diff --git a/opnsense/readme.md b/opnsense/readme.md
index 28109e0..03fa85b 100644
--- a/opnsense/readme.md
+++ b/opnsense/readme.md
@@ -35,6 +35,8 @@ Two physical network cards - NICs
* create new virtual switch - `vSwitch1-WAN`
* create new port group - `WAN Network`, assign to it `vSwitch1-WAN`
+If plannig VLANs port groups need them assigned, trunk needs vlan 4095 set.
+
#### Virtual machine creation
* Guest OS family - Other
@@ -159,7 +161,12 @@ So I guess its living with this.
* LAN - set network and mask, I prefer 10.0.X.1
* root password
* Update
-*
+
+
+* `System: Settings: Miscellaneous` - `Periodic NetFlow Backup` - `Disabled`
+ avoids long wait time on restart / shutdown
+
+
@@ -384,6 +391,16 @@ Services: Unbound DNS: General
---
---
+
+VLANs
+
+[written on it here](https://github.com/DoTheEvo/selfhosted-apps-docker/blob/master/_knowledge-base/vlans.md)
+
+
+
+---
+---
+
Monitoring
@@ -429,6 +446,8 @@ Must **enable logging** for a rule to be visible there.
Plugins
+[zenarmor](https://www.zenarmor.com/docs/guides/best-practices-for-zenarmor-deployment)
+
* os-vnstat to have some general idea about traffic