br /&gt;
* [x] &#039;&#039;&#039;SEG3 — NAT and VIPs&#039;&#039;&#039; → [[Training: NAT and Virtual IPs]]&lt;br /&gt;
* [x] &#039;&#039;&#039;SEG4 — pfSense Services&#039;&#039;&#039; → [[Training: pfSense Services]]&lt;br /&gt;
* [x] &#039;&#039;&#039;SEG5 — VPNs and IPsec&#039;&#039;&#039; → [[Training: IPsec VPN]]&lt;br /&gt;
* [x] &#039;&#039;&#039;SEG6 — OpenVPN&#039;&#039;&#039; → [[Training: OpenVPN]]&lt;br /&gt;
* [x] &#039;&#039;&#039;SEG7 — WireGuard&#039;&#039;&#039; → [[Training: WireGuard]]&lt;br /&gt;
* [x] &#039;&#039;&#039;SEG8 — Multi-WAN&#039;&#039;&#039; → [[Training: Multi-WAN]]&lt;br /&gt;
* [x] &#039;&#039;&#039;SEG9 — Traffic Shaping&#039;&#039;&#039; → [[Training: Traffic Shaping]]&lt;br /&gt;
* [x] &#039;&#039;&#039;SEG10 — High Availability&#039;&#039;&#039; → [[Training: High Availability]]&lt;br /&gt;
* [x] &#039;&#039;&#039;SEG11 — Other Features&#039;&#039;&#039; → [[Training: Monitoring and Packages]]&lt;br /&gt;
&lt;br /&gt;
=== Labs ===&lt;br /&gt;
* [x] &#039;&#039;&#039;Lab 1 — Intro, Getting Started, Backup/Restore&#039;&#039;&#039; → [[Training Lab 1: Introduction and Backup Restore]]&lt;br /&gt;
* [x] &#039;&#039;&#039;Lab 2 — Interfaces, Firewall Rules, Aliases&#039;&#039;&#039; → [[Training Lab 2: Firewall Rules and Aliases]]&lt;br /&gt;
* [x] &#039;&#039;&#039;Lab 3 — Virtual IPs and NAT&#039;&#039;&#039; → [[Training Lab 3: NAT and Virtual IPs]]&lt;br /&gt;
* [x] &#039;&#039;&#039;Lab 4 — Services and Branch Network Setup&#039;&#039;&#039; → [[Training Lab 4: Services and Branch Network]]&lt;br /&gt;
* [x] &#039;&#039;&#039;Lab 5 — IPsec&#039;&#039;&#039; → [[Training Lab 5: IPsec VPN]]&lt;br /&gt;
* [x] &#039;&#039;&#039;Lab 6 — OpenVPN&#039;&#039;&#039; → [[Training Lab 6: OpenVPN]]&lt;br /&gt;
* [x] &#039;&#039;&#039;Lab 7 — WireGuard&#039;&#039;&#039; → [[Training Lab 7: WireGuard]]&lt;br /&gt;
* [x] &#039;&#039;&#039;Lab 8 — Multi-WAN&#039;&#039;&#039; → [[Training Lab 8: Multi-WAN]]&lt;br /&gt;
* [x] &#039;&#039;&#039;Lab 9 — Traffic Shaping&#039;&#039;&#039; → [[Training Lab 9: Traffic Shaping]]&lt;br /&gt;
* [x] &#039;&#039;&#039;Lab 10 — High Availability&#039;&#039;&#039; → [[Training Lab 10: High Availability]]&lt;br /&gt;
&lt;br /&gt;
=== Comfac Original Content ===&lt;br /&gt;
* [x] &#039;&#039;&#039;Introduction Training (Module 0)&#039;&#039;&#039; → [[Training: Setting Up a Firewall for Yourself]] — Personal/small business firewall&lt;br /&gt;
* [ ] &#039;&#039;&#039;the-pfsense-documentation.pdf&#039;&#039;&#039; → Summarize into [[Training: pfSense Complete Reference]] or link as external reference&lt;br /&gt;
* [ ] &#039;&#039;&#039;WindowsTrainingSupportFiles.zip&#039;&#039;&#039; → Extract and document client software requirements ([[Training: Client Software Requirements]])&lt;br /&gt;
* [ ] &#039;&#039;&#039;Training Videos (4× .mkv)&#039;&#039;&#039; → Catalog timestamps and link from relevant wiki pages&lt;br /&gt;
&lt;br /&gt;
== Phase 1: Infrastructure Setup ==&lt;br /&gt;
Build the virtual training environment on Comfac&#039;s 200-core / 1TB RAM machine.&lt;br /&gt;
&lt;br /&gt;
=== Resource Analysis (Completed) ===&lt;br /&gt;
* [x] &#039;&#039;&#039;R.1&#039;&#039;&#039; Compare Pure Linux (FOSS) vs Windows stacks -&amp;gt; [[Networking PfSense Index#Resource Estimates Per Student]]&lt;br /&gt;
* [x] &#039;&#039;&#039;R.2&#039;&#039;&#039; Calculate 20% server utilization targets -&amp;gt; 13 students (Linux), 6 students (Windows)&lt;br /&gt;
* [x] &#039;&#039;&#039;R.3&#039;&#039;&#039; Analyze container-based alternatives -&amp;gt; LXC for Linux routers; KVM still required for pfSense&lt;br /&gt;
* [x] &#039;&#039;&#039;R.4&#039;&#039;&#039; Define exercise-limited deployment model -&amp;gt; Right-size per lab; 0-4 vCPUs per student&lt;br /&gt;
* [x] &#039;&#039;&#039;R.5&#039;&#039;&#039; Specify smaller server options for 10 students -&amp;gt; Dell R630 (Linux) / R740 (Windows)&lt;br /&gt;
* [x] &#039;&#039;&#039;R.6&#039;&#039;&#039; Design AI evaluation pipeline -&amp;gt; Qwen 3.5 Coder 9GB + DeepSeek + OpenCode for automated readiness&lt;br /&gt;
&lt;br /&gt;
=== Host Preparation ===&lt;br /&gt;
* [ ] &#039;&#039;&#039;A.1&#039;&#039;&#039; Install Ubuntu Server LTS on 200-core host&lt;br /&gt;
* [ ] &#039;&#039;&#039;A.2&#039;&#039;&#039; Configure KVM/libvirt with storage pools (NVMe for images, SSD for ephemeral clones)&lt;br /&gt;
* [ ] &#039;&#039;&#039;A.3&#039;&#039;&#039; Set up network bridges: br-mgmt, br-lan, br-wan, br-dmz, br-internet&lt;br /&gt;
* [ ] &#039;&#039;&#039;A.4&#039;&#039;&#039; Configure VLANs for student isolation (one VLAN per student or per lab)&lt;br /&gt;
* [ ] &#039;&#039;&#039;A.5&#039;&#039;&#039; Install and configure Ansible controller (host or container)&lt;br /&gt;
&lt;br /&gt;
=== Base Images ===&lt;br /&gt;
* [ ] &#039;&#039;&#039;B.1&#039;&#039;&#039; Download pfSense CE ISO and create qcow2 golden image (1 vCPU, 512 MB RAM, 4 GB disk - microVM)&lt;br /&gt;
* [ ] &#039;&#039;&#039;B.2&#039;&#039;&#039; Create Alpine Linux LXC golden image (0.5 vCPU, 256 MB RAM, 1 GB disk)&lt;br /&gt;
* [ ] &#039;&#039;&#039;B.3&#039;&#039;&#039; Create Debian XFCE LXC golden image for NoVNC client (0.5 vCPU, 256 MB RAM, 2 GB disk)&lt;br /&gt;
* [ ] &#039;&#039;&#039;B.4&#039;&#039;&#039; Create Ubuntu Server LXC golden image (0.5 vCPU, 256 MB RAM, 1 GB disk)&lt;br /&gt;
* [ ] &#039;&#039;&#039;B.5&#039;&#039;&#039; Create &amp;quot;Internet Router&amp;quot; LXC golden image (0.5 vCPU, 128 MB RAM, 0.5 GB disk)&lt;br /&gt;
* [ ] &#039;&#039;&#039;B.6&#039;&#039;&#039; Test each golden image boots and functions correctly&lt;br /&gt;
&lt;br /&gt;
=== Automation ===&lt;br /&gt;
* [ ] &#039;&#039;&#039;C.1&#039;&#039;&#039; Write Ansible playbook: lab1-student-env.yml (1 pfSense microVM + 1 LXC client)&lt;br /&gt;
* [ ] &#039;&#039;&#039;C.2&#039;&#039;&#039; Write Ansible playbook: lab2-student-env.yml (1 pfSense + 1 client + 1 server LXC)&lt;br /&gt;
* [ ] &#039;&#039;&#039;C.3&#039;&#039;&#039; Write Ansible playbook: lab3-student-env.yml (1 pfSense + 1 server + internet router LXC)&lt;br /&gt;
* [ ] &#039;&#039;&#039;C.4&#039;&#039;&#039; Write Ansible playbook: lab4-student-env.yml (2 pfSense + 2 clients + 1 server)&lt;br /&gt;
* [ ] &#039;&#039;&#039;C.5&#039;&#039;&#039; Write Ansible playbooks for Labs 5-10 (VPNs, Multi-WAN, Shaping, HA)&lt;br /&gt;
* [ ] &#039;&#039;&#039;C.6&#039;&#039;&#039; Write Ansible playbook: cleanup-student-env.yml (destroy VMs/LXCs, free resources)&lt;br /&gt;
* [ ] &#039;&#039;&#039;C.7&#039;&#039;&#039; Write Ansible playbook: reset-student-env.yml (revert to snapshot/linked clone base)&lt;br /&gt;
* [ ] &#039;&#039;&#039;C.8&#039;&#039;&#039; Test all playbooks end-to-end with a single student ID&lt;br /&gt;
&lt;br /&gt;
=== NoVNC Portal ===&lt;br /&gt;
* [ ] &#039;&#039;&#039;D.1&#039;&#039;&#039; Evaluate Kimchi vs Apache Guacamole vs custom NoVNC proxy&lt;br /&gt;
* [ ] &#039;&#039;&#039;D.2&#039;&#039;&#039; Install and configure chosen NoVNC solution&lt;br /&gt;
* [ ] &#039;&#039;&#039;D.3&#039;&#039;&#039; Integrate NoVNC with student authentication (LDAP, local wiki accounts, or simple token-based)&lt;br /&gt;
* [ ] &#039;&#039;&#039;D.4&#039;&#039;&#039; Build student dashboard: list of phases/labs, &amp;quot;Launch Lab&amp;quot; button, countdown timer&lt;br /&gt;
* [ ] &#039;&#039;&#039;D.5&#039;&#039;&#039; Test 5 concurrent NoVNC sessions for stability&lt;br /&gt;
* [ ] &#039;&#039;&#039;D.6&#039;&#039;&#039; Test 20 concurrent NoVNC sessions for performance&lt;br /&gt;
&lt;br /&gt;
=== AI Evaluation Pipeline ===&lt;br /&gt;
* [ ] &#039;&#039;&#039;E.1&#039;&#039;&#039; Deploy Qwen 3.5 Instruct Coder 9GB on GPU box or 200-core host&lt;br /&gt;
* [ ] &#039;&#039;&#039;E.2&#039;&#039;&#039; Build pytest + Selenium test suite for pfSense GUI validation&lt;br /&gt;
* [ ] &#039;&#039;&#039;E.3&#039;&#039;&#039; Build SSH-based health check suite for VM/LXC connectivity&lt;br /&gt;
* [ ] &#039;&#039;&#039;E.4&#039;&#039;&#039; Integrate DeepSeek or OpenCode for playbook syntax validation&lt;br /&gt;
* [ ] &#039;&#039;&#039;E.5&#039;&#039;&#039; Create readiness dashboard (pass/fail per lab, resource usage graphs)&lt;br /&gt;
* [ ] &#039;&#039;&#039;E.6&#039;&#039;&#039; Schedule automated nightly tests of all lab environments&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Phase 2: Curriculum Development ==&lt;br /&gt;
Design the student-facing training program.&lt;br /&gt;
&lt;br /&gt;
=== Introduction Course (Most Common Use Case) ===&lt;br /&gt;
* [x] &#039;&#039;&#039;E.1&#039;&#039;&#039; Define &amp;quot;Setting Up a Firewall for Yourself&amp;quot; scope: home office / small business&lt;br /&gt;
* [x] &#039;&#039;&#039;E.2&#039;&#039;&#039; Write Module 0: Why You Need a Firewall (threats, NAT basics, basic topology)&lt;br /&gt;
* [x] &#039;&#039;&#039;E.3&#039;&#039;&#039; Write Module 1: Install pfSense on Old PC or VM (hardware requirements, USB install, first boot wizard)&lt;br /&gt;
* [x] &#039;&#039;&#039;E.4&#039;&#039;&#039; Write Module 2: Basic WAN + LAN Setup (DHCP, DNS, first internet connection)&lt;br /&gt;
* [x] &#039;&#039;&#039;E.5&#039;&#039;&#039; Write Module 3: Essential Firewall Rules (block incoming, allow outgoing, ICMP)&lt;br /&gt;
* [x] &#039;&#039;&#039;E.6&#039;&#039;&#039; Write Module 4: Port Forwarding for Common Services (game server, camera, NAS)&lt;br /&gt;
* [x] &#039;&#039;&#039;E.7&#039;&#039;&#039; Write Module 5: VPN for Remote Access (WireGuard road warrior setup)&lt;br /&gt;
* [x] &#039;&#039;&#039;E.8&#039;&#039;&#039; Write Module 6: Backup and Updates (config.xml backup, update schedule)&lt;br /&gt;
* [x] &#039;&#039;&#039;E.9&#039;&#039;&#039; Create hands-on lab for Introduction Course (single pfSense + 1 client VM)&lt;br /&gt;
* [ ] &#039;&#039;&#039;E.10&#039;&#039;&#039; Record or source video walkthroughs for each module&lt;br /&gt;
&lt;br /&gt;
=== Full FUND001 Adaptation ===&lt;br /&gt;
* [x] &#039;&#039;&#039;F.1&#039;&#039;&#039; Map each SEG slide deck to a wiki training page with summary + key takeaways&lt;br /&gt;
* [x] &#039;&#039;&#039;F.2&#039;&#039;&#039; Adapt Netgate labs from physical/virtualbox environment to KVM/Ansible environment&lt;br /&gt;
* [ ] &#039;&#039;&#039;F.3&#039;&#039;&#039; Update IP addressing schema for Comfac virtual lab (avoid conflicts with production)&lt;br /&gt;
* [ ] &#039;&#039;&#039;F.4&#039;&#039;&#039; Write pre-lab briefing pages (what you&#039;ll learn, expected outcomes)&lt;br /&gt;
* [ ] &#039;&#039;&#039;F.5&#039;&#039;&#039; Write post-lab review pages (common mistakes, verification steps, &amp;quot;show me&amp;quot; checklist)&lt;br /&gt;
* [ ] &#039;&#039;&#039;F.6&#039;&#039;&#039; Create quiz questions for each phase (5–10 questions, auto-graded if possible)&lt;br /&gt;
&lt;br /&gt;
== Phase 3: Pilot &amp;amp; Refinement ==&lt;br /&gt;
Run the training with a small group before full rollout.&lt;br /&gt;
&lt;br /&gt;
=== Internal Pilot ===&lt;br /&gt;
* [ ] &#039;&#039;&#039;G.1&#039;&#039;&#039; Recruit 3–5 internal Comfac IT staff as pilot students&lt;br /&gt;
* [ ] &#039;&#039;&#039;G.2&#039;&#039;&#039; Run Phase 1 (Foundations) with pilot group — collect feedback&lt;br /&gt;
* [ ] &#039;&#039;&#039;G.3&#039;&#039;&#039; Run Phase 2 (NAT &amp;amp; Services) with pilot group — collect feedback&lt;br /&gt;
* [ ] &#039;&#039;&#039;G.4&#039;&#039;&#039; Run one VPN lab (IPsec or OpenVPN) with pilot group — test resource limits&lt;br /&gt;
* [ ] &#039;&#039;&#039;G.5&#039;&#039;&#039; Document all bugs, confusion points, and timeouts&lt;br /&gt;
* [ ] &#039;&#039;&#039;G.6&#039;&#039;&#039; Refine playbooks and wiki pages based on pilot feedback&lt;br /&gt;
&lt;br /&gt;
=== Resource Tuning ===&lt;br /&gt;
* [ ] &#039;&#039;&#039;H.1&#039;&#039;&#039; Measure actual CPU/RAM/disk usage per student during pilot&lt;br /&gt;
* [ ] &#039;&#039;&#039;H.2&#039;&#039;&#039; Adjust VM specs if over- or under-provisioned&lt;br /&gt;
* [ ] &#039;&#039;&#039;H.3&#039;&#039;&#039; Test memory overcommit ratios for safe concurrency scaling&lt;br /&gt;
* [ ] &#039;&#039;&#039;H.4&#039;&#039;&#039; Document maximum safe concurrent student count&lt;br /&gt;
&lt;br /&gt;
== Phase 4: Deployment &amp;amp; Operations ==&lt;br /&gt;
Prepare for regular training delivery.&lt;br /&gt;
&lt;br /&gt;
=== Student Onboarding ===&lt;br /&gt;
* [ ] &#039;&#039;&#039;I.1&#039;&#039;&#039; Create student onboarding guide (how to access portal, use NoVNC, reset lab)&lt;br /&gt;
* [ ] &#039;&#039;&#039;I.2&#039;&#039;&#039; Create instructor guide (how to monitor progress, assist students, grade labs)&lt;br /&gt;
* [ ] &#039;&#039;&#039;I.3&#039;&#039;&#039; Set up scheduling system (book lab time slots, prevent over-allocation)&lt;br /&gt;
* [ ] &#039;&#039;&#039;I.4&#039;&#039;&#039; Create completion certificates or badges&lt;br /&gt;
&lt;br /&gt;
=== Monitoring &amp;amp; Maintenance ===&lt;br /&gt;
* [ ] &#039;&#039;&#039;J.1&#039;&#039;&#039; Set up host monitoring (Prometheus/Grafana or simple `libvirt` stats)&lt;br /&gt;
* [ ] &#039;&#039;&#039;J.2&#039;&#039;&#039; Configure alerts for host resource exhaustion&lt;br /&gt;
* [ ] &#039;&#039;&#039;J.3&#039;&#039;&#039; Schedule weekly base image updates (pfSense patches, OS updates)&lt;br /&gt;
* [ ] &#039;&#039;&#039;J.4&#039;&#039;&#039; Document disaster recovery (rebuild host from Ansible, restore golden images)&lt;br /&gt;
&lt;br /&gt;
== Quick Status Dashboard ==&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Phase !! Status !! % Complete !! Blockers&lt;br /&gt;
|-&lt;br /&gt;
| Phase 0: Material Conversion || 🟢 Done (22/23) || 96% || Pending: reference PDF, support files, videos&lt;br /&gt;
|-&lt;br /&gt;
| Phase 1: Infrastructure Setup || 🟡 In Progress || 15% || Resource analysis complete; need host access for image builds&lt;br /&gt;
|-&lt;br /&gt;
| Phase 2: Curriculum Development || 🟡 In Progress || 65% || Need video recordings, quizzes, pre/post lab pages&lt;br /&gt;
|-&lt;br /&gt;
| Phase 3: Pilot &amp;amp; Refinement || 🔴 Not Started || 0% || Waiting on Phase 1 + 2&lt;br /&gt;
|-&lt;br /&gt;
| Phase 4: Deployment &amp;amp; Operations || 🔴 Not Started || 0% || Waiting on Phase 3&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Resource Summary ==&lt;br /&gt;
&#039;&#039;&#039;Per-student minimum:&#039;&#039;&#039; 6 vCPUs, 6.5 GB RAM, 62 GB disk&lt;br /&gt;
&#039;&#039;&#039;Per-student full lab:&#039;&#039;&#039; 10 vCPUs, 10.5 GB RAM, 110 GB disk&lt;br /&gt;
&#039;&#039;&#039;200-core / 1TB capacity:&#039;&#039;&#039; 20–40 concurrent students (conservative to optimized)&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Next Actions (This Week):&#039;&#039;&#039;&lt;br /&gt;
# Summarize the-pfsense-documentation.pdf into a reference page&lt;br /&gt;
# Document WindowsTrainingSupportFiles.zip contents&lt;br /&gt;
# Catalog training video timestamps&lt;br /&gt;
# Begin Ansible playbook drafting for Lab 1 environment&lt;br /&gt;
# Evaluate Kimchi vs Guacamole for NoVNC portal&lt;/div&gt;</summary>
		<author><name>Justinaquino</name></author>
	</entry>
	<entry>
		<id>https://mediawiki.comfac.net/index.php?title=Networking_PfSense_Index&amp;diff=249</id>
		<title>Networking PfSense Index</title>
		<link rel="alternate" type="text/html" href="https://mediawiki.comfac.net/index.php?title=Networking_PfSense_Index&amp;diff=249"/>
		<updated>2026-04-23T10:10:50Z</updated>

		<summary type="html">&lt;p&gt;Justinaquino: Update Resource Estimates: Add Linux FOSS vs Windows stacks, 20% utilization target, container analysis, AI evaluation, exercise-limited deployment&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__NOTOC__&lt;br /&gt;
&amp;lt;div style=&amp;quot;background:#f0f7ff; border:1px solid #b8d4f0; border-radius:4px; padding:12px 16px; margin-bottom:20px;&amp;quot;&amp;gt;&lt;br /&gt;
&#039;&#039;&#039;Consolidated index&#039;&#039;&#039; for all networking infrastructure guides, pfSense documentation, DNS/ad-blocking resources, and network equipment references at Comfac IT.&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== pfSense Core Guides ==&lt;br /&gt;
* [[pfSense Sales Training Material]] — Product knowledge and sales positioning for Netgate/pfSense hardware and software&lt;br /&gt;
* [[Modern Guide: pfSense Captive Portal with FreeRADIUS &amp;amp; ACME]] — Enterprise Wi-Fi captive portal with RADIUS authentication and Let&#039;s Encrypt SSL&lt;br /&gt;
* [[pfSense CE → pfSense Plus Upgrade Guide]] — Step-by-step migration from Community Edition to pfSense Plus&lt;br /&gt;
* [[SOP: Network Troubleshooting &amp;amp; pfSense Monitoring 251130]] — Standard operating procedures for network diagnostics and pfSense health monitoring&lt;br /&gt;
&lt;br /&gt;
== Network Infrastructure &amp;amp; Equipment ==&lt;br /&gt;
* [[Tplink Mikrotik Equivalent]] — Cross-reference of TP-Link and MikroTik models for network deployments&lt;br /&gt;
* [[Controller Systems 251213-01]] — Network and infrastructure controller systems&lt;br /&gt;
* [[Power Distribution Tree 251213]] — Power architecture for network and server racks&lt;br /&gt;
* [[NPM Migration to Homelab VPS Relay 260401]] — Nginx Proxy Manager migration; VPS as iptables/ZeroTier relay with homelab redundancy&lt;br /&gt;
&lt;br /&gt;
== DNS, Ad Blocking &amp;amp; Pi-hole ==&lt;br /&gt;
* [https://github.com/Comfac-Global-Group/pi-hole Comfac Pi-hole Repository] — GitHub repository for Pi-hole DNS sinkhole deployment&lt;br /&gt;
* [https://github.com/Comfac-Global-Group/pi-hole/blob/master/How%20this%20Works.md How Pi-hole Works] — Technical overview of the Pi-hole DNS filtering architecture&lt;br /&gt;
&lt;br /&gt;
== Training &amp;amp; Skills ==&lt;br /&gt;
* [[Skills and Competencies for IT Staff Trained in pfSense]] — Required competencies and certification path for pfSense-administering staff&lt;br /&gt;
* [[PfSense Training Project Tracker]] — &#039;&#039;&#039;Implementation tracker&#039;&#039;&#039; for the NoVNC virtual lab, material conversion, and curriculum development&lt;br /&gt;
&lt;br /&gt;
== Practical Training System (NoVNC Virtual Lab) ==&lt;br /&gt;
&#039;&#039;&#039;Goal:&#039;&#039;&#039; Build a self-hosted, virtualized pfSense training environment where Comfac trainees can learn hands-on without physical hardware. All labs run via NoVNC in a browser, orchestrated on Comfac&#039;s 200-core / 1TB RAM machine.&lt;br /&gt;
&lt;br /&gt;
=== Training Architecture Vision ===&lt;br /&gt;
Each student gets an isolated virtual network sandbox containing:&lt;br /&gt;
* 2× pfSense VMs (HQ HA pair or HQ + Branch)&lt;br /&gt;
* 1–2× Client VMs (Windows/Linux desktop)&lt;br /&gt;
* 1× Server VM (web/DNS/target)&lt;br /&gt;
* 1× Simulated &amp;quot;Internet&amp;quot; router VM&lt;br /&gt;
&lt;br /&gt;
Access is through a NoVNC web portal. Students click a lab, and their environment is provisioned automatically via Ansible/Terraform or Docker/KVM.&lt;br /&gt;
&lt;br /&gt;
=== Resource Estimates Per Student ===&lt;br /&gt;
&lt;br /&gt;
==== Stack A: Pure Linux / FOSS (Recommended for Comfac) ====&lt;br /&gt;
All components run on open-source software. Clients are lightweight Linux VMs or LXC containers. No Windows licensing required.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Component !! vCPUs !! RAM !! Disk !! Virtualization !! Notes&lt;br /&gt;
|-&lt;br /&gt;
| pfSense VM || 1 || 512 MB || 4 GB || KVM microVM || FreeBSD requires KVM; use tiny QEMU args&lt;br /&gt;
|-&lt;br /&gt;
| Linux Client (LXC) || 0.5 || 256 MB || 1 GB || LXC container || Alpine or Debian with XFCE; NoVNC access&lt;br /&gt;
|-&lt;br /&gt;
| Linux Server (LXC) || 0.5 || 256 MB || 1 GB || LXC container || nginx, BIND, or simple Python HTTP&lt;br /&gt;
|-&lt;br /&gt;
| Internet Router (LXC) || 0.5 || 128 MB || 0.5 GB || LXC container || Static routes only; FRR optional&lt;br /&gt;
|-&lt;br /&gt;
| NoVNC Proxy (Docker) || 0.5 || 256 MB || 0.5 GB || Docker container || websockify + nginx&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;Total per student&#039;&#039;&#039; || &#039;&#039;&#039;3&#039;&#039;&#039; || &#039;&#039;&#039;1.4 GB&#039;&#039;&#039; || &#039;&#039;&#039;7 GB&#039;&#039;&#039; || — || Thin-provisioned; linked clones&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== Stack B: Windows Client (Full Desktop Experience) ====&lt;br /&gt;
For trainees who need a Windows desktop for browser-based management or specific client software.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Component !! vCPUs !! RAM !! Disk !! Virtualization !! Notes&lt;br /&gt;
|-&lt;br /&gt;
| pfSense VM || 2 || 1 GB || 8 GB || KVM || Standard qcow2 image&lt;br /&gt;
|-&lt;br /&gt;
| Windows Client || 2 || 4 GB || 40 GB || KVM || Windows 10/11 thin client; needs GPU if GUI-heavy&lt;br /&gt;
|-&lt;br /&gt;
| Ubuntu Server || 1 || 1 GB || 10 GB || KVM || Full VM for compatibility&lt;br /&gt;
|-&lt;br /&gt;
| Internet Router || 1 || 512 MB || 4 GB || KVM || Ubuntu with static routes&lt;br /&gt;
|-&lt;br /&gt;
| NoVNC Proxy || 0.5 || 256 MB || 0.5 GB || Docker || Shared across students&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;Total per student&#039;&#039;&#039; || &#039;&#039;&#039;6.5&#039;&#039;&#039; || &#039;&#039;&#039;6.8 GB&#039;&#039;&#039; || &#039;&#039;&#039;63 GB&#039;&#039;&#039; || — || Higher resource cost&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== Stack C: Hybrid — Containers for Linux Router Exercises ====&lt;br /&gt;
For basic routing/firewall concept labs only (not pfSense-specific), replace pfSense with Linux routers in containers.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Component !! vCPUs !! RAM !! Disk !! Virtualization !! Notes&lt;br /&gt;
|-&lt;br /&gt;
| Linux Router (LXC) || 0.5 || 128 MB || 0.5 GB || LXC || Alpine + iptables/nftables + WireGuard&lt;br /&gt;
|-&lt;br /&gt;
| Linux Client (LXC) || 0.5 || 256 MB || 1 GB || LXC || Alpine or Debian&lt;br /&gt;
|-&lt;br /&gt;
| Linux Server (LXC) || 0.5 || 256 MB || 1 GB || LXC || nginx, BIND&lt;br /&gt;
|-&lt;br /&gt;
| Internet Router (LXC) || 0.5 || 128 MB || 0.5 GB || LXC || Static routes&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;Total per student&#039;&#039;&#039; || &#039;&#039;&#039;2&#039;&#039;&#039; || &#039;&#039;&#039;768 MB&#039;&#039;&#039; || &#039;&#039;&#039;3 GB&#039;&#039;&#039; || — || Cannot teach pfSense GUI; teaches concepts only&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Important:&#039;&#039;&#039; pfSense is FreeBSD-based and cannot run in Linux containers (Docker/LXC). Stack C is suitable for teaching routing/VPN concepts using Linux tools (iptables, nftables, WireGuard, strongSwan), but not for teaching the pfSense web interface. For pfSense GUI training, use Stack A or B.&lt;br /&gt;
&lt;br /&gt;
=== Server Capacity: 20% Utilization Target ===&lt;br /&gt;
The goal is to run the training environment using only 20% of the 200-core / 1TB RAM server, leaving 80% for other Comfac workloads (ERPNext, AI models, file services).&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;20% of available resources:&#039;&#039;&#039;&lt;br /&gt;
* 40 vCPUs (20% of 200)&lt;br /&gt;
* 200 GB RAM (20% of 1 TB)&lt;br /&gt;
* ~2 TB SSD (assuming 10 TB array, 20% = 2 TB)&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Concurrent student capacity at 20% utilization:&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Stack !! Per-Student Resources !! Students at 20% CPU !! Students at 20% RAM !! Limiting Factor&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;A: Pure Linux&#039;&#039;&#039; || 3 vCPU / 1.4 GB || 13 || 142 || &#039;&#039;&#039;CPU: 13 students&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;B: Windows&#039;&#039;&#039; || 6.5 vCPU / 6.8 GB || 6 || 29 || &#039;&#039;&#039;CPU: 6 students&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;C: Containers&#039;&#039;&#039; || 2 vCPU / 0.8 GB || 20 || 250 || &#039;&#039;&#039;CPU: 20 students&#039;&#039;&#039;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Recommendation:&#039;&#039;&#039; Use Stack A (Pure Linux) for all labs. This yields ~13 concurrent students within the 20% budget, or up to ~30 students if spread across time slots (not everyone needs a lab simultaneously).&lt;br /&gt;
&lt;br /&gt;
=== Smaller Server: What Hardware for 10 Students? ===&lt;br /&gt;
If buying a dedicated training server instead of using the 200-core machine:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Stack !! CPU !! RAM !! Storage !! NICs !! Example Hardware&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;A: Pure Linux&#039;&#039;&#039; || 32 cores || 32 GB || 500 GB NVMe || 2x 1GbE || Used Dell R630/R640 (~$300-500)&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;B: Windows&#039;&#039;&#039; || 64 cores || 96 GB || 1 TB NVMe || 2x 1GbE || Used Dell R740 / HP DL360 (~$600-900)&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;C: Containers&#039;&#039;&#039; || 16 cores || 16 GB || 250 GB NVMe || 2x 1GbE || Old desktop + Intel NIC (~$100-200)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Exercise-Limited Deployment (Right-Sizing per Lab) ===&lt;br /&gt;
Not every lab needs the full sandbox. Deploy only what is needed:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Lab !! Stack A Deployed !! vCPUs Used !! RAM Used !! Disk Used&lt;br /&gt;
|-&lt;br /&gt;
| Day 1 — Theory only || None (wiki only) || 0 || 0 || 0&lt;br /&gt;
|-&lt;br /&gt;
| Lab 1 (Intro/Backup) || 1 pfSense + 1 client || 1.5 || 768 MB || 5 GB&lt;br /&gt;
|-&lt;br /&gt;
| Lab 2 (Rules) || 1 pfSense + 1 client + 1 server || 2 || 1 GB || 6 GB&lt;br /&gt;
|-&lt;br /&gt;
| Lab 3 (NAT) || 1 pfSense + 1 server + router || 2 || 900 MB || 5.5 GB&lt;br /&gt;
|-&lt;br /&gt;
| Lab 4 (Services) || 2 pfSense + 2 clients + 1 server || 4 || 2.1 GB || 11 GB&lt;br /&gt;
|-&lt;br /&gt;
| Lab 5-7 (VPNs) || 2 pfSense + 2 clients || 3 || 1.5 GB || 10 GB&lt;br /&gt;
|-&lt;br /&gt;
| Lab 8 (Multi-WAN) || 1 pfSense + 1 client + router || 2 || 900 MB || 5.5 GB&lt;br /&gt;
|-&lt;br /&gt;
| Lab 9 (Shaping) || 1 pfSense + 2 clients || 2.5 || 1.3 GB || 6 GB&lt;br /&gt;
|-&lt;br /&gt;
| Lab 10 (HA) || 2 pfSense + 1 client || 2.5 || 1.3 GB || 9 GB&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Scheduling strategy:&#039;&#039;&#039; If students are scheduled in 1-hour slots and labs are provisioned on-demand, the same 40 vCPUs / 200 GB RAM can serve 40-60 student-slots per day (not concurrently, but sequentially).&lt;br /&gt;
&lt;br /&gt;
=== Phase 1: Resource Setup Validation ===&lt;br /&gt;
Before full student rollout, validate the resource model with these tests:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Test !! Purpose !! Command / Method !! Pass Criteria&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;T1: MicroVM Boot&#039;&#039;&#039; || Verify pfSense runs in 512MB/1vCPU || qemu-system-x86_64 -m 512 -smp 1 -drive file=pfsense.qcow2 || Boots to login in &amp;lt; 120s&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;T2: LXC Container Spawn&#039;&#039;&#039; || Verify sub-1GB containers work || lxc launch images:alpine/3.19 client || Starts in &amp;lt; 10s; SSH reachable&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;T3: NoVNC Session&#039;&#039;&#039; || Verify one student can access console || websockify + TigerVNC || 640x480 responsive; &amp;lt; 500ms latency&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;T4: 5 Concurrent Students&#039;&#039;&#039; || Validate 20% CPU/RAM budget || Ansible: deploy 5x Stack A || Total &amp;lt; 8 vCPU, &amp;lt; 7 GB RAM&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;T5: Lab 4 Full Deploy&#039;&#039;&#039; || Heaviest lab (2 pfSense + 2 clients + server) || ansible-playbook lab4.yml || Deploys in &amp;lt; 5 min; all VMs pingable&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;T6: Snapshot Reset Speed&#039;&#039;&#039; || Time to reset between students || virsh snapshot-revert + virsh start || &amp;lt; 60 seconds total&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;T7: AI Evaluation Readiness&#039;&#039;&#039; || Validate environment for automated testing || See AI Evaluation section below || All labs pass synthetic health checks&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AI Evaluation: Automated Readiness Testing ===&lt;br /&gt;
Before students arrive, AI agents will validate that each lab environment is functional. This replaces manual smoke-testing.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Evaluation Stack:&#039;&#039;&#039;&lt;br /&gt;
* &#039;&#039;&#039;Qwen 3.5 Instruct Coder (9GB)&#039;&#039;&#039; — Runs locally on the 200-core server or a dedicated GPU box. Evaluates: pfSense GUI accessibility, rule syntax, VPN handshake status, config.xml validity.&lt;br /&gt;
* &#039;&#039;&#039;DeepSeek Coder (optional)&#039;&#039;&#039; — Cloud or local. Validates Ansible playbook correctness, network topology logic, resource allocation math.&lt;br /&gt;
* &#039;&#039;&#039;OpenCode (local agent)&#039;&#039;&#039; — Executes shell commands inside VMs/containers via SSH/API. Performs end-to-end tests: ping, curl, ipsec status, wg show, etc.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Automated Test Sequence (per lab):&#039;&#039;&#039;&lt;br /&gt;
# Deploy lab environment via Ansible&lt;br /&gt;
# AI agent logs into pfSense (admin credentials)&lt;br /&gt;
# Screenshot/check each configured page matches expected state&lt;br /&gt;
# Run connectivity tests from client VMs&lt;br /&gt;
# Verify services are listening on correct ports&lt;br /&gt;
# Generate pass/fail report with specific error details&lt;br /&gt;
# Destroy lab environment&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Benefits:&#039;&#039;&#039;&lt;br /&gt;
* Catch broken base images before students arrive&lt;br /&gt;
* Validate that config.xml injections work correctly&lt;br /&gt;
* Ensure network isolation between students&lt;br /&gt;
* Measure actual resource usage vs. estimates&lt;br /&gt;
* Generate readiness dashboard for instructors&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Implementation:&#039;&#039;&#039;&lt;br /&gt;
* Python + Selenium/Playwright for pfSense GUI testing&lt;br /&gt;
* Paramiko/fabric for SSH-based VM tests&lt;br /&gt;
* pytest framework for test organization&lt;br /&gt;
* GitHub Actions or local Cron for scheduled runs&lt;br /&gt;
* Output: Markdown report posted to wiki or sent via Matrix/Email&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Related Infrastructure ==&lt;br /&gt;
* [[System Hardening Strategy: Win2Lin Migration &amp;amp; Infrastructure 251129]] — Server migration and infrastructure hardening&lt;br /&gt;
* [[Introduction: Why Self-Host Your Email?]] — Self-hosted email infrastructure context&lt;br /&gt;
* [[Mailcow + Thunderbird Setup Guide (Email + Calendar)]] — Email server deployment&lt;br /&gt;
* [[Portainer to Docker Compose Migration Guide]] — Container orchestration for network services&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&#039;&#039;This index consolidates networking resources previously scattered across the [[Main Page]]. Last updated: 260423.&#039;&#039;&lt;/div&gt;</summary>
		<author><name>Justinaquino</name></author>
	</entry>
	<entry>
		<id>https://mediawiki.comfac.net/index.php?title=PfSense_Training_Project_Tracker&amp;diff=248</id>
		<title>PfSense Training Project Tracker</title>
		<link rel="alternate" type="text/html" href="https://mediawiki.comfac.net/index.php?title=PfSense_Training_Project_Tracker&amp;diff=248"/>
		<updated>2026-04-23T07:22:44Z</updated>

		<summary type="html">&lt;p&gt;Justinaquino: Update tracker - Phase 0 material conversion 96% complete&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__NOTOC__&lt;br /&gt;
&amp;lt;div style=&amp;quot;background:#fff8e1; border:1px solid #ffcc80; border-radius:4px; padding:12px 16px; margin-bottom:20px;&amp;quot;&amp;gt;&lt;br /&gt;
&#039;&#039;&#039;Project Tracker&#039;&#039;&#039; for Comfac&#039;s pfSense Practical Training System implementation. This page tracks all tasks from material conversion to infrastructure deployment and course delivery.&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Phase 0: Material Conversion (FUND001 → Wiki) ==&lt;br /&gt;
Convert all Netgate FUND001 training PDFs into CITWiki pages with detailed summaries. Each wiki page should include: learning objectives, key concepts, step-by-step lab instructions adapted for virtual environment, and troubleshooting tips.&lt;br /&gt;
&lt;br /&gt;
=== Slide Decks ===&lt;br /&gt;
* [x] &#039;&#039;&#039;SEG1 — Introduction to pfSense&#039;&#039;&#039; → [[Training: pfSense Introduction]]&lt;br /&gt;
* [x] &#039;&#039;&#039;SEG2 — Interfaces, VIPs, and Rules&#039;&#039;&#039; → [[Training: Interfaces and Firewall Rules]]&lt;br /&gt;
* [x] &#039;&#039;&#039;SEG3 — NAT and VIPs&#039;&#039;&#039; → [[Training: NAT and Virtual IPs]]&lt;br /&gt;
* [x] &#039;&#039;&#039;SEG4 — pfSense Services&#039;&#039;&#039; → [[Training: pfSense Services]]&lt;br /&gt;
* [x] &#039;&#039;&#039;SEG5 — VPNs and IPsec&#039;&#039;&#039; → [[Training: IPsec VPN]]&lt;br /&gt;
* [x] &#039;&#039;&#039;SEG6 — OpenVPN&#039;&#039;&#039; → [[Training: OpenVPN]]&lt;br /&gt;
* [x] &#039;&#039;&#039;SEG7 — WireGuard&#039;&#039;&#039; → [[Training: WireGuard]]&lt;br /&gt;
* [x] &#039;&#039;&#039;SEG8 — Multi-WAN&#039;&#039;&#039; → [[Training: Multi-WAN]]&lt;br /&gt;
* [x] &#039;&#039;&#039;SEG9 — Traffic Shaping&#039;&#039;&#039; → [[Training: Traffic Shaping]]&lt;br /&gt;
* [x] &#039;&#039;&#039;SEG10 — High Availability&#039;&#039;&#039; → [[Training: High Availability]]&lt;br /&gt;
* [x] &#039;&#039;&#039;SEG11 — Other Features&#039;&#039;&#039; → [[Training: Monitoring and Packages]]&lt;br /&gt;
&lt;br /&gt;
=== Labs ===&lt;br /&gt;
* [x] &#039;&#039;&#039;Lab 1 — Intro, Getting Started, Backup/Restore&#039;&#039;&#039; → [[Training Lab 1: Introduction and Backup Restore]]&lt;br /&gt;
* [x] &#039;&#039;&#039;Lab 2 — Interfaces, Firewall Rules, Aliases&#039;&#039;&#039; → [[Training Lab 2: Firewall Rules and Aliases]]&lt;br /&gt;
* [x] &#039;&#039;&#039;Lab 3 — Virtual IPs and NAT&#039;&#039;&#039; → [[Training Lab 3: NAT and Virtual IPs]]&lt;br /&gt;
* [x] &#039;&#039;&#039;Lab 4 — Services and Branch Network Setup&#039;&#039;&#039; → [[Training Lab 4: Services and Branch Network]]&lt;br /&gt;
* [x] &#039;&#039;&#039;Lab 5 — IPsec&#039;&#039;&#039; → [[Training Lab 5: IPsec VPN]]&lt;br /&gt;
* [x] &#039;&#039;&#039;Lab 6 — OpenVPN&#039;&#039;&#039; → [[Training Lab 6: OpenVPN]]&lt;br /&gt;
* [x] &#039;&#039;&#039;Lab 7 — WireGuard&#039;&#039;&#039; → [[Training Lab 7: WireGuard]]&lt;br /&gt;
* [x] &#039;&#039;&#039;Lab 8 — Multi-WAN&#039;&#039;&#039; → [[Training Lab 8: Multi-WAN]]&lt;br /&gt;
* [x] &#039;&#039;&#039;Lab 9 — Traffic Shaping&#039;&#039;&#039; → [[Training Lab 9: Traffic Shaping]]&lt;br /&gt;
* [x] &#039;&#039;&#039;Lab 10 — High Availability&#039;&#039;&#039; → [[Training Lab 10: High Availability]]&lt;br /&gt;
&lt;br /&gt;
=== Comfac Original Content ===&lt;br /&gt;
* [x] &#039;&#039;&#039;Introduction Training (Module 0)&#039;&#039;&#039; → [[Training: Setting Up a Firewall for Yourself]] — Personal/small business firewall&lt;br /&gt;
* [ ] &#039;&#039;&#039;the-pfsense-documentation.pdf&#039;&#039;&#039; → Summarize into [[Training: pfSense Complete Reference]] or link as external reference&lt;br /&gt;
* [ ] &#039;&#039;&#039;WindowsTrainingSupportFiles.zip&#039;&#039;&#039; → Extract and document client software requirements ([[Training: Client Software Requirements]])&lt;br /&gt;
* [ ] &#039;&#039;&#039;Training Videos (4× .mkv)&#039;&#039;&#039; → Catalog timestamps and link from relevant wiki pages&lt;br /&gt;
&lt;br /&gt;
== Phase 1: Infrastructure Setup ==&lt;br /&gt;
Build the virtual training environment on Comfac&#039;s 200-core / 1TB RAM machine.&lt;br /&gt;
&lt;br /&gt;
=== Host Preparation ===&lt;br /&gt;
* [ ] &#039;&#039;&#039;A.1&#039;&#039;&#039; Install Ubuntu Server LTS on 200-core host&lt;br /&gt;
* [ ] &#039;&#039;&#039;A.2&#039;&#039;&#039; Configure KVM/libvirt with storage pools (NVMe for images, SSD for ephemeral clones)&lt;br /&gt;
* [ ] &#039;&#039;&#039;A.3&#039;&#039;&#039; Set up network bridges: `br-mgmt`, `br-lan`, `br-wan`, `br-dmz`, `br-internet`&lt;br /&gt;
* [ ] &#039;&#039;&#039;A.4&#039;&#039;&#039; Configure VLANs for student isolation (one VLAN per student or per lab)&lt;br /&gt;
* [ ] &#039;&#039;&#039;A.5&#039;&#039;&#039; Install and configure Ansible controller (host or container)&lt;br /&gt;
&lt;br /&gt;
=== Base Images ===&lt;br /&gt;
* [ ] &#039;&#039;&#039;B.1&#039;&#039;&#039; Download pfSense CE ISO and create qcow2 golden image (2 vCPU, 1 GB RAM, 8 GB disk)&lt;br /&gt;
* [ ] &#039;&#039;&#039;B.2&#039;&#039;&#039; Create Ubuntu Server 22.04/24.04 golden image (1 vCPU, 1 GB RAM, 10 GB disk)&lt;br /&gt;
* [ ] &#039;&#039;&#039;B.3&#039;&#039;&#039; Create Windows 10/11 thin client golden image (2 vCPU, 4 GB RAM, 40 GB disk) — OR decide to use Linux clients only&lt;br /&gt;
* [ ] &#039;&#039;&#039;B.4&#039;&#039;&#039; Create &amp;quot;Internet Router&amp;quot; golden image (Ubuntu with FRR/Quagga or simple static routes, 1 vCPU, 512 MB RAM)&lt;br /&gt;
* [ ] &#039;&#039;&#039;B.5&#039;&#039;&#039; Test each golden image boots and functions correctly&lt;br /&gt;
&lt;br /&gt;
=== Automation ===&lt;br /&gt;
* [ ] &#039;&#039;&#039;C.1&#039;&#039;&#039; Write Ansible playbook: `lab1-student-env.yml` (1 pfSense + 1 client)&lt;br /&gt;
* [ ] &#039;&#039;&#039;C.2&#039;&#039;&#039; Write Ansible playbook: `lab2-student-env.yml` (1 pfSense + 1 client + 1 server)&lt;br /&gt;
* [ ] &#039;&#039;&#039;C.3&#039;&#039;&#039; Write Ansible playbook: `lab3-student-env.yml` (1 pfSense + 1 server + internet)&lt;br /&gt;
* [ ] &#039;&#039;&#039;C.4&#039;&#039;&#039; Write Ansible playbook: `lab4-student-env.yml` (2 pfSense + 2 clients + 1 server)&lt;br /&gt;
* [ ] &#039;&#039;&#039;C.5&#039;&#039;&#039; Write Ansible playbooks for Labs 5–10 (VPNs, Multi-WAN, Shaping, HA)&lt;br /&gt;
* [ ] &#039;&#039;&#039;C.6&#039;&#039;&#039; Write Ansible playbook: `cleanup-student-env.yml` (destroy VMs, free resources)&lt;br /&gt;
* [ ] &#039;&#039;&#039;C.7&#039;&#039;&#039; Write Ansible playbook: `reset-student-env.yml` (revert to snapshot/linked clone base)&lt;br /&gt;
* [ ] &#039;&#039;&#039;C.8&#039;&#039;&#039; Test all playbooks end-to-end with a single student ID&lt;br /&gt;
&lt;br /&gt;
=== NoVNC Portal ===&lt;br /&gt;
* [ ] &#039;&#039;&#039;D.1&#039;&#039;&#039; Evaluate Kimchi vs Apache Guacamole vs custom NoVNC proxy&lt;br /&gt;
* [ ] &#039;&#039;&#039;D.2&#039;&#039;&#039; Install and configure chosen NoVNC solution&lt;br /&gt;
* [ ] &#039;&#039;&#039;D.3&#039;&#039;&#039; Integrate NoVNC with student authentication (LDAP, local wiki accounts, or simple token-based)&lt;br /&gt;
* [ ] &#039;&#039;&#039;D.4&#039;&#039;&#039; Build student dashboard: list of phases/labs, &amp;quot;Launch Lab&amp;quot; button, countdown timer&lt;br /&gt;
* [ ] &#039;&#039;&#039;D.5&#039;&#039;&#039; Test 5 concurrent NoVNC sessions for stability&lt;br /&gt;
* [ ] &#039;&#039;&#039;D.6&#039;&#039;&#039; Test 20 concurrent NoVNC sessions for performance&lt;br /&gt;
&lt;br /&gt;
== Phase 2: Curriculum Development ==&lt;br /&gt;
Design the student-facing training program.&lt;br /&gt;
&lt;br /&gt;
=== Introduction Course (Most Common Use Case) ===&lt;br /&gt;
* [x] &#039;&#039;&#039;E.1&#039;&#039;&#039; Define &amp;quot;Setting Up a Firewall for Yourself&amp;quot; scope: home office / small business&lt;br /&gt;
* [x] &#039;&#039;&#039;E.2&#039;&#039;&#039; Write Module 0: Why You Need a Firewall (threats, NAT basics, basic topology)&lt;br /&gt;
* [x] &#039;&#039;&#039;E.3&#039;&#039;&#039; Write Module 1: Install pfSense on Old PC or VM (hardware requirements, USB install, first boot wizard)&lt;br /&gt;
* [x] &#039;&#039;&#039;E.4&#039;&#039;&#039; Write Module 2: Basic WAN + LAN Setup (DHCP, DNS, first internet connection)&lt;br /&gt;
* [x] &#039;&#039;&#039;E.5&#039;&#039;&#039; Write Module 3: Essential Firewall Rules (block incoming, allow outgoing, ICMP)&lt;br /&gt;
* [x] &#039;&#039;&#039;E.6&#039;&#039;&#039; Write Module 4: Port Forwarding for Common Services (game server, camera, NAS)&lt;br /&gt;
* [x] &#039;&#039;&#039;E.7&#039;&#039;&#039; Write Module 5: VPN for Remote Access (WireGuard road warrior setup)&lt;br /&gt;
* [x] &#039;&#039;&#039;E.8&#039;&#039;&#039; Write Module 6: Backup and Updates (config.xml backup, update schedule)&lt;br /&gt;
* [x] &#039;&#039;&#039;E.9&#039;&#039;&#039; Create hands-on lab for Introduction Course (single pfSense + 1 client VM)&lt;br /&gt;
* [ ] &#039;&#039;&#039;E.10&#039;&#039;&#039; Record or source video walkthroughs for each module&lt;br /&gt;
&lt;br /&gt;
=== Full FUND001 Adaptation ===&lt;br /&gt;
* [x] &#039;&#039;&#039;F.1&#039;&#039;&#039; Map each SEG slide deck to a wiki training page with summary + key takeaways&lt;br /&gt;
* [x] &#039;&#039;&#039;F.2&#039;&#039;&#039; Adapt Netgate labs from physical/virtualbox environment to KVM/Ansible environment&lt;br /&gt;
* [ ] &#039;&#039;&#039;F.3&#039;&#039;&#039; Update IP addressing schema for Comfac virtual lab (avoid conflicts with production)&lt;br /&gt;
* [ ] &#039;&#039;&#039;F.4&#039;&#039;&#039; Write pre-lab briefing pages (what you&#039;ll learn, expected outcomes)&lt;br /&gt;
* [ ] &#039;&#039;&#039;F.5&#039;&#039;&#039; Write post-lab review pages (common mistakes, verification steps, &amp;quot;show me&amp;quot; checklist)&lt;br /&gt;
* [ ] &#039;&#039;&#039;F.6&#039;&#039;&#039; Create quiz questions for each phase (5–10 questions, auto-graded if possible)&lt;br /&gt;
&lt;br /&gt;
== Phase 3: Pilot &amp;amp; Refinement ==&lt;br /&gt;
Run the training with a small group before full rollout.&lt;br /&gt;
&lt;br /&gt;
=== Internal Pilot ===&lt;br /&gt;
* [ ] &#039;&#039;&#039;G.1&#039;&#039;&#039; Recruit 3–5 internal Comfac IT staff as pilot students&lt;br /&gt;
* [ ] &#039;&#039;&#039;G.2&#039;&#039;&#039; Run Phase 1 (Foundations) with pilot group — collect feedback&lt;br /&gt;
* [ ] &#039;&#039;&#039;G.3&#039;&#039;&#039; Run Phase 2 (NAT &amp;amp; Services) with pilot group — collect feedback&lt;br /&gt;
* [ ] &#039;&#039;&#039;G.4&#039;&#039;&#039; Run one VPN lab (IPsec or OpenVPN) with pilot group — test resource limits&lt;br /&gt;
* [ ] &#039;&#039;&#039;G.5&#039;&#039;&#039; Document all bugs, confusion points, and timeouts&lt;br /&gt;
* [ ] &#039;&#039;&#039;G.6&#039;&#039;&#039; Refine playbooks and wiki pages based on pilot feedback&lt;br /&gt;
&lt;br /&gt;
=== Resource Tuning ===&lt;br /&gt;
* [ ] &#039;&#039;&#039;H.1&#039;&#039;&#039; Measure actual CPU/RAM/disk usage per student during pilot&lt;br /&gt;
* [ ] &#039;&#039;&#039;H.2&#039;&#039;&#039; Adjust VM specs if over- or under-provisioned&lt;br /&gt;
* [ ] &#039;&#039;&#039;H.3&#039;&#039;&#039; Test memory overcommit ratios for safe concurrency scaling&lt;br /&gt;
* [ ] &#039;&#039;&#039;H.4&#039;&#039;&#039; Document maximum safe concurrent student count&lt;br /&gt;
&lt;br /&gt;
== Phase 4: Deployment &amp;amp; Operations ==&lt;br /&gt;
Prepare for regular training delivery.&lt;br /&gt;
&lt;br /&gt;
=== Student Onboarding ===&lt;br /&gt;
* [ ] &#039;&#039;&#039;I.1&#039;&#039;&#039; Create student onboarding guide (how to access portal, use NoVNC, reset lab)&lt;br /&gt;
* [ ] &#039;&#039;&#039;I.2&#039;&#039;&#039; Create instructor guide (how to monitor progress, assist students, grade labs)&lt;br /&gt;
* [ ] &#039;&#039;&#039;I.3&#039;&#039;&#039; Set up scheduling system (book lab time slots, prevent over-allocation)&lt;br /&gt;
* [ ] &#039;&#039;&#039;I.4&#039;&#039;&#039; Create completion certificates or badges&lt;br /&gt;
&lt;br /&gt;
=== Monitoring &amp;amp; Maintenance ===&lt;br /&gt;
* [ ] &#039;&#039;&#039;J.1&#039;&#039;&#039; Set up host monitoring (Prometheus/Grafana or simple `libvirt` stats)&lt;br /&gt;
* [ ] &#039;&#039;&#039;J.2&#039;&#039;&#039; Configure alerts for host resource exhaustion&lt;br /&gt;
* [ ] &#039;&#039;&#039;J.3&#039;&#039;&#039; Schedule weekly base image updates (pfSense patches, OS updates)&lt;br /&gt;
* [ ] &#039;&#039;&#039;J.4&#039;&#039;&#039; Document disaster recovery (rebuild host from Ansible, restore golden images)&lt;br /&gt;
&lt;br /&gt;
== Quick Status Dashboard ==&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Phase !! Status !! % Complete !! Blockers&lt;br /&gt;
|-&lt;br /&gt;
| Phase 0: Material Conversion || 🟢 Done (22/23) || 96% || Pending: reference PDF, support files, videos&lt;br /&gt;
|-&lt;br /&gt;
| Phase 1: Infrastructure Setup || 🔴 Not Started || 0% || Need 200-core host access&lt;br /&gt;
|-&lt;br /&gt;
| Phase 2: Curriculum Development || 🟡 In Progress || 65% || Need video recordings, quizzes, pre/post lab pages&lt;br /&gt;
|-&lt;br /&gt;
| Phase 3: Pilot &amp;amp; Refinement || 🔴 Not Started || 0% || Waiting on Phase 1 + 2&lt;br /&gt;
|-&lt;br /&gt;
| Phase 4: Deployment &amp;amp; Operations || 🔴 Not Started || 0% || Waiting on Phase 3&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Resource Summary ==&lt;br /&gt;
&#039;&#039;&#039;Per-student minimum:&#039;&#039;&#039; 6 vCPUs, 6.5 GB RAM, 62 GB disk&lt;br /&gt;
&#039;&#039;&#039;Per-student full lab:&#039;&#039;&#039; 10 vCPUs, 10.5 GB RAM, 110 GB disk&lt;br /&gt;
&#039;&#039;&#039;200-core / 1TB capacity:&#039;&#039;&#039; 20–40 concurrent students (conservative to optimized)&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Next Actions (This Week):&#039;&#039;&#039;&lt;br /&gt;
# Summarize the-pfsense-documentation.pdf into a reference page&lt;br /&gt;
# Document WindowsTrainingSupportFiles.zip contents&lt;br /&gt;
# Catalog training video timestamps&lt;br /&gt;
# Begin Ansible playbook drafting for Lab 1 environment&lt;br /&gt;
# Evaluate Kimchi vs Guacamole for NoVNC portal&lt;/div&gt;</summary>
		<author><name>Justinaquino</name></author>
	</entry>
	<entry>
		<id>https://mediawiki.comfac.net/index.php?title=Training:_Setting_Up_a_Firewall_for_Yourself&amp;diff=247</id>
		<title>Training: Setting Up a Firewall for Yourself</title>
		<link rel="alternate" type="text/html" href="https://mediawiki.comfac.net/index.php?title=Training:_Setting_Up_a_Firewall_for_Yourself&amp;diff=247"/>
		<updated>2026-04-23T07:21:00Z</updated>

		<summary type="html">&lt;p&gt;Justinaquino: Create Introduction Training Module 0 - personal/small business firewall setup&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__NOTOC__&lt;br /&gt;
&amp;lt;div style=&amp;quot;background:#fff3e0; border:1px solid #ffb74d; border-radius:4px; padding:12px 16px; margin-bottom:20px;&amp;quot;&amp;gt;&lt;br /&gt;
&#039;&#039;&#039;Comfac Entry-Level Training: Module 0&#039;&#039;&#039; — Setting Up a Firewall for Yourself. The most common, practical starting point before advancing to the full FUND001 curriculum.&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Target Audience ==&lt;br /&gt;
* Home users who want to secure their network&lt;br /&gt;
* Small business owners (1–10 employees)&lt;br /&gt;
* IT staff new to networking before they tackle enterprise deployments&lt;br /&gt;
* Anyone who has never configured a router or firewall before&lt;br /&gt;
&lt;br /&gt;
== Learning Objectives ==&lt;br /&gt;
By the end of this module, you will be able to:&lt;br /&gt;
* Explain why a firewall is necessary for homes and small offices&lt;br /&gt;
* Install pfSense on an old PC or VM with minimum hardware&lt;br /&gt;
* Configure basic WAN and LAN interfaces&lt;br /&gt;
* Set up essential firewall rules (allow outgoing, block incoming)&lt;br /&gt;
* Configure port forwarding for common services&lt;br /&gt;
* Set up a basic WireGuard VPN for remote access&lt;br /&gt;
* Back up and update the firewall configuration&lt;br /&gt;
* Diagnose common connectivity problems&lt;br /&gt;
&lt;br /&gt;
== Module 0: Why You Need a Firewall ==&lt;br /&gt;
=== The Threats at Home and Small Office ===&lt;br /&gt;
Most people rely on the &amp;quot;router&amp;quot; provided by their ISP. These devices are:&lt;br /&gt;
* &#039;&#039;&#039;Minimally configured&#039;&#039;&#039; — often with default passwords and outdated firmware&lt;br /&gt;
* &#039;&#039;&#039;Poorly maintained&#039;&#039;&#039; — ISPs rarely push security updates promptly&lt;br /&gt;
* &#039;&#039;&#039;Limited in features&#039;&#039;&#039; — no VPN, no traffic logging, no intrusion detection&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Common risks:&#039;&#039;&#039;&lt;br /&gt;
* Unauthorized remote access to cameras, NAS, printers&lt;br /&gt;
* Malware spreading between family/employee devices&lt;br /&gt;
* Cryptojacking, ransomware, botnet participation&lt;br /&gt;
* Data exfiltration from poorly secured IoT devices&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;What a firewall gives you:&#039;&#039;&#039;&lt;br /&gt;
* &#039;&#039;&#039;Stateful inspection&#039;&#039;&#039; — only allows return traffic for connections you initiated&lt;br /&gt;
* &#039;&#039;&#039;Network segmentation&#039;&#039;&#039; — isolate guests, IoT, and work devices&lt;br /&gt;
* &#039;&#039;&#039;VPN access&#039;&#039;&#039; — securely access your home/office network from anywhere&lt;br /&gt;
* &#039;&#039;&#039;Logging &amp;amp; visibility&#039;&#039;&#039; — see what devices are doing on your network&lt;br /&gt;
* &#039;&#039;&#039;Ad and malware blocking&#039;&#039;&#039; — integrate with DNS blocklists (Pi-hole)&lt;br /&gt;
&lt;br /&gt;
== Module 1: Hardware and Installation ==&lt;br /&gt;
=== Minimum Hardware ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Component !! Minimum !! Recommended&lt;br /&gt;
|-&lt;br /&gt;
| CPU || 64-bit, 1 GHz || 64-bit, 2+ cores, AES-NI support&lt;br /&gt;
|-&lt;br /&gt;
| RAM || 1 GB || 4 GB&lt;br /&gt;
|-&lt;br /&gt;
| Storage || 8 GB SSD/USB || 32 GB SSD&lt;br /&gt;
|-&lt;br /&gt;
| NICs || 2 Ethernet ports || Intel i210/i350 dual/quad port NIC&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Good sources of cheap hardware:&#039;&#039;&#039;&lt;br /&gt;
* Old office desktops (Dell OptiPlex, HP EliteDesk)&lt;br /&gt;
* Thin clients with PCIe slot for NIC&lt;br /&gt;
* Used 1U servers (noisy but cheap)&lt;br /&gt;
* Protectli/Qotom mini-PCs (purpose-built, fanless)&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Installation methods:&#039;&#039;&#039;&lt;br /&gt;
# Download pfSense CE ISO from https://www.pfsense.org/downloads&lt;br /&gt;
# Write to USB with Rufus (Windows) or dd (Linux)&lt;br /&gt;
# Boot from USB, install to SSD/HDD&lt;br /&gt;
# Remove USB, reboot&lt;br /&gt;
# Default LAN: 192.168.1.1&lt;br /&gt;
&lt;br /&gt;
== Module 2: First Boot and Basic Setup ==&lt;br /&gt;
=== The Setup Wizard ===&lt;br /&gt;
# Connect laptop to LAN port&lt;br /&gt;
# Browse to https://192.168.1.1&lt;br /&gt;
# Log in: admin / pfsense&lt;br /&gt;
# Complete the wizard:&lt;br /&gt;
#* &#039;&#039;&#039;General Info&#039;&#039;&#039; — Set hostname (e.g., homefw), domain (local)&lt;br /&gt;
#* &#039;&#039;&#039;Time Server&#039;&#039;&#039; — Use default or local NTP&lt;br /&gt;
#* &#039;&#039;&#039;WAN&#039;&#039;&#039; — Select DHCP (most home/DSL) or PPPoE (some fiber)&lt;br /&gt;
#* &#039;&#039;&#039;LAN&#039;&#039;&#039; — Leave 192.168.1.1/24 or change to obscure subnet (e.g., 10.47.83.1/24)&lt;br /&gt;
#* &#039;&#039;&#039;Password&#039;&#039;&#039; — Change from default immediately&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Why change from 192.168.1.1?&#039;&#039;&#039; If you later connect via VPN from a coffee shop that also uses 192.168.1.x, your traffic may not route correctly. Using an obscure subnet avoids this.&lt;br /&gt;
&lt;br /&gt;
=== Essential Post-Setup ===&lt;br /&gt;
# &#039;&#039;&#039;System -&amp;gt; General Setup&#039;&#039;&#039; — Set timezone, language&lt;br /&gt;
# &#039;&#039;&#039;System -&amp;gt; Advanced -&amp;gt; Networking&#039;&#039;&#039; — Disable NAT reflection if not needed&lt;br /&gt;
# &#039;&#039;&#039;System -&amp;gt; Update&#039;&#039;&#039; — Check for updates immediately&lt;br /&gt;
# &#039;&#039;&#039;Diagnostics -&amp;gt; Backup &amp;amp; Restore&#039;&#039;&#039; — Download first config backup&lt;br /&gt;
&lt;br /&gt;
== Module 3: Essential Firewall Rules ==&lt;br /&gt;
=== Default Rules (pfSense handles these automatically) ===&lt;br /&gt;
* &#039;&#039;&#039;LAN&#039;&#039;&#039; — Allow all (default)&lt;br /&gt;
* &#039;&#039;&#039;WAN&#039;&#039;&#039; — Block all (implicit, not shown)&lt;br /&gt;
&lt;br /&gt;
=== Best Practice: Restrict LAN Outbound ===&lt;br /&gt;
For a more secure home/small office, replace &amp;quot;LAN allow all&amp;quot; with specific allowed protocols:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Protocol !! Port !! Purpose&lt;br /&gt;
|-&lt;br /&gt;
| TCP/UDP || 53 || DNS&lt;br /&gt;
|-&lt;br /&gt;
| TCP/UDP || 123 || NTP&lt;br /&gt;
|-&lt;br /&gt;
| TCP/UDP || 443 || HTTPS&lt;br /&gt;
|-&lt;br /&gt;
| TCP || 80 || HTTP (optional)&lt;br /&gt;
|-&lt;br /&gt;
| TCP/UDP || 5222 || XMPP/chat (optional)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;How to do it:&#039;&#039;&#039;&lt;br /&gt;
# Firewall -&amp;gt; Rules -&amp;gt; LAN&lt;br /&gt;
# Delete the default &amp;quot;Allow All&amp;quot; rule&lt;br /&gt;
# Add rules for each protocol/port above&lt;br /&gt;
# Add a final &amp;quot;Block&amp;quot; rule at the bottom (with logging enabled)&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Note:&#039;&#039;&#039; This breaks some apps/games. For a family home, &amp;quot;Allow All&amp;quot; outbound is usually fine. For a business, restrict outbound.&lt;br /&gt;
&lt;br /&gt;
== Module 4: Port Forwarding ===&lt;br /&gt;
=== Common Scenarios ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Service !! External Port !! Internal IP !! Internal Port !! Notes&lt;br /&gt;
|-&lt;br /&gt;
| Minecraft server || 25565 || 192.168.1.50 || 25565 || Gaming&lt;br /&gt;
|-&lt;br /&gt;
| Camera/DVR || 8080 || 192.168.1.60 || 80 || Change default port&lt;br /&gt;
|-&lt;br /&gt;
| NAS/Web || 443 || 192.168.1.70 || 443 || Use reverse proxy if multiple services&lt;br /&gt;
|-&lt;br /&gt;
| Plex || 32400 || 192.168.1.80 || 32400 || Remote streaming&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Steps:&#039;&#039;&#039;&lt;br /&gt;
# Firewall -&amp;gt; NAT -&amp;gt; Port Forward&lt;br /&gt;
# Click Add&lt;br /&gt;
# Interface: WAN&lt;br /&gt;
# Protocol: TCP (or TCP/UDP)&lt;br /&gt;
# Destination: WAN Address&lt;br /&gt;
# Destination Port Range: external port&lt;br /&gt;
# Redirect Target IP: internal server IP&lt;br /&gt;
# Redirect Target Port: internal port&lt;br /&gt;
# Save → Apply&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Security tip:&#039;&#039;&#039; Don&#039;t forward RDP (3389) or SSH (22) directly. Use a VPN instead.&lt;br /&gt;
&lt;br /&gt;
== Module 5: WireGuard VPN (Road Warrior) ==&lt;br /&gt;
=== Why VPN beats port forwarding ===&lt;br /&gt;
* One secure tunnel instead of many open ports&lt;br /&gt;
* Access your entire network as if you were there&lt;br /&gt;
* Works on phones, laptops, tablets&lt;br /&gt;
* No need to expose individual services&lt;br /&gt;
&lt;br /&gt;
=== Setup Steps ===&lt;br /&gt;
# Install &#039;&#039;&#039;WireGuard package&#039;&#039;&#039; — System -&amp;gt; Package Manager -&amp;gt; Available Packages&lt;br /&gt;
# VPN -&amp;gt; WireGuard -&amp;gt; Settings → Enable&lt;br /&gt;
# Tunnels → Add Tunnel&lt;br /&gt;
#* Name: RoadWarrior&lt;br /&gt;
#* Listen Port: 51820&lt;br /&gt;
#* Interface Keys: Generate key pair&lt;br /&gt;
# Save&lt;br /&gt;
# Assign interface — Interfaces -&amp;gt; Assignments → add wg0 as OPTx&lt;br /&gt;
# Enable interface, set static IP: 10.200.200.1/24&lt;br /&gt;
# Peers → Add Peer&lt;br /&gt;
#* Tunnel: RoadWarrior&lt;br /&gt;
#* Public Key: [client&#039;s public key]&lt;br /&gt;
#* Allowed IPs: 10.200.200.2/32&lt;br /&gt;
#* Endpoint: [blank for roaming clients]&lt;br /&gt;
# Firewall -&amp;gt; Rules -&amp;gt; WireGuard interface → Allow All&lt;br /&gt;
# Firewall -&amp;gt; Rules -&amp;gt; LAN → Allow from WireGuard net&lt;br /&gt;
# Firewall -&amp;gt; NAT -&amp;gt; Outbound → Manual → Add rule for WireGuard net → WAN&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Client config (phone/laptop):&#039;&#039;&#039;&lt;br /&gt;
* Install WireGuard app&lt;br /&gt;
* Create tunnel, scan QR code or paste config&lt;br /&gt;
* Peer: [server public key], Endpoint: your-public-ip:51820&lt;br /&gt;
* Allowed IPs: 0.0.0.0/0 (full tunnel) or 192.168.1.0/24 (split tunnel)&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Opening the port:&#039;&#039;&#039;&lt;br /&gt;
# Firewall -&amp;gt; Rules -&amp;gt; WAN&lt;br /&gt;
# Add rule: Protocol UDP, Port 51820, Source Any, Destination WAN Address&lt;br /&gt;
&lt;br /&gt;
== Module 6: Backup and Maintenance ==&lt;br /&gt;
=== Monthly Checklist ===&lt;br /&gt;
* [ ] System -&amp;gt; Update: Check for updates&lt;br /&gt;
* [ ] Diagnostics -&amp;gt; Backup &amp;amp; Restore: Download config backup&lt;br /&gt;
* [ ] Check Dashboard for interface errors, high CPU, or memory usage&lt;br /&gt;
* [ ] Review Firewall logs for blocked suspicious traffic&lt;br /&gt;
* [ ] Verify VPN clients can still connect&lt;br /&gt;
&lt;br /&gt;
=== Yearly Checklist ===&lt;br /&gt;
* [ ] Rotate WireGuard keys&lt;br /&gt;
* [ ] Review all port forwards — remove unused ones&lt;br /&gt;
* [ ] Check certificate expiry (if using ACME/Let&#039;s Encrypt)&lt;br /&gt;
* [ ] Audit user accounts and passwords&lt;br /&gt;
* [ ] Test restore from backup on a spare VM&lt;br /&gt;
&lt;br /&gt;
== Troubleshooting Common Problems ==&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Problem !! Likely Cause !! Fix&lt;br /&gt;
|-&lt;br /&gt;
| No Internet after install || WAN not getting IP || Check cable; set WAN to DHCP or PPPoE&lt;br /&gt;
|-&lt;br /&gt;
| Can&#039;t access web GUI || Wrong IP; HTTPS blocked || Try http://192.168.1.1; check laptop IP&lt;br /&gt;
|-&lt;br /&gt;
| Port forward not working || ISP CGNAT || Check WAN IP vs public IP; use VPN instead&lt;br /&gt;
|-&lt;br /&gt;
| VPN connects but no LAN access || Missing firewall/NAT rule || Add allow rule on WireGuard iface; add outbound NAT&lt;br /&gt;
|-&lt;br /&gt;
| Slow Internet || Hardware too weak || Check CPU usage; upgrade NIC or whole box&lt;br /&gt;
|-&lt;br /&gt;
| Can&#039;t reach some websites || DNS issue || Use 1.1.1.1 or 8.8.8.8 in DNS Resolver forwarders&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Build Your Own Firewall — Capstone Exercise ==&lt;br /&gt;
&#039;&#039;&#039;Scenario:&#039;&#039;&#039; You have an old Dell OptiPlex, a 2-port Intel NIC, and a home fiber connection.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Requirements:&#039;&#039;&#039;&lt;br /&gt;
# Install pfSense CE&lt;br /&gt;
# Configure WAN (DHCP) and LAN (static 10.47.83.1/24)&lt;br /&gt;
# Set admin password&lt;br /&gt;
# Enable DNS Resolver with forwarding to Cloudflare (1.1.1.1)&lt;br /&gt;
# Create firewall rules: allow DNS, HTTPS, NTP outbound only&lt;br /&gt;
# Set up WireGuard for 2 devices (phone + laptop)&lt;br /&gt;
# Forward port 32400 to a Plex server at 10.47.83.50&lt;br /&gt;
# Enable AutoConfigBackup (or manual monthly backups)&lt;br /&gt;
# Document everything in a simple runbook&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Success criteria:&#039;&#039;&#039;&lt;br /&gt;
* Family can browse web normally&lt;br /&gt;
* You can VPN in from outside and access LAN resources&lt;br /&gt;
* Plex is accessible remotely&lt;br /&gt;
* Configuration is backed up&lt;br /&gt;
&lt;br /&gt;
== Next Steps ==&lt;br /&gt;
Once comfortable with this module, advance to the full &#039;&#039;&#039;FUND001 curriculum&#039;&#039;&#039;:&lt;br /&gt;
# [[Training: pfSense Introduction]] — Phase 1, Day 1&lt;br /&gt;
# [[Training Lab 1: Introduction and Backup Restore]] — Hands-on lab&lt;br /&gt;
&lt;br /&gt;
Or explore specialized topics:&lt;br /&gt;
* [[Training: pfSense Services]] — DHCP, DNS, Dynamic DNS deep dive&lt;br /&gt;
* [[Training: Multi-WAN]] — Add a backup ISP connection&lt;br /&gt;
* [[Networking PfSense Index]] — All Comfac networking resources&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&#039;&#039;This module was created for Comfac IT practical training. Built on real-world frequency of problems encountered from personal to small-business networks.&#039;&#039;&lt;/div&gt;</summary>
		<author><name>Justinaquino</name></author>
	</entry>
	<entry>
		<id>https://mediawiki.comfac.net/index.php?title=Training:_Monitoring_and_Packages&amp;diff=246</id>
		<title>Training: Monitoring and Packages</title>
		<link rel="alternate" type="text/html" href="https://mediawiki.comfac.net/index.php?title=Training:_Monitoring_and_Packages&amp;diff=246"/>
		<updated>2026-04-23T07:16:09Z</updated>

		<summary type="html">&lt;p&gt;Justinaquino: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__NOTOC__&lt;br /&gt;
&amp;lt;div style=&amp;quot;background:#1e3a5f; color:#fff; padding:12px; border-radius:6px; margin-bottom:16px;&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;font-size:1.2em; font-weight:bold;&amp;quot;&amp;gt;📘 Netgate pfSense Training — Module 11&amp;lt;/span&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
System Monitoring, Logging, and the Package System&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Learning Objectives ==&lt;br /&gt;
&lt;br /&gt;
By the end of this module, you should be able to:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width:100%;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Objective&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| Monitor system health&lt;br /&gt;
| Use built-in Status pages, Traffic Graphs, and RRD Graphs to observe system performance.&lt;br /&gt;
|-&lt;br /&gt;
| Configure logging&lt;br /&gt;
| Access system logs and export them to an external log aggregation server.&lt;br /&gt;
|-&lt;br /&gt;
| Understand SNMP&lt;br /&gt;
| Enable and use SNMP for remote monitoring and integration with NMS tools.&lt;br /&gt;
|-&lt;br /&gt;
| Manage packages&lt;br /&gt;
| Install, update, and remove packages to extend pfSense functionality.&lt;br /&gt;
|-&lt;br /&gt;
| Evaluate package maturity&lt;br /&gt;
| Interpret version numbers (e.g., 0.x = young package) and assess stability.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== System Monitoring ==&lt;br /&gt;
&lt;br /&gt;
=== Status Pages ===&lt;br /&gt;
&lt;br /&gt;
pfSense provides many built-in &#039;&#039;&#039;Status&#039;&#039;&#039; pages that give real-time and historical insight into system behavior:&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;Dashboard&#039;&#039;&#039; — customizable overview with widgets for system info, interfaces, services, and gateways.&lt;br /&gt;
* &#039;&#039;&#039;Traffic Graph&#039;&#039;&#039; — live view of traffic per interface.&lt;br /&gt;
* &#039;&#039;&#039;RRD Graphs&#039;&#039;&#039; — historical data for CPU, memory, interface traffic, packets, states, and quality.&lt;br /&gt;
* &#039;&#039;&#039;System Logs&#039;&#039;&#039; — consolidated logging for the firewall, DHCP, DNS, VPN, and other services.&lt;br /&gt;
&lt;br /&gt;
=== RRD Graphs ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;RRDtool&#039;&#039;&#039; is integrated into pfSense to store and graph time-series data. Available graphs include:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width:100%;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Category&lt;br /&gt;
! Metrics&lt;br /&gt;
|-&lt;br /&gt;
| System&lt;br /&gt;
| CPU usage, memory usage, swap usage, load average&lt;br /&gt;
|-&lt;br /&gt;
| Traffic&lt;br /&gt;
| Inbound/outbound bytes and packets per interface&lt;br /&gt;
|-&lt;br /&gt;
| Packets&lt;br /&gt;
| Passed, blocked, and error packet counts&lt;br /&gt;
|-&lt;br /&gt;
| Quality&lt;br /&gt;
| Gateway latency and packet loss over time&lt;br /&gt;
|-&lt;br /&gt;
| States&lt;br /&gt;
| Current firewall state table size&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SNMP Monitoring ===&lt;br /&gt;
&lt;br /&gt;
pfSense includes an &#039;&#039;&#039;SNMP service&#039;&#039;&#039; (via &#039;&#039;&#039;bsnmpd&#039;&#039;&#039;) that allows remote monitoring with tools such as:&lt;br /&gt;
&lt;br /&gt;
* Zabbix&lt;br /&gt;
* Nagios / Icinga&lt;br /&gt;
* Cacti&lt;br /&gt;
* PRTG&lt;br /&gt;
* LibreNMS&lt;br /&gt;
&lt;br /&gt;
Enable SNMP under &#039;&#039;&#039;Services → SNMP&#039;&#039;&#039; and configure community strings, traps, and binding interfaces as needed.&lt;br /&gt;
&lt;br /&gt;
=== Logging ===&lt;br /&gt;
&lt;br /&gt;
System logs are available under the &#039;&#039;&#039;Status → System Logs&#039;&#039;&#039; menu. Key capabilities:&lt;br /&gt;
&lt;br /&gt;
* View logs by category (Firewall, DHCP, DNS Resolver, VPN, etc.)&lt;br /&gt;
* Adjust log verbosity and retention&lt;br /&gt;
* &#039;&#039;&#039;Export logs&#039;&#039;&#039; to an external log aggregation server (e.g., Syslog, Graylog, ELK stack, Splunk) for centralized analysis&lt;br /&gt;
&lt;br /&gt;
== Package System ==&lt;br /&gt;
&lt;br /&gt;
=== Overview ===&lt;br /&gt;
&lt;br /&gt;
The &#039;&#039;&#039;Package System&#039;&#039;&#039; extends pfSense beyond the base installation. Packages are installed from the official Netgate repository via &#039;&#039;&#039;System → Package Manager&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
=== Common and Popular Packages ===&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width:100%;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Package&lt;br /&gt;
! Purpose&lt;br /&gt;
! Category&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;pfBlockerNG&#039;&#039;&#039;&lt;br /&gt;
| IP and DNS-based blocking for geo-location, threat feeds, and ad blocking&lt;br /&gt;
| Security / Filtering&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;Suricata&#039;&#039;&#039;&lt;br /&gt;
| High-performance Network IDS/IPS with rule-based threat detection&lt;br /&gt;
| Security&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;Snort&#039;&#039;&#039;&lt;br /&gt;
| Network intrusion detection and prevention system&lt;br /&gt;
| Security&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;HAProxy&#039;&#039;&#039;&lt;br /&gt;
| TCP/HTTP load balancer and reverse proxy&lt;br /&gt;
| Traffic Management&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;Squid / SquidGuard&#039;&#039;&#039;&lt;br /&gt;
| Web proxy with content filtering and access control&lt;br /&gt;
| Proxy / Filtering&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;pfSense-pkg-FRR&#039;&#039;&#039;&lt;br /&gt;
| Routing protocols (BGP, OSPF, RIP)&lt;br /&gt;
| Routing&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;ntopng&#039;&#039;&#039;&lt;br /&gt;
| Network traffic probe and flow analysis&lt;br /&gt;
| Monitoring&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;NRPE / Zabbix Agent&#039;&#039;&#039;&lt;br /&gt;
| Client agents for remote monitoring integration&lt;br /&gt;
| Monitoring&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;ACME&#039;&#039;&#039;&lt;br /&gt;
| Automatic SSL/TLS certificate issuance via Let&#039;s Encrypt&lt;br /&gt;
| Certificates&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;Telegraf&#039;&#039;&#039;&lt;br /&gt;
| Metrics collection agent for InfluxDB/Prometheus&lt;br /&gt;
| Monitoring&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Package Installation Best Practices ===&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;Pay attention to version numbers!&#039;&#039;&#039; A version of &#039;&#039;&#039;0.n&#039;&#039;&#039; typically indicates a young or experimental package.&lt;br /&gt;
* Install packages only from the official repository or trusted sources.&lt;br /&gt;
* Use &#039;&#039;&#039;Backup / Restore&#039;&#039;&#039; to preserve package states for reinstallation after upgrades.&lt;br /&gt;
* Review package documentation before installing in production.&lt;br /&gt;
&lt;br /&gt;
=== Backup and Restore for Packages ===&lt;br /&gt;
&lt;br /&gt;
pfSense&#039;s built-in backup system includes an option to reinstall packages automatically after a restore. Ensure this option is enabled under &#039;&#039;&#039;Diagnostics → Backup &amp;amp; Restore&#039;&#039;&#039; when creating configuration backups.&lt;br /&gt;
&lt;br /&gt;
== Summary ==&lt;br /&gt;
&lt;br /&gt;
* pfSense provides robust &#039;&#039;&#039;system monitoring&#039;&#039;&#039; through Status pages, Traffic Graphs, &#039;&#039;&#039;RRD Graphs&#039;&#039;&#039;, and &#039;&#039;&#039;SNMP&#039;&#039;&#039;.&lt;br /&gt;
* &#039;&#039;&#039;System logs&#039;&#039;&#039; can be viewed locally or exported to external aggregation servers for centralized analysis.&lt;br /&gt;
* The &#039;&#039;&#039;Package System&#039;&#039;&#039; dramatically extends pfSense capabilities with popular additions such as &#039;&#039;&#039;pfBlockerNG&#039;&#039;&#039;, &#039;&#039;&#039;Suricata&#039;&#039;&#039;, &#039;&#039;&#039;HAProxy&#039;&#039;&#039;, and &#039;&#039;&#039;Squid&#039;&#039;&#039;.&lt;br /&gt;
* Always evaluate &#039;&#039;&#039;package maturity&#039;&#039;&#039; (version numbers) and maintain &#039;&#039;&#039;backups&#039;&#039;&#039; before making significant changes.&lt;br /&gt;
&lt;br /&gt;
== Next Module ==&lt;br /&gt;
&lt;br /&gt;
* Previous: [[Training: Firewall Rules and NAT]]&lt;br /&gt;
* Next: [[Training: VPN Configuration]]&lt;br /&gt;
* Return to [[Training: pfSense Course Index]]&lt;br /&gt;
&lt;br /&gt;
== Source Attribution ==&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;Source:&#039;&#039;&#039; Netgate pfSense Training Material&lt;br /&gt;
* &#039;&#039;&#039;Document:&#039;&#039;&#039; FUND001-LIVE-SLIDE-SEG11-OTHER.pdf&lt;br /&gt;
* &#039;&#039;&#039;Section:&#039;&#039;&#039; 11 — Other Features (Monitoring, Logging, Packages)&lt;br /&gt;
* &#039;&#039;&#039;Copyright:&#039;&#039;&#039; © 2017 Rubicon Communications dba Netgate&lt;br /&gt;
* &#039;&#039;&#039;Conversion Date:&#039;&#039;&#039; {{CURRENTYEAR}}-{{CURRENTMONTH}}-{{CURRENTDAY}}&lt;br /&gt;
&lt;br /&gt;
[[Category:pfSense Training]]&lt;br /&gt;
[[Category:Network Security]]&lt;/div&gt;</summary>
		<author><name>Justinaquino</name></author>
	</entry>
	<entry>
		<id>https://mediawiki.comfac.net/index.php?title=Training:_Monitoring_and_Packages&amp;diff=245</id>
		<title>Training: Monitoring and Packages</title>
		<link rel="alternate" type="text/html" href="https://mediawiki.comfac.net/index.php?title=Training:_Monitoring_and_Packages&amp;diff=245"/>
		<updated>2026-04-23T07:14:48Z</updated>

		<summary type="html">&lt;p&gt;Justinaquino: Created page with &amp;quot;__NOTOC__ &amp;lt;div style=&amp;quot;background:#1e3a5f; color:#fff; padding:12px; border-radius:6px; margin-bottom:16px;&amp;quot;&amp;gt; &amp;lt;span style=&amp;quot;font-size:1.2em; font-weight:bold;&amp;quot;&amp;gt;📘 Netgate pfSense Training — Module 11&amp;lt;/span&amp;gt;&amp;lt;br/&amp;gt; System Monitoring, Logging, and the Package System &amp;lt;/div&amp;gt;  == Learning Objectives ==  By the end of this module, you should be able to:  {| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width:100%;&amp;quot; |- ! Objective ! Description |- | Monitor system health | Use built-in Status pages...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__NOTOC__&lt;br /&gt;
&amp;lt;div style=&amp;quot;background:#1e3a5f; color:#fff; padding:12px; border-radius:6px; margin-bottom:16px;&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;font-size:1.2em; font-weight:bold;&amp;quot;&amp;gt;📘 Netgate pfSense Training — Module 11&amp;lt;/span&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
System Monitoring, Logging, and the Package System&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Learning Objectives ==&lt;br /&gt;
&lt;br /&gt;
By the end of this module, you should be able to:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width:100%;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Objective&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| Monitor system health&lt;br /&gt;
| Use built-in Status pages, Traffic Graphs, and RRD Graphs to observe system performance.&lt;br /&gt;
|-&lt;br /&gt;
| Configure logging&lt;br /&gt;
| Access system logs and export them to an external log aggregation server.&lt;br /&gt;
|-&lt;br /&gt;
| Understand SNMP&lt;br /&gt;
| Enable and use SNMP for remote monitoring and integration with NMS tools.&lt;br /&gt;
|-&lt;br /&gt;
| Manage packages&lt;br /&gt;
| Install, update, and remove packages to extend pfSense functionality.&lt;br /&gt;
|-&lt;br /&gt;
| Evaluate package maturity&lt;br /&gt;
| Interpret version numbers (e.g., 0.x = young package) and assess stability.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== System Monitoring ==&lt;br /&gt;
&lt;br /&gt;
=== Status Pages ===&lt;br /&gt;
&lt;br /&gt;
pfSense provides many built-in &#039;&#039;&#039;Status&#039;&#039;&#039; pages that give real-time and historical insight into system behavior:&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;Dashboard&#039;&#039;&#039; — customizable overview with widgets for system info, interfaces, services, and gateways.&lt;br /&gt;
* &#039;&#039;&#039;Traffic Graph&#039;&#039;&#039; — live view of traffic per interface.&lt;br /&gt;
* &#039;&#039;&#039;RRD Graphs&#039;&#039;&#039; — historical data for CPU, memory, interface traffic, packets, states, and quality.&lt;br /&gt;
* &#039;&#039;&#039;System Logs&#039;&#039;&#039; — consolidated logging for the firewall, DHCP, DNS, VPN, and other services.&lt;br /&gt;
&lt;br /&gt;
=== RRD Graphs ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;RRDtool&#039;&#039;&#039; is integrated into pfSense to store and graph time-series data. Available graphs include:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width:100%;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Category&lt;br /&gt;
! Metrics&lt;br /&gt;
|-&lt;br /&gt;
| System&lt;br /&gt;
| CPU usage, memory usage, swap usage, load average&lt;br /&gt;
|-&lt;br /&gt;
| Traffic&lt;br /&gt;
| Inbound/outbound bytes and packets per interface&lt;br /&gt;
|-&lt;br /&gt;
| Packets&lt;br /&gt;
| Passed, blocked, and error packet counts&lt;br /&gt;
|-&lt;br /&gt;
| Quality&lt;br /&gt;
| Gateway latency and packet loss over time&lt;br /&gt;
|-&lt;br /&gt;
| States&lt;br /&gt;
| Current firewall state table size&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SNMP Monitoring ===&lt;br /&gt;
&lt;br /&gt;
pfSense includes an &#039;&#039;&#039;SNMP service&#039;&#039;&#039; (via &#039;&#039;&#039;bsnmpd&#039;&#039;&#039;) that allows remote monitoring with tools such as:&lt;br /&gt;
&lt;br /&gt;
* Zabbix&lt;br /&gt;
* Nagios / Icinga&lt;br /&gt;
* Cacti&lt;br /&gt;
* PRTG&lt;br /&gt;
* LibreNMS&lt;br /&gt;
&lt;br /&gt;
Enable SNMP under &#039;&#039;&#039;Services → SNMP&#039;&#039;&#039; and configure community strings, traps, and binding interfaces as needed.&lt;br /&gt;
&lt;br /&gt;
=== Logging ===&lt;br /&gt;
&lt;br /&gt;
System logs are available under the &#039;&#039;&#039;Status → System Logs&#039;&#039;&#039; menu. Key capabilities:&lt;br /&gt;
&lt;br /&gt;
* View logs by category (Firewall, DHCP, DNS Resolver, VPN, etc.)&lt;br /&gt;
* Adjust log verbosity and retention&lt;br /&gt;
* &#039;&#039;&#039;Export logs&#039;&#039;&#039; to an external log aggregation server (e.g., Syslog, Graylog, ELK stack, Splunk) for centralized analysis&lt;br /&gt;
&lt;br /&gt;
== Package System ==&lt;br /&gt;
&lt;br /&gt;
=== Overview ===&lt;br /&gt;
&lt;br /&gt;
The &#039;&#039;&#039;Package System&#039;&#039;&#039; extends pfSense beyond the base installation. Packages are installed from the official Netgate repository via &#039;&#039;&#039;System → Package Manager&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
=== Common and Popular Packages ===&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width:100%;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Package&lt;br /&gt;
! Purpose&lt;br /&gt;
! Category&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;pfBlockerNG&#039;&#039;&#039;&lt;br /&gt;
| IP and DNS-based blocking for geo-location, threat feeds, and ad blocking&lt;br /&gt;
| Security / Filtering&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;Suricata&#039;&#039;&#039;&lt;br /&gt;
| High-performance Network IDS/IPS with rule-based threat detection&lt;br /&gt;
| Security&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;Snort&#039;&#039;&#039;&lt;br /&gt;
| Network intrusion detection and prevention system&lt;br /&gt;
| Security&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;HAProxy&#039;&#039;&#039;&lt;br /&gt;
| TCP/HTTP load balancer and reverse proxy&lt;br /&gt;
| Traffic Management&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;Squid / SquidGuard&#039;&#039;&#039;&lt;br /&gt;
| Web proxy with content filtering and access control&lt;br /&gt;
| Proxy / Filtering&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;pfSense-pkg-FRR&#039;&#039;&#039;&lt;br /&gt;
| Routing protocols (BGP, OSPF, RIP)&lt;br /&gt;
| Routing&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;ntopng&#039;&#039;&#039;&lt;br /&gt;
| Network traffic probe and flow analysis&lt;br /&gt;
| Monitoring&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;NRPE / Zabbix Agent&#039;&#039;&#039;&lt;br /&gt;
| Client agents for remote monitoring integration&lt;br /&gt;
| Monitoring&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;ACME&#039;&#039;&#039;&lt;br /&gt;
| Automatic SSL/TLS certificate issuance via Let&#039;s Encrypt&lt;br /&gt;
| Certificates&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;Telegraf&#039;&#039;&#039;&lt;br /&gt;
| Metrics collection agent for InfluxDB/Prometheus&lt;br /&gt;
| Monitoring&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Package Installation Best Practices ===&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;Pay attention to version numbers!&#039;&#039;&#039; A version of &#039;&#039;&#039;0.n&#039;&#039;&#039; typically indicates a young or experimental package.&lt;br /&gt;
* Install packages only from the official repository or trusted sources.&lt;br /&gt;
* Use &#039;&#039;&#039;Backup / Restore&#039;&#039;&#039; to preserve package states for reinstallation after upgrades.&lt;br /&gt;
* Review package documentation before installing in production.&lt;br /&gt;
&lt;br /&gt;
=== Backup and Restore for Packages ===&lt;br /&gt;
&lt;br /&gt;
pfSense&#039;s built-in backup system includes an option to reinstall packages automatically after a restore. Ensure this option is enabled under &#039;&#039;&#039;Diagnostics → Backup&lt;/div&gt;</summary>
		<author><name>Justinaquino</name></author>
	</entry>
	<entry>
		<id>https://mediawiki.comfac.net/index.php?title=Training_Lab_9:_Traffic_Shaping&amp;diff=244</id>
		<title>Training Lab 9: Traffic Shaping</title>
		<link rel="alternate" type="text/html" href="https://mediawiki.comfac.net/index.php?title=Training_Lab_9:_Traffic_Shaping&amp;diff=244"/>
		<updated>2026-04-23T07:10:26Z</updated>

		<summary type="html">&lt;p&gt;Justinaquino: Imported from FUND001-LIVE-Lab9-TrafficShaping.pdf&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__NOTOC__&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;background:#005500; color:white; padding:12px; border-radius:6px; margin-bottom:16px;&amp;quot;&amp;gt;&lt;br /&gt;
&#039;&#039;&#039;Netgate pfSense Plus Fundamentals — Lab 9: Traffic Shaping&#039;&#039;&#039;&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;small&amp;gt;Training lab manual: FUND001-LIVE-Lab9-TrafficShaping.pdf&amp;lt;/small&amp;gt;&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Overview ==&lt;br /&gt;
&lt;br /&gt;
This lab covers limiters and traffic shaping at an introductory level.&lt;br /&gt;
&lt;br /&gt;
We will configure limiters to restrict HQ LAN hosts to &#039;&#039;&#039;2 Mb down / 512 Kb up&#039;&#039;&#039;. The mask option of limiters is used to configure this limit on a &#039;&#039;&#039;per-IP basis&#039;&#039;&#039; — so each IP in the LAN gets its own 2 Mb down, 512 Kb up pipe.&lt;br /&gt;
&lt;br /&gt;
== Understanding Limiter Direction ==&lt;br /&gt;
&lt;br /&gt;
Limiters are applied to firewall rules by specifying them under &#039;&#039;&#039;In&#039;&#039;&#039; and &#039;&#039;&#039;Out&#039;&#039;&#039; in the advanced options. The direction of traffic is from the perspective of that interface of the firewall.&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;Traffic coming into the LAN NIC&#039;&#039;&#039; = upload traffic&lt;br /&gt;
* &#039;&#039;&#039;Traffic leaving the LAN NIC&#039;&#039;&#039; = download traffic&lt;br /&gt;
&lt;br /&gt;
The mask of limiters can be configured on a &#039;&#039;&#039;source address&#039;&#039;&#039; or &#039;&#039;&#039;destination address&#039;&#039;&#039; basis:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Limiter !! Mask Setting !! Reason&lt;br /&gt;
|-&lt;br /&gt;
| Download (2M-down) || Destination addresses || Traffic leaving the LAN interface has internal clients&#039; IPs as the destination.&lt;br /&gt;
|-&lt;br /&gt;
| Upload (512K-up) || Source addresses || Traffic entering the LAN interface is sourced from internal clients&#039; IPs.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Configuring Limiters ==&lt;br /&gt;
&lt;br /&gt;
On &#039;&#039;&#039;fw1-HQ&#039;&#039;&#039;, browse to &#039;&#039;&#039;Firewall → Traffic Shaper → Limiters&#039;&#039;&#039; tab. Click &#039;&#039;&#039;New Limiter&#039;&#039;&#039; to add a new limiter.&lt;br /&gt;
&lt;br /&gt;
=== Download Limiter ===&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Setting !! Value&lt;br /&gt;
|-&lt;br /&gt;
| Name || 2M-down&lt;br /&gt;
|-&lt;br /&gt;
| Enable || (checked)&lt;br /&gt;
|-&lt;br /&gt;
| Bandwidth || 2 Mbit/s&lt;br /&gt;
|-&lt;br /&gt;
| Mask || Destination addresses&lt;br /&gt;
|-&lt;br /&gt;
| Description || 2 Mb down per-IP&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
Leave the remainder at defaults and click &#039;&#039;&#039;Save&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
=== Upload Limiter ===&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Setting !! Value&lt;br /&gt;
|-&lt;br /&gt;
| Name || 512K-up&lt;br /&gt;
|-&lt;br /&gt;
| Enable || (checked)&lt;br /&gt;
|-&lt;br /&gt;
| Bandwidth || 512 Kbps&lt;br /&gt;
|-&lt;br /&gt;
| Mask || Source addresses&lt;br /&gt;
|-&lt;br /&gt;
| Description || 512 Kb up per-IP&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
Leave the remainder at defaults, click &#039;&#039;&#039;Save&#039;&#039;&#039;, then &#039;&#039;&#039;Apply Changes&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
== Applying Limiters to Firewall Rules ==&lt;br /&gt;
&lt;br /&gt;
Just configuring the limiters doesn&#039;t make them active. They must be assigned to a firewall rule to be applied.&lt;br /&gt;
&lt;br /&gt;
# Browse to &#039;&#039;&#039;Firewall → Rules → LAN&#039;&#039;&#039;.&lt;br /&gt;
# Edit the &#039;&#039;&#039;&amp;quot;Default allow LAN to any&amp;quot;&#039;&#039;&#039; rule.&lt;br /&gt;
# Scroll down under &#039;&#039;&#039;Advanced&#039;&#039;&#039;, and click the &#039;&#039;&#039;Advanced&#039;&#039;&#039; button to the right of &#039;&#039;&#039;In/Out&#039;&#039;&#039;.&lt;br /&gt;
# For the &#039;&#039;&#039;In&#039;&#039;&#039; limiter, choose &#039;&#039;&#039;512K-up&#039;&#039;&#039;.&lt;br /&gt;
# For the &#039;&#039;&#039;Out&#039;&#039;&#039; limiter, choose &#039;&#039;&#039;2M-down&#039;&#039;&#039;.&lt;br /&gt;
# Click &#039;&#039;&#039;Save&#039;&#039;&#039; and &#039;&#039;&#039;Apply Changes&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
Back at the LAN firewall rules screen, you&#039;ll see the &#039;&#039;&#039;(a)&#039;&#039;&#039; icon to the left of the default LAN rule, meaning one or more advanced options are specified on that rule. Hover your mouse cursor over that button to see what is configured.&lt;br /&gt;
&lt;br /&gt;
== Testing Limiters ==&lt;br /&gt;
&lt;br /&gt;
# Pull up &#039;&#039;&#039;Status → Traffic Graph → WAN&#039;&#039;&#039; on fw1-HQ.&lt;br /&gt;
# Run a speed test (e.g., speedtest.net).&lt;br /&gt;
# You should see speeds of approximately &#039;&#039;&#039;2 Mb down, 512 Kb up&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
== Traffic Shaper Basic Configuration (Wizard) ==&lt;br /&gt;
&lt;br /&gt;
In this section we configure a basic traffic shaping setup prioritizing VoIP over all else at the branch location (fw1-branch).&lt;br /&gt;
&lt;br /&gt;
=== Wizard Setup ===&lt;br /&gt;
&lt;br /&gt;
# Browse to &#039;&#039;&#039;Firewall → Traffic Shaper → Wizards&#039;&#039;&#039;.&lt;br /&gt;
# Choose &#039;&#039;&#039;traffic_shaper_wizard_multi_all.xml&#039;&#039;&#039;.&lt;br /&gt;
# At the first screen, specify &#039;&#039;&#039;1&#039;&#039;&#039; for the number of WAN and LAN connections and click &#039;&#039;&#039;Next&#039;&#039;&#039;.&lt;br /&gt;
# Choose &#039;&#039;&#039;PRIQ&#039;&#039;&#039; for both download and upload schedulers.&lt;br /&gt;
# Specify connection bandwidth as &#039;&#039;&#039;100 Mbit/s&#039;&#039;&#039; upload and download.&lt;br /&gt;
# Click &#039;&#039;&#039;Next&#039;&#039;&#039;.&lt;br /&gt;
# Check &#039;&#039;&#039;&amp;quot;Prioritize Voice over IP traffic&amp;quot;&#039;&#039;&#039;. Fill in &#039;&#039;&#039;128 Kbit/s&#039;&#039;&#039; for upload and download bandwidth (not actually used with PRIQ).&lt;br /&gt;
# Click &#039;&#039;&#039;Next&#039;&#039;&#039; three times past penalty box, peer-to-peer networking, and network games.&lt;br /&gt;
# At the &#039;&#039;&#039;&amp;quot;Raise or lower other applications&amp;quot;&#039;&#039;&#039; screen, enable it and choose &#039;&#039;&#039;VNC&#039;&#039;&#039; as higher priority.&lt;br /&gt;
# Click &#039;&#039;&#039;Finish&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
== Reviewing Firewall Rule Shaping Configuration ==&lt;br /&gt;
&lt;br /&gt;
Browse to &#039;&#039;&#039;Firewall → Rules → Floating&#039;&#039;&#039; to see the traffic shaper rules added by the wizard. These are match rules which specify the appropriate queue for each type of traffic.&lt;br /&gt;
&lt;br /&gt;
* The VoIP traffic classification ends up as a rule matching all UDP traffic from any source to any destination, with queue &#039;&#039;&#039;qVoIP&#039;&#039;&#039;.&lt;br /&gt;
* All traffic not matching a floating rule specifying a queue will go into the &#039;&#039;&#039;default queue&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
== Reviewing Shaper Queue Configuration ==&lt;br /&gt;
&lt;br /&gt;
Browse to &#039;&#039;&#039;Firewall → Traffic Shaper&#039;&#039;&#039;. The &#039;&#039;&#039;By Interface&#039;&#039;&#039; and &#039;&#039;&#039;By Queue&#039;&#039;&#039; tabs both show configured queues (two different layouts of the same data).&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;By Queue&#039;&#039;&#039; is typically used for manual configuration.&lt;br /&gt;
* &#039;&#039;&#039;By Interface&#039;&#039;&#039; is the standard review view.&lt;br /&gt;
* You can click &#039;&#039;&#039;&amp;quot;Remove Shaper&amp;quot;&#039;&#039;&#039; on the &#039;&#039;&#039;By Interface&#039;&#039;&#039; tab to remove and disable traffic shaping.&lt;br /&gt;
&lt;br /&gt;
== Testing and Checking Status ==&lt;br /&gt;
&lt;br /&gt;
# Reset all states: &#039;&#039;&#039;Diagnostics → States → Reset States&#039;&#039;&#039; tab → click &#039;&#039;&#039;Reset&#039;&#039;&#039;.&lt;br /&gt;
# Browse to &#039;&#039;&#039;Status → Queues&#039;&#039;&#039; and monitor while generating traffic.&lt;br /&gt;
# Run a speed test — the speed test traffic will fall into the &#039;&#039;&#039;default queue&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
== Generating SIP Traffic ==&lt;br /&gt;
&lt;br /&gt;
Use &#039;&#039;&#039;SIPp&#039;&#039;&#039; on the test systems:&lt;br /&gt;
&lt;br /&gt;
On &#039;&#039;&#039;remote-host&#039;&#039;&#039; (100.64.0.50):&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
training@remote-host:~$ sipp -sn uas&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
On &#039;&#039;&#039;branch-client&#039;&#039;&#039; (172.18.1.100):&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
training@branch-client:~$ sipp -sn uac 100.64.0.50&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These commands initiate 10 SIP calls per second indefinitely. View &#039;&#039;&#039;Status → Queues&#039;&#039;&#039; while running to see traffic in the VoIP queue.&lt;br /&gt;
&lt;br /&gt;
== Long-term Monitoring ==&lt;br /&gt;
&lt;br /&gt;
When traffic shaping is enabled, RRD graphs include queue statistics and queue drops.&lt;br /&gt;
&lt;br /&gt;
# Browse to &#039;&#039;&#039;Status → Monitoring&#039;&#039;&#039; and click the wrench icon.&lt;br /&gt;
# For &#039;&#039;&#039;Left Axis&#039;&#039;&#039;, choose &#039;&#039;&#039;Queues&#039;&#039;&#039;.&lt;br /&gt;
# The &#039;&#039;&#039;Queue Drops&#039;&#039;&#039; graph shows packets dropped from each queue.&lt;br /&gt;
&lt;br /&gt;
Ideally, you want to see &#039;&#039;&#039;0 drops&#039;&#039;&#039; across all high-priority queues, with drops limited to lower or default priority traffic.&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;background:#f0f8ff; padding:10px; border-left:4px solid #005500;&amp;quot;&amp;gt;&lt;br /&gt;
&#039;&#039;&#039;Previous Module:&#039;&#039;&#039; [[Training:_Traffic_Shaping|Section 9 — Traffic Shaping (Slides)]]&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Source Attribution ==&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;Document:&#039;&#039;&#039; FUND001-LIVE-Lab9-TrafficShaping.pdf&lt;br /&gt;
* &#039;&#039;&#039;Course:&#039;&#039;&#039; pfSense Plus Fundamentals and Practical Applications&lt;br /&gt;
* &#039;&#039;&#039;Copyright:&#039;&#039;&#039; © 2021 Rubicon Communications, LLC (Netgate)&lt;br /&gt;
* &#039;&#039;&#039;Extracted and formatted for internal training wiki.&#039;&#039;&#039;&lt;/div&gt;</summary>
		<author><name>Justinaquino</name></author>
	</entry>
	<entry>
		<id>https://mediawiki.comfac.net/index.php?title=Training:_Traffic_Shaping&amp;diff=243</id>
		<title>Training: Traffic Shaping</title>
		<link rel="alternate" type="text/html" href="https://mediawiki.comfac.net/index.php?title=Training:_Traffic_Shaping&amp;diff=243"/>
		<updated>2026-04-23T07:10:06Z</updated>

		<summary type="html">&lt;p&gt;Justinaquino: Imported from FUND001-LIVE-SLIDE-SEG9-SHAPE.pdf&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__NOTOC__&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;background:#003366; color:white; padding:12px; border-radius:6px; margin-bottom:16px;&amp;quot;&amp;gt;&lt;br /&gt;
&#039;&#039;&#039;Netgate pfSense Plus Fundamentals — Section 9: Traffic Shaping&#039;&#039;&#039;&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;small&amp;gt;Training slide deck: FUND001-LIVE-SLIDE-SEG9-SHAPE.pdf&amp;lt;/small&amp;gt;&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Traffic Shaping — Overview ==&lt;br /&gt;
&lt;br /&gt;
Traffic shaping is a form of &#039;&#039;&#039;managed unfairness of bandwidth&#039;&#039;&#039;. It helps avoid the default FIFO queueing behavior imposed by ISPs.&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;Queues&#039;&#039;&#039; define traffic priorities.&lt;br /&gt;
* &#039;&#039;&#039;Rules&#039;&#039;&#039; assign traffic to queues.&lt;br /&gt;
* There are two separate methods for shaping:&lt;br /&gt;
** &#039;&#039;&#039;Limiters&#039;&#039;&#039; (dummynet pipes)&lt;br /&gt;
** &#039;&#039;&#039;Traffic Shaper&#039;&#039;&#039; (ALTQ)&lt;br /&gt;
&lt;br /&gt;
== Limiters ==&lt;br /&gt;
&lt;br /&gt;
Limiters provide a quick, easy means of imposing &#039;&#039;&#039;hard bandwidth limits&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
* Can be applied on a &#039;&#039;&#039;group or per-IP basis&#039;&#039;&#039;.&lt;br /&gt;
* Optionally &#039;&#039;&#039;schedule-based&#039;&#039;&#039;.&lt;br /&gt;
* Advanced options include:&lt;br /&gt;
** Queue size&lt;br /&gt;
** Delay&lt;br /&gt;
** Packet Loss&lt;br /&gt;
&lt;br /&gt;
== Traffic Shaping Rules ==&lt;br /&gt;
&lt;br /&gt;
* Rules are evaluated from the &#039;&#039;&#039;point of view of traffic leaving an interface&#039;&#039;&#039;.&lt;br /&gt;
* Typically use &#039;&#039;&#039;floating rules&#039;&#039;&#039; to apply shaping.&lt;br /&gt;
* &#039;&#039;&#039;In/Out&#039;&#039;&#039; options under advanced rule options are used to assign queues.&lt;br /&gt;
* Matches only assign queues — they do not control access.&lt;br /&gt;
&lt;br /&gt;
== Traffic Shaping Wizards ==&lt;br /&gt;
&lt;br /&gt;
The wizards offer an easy way to implement queueing and attempt to automate common scenarios.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Wizard Type !! Description&lt;br /&gt;
|-&lt;br /&gt;
| Multiple LAN/WAN || Most common scenario&lt;br /&gt;
|-&lt;br /&gt;
| Dedicated Links || For dedicated link configurations&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Traffic Shaping Schedulers ==&lt;br /&gt;
&lt;br /&gt;
Schedulers are methods of handling queueing. The following schedulers are available:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Scheduler !! Notes&lt;br /&gt;
|-&lt;br /&gt;
| HFSC || Hierarchical Fair Service Curve&lt;br /&gt;
|-&lt;br /&gt;
| CBQ || Class-Based Queueing&lt;br /&gt;
|-&lt;br /&gt;
| FAIRQ || Legacy scheduler&lt;br /&gt;
|-&lt;br /&gt;
| CODELQ || Legacy scheduler&lt;br /&gt;
|-&lt;br /&gt;
| PRIQ || &#039;&#039;&#039;Easiest solution — recommended wherever possible&#039;&#039;&#039;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Section 9 Summary ==&lt;br /&gt;
&lt;br /&gt;
* Try to keep configurations as simple as possible.&lt;br /&gt;
* Use &#039;&#039;&#039;PRIQ&#039;&#039;&#039; wherever possible.&lt;br /&gt;
* Limiter rules can be on a schedule.&lt;br /&gt;
* Limiters can be per-IP or per-network (masking).&lt;br /&gt;
* Ensure appropriate rule matches.&lt;br /&gt;
* Clear states if needed after making changes.&lt;br /&gt;
* Check the Traffic-Shaping section of the book for more details.&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;background:#f0f8ff; padding:10px; border-left:4px solid #003366;&amp;quot;&amp;gt;&lt;br /&gt;
&#039;&#039;&#039;Next Module:&#039;&#039;&#039; [[Training_Lab_9:_Traffic_Shaping|Lab 9 — Traffic Shaping (Hands-on)]]&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Source Attribution ==&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;Document:&#039;&#039;&#039; FUND001-LIVE-SLIDE-SEG9-SHAPE.pdf&lt;br /&gt;
* &#039;&#039;&#039;Course:&#039;&#039;&#039; pfSense Plus Fundamentals and Practical Applications&lt;br /&gt;
* &#039;&#039;&#039;Copyright:&#039;&#039;&#039; © 2017 Rubicon Communications, LLC dba Netgate&lt;br /&gt;
* &#039;&#039;&#039;Extracted and formatted for internal training wiki.&#039;&#039;&#039;&lt;/div&gt;</summary>
		<author><name>Justinaquino</name></author>
	</entry>
	<entry>
		<id>https://mediawiki.comfac.net/index.php?title=Training_Lab_7:_WireGuard&amp;diff=242</id>
		<title>Training Lab 7: WireGuard</title>
		<link rel="alternate" type="text/html" href="https://mediawiki.comfac.net/index.php?title=Training_Lab_7:_WireGuard&amp;diff=242"/>
		<updated>2026-04-23T07:09:24Z</updated>

		<summary type="html">&lt;p&gt;Justinaquino: Created page with &amp;quot;__NOTOC__  &amp;lt;div style=&amp;quot;background:#e7f3ff;border:1px solid #a3c6ff;padding:10px;margin-bottom:15px;&amp;quot;&amp;gt; &amp;#039;&amp;#039;&amp;#039;Training Lab 7: WireGuard Site-to-Site VPN&amp;#039;&amp;#039;&amp;#039; — pfSense Plus Fundamentals and Practical Application &amp;lt;/div&amp;gt;  == Overview ==  This lab goes through an example configuration of WireGuard for site-to-site VPNs.  WireGuard has no concept of sessions or connections. The protocol uses public and private keys to authenticate and route traffic. WireGuard instances consist of...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__NOTOC__&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;background:#e7f3ff;border:1px solid #a3c6ff;padding:10px;margin-bottom:15px;&amp;quot;&amp;gt;&lt;br /&gt;
&#039;&#039;&#039;Training Lab 7: WireGuard Site-to-Site VPN&#039;&#039;&#039; — pfSense Plus Fundamentals and Practical Application&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Overview ==&lt;br /&gt;
&lt;br /&gt;
This lab goes through an example configuration of WireGuard for site-to-site VPNs.&lt;br /&gt;
&lt;br /&gt;
WireGuard has no concept of sessions or connections. The protocol uses public and private keys to authenticate and route traffic. WireGuard instances consist of a tunnel and one or more peer definitions which contain the necessary keys and other configuration data that allows the two sides to communicate.&lt;br /&gt;
&lt;br /&gt;
== Step 1: Delete OpenVPN ==&lt;br /&gt;
&lt;br /&gt;
First, since we have an OpenVPN configured here already, we need to delete it so it doesn’t interfere with our WireGuard setup. On both fw1-HQ and fw1-branch, browse to &#039;&#039;&#039;VPN → OpenVPN&#039;&#039;&#039; and delete all client and server instances.&lt;br /&gt;
&lt;br /&gt;
== Step 2: Configure WireGuard Settings ==&lt;br /&gt;
&lt;br /&gt;
Browse to &#039;&#039;&#039;VPN → WireGuard → Settings&#039;&#039;&#039; on both firewalls and:&lt;br /&gt;
&lt;br /&gt;
* Click the &#039;&#039;&#039;Enable&#039;&#039;&#039; checkbox&lt;br /&gt;
* For Interface Group Membership, choose &#039;&#039;&#039;Only Unassigned Tunnels&#039;&#039;&#039;&lt;br /&gt;
* Uncheck &#039;&#039;&#039;Hide Secrets&#039;&#039;&#039; and &#039;&#039;&#039;Hide Peers&#039;&#039;&#039;&lt;br /&gt;
* Scroll down and click &#039;&#039;&#039;Save&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== Step 3: Add a New Tunnel on Both Firewalls ==&lt;br /&gt;
&lt;br /&gt;
On FW1-HQ and Branch-FW, navigate to &#039;&#039;&#039;VPN → WireGuard → Tunnels&#039;&#039;&#039; and click the green &#039;&#039;&#039;+Add Tunnel&#039;&#039;&#039; button.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Setting !! Value&lt;br /&gt;
|-&lt;br /&gt;
| Enabled || checked&lt;br /&gt;
|-&lt;br /&gt;
| Description || Site-to-Site VPN&lt;br /&gt;
|-&lt;br /&gt;
| Listen Port || 51820&lt;br /&gt;
|-&lt;br /&gt;
| Interface Keys || Press the blue Generate button&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
Make a note of the public key on &#039;&#039;&#039;BOTH&#039;&#039;&#039; firewalls, as this will be required later. Then click &#039;&#039;&#039;Save&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
== Step 4: Configure a Peer on FW1-HQ ==&lt;br /&gt;
&lt;br /&gt;
Edit the tunnel on FW1-HQ and click &#039;&#039;&#039;+Add Peer&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Setting !! Value&lt;br /&gt;
|-&lt;br /&gt;
| Enable || checked&lt;br /&gt;
|-&lt;br /&gt;
| Description || Branch Office Peer&lt;br /&gt;
|-&lt;br /&gt;
| Dynamic Endpoint || unchecked&lt;br /&gt;
|-&lt;br /&gt;
| Endpoint || 203.0.113.10&lt;br /&gt;
|-&lt;br /&gt;
| Endpoint Port || 51820&lt;br /&gt;
|-&lt;br /&gt;
| Public Key || (paste public key from Branch-FW)&lt;br /&gt;
|-&lt;br /&gt;
| Pre-shared Key || (blank)&lt;br /&gt;
|-&lt;br /&gt;
| Allowed IPs || 10.6.210.0/30 (Tunnel Network), 172.18.1.0/24 (Branch LAN)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
Scroll down and click &#039;&#039;&#039;Save Peer&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
== Step 5: Configure a Peer on Branch-FW ==&lt;br /&gt;
&lt;br /&gt;
Edit the tunnel on Branch-FW and click &#039;&#039;&#039;+Add Peer&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Setting !! Value&lt;br /&gt;
|-&lt;br /&gt;
| Enable || checked&lt;br /&gt;
|-&lt;br /&gt;
| Description || HQ Peer&lt;br /&gt;
|-&lt;br /&gt;
| Dynamic Endpoint || unchecked&lt;br /&gt;
|-&lt;br /&gt;
| Endpoint || 192.0.2.2&lt;br /&gt;
|-&lt;br /&gt;
| Endpoint Port || 51820&lt;br /&gt;
|-&lt;br /&gt;
| Public Key || (paste public key from FW1-HQ)&lt;br /&gt;
|-&lt;br /&gt;
| Pre-shared Key || (blank)&lt;br /&gt;
|-&lt;br /&gt;
| Allowed IPs || 10.6.210.0/30 (Tunnel Network), 172.17.1.0/24 (HQ LAN)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
Scroll down and click &#039;&#039;&#039;Save Peer&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
== Step 6: Assign Interfaces ==&lt;br /&gt;
&lt;br /&gt;
=== Select Default Gateways ===&lt;br /&gt;
&lt;br /&gt;
On both firewalls, navigate to &#039;&#039;&#039;System → Routing&#039;&#039;&#039; and set Default Gateway IPv4 to a specific gateway, such as WANGW. Click &#039;&#039;&#039;Save&#039;&#039;&#039; and &#039;&#039;&#039;Apply&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
=== Assign WireGuard Interface on FW1-HQ ===&lt;br /&gt;
&lt;br /&gt;
Navigate to &#039;&#039;&#039;Interfaces → Assignments&#039;&#039;&#039;, choose the tun_gw0 interface, and click &#039;&#039;&#039;+Add&#039;&#039;&#039; (creates OPT4). Configure OPT4:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Setting !! Value&lt;br /&gt;
|-&lt;br /&gt;
| Enable || checked&lt;br /&gt;
|-&lt;br /&gt;
| Description || BRANCH_VPN&lt;br /&gt;
|-&lt;br /&gt;
| IPv4 Configuration Type || Static IPv4&lt;br /&gt;
|-&lt;br /&gt;
| IPv4 Address || 10.6.210.1/30&lt;br /&gt;
|-&lt;br /&gt;
| Gateway Name || VPN_BRANCHGW&lt;br /&gt;
|-&lt;br /&gt;
| Gateway IPv4 || 10.6.210.2&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Assign WireGuard Interface on Branch-FW ===&lt;br /&gt;
&lt;br /&gt;
Navigate to &#039;&#039;&#039;Interfaces → Assignments&#039;&#039;&#039;, choose the tun_gw0 interface, and click &#039;&#039;&#039;+Add&#039;&#039;&#039; (creates OPT1). Configure OPT1:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Setting !! Value&lt;br /&gt;
|-&lt;br /&gt;
| Enable || checked&lt;br /&gt;
|-&lt;br /&gt;
| Description || HQ_VPN&lt;br /&gt;
|-&lt;br /&gt;
| IPv4 Configuration Type || Static IPv4&lt;br /&gt;
|-&lt;br /&gt;
| IPv4 Address || 10.6.210.2/30&lt;br /&gt;
|-&lt;br /&gt;
| Gateway Name || VPN_HQGW&lt;br /&gt;
|-&lt;br /&gt;
| Gateway IPv4 || 10.6.210.1&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Step 7: Create Firewall Rules on WAN ==&lt;br /&gt;
&lt;br /&gt;
On both firewalls, navigate to &#039;&#039;&#039;Firewall → Rules → WAN&#039;&#039;&#039; and add a rule to the top:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Setting !! Value&lt;br /&gt;
|-&lt;br /&gt;
| Action || Pass&lt;br /&gt;
|-&lt;br /&gt;
| Protocol || UDP&lt;br /&gt;
|-&lt;br /&gt;
| Source || Any&lt;br /&gt;
|-&lt;br /&gt;
| Destination || WAN Address&lt;br /&gt;
|-&lt;br /&gt;
| Destination Port || 51820&lt;br /&gt;
|-&lt;br /&gt;
| Description || Pass traffic to WireGuard&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
Click &#039;&#039;&#039;Save&#039;&#039;&#039; and &#039;&#039;&#039;Apply Changes&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
== Step 8: Add Routing Between Sites ==&lt;br /&gt;
&lt;br /&gt;
=== HQ-FW1 Static Route ===&lt;br /&gt;
&lt;br /&gt;
Navigate to &#039;&#039;&#039;System → Routing → Static Routes&#039;&#039;&#039; and click &#039;&#039;&#039;+Add&#039;&#039;&#039;:&lt;br /&gt;
* Destination Network: 172.18.1.0/24&lt;br /&gt;
* Gateway: VPN_BRANCHGW&lt;br /&gt;
&lt;br /&gt;
=== Branch-FW Static Route ===&lt;br /&gt;
&lt;br /&gt;
Navigate to &#039;&#039;&#039;System → Routing → Static Routes&#039;&#039;&#039; and click &#039;&#039;&#039;+Add&#039;&#039;&#039;:&lt;br /&gt;
* Destination Network: 172.17.1.0/24&lt;br /&gt;
* Gateway: VPN_HQGW&lt;br /&gt;
&lt;br /&gt;
== Step 9: Allow Tunnel Traffic ==&lt;br /&gt;
&lt;br /&gt;
=== HQ-FW1 Tunnel Rule ===&lt;br /&gt;
&lt;br /&gt;
On HQ-FW1, navigate to &#039;&#039;&#039;Firewall → Rules → BRANCH_VPN&#039;&#039;&#039; and add:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Setting !! Value&lt;br /&gt;
|-&lt;br /&gt;
| Action || Pass&lt;br /&gt;
|-&lt;br /&gt;
| Interface || BRANCH_VPN&lt;br /&gt;
|-&lt;br /&gt;
| Protocol || Any&lt;br /&gt;
|-&lt;br /&gt;
| Source || Any&lt;br /&gt;
|-&lt;br /&gt;
| Destination || Any&lt;br /&gt;
|-&lt;br /&gt;
| Description || Allow WireGuard VPN Traffic&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Branch-FW Tunnel Rule ===&lt;br /&gt;
&lt;br /&gt;
On Branch-FW, navigate to &#039;&#039;&#039;Firewall → Rules → HQ_VPN&#039;&#039;&#039; and add the same rule (Interface: HQ_VPN).&lt;br /&gt;
&lt;br /&gt;
== Step 10: Testing ==&lt;br /&gt;
&lt;br /&gt;
WireGuard doesn’t have much status information. In most cases it either works if you configured it properly, or it does not. One place to look is for the existence of a recent “handshake.”&lt;br /&gt;
&lt;br /&gt;
=== Check Status ===&lt;br /&gt;
&lt;br /&gt;
On each firewall, navigate to &#039;&#039;&#039;VPN → WireGuard → Status&#039;&#039;&#039;. One of the only indicators that the VPN is up is the presence of the peer’s handshake.&lt;br /&gt;
&lt;br /&gt;
=== Try to Ping Across ===&lt;br /&gt;
&lt;br /&gt;
From the HQ-Client, try to ping the Branch-FW LAN interface at &#039;&#039;&#039;172.18.1.1&#039;&#039;&#039;. If the tunnel is up, your pings should be successful.&lt;br /&gt;
&lt;br /&gt;
If the pings failed, you have a configuration issue and need to check your configuration.&lt;br /&gt;
&lt;br /&gt;
== Troubleshooting ==&lt;br /&gt;
&lt;br /&gt;
Due to its stateless nature, WireGuard doesn’t have status screens, and there is very little logging to be consulted. If your tunnel fails:&lt;br /&gt;
&lt;br /&gt;
* Check the peer settings on both sides, paying particular attention to the public keys of the far-end peers&lt;br /&gt;
* Check for an active WireGuard state by navigating to &#039;&#039;&#039;Diagnostics → States&#039;&#039;&#039; and searching for a state that matches port 51820&lt;br /&gt;
&lt;br /&gt;
The existence of this state can indicate that the VPN is connected. This state may age out, so you may need to try your ping again to bring it back up.&lt;br /&gt;
&lt;br /&gt;
Once you are satisfied that WireGuard is working, you may delete it in order to simplify the next labs.&lt;br /&gt;
&lt;br /&gt;
== Next Module ==&lt;br /&gt;
* [[Training: WireGuard|← Back to Training: WireGuard]]&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&amp;lt;small&amp;gt;&#039;&#039;&#039;Source:&#039;&#039;&#039; Netgate pfSense Training — FUND001-LIVE-Lab7-WireGuard.pdf (© 2015-2021 Electric Sheep Fencing LLC)&amp;lt;/small&amp;gt;&lt;/div&gt;</summary>
		<author><name>Justinaquino</name></author>
	</entry>
	<entry>
		<id>https://mediawiki.comfac.net/index.php?title=Training:_WireGuard&amp;diff=241</id>
		<title>Training: WireGuard</title>
		<link rel="alternate" type="text/html" href="https://mediawiki.comfac.net/index.php?title=Training:_WireGuard&amp;diff=241"/>
		<updated>2026-04-23T07:09:24Z</updated>

		<summary type="html">&lt;p&gt;Justinaquino: Created page with &amp;quot;__NOTOC__  &amp;lt;div style=&amp;quot;background:#e7f3ff;border:1px solid #a3c6ff;padding:10px;margin-bottom:15px;&amp;quot;&amp;gt; &amp;#039;&amp;#039;&amp;#039;Training Module: WireGuard (Section 7)&amp;#039;&amp;#039;&amp;#039; — pfSense Plus Fundamentals and Practical Application &amp;lt;/div&amp;gt;  == Introduction ==  WireGuard is a very new VPN technology that is entirely stateless.  * Tends to be very performant * Lives in the kernel space * Uses “Crypto-Key Routing” * Ensures routing traffic to correct destination * Very little status info — it work...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__NOTOC__&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;background:#e7f3ff;border:1px solid #a3c6ff;padding:10px;margin-bottom:15px;&amp;quot;&amp;gt;&lt;br /&gt;
&#039;&#039;&#039;Training Module: WireGuard (Section 7)&#039;&#039;&#039; — pfSense Plus Fundamentals and Practical Application&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Introduction ==&lt;br /&gt;
&lt;br /&gt;
WireGuard is a very new VPN technology that is entirely stateless.&lt;br /&gt;
&lt;br /&gt;
* Tends to be very performant&lt;br /&gt;
* Lives in the kernel space&lt;br /&gt;
* Uses “Crypto-Key Routing”&lt;br /&gt;
* Ensures routing traffic to correct destination&lt;br /&gt;
* Very little status info — it works or it doesn’t&lt;br /&gt;
* Easy roaming between networks&lt;br /&gt;
* Endpoint IP always updated&lt;br /&gt;
* Configuration may be more time-consuming&lt;br /&gt;
&lt;br /&gt;
== Simplified Codebase ==&lt;br /&gt;
&lt;br /&gt;
WireGuard has a dramatically smaller codebase compared to traditional VPN solutions:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Protocol !! Lines of Code&lt;br /&gt;
|-&lt;br /&gt;
| IPsec || ~ 400,000&lt;br /&gt;
|-&lt;br /&gt;
| OpenVPN || ~ 600,000&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;WireGuard&#039;&#039;&#039; || &#039;&#039;&#039;~ 4,000&#039;&#039;&#039;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
Less Code = Greater Efficiency&lt;br /&gt;
&lt;br /&gt;
== Rigid Crypto Protocols ==&lt;br /&gt;
&lt;br /&gt;
WireGuard uses modern, rigidly defined cryptographic protocols:&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;ChaCha20&#039;&#039;&#039; for symmetric encryption, authenticated with &#039;&#039;&#039;Poly1305&#039;&#039;&#039;&lt;br /&gt;
* &#039;&#039;&#039;Curve25519&#039;&#039;&#039; for ECDH&lt;br /&gt;
* &#039;&#039;&#039;BLAKE2s&#039;&#039;&#039; for hashing and keyed hashing&lt;br /&gt;
* &#039;&#039;&#039;SipHash24&#039;&#039;&#039; for hashtable keys&lt;br /&gt;
* &#039;&#039;&#039;HKDF&#039;&#039;&#039; for key derivation&lt;br /&gt;
&lt;br /&gt;
== Site-to-Site ==&lt;br /&gt;
&lt;br /&gt;
WireGuard creates a local wg0 interface. Peers have their own public &amp;amp; private keys.&lt;br /&gt;
&lt;br /&gt;
* Exchange public key with peers&lt;br /&gt;
* Crypto-key routing — looks up peer wg0 address and public key&lt;br /&gt;
* Forwards traffic out local wg0 interface to peer&lt;br /&gt;
&lt;br /&gt;
== Local Setup ==&lt;br /&gt;
&lt;br /&gt;
Some assembly required:&lt;br /&gt;
&lt;br /&gt;
# Activate the service&lt;br /&gt;
# Give wg0 a local IP/mask&lt;br /&gt;
# Generate Public/Private keys&lt;br /&gt;
# Assign wg0 to an OPT interface&lt;br /&gt;
# Create a gateway&lt;br /&gt;
# Open WG port on firewall&lt;br /&gt;
# Create firewall rules to allow traffic&lt;br /&gt;
&lt;br /&gt;
== Peer Setup ==&lt;br /&gt;
&lt;br /&gt;
Required information for peer configuration:&lt;br /&gt;
&lt;br /&gt;
* Peer’s initial end-point IP&lt;br /&gt;
* Peer’s public key&lt;br /&gt;
* Peer’s wg0 IP (typically same as allowed IPs)&lt;br /&gt;
&lt;br /&gt;
Assuming peer’s firewall is setup, try ping!&lt;br /&gt;
&lt;br /&gt;
== Summary ==&lt;br /&gt;
&lt;br /&gt;
* WireGuard is completely stateless&lt;br /&gt;
* Updated crypto protocols&lt;br /&gt;
* Uses crypto-key routing — routing table not a factor&lt;br /&gt;
* Requires its own OPT interface and gateway&lt;br /&gt;
* Very limited status information&lt;br /&gt;
* &#039;&#039;&#039;It works, or it doesn’t&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== Next Module ==&lt;br /&gt;
* [[Training Lab 7: WireGuard|Lab 7: WireGuard — Site-to-Site VPN Configuration]]&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&amp;lt;small&amp;gt;&#039;&#039;&#039;Source:&#039;&#039;&#039; Netgate pfSense Training — FUND001-LIVE-SLIDE-SEG7-WG.pdf (© 2017 Rubicon Communications dba Netgate)&amp;lt;/small&amp;gt;&lt;/div&gt;</summary>
		<author><name>Justinaquino</name></author>
	</entry>
	<entry>
		<id>https://mediawiki.comfac.net/index.php?title=Training_Lab_6:_OpenVPN&amp;diff=240</id>
		<title>Training Lab 6: OpenVPN</title>
		<link rel="alternate" type="text/html" href="https://mediawiki.comfac.net/index.php?title=Training_Lab_6:_OpenVPN&amp;diff=240"/>
		<updated>2026-04-23T07:08:32Z</updated>

		<summary type="html">&lt;p&gt;Justinaquino: Automated upload of Netgate pfSense training content&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__NOTOC__&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;background:#e7f3ff; border-left:6px solid #2196F3; padding:10px; margin-bottom:15px;&amp;quot;&amp;gt;&lt;br /&gt;
&#039;&#039;&#039;Training Lab 6: OpenVPN&#039;&#039;&#039;&amp;lt;br/&amp;gt;&lt;br /&gt;
Hands-on lab covering site-to-site SSL/TLS VPN, remote access VPN, certificate infrastructure, and testing in pfSense.&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Overview ==&lt;br /&gt;
&lt;br /&gt;
This lab goes through example configurations of OpenVPN for site-to-site and remote access.&lt;br /&gt;
&lt;br /&gt;
== OpenVPN SSL/TLS Site-to-Site VPN ==&lt;br /&gt;
&lt;br /&gt;
We’re going to configure OpenVPN to connect the HQ and branch networks. HQ will run the server, and the branch will be the client.&lt;br /&gt;
&lt;br /&gt;
There is no functional difference in whether HQ or branch runs the server side. Most often people put the server instances on the main location’s end. If one end has a dynamic IP and one static, run the server on the static IP side. If one end is behind NAT, that end should be the client. In this case, the server side will be on the fw1-hq firewall.&lt;br /&gt;
&lt;br /&gt;
=== Delete IPsec ===&lt;br /&gt;
&lt;br /&gt;
First, since we have an IPsec VPN configured here already, IPsec needs to be disabled. On both fw1-HQ and fw1-branch, browse to &#039;&#039;&#039;VPN &amp;gt; IPsec&#039;&#039;&#039;. Put a check mark by each IPsec tunnel and click &#039;&#039;&#039;Delete P1s&#039;&#039;&#039;. Click &#039;&#039;&#039;Save&#039;&#039;&#039;, then &#039;&#039;&#039;Apply Changes&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
=== Create the Certificate Infrastructure ===&lt;br /&gt;
&lt;br /&gt;
OpenVPN makes use of a certificate infrastructure in authenticating the session as well as routing traffic to and from member sites. On the server we must create a new Certificate Authority (CA), as well as server and client certificate/key pairs. This will be done on fw1-hq.&lt;br /&gt;
&lt;br /&gt;
==== Create the Certificate Authority (CA) ====&lt;br /&gt;
&lt;br /&gt;
Navigate to &#039;&#039;&#039;System &amp;gt; Cert Manager&#039;&#039;&#039; and click the green &#039;&#039;&#039;+Add&#039;&#039;&#039; button to add a new CA.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Field !! Value&lt;br /&gt;
|-&lt;br /&gt;
| Descriptive Name || S2SCA&lt;br /&gt;
|-&lt;br /&gt;
| Method || Create an Internal Certificate Authority&lt;br /&gt;
|-&lt;br /&gt;
| Randomize Serial || (checked)&lt;br /&gt;
|-&lt;br /&gt;
| Key Type || RSA 2048&lt;br /&gt;
|-&lt;br /&gt;
| Digest Algorithm || sha256&lt;br /&gt;
|-&lt;br /&gt;
| Lifetime || 3650&lt;br /&gt;
|-&lt;br /&gt;
| Common Name || S2SCA&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
(Leave the rest blank and click &#039;&#039;&#039;Save&#039;&#039;&#039;.)&lt;br /&gt;
&lt;br /&gt;
==== Create the Server Certificate ====&lt;br /&gt;
&lt;br /&gt;
Next, click on the &#039;&#039;&#039;Certificates&#039;&#039;&#039; tab, and click the green &#039;&#039;&#039;+Add/Sign&#039;&#039;&#039; button near the bottom.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Field !! Value&lt;br /&gt;
|-&lt;br /&gt;
| Method || Create an internal server certificate&lt;br /&gt;
|-&lt;br /&gt;
| Descriptive Name || VPNserver&lt;br /&gt;
|-&lt;br /&gt;
| Certificate Authority || S2SCA&lt;br /&gt;
|-&lt;br /&gt;
| Key Type || RSA 2048&lt;br /&gt;
|-&lt;br /&gt;
| Digest Algorithm || sha256&lt;br /&gt;
|-&lt;br /&gt;
| Lifetime || 398&lt;br /&gt;
|-&lt;br /&gt;
| Common Name || VPNserver&lt;br /&gt;
|-&lt;br /&gt;
| Certificate Type || Server Certificate&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
Scroll down and click &#039;&#039;&#039;Save&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
==== Create the Client Certificate ====&lt;br /&gt;
&lt;br /&gt;
While still on the &#039;&#039;&#039;Certificates&#039;&#039;&#039; tab, click the green &#039;&#039;&#039;+Add/Sign&#039;&#039;&#039; button near the bottom to create the client certificate.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Field !! Value&lt;br /&gt;
|-&lt;br /&gt;
| Method || Create an internal certificate&lt;br /&gt;
|-&lt;br /&gt;
| Descriptive Name || VPNclient&lt;br /&gt;
|-&lt;br /&gt;
| Certificate Authority || S2SCA&lt;br /&gt;
|-&lt;br /&gt;
| Key Type || RSA 2048&lt;br /&gt;
|-&lt;br /&gt;
| Digest Algorithm || sha256&lt;br /&gt;
|-&lt;br /&gt;
| Lifetime || 3650&lt;br /&gt;
|-&lt;br /&gt;
| Common Name || VPNclient&lt;br /&gt;
|-&lt;br /&gt;
| Certificate Type || User Certificate&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
Scroll down and click &#039;&#039;&#039;Save&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
==== Export Certificates and Keys ====&lt;br /&gt;
&lt;br /&gt;
The next task is to export the certificates and keys which the client requires when connecting to the OpenVPN server.&lt;br /&gt;
&lt;br /&gt;
# Navigate to &#039;&#039;&#039;System &amp;gt; Cert Manager &amp;gt; CAs&#039;&#039;&#039; and find the S2SCA. Click the export button to save the CA certificate to the downloads folder on HQ-Client.&lt;br /&gt;
# Next, click on the &#039;&#039;&#039;Certificates&#039;&#039;&#039; tab and scroll down until you see the VPNclient certificate entry. Click the export button to save the certificate data and the key data to the Downloads folder on HQ-Client.&lt;br /&gt;
&lt;br /&gt;
=== Configure Server on fw1-HQ ===&lt;br /&gt;
&lt;br /&gt;
Browse to &#039;&#039;&#039;VPN &amp;gt; OpenVPN&#039;&#039;&#039; on fw1-HQ. On the &#039;&#039;&#039;Server&#039;&#039;&#039; tab, click &#039;&#039;&#039;+Add&#039;&#039;&#039; to add a new server instance.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Field !! Value&lt;br /&gt;
|-&lt;br /&gt;
| Server Mode || Peer to Peer (SSL/TLS)&lt;br /&gt;
|-&lt;br /&gt;
| Description || HQ to Branch VPN&lt;br /&gt;
|-&lt;br /&gt;
| TLS Configuration || (checked)&lt;br /&gt;
|-&lt;br /&gt;
| Automatically generate TLS key || (checked)&lt;br /&gt;
|-&lt;br /&gt;
| Peer Certificate Authority || S2SCA&lt;br /&gt;
|-&lt;br /&gt;
| Server Certificate || VPNserver&lt;br /&gt;
|-&lt;br /&gt;
| IPv4 Tunnel Network || 172.17.6.0/24&lt;br /&gt;
|-&lt;br /&gt;
| IPv4 Local Network(s) || 172.17.1.0/24, 172.17.2.0/24, 172.18.1.0/24&lt;br /&gt;
|-&lt;br /&gt;
| IPv4 Remote Network(s) || 172.18.1.0/24&lt;br /&gt;
|-&lt;br /&gt;
| Inactive || 0 (connections can stay up indefinitely)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
Click &#039;&#039;&#039;Save&#039;&#039;&#039; at the bottom, then click the edit icon to edit the server you just created. Highlight and copy the entire contents of the &#039;&#039;&#039;TLS Key&#039;&#039;&#039; box. Paste it into a file called &#039;&#039;&#039;TLS.key&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
This TLS key will be needed on the client side of the connection.&lt;br /&gt;
&lt;br /&gt;
=== Create Client-Specific Overrides ===&lt;br /&gt;
&lt;br /&gt;
The purpose of the Client-Specific Override (CSO) is to tie a client’s subnet to their certificate. Navigate to &#039;&#039;&#039;VPN &amp;gt; OpenVPN&#039;&#039;&#039; and click the &#039;&#039;&#039;Client Specific Overrides&#039;&#039;&#039; tab. Click the green &#039;&#039;&#039;+Add&#039;&#039;&#039; button.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Field !! Value&lt;br /&gt;
|-&lt;br /&gt;
| Server List || HQ to Branch VPN&lt;br /&gt;
|-&lt;br /&gt;
| Common Name || VPNclient&lt;br /&gt;
|-&lt;br /&gt;
| IPv4 Remote Network || 172.18.1.0/24&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
Leave everything else blank or default, scroll down and click &#039;&#039;&#039;Save&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
=== Permit Traffic to Server ===&lt;br /&gt;
&lt;br /&gt;
Now we need to add a firewall rule to permit the outside portion of the VPN, from the client to the server. On fw1-HQ, browse to &#039;&#039;&#039;Firewall &amp;gt; Rules &amp;gt; WAN&#039;&#039;&#039;. Click &#039;&#039;&#039;Add&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Field !! Value&lt;br /&gt;
|-&lt;br /&gt;
| Action || Pass&lt;br /&gt;
|-&lt;br /&gt;
| Interface || WAN&lt;br /&gt;
|-&lt;br /&gt;
| Protocol || UDP&lt;br /&gt;
|-&lt;br /&gt;
| Source || 203.0.113.10&lt;br /&gt;
|-&lt;br /&gt;
| Source port || any&lt;br /&gt;
|-&lt;br /&gt;
| Destination || WAN address&lt;br /&gt;
|-&lt;br /&gt;
| Destination port || 1194&lt;br /&gt;
|-&lt;br /&gt;
| Description || allow branch OpenVPN site to site&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
Then click &#039;&#039;&#039;Save&#039;&#039;&#039; and &#039;&#039;&#039;Apply Changes&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
=== Permit Traffic within VPN ===&lt;br /&gt;
&lt;br /&gt;
Traffic within OpenVPN connections is filtered by the firewall rules on the OpenVPN tab. Browse to &#039;&#039;&#039;Firewall &amp;gt; Rules &amp;gt; OpenVPN&#039;&#039;&#039;. Click &#039;&#039;&#039;Add&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Field !! Value&lt;br /&gt;
|-&lt;br /&gt;
| Interface || OpenVPN&lt;br /&gt;
|-&lt;br /&gt;
| Protocol || Any&lt;br /&gt;
|-&lt;br /&gt;
| Source || Network, 172.18.0.0/16&lt;br /&gt;
|-&lt;br /&gt;
| Destination || any&lt;br /&gt;
|-&lt;br /&gt;
| Description || allow branch network&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
Click &#039;&#039;&#039;Save&#039;&#039;&#039; and &#039;&#039;&#039;Apply Changes&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
The server-side configuration is now complete.&lt;br /&gt;
&lt;br /&gt;
=== Configure Client on fw1-branch ===&lt;br /&gt;
&lt;br /&gt;
Before we can create the client side of the VPN, we must first import the CA and Client Certificate and Keys into the fw1-branch firewall.&lt;br /&gt;
&lt;br /&gt;
==== Import the CA Certificate ====&lt;br /&gt;
&lt;br /&gt;
Click on &#039;&#039;&#039;System &amp;gt; Cert Manager&#039;&#039;&#039; and click the green &#039;&#039;&#039;+Add&#039;&#039;&#039; button.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Field !! Value&lt;br /&gt;
|-&lt;br /&gt;
| Descriptive Name || S2SCA&lt;br /&gt;
|-&lt;br /&gt;
| Method || Import an existing Certificate Authority&lt;br /&gt;
|-&lt;br /&gt;
| Certificate Data || Paste contents of S2SCA.crt&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
Highlight all the contents of the &#039;&#039;&#039;S2SCA.crt&#039;&#039;&#039; file, and paste it into the &#039;&#039;&#039;Certificate Data&#039;&#039;&#039; field on fw1-branch, and click &#039;&#039;&#039;Save&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
==== Import the Client Certificate and Key ====&lt;br /&gt;
&lt;br /&gt;
Click on the &#039;&#039;&#039;Certificates&#039;&#039;&#039; tab and click the green &#039;&#039;&#039;+Add/Sign&#039;&#039;&#039; button near the bottom to import your Client Certificate.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Field !! Value&lt;br /&gt;
|-&lt;br /&gt;
| Method || Import an existing certificate&lt;br /&gt;
|-&lt;br /&gt;
| Descriptive Name || VPNclient&lt;br /&gt;
|-&lt;br /&gt;
| Certificate Data || Paste contents of VPNclient.crt&lt;br /&gt;
|-&lt;br /&gt;
| Certificate Key || Paste contents of VPNclient.key&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
Click &#039;&#039;&#039;Save&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
==== Create the OpenVPN Client ====&lt;br /&gt;
&lt;br /&gt;
Navigate to &#039;&#039;&#039;VPN &amp;gt; OpenVPN&#039;&#039;&#039; and click on the &#039;&#039;&#039;Clients&#039;&#039;&#039; tab. Click the green &#039;&#039;&#039;+Add&#039;&#039;&#039; button.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Field !! Value&lt;br /&gt;
|-&lt;br /&gt;
| Server Mode || Peer to Peer (SSL/TLS)&lt;br /&gt;
|-&lt;br /&gt;
| Device Mode || tun&lt;br /&gt;
|-&lt;br /&gt;
| Server host or address || 192.0.2.2&lt;br /&gt;
|-&lt;br /&gt;
| Description || Branch to HQ VPN&lt;br /&gt;
|-&lt;br /&gt;
| Automatically generate a TLS key || UNCHECKED&lt;br /&gt;
|-&lt;br /&gt;
| Peer Certificate Authority || S2SCA&lt;br /&gt;
|-&lt;br /&gt;
| Client Certificate || VPNclient&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
(Here, you will edit the OpenVPN server configuration on fw1-hq, and copy the TLS key data from that server configuration into this client’s TLS key box. You may have saved this file on your HQ-Client as &#039;&#039;&#039;TLS.key&#039;&#039;&#039;.)&lt;br /&gt;
&lt;br /&gt;
Scroll down and click &#039;&#039;&#039;Save&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
==== Permit Traffic within VPN ====&lt;br /&gt;
&lt;br /&gt;
Add a firewall rule to permit traffic within the VPN, same as the other side but changing the source to HQ’s 172.17.0.0/16.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Field !! Value&lt;br /&gt;
|-&lt;br /&gt;
| Action || Pass&lt;br /&gt;
|-&lt;br /&gt;
| Interface || OpenVPN&lt;br /&gt;
|-&lt;br /&gt;
| Protocol || Any&lt;br /&gt;
|-&lt;br /&gt;
| Source || 172.17.0.0/16&lt;br /&gt;
|-&lt;br /&gt;
| Destination || any&lt;br /&gt;
|-&lt;br /&gt;
| Description || Allow HQ&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Save&#039;&#039;&#039; and &#039;&#039;&#039;Apply Changes&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
=== Check Status and Test ===&lt;br /&gt;
&lt;br /&gt;
On fw1-branch, browse to &#039;&#039;&#039;Status &amp;gt; OpenVPN&#039;&#039;&#039;. There you should see the status as up. If not, skip to the troubleshooting section.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Testing:&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
From HQ-client, try to ping fw1-branch and branch-client:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
training@hq-client:~$ ping -c 3 172.18.1.1&lt;br /&gt;
PING 172.18.1.1 (172.18.1.1) 56(84) bytes of data.&lt;br /&gt;
64 bytes from 172.18.1.1: icmp_seq=1 ttl=63 time=2.40 ms&lt;br /&gt;
...&lt;br /&gt;
--- 172.18.1.1 ping statistics ---&lt;br /&gt;
3 packets transmitted, 3 received, 0% packet loss, time 2004ms&lt;br /&gt;
rtt min/avg/max/mdev = 2.406/3.841/4.843/1.043 ms&lt;br /&gt;
&lt;br /&gt;
training@hq-client:~$ ping -c 3 172.18.1.100&lt;br /&gt;
PING 172.18.1.100 (172.18.1.100) 56(84) bytes of data.&lt;br /&gt;
64 bytes from 172.18.1.100: icmp_seq=1 ttl=62 time=4.26 ms&lt;br /&gt;
...&lt;br /&gt;
--- 172.18.1.100 ping statistics ---&lt;br /&gt;
3 packets transmitted, 3 received, 0% packet loss, time 2003ms&lt;br /&gt;
rtt min/avg/max/mdev = 3.783/4.309/4.877/0.447 ms&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Then from branch-client, try to ping HQ-client and server1:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
training@branch-client:~$ ping -c 3 172.17.1.100&lt;br /&gt;
PING 172.17.1.100 (172.17.1.100) 56(84) bytes of data.&lt;br /&gt;
64 bytes from 172.17.1.100: icmp_seq=1 ttl=62 time=3.73 ms&lt;br /&gt;
64 bytes from 172.17.1.100: icmp_seq=2 ttl=62 time=5.21 ms&lt;br /&gt;
64 bytes from 172.17.1.100: icmp_seq=3 ttl=62 time=5.14 ms&lt;br /&gt;
--- 172.17.1.100 ping statistics ---&lt;br /&gt;
3 packets transmitted, 3 received, 0% packet loss, time 2003ms&lt;br /&gt;
rtt min/avg/max/mdev = 3.730/4.698/5.219/0.685 ms&lt;br /&gt;
&lt;br /&gt;
training@branch-client:~$ ping -c 3 172.17.2.10&lt;br /&gt;
PING 172.17.2.10 (172.17.2.10) 56(84) bytes of data.&lt;br /&gt;
64 bytes from 172.17.2.10: icmp_seq=1 ttl=62 time=4.02 ms&lt;br /&gt;
64 bytes from 172.17.2.10: icmp_seq=2 ttl=62 time=4.01 ms&lt;br /&gt;
64 bytes from 172.17.2.10: icmp_seq=3 ttl=62 time=5.19 ms&lt;br /&gt;
--- 172.17.2.10 ping statistics ---&lt;br /&gt;
3 packets transmitted, 3 received, 0% packet loss, time 2004ms&lt;br /&gt;
rtt min/avg/max/mdev = 4.011/4.408/5.192/0.554 ms&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
You can also try browsing to server1 from branch-client: &amp;lt;code&amp;gt;http://172.17.2.10&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Troubleshooting ===&lt;br /&gt;
&lt;br /&gt;
If the client side status doesn’t show as up, check the troubleshooting section of the OpenVPN chapter in the book for guidance. The most likely causes are an incorrect or missing firewall rule on the WAN of the server (port 1194 rule created above). Check fw1-HQ firewall logs for any blocks. If it’s not getting blocked, and connectivity between the sites works in general, something in the OpenVPN server or client configuration is the likely cause. Double check your configuration on both the client and server, and ensure the shared key was pasted over correctly.&lt;br /&gt;
&lt;br /&gt;
== OpenVPN Remote Access VPN ==&lt;br /&gt;
&lt;br /&gt;
In this section we’re going to set up an OpenVPN remote access server for remote mobile clients.&lt;br /&gt;
&lt;br /&gt;
=== Server Setup Wizard ===&lt;br /&gt;
&lt;br /&gt;
On fw1-HQ, browse to &#039;&#039;&#039;VPN &amp;gt; OpenVPN&#039;&#039;&#039;, and click the &#039;&#039;&#039;Wizard&#039;&#039;&#039; tab.&lt;br /&gt;
&lt;br /&gt;
=== Authentication Backend ===&lt;br /&gt;
&lt;br /&gt;
Choose &#039;&#039;&#039;Local User Access&#039;&#039;&#039; and click &#039;&#039;&#039;Next&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
=== Create New Certificate Authority ===&lt;br /&gt;
&lt;br /&gt;
Fill in these values as desired. The locale information has no functional impact and generally isn’t visible anywhere unless you go looking for it.&lt;br /&gt;
&lt;br /&gt;
=== Create New Server Certificate ===&lt;br /&gt;
&lt;br /&gt;
Again, fill in these values as desired.&lt;br /&gt;
&lt;br /&gt;
=== OpenVPN Server Configuration ===&lt;br /&gt;
&lt;br /&gt;
Most things can be left at defaults here. The port must be changed, since we’re already using port 1194 for the site-to-site VPN server.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Field !! Value&lt;br /&gt;
|-&lt;br /&gt;
| Local Port || 1195&lt;br /&gt;
|-&lt;br /&gt;
| Description || Remote Access VPN&lt;br /&gt;
|-&lt;br /&gt;
| Tunnel Network || 172.17.4.0/24&lt;br /&gt;
|-&lt;br /&gt;
| Local Network || 172.16.0.0/12&lt;br /&gt;
|-&lt;br /&gt;
| DNS Server 1 || 172.17.1.1&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
Leave everything not listed above at defaults and click &#039;&#039;&#039;Next&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
=== Firewall Rule Configuration ===&lt;br /&gt;
&lt;br /&gt;
The last step of the wizard prompts whether you want to add a rule to allow traffic from clients to the OpenVPN server, and allow traffic inside the VPN from clients when connected. Check both boxes and click &#039;&#039;&#039;Next&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
Click &#039;&#039;&#039;Finish&#039;&#039;&#039; on the last page.&lt;br /&gt;
&lt;br /&gt;
=== Configuration Complete ===&lt;br /&gt;
&lt;br /&gt;
The configuration is now complete. The last screen reminds you to install the OpenVPN Client Export package if you’d like to use it. It’s already pre-installed on this system to save time. Click &#039;&#039;&#039;Finish&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
Browse to &#039;&#039;&#039;Firewall &amp;gt; Rules&#039;&#039;&#039; to see the rules added by the wizard. On the &#039;&#039;&#039;WAN&#039;&#039;&#039; tab, you’ll see the rule allowing traffic to reach the OpenVPN server instance. Then click the &#039;&#039;&#039;OpenVPN&#039;&#039;&#039; tab to see the rule added to permit traffic from the connected clients.&lt;br /&gt;
&lt;br /&gt;
This may be overly-permissive for real world scenarios since it allows all traffic coming in via OpenVPN from any source to any destination. In a real world setup, you may need to restrict this rule.&lt;br /&gt;
&lt;br /&gt;
=== Special Configuration for Older Clients ===&lt;br /&gt;
&lt;br /&gt;
Although this is rarely necessary, some older OpenVPN clients, like the one installed on your remote-host, will require some extra configuration in the OpenVPN server. Click the &#039;&#039;&#039;Edit&#039;&#039;&#039; button under the Remote Access VPN, and scroll down to the bottom of the screen. Place this into the &#039;&#039;&#039;Custom Options&#039;&#039;&#039; box and Save:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
tls-version-min 1.0;&lt;br /&gt;
tls-cipher DEFAULT:@SECLEVEL=0&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== User Setup ===&lt;br /&gt;
&lt;br /&gt;
Users need a certificate from the RemoteVPNCA to connect. We’ll add a certificate to the &#039;&#039;&#039;vpntest&#039;&#039;&#039; account created during the IPsec lab. Browse to &#039;&#039;&#039;System &amp;gt; User Manager&#039;&#039;&#039;, and edit the vpntest user. Then click the &#039;&#039;&#039;Add&#039;&#039;&#039; button next to &#039;&#039;&#039;User Certificate&#039;&#039;&#039; to create the certificate.&lt;br /&gt;
&lt;br /&gt;
Choose method &#039;&#039;&#039;Create an internal certificate.&#039;&#039;&#039; Both &#039;&#039;&#039;Descriptive name&#039;&#039;&#039; and &#039;&#039;&#039;Common Name&#039;&#039;&#039; should be set to the username. The other fields can be left to defaults.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Field !! Value&lt;br /&gt;
|-&lt;br /&gt;
| User || vpntest&lt;br /&gt;
|-&lt;br /&gt;
| Certificate Method || Create an internal certificate&lt;br /&gt;
|-&lt;br /&gt;
| Descriptive Name || vpntest&lt;br /&gt;
|-&lt;br /&gt;
| Common Name || vpntest&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
Click &#039;&#039;&#039;Save&#039;&#039;&#039;. Back at the user edit screen, you’ll see the user’s certificate. Click &#039;&#039;&#039;Save&#039;&#039;&#039; to save the user changes.&lt;br /&gt;
&lt;br /&gt;
=== Client Configuration ===&lt;br /&gt;
&lt;br /&gt;
The OpenVPN Client Export utility eases the process of client configuration. It’s a package that comes pre-installed on the lab VMs, but will need to be installed under &#039;&#039;&#039;System &amp;gt; Packages&#039;&#039;&#039; on your other systems.&lt;br /&gt;
&lt;br /&gt;
Browse to &#039;&#039;&#039;VPN &amp;gt; OpenVPN&#039;&#039;&#039;, and click the &#039;&#039;&#039;Client Export&#039;&#039;&#039; tab.&lt;br /&gt;
&lt;br /&gt;
For our lab purposes, all other settings can be left at their defaults. Scroll down to the bottom to find the vpntest user’s client export options.&lt;br /&gt;
&lt;br /&gt;
For Windows systems, the Windows installer is what you’ll want. Choose x86 for 32 bit versions of Windows and x64 for 64 bit versions. The Viscosity bundle is for Windows or Mac OS X clients running the Viscosity client. The inline configuration options are most commonly used for iOS and Android clients.&lt;br /&gt;
&lt;br /&gt;
The &#039;&#039;&#039;Standard Configuration&#039;&#039;&#039; Archive option downloads a zip containing the user’s certificate, TLS key for the server, and OpenVPN config file.&lt;br /&gt;
&lt;br /&gt;
Here you will see the remote access server just created in the wizard. Because the RemoteHost’s VPN client is older, we need to scroll down the page and make sure to put a check mark on &#039;&#039;&#039;Legacy Client&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
=== Testing ===&lt;br /&gt;
&lt;br /&gt;
In this lab environment, the only machine that’s available in the circumstance of a typical client out on the Internet is the remote-host VM. First, add it to the &#039;&#039;&#039;RemoteAdmin&#039;&#039;&#039; alias on fw1-HQ so you can log into fw1-HQ from that host to ease getting the OpenVPN configuration onto the client. Browse to &#039;&#039;&#039;Firewall &amp;gt; Aliases&#039;&#039;&#039;, and edit the RemoteAdmin alias. Add &#039;&#039;&#039;100.64.0.50/32&#039;&#039;&#039; to that alias, save, then apply changes.&lt;br /&gt;
&lt;br /&gt;
Now connect with VNC to &#039;&#039;&#039;100.64.0.50&#039;&#039;&#039; (remote-host) to begin the client-side setup. Bring up its web browser and browse to &#039;&#039;&#039;https://192.0.2.2&#039;&#039;&#039;. Log in and browse to &#039;&#039;&#039;VPN &amp;gt; OpenVPN &amp;gt; Client Export&#039;&#039;&#039; tab. Export the &#039;&#039;&#039;Configuration Archive&#039;&#039;&#039; option for the vpntest user.&lt;br /&gt;
&lt;br /&gt;
Make a folder called OpenVPN in your Documents folder, and save the zip file there. Right click the zip file and choose &#039;&#039;&#039;Extract Here&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
Click the Network Manager icon → VPN Connections → Configure VPN.&lt;br /&gt;
&lt;br /&gt;
Click &#039;&#039;&#039;Add&#039;&#039;&#039; and scroll down to &#039;&#039;&#039;Import a Saved Configuration&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
Navigate to the folder where the OpenVPN configuration archive was extracted. Click on the &#039;&#039;&#039;.ovpn&#039;&#039;&#039; file and choose &#039;&#039;&#039;Open&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
Fill in the username and password portions of the next screen, and click &#039;&#039;&#039;Save&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
You may get prompted to choose a password for a new keyring. If so, just enter “password” in both blanks and click &#039;&#039;&#039;Continue&#039;&#039;&#039; and then &#039;&#039;&#039;Close&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
Now connect to the OpenVPN server by clicking on the Network Manager → VPN Connections and choosing your VPN configuration.&lt;br /&gt;
&lt;br /&gt;
Enter your password and click &#039;&#039;&#039;Ok&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
Now you should verify you can reach things on the HQ LAN and DMZ networks. Try HQ-client at &#039;&#039;&#039;172.17.1.100&#039;&#039;&#039;, server1 at &#039;&#039;&#039;172.17.2.10&#039;&#039;&#039; and server2 at &#039;&#039;&#039;172.17.2.20&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
Once you have verified that the OpenVPN connection is functioning as expected, please disconnect the OpenVPN session on the remote host.&lt;br /&gt;
&lt;br /&gt;
== Conclusion ==&lt;br /&gt;
&lt;br /&gt;
This concludes Lab 6.&lt;br /&gt;
&lt;br /&gt;
== Source Attribution ==&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Source: Netgate pfSense Training Material — FUND001-LIVE-Lab6-OpenVPN.pdf © 2021 Rubicon Communications, LLC (Netgate)&#039;&#039;&lt;/div&gt;</summary>
		<author><name>Justinaquino</name></author>
	</entry>
	<entry>
		<id>https://mediawiki.comfac.net/index.php?title=Training:_OpenVPN&amp;diff=239</id>
		<title>Training: OpenVPN</title>
		<link rel="alternate" type="text/html" href="https://mediawiki.comfac.net/index.php?title=Training:_OpenVPN&amp;diff=239"/>
		<updated>2026-04-23T07:08:32Z</updated>

		<summary type="html">&lt;p&gt;Justinaquino: Automated upload of Netgate pfSense training content&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__NOTOC__&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;background:#e7f3ff; border-left:6px solid #2196F3; padding:10px; margin-bottom:15px;&amp;quot;&amp;gt;&lt;br /&gt;
&#039;&#039;&#039;Training Module: OpenVPN (Section 6)&#039;&#039;&#039;&amp;lt;br/&amp;gt;&lt;br /&gt;
This page covers the fundamentals of OpenVPN in pfSense — intro, site-to-site, remote access, and the Client Export Utility.&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Introduction ==&lt;br /&gt;
&lt;br /&gt;
OpenVPN is an SSL/TLS open source VPN solution.&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;Not&#039;&#039;&#039; a browser-based SSL VPN&lt;br /&gt;
* Supports site-to-site and remote access&lt;br /&gt;
* Uses client and server roles&lt;br /&gt;
* Runs over TCP or UDP (UDP is preferable)&lt;br /&gt;
* Built on a client/server relationship&lt;br /&gt;
&lt;br /&gt;
== Remote Access ==&lt;br /&gt;
&lt;br /&gt;
The OpenVPN Wizard in pfSense takes all the guess-work out of configuration.&lt;br /&gt;
&lt;br /&gt;
* Install the &#039;&#039;&#039;Client Export Utility&#039;&#039;&#039;&lt;br /&gt;
* Users will need a &#039;&#039;&#039;user certificate&#039;&#039;&#039;&lt;br /&gt;
* Simple status screen&lt;br /&gt;
* Log files for troubleshooting&lt;br /&gt;
&lt;br /&gt;
== Site-to-Site ==&lt;br /&gt;
&lt;br /&gt;
=== Server-Side Requirements ===&lt;br /&gt;
&lt;br /&gt;
* Must have a publicly-reachable TCP or UDP port&lt;br /&gt;
* Static IP is preferred (dynamic DNS is possible)&lt;br /&gt;
&lt;br /&gt;
=== Client-Side Requirements ===&lt;br /&gt;
&lt;br /&gt;
* Only needs outbound Internet access&lt;br /&gt;
* Works behind NAT or firewall with no issue&lt;br /&gt;
* Setup is initiated by Client → Server&lt;br /&gt;
* Remarkably simple configuration&lt;br /&gt;
&lt;br /&gt;
=== Important Changes ===&lt;br /&gt;
&lt;br /&gt;
* Peer-to-Peer (Shared Key) mode is &#039;&#039;&#039;deprecated&#039;&#039;&#039;&lt;br /&gt;
* Peer-to-Peer (SSL/TLS) is the only supported mode moving forward&lt;br /&gt;
* This opens the door to new capabilities like &#039;&#039;&#039;DCO&#039;&#039;&#039; (Data Channel Offload)&lt;br /&gt;
&lt;br /&gt;
=== Configuration Checklist ===&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! colspan=&amp;quot;2&amp;quot; | Server Information Needed&lt;br /&gt;
|-&lt;br /&gt;
| CA and Certificate Infrastructure || Required for trust&lt;br /&gt;
|-&lt;br /&gt;
| Server and Client Certificates || Authenticate both ends&lt;br /&gt;
|-&lt;br /&gt;
| Server Mode || Peer to Peer (SSL/TLS)&lt;br /&gt;
|-&lt;br /&gt;
| TLS Key || Automatically created&lt;br /&gt;
|-&lt;br /&gt;
| Tunnel Network || Subnet for the VPN tunnel&lt;br /&gt;
|-&lt;br /&gt;
| Local Network || Networks on the server side&lt;br /&gt;
|-&lt;br /&gt;
| Remote Network || Networks on the client side&lt;br /&gt;
|-&lt;br /&gt;
| Client-Specific Overrides || Tie client subnets to certificates&lt;br /&gt;
|-&lt;br /&gt;
| Firewall Rules || Don’t forget to allow traffic!&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! colspan=&amp;quot;2&amp;quot; | Client Information Needed&lt;br /&gt;
|-&lt;br /&gt;
| CA and Certificate/Keys from server || Import the server&#039;s CA&lt;br /&gt;
|-&lt;br /&gt;
| Server Mode || Peer to Peer (SSL/TLS)&lt;br /&gt;
|-&lt;br /&gt;
| TLS Key || Copy from the server side&lt;br /&gt;
|-&lt;br /&gt;
| Server IP Address || Public address of the server&lt;br /&gt;
|-&lt;br /&gt;
| Peer CA || Same CA as server&lt;br /&gt;
|-&lt;br /&gt;
| Client Certificate/Key || Generated for this client&lt;br /&gt;
|-&lt;br /&gt;
| Firewall Rules || Don’t forget to allow traffic!&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Section Summary ==&lt;br /&gt;
&lt;br /&gt;
* Pay attention to crypto settings — they &#039;&#039;&#039;must agree&#039;&#039;&#039; on both sides&lt;br /&gt;
* Very simple setup&lt;br /&gt;
* Very tenacious — comes up and recovers quickly&lt;br /&gt;
* Routed VPN instead of policy-based&lt;br /&gt;
* Can co-exist with IPsec&lt;br /&gt;
* &#039;&#039;&#039;Cannot&#039;&#039;&#039; route the same networks! (Policy &amp;gt; Routed)&lt;br /&gt;
* Still need firewall rules to allow traffic to pass&lt;br /&gt;
&lt;br /&gt;
== Next Module ==&lt;br /&gt;
&lt;br /&gt;
→ Continue to &#039;&#039;&#039;[[Training_Lab_6:_OpenVPN|Lab 6: OpenVPN]]&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== Source Attribution ==&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Source: Netgate pfSense Training Material — FUND001-LIVE-SLIDE-SEG6-OVPN.pdf © 2017 Rubicon Communications dba Netgate&#039;&#039;&lt;/div&gt;</summary>
		<author><name>Justinaquino</name></author>
	</entry>
	<entry>
		<id>https://mediawiki.comfac.net/index.php?title=Training_Lab_5:_IPsec_VPN&amp;diff=238</id>
		<title>Training Lab 5: IPsec VPN</title>
		<link rel="alternate" type="text/html" href="https://mediawiki.comfac.net/index.php?title=Training_Lab_5:_IPsec_VPN&amp;diff=238"/>
		<updated>2026-04-23T07:07:12Z</updated>

		<summary type="html">&lt;p&gt;Justinaquino: Imported from Netgate pfSense training PDF via bot&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__NOTOC__&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;background-color: #fff3cd; border-left: 6px solid #ffc107; padding: 10px; margin-bottom: 15px;&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;strong&amp;gt;Netgate pfSense Plus Fundamentals — Lab 5: IPsec VPN&amp;lt;/strong&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
Hands-on lab covering site-to-site IPsec with pre-shared key and mobile IPsec remote access configuration.&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Lab 5: IPsec =&lt;br /&gt;
&lt;br /&gt;
In this lab, we connect the &#039;&#039;&#039;HQ&#039;&#039;&#039; and &#039;&#039;&#039;branch&#039;&#039;&#039; networks with a site-to-site IPsec VPN, then configure mobile IPsec to offer a remote access option for mobile clients.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Lab topology references:&#039;&#039;&#039;&lt;br /&gt;
* HQ WAN IP: &#039;&#039;&#039;192.0.2.2&#039;&#039;&#039;&lt;br /&gt;
* Branch WAN IP: &#039;&#039;&#039;203.0.113.10&#039;&#039;&#039;&lt;br /&gt;
* HQ network: 172.17.0.0/16&lt;br /&gt;
* Branch network: 172.18.0.0/16&lt;br /&gt;
&lt;br /&gt;
= Part 1: IPsec Pre-Shared Key Site-to-Site VPN =&lt;br /&gt;
&lt;br /&gt;
== Enable fw1-HQ IPsec ==&lt;br /&gt;
&lt;br /&gt;
On &#039;&#039;&#039;fw1-HQ&#039;&#039;&#039;, browse to &#039;&#039;&#039;VPN &amp;gt; IPsec&#039;&#039;&#039;. Click &#039;&#039;&#039;+Add P1&#039;&#039;&#039; to add a new Phase 1 configuration.&lt;br /&gt;
&lt;br /&gt;
=== HQ Phase 1 Configuration ===&lt;br /&gt;
&lt;br /&gt;
At the resulting Edit Phase 1 screen:&lt;br /&gt;
* &#039;&#039;&#039;Remote Gateway:&#039;&#039;&#039; Branch WAN IP (203.0.113.10)&lt;br /&gt;
* &#039;&#039;&#039;Interface:&#039;&#039;&#039; WAN&lt;br /&gt;
* &#039;&#039;&#039;Description:&#039;&#039;&#039; (your choice)&lt;br /&gt;
&lt;br /&gt;
=== Phase 1 Proposal Configuration ===&lt;br /&gt;
&lt;br /&gt;
Scroll down to the Phase 1 proposal configuration.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Generating Pre-Shared Key:&#039;&#039;&#039;&lt;br /&gt;
* Click the yellow button to generate your pre-shared key automatically&lt;br /&gt;
* Make note of it — it will be needed to configure the other end of the VPN&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Advanced Options:&#039;&#039;&#039;&lt;br /&gt;
* Leave &#039;&#039;&#039;NAT Traversal&#039;&#039;&#039; to &#039;&#039;&#039;Auto&#039;&#039;&#039;&lt;br /&gt;
* The underlying strongSwan service will determine if NAT-T is required and automatically enable it if so&lt;br /&gt;
&lt;br /&gt;
Leave the other settings at their defaults, then click &#039;&#039;&#039;Save&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
== Adding HQ Phase 2 ==&lt;br /&gt;
&lt;br /&gt;
Back at the IPsec Tunnels tab, click the &#039;&#039;&#039;+&#039;&#039;&#039; under the newly-created Phase 1 to expose the Phase 2 configuration, then click &#039;&#039;&#039;+Add P2&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
=== Configuring HQ Phase 2 ===&lt;br /&gt;
&lt;br /&gt;
For local and remote networks, use the /16 network summarizing all available IP subnets for each location:&lt;br /&gt;
* &#039;&#039;&#039;Local Network:&#039;&#039;&#039; Type: Network, &#039;&#039;&#039;172.17.0.0/16&#039;&#039;&#039;&lt;br /&gt;
* &#039;&#039;&#039;Remote Network:&#039;&#039;&#039; Type: Network, &#039;&#039;&#039;172.18.0.0/16&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
=== Phase 2 Proposal Configuration ===&lt;br /&gt;
&lt;br /&gt;
Choose specific parameters for each area rather than having multiple options enabled. This is always best for site-to-site VPNs.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Setting !! Recommendation&lt;br /&gt;
|-&lt;br /&gt;
| Encryption || AES-256 (single option)&lt;br /&gt;
|-&lt;br /&gt;
| Hash || SHA256 (single option)&lt;br /&gt;
|-&lt;br /&gt;
| PFS || On (match group)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
Having multiple options enabled could lead to a less secure, slower algorithm like 3DES being chosen over a faster, more secure option like AES-256.&lt;br /&gt;
&lt;br /&gt;
=== Automatically Ping Host ===&lt;br /&gt;
&lt;br /&gt;
Enter an IP address within the remote subnet to keep the VPN alive:&lt;br /&gt;
* Use &#039;&#039;&#039;fw1-branch LAN IP&#039;&#039;&#039; (e.g., 172.18.1.1)&lt;br /&gt;
* IPsec is &amp;quot;dial-on-demand&amp;quot; — it doesn&#039;t try to connect unless traffic is trying to traverse the VPN&lt;br /&gt;
* The IP doesn&#039;t have to reply; it&#039;s the initiation of the request that triggers the VPN to come up&lt;br /&gt;
&lt;br /&gt;
Then click &#039;&#039;&#039;Save&#039;&#039;&#039;, and at the main IPsec Tunnels screen click &#039;&#039;&#039;Apply Changes&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
== Configure HQ IPsec Firewall Rules ==&lt;br /&gt;
&lt;br /&gt;
Traffic coming in via IPsec is filtered by the firewall rules on the &#039;&#039;&#039;IPsec tab&#039;&#039;&#039;. By default, this contains no rules, so all VPN traffic will be blocked.&lt;br /&gt;
&lt;br /&gt;
Browse to &#039;&#039;&#039;Firewall &amp;gt; Rules&#039;&#039;&#039;, IPsec tab. Click &#039;&#039;&#039;Add&#039;&#039;&#039; and configure:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Field !! Value&lt;br /&gt;
|-&lt;br /&gt;
| Action || Pass&lt;br /&gt;
|-&lt;br /&gt;
| Interface || IPsec&lt;br /&gt;
|-&lt;br /&gt;
| Protocol || any&lt;br /&gt;
|-&lt;br /&gt;
| Source || 172.18.0.0/16&lt;br /&gt;
|-&lt;br /&gt;
| Destination || any&lt;br /&gt;
|-&lt;br /&gt;
| Description || allow branch network in via IPsec&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
Click &#039;&#039;&#039;Save&#039;&#039;&#039;, and &#039;&#039;&#039;Apply Changes&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Notes:&#039;&#039;&#039;&lt;br /&gt;
* The outer portion of the VPN requires UDP port 500 and ESP protocol on WAN — these rules are handled automatically&lt;br /&gt;
* Traffic is allowed out from HQ to branch by the default LAN rule&lt;br /&gt;
* The HQ DMZ subnet will not be able to initiate connections to the remote branch network because of the DMZ rule rejecting private network destinations&lt;br /&gt;
&lt;br /&gt;
== Configure fw1-branch IPsec ==&lt;br /&gt;
&lt;br /&gt;
Browse to &#039;&#039;&#039;https://172.18.1.1&#039;&#039;&#039; to reach fw1-branch.&lt;br /&gt;
&lt;br /&gt;
=== Add Phase 1 Entry ===&lt;br /&gt;
&lt;br /&gt;
Add a new Phase 1 entry for the HQ VPN:&lt;br /&gt;
* &#039;&#039;&#039;Remote Gateway:&#039;&#039;&#039; fw1-HQ&#039;s WAN IP — &#039;&#039;&#039;192.0.2.2&#039;&#039;&#039;&lt;br /&gt;
* Match all other parameters exactly with fw1-HQ&lt;br /&gt;
&lt;br /&gt;
=== Phase 1 Proposal and Advanced ===&lt;br /&gt;
&lt;br /&gt;
All Phase 1 proposal settings must match exactly to fw1-HQ. After matching up everything, click &#039;&#039;&#039;Save&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
=== Branch Phase 2 Configuration ===&lt;br /&gt;
&lt;br /&gt;
Add a new Phase 2 entry under the Phase 1 just added. Everything is identical to HQ&#039;s Phase 2, except flip local and remote networks:&lt;br /&gt;
* &#039;&#039;&#039;Local Network:&#039;&#039;&#039; 172.18.0.0/16&lt;br /&gt;
* &#039;&#039;&#039;Remote Network:&#039;&#039;&#039; 172.17.0.0/16&lt;br /&gt;
&lt;br /&gt;
Leave &#039;&#039;&#039;Automatically ping host&#039;&#039;&#039; blank on this side (the other end will keep the tunnel active).&lt;br /&gt;
&lt;br /&gt;
Then click &#039;&#039;&#039;Save&#039;&#039;&#039;, and &#039;&#039;&#039;Apply Changes&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
=== Add IPsec Firewall Rule ===&lt;br /&gt;
&lt;br /&gt;
Browse to &#039;&#039;&#039;Firewall &amp;gt; Rules&#039;&#039;&#039;, IPsec tab, and add an allow-all rule:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Field !! Value&lt;br /&gt;
|-&lt;br /&gt;
| Action || Pass&lt;br /&gt;
|-&lt;br /&gt;
| Interface || IPsec&lt;br /&gt;
|-&lt;br /&gt;
| Protocol || any&lt;br /&gt;
|-&lt;br /&gt;
| Source || Network, 172.17.0.0/16&lt;br /&gt;
|-&lt;br /&gt;
| Destination || any&lt;br /&gt;
|-&lt;br /&gt;
| Description || allow HQ in via VPN&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
Save and Apply Changes.&lt;br /&gt;
&lt;br /&gt;
== Testing the VPN ==&lt;br /&gt;
&lt;br /&gt;
Browse to &#039;&#039;&#039;Status &amp;gt; IPsec&#039;&#039;&#039; on the branch firewall. If the status shows &amp;quot;Disconnected&amp;quot;, click the &#039;&#039;&#039;Connect VPN&#039;&#039;&#039; button.&lt;br /&gt;
&lt;br /&gt;
Once something attempts to bring up the VPN, it should change status to &#039;&#039;&#039;ESTABLISHED&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
=== Troubleshooting ===&lt;br /&gt;
&lt;br /&gt;
If the VPN does not come up:&lt;br /&gt;
* Closely review all settings in Phase 1 and Phase 2 on both sides&lt;br /&gt;
* Check for typos in IP addresses&lt;br /&gt;
* Verify the pre-shared key was pasted correctly&lt;br /&gt;
* Ensure no inadvertently mismatched settings&lt;br /&gt;
&lt;br /&gt;
=== Passing Traffic Across VPN ===&lt;br /&gt;
&lt;br /&gt;
On &#039;&#039;&#039;HQ-client&#039;&#039;&#039;, test connectivity:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
training@hq-client:~$ ping -c 3 172.18.1.1&lt;br /&gt;
training@hq-client:~$ ping -c 3 172.18.1.100&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
On &#039;&#039;&#039;branch-client&#039;&#039;&#039;, ping back:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
training@branch-client:~$ ping -c 3 172.17.1.1&lt;br /&gt;
training@branch-client:~$ ping -c 3 172.17.1.100&lt;br /&gt;
training@branch-client:~$ ping -c 3 172.17.2.10&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
You should also be able to browse to web servers in the HQ DMZ network from branch-client.&lt;br /&gt;
&lt;br /&gt;
= Part 2: IPsec Remote Access VPN =&lt;br /&gt;
&lt;br /&gt;
Next, configure IPsec for mobile clients. This works with any standard IPsec clients, specifically focused towards the Cisco IPsec clients built into Mac OS X and Apple iOS. The Shrew Soft client is used in this lab.&lt;br /&gt;
&lt;br /&gt;
== User and Group Setup ==&lt;br /&gt;
&lt;br /&gt;
IPsec remote-access users require the &#039;&#039;&#039;&amp;quot;IPsec xauth Dialin&amp;quot;&#039;&#039;&#039; privilege.&lt;br /&gt;
&lt;br /&gt;
=== Add IPsec Mobile Group ===&lt;br /&gt;
&lt;br /&gt;
On &#039;&#039;&#039;fw1-HQ&#039;&#039;&#039;, browse to &#039;&#039;&#039;System &amp;gt; User Manager&#039;&#039;&#039;, Groups tab. Click &#039;&#039;&#039;+Add&#039;&#039;&#039;:&lt;br /&gt;
* Give the group a name (e.g., &amp;quot;Mobile_IPsec&amp;quot;) and description&lt;br /&gt;
* Save&lt;br /&gt;
* Edit the group and under &#039;&#039;&#039;Assigned Privileges&#039;&#039;&#039;, click &#039;&#039;&#039;Add&#039;&#039;&#039;&lt;br /&gt;
* Choose only the &#039;&#039;&#039;&amp;quot;VPN - IPsec xauth Dialin&amp;quot;&#039;&#039;&#039; privilege&lt;br /&gt;
* Save again&lt;br /&gt;
&lt;br /&gt;
=== Creating User for VPN ===&lt;br /&gt;
&lt;br /&gt;
Go to the Users tab, click &#039;&#039;&#039;+Add&#039;&#039;&#039;:&lt;br /&gt;
* &#039;&#039;&#039;Username:&#039;&#039;&#039; vpntest&lt;br /&gt;
* &#039;&#039;&#039;Password:&#039;&#039;&#039; password&lt;br /&gt;
* &#039;&#039;&#039;Group:&#039;&#039;&#039; Mobile_IPsec&lt;br /&gt;
* Save&lt;br /&gt;
&lt;br /&gt;
== Server Configuration ==&lt;br /&gt;
&lt;br /&gt;
On &#039;&#039;&#039;fw1-HQ&#039;&#039;&#039;, browse to &#039;&#039;&#039;VPN &amp;gt; IPsec&#039;&#039;&#039;, click the &#039;&#039;&#039;Mobile clients&#039;&#039;&#039; tab:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Setting !! Value&lt;br /&gt;
|-&lt;br /&gt;
| Enable IPsec Mobile Client Support || Checked&lt;br /&gt;
|-&lt;br /&gt;
| User Authentication || Local Database&lt;br /&gt;
|-&lt;br /&gt;
| Group Authentication || Checked&lt;br /&gt;
|-&lt;br /&gt;
| Authentication Groups || Rights for Mobile IPsec (Mobile_IPsec)&lt;br /&gt;
|-&lt;br /&gt;
| Virtual Address Pool || 172.17.5.0/24&lt;br /&gt;
|-&lt;br /&gt;
| Network List || Checked — &amp;quot;Provide a list of accessible networks to clients&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| DNS Default Domain || example.com&lt;br /&gt;
|-&lt;br /&gt;
| DNS Servers || 172.17.1.1&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
Leave all other fields at defaults and click &#039;&#039;&#039;Save&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
== Phase 1 Creation ==&lt;br /&gt;
&lt;br /&gt;
After saving, you will see a prompt to create a Phase 1 definition for mobile clients. Click &#039;&#039;&#039;Create Phase 1&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Parameter !! Value&lt;br /&gt;
|-&lt;br /&gt;
| Key Exchange Version || IKEv1&lt;br /&gt;
|-&lt;br /&gt;
| Description || Mobile clients&lt;br /&gt;
|-&lt;br /&gt;
| Authentication Method || Mutual PSK + Xauth&lt;br /&gt;
|-&lt;br /&gt;
| My Identifier || My IP address&lt;br /&gt;
|-&lt;br /&gt;
| Peer Identifier || User distinguished name, vpn@example.com&lt;br /&gt;
|-&lt;br /&gt;
| Pre-Shared Key || Generate new (make note)&lt;br /&gt;
|-&lt;br /&gt;
| Encryption Algorithm || AES 128 bit&lt;br /&gt;
|-&lt;br /&gt;
| Hash Algorithm || SHA1&lt;br /&gt;
|-&lt;br /&gt;
| DH Group || 2&lt;br /&gt;
|-&lt;br /&gt;
| Lifetime || 86400&lt;br /&gt;
|-&lt;br /&gt;
| NAT Traversal || Force&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
Leave all else at defaults, and click &#039;&#039;&#039;Save&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
== Configure Phase 2 ==&lt;br /&gt;
&lt;br /&gt;
Back at the IPsec Tunnels screen, expand the mobile Phase 1 and click &#039;&#039;&#039;+Add P2&#039;&#039;&#039;:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Parameter !! Value&lt;br /&gt;
|-&lt;br /&gt;
| Mode || Tunnel IPv4&lt;br /&gt;
|-&lt;br /&gt;
| Local Network || Type: Network, 0.0.0.0/0&lt;br /&gt;
|-&lt;br /&gt;
| Encryption || AES 128&lt;br /&gt;
|-&lt;br /&gt;
| Hash || SHA1&lt;br /&gt;
|-&lt;br /&gt;
| PFS || off&lt;br /&gt;
|-&lt;br /&gt;
| Lifetime || 28800&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Note:&#039;&#039;&#039; The Phase 2 &amp;quot;Local Network&amp;quot; determines what networks are sent to the client. &#039;&#039;&#039;0.0.0.0/0&#039;&#039;&#039; sends all traffic across the VPN. To send only internal traffic, use &#039;&#039;&#039;172.17.0.0/16&#039;&#039;&#039; or &#039;&#039;&#039;172.16.0.0/12&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
Then click &#039;&#039;&#039;Save&#039;&#039;&#039;, and &#039;&#039;&#039;Apply Changes&#039;&#039;&#039;. The server-side IPsec configuration is now complete.&lt;br /&gt;
&lt;br /&gt;
== Firewall Rule Configuration ==&lt;br /&gt;
&lt;br /&gt;
Browse to &#039;&#039;&#039;Firewall &amp;gt; Rules&#039;&#039;&#039;, IPsec tab. Add a new rule:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Field !! Value&lt;br /&gt;
|-&lt;br /&gt;
| Action || Pass&lt;br /&gt;
|-&lt;br /&gt;
| Interface || IPsec&lt;br /&gt;
|-&lt;br /&gt;
| Protocol || Any&lt;br /&gt;
|-&lt;br /&gt;
| Source || Network 172.17.5.0/24&lt;br /&gt;
|-&lt;br /&gt;
| Destination || any&lt;br /&gt;
|-&lt;br /&gt;
| Description || allow in mobile client IPsec&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
Then Save and Apply Changes.&lt;br /&gt;
&lt;br /&gt;
== Client Configuration ==&lt;br /&gt;
&lt;br /&gt;
On &#039;&#039;&#039;remote-host&#039;&#039;&#039;, launch &#039;&#039;&#039;Shrew Soft VPN Access Manager&#039;&#039;&#039;. Click &#039;&#039;&#039;Add&#039;&#039;&#039; to create a new configuration.&lt;br /&gt;
&lt;br /&gt;
=== General Tab ===&lt;br /&gt;
* Fill in the WAN IP of fw1-HQ: &#039;&#039;&#039;192.0.2.2&#039;&#039;&#039;&lt;br /&gt;
* Leave all else at defaults&lt;br /&gt;
&lt;br /&gt;
=== Authentication Tab ===&lt;br /&gt;
* &#039;&#039;&#039;Authentication Method:&#039;&#039;&#039; Mutual PSK + XAuth&lt;br /&gt;
* &#039;&#039;&#039;Local Identity:&#039;&#039;&#039; User Fully Qualified Domain Name — &#039;&#039;&#039;vpn@example.com&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
=== Remote Identity Tab ===&lt;br /&gt;
* Choose &#039;&#039;&#039;Identification type:&#039;&#039;&#039; IP address&lt;br /&gt;
&lt;br /&gt;
=== Credentials Tab ===&lt;br /&gt;
* Enter or paste the PSK generated during Phase 1 creation&lt;br /&gt;
&lt;br /&gt;
=== Phase 1 Tab ===&lt;br /&gt;
* Change &#039;&#039;&#039;DH Exchange&#039;&#039;&#039; to &#039;&#039;&#039;group 2&#039;&#039;&#039;&lt;br /&gt;
* Leave all else at defaults&lt;br /&gt;
&lt;br /&gt;
=== Phase 2 Tab ===&lt;br /&gt;
* Set &#039;&#039;&#039;Lifetime&#039;&#039;&#039; to &#039;&#039;&#039;28800&#039;&#039;&#039; seconds&lt;br /&gt;
* Leave everything else at defaults&lt;br /&gt;
&lt;br /&gt;
Then click &#039;&#039;&#039;Save&#039;&#039;&#039;. You can rename the connection (e.g., &amp;quot;HQ VPN&amp;quot;).&lt;br /&gt;
&lt;br /&gt;
== Testing ==&lt;br /&gt;
&lt;br /&gt;
Select the connection and click &#039;&#039;&#039;Connect&#039;&#039;&#039;. Fill in:&lt;br /&gt;
* &#039;&#039;&#039;Username:&#039;&#039;&#039; vpntest&lt;br /&gt;
* &#039;&#039;&#039;Password:&#039;&#039;&#039; password&lt;br /&gt;
&lt;br /&gt;
Then click &#039;&#039;&#039;Connect&#039;&#039;&#039;. If you see &amp;quot;tunnel enabled&amp;quot; as the last line in the status, it&#039;s connected successfully.&lt;br /&gt;
&lt;br /&gt;
Try to ping across to HQ-client (172.17.1.100) and server1 (172.17.2.10).&lt;br /&gt;
&lt;br /&gt;
This concludes the IPsec lab.&lt;br /&gt;
&lt;br /&gt;
= Next Module =&lt;br /&gt;
&lt;br /&gt;
* [[Training:_IPsec_VPN|Section 5: IPsec VPN Concepts]] (review)&lt;br /&gt;
&lt;br /&gt;
= Source Attribution =&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;Document:&#039;&#039;&#039; FUND001-LIVE-Lab5-IPsec.pdf&lt;br /&gt;
* &#039;&#039;&#039;Course:&#039;&#039;&#039; pfSense Plus Fundamentals and Practical Application&lt;br /&gt;
* &#039;&#039;&#039;Copyright:&#039;&#039;&#039; © 2021 Rubicon Communications, LLC (Netgate)&lt;br /&gt;
* &#039;&#039;&#039;Extracted:&#039;&#039;&#039; 2026-04-23 via pdftotext&lt;/div&gt;</summary>
		<author><name>Justinaquino</name></author>
	</entry>
	<entry>
		<id>https://mediawiki.comfac.net/index.php?title=Training:_IPsec_VPN&amp;diff=237</id>
		<title>Training: IPsec VPN</title>
		<link rel="alternate" type="text/html" href="https://mediawiki.comfac.net/index.php?title=Training:_IPsec_VPN&amp;diff=237"/>
		<updated>2026-04-23T07:07:11Z</updated>

		<summary type="html">&lt;p&gt;Justinaquino: Imported from Netgate pfSense training PDF via bot&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__NOTOC__&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;background-color: #e7f3fe; border-left: 6px solid #2196F3; padding: 10px; margin-bottom: 15px;&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;strong&amp;gt;Netgate pfSense Plus Fundamentals — Section 5: VPNs and IPsec&amp;lt;/strong&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
This page covers VPN concepts, IPsec remote access, site-to-site configurations, and IKE phase negotiations.&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= VPNs and IPsec =&lt;br /&gt;
&lt;br /&gt;
== VPNs — Remote Access ==&lt;br /&gt;
&lt;br /&gt;
Remote access VPNs provide connectivity for mobile or remote users, enabling secure tunneling over untrusted networks.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Use cases:&#039;&#039;&#039;&lt;br /&gt;
* Tunneling for access or performance reasons&lt;br /&gt;
* Additional wireless protection&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Available options:&#039;&#039;&#039;&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Option !! Best For&lt;br /&gt;
|-&lt;br /&gt;
| IPsec || Built-in clients (OS X, iOS, Android)&lt;br /&gt;
|-&lt;br /&gt;
| OpenVPN || Ease of client configuration&lt;br /&gt;
|-&lt;br /&gt;
| WireGuard || Good performance for simple setup&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
The best option is largely a matter of &#039;&#039;&#039;personal preference&#039;&#039;&#039; and the specific client ecosystem in use.&lt;br /&gt;
&lt;br /&gt;
== VPNs — Site to Site ==&lt;br /&gt;
&lt;br /&gt;
Site-to-site VPNs provide a permanent connection between networks, commonly used for:&lt;br /&gt;
* Multiple company offices or data centers&lt;br /&gt;
* Service providers&lt;br /&gt;
* Partners&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Available options:&#039;&#039;&#039;&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Option !! Best For&lt;br /&gt;
|-&lt;br /&gt;
| IPsec || Widely interoperable&lt;br /&gt;
|-&lt;br /&gt;
| OpenVPN || Client behind NAT&lt;br /&gt;
|-&lt;br /&gt;
| WireGuard || Client behind NAT, modern crypto&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
Again, the best option depends on personal preference and a weighing of strengths and weaknesses. If a client is behind NAT, OpenVPN or WireGuard may be preferable. For wide interoperability, IPsec is the standard.&lt;br /&gt;
&lt;br /&gt;
= About IPsec =&lt;br /&gt;
&lt;br /&gt;
IPsec is a widely interoperable VPN protocol that typically offers higher performance than most alternatives.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Key characteristics:&#039;&#039;&#039;&lt;br /&gt;
* Peer-to-peer relationship&lt;br /&gt;
* Typically &#039;&#039;&#039;policy-based&#039;&#039;&#039; (but can be &#039;&#039;&#039;VTI / route-based&#039;&#039;&#039;)&lt;br /&gt;
* &#039;&#039;&#039;Phase 1&#039;&#039;&#039; protects IKE messages between peers&lt;br /&gt;
* &#039;&#039;&#039;Phase 2&#039;&#039;&#039; protects IP traffic between endpoints&lt;br /&gt;
* Establishes a &#039;&#039;&#039;Security Association (SA)&#039;&#039;&#039; between networks&lt;br /&gt;
* The SA determines which traffic traverses the tunnel&lt;br /&gt;
&lt;br /&gt;
== IPsec Phase 1 ==&lt;br /&gt;
&lt;br /&gt;
Phase 1 protects IKE messages between peers.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Key points:&#039;&#039;&#039;&lt;br /&gt;
* Peers are typically a single IP address&lt;br /&gt;
* Encryption and authentication protocols are required&lt;br /&gt;
* Common example: &#039;&#039;&#039;AES-256 / SHA256&#039;&#039;&#039;&lt;br /&gt;
* Provides a secure path for Phase 2 negotiation&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Parameter !! Typical Value&lt;br /&gt;
|-&lt;br /&gt;
| Encryption || AES-256&lt;br /&gt;
|-&lt;br /&gt;
| Authentication || SHA256&lt;br /&gt;
|-&lt;br /&gt;
| DH Group || 14 (2048-bit) or higher&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== IPsec Phase 2 ==&lt;br /&gt;
&lt;br /&gt;
Phase 2 protects IP traffic between endpoints.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Key points:&#039;&#039;&#039;&lt;br /&gt;
* Security Association is formed between networks&lt;br /&gt;
* Encryption is optional for Phase 2 traffic — but strongly recommended&lt;br /&gt;
* Authentication method is still required&lt;br /&gt;
&lt;br /&gt;
= IPsec — How It Looks =&lt;br /&gt;
&lt;br /&gt;
Conceptually, IPsec creates an encrypted tunnel between two peer gateways:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
[Network A] --- [Gateway A] ====== encrypted tunnel ====== [Gateway B] --- [Network B]&lt;br /&gt;
                    ↑                                    ↑&lt;br /&gt;
              Phase 1 (IKE)                        Phase 1 (IKE)&lt;br /&gt;
              Phase 2 (ESP/AH)                     Phase 2 (ESP/AH)&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Section 5 Summary =&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Point !! Detail&lt;br /&gt;
|-&lt;br /&gt;
| Style || Peer-to-peer VPN&lt;br /&gt;
|-&lt;br /&gt;
| Routing || Can be policy-based or route-based (VTI)&lt;br /&gt;
|-&lt;br /&gt;
| Routing table || Not considered if policy-based&lt;br /&gt;
|-&lt;br /&gt;
| Agreement || As long as both sides agree, the tunnel will come up&lt;br /&gt;
|-&lt;br /&gt;
| Firewall || Still need a firewall rule to allow tunnel traffic&lt;br /&gt;
|-&lt;br /&gt;
| Performance || Consider taking advantage of AES-NI for performance&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Next Module =&lt;br /&gt;
&lt;br /&gt;
* [[Training_Lab_5:_IPsec_VPN|Lab 5: IPsec VPN Hands-On]]&lt;br /&gt;
&lt;br /&gt;
= Source Attribution =&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;Document:&#039;&#039;&#039; FUND001-LIVE-SLIDE-SEG5-IPSEC.pdf&lt;br /&gt;
* &#039;&#039;&#039;Course:&#039;&#039;&#039; pfSense Plus Fundamentals and Practical Application&lt;br /&gt;
* &#039;&#039;&#039;Copyright:&#039;&#039;&#039; © 2017 Rubicon Communications, LLC dba Netgate&lt;br /&gt;
* &#039;&#039;&#039;Extracted:&#039;&#039;&#039; 2026-04-23 via pdftotext&lt;/div&gt;</summary>
		<author><name>Justinaquino</name></author>
	</entry>
	<entry>
		<id>https://mediawiki.comfac.net/index.php?title=Training_Lab_10:_High_Availability&amp;diff=236</id>
		<title>Training Lab 10: High Availability</title>
		<link rel="alternate" type="text/html" href="https://mediawiki.comfac.net/index.php?title=Training_Lab_10:_High_Availability&amp;diff=236"/>
		<updated>2026-04-23T07:07:10Z</updated>

		<summary type="html">&lt;p&gt;Justinaquino: Created from Netgate pfSense training PDF&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__NOTOC__&lt;br /&gt;
&amp;lt;div style=&amp;quot;background:#003366; color:#ffffff; padding:10px; border-radius:5px; margin-bottom:15px;&amp;quot;&amp;gt;&lt;br /&gt;
&#039;&#039;&#039;Netgate pfSense Plus Fundamentals — Lab 10: High Availability&#039;&#039;&#039;&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Overview ==&lt;br /&gt;
&lt;br /&gt;
In this lab, we add high availability at HQ by configuring a secondary firewall (&#039;&#039;&#039;fw2-HQ&#039;&#039;&#039;) to operate as the backup in an active/passive HA pair.&lt;br /&gt;
&lt;br /&gt;
== Configuring fw2-HQ ==&lt;br /&gt;
&lt;br /&gt;
From your machine or HQ-client, log into fw2-HQ at &#039;&#039;&#039;https://172.17.1.3&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
=== Interface Assignment ===&lt;br /&gt;
&lt;br /&gt;
On fw2-HQ, browse to &#039;&#039;&#039;Interfaces &amp;gt; Assign&#039;&#039;&#039; and verify that your 5 interfaces are assigned correctly.&lt;br /&gt;
&lt;br /&gt;
=== Interface Configuration ===&lt;br /&gt;
&lt;br /&gt;
==== WAN ====&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Setting !! Value&lt;br /&gt;
|-&lt;br /&gt;
| Description || WAN&lt;br /&gt;
|-&lt;br /&gt;
| IPv4 Configuration Type || Static IPv4&lt;br /&gt;
|-&lt;br /&gt;
| IPv4 Address || 192.0.2.3/24&lt;br /&gt;
|-&lt;br /&gt;
| Gateway || GW_WAN — 192.0.2.1 (default gateway)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
Then Save and Apply Changes.&lt;br /&gt;
&lt;br /&gt;
==== DMZ ====&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Setting !! Value&lt;br /&gt;
|-&lt;br /&gt;
| Description || DMZ&lt;br /&gt;
|-&lt;br /&gt;
| IPv4 Configuration Type || Static IPv4&lt;br /&gt;
|-&lt;br /&gt;
| IPv4 Address || 172.17.2.3/24&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
Save and Apply Changes.&lt;br /&gt;
&lt;br /&gt;
==== WAN2 ====&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Setting !! Value&lt;br /&gt;
|-&lt;br /&gt;
| Description || WAN2&lt;br /&gt;
|-&lt;br /&gt;
| IPv4 Configuration Type || Static IPv4&lt;br /&gt;
|-&lt;br /&gt;
| IPv4 Address || 198.51.100.3/24&lt;br /&gt;
|-&lt;br /&gt;
| Gateway || GW_WAN2 — 198.51.100.1 (not default gateway)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
Save and Apply Changes.&lt;br /&gt;
&lt;br /&gt;
==== SYNC ====&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Setting !! Value&lt;br /&gt;
|-&lt;br /&gt;
| Description || SYNC&lt;br /&gt;
|-&lt;br /&gt;
| IPv4 Configuration Type || Static IPv4&lt;br /&gt;
|-&lt;br /&gt;
| IPv4 Address || 172.17.3.3/24&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
Save and Apply Changes.&lt;br /&gt;
&lt;br /&gt;
=== HA Sync Configuration (fw2-HQ) ===&lt;br /&gt;
&lt;br /&gt;
Browse to &#039;&#039;&#039;System &amp;gt; High Avail Sync&#039;&#039;&#039;. Only the top portion is configured on the secondary, enabling it to send and receive state synchronization traffic.&lt;br /&gt;
&lt;br /&gt;
* Check &#039;&#039;&#039;Synchronize States&#039;&#039;&#039;&lt;br /&gt;
* Choose &#039;&#039;&#039;Synchronize Interface&#039;&#039;&#039; = SYNC&lt;br /&gt;
* &#039;&#039;&#039;pfsync Synchronize Peer IP&#039;&#039;&#039;: 172.17.3.2&lt;br /&gt;
&lt;br /&gt;
Then click Save at the very bottom of the page.&lt;br /&gt;
&lt;br /&gt;
=== Increase FW2 GUI Processes ===&lt;br /&gt;
&lt;br /&gt;
Navigate to &#039;&#039;&#039;System &amp;gt; Advanced&#039;&#039;&#039; and change &#039;&#039;&#039;Max Processes&#039;&#039;&#039; from the default 2 to &#039;&#039;&#039;5&#039;&#039;&#039;, to account for the extra work of sync and configuration.&lt;br /&gt;
&lt;br /&gt;
=== Firewall Rule Configuration (fw2-HQ) ===&lt;br /&gt;
&lt;br /&gt;
Browse to &#039;&#039;&#039;Firewall &amp;gt; Rules&#039;&#039;&#039;, SYNC tab, and click Add to allow the initial config sync:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Setting !! Value&lt;br /&gt;
|-&lt;br /&gt;
| Action || Pass&lt;br /&gt;
|-&lt;br /&gt;
| Interface || SYNC&lt;br /&gt;
|-&lt;br /&gt;
| Protocol || any&lt;br /&gt;
|-&lt;br /&gt;
| Source || any&lt;br /&gt;
|-&lt;br /&gt;
| Destination || any&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
Then Save and Apply Changes.&lt;br /&gt;
&lt;br /&gt;
fw2-HQ is now ready.&lt;br /&gt;
&lt;br /&gt;
== Configuring fw1-HQ ==&lt;br /&gt;
&lt;br /&gt;
Switch over to fw1-HQ to continue the configuration.&lt;br /&gt;
&lt;br /&gt;
=== Assign and Configure Sync Interface ===&lt;br /&gt;
&lt;br /&gt;
Browse to &#039;&#039;&#039;Interfaces &amp;gt; Assign&#039;&#039;&#039; and verify the SYNC interface is assigned.&lt;br /&gt;
&lt;br /&gt;
Browse to &#039;&#039;&#039;Interfaces &amp;gt; OPT3&#039;&#039;&#039; and configure:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Setting !! Value&lt;br /&gt;
|-&lt;br /&gt;
| Enable || checked&lt;br /&gt;
|-&lt;br /&gt;
| Description || SYNC&lt;br /&gt;
|-&lt;br /&gt;
| IPv4 Configuration Type || Static IPv4&lt;br /&gt;
|-&lt;br /&gt;
| IPv4 Address || 172.17.3.2/24&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
Save and Apply Changes.&lt;br /&gt;
&lt;br /&gt;
=== Add Sync Firewall Rules (fw1-HQ) ===&lt;br /&gt;
&lt;br /&gt;
Browse to &#039;&#039;&#039;Firewall &amp;gt; Rules&#039;&#039;&#039;, Sync tab. Add:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Setting !! Value&lt;br /&gt;
|-&lt;br /&gt;
| Action || Pass&lt;br /&gt;
|-&lt;br /&gt;
| Interface || Sync&lt;br /&gt;
|-&lt;br /&gt;
| Protocol || any&lt;br /&gt;
|-&lt;br /&gt;
| Source || any&lt;br /&gt;
|-&lt;br /&gt;
| Destination || any&lt;br /&gt;
|-&lt;br /&gt;
| Description || allow sync&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
Save and apply changes.&lt;br /&gt;
&lt;br /&gt;
=== Change Interface IPs (fw1-HQ) ===&lt;br /&gt;
&lt;br /&gt;
The gateway IPs on the internal interfaces need to be CARP IPs so they fail over. Change the LAN and DMZ interface IPs:&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;LAN&#039;&#039;&#039;: change from 172.17.1.1 to &#039;&#039;&#039;172.17.1.2&#039;&#039;&#039;&lt;br /&gt;
* &#039;&#039;&#039;DMZ&#039;&#039;&#039;: change from 172.17.2.1 to &#039;&#039;&#039;172.17.2.2&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
The .1 IPs will be added back as CARP IPs in the next step. Save and apply changes after each interface.&lt;br /&gt;
&lt;br /&gt;
=== Add CARP VIPs (fw1-HQ) ===&lt;br /&gt;
&lt;br /&gt;
Browse to &#039;&#039;&#039;Firewall &amp;gt; Virtual IPs&#039;&#039;&#039;, and click &#039;&#039;&#039;+Add&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
==== LAN CARP VIP ====&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Setting !! Value&lt;br /&gt;
|-&lt;br /&gt;
| Type || CARP&lt;br /&gt;
|-&lt;br /&gt;
| Interface || LAN&lt;br /&gt;
|-&lt;br /&gt;
| IP Address || 172.17.1.1/24&lt;br /&gt;
|-&lt;br /&gt;
| Virtual IP Password || random characters (syncs automatically)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
Leave the remainder at defaults. Save and Apply Changes.&lt;br /&gt;
&lt;br /&gt;
==== DMZ CARP VIP ====&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Setting !! Value&lt;br /&gt;
|-&lt;br /&gt;
| Type || CARP&lt;br /&gt;
|-&lt;br /&gt;
| Interface || DMZ&lt;br /&gt;
|-&lt;br /&gt;
| IP Address || 172.17.2.1/24&lt;br /&gt;
|-&lt;br /&gt;
| Virtual IP Password || random string&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
Note the VHID group increments to 2. Save and apply changes.&lt;br /&gt;
&lt;br /&gt;
=== Edit Existing WAN VIPs (fw1-HQ) ===&lt;br /&gt;
&lt;br /&gt;
==== WAN .4 VIP ====&lt;br /&gt;
&lt;br /&gt;
Edit 192.0.2.4: change type from IP Alias to CARP, subnet mask /24, VHID Group 3, random Virtual IP Password. Save.&lt;br /&gt;
&lt;br /&gt;
==== WAN .5 and .6 VIPs ====&lt;br /&gt;
&lt;br /&gt;
Edit 192.0.2.5 and 192.0.2.6: keep as IP Alias but change parent interface to the WAN CARP IP (192.0.2.4). Save and apply changes.&lt;br /&gt;
&lt;br /&gt;
==== WAN2 CARP VIPs ====&lt;br /&gt;
&lt;br /&gt;
Change 198.51.100.4 to CARP, and change the interface of 198.51.100.5 and .6 to 198.51.100.4.&lt;br /&gt;
&lt;br /&gt;
=== Configure HA Sync (fw1-HQ) ===&lt;br /&gt;
&lt;br /&gt;
Browse to &#039;&#039;&#039;System &amp;gt; High Avail. Sync&#039;&#039;&#039;:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Setting !! Value&lt;br /&gt;
|-&lt;br /&gt;
| Synchronize States || checked&lt;br /&gt;
|-&lt;br /&gt;
| Synchronize Interface || SYNC&lt;br /&gt;
|-&lt;br /&gt;
| pfsync Synchronize Peer IP || 172.17.3.3&lt;br /&gt;
|-&lt;br /&gt;
| Synchronize Config to IP || 172.17.3.3&lt;br /&gt;
|-&lt;br /&gt;
| Remote System Username || admin&lt;br /&gt;
|-&lt;br /&gt;
| Remote System Password || pfsense&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
Click &#039;&#039;&#039;toggle all&#039;&#039;&#039; to check all synchronize configuration boxes, then click Save.&lt;br /&gt;
&lt;br /&gt;
Configuration and state synchronization are now fully enabled. Do not make config changes directly on the secondary from here out, as they’ll be overwritten by the primary.&lt;br /&gt;
&lt;br /&gt;
=== Configure Outbound NAT ===&lt;br /&gt;
&lt;br /&gt;
Browse to &#039;&#039;&#039;Firewall &amp;gt; NAT&#039;&#039;&#039;, Outbound tab. Edit rules so traffic is NATed to IPs that fail over:&lt;br /&gt;
&lt;br /&gt;
* Edit &amp;quot;HQ 172.17./16 out via WAN IP&amp;quot; — change Translation to &#039;&#039;&#039;192.0.2.6&#039;&#039;&#039;&lt;br /&gt;
* Edit &amp;quot;HQ 172.17./16 out via WAN2 IP&amp;quot; — change Translation to &#039;&#039;&#039;198.51.100.6&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
=== Configure LAN DHCP ===&lt;br /&gt;
&lt;br /&gt;
Browse to &#039;&#039;&#039;Services &amp;gt; DHCP Server&#039;&#039;&#039;, LAN tab:&lt;br /&gt;
&lt;br /&gt;
* Set default gateway to the LAN CARP VIP &#039;&#039;&#039;172.17.1.1&#039;&#039;&#039;&lt;br /&gt;
* Set &#039;&#039;&#039;Failover Peer IP&#039;&#039;&#039; to fw2-HQ LAN IP &#039;&#039;&#039;172.17.1.3&#039;&#039;&#039;&lt;br /&gt;
* Save&lt;br /&gt;
&lt;br /&gt;
== Check Status ==&lt;br /&gt;
&lt;br /&gt;
Browse to &#039;&#039;&#039;Status &amp;gt; CARP&#039;&#039;&#039; on both fw1-HQ and fw2-HQ. All CARP IPs should show:&lt;br /&gt;
* &#039;&#039;&#039;master&#039;&#039;&#039; status on fw1-HQ&lt;br /&gt;
* &#039;&#039;&#039;backup&#039;&#039;&#039; status on fw2-HQ&lt;br /&gt;
&lt;br /&gt;
== Testing Failover ==&lt;br /&gt;
&lt;br /&gt;
=== Force Failover by Disabling CARP on Primary ===&lt;br /&gt;
&lt;br /&gt;
On fw1-HQ, browse to &#039;&#039;&#039;Status &amp;gt; CARP&#039;&#039;&#039; and click &#039;&#039;&#039;Temporarily Disable CARP&#039;&#039;&#039;. After reload, all CARP IPs change to &amp;quot;disabled.&amp;quot; Check fw2-HQ — they should all show master status.&lt;br /&gt;
&lt;br /&gt;
=== Force Failover by Simulating Power Removal ===&lt;br /&gt;
&lt;br /&gt;
Navigate to &#039;&#039;&#039;Diagnostics &amp;gt; Halt System&#039;&#039;&#039; and click &#039;&#039;&#039;Reboot&#039;&#039;&#039; on the primary. Within a second after rebooting, fw2-HQ should show master status on all CARP IPs. After fw1-HQ reboots, it will regain master status automatically.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;background:#e6f2ff; padding:10px; border-left:4px solid #003366; margin-top:15px;&amp;quot;&amp;gt;&lt;br /&gt;
&#039;&#039;&#039;Previous Module:&#039;&#039;&#039; [[Training: High Availability|Training: High Availability — HA Overview and Concepts]]&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Source Attribution ==&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;Netgate pfSense Plus Fundamentals and Practical Application&#039;&#039;&lt;br /&gt;
* © 2021 Rubicon Communications, LLC (Netgate)&lt;br /&gt;
* Source PDF: FUND001-LIVE-Lab10-HA.pdf&lt;br /&gt;
* Reference fw2-HQ IPs: WAN 192.0.2.3, LAN 172.17.1.3, DMZ 172.17.2.3&lt;/div&gt;</summary>
		<author><name>Justinaquino</name></author>
	</entry>
	<entry>
		<id>https://mediawiki.comfac.net/index.php?title=Training:_High_Availability&amp;diff=235</id>
		<title>Training: High Availability</title>
		<link rel="alternate" type="text/html" href="https://mediawiki.comfac.net/index.php?title=Training:_High_Availability&amp;diff=235"/>
		<updated>2026-04-23T07:07:10Z</updated>

		<summary type="html">&lt;p&gt;Justinaquino: Created from Netgate pfSense training PDF&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__NOTOC__&lt;br /&gt;
&amp;lt;div style=&amp;quot;background:#003366; color:#ffffff; padding:10px; border-radius:5px; margin-bottom:15px;&amp;quot;&amp;gt;&lt;br /&gt;
&#039;&#039;&#039;Netgate pfSense Plus Fundamentals — Section 10: High Availability&#039;&#039;&#039;&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Overview ==&lt;br /&gt;
&lt;br /&gt;
High Availability (HA) in pfSense uses an &#039;&#039;&#039;active/passive pair&#039;&#039;&#039; of firewalls to provide hardware redundancy. This architecture offers:&lt;br /&gt;
&lt;br /&gt;
* Increased redundancy options&lt;br /&gt;
* Less painful upgrades&lt;br /&gt;
* Seamless failover capabilities&lt;br /&gt;
&lt;br /&gt;
HA relies on &#039;&#039;&#039;three separate functions&#039;&#039;&#039; working together:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Function !! Purpose&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;CARP&#039;&#039;&#039; || Provides redundant IP addresses (Virtual IPs) shared between HA members&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;pfSync&#039;&#039;&#039; || Synchronizes the state table between HA members for seamless failover&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;XMLRPC&#039;&#039;&#039; || Synchronizes configuration from the primary to secondary firewalls&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== CARP (Common Address Redundancy Protocol) ==&lt;br /&gt;
&lt;br /&gt;
* Uses multicast for announcements&lt;br /&gt;
* Every CARP VIP has a unique &#039;&#039;&#039;VHID&#039;&#039;&#039; (Virtual Host ID)&lt;br /&gt;
* CARP VIP is shared between VHID members&lt;br /&gt;
* VHID groups are password protected&lt;br /&gt;
* At least &#039;&#039;&#039;3 public IPs required&#039;&#039;&#039; per WAN&lt;br /&gt;
* WAN needs at least a &#039;&#039;&#039;/29&#039;&#039;&#039; subnet&lt;br /&gt;
&lt;br /&gt;
== pfSync ==&lt;br /&gt;
&lt;br /&gt;
* Syncs state table between the two HA members&lt;br /&gt;
* Enables seamless failover during an outage&lt;br /&gt;
* Can use multicast or unicast for updates&lt;br /&gt;
* No authentication for updates&lt;br /&gt;
* &#039;&#039;&#039;Likes a dedicated interface&#039;&#039;&#039; (recommended)&lt;br /&gt;
&lt;br /&gt;
== XMLRPC (Configuration Sync) ==&lt;br /&gt;
&lt;br /&gt;
* Syncs configuration between HA members&lt;br /&gt;
* Syncs from primary to secondaries&lt;br /&gt;
* Only need to configure one firewall&lt;br /&gt;
* May not sync everything — &#039;&#039;&#039;packages are responsible for their own config sync&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== CARP Configuration Requirements ==&lt;br /&gt;
&lt;br /&gt;
* At least one CARP VIP on WAN&lt;br /&gt;
* At least one CARP VIP on LAN&lt;br /&gt;
* Manual Outbound NAT to CARP VIP&lt;br /&gt;
* DHCP adjustments needed (use CARP VIP as default gateway)&lt;br /&gt;
&lt;br /&gt;
== Typical Topology ==&lt;br /&gt;
&lt;br /&gt;
=== Single WAN ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ISP1&lt;br /&gt;
  |&lt;br /&gt;
[ HA Pair ] — LAN&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Multi-WAN ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ISP1     ISP2&lt;br /&gt;
  |        |&lt;br /&gt;
[   HA Pair   ] — LAN&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Common Failures ==&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;Dual master&#039;&#039;&#039; on CARP VIPs&lt;br /&gt;
* Loss of active connections on failover&lt;br /&gt;
* Loss of connectivity on failover&lt;br /&gt;
&lt;br /&gt;
== Section 10 Summary ==&lt;br /&gt;
&lt;br /&gt;
* Active/Passive pair&lt;br /&gt;
* Will need at least &#039;&#039;&#039;/29&#039;&#039;&#039; of network space per WAN&lt;br /&gt;
* Use a &#039;&#039;&#039;unique VHID&#039;&#039;&#039; for every CARP VIP&lt;br /&gt;
* Use a &#039;&#039;&#039;separate private interface&#039;&#039;&#039; for pfSync data&lt;br /&gt;
* Packages are responsible for their own config sync&lt;br /&gt;
* Outbound NAT to CARP VIP&lt;br /&gt;
* DHCP adjusted for CARP VIP as default gateway&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;background:#e6f2ff; padding:10px; border-left:4px solid #003366; margin-top:15px;&amp;quot;&amp;gt;&lt;br /&gt;
&#039;&#039;&#039;Next Module:&#039;&#039;&#039; [[Training Lab 10: High Availability|Training Lab 10: High Availability — Hands-on Configuration and Failover Testing]]&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Source Attribution ==&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;Netgate pfSense Plus Fundamentals and Practical Application&#039;&#039;&lt;br /&gt;
* © 2017–2021 Rubicon Communications, LLC (Netgate)&lt;br /&gt;
* Source PDF: FUND001-LIVE-SLIDE-SEG10-HA.pdf&lt;/div&gt;</summary>
		<author><name>Justinaquino</name></author>
	</entry>
</feed>