#networking
1 messages ยท Page 4 of 1
Classes A,B, and C are reserved private IPS. They can configured for WAN or LAN use.
holy! it's $11k here, excluding VAT! 
Entry levels are 6.5Gbps max, 70F, 80F and all of their variants
Probably not an F series
E series has shitty VPN performance
F is the newest and current
ahh okay, but an E is probably sufficient for my home network? 
Yeah
also tbf I only have a gigabit connection in/out from my home
friend has a 60E on a gig/gig fios connection
so probably don't really need 10G equipment for anything but the stuff on my internal network
if you're not doing 10G inter VLAN you don't need 10G router
I'm going to do 10G internally soonโข๏ธ
10G in just one VLAN or between VLANs
if you're doing 10G on one VLAN and all of the clients are in that same VLAN you don't need a 10G router
but if you're doing 10G between VLANs and the clients need to route between VLANs you need a 10G router
or a switch with layer 3 and can handle 10G
since I have kinda committed to the UniFi ecosystem, I was considering XG-16 or something (I can't recall the model name of that 10G switch)
only the 192.168/16 is private not the entire 192/8
Correct
๐
I misinterpreted my statement
If you don't need IPS between local subnets you could use an L3 switch and save money
all good
well presumably I'm going to have servers and VMs on separate VLAN to clients, and I want my clients to be able to transfer files to and from the NAS over 10Gb
Nice.. thats gonna be a beefy NAS.
Yessir!
yeah 10G router or L3 switch
UniFi doesn't have any really good L3 switches right now
UDMP is 10G already ๐ฎ
but the UDMP can do 10G routing
that's why I got it - though I'm quite beginner at networking stuff
Ubiquiti has UniFi layer 3 switches but they don't have any support for ACLs
So while it can route between VLANs there's no ACL between it
Meaning any L3 VLAN can access any other L3 VLAN
So they're good for L2 and propping up wobbly table legs?
i can highly recommend Netbox for keeping track of everything. If you go over a dozen devices or so it can get tricky to remember what you connected into what.
and any CLI changes get wiped when the switch provisions from controller
Compelling
ugh, my projects are piling up ๐ I got to get a grip and finish one project at a time, not constantly find new ones
but man is networking ever expensive, and when you also start adding NAS etc to the equation - bye bye wallet!
and hat price shoots up when you want to go above 1G
yeah, 1G stuff is relatively affordable, depending on what you need - at least there are a ton more options, and a ton more stuff floating on the second hand market
someone I talked to had 40 and 100G equipment at home ๐
current state of everything โข๏ธ
I've been meaning to setup shit but i haven't
Yeah, i'm perpetually 70% through documenting my stuff.
only a couple days ago did I setup redundant dns
looks like a nice setup, I have an R610 and R710, have considered swapping them out for my 5900X build when the 7000-series starts shipping
just the mobo, memory, and cpu though
got the idea of turning my Define 7 XL into a rack mounted PC case ๐
it's like extremely difficult to find rack mountable cases support ATX mobos in Norway
All of the network runs in the house terminate to a separate patch panel
yeah, I will do that as well when I get my own place
right now I'm just renting, but all of the network ports still terminate in the same room
I got no patch panel or anything though, I don't even have a rack 
Looks pretty pogg, ngl!
sure, it's okay for a homelab, but I would really prefer to have a small rack to fit this hardware into
and I would love to fit a GPU for hardware acceleration into my R710
yeah, having the rack will save a lot of space lol!
racks that support a full size server like these aren't cheap, especially not the size I need (iirc roughly 60cm tall max)
yeah, can't fit that in here, if I could I would probably look for one for free
looked at that one, or well, the 12U version of it, but it's $400 here
I do have a shed, and that shed is behind my landlords garage, where the fiber comes up, so I could potentially just wire up my servers there, in a 42U rack 
better cooling too, no noise in here ever from the servers either
then just run a fiber cable up to my apartment
just unsure if the climate is suitable there, especially during winter... but with the servers and other stuff running 24/7, it should probably not be too bad, but I do fear condensation a little bit
Why do you run cyberchef 24/7? You need to decode data that often?
its only using like 5MB of RAM ๐คฃ
i can spare 5MB of RAM to keep cyberchef running
and yeah I use it for ctf and shit
Nice. That is the type of stuff I do for work
nice
what exactly is CTF? iirc I've heard the term before, but can't really seem to remember what it is for (I mean I know the acronym I guess)
Oh god, my worst nightmare
ahh, I see, not into cybersecurity, but it does sound interesting
You find "flags"/strings hidden somewhere or in something
legal ways to practice and learn how to break into systems and perform digital forensics
^
very useful for people as they learn hands on cybersecurity
for work I'm just a customer support / software tester (Q&A I guess) ๐ I used to be a system engineer though, but cba with it as work for now
@rocky badge have you ever performed any memory forensics (analysis of RAM samples)?
nope ๐ haven't tried those
ahh, I see, might look into that in the future, so I can do some basic pen testing on my own stuff
i like CTF but i like a lot of network security more than programming/reverse engineering
yea, I am pretty lucky in that I get to jump around all the areas with really interesting real world data
I think I would like to work with networking related stuff, but I do like programming (not so much reverse engineering), because then I can solve inconveniences in my life etc
Our clients are all heavily targeted by nation states hostile to western interests... so we get to see cutting edge malware and toolkits targeting our clients, and we have host + network visibility to perform as thorough forensics as we want. Also, lots of reversing of exploits and malware samples.
so far I like my job though, pretty chill, just ezpz stuff, aside from the internal routines and ways of doing things ๐
It is never boring ๐
like some customer complaining their site didn't work when accessing from Google - broken SSL cert (well, was missing www)
i've never really went through any courses or have anybody teaching me this shit lol
that does sound pretty exciting, but also stressful to work with ngl!
it's all been frantically googling when at the actual CTF competition
same, I've picked up quite literally everything I know as I go ๐ be it what little I know about networking, or troubleshooting hardware or software, programming etc
same even with English ngl, I guess I did learn some basic stuff in school, but man was I ever bad at English when I was in school
looks like my PC and laptop regardless of what I do ๐
Oo, nice, sound my old router
hi yall does anyone know what an ipv4/6 dns relay is? its a setting on my arris gateway
Like no one uses classes anymore
errm.
What's your option? Is it just enable or disable?
yep, if its enabled the dns options are greyed out tho
Ok, so its probably DNS relay vs Proxy.. This description i stoel from the web probably words it better than i can.
DNS relay is similar to DNS proxy. The difference is whether they search for DNS entries saved in the local domain name resolution table, including the static domain name resolution table and the local domain name cache after receiving DNS query messages from DNS clients.
The DNS proxy searches for DNS entries saved in the local domain name cache after receiving DNS query messages from DNS clients. If requested DNS entries are not saved in the cache, DNS query messages are forwarded to the DNS server.
The DNS relay does not search for DNS entries saved in the local domain name cache after receiving DNS query messages from DNS clients. It forwards the messages directly to the DNS server for resolution. On one hand, it can save the cost for the cache on the DNS relay. On the other hand, it guarantees the real-time requirements for that the DNS client obtain resolution results. (If the domain names and IP addresses on the DNS server changes and the cache on the DNS proxy is not updated in time, the resolution result obtained by the DNS Client is incorrect.)
Well, it is part of the structure. and you scrolled up so far lol
I've never seen someone actually at work say class a, b, or c
/24, /16, etc. etc
Didn't iana or whatever the numbers authority is deprecate classful networking
variable length
Wasn't it also partially replaced so public ips could be assigned in blocks lesser than /24
i mean, it's not super common anymore. i have some older networking textbooks from the early 2000s that made a big deal about knowing classes and cidr and converting between them
hasn't come up in the last 5 years for me in any serious way
VLSM was far before they were worried about the "public" side at the time. When they finally realized how fast the internet was expanding, they needed a method to stop wasting IP space. At this time, IP blocks were being handed out via email at request.
ah
Still in modern text books/classes. Its there more of a history when discussing subnetting, ex. start with classful networks, demonstrate the scaling/issues, introduce subnetting of those networks and hence introducing classless. It made sense from a academic standpoint, but should not be used anymore honestly. Too many people, even professionals in this field, that still use the term
I don't recall the guys name, but the guy that was handling the assignment at the IETF still has the holy grail of notebooks which is a scratchpad of names and IP blocks that was used to keep track of who had what network
lmao
I am used to it because of learning it for exams
I know it isn't a common practice to say, but in my mind it is a tool to approximate what IP is what.
To summarize I absorb knowledge of what I have learned prior to taking exams.
lol, I remember learning about classes being relevant when I did IT in high school like 8 years ago
not saying you're wrong, I'm bashing my course in case that was unclear
lol
I never really understood the point of the network classes anyway tbf, maybe it made more sense like ~20 years ago?
Yeah, thats why I mentioned above it's still being taught. They just don't emphasize enough that classful is no longer used and many people continue to think it is
yeah, pretty dumb ngl, but then again IT in high school is really basic (even a dedicated course like the one I did), so I guess if I did uni or something primarily around networking, they'd emphasis it more(?)
You know the "you'll never need more that 64KB memory" meme? Yeah the IETF was the OG.
Remember, IPv4 was in development in the 70s and was primarily for universities and research (until the gov. stepped into to fund it for their use as well). They never though they would ever need more networks
Classes made sense then with their hardware and protocols. But as they expanded, they quickly realized how wrong they were
Right, Now since IPv6 is rolling around, it is using hexadecimal notation instead of the traditional decimal used.
Thats why IPv6 was overengineered to be so large and never classful. But because engineers are careless, IPv6 has its own soft limit.
Yeah!
I want IPv6 services ๐ก
IPv6 using hex is just for readability. Bit notation is still the underlying concept of both v4/v6. Its all about the bit values
MTA Certs or even CompTIA cert courses go over classes. The courses go through certain lessons where those lessons are obsolete to learn.
Present's Fios region finally got v6, I am still waiting on my region to get it as well
Are you all living in the United States?
I am
lmao what a mess! being self taught has its perks I guess
Well, I did teach myself more or less what I know, but having to take those exams, I wanted to make sure I would pass.
I am an underachiever with excelling qualities.
i should setup bgp /s
I want to take the A+, Network + and more, but I feel like I'll fail and waste money taking it.
CompTIA at this point is ignored by most employers
BGP โค๏ธ
yeah definitely, haven't been particularly invested in networking, but was planning to do some CLI and setup my home network more along the lines of a commercial network - though it never happened, aside from getting a UDMP and ditching the ISP provided equipment lol
LMAO!
So far, I have configured a basic FTP Server and VPN so I can access my home network wherever I want to and access my own files. 12TB of storage vs OneDrive lol. My VPN uses LDAP/IKEv2 protocols with SSL.
And I have a website configured but never finished it.
Get on dn42
lol
I was thinking setting up ospf
Esp when I will have site-site vpn
Just so I don't need to setup a bunch of statics
Lmao!
lol
Zt = zerotier?
yeah
Yeah prob gonna use it for site to site
ZT can get through NAT easily
Hm, What application are you using to manage your network?
@rocky badge
this is my router's gui lol
ah tbf, I have a storage server 5x4TB HDDs iirc, and I run a Nginx server for reverse proxy to host multiple web apps etc if need be, can't remember if I have any online right now lmao ๐ I also have a pihole vm I almost never use
thxx but i dont quite understand it, so is the relay good?
what it sounded like to me is a relay will get DNS records from a DNS server, without relay it gets them from a cache instead, assuming it's present in the cache - if not present in the cache, it asks the DNS server instead
if you're not really looking to learn this, but just have a functional network, I'm not sure you'll notice that much of a difference - although I'd turn on relay
in case it was unclear though, I'm on very thin ice answering this, don't assume my information is accurate
Relay won't use a local look up for names on your domain (which i suspect you don't have anyway). i would leave off (but for most peoples needs it really makes no difference) but it will make no difference. If its something you would like tune you can benchmark your DNS and find the quickest servers for yourself using a tool like https://www.grc.com/dns/benchmark.htm
I use Tailscale and ZeroTier to create VLANs to host a minecraft server privately... Recently both of them went on relays instead of direct connections, assuming my ISP did something in the backend that's preventing direct connections.
Can a P2P enabled VPN solve this problem?
(if I use a VPN that has a server in the same country that is)
uhh what
tailscale and zt don't create vlans
tailscale and zt are p2p except if they can't
your ISP may have done something with NAT
oh... I assumed since it's a virtual subnet it's called a vlan
yup they keep doing that randomly every year, I hate it
that's technically a VPN
Since a P2P VPN will connect through a proper server, friends should have a direct connection through it to my server
you know what p2p means? Peer to peer, meaning they connect directly to your server
should've said p2p supported *
nothing in the middle
This is a random MS paint representation of what I was thinking ๐
so you want not p2p
oh well... if these direct p2p solutions can't connect directly now, what are my options
that basically what it's doing rn with relays
what is the issue
The default relay servers are extremely slow and laggy
Zerotier gives me 500ms+ ping with a relay... Tailscale gives 100ms+ and very slow speeds
= unplayable game, people just connecting and disconnecting over and over
wireguard probably works
PC A, peers B & C
PC B, peers A &C
PC C, peers A & B
but this is essentially what ZeroTier is doing its just automatic
Since Tailscale uses wireguard and can't get a direct connection no matter what I try (out of nowhere after being perfectly fine since 5 months), will using wireguard let these things connect directly?
@peak cloak Somehow ZT at school is getting direct connections
there's probably a bigger issue than zerotier or tailscale here ยฏ_(ใ)_/ยฏ
something's preventing them from traversing NAT and requiring them to go through public relay servers
My ISP messing around with their NAT is one I'd assume
If there's a CGNAT I'd just use a Wireguard server in EC2/the like and port-forward it from the instance. Use whitelisting for MC rather than needing everyone to install a VPN client
^ that's what I do for web services without exposing HTTPS directly to the web
yup but that'll have a cost... I already have a 2nd server build that has enough resources and everything for this. All I need to figure out is networking
Sure does have a cost... about $3.50/month?
It's either that or deal with what you have
yeah thought so... :/
Nice, I'll try this if I can
I use Lightsail though with the increase in free tier BW I could probably do a t3/4 variant cheaper
any guide / info about what all you're using for that? Lightsail?
Lightsail is an AWS product that bundles everything in including data, in exchange for giving you a watered down API and frontend
It's EC2 for noobs basically, but the bundled data is cheaper than their EC2 rate
That was Lightsail yes
alright awesome, will try setting it up today, thanks ๐
oracle cloud free vps
I used the DO $200 credits with the most basic VPS, lasted a long time, and I just canceled it because I didn't use it anymore
#humblebrag
oh thanks I'll check that too... im a college student with absolutely no source of income right now and I can't be asking parents for every little thing anymore so I'll see what I can do
Hey, working on setting up a cool homelab for college and was wondering if anyone had a recomendation for a cheap router that can handle a site to site VPN. Ubiquiti is just too expensive for my use case and my netgear router doesnt have the features
Internet works completely fine until i open a game with any amount of internet requirements. I have 500~ megabytes of download speed and its only MY pc that disconnects while a game is open.
This is not game-specific. if it was, this problem would've been solved long ago.
Video is an example of scrap mechanic and chrome.
this issue has plagued me for so long and my friend told me to get help here
i feel like i've tried everything in my knowledge to fix this but literally nothing changes.
I know its router-specific, because this issue doest happen at my dad's house.
(and yes i have tried the blatantly obvious router restart numerous times)
If you want some more evidence just ask
are you connecting over wifi? and/or how old is your router/ap/cabling
from a quick search, microsoft answers mentioned a similar problem where the power was the main issue
if the router is old enough, or the power adapter for it is old/breaking the power throughput of the connection to your device may be breaking it. Is this the only gaming PC in your house? simple troubleshooting could be if others with similar internet demands are facing the same problem
- wifi, we got the router and cables a month ago
- this problem persisted even before we got a new router a month ago
- i have a good computer
- yes there are 2 more, but nothing changes even if they're using internet or off completely
Hmmm then it may be the network card on the pc itself. I would try hardwire (if you can) or a new Wi-Fi adapter
Even on high end devices fault components like mother board Wi-Fi could be the root cause of it doesnโt have line of site or interference
ok
but here's the funny thing!
it works completely as usual when im at my dad's house
so it cant be a hardware issue
right?
Well it depends distance from the router. Material through walls etcโฆ if your Wi-Fi is faulty it could still get a good connection at your dads because the router is close but at your other house distance/blockage may break it. Have you tried moving the device around maybe closer to the device? Beyond that Iโm not sure itโs definitely a weird issue. If you can I would try a hardwire connection for testing to see if it works better that can narrow the problem
that wouldnt cause a pc-wide disconnect when games are open, right? i can still browse the web at very good speed, the same as my dad's house
Well if running a game that uses p2p it definitely could break the internet for your device. As it takes a lot of bandwidth. If your network card is faulty or breaking, it could cause this issue. Another good test would be to open task manager, advanced settings, and Wi-Fi. Watch to see if you are getting packet drop and/or your network throughput is maxed out. Another trouble shooting step would be to see if your device is being limited in router settings, sometimes a bad config could limit a devices network connectivity hence bad response times when running a game.
i dont use p2p
this is all of my games that use any amount of internet here
ive made multiple "fixes" to my configs and nothing has changed
Huh interesting. Many games which connect to server can utilize p2p without the end user knowing it buut odds are that is not the issue just a possibility. Iโd start with Troubleshooting with both wired and wireless next to an AP or the router. If the speed are better than the network card is to blame. If they stay the same the router is more of the problem. From there I would load wireshsark and monitor network traffic. If you are noticing packet loss and other errors. Your router/ap is to blame. You may just have awful luck and upgraded from a bad router to broken one
more like broken router to broken router
ive used wireshark and its near 100% packet loss
then immediately after the game closes its around 0%
i understand if this is confusing, two other people have tried to help and were stumped completely.
Wow, thatโs actually a really fascinating issue and so sorry it is affecting you. No worries I know wanna figure this out for my sanity. With your experiences with wireshark there is a good chance your games is using up all of the network bandwidth which adds to the original thought of fault/bad connection to your network
500mbs
While not a fix, a possible issue could be network saturation from multiple wireless networks. In most urban environments like apartments, several people in close contact broadcasting their own network can break and saturate Wi-Fi making it impossible to use. Does your dad live in an area with lest SSID broadcast?
ok
i live in an apartment complex, my dad lives in a neighborhood
so that seems very likely actually
we do also get call drops sometimes too
I would look up how to change channels for Wi-Fi networks. By changing to a less used it could make things better. And it looks like network saturations along with cellular dead zones may just be creating a cluster of network problems
alright ill try
Are you on a 5ghz or 2.4? Depending on the age of the pc it could be connecting on 2.4 which has a the largest radius and is the most saturated along with more devices creating noise on the network. If you can I would make sure your device is on 5ghz and as close to the router as possible
Haha alright on your pc run ipconfig /all
kk
You will see your network address and hopefully the gateway
Odds are it is 192.168.1.1 192.168.0.1 or if itโs dance 10.0.0.1
Haha yup so it is 10.0.0.1
Gateways are always the first up of the network which is why you can only use from 2-254
Oh easy to look up
how?
Just search up your router manufacture/ model and search default login
Usually username โadminโ password โadminโ but could be different
What model do you have? Xfinity is starting to phase out there router control
Haha no thatโs the network chip
Router manufactures are like
Comcast, netgear, tp-link, asus,pfsense, and ubiquiti
Ahh so it is a comcast router
guess so
Should be username admin password password
it worked!
If not then someone has already logged in and configured it to change the password
Perfect
oh wait its making me do a new password
Yeaaah definitely make that lore secure
should i just make it admin admin?
Preferable make it an actual password for security it can be whatever you want as long as you remember it
Haha perfect. You are already doing better than the Dutch government. They forgot to change the default password so anyone who new something about networking could login to their hardware. Anyways. You are gonna look to change the channel for Wi-Fi
I canโt remember off the top of my head but maybe??? Comcast routers are starting to get locked down so if you canโt find what you want you will want to log into the xfinity xfi web console through the xfinity website and sign in under the account holders name and password and mess with settings there
Ahh under connection,Wi-Fi
Perfect next to 2.4ghz and 5ghz edit and make sure they are set to automatic. If you want to set it manually (recommended) you will want to download a Wi-Fi spectrum analyzer on your phone and see what networks are congested choose the Channel with the least use and set that as the channel for your Wi-Fi
That should put your Wi-Fi on a channel that is not as cluttered hopefully fixing part of your problem
@terse pecan
i got it working thanks @terse pecan
did that fix the issue?
Yes, HOWEVER
most of my games end up making my router set its channel back to the shitty one, WHICH IS INFURIATING TO NO END
Like, i FINALLY got this issue figured out, but YET ANOTHER HURDLE
games do not have the ability to change the channel
I know that
Im just angry
I dont know whats causing it, but my router decides to switch back when i try to play certain games.
Granted, i can play the main games i wanted, but still
Oh alright then xfinity
Now its straight up setting it back immediately
considering you weren't able to ping at all when a game was running, I feel it's a much deeper issue than just changing channels
Ya think??
yes
Well, everything works completely fine when it wasnt setting itself back to channel 44
All games would work and the issue didnt happen
Until it switched back and the issue happened mid-session
if I had to bet, it's something with driver
I really don't think so
but yeah idk, why I hate wifi
Yup
So apparently there is no way to stop the router from switching its channel
From my searching
UGHHHHHH xfinity why
chuck their router and put something like an edgerouter instead and buy an access point
and should I be impressed?
Also channel rule ^^
lol, yup
im tryna fix this without buying new shit
:/
๐ฆ
I'll share ๐ค
the normal conncetion speed in Tรผrkiye
๐คทโโ๏ธ
lol
where are you from
USA
i plugged an ethernet into my ipod nano now it overclocks to 15gb of vram
what model router
it should say on the back
it will be something like XB3, XB6, XB7, XB8 or similar
99% of the time it will auto select an appropriate channel and it should work fine
๐
not sure if you're even supposed to be able to configure the channel but regardless, that is probably not the problem
At least your ping is better (:
mans coming in here to flex on his internet
What does 50mi mean it cant be the same 50ms ? because 50ms is pretty bad for such a good connection speed wise. I have 500mbps up and down and 1ms here in Sweden.
I have never noticed that speed test shows the distance from the server. Is that a new future or is just in the USA.
it's always been in there
it's approximate too
since your location will never be known exactly
@rocky badge I'm getting all sorts of new ads on insta now because of v6 geoip
ads of some ISP in Virginia
oof
it's not bad, it's just the ISP ad that was huh, interesting
used to compare your speed to every other test as well, so itd say "better than X% of the US" for example
everything else is fine
gotta
for what?
I guess, why not just vpn in
if i take my desktop to uni i won't have another windows desktop
currently experimenting with nvr software
installing https://frigate.video/
nice
shinobi and zoneminder kinda suck
i wouldn't mind milestone
shinobi is so weird, you have to go to like /super to do like superuser things like changing setttings
but $$
Explore your possibilities with Milestoneโs industry-leading video management software. XProtect VMS helps protect your business.
I see there is a free version
Yeah
but idk, frigate seems nice with a simple webui
That looks interesting. Does it use GPU resource for identification?
Can it? I have a VM server with a couple of 3080's in that i would rather load up than the cpu
By default, Frigate will use a single CPU detector. If you have a Coral, you will need to configure your detector devices in the config file. When using multiple detectors, they run in dedicated processes, but pull from a common queue of requested detections across all cameras.
Note: There is no support for Nvidia GPUs to perform object detection with tensorflow. It can be used for ffmpeg decoding, but not object detection
thanks for the quick response. Sorry i should have gone and looked myself but appreciate it. Still interesting.
this is for RDP?
btw just telling you if you share this make sure you block your ip if you don't have a vpn on
idc
nice
its not exposed to web
@peak cloak
JumpCloud
oh
quicktime player
Quicktime player can do a recording of the iphone over usb
oh interesting
yeah with android I can use the adb interface to control it
it can do any ios or apple tv
apple tv over the network
macos can receive iphone screen over the network but not quicktime player
the airplay receiver on the mac goes full screen
ooh

Hey all new on here, was wondering if anyone here is a networking guru I am having some issues with my homelab networking with pfsense and proxmox
wowwwww
i think my school had the same thing (don't remember if it was resnet or another similar provider, or something homegrown) but i think there was a way around it where you could get an alternative login for things like game consoles or chromecasts that couldn't easily be registered or joined
or maybe it was the reverse - a captive portal login but you could also register devices by MAC
i just remember there was some way around the really annoying bit
@waxen scroll LMAO LTT router
"If we get 100 Gig internet, we might need a switch with routing capabilities"
Just buy a fucking purpose built router and not a pfSense x86 box
ugh
would love to help, but not a networking guru 
omg lmao @waxen scroll
all of the interfaces lmao
They put int he new router and didn't even care about the other VLANs LMAO
oh godddd they switched to OPNsense
Thank you, for a quick rundown I have a PFSense running as a VM in a cluster of 3 proxmox servers, PVE, PVE2 and PVE3 where the pfsense is on, and this is all divided by HP2920 L3 switch, now my main issue is on my proxmox PVE2 I have 3 VLANS 172 (172.21.10.0/24) 173 (172.21.20.0/24) 174 (172.30.0.0/16) and they are all tagged for all ports on the switch at the moment just for diagnoses purposes, now for the actual issue, on the containers on the PVE2 the vlans are setup as en0.172 etc instead of tagging them on the network interface per container for easier setup via Ansible but the issue is for whatever reason they cannot ping 172.21.10.1 which is the PFsense (respective subnets per VLAN dont work either) but they can all talk to each other in their respective vlan/subnet even between PVE2 and PVE3 on another container, when doing an arp I do not get a hardware add for 172.21.10.1 (the gateway)
@waxen scroll LMG's networking is making me cringe\
yeah pfsense is great but not at that level wtf
at some point i was like "they're doing this for the content they're not actually idiots"
I'm starting to second guess that
ngl I would put different departments/office spaces/buildings on their own vlan
not one big /16
Thats nothing in terms of number of interfaces!
Also please don't tell me there is a FP video of them trying to do 100gbps on Pfsense....
yeah, i was saying the lack of vlans lol
not yet 
Where were the those screenshots from?
LTT got a new pfSense router
the yt vid isn't up yet but the fp vid is
it's got 25 & 10 gig sfps
it also has like a 20C 100 something TDP Xeon-D and 32GB of ram lol
they just need to get a real router
They were using pfSense so they could do a vpn but?????
they couldn't get performance they wanted from openvpn
Apparently they are now using zerotier
I would assume they are not just using this for routing and this is also their firewall right?
yes
but like....cisco has anyconnect, fortigate has ssl vpn/forticlient, palo alto has globalprotect, etc...
So not only do they need REAL hardware to route, they need a firewall that can perform at 100G if that is their goal
Yes
they currently have 10G
They were going to upgrade to 20 or 25G but linus shot it down because it was expensive
but they got the new router for "future"
My point is 100G routing is $$, 100G stateful firewall is $$$$$$
lol
rip lol
Even more $$$ for 400G NGFW >.>
i don't get why they didn't do MTP/MPO for fiber
and ran individual fiber for each station
even though its legit in the same room
That would involve planning
You see the Fortinet 2.4Tbps firewall?
i don't get their obsession with SFP+ to RJ45
an actual DAC is cheaper than a SFP+ to RJ45
in a 4U too
Yah, 55Gbps of TLSv1.3 decryption
2 houses please ๐
Damn...
800g ipsec, 70g app control ips av logging and sandboxing
@clear igloo @hollow marlin
this is how linus and crew treat their incoming fiber lol
๐คข
Well you can't do VLANs cuz they the devil!
/16 is weird but 100 devices on a /24 is the same broadcast traffic as 100 on a /16
Yea that's pretty weird. A bunch of /24s would make more sense
Looks like Juniper's only competitor is the SRX5800, and the 5600 being slightly worse. But they are not 4 RU chassis' lol
Yeah
imagine if creator warehouse & LAB are on the /16 
probably
all of that broadcast going over a p2p link
@clear igloo OH BRUH
This VM can see all VM traffic LMAO
10.0.10.10 is the VM
Looks like LTT just uploaded the video on YT ๐ฟ Lets see how this goes
its seeing SNMP between 10.0.10.8 and 10.0.10.6
lol, you hope
๐
who has 10.10.10.10?
ur mom

linus is the reason so many people come in here like durrrrr pfsense for business!
pfsense on ancient hardware drawing 200w of power idle!!!
๐ 200W
200? no. 500-1000
my router draws 10W max
gotta have a sweet GPU
mine draws like 50w >.>
ah
i don't understand why are they are using pfsense
they are legit not using anything pfsense offers
i wonder how much that fw was
๐ ๐ ๐ ๐
oh, get pricing
@waxen scroll @hollow marlin The router also has a 800W PSU
EIGHT HUNDRED WATT psu for a router
that probably can't hit 25g
He's also buying new high end hardware more than normal
That's a $2k CPU
A business would spec a router and use it 5 years
too complex they said
๐
They used to have a Cisco 2821 router WAY back in the day
Did they just say they have over 100 static DHCP reservations in their router......
yeah
I feel like enterprise gear would have a way better ui than pfsense
They used to have Windows Server DHCP but moved to pfSense doing DHCP
what ui? ๐
I doubt they'd be in cli/api
Most enterprise gear is CLI unless you go controller based stuff
Also quit calling me out. I'll use cli eventually
which adds much more cost
Pan panorama โฅ๏ธ
Mainly just visualizing the ruleset and knowing where I'm making the new one
Nsx you have to use use the API just to apply a management cert
Not really used anything other than ancient ASAs. But I have no complaints
ASDM or CSM?
Asdm
The one thing I did like about it was grouping rules by interface
@rocky badge I almost threw up when he didn't bother shutting down the old box and just pulled power
Junos is based on FreeBSD as well and I can say that it DOES NOT handle sudden power loss at all
@rocky badge frigate is pretty cool
Just cpu detection is slow
and can't use gpu for acceleration
oof
needs a google coral
which is $60 officially, you I can't find it anywhere at that price
@peak cloak Apparently Windows includes drivers for vmxnet3 now
it worked right out of the box
hi, i was wondering what the best router i can get from walmart or best buy for a 2 bedroom apartment with 300mbps speeds for like 30-50$, im fine buying from like amazon or something and even ebay as long as it will deliver to CONUS by aug 24. The person its for is cheap as hell so they would much rather spend 30 than 50 but its fine if its 50 for a big upgrade. Pls ping for answers or if you need more info, thank you for helping!
no
ok thats better
it's regular AD
is your user a member of Administrators group locally on the computer
it's local yeah
my uni uses a program called "MakeMeAdmin"
interesting
Make Me Admin is a simple, open-source application for Windows that allows standard user accounts to be elevated to administrator-level, on a temporary basis. - How It Works ยท pseymour/MakeMeAdmin ...
honestly, I may use that on my PC
That way your account isn't always admin
@rocky badge I assume it's bad to l3 adopt unifi APs over internet?
ah ok
cuz we do that at work
yeah it makes sense if you're a msp or something
and you need unifi but don't want to use a unifi os router or have on site
@rocky badge have you messed with domain GPO?
GPO in AD? yeah
I need to figure out how to make all the computers be in the same timezone
never used AD GPO before
I should prob lab it
i think it'll have to be a registry GPO
i got rid of ad at home
I had it for a very short time when I had no clue what I was doing
@clear igloo @waxen scroll I submitted feedback on a terribly written Juniper KB article a few month back and their documentation/KB team even reached out to schedule a call to discuss it. They butchered my diagram with one of their own, but other than that, much of my config example and descriptions are word for word.
Kinda neat seeing my wording in official vendor docs
Nice one, i for one appreciate a clear diagram.
They butchered it with a diagram done literally in paint, but a diagram is better than nothing. Especially in that KB topic
I often end up searching one of my old wikis and find the equivalent of a finger painting, still helps.
I mostly shocked that not only did they take my feedback, the even scheduled a call for additional input
what's the silver box?
I was about to contribute to the vyos docs, but I never got around to it and forgot everything
all I remember it was with BGP and v6
Was it with link-local peering we looked at a while back?
yeah I think so
thunderbolt 4 dock
ah, I don't I ever used thunderbolt
anything for the pristine audio quality 
not in the budget
So Iโm a bit of a audiophile and Iโm in some audiophile discord servers and 2 people swore that gold plated fibre optic cables sounded better because the gold I shit you not โmakes the light go fasterโ
for years, humans thought nothing can go faster the C (the speed of light)
but it seems gold plating helps
Ok, I'm watching the latest router install video and getting slightly triggered.. anyone from ltt around know if you all use a dcim/ipam? If not, I can't recommend netbox enough
the video has all sorts of wrong...
scroll up to see more about it
and knowing them, probably not
Idk about wrong.. maybe just not ideal. They're not a big shop
ehhh, they kinda are
bigger than the company I work at
and we have actual dual redundant firewall routers
not some jank pfsense
hey I loved pf back when it was mostly free, if fit in an empty price/performance slot nobody else did. But these days they think way too highly of themselves and the stability has gone to the gutter so yeah.
pfsense has a place, but not at this level
Id probably want to try vyos for them if licensing is an issue, but its been a few years since I've used it. You can't get better than arista imo but oh man $$$
nah at this point you want dedicated hardware
I like vyos, but it isn't fit here either
assuming they could even figure out cli
Why is it a bad fit?
lmao
Ah you said hardware. Yeah maybe, vpp/dpdk and all that has come a long way though.. id at least want to try it out to see if it could hang. Should be able to in theory but iI haven't seen much outside vmware really implement it well
you would want hardware built to specs, hardware acceleration, etc. Not just trying to push more CPU power, wasting money and time
So my router/modem (itโs both) supports WPA and WPA2 only
No other ones
Can I use a network extender or something to turn it from WPA/WPA2 to WEP or WEP/WPA (if WEP/WPA is a thing) or no?
@ me answer
I think so. Is the goal here connecting an older device?
Ive got an old tp link extender i use when i need to connect a Nintendo ds or ps vita to my network since they cant see my main connection
OMG YES, YOU DO UNDERSTAND
Does it work with turning wpa to wep?
Or wpa2 to wep?
Just plug it in and try
I donโt have one or know what model yours is?
I dont know how it works exactly, just know that it does. Gimme a sec and ill link you to what ive got
TP-Link AC750 WiFi Extender (RE220), Covers Up to 1200 Sq.ft and 20 Devices, Up to 750Mbps Dual Band WiFi Range Extender, WiFi Booster to Extend Range of WiFi Internet Connection https://a.co/d/cBWw2Tw
RE220 expands your existing Wi-Fi coverage with next generation 11AC Wi-Fi technology. It works with any standard Wi-Fi router and creates stronger dual band connections in hard-to-reach areas, allowing you to enjoy seamless wireless coverage throughout your home or office. RE220 provides APS (Ad...
Pretty sure this is the one i use. Its in a box somewhere rn but im 99% sure this is it
Do you still use it?
When i need to yea
In a box where?
Remembers my config most of the time, easy to setup when it doesn't.
Uhhh the storage room downstairs i think. Its a shared space and its wayyy to late to go down there making noise rn
I was looking for something in the $10 to $15 range
$20 at most
Depending on specs
The RE105 is 20 bucks. Cant vouch for it tho. The re220 i showed you is only listed at 22 right now, which is less then i paid
May pull mine back out, see if it helps the speeds on my xbox in the bedroom. Or i could just re run that Ethernet cable.....had to undo it bc i needed the cable run for more important stuff
Honestly need to just get a smart managed switch for my living room but ehhhh thats alot of work. My server and main pc dont like being on the same connection with a basic unmanaged switch
OG XBOX?
Sorry for caps
Would it work with like Wii or Wii U with the Ethernet adapter?
Series S. Not that far distance wise, but this apartment is very well soundproofed. So the modem being on the other side of the apartment makes the speed a bit slow in my bedroom
Oh xbox series s
I see
Donโt you have like a living room or something)
?
Like in the Big Bang theory
Yes, which has a windows machine that has gamepass ultimate, plus remote play to the bedroom xbox
Then you could just use Ethernet splitters or network switch
Cant use a basic switch with anything connected to my server.
Wait wasnโt there this one ds and Wii thing that you plug into your router with usb and you could use for wep?
Ahhh I see
Idk anything about that.
There used to be a Ethernet cable running across my apartment to the xbox, but when i moved stuff, i needed both of my long cables for the 2 machines in the living room (since my server doesnt play well with a regular switch i have on hand like i said)
Eventually ill take the $400 or whatever itll cost to properly setup my network and get better switches and off my comcast box and all that. But thats money i aint got rn
I ainโt rich enough for that
I still live with my parentsโฆ.
Imma just dm you something rq
@sly lark i was close. Ive got the same sku, but mine is re200. I don't really do dms sorry
Even more expensive
is anyone in here experienced with advanced networking that would be willing to help me
so i have 1200 down fiber i own an amplifi alien from ubiquity everything is cat 6 cable but i am getting no more then 400 down through the alien i have verified that xfinity is indeed giving me 1200 down by going directly through the modem with bridged mode off
It heavily depends on the client device also
Like iPhones / Apple devices are not known for the best WiFi performance
or do you mean wired?
hi im trying to get link aggregation working on a windows 10 boxs with a unifi usw-24-g1 but i cant get it working does annyone have a idea what it could be
So I am assuming the amplifi is a repeater/extender for your network, if not I will cover contingencies.
-
If you have a repeater and you are wanting to expand your network, you need to place the repeater in areas where Wi-Fi speeds have lost 1/2 of or 2/3. Find your dead zones and place the repeaters semi-close to your router or perhaps other repeaters.
-
If you are using a Wi-Fi device, you need to be so close to the router to pick up the speeds you are wanting. Like with repeaters, they will not send out 1200Mbps, they will send out whatever they can due to frequency location.
-
I am sure this isn't a matter but to give some info CAT6 cables travel up to 55m before performance of 10Gbps decays. CAT6A provides 100m of 10Gbps. Make sure your ethernet controllers support 1Gbps or 1Gbps speeds. Some Ethernet controllers ports do not support certain standards.
Make sure you do a speedtest, speedtest.net, to confirm that you are getting 1200 down.
So are you wanting Ethernet 4 and Ethernet 5 to be linked?
Just to make sure, do the ethernet connections come from different ISPs or no?
Yea same isp same switch
Why are you wanting to link them? You won't gain any performance nor speeds.
My nas is also connected to that switch with 10gb so wanted a bit faster transfer speed
Dont you need to setup LAG on the switch
When i just set it up in windows only it gives me a max of 1 gb not 2 gb trueputt
It doesn't increase bandwidth
A single connection will only get the max of a single link
If your ethernet controller only supports 1Gbps and your network throughput is 2, you will only get 1Gbps.
To make sure that your ethernet controller is 1 or 2, go to Device Manager, right click on your network adapter, click on properties, and then click on the Advanced Tab. In the Advanced tab, you should see a scrollable list called "Property:". From there, scroll down until you see Speed & Duplex, and make sure it is set to the highest value.
You should get to this point
i see but there are 2 cables in my pc and 2 adapters
Your network begins at the modem and router and from there you have two ethernet cables going to your computer. You will obtain the same speeds regardless of one or two because of the throughput being sent from the ISP directly hitting your modem and router. Typically if you have other hosts, you are cutting network performance down by a fraction depending on network usage.
They have a Nas on 10gig
jep and the speed of that doent go above 1 gb
Yes and it won't
i should get 2 gb to that
.
Is the NAS on the same network or on a different network?
the nas is connected to the same switch as the pc
What speeds are you supposed to get from your ISP?
1gb but im not trying to get more speed to the internet im trying to get more speed to my nas
You will need to get an Ethernet-to-USB-C/3.1 or .2 that supports 10Gbps.
Aggregation will load-balance traffic on a per-flow basis. This hashing means traffic with the same src./dst. MAC/IP will be sent over the same link.
In a LAG consisting of 2 - 1gbps link, a single stream (flow) will max out at 1gbps
Yessir!
You can bridge from the host computer to your NAS with a ethernet to USB-C or 3.1 or 3.2 Forget which revisions support more than 10Gbps
That would actually work if you can buy an adapter
okey if i understand it correctly than i am not able to get more than 1 gb of internal speed ???
Not from a single stream no
Huh, didn't know that even 2 connections it will still be 1gig
@dull pagoda Does your Network Switch support 10Gbps?
yes
Buy an Ethernet-to-USB-C or 3.2 adapter or buy a PCI network adapter that supports 10Gbps, and connect it to your network switch.
Depends on the hash. Enterprise vendors allow you to hash not just the MAC/IP but also port values. This is actually crucial to pay attention to as in some situations you would get wildly different utilization. Same goes for ECMP at L3
I see
cous this is my setup curently (yes i know paint)
do you know how to paint?
no lol
don't sell yourself short, i have seen worse paint diagrams with more important information.
lol
Yo, I recently built my first computer and have been having problems with my hdd not being found by windows but shoing up as fully functional in bios, anybody willing to help me?
did you format it?
cant
disk partitionar?
Do you have the Media Creation Tool or the iso?
for Windows
What is on your HDD?
as in size?
Do you have any files in your HDD?
No
https://www.youtube.com/watch?v=nbGkPYtXtmA
@grizzled forum Watch this video
0:00 Intro
0:10 Prepping the installer
1:39 Start the install via USB
In order to install Windows 10 on a PC via USB, follow these steps. Use a blank USB drive with a capacity of at least 8 gigabytes to host the files.
MORE HOW TO VIDEOS:
How To Install Windows 10
https://www.youtube.com/watch?v=6Fgm7gdIKA4
How To Upload Music To Spotify
http...
yea how much storage?
What sata mode is it in
Raid ? Ahci?
I cant find that but its a Seagate barracuda internal drive
@hardy python Thats the way i set up windows yes
If you haven't used it before, it should be ahci, I believe.
I was able to make it a vhd but that is not what it is and it basically stores files on my ssd when i do that
@vivid wind it's 3.81tb
On a Cisco catalyst switch, is it possible to have multiple VLANs on a single port (without bridging) so that a computer connected to that port can switch networks by changing its static IP?
I want to be able to;
Manually set the IP to 192.168.44.12 and be on VLAN 44
Manually set the IP to 192.168.20.12 and be on VLAN 20
Manually set the IP to 192.168.63.12 and be on VLAN 63
Just as an example
that's not how vlans work
I mean, technically you could have the switch detect the IP of the device and place it on the correct VLAN I guess
but I doubt that's a feature because it's pretty useless
Make a new vlan.. 1337. Physically wire ports from 44,20,63 into the new vlan 1337 port
Put the PC in vlan 1337
@clear igloo and there's your dinner
If anyone can help me with port forwarding that would be much appreciated.
I've been pulling my hair out for over a week and I don't know who I should talk to (ISP, Router Manufacturer, etc.).
I recently got a static IP from my ISP, which they SAID should allow me to port forward.
I've tried 2 different routers (Zyxel from my ISP, and Linksys) and configured them in much the same way.
I have made sure the ports are being listened to using the "NETSTAT -ano" command.
Network port testers say that the connection times out.
It'll make my day if anyone is at least able to figure out what is going wrong.
I hope they're firewalled with something other than windows
the alien is running my dhcp its from Ubiquiti
no repeater either its a direct connect from my modem the only thing i use the modem from xfinity for is to convert the signal from fiber to LAN
Nice
yeah
the uni has a fw blocking inbound
Xfinity doesn't have a 1200Mbps fiber plan that I'm aware of - are you sure you don't have regular cable internet? in any case, 400Mbps is pretty normal for wifi
@south crypt
there's probably nothing wrong with how you have it set up, you just might need to lower your expectations. I'm not sure which amplifi model you have but that sounds about right
speaking of Xfinity though... mid split hype
When I signed up for Xfinity when I moved last month, they promised me that theyโd magically update my coax 1200mbps plan to symmetrical gigabitโฆ I wonder if this is itโฆ
Oh I just read the full paragraph lol thatโs definitely what it is
i mean, i don't think they're supposed to be promising that like it's happening next week or something ๐ฌ
but yes that's the plan down the line
They guy said it was slated for my area in July but it was postponed a month
this is mid split - enables ~200Mbps upload
then in another couple years with docsis 4.0 you'll be able to get actual symmetric gigabit, in theory
that's all public information if you read ISP industry press outlets actually
just nobody seems to know to look there
but yeah the mid split upgrade is happening now with current docsis 3.1 tech
Anyways, speaking of Xfinity. Any plex gods around to help me out?
Setup my PMS at the new place. Port is forwarded on my Xfinity router for the device. Plex says it has full access to outside network.. but when I have someone stream remotely, it says itโs an indirect connection and forces them to 720p through Plex Relay. Any other settings I should be changing?
Iโve manually specified the same port
i don't know plex well but is it possible that something has to be configured on their end to make sure it's connecting directly?
From my remote user? No, that shouldnโt be the case
After changing nothing, it works
I love windows
I love Xfinity even more
The best
Where can I find the most up-to-date info? All I have is the word of the Xfinity rep and an article from two years ago of them starting trials
I consume VLANs now?
https://www.fiercetelecom.com/operators/comcast-focuses-mid-split-to-get-to-docsis-4-0-stalls-wireless-infra-plan decent overview
Comcast zeroed in on mid-splits as a key step on the path to next generation capabilities as it works to accelerate its transition to DOCSIS 4.0, CFO Michael Cavanagh rev | Comcast zeroed in on mid-splits as a key step on the path to next generation capabilities as it works to accelerate its transition to DOCSIS 4.0, CFO Michael Cavanagh revealed.
but yeah if a sales rep told you that symmetrical gigabit was coming in the next few months that was a straight up lie
unfortunately sales is ... sales and basically gets a free pass to lie as long as they meet their metrics
my advice is to call back and say that you were told this was happening soon, and you feel like the sales person was dishonest, and you're thinking about cancelling
they'll probably give you a retention discount or at the very least give you a specific timeline for mid split for your area
I fix that by buying fiber DIA
@clear igloo making an SSH scheduler algorithm today
API aint taking over yet folks
@clear igloo @waxen scroll
Email from customer that peers with us as well as Cogent (who we also peer with):
"We are having major connectivity issues with services reached through Cogent and we need this issue addressed and resolved."
Thats it. No dst./src. prefixes or IPs, no basic traceroutes, nothing. Sure, Ill get right on that...
I got you fam
I learned from ATT
Hello COSTumer. Please let us know when we can perform intrusive testing
<after testing> Hello dear COSTumer, the circuit cleared before testing. Have a nice day.
Simply "test" the circuit and say it looks good on your end
I wish NBN co in Australia didn't have their heads up their backsides on this. https://www.itnews.com.au/news/nbn-cos-100-40mbps-demise-is-accelerating-584149
oh yeah that's insane I've heard from AU friends that nbn is making all the wrong decisions for cost cutting reasons
They're actively making it worse because upload speed is a "business feature" and they might be able to make a tiny bit more by gating upload speeds behind wildly inflated pricing
NBN's 1000/400 plan for home users as promised something like 10 years ago is now $230/mo WHOLESALE with 142:1 contention
So it goes for ~$400/mo
I doubt prices are coming down to earth on that in the foreseeable future
On the bright side my gigabit router is going to last a very long time
meanwhile verizon, all symetrical
I would go Verizon
Or even att
But Comcast has me by the balls because they are the only ones offering decent net
it's either verizon or optimum (atlice) here
I'd kill for symmetrical
^
Perhaps not literally, but try me again after another two years of 50/20 with no real higher speed option
optimum is now rolling out fiber and it's symetrical as well
only thing that sucks is the equipment
My problem is only Comcast offered decent net, att only has like 16/4 and fios isn't offered in my area
oh and there is like nothing about ipv6 on optimum
verizon deployed it in my area like a week or 2 ago
that's what we're talking about - improving upload speeds to like 600/100 or 1200/200
and within a few years full duplex with docsis 4
the actual provisioned speeds for those are like 20-25% higher to make sure you get the advertised speed even in the event of degraded performance
I mean the way I see it it won't happen... Comcast has been pretty stubborn
Though I did hear we were going to see a bump in up speeds like mentioned above
i mean, they wouldn't be investing massive amounts of money in rolling out the network capacity for it if they were just going to decide not to ๐
it already is happening in some places
I tried changing my MAC address thru my router gateway. I experienced about 0.70 download speed on my PC and 10 download speed on my phone (Mbps). We usually get 100-400 depending on the device used. I changed my MAC address and restarted + reset my router. This still comes up. It's a netgear nighthawk rax43
changing MAC of router?
The MAC address yes
yeah... that may cause issues
Shiiiii I was watching a trusted video on it and that's what they said would change the IP
Well I have no way to tell, my router won't connect to the internet. I tried setting it up thru my nighthawk app and
โ
all cables connected
โno internet connection
Yeah, spectrum modem
2020 model i think
Is there any way to get the internet up and running? Our area has also seen some really bad speeds across multiple carriers and ISPs as of recently
this is what my phone gets with verizon
It could be an outage.. have you checked with spectrum?
no outages reported in any cities near me
hmm. Iโm not sure then
it was working beforehand -- just very slow and nearly unusable
