#networking

1 messages · Page 87 of 1

pseudo blade
#

RB951 can do QoS but is far too slow and old to be any good at it. The CPU in that has no chance at shaping well even if it didn't have 100 megabit interfaces only...

#

The RB951 is a router only. Not a modem. So if you have a modem it's something else.

noble frost
#

Tbh I have no idea how to use anything and till now we had internet from our neighbors so im not really good at networking and rn i just dont know what to get and if i should get a router or i also need a modem or if i should buy a modem router combo😭 Could you explain what u just said but for a guy thats dumb😂

pseudo blade
noble frost
opal pagoda
#

ah, a wisp

noble frost
#

MikroTik's hAP ax²
is this good?

pseudo blade
# noble frost MikroTik's hAP ax² is this good?

It's pretty good though if you're an absolute noob at networking why are you trying to implement QoS you may find it more complicated to configure than a basic offering from a consumer brand. Same OS as what your RB951 has though.

Also that thing on the roof? WiFi. Might be in a licensed band, might not be. But WiFi. Technically it has a modem but not one as you'd call it and nothing you wouldn't find in a common WiFi router except a big ol' antenna.

#

Range is worse than an AX^3 or IMO the older AC^2 but is nonetheless very workable for small to medium-sized homes.

noble frost
graceful birch
#

you know its shit when ur wifi is faster than ethernet with the extention cables I use

#

the ethernet gives me 80

stuck grove
#

wdym "extension cables"

jolly coral
#

rate my home setup

ornate jungle
flint sage
#

I hate my isp SOOO MUCH THAT I WISH THEY GO TO HELL

flint sage
pastel monolith
#

Have always had really good service here but am not far from major city, Xfinity was spottier than at&t has been but both not too terrible here

flint sage
pastel monolith
#

Forced to rent hardware or buy specific modem probably the worst of it but overall can't complain much here, what's the pain?

flint sage
pastel monolith
#

Ah nat pain

flint sage
#

yes ive tryed upnp dmz AND ALL THT I CAN THINK OF

flint sage
#

ah wait

#

i think they will charge extra

#

FOR NAT TYPE >B

#

my attempet at trying to trace spage_tti and sm questions

compact thistle
silent flax
silent flax
#

cause in that case you would need a personal pover plant i suspect

opal pagoda
silent flax
#

i am usually around 8-10kWh for my whole home (a Threadripper server, a 9950X+4080 Super desktop, fridge, other minor electronics etc). So on daily level you are probably at my rate, except you got solar panels to offset part of it

opal pagoda
silent flax
#

sometimes it is 9, sometimes 11kWh per day

opal pagoda
opal pagoda
#

But shelly 3pm is also decent and i have installed it in the server room

twin pier
#

clamp meters?

clear igloo
#

Yup

twin pier
#

actually that makes me curious whether its just measuring the apparent power or if it actually corrects for real power

clear igloo
#

My setup with Empira Vue clamps

twin pier
clear igloo
#

I believe most just do real power

#

They sense the current and do some calculations

opal pagoda
clear igloo
#

but my understanding is SUPER basic so I could 100% be wrong

opal pagoda
#

As it has hookups for voltage measurements of all 3 phases

twin pier
#

That's good

#

maybe I need something like this

opal pagoda
#

Data exposed to home assistant

twin pier
#

That's beautiful

#

Did you install this diy or can you pay an electrician to do it

opal pagoda
opal pagoda
ocean tulip
silent flax
frosty stone
clear igloo
silent flax
frosty stone
#

That's a very normal looking panel

#

Though I can't tell which one the main switch is from either photo

#

Bad design

frosty stone
#

That isn't a main switch

#

That's an RCD

silent flax
#

but the black one is the main 3-phase power cut switch inside the house

frosty stone
#

The fuck kinda design is that

silent flax
#

you can see how 3 phases come in (black, brown, grey), plus grounding (yellow/green). The blue is neutral

frosty stone
#

All this black wiring after the main switches... Please shoot whoever did this. Imagine having to trace which is which because they didn't colour them

opal pagoda
tough tinsel
#

Planning on setting up a voip service for my parents hmmm they want three phones line and its a headache with our isp because we have to use two modems. Now for the question. I'm planning to follow the network chuck tutorial. But is there any other resources you all recommended looking into before I attempt this?

silent flax
#

i was trying to solve weird internet issues all day, and in the end it was the main china switchs power adapter acting weird - if the extension cord it is plugged in was plugged in certain angles, the power would cut out, switch reboots, powers on, transmits few packets, reboots 😄

ornate jungle
# tough tinsel Planning on setting up a voip service for my parents <:hmmm:1001689590228332554>...
silent flax
# opal pagoda the 10g/2.5g one?

yes. but it is not an adapter issue itself. It's just that when the plug is upside down, it doesn't have good connection it seems. But the space is very tight at that location where the switch & cable modem is

#

it is plugged in a power splitter like this

#

and it seems in certain angles the plug just "disconnects" from power it seems

#

but hopefully i "fixed it"

pseudo blade
#

I don't know if I'd bother with an SBC, though I have set one up before to make some used Yealinks we bought work at an old workplace

#

Most of us preferred the mobile+web apps over the physical handsets anyways

bold stump
#

does anyone PLEASE know how to get this POS unstuck

#

should I circumcise it a bit

amber urchin
#

The fiber gets disconnected then the lever can open to release the transeiver. Be very careful of exposed fiber ends. If this is your internet connection, it's not likely to work by simply plugging into the switch.

opal pagoda
#

then you can press on the blue lever and pull the fiber out
after fiber is out you can pull the red lever and take out sfp module

bold stump
#

I did unfortanatly try it and there is not enough space it seams, and its hard plastic so it deforms very little, trying to get both things under this level just ends up leaving lever in the middle again

#

Pulling them out at this point also does not work unforatantly

opal pagoda
#

this is proper orientation of the levers

bold stump
#

I owe you one

thick mirage
#

Ok now for the stupidest question ever. Soo other than Cloudflare tunnels what super secure way is there to expose things like Nextcloud to the internet. I’m behind a double/tripple NAT. A VPS is definitely an option also.

ornate jungle
thick mirage
ornate jungle
amber urchin
#

I'll be looking into Headscale myself.

#

@thick mirage You do know that it's real and not a joke right? "Headscale is an open source, self-hosted implementation of the Tailscale control server."
https://headscale.net/stable/

An open source, self-hosted implementation of the Tailscale control server.

thick mirage
#

I’m paying for the transporting and simplicity for now. I eventually plan on locking up a few nodes in different locations and setting them up as hipaa compliant.

#

It’s gonna be hell my setup I already know

#

😆

opal pagoda
#

but i havent tried it, i use tailscale when i need it

thick mirage
opal pagoda
thick mirage
#

Tailscale is my gut feeling for now

opal pagoda
south blade
#

Hey, I'm trying to make my network use AdGuard Home, but on my Spectrum box it wants a primary and secondary DNS, which can't be the same, what do?

mystic latch
south blade
#

Something isn't working, PC set to automatic DHCP, even tried ipconfig /renew seems to just do 192.168.1.1 as my DNS

#

I don't see a place to check what the phone is grabbing for DNS, but using WiFiMan and doing a speedtest shows an IPv6 address, the AdGuard home address, and quad9 DNS. I don't see anywhere on the Spectrum router to put any other DNS servers so don't know where the phone is getting that IPv6 DNS.

#

Actually it looks like my desktop is grabbing the same IPv6 address for DNS too -_-

pseudo blade
#

If you can't configure it, it may be time to look into bridge mode and another router/buying a suitably capable cable modem and router if necessary.

#

Unless you want to play with hacking the firmware to get sufficient access to make changes, but please make sure you actually own the device before doing something you might regret...

#

I understand that owning the router isn't an "always" thing in the US

#

Telstra here's kinda new to expecting to get them back if you cancel before two years but that's not the same as renting it forever

south blade
# pseudo blade I understand that owning the router isn't an "always" thing in the US

Yep don't own the router, in fact I don't think I was supposed to get this router I have now as I think it's their "business" one with 1WAN/4 LAN ports and I was supposed to get one with just 2, so might be switching it or getting rid of it completely once the 2 years are up...and this is fiber, so don't think I'm getting my own fiber modem. 😛

pseudo blade
#

But it's on the harder end and bridge mode is often fine

fringe void
#

All my Ubiquiti stuff came today

unborn sluice
fringe void
native seal
#

me and my son have a new switch

native seal
#

time to spent 4 hours terminating rj45's and cable managing lol

native seal
#

one of the terminals of all time

#

u bin compuper
I put in my rack

#

might get a track pad for this
if not at least glue a trackball onto it lmao

opal pagoda
pseudo blade
opal pagoda
#

most senior members of server team do not understand change managment and just shuts down one of our most critical VM's DANger

pseudo blade
#

An old boss of mine was adamant that nobody needs more than 100mbps to their desk. It was very inconvenient hooking up the steam pipes out to the boiler to run said Catalyst 2950 though.

#

Hello what's this

pseudo blade
#

Looks like ISE allows exactly two

opal pagoda
pseudo blade
#

Oh that's very fun

opal pagoda
#

later that day he shuts down all ise nodes on other sites too, one by one

pseudo blade
#

OK, in future dude does not get direct access to one of them and must ask a coworker

Or if he's got a taste for doing it maybe finding other employment

pseudo blade
#

Mmmmm identity services

opal pagoda
#

and today CIO has done this

pseudo blade
#

NGL I kinda hate change management sometimes (some of the companies I work with can turn single endpoint software upgrades into multi-week endeavours) but then I am reminded that people like this exist

#

Tbh having the policy alone won't stop them but that's another problem

opal pagoda
pseudo blade
#

Had one raise a case on our software last year and when we proposed a tool upgrade or troubleshooting we got a "Nope, it's November. Not until January end"

Ok case closed then lol, raise one when you're actually ready for help

#

Some companies take it very seriously

opal pagoda
native seal
#

right so I've a problem

router is configured as far as I can tell, I can ping local and I can ping cloudflare, and Vlans and trunk is cofigured
switch is configured and ports are assigned

but I don't get Internet out the switch

i imagine it's smth dumb I've overlooked but idk what it is

pseudo blade
#

Of course we notice things that are bad practice

native seal
#

yeah ik it's just a temp patch so my pc is running off the ISP router while i set up the rack, that cable will be replaced ASAP

#

the 3650 switch i've under my new one does get connection to the internet so i'd assume i've misconfigured the new switch but idk what i've done differently i'm almost certain i've done them the same

pseudo blade
#

Did you wipe the old config it had?

native seal
#

ye i fac reset the "new one" where idk how it was set up by it's last users

native seal
#

i know what i diiiiiiiiiid
the IP for the 2nd router changed so set to static and have to change the default gateway in the switch for each vlan

#

nope still borked no clue lmao

#

got it working but idk how lmao

whatever

just re-did the entire process i prolly did a typo

molten cairn
#

hey guys
Can anyone advise what to use to implement a utility to search for the nearest access points and output some minimal amount of information like SSID BSSID protocol, in C
Preferably without third-party libraries
I've already tried using net sockets, but nothing worked, and in general there is almost no information about them

opal pagoda
pastel monolith
#

Sockets are typically used as means of piping data from one system to another after a link is established so I think maybe not needed if only care about scanning for ssids

#

Broadly a socket is a IP/port pair and buffer for data being sent through a given connection

pseudo blade
nova glacier
random stream
#

can anyone help me choose a poe switch

ornate jungle
# random stream can anyone help me choose a poe switch

You need to share more information about what you're trying to power and any other needs for us to make an effective recommendation. Share make / models of the equipment you're going to connect to this PoE switch, where it's being mounted / setup, and the rest of your existing networking setup.

random stream
random stream
#

thanks, but is it made of gold lol? Way out of my price range. also i dont neet that much speed, 1 gb would be fine

ornate jungle
# random stream thanks, but is it made of gold lol? Way out of my price range. also i dont neet ...

Price was not included in your original request... Anywho, in that case, I would just re-order the TP-Link one you likely bought, but this time ensure you receive the correct model.
https://www.amazon.com/TP-Link-Compliant-Shielded-Optimization-TL-SG1005P/dp/B076HZFY3F

#

If you're okay buying off-brand / no-name / generic networking hardware (I wouldn't be, but you do you) then something like this could work... but you get what you pay for so up to you.
https://www.amazon.com/Ethernet-Function-Managed-Fanless-Desktop/dp/B099PKV69M/

random stream
# ornate jungle Price was not included in your original request... Anywho, in that case, I would...

Thanks. I also thought of buying the tplink again, but idk if I want to risk it. I am buying from germany and I dont live there... Is maybe this from ugreen fine? https://www.amazon.de/-/en/gp/product/B0DXV9Y4B8/ref=ewc_pr_img_1?smid=AXZ3JQ1GVFPIF&psc=1 ?

ornate jungle
random stream
ornate jungle
#

Then give it a go. Worst case, you return it in 30 days, claim warranty on it, or you're only out less than $50 USD. (I understand that may be a lot of money, but also... it's very cheap in network switch land.)

random stream
#

Also a question about poe. If I connect like this: Deco x50 poe as main router --- poe switch --- normal switch on other floor --- other deco. WIll that other deco still be powered by its own supply since there is normal switch between?

ornate jungle
random stream
frosty stone
twin pier
#

ubiquiti switches arent made of gold, they're made of aluminum, that's why they're so cheap

frosty stone
#

And other ones are cheaper because... Plastic, and less effort

ancient arch
#

Maybe they want unmanaged switch. Or have only checked unmanaged switches till now.

topaz patrol
twin pier
topaz patrol
#

$200USD on a network switch can be a lot to many people

grave elbow
waxen scroll
#

I had to go through at least 8 of them in the last few years

#

I had one tell us no more datacenter wiring work until weekends, when our cable vendor doesnt work

waxen scroll
# pseudo blade Some companies take it very seriously

I only work for places that end up taking it seriously. Those EOY freezes are so that they can guarantee no impact while accounting does their closeouts. For companies with the public as customers, it ensures no impact during the height of spending patterns

#

Unfortunately most companies tech stacks are not flexible to downtimes. Newer companies can get around it by not using poor practices for their apps

#

The app that makes us the most money has a long and complicated procedure to drain it of traffic and put the traffic elsewhere, so we cant just upgrade the A-side switches during the day because it will blow up their app

#

At best its 4hr of work

pseudo blade
#

Tbh if the process to drain nodes is that slow, maybe those systems need to be improved

waxen scroll
#

not gonna disagree but the costs are in the millions to rewrite apps with modern practices and many of the components are 3rd party

pseudo blade
#

Yeah unfortunately I am familiar with several banks' internal infra at this point

waxen scroll
#

< bank

#

le sigh

pseudo blade
#

They have a distinct smell to them

#

:P

#

Usually an IBM one

#

For your sake I hope yours isn't a big AIX user

waxen scroll
#

IBM, HP, AIX

pseudo blade
#

I'm sorry for your loss

waxen scroll
#

and on and on

#

the mainframes cant even fail to other DCs, I guess thats not a thing

#

you have to basically do a DR plan

pseudo blade
#

The mainframes are supposed to be HA in of themselves usually

#

But yeah multisite... no

frosty stone
#

I guess today we get a reminder that the world's important stuff is built on shit and it's a miracle it even works

waxen scroll
#

I asked them if I can do a highly impactful maintenance to their stuff and they laughed at me. Actually laughed.

pseudo blade
#

I loathe supporting the AIX stuff

waxen scroll
#

New ticket: AIX timeouts

pseudo blade
#

For all the talk of high uptimes the platforms have often not seen the slightest of love in over a decade

#

They also freak out over nothing and IBM are a pain about getting toolchains for the older stuff people insist on not upgrading

waxen scroll
frosty stone
#

Sneeze wrong and the world burns

pseudo blade
#

It's enough of an ordeal just to get customers to install the stuff to make C++ compiled applications work

waxen scroll
#

It probably got better for new companies doing 100% cloud but now with vibe code coming I think computing is about to go to hell in a few years

pseudo blade
#

Tbh I have mixed opinions about the average competence of software engineers to begin with

waxen scroll
#

true, we kind of think "big tech" when speaking of them but thats not the average

pseudo blade
#

I am including big tech in that

#

Big bucks != big brains

waxen scroll
#

well, they all study leetcode instead of being productive and get chosen in the interview

#

I know someone IRL who works for meta and he was telling me he turned down a candidate for using AI during the interview

#

I was like, bro.... you make AI there

#

why are you making AI and then banning its use? dumb? lol

pseudo blade
#

Tbh if I was hiring engineers I'd like them to be able to use their own brains in the interview even if they did use AI in the job

#

Doing the job competently requires a decent understanding to begin with

#

Also every time I hear someone tell me about the output of copilot or any other LLM as an authoritative source I die a bit more inside

#

If you're stuck it's a fantastic rubber duck and it can sometimes generate glue code pretty well

waxen scroll
#

I dont really use AI myself. Dont even have a GPT sub or copilot. I know if I get used to using it my brain is going to rot.

#

But sure, stuck on a code problem for 15-30min, go for it

#

I have not really been making small one function scripts lately. I am doing complex ones so I cant even tell AI to build anything. It's all glued over multiple attempts if I did. v_v

pseudo blade
#

Yeah it's not proven competent at that in my experience

waxen scroll
#

I saw a demo at cisco live where they showed GPT in vscode and even when it builds smaller functions there can be all sorts of problems that you wont see if you arent good at code

#

one of the big ones was just plain security

pastel monolith
#

Lots of developers introduce security issues as well, not saying chatgpt is as good or better than all but always good to measure against current solutions (people) rather than compare with perfection too. I've been using LLMs since they became available for use and used lots of them so see the pluses and minuses to different models and where they fall short or what they can be good at with enough direction/prompting and guiding them on the rails

#

Helping a buddy at work who is wanting to separate out the colored parts of 3d model files from the "main body" that isn't painted to reduce waste from multi-color prints (effectively if can print the multicolor bit standalone and other part as a solid then glue together for little toys or whatever he wants to be able to print but not waste a ton of plastic).

Long long story short I now know way more about 3mf file format than ever really cared to know but also got chatgpt to slap together a script to convert the color data from the 3mf files into PLY files that I can import/use in Blender... ideally I'm going to just have the script split the 3mf file based on colored parts or not but am unsure if the print apps will deal with "non manifold" mesh in the 3mf or if I'll need to like manually boolean parts with boxes in order to maintain the "manifold shape". That last part kind of things ChatGPT or other LLMs really going to struggle with since is 3d spatial problem but up till that part is useful to have to bang out scripts: https://github.com/shusain/convert-bambu-3mf-to-ply/blob/main/convert_3mf_to_ply.py

GitHub

Contribute to shusain/convert-bambu-3mf-to-ply development by creating an account on GitHub.

#

Effectively if you already know something is possible with a given tech stack/libraries etc then can be useful to short cut to trying solutions but do need to know how to debug a bit and explain direction overall or else can end up wasting time relaying the wrong info to an LLM to try and get something corrected etc. still requires thinking just doesn't require so much manual looking up every method.

#

Also a blender add-on for importing/exporting 3mf files exists but isn't really maintained and has some bugs with working with bambulabs generated 3mf files, for my purposes here is sort of moot but was easier to just have chatgpt make standalone scripts that I can debug than go fiddling with the 50 forks from this addon to figure out what they tried to fix or which one will work

#

Semi-recently for work I had chatgpt throw together a script that would generate bulk inserts for a DB using JavaFaker and some custom bits to generate that data for the fields to be "valid enough" for doing some load testing against things, stuff like that is perfect use case for it, easy to check the result and non-critical path really but just need a utility to do a one off thing

#

would have probably been a few days if I were to have manually written the script vs like an hr working with LLM to get it done

#

I spent some time after documenting usage and how to check the actual performance (more time to focus on validation steps and explaining why the results are what they are etc. there's always more to do).

#

To bring it back to networking I think embodiment (putting AI into a body) is an important piece to understanding the physical world and being able to train with real world constraints/physics and outside forces etc. but is surprising how capable LLMs are given they are just living in the world of text salad

#

and as is still need bodies for moving wires around and whatnot 😄 think networking like plumbing or electric still has some future for people even once we have semi functional humanoids, long term maybe they can do all the jerbs too but at least in the near future there's still at least a few major challenges to overcome

#

"digital twins" or simulating reality with things like unreal engine are proving to be a great way to train models meant to operate in physical space but the simulations aren't perfect and always need to leave wiggle room for mapping things to reality.

stiff steeple
#

within the openvpn configuration tools in ubuntu, how do i ensure that only traffic to 192.168.111.* flows down the VPN tunnel?

pastel monolith
#

@stiff steeple you may want to try in #linux too and just include some details about the networking tools and config you're using as is and/or screenshots (just fuzz WAN IPs if concerned LAN IPs barely matter, if someone is on your network that ship has sailed)

#

I personally don't think WAN IPs matter either since sent as source/response location for all packets leaving your network, just paranoid about keys

stiff steeple
#

i tried this before, and didn't remember it having an effect.

pastel monolith
#

ah cool well good to hear is easy fix

stiff steeple
#

i guess i didn't cycle the network connection then.

waxen scroll
#

@rocky badge pepoJuice

#

@pseudo blade ^

lofty hawk
#

Hi, I am sharing my current Network Diagram, Routers working in extended mode.
I just have two requirements.

  1. I want all the devices connected in Router 1 and Router 2 should not be able to access the NAS and Local Host IP for the ER605 Login Page
  2. IOT Devices connected in Router 2 cannot access anything else like AP Isolation.
lofty hawk
stiff steeple
#

i don't think you can do that.

#

an unmanaged switch can't do VLANs. that's kind of the whole deal of a managed switch

#

so if you want to restrict traffic from router 2, it'd have to be plugged directly into the omada router. (or, change to an omada-managed switch).'

#

i assume they're just acting as access points, and leaving DHCP allocation to omada?

#

with regard to actually restricting traffic between vlans, let me know when you figure it out. i'm in the same boat, but not working on it very hard. I know it's possible, but i'm lazy.'

lofty hawk
stiff steeple
#

use an omada switch

#

and control them both with omada SDN

#

replace your AP's while you're at it

#

if you leave your linux PC on 24/7, you can host the omada controller in a docker

pseudo blade
#

You could of course directly connect the second AP to the ER605 and give it its own subnetwork

#

Neither of the routers route in that scenario because frankly they likely do not offer useful firewalling functionality anyways and the ER605 is likely much more capable. If the cable to the switch is long however and you can't cable to the AP... well not being able to segment traffic makes stuff hard doesn't it!

thin hedge
lofty hawk
# pseudo blade Neither of the routers route in that scenario because frankly they likely do not...

@stiff steeple & @pseudo blade Now I was thinking of using both the routers as extenders of Single VLAN from ER605 Subnet and use MAC filter to stop anyone else acessing my Network.

The reason I wanted to stop others accessing my network is that WIFI is less secure than LAN.

What if I get my routers get compromised? Now I though if my wireless router gets compromised they might be able to reroute my traffic as per thier wish.

So I am trying to secure my network first. It is a time taking process to get MAC of 25-30 devices add one by one. I would simply let go of IOT (mostly cheap chinese chips inside). Update that into MAC filter of ER605. So any even if any new device gets connected they my wifi their packets drop.

clear igloo
#

If someone is on your WiFi and you're hosting servers locally unsecured or browsing in HTTP and not HTTPS then sure, there's issues

lofty hawk
clear igloo
#

ARP has nothing to do with MAC spoofing, I can sniff your WiFi traffic and clone a MAC address in a snap

#

Sure a MAC filter might slow someone down for a minute but honestly it's more hassle than it's worth

lone crane
#

just do WPA3 and if someone is able to read that data then O BOY

lofty hawk
lone crane
#

just get a dedicated AP and do a VLAN for it

lofty hawk
clear igloo
#

Seriously, unless you're some high value target nobody is hacking your wifi network and stealing traffic to get login credentials

#

Unless you have a wifi password of "password" or similar, nobody cares

lone crane
clear igloo
lone crane
#

o yea true

lofty hawk
lofty hawk
lofty hawk
clear igloo
#

Well yah, just having VLANs and a single router isn't going to stop access

#

You need to apply firewall rules or ACLs to block traffic from traversing the VLANs

lofty hawk
#

If you guys can come into vc and explain a bit, typing is time consuming and cant type the entire problems

#

Well No Vc's here

lofty hawk
lofty hawk
lofty hawk
lofty hawk
#

Hello Everyone I want a simple gui tool where i can see what devices are connected to my network and manage them. Can someone guide me? I a newbie to networking so please highlight simple tools which i can maybe directly use on my linux pc or host on a linux server with a webgui to monitor. I have tried installing Wireshark on my Ubuntu 24,04, it is quite complex UI to understand something simple if you can please?

opal pagoda
lofty hawk
opal pagoda
lofty hawk
opal pagoda
#

cloud controller is 9.99 per device per year for basic license and 49.99 for advanced

lofty hawk
#

i dont want to pay them, what about self hosted tools and snmp?

lofty hawk
lofty hawk
lofty hawk
# opal pagoda

they reroute me to India server where these files are not there.

opal pagoda
#

google it, look for yt vids

vagrant nimbus
#

Just sign into your router lol

regal cloud
#

what are some nice but also cheap (not much more than 70€) access points, preferably with poe, and a decent enough range, doesnt matter if theyre used

#

also plus points if they pair well with home assistant

pastel monolith
#

@lofty hawk etherape is an alright if dated GUI for getting quick info about traffic being seen by a given client on the network https://etherape.sourceforge.io/ wireshark is really a great tool for getting deep on individual packets but you do need to filter by protocol or source IP or something or else it just looks like noise

#

ntop is another networking tool that can be installed on whatever distro and gives graphical/web interface similar to what omada looks like to me at least on the surface but you would still need to "mitm" have this wired inline somewhere to be able to really capture all traffic unless are only concerned with traffic from the client machine you're running it on

#

typically like @vagrant nimbus said there too though your router config will usually be easy way to get device list and overall stats and segment network for IoT things etc. if need tighter control than your router offers maybe worth looking at different router... you can run ddwrt or have your own DHCP server or whatever but just depends on how deep you want/need to get on that

lofty hawk
pastel monolith
#

yea etherape is easy/tiny install and app doesn't do much but gives you high level idea of what is talking with what graphically which can be helpful for local stuff, ntop bigger to setup has a DB to track stats over time and all for the web interface

carmine matrix
#

Finally finished racking everything up for my home lab. Just need cables. So far I love how it turned out.

topaz patrol
pseudo blade
topaz patrol
silent flax
#

stuff like this

carmine matrix
pseudo blade
# topaz patrol If you were really desperate you could chuck it in a docker container on a Mac

That's a Linux VM that runs docker like that, virtualisation doesn't count
Also if I were in a situation where my only option to run Linux software is in a VM (container or no) I'm going to have to pinch myself until I wake up (In reality it's probably a doctors office and I'm probably going to tell them to buy one of their controller appliances instead (god knows they can likely afford it))

#

I could even put an Apple sticker on it so they don't get too scared

ionic grove
#

Weird, I would think an Apple would be the last thing a doctor's office would want around

pseudo blade
#

I see a lot of it, including a couple using some medical record application built on top of 4DSoftware's RAD/database application - indeed running on a dedicated Mac server

#

It's that, Intrahealth Profile (which I've also had the pleasure of administering and saw the worst of), or the niche EMR shit I've apparently long forgotten

opal pagoda
silent flax
opal pagoda
#

that looks suspiciously like install without patch pannels

ionic grove
silent flax
ionic grove
silent flax
#

so you can do

pseudo blade
silent flax
#

yeah, all i said i miss these from his rack 🙂

molten cairn
#

Hey guys, pretty easy questions, however with almost no normal answers, can libcap catch packets at the network card level before they are processed by the kernel?

opal pagoda
opal pagoda
ionic grove
opal pagoda
#

both

#

with a dash of no budget

#

i havent heard a single soul who enjoyed healthcare IT

hidden obsidian
#

Big facts lol

#

From all of my friends that've worked IT for healthcare (hospitals & clinics) its been rough. Lack of budget and time to do neccesary downtime for upgrades and patches, its part of why there are systems still running Windows XP (closed off from the internet of course)

carmine matrix
# silent flax so you can do

But why if I have patch panels. This rack isn’t going to go to any ports in the house it’s just a little home lab

carmine matrix
#

I’m in financial institution IT and it’s been good

peak cloak
#

Many production machines are running 95

#

There's little to no benefit upgrading

opal pagoda
peak cloak
hidden obsidian
#

Makes me glad that I work in the service provider space. We get all the fun toys to mess with lol

ionic grove
#

What about university/college IT?

opal pagoda
rocky badge
waxen scroll
worn gate
#

Hey all,

I am currently attending college and am looking at setting up a mini lab.

The way my college's network is setup is that to connect a device to the network I need to give a MAC address and I can only have 5 devices connected at a time.

I was wondering for wired devices anyway, i believe I could just connect a switch, give my college the MAC address of the port I connect on the switch, and I should be able to connect as many devices as I want wired.

I plan on mainly just having my PC and a NAS on the network with potentially a mini pc on the network running proxmox or something of the like.

I would like all my devices to have statically assigned network addresses and for them to communicate out to the internet (at least my pc). I am assuming the way I should go about this is setting up ACLs to direct any traffic on my "internal" network (ex. 193.167.x.x) to ports I choose and the rest of traffic to the outside network?

amber urchin
worn gate
#

I'm trying to avoid using a router and would only have a switch

#

I don't have the switch but I believe it to be either a 3560 or 3960

amber urchin
#

As long as you know that you'd still be giving the 5 MAC addresses of the clients you connect to the switch.

#

Also - 193.167 is public address space. Did you mean 192.168?

nova glacier
amber urchin
#

Honestly, if the point is to learn and to have fun, a VM with opnsense or heck the mini PC being the opnsense router is fun.

worn gate
amber urchin
#

I made one in a VM for an experiment that was pretty fun.

nova glacier
#

If you aren't ready to be using nftables, I agree with ice to just setup a router VM on the proxmox machine. Just have two network adapters so one can be the "WAN" that you connect to the college network and the other goes to your switch

worn gate
amber urchin
#

You could also run a local network that isn't connected to their infra at all. You are not limited to just one network card on a machine. My playtoy and desktop both have 25 gig cards that are directly connected to eachother with a direct attach copper cable.

#

Although then you have no updates and such so that part is a bummer and where the router would come in handy.

worn gate
#

And also was my original plan, but i'm getting an old 48 port switch through work

amber urchin
#

Do you really need that many ports?

worn gate
#

No, but it's free

amber urchin
#

Also - I'd like to circle back to my previous mention of the mac addresses containing vendor IDs. If you go the router route - clone the MAC address of your PC to it or something so you aren't just giving them a MAC that they will know is Linksys or whatever.

#

Unless they're OK with that anyway

worn gate
amber urchin
#

Aren't new routers cheaper than that?

worn gate
#

I'm looking at 2911, which is what I have experience with in labs

nova glacier
#

but why buy an outdated potentially exploitable router when all you need is a NAT? Any linux distro using nftables can do a basic NAT. nftables isn't even 3rd party software, it's the networking system on linux. You could also use pfsense or opnsense if you'd rather have a GUI

amber urchin
#

I'm surprised, I figured there'd be like a $30 router without wifi but I'm not seeing anything of the sort.

nova glacier
#

I mean there is. It's called a raspberry pi 4

worn gate
worn gate
amber urchin
#

Yeah, I mean all you need is a single WAN and single LAN port since you already have a switch - although have you heard said switch actually powered on? Some enterprise switches sound like you're on airport tarmac

worn gate
worn gate
worn gate
amber urchin
#

Part of me wanted a 9300 Cisco so I could have my 25gig on the main network but it's not worth the noise.

worn gate
#

Gonna be honest, I was just gonna buy an unmanaged switch and have the Nas be on its own separate network, but then I was told we had an old switch that was getting recycled, i believe it's a 2960 unfortunately, but I won't say no as it saves $100

amber urchin
#

There was one for $175 with 48 1000base-t, 4 SFP28 25gig and 2 QSFP28 100gig. Such a deal

worn gate
#

Looking at mikrotik stuff kinda got me jealous, theres basically that same switch, but with 4 10g sfp+ ports and 2 4gb qsfp+ ports brand new for $600

amber urchin
#

Yeah they have some decent stuff. There was a 4 port I had interest in but like 300$

nova glacier
worn gate
#

From what I understand the cli is pretty shit, but it's pretty cheap

worn gate
pseudo blade
#

The Mikrotik one?

#

The CLI is fine, but don't ask about scripting

#

It's not an IOS clone, which is to many admins a great sin... but it's not like IOS's CLI isn't a quagmire anyways

worn gate
pseudo blade
# worn gate Or a regular hex for $60

I use one for my home network doing routing duties with an ISP router playing AP. The CPU simply isn't quite good enough for gigabit though and I'm maxed out at 900mbps with a bunch of features turned off

#

But for anything less or no nat it's alright, if a bit dated

worn gate
pseudo blade
#

I bought the hex to run my homelab for university in what I vaguely remember to be 2018 🤣

worn gate
#

And only one of those devices would ever regularly be communicating outside of the "internal" network

#

Worst case scenario, i do what I planned anyway and just not even connect my Nas to the internet at all and just have an overkill switch

pseudo blade
#

Ah there it is

nova glacier
#

I wonder if there's something for less money that would have a so much more RAM and CPU resources that it could actually do several other things at the same time as being a simple NAT router. Sorry, that's last comment clioaiClueless

peak cloak
#

I'm a fan of vyos

worn gate
#

Again, we will see, i might just be lazy and never connect the Nas to internet

pseudo blade
#

Tbh they are now like $100 due to our weakening dollar lol

nova glacier
pseudo blade
#

Mikrotik have the hap AC2 which is basically perfect for not much more - just turn WiFi off if you don't want it or remove the wireless package

worn gate
pseudo blade
worn gate
pseudo blade
#

AC2's also old but it's ARM and legitimately quad core vs 2 with 2 threads

#

Plus the WiFi antenna design on it's pretty good if you decided to not buy a WiFi router and disable the headline feature :P

#

It's only like $20 more than the hex

worn gate
pseudo blade
#

¯_(ツ)_/¯

#

Fair enough

worn gate
#

I was already accepting that kinda jank solution, but figured it would be worth seeing if I could use the switch to act as a router of sorts

pseudo blade
worn gate
#

I'm still gonna take the switch as it's free, and is managed compared to the one I was looking at

pseudo blade
#

If it has one, you can route on a stick off it

worn gate
pseudo blade
#

Take your switch, (take the top off and cool it directly with a larger fan) and trunk two VLANs to the hypervisor

amber urchin
#

Why not get some dumpster trash Dell and put a second network card in it?

worn gate
amber urchin
#

opnsense has quite low system requirements iirc

worn gate
nova glacier
#

most hypervisors main network method is a NAT

peak cloak
#

Pretty ingenious tbh

worn gate
nova glacier
#

the router gets the WAN port through one of the network interfaces attached to the VM host

peak cloak
#

Doesn't even need to be a vm

nova glacier
#

true, it could be dedicated

peak cloak
#

On any major router os you create a virtual interface (basically interface on a vlan) and then you can have it get a DHCP lease from upstream

#

And do all the nat and routing from lan which can be a separate virtual interface

worn gate
#

Would I still need to connect my incoming internet connection to the mini pc, needing a second Ethernet port

peak cloak
#

No

#

Just a switch that supports vlans

#

Your basically using the switch to extend that one physical interface into many

nova glacier
#

You'd be making that link effectively half duplex though. The NAT'd packets destined to/from the WAN would go back and forth.

worn gate
#

So I'd give the interface connected to the internet on my switch something like vlan 10, and any devices on my "internal" networking vlan 20, with a trunk link between my switch and proxmox machine allowing both vlans

peak cloak
#

Mine was capped to 300

worn gate
#

Sorry, i don't have much experience outside of classroom networking stuff

#

And especially any experience using virtualization stuff

peak cloak
#

I mean we were all there before, I self taught myself and I'm not even going into IT

worn gate
#

Looking at ways I can simulate this now

worldly garnet
#

Good morning, could someone please tell me how I can determine/calculate the best network speed and hardware needs for my wife and I to be able to edit 1080-1440p video off our NAS? Is there a site that's easily digestible to help with this?

We currently use HDDs with an old i9-9700k and 32gb ram (yes, my old gaming machine became our NAS/extra computer for LAN gaming) I'm not sure if 2.5gb is too little for two people to hit the NAS at the same time or if HDDs would struggle sending stuff to two people.

We wouldn't need to render simultaneously, just sometimes edit simultaneously.

Thanks for any help!

lone crane
#

i7

lone crane
#

1440p high bitrate i would imagine for 2 people can be done ezpz at 2.5 gig

#

but worst case that pc can do 100gig even without any major issues, but do not go for that as its HELLA spensive and only really worth it for NVME storage

worldly garnet
lone crane
#

intel is a bit annoying

#

many many numbers

worldly garnet
#

The NAS is overkill now, but my current editing rig's i9-9900, Motherboard, and RAM are gonna get upgraded soon. Not sure what I will do with them. 5-6yrs old stuff there.

THANKS AGAIN!

full storm
#

don't you love it when your ISP does some weird validation thing with their OEM routers and they also don't support bridge mode so you have to run a dual NAT setup

#

also a moment of silence for the people working at linksys that spent a while adding firmware utilities like backups and reverts in the troubleshooting tab and then decided to put the firmware upgrade section in the mf connectivity section KEKW

amber urchin
#

That is unless you're using proxies, you might be able to get away with that.

worldly garnet
pseudo blade
#

Go do some editing locally. Scrub around a bit. Have a look at the disk IO you see to the SSD (can use Task manager or Resource Monitor). Decide if the performance is adequate and if so... convert the bandwidth needed to megabits. Can also look at your source bitrates to get a hint about it too. Then decide if proxy editing is suitable and reduce the bandwidth estimate proportionally

haughty spruce
#

I tested my old router (TP-Link Archer C6 V2) vs new AP (Ubiquiti U7 Lite) in my apartment today and came to an interesting conclusion... Archer seems to be better in most cases (signal strength and 2.4GHz speeds).
I tested everything with the same laptop in NetSpot and the transmitters were both in the same place (Archer about a meter from the ground on a table and Ubiquiti on the ceiling) with an interval of about half an hour.

Could someone explain to me why the U7 Lite is a significant amount weaker in performance and why the 2.4GHz band is more than half as slow (download)? It seems to me that an AP from this year should at least be on par with an X-year-old router that has identical (or worse) specs on paper (both in terms of performance, standards and max speeds).

The only explanation I can think of is that the U7 Lite is focused mainly on the 5GHz band in which it beats Archer even with a weaker signal. But it seems to me that there is only a difference between WiFi 5 and 6.

Note: I also have U7 Pro XG that will be located in Living Room (I want 6GHz band for my Quest 3 that I play in there), so at the end, my signal will be good enough in all rooms. I am just courious why is the U7 Lite worse than the Archer 😄

pseudo blade
#

The absolute power received differences are actually much larger

#

Anyways... can highly depend based on how you have the AP positioned. UAPs are meant to be roof-mounted and the archers are not

#

Bandwidth also depends on channel configs and bandwidth - perhaps you are using a 40mhz channel on the Archer and a 20mhz channel on the UAP?

haughty spruce
haughty spruce
haughty spruce
pastel monolith
#

Pretty sure WiFi routers/APs will dynamically adjust power output to try and limit interference too but usually some ability to adjust the max transmission power (can depend on region/local RF laws)

full storm
#

my main router will not recognise my openwrt router but it did recognise it when it was running the linksys firmware...

#

won't do dhcp, won't allow static IP via MAC

opal pagoda
#

u7 lite:

haughty spruce
#

What I dont understand is why 2.5Ghz is so much slower on U7 Lite when it has much more output power

haughty spruce
#

Uploads from wifi device -> iperf3 server are +- fine, but downloads (AP transmits) are like 50-80% slower

opal pagoda
haughty hound
#

Let's see yer racks

full storm
#

meanwhile: my router thinks my phone is connected via Ethernet 😃 the weird part is that it gave my phone 2 names for the different APs running, different name for 2.4 GHz than for 5GHz and also 5GHz is some how connected via ethernet and also my 2.4GHz doesn't do IPv6 for whatever reason but it's not that deep ig kekwarpexplode

ancient path
#

so i just got a home and was told the Ethernet jacks were already ran through the house, i take it these are the cables for it?

lone crane
#

Yup

ancient path
#

Guess it’s time to get a cable tester and figure out this mess of cables and which jacks they go to.

full storm
#

probably not the most efficient way of doing it but it could work in a jiffy KEKW

#

hell you could even leave them all plugged into the switch and just label the ports on the switch

#

then your switch is labelled too, less effort solutions

#

also, unrelated; where does one buy ECC SODIMM DDR3 ram sticks for cheap kekwarpexplode

ornate jungle
ornate jungle
ancient path
weary marsh
#

why does technicolor make routers

#

anyways my one (dga0122) has a usb a port, don’t know what it is for but in the gateway it says something about keeping a log file in the usb but can you use it for network storage?

tight pecan
weary marsh
#

I don’t think it says anything about sharing the drive

tight pecan
#

It's pretty much supported by most of the aio router/ap boxes

#

Or check the user manual ig

vagrant nimbus
#

I’d fire an employee if I saw them leave that shit

frosty stone
#

It's the homeowner's responsibility to do something with the cables... But most homeowners don't have a damn clue, and are too cheap to hire anyone as long as their wifi works at all

ancient path
#

It’s a new home builder so it’s more on me for that stuff, but I plan on getting a patch panel to get it all sorted in the next week hopefully.

full storm
#

can i install pfsense in a proxmox vm

#

it should work right?

opal pagoda
full storm
high bronze
#

you can, but if you want high speeds (10g+) you'll need to do pci passthrough with a network card

full storm
#

well, i have a switch with 2 x 10GB SFP+ ports on it but i think i'll use those to connect to another switch if i need more ports, then again i don't think i'll be using 24 switch ports but who knows xD

#

managed switches are cool

opal pagoda
pseudo blade
#

A nine-gigabit half-duplex LAN-WAN?

#

Certainly unique

pseudo blade
#

Probably 8 and an OOB management port

full storm
#

that's what i thought at first too kekwarpexplode

#

or atleast it's not labelled as one, it's labelled as an actual ethernet port

#

and the bios doesn't mention anything about it being a management port but then again it does only show 4 ethernet ports in the bios so maybe actually idk

delicate yew
#

Yo anybody got suggestions for a new wifi mesh system
This shit is fucking garbage and I’m tired of it

#

I love when my super advanced technology that costs an arm a leg and half my kidney only lasts 3 years until it decides it wants to become ewaste

delicate yew
#

Aaaand it connected to a satellite that doesn’t even exist

delicate yew
#

🎊

full storm
#

unifi do some great wifi gear

#

lil bit expensive but sometimes you can find them on ebay for cheap

delicate yew
full storm
delicate yew
#

Imma find some YouTube videos on it

full storm
peak cloak
#

run ethernet if you can

delicate yew
#

Can’t
If I had it my way this entire house would have cat 6

#

But unfortunately when we remodeled the owners didn’t think about or didn’t want to

ornate jungle
# delicate yew Imma find some YouTube videos on it

If you're looking to dive into UniFi Network, but you don't know where to start, or you're confused about all of the different models of gateways, access points, and network switches available, this is the video for you!

Build your own!
UI Product Selector: https://uiproductselector.com

(or if that link doesn't work because it's a re-direct -...

▶ Play video
#

Also this, though some of these "basic" setup videos go way above and beyond what home users need. https://www.youtube.com/watch?v=vG2Lc_WM5JA

In this video I go through the full setup of UniFi Network application. The UniFi OS version I am running is 4.2.12 and the network application is 9.1.120. Im sure there were some things missed in this video as its is a lot to go through

Hire Me
https://mactelecomnetworks.com/

Ubiquiti affiliate link :
https://store.ui.com/us/en?a_ai...

▶ Play video
delicate yew
#

Awesome thanks!

ornate jungle
#

This doesn't mean you need to spend $10,000 for a network setup, especially at home, but expect to spend a few hundred if you want a capable system that will last. Also, prosumer setups from Ubiquiti or TP-Link should last at least 5 years, potentially up to 10 years, but that's only if you don't want or need the latest WiFi version.

delicate yew
#

Oh trust me
I’m done with cheap I’ve gone cheap all my life and have recently been putting in the extra effort for good stuff

clear igloo
#

Definitely need some service contracts and support with 4 hour on-site replacement

pseudo blade
kind pivot
#

Are there pcie cards that does wifi + 10GbE ethernet (at a human price) ?

If no, maybe with USB ?

I think I'll use my linux home server directly to make a wifi AP and since I also need (well, "want" more than "need" ) 10GbE ethernet ...

pseudo blade
#

That said, I think it's something that could be made at some expense...

#

With bifurcation you could just get a PCIe card with two A-key slots on it and then just use one for ethernet with an m.2 ethernet adapter

kind pivot
#

Yeah it would be cool, though I don't think it exists indeed

pseudo blade
#

You'd have to basically make it from parts like so

kind pivot
#

Probably a better idea to have one of them with an usb adapter and the other with pcie

pseudo blade
#

Tbh I've never particularly liked USB solutions for either but it'd work sure

#

If I had to pick one to be USB it'd be the ethernet. How exactly do you have a system lacking an ethernet port but with PCIe options?

#

Oh as a router?

#

Idk depends on which you care about most

#

Be aware that wifi cards typically will only do wireless on one band at a time and multiple are needed for multiple bands

#

Go ethernet. Buy an AP.

#

It's by far the best solution if you're building a router from a regular computer

silent flax
#

so now i see 8x2.5 + 2x10 SFP+ switches. Wondering what Realtek SKU this one uses. Also makes my purchase of 8+1 switch a year and half ago "questionable"

#

(i mean i could have 10G link now from my desktop to the server)

#

also just 50-ish euros

onyx bobcat
#

file transfer over network to my NAS 🤑

pseudo blade
#

Low-port 10 gig is getting cheaper

nocturne comet
#

Anyone wanna tell me how ancient this is?

#

So I can tell my grandparents they should upgrade

clear igloo
#

Why do they need to upgrade? If it works for them

silent flax
# nocturne comet So I can tell my grandparents they should upgrade

there are few reasons to upgrade, but none of that might apply:

  1. higher networking speeds - but if they have only let's say 100 mbit internet, then 802.11n is more than enough.
  2. security - many routers/APs are abandoned from security standpoint by their manufacturers, but i suspect that the belking thingy is just an AP, so whatever
silent flax
#

but again, an 802.11n router/AP could be all they need

nocturne comet
#

Speeds or like 30 Mega bits a second😭

nocturne comet
silent flax
nocturne comet
silent flax
#

well, that is between you and them. Tell them that you will foot the cost of the difference for example 🤷‍♂️

nocturne comet
silent flax
#

then just tell them you need faster internet for the school (figure out the reasons)

waxen scroll
full storm
#

stupid server won't POST i don't think, BMC light is blinking (it was sold with IPMI broken so i can't login to IPMI even though the web interface is online)

#

either way i have no VGA signal

full storm
#

just ordered a serial cable, comes tomorrow so i'll find out if it's giving a serial output

royal loom
#

Can anyone help me figure out if the switch's controller signals are
A) Bluetooth. I know that's how it communicates when used on PC but I'm not sure that's what it uses natively on the switch
B) Encrypted in a way I can't decrypt.
I'd like to see if I can sniff and then mimic the packets it sends to make my own controller from scratch

#

I figured someone in here might have both a switch pro controller and some way of intercepting/reading bluetooth signals

ornate jungle
royal loom
#

are you in reasonable driving distance of north carolina

ornate jungle
#

Nope. Opposite side of the continent.

full storm
royal loom
#

I have a switch 2, an HAC-001 switch I built myself, and a retail later generation switch

#

I haven't tested yet. I would likely need to buy equipment to do so (unless a conventional PC can test some of this) so I wanted to ask where to start poking

full storm
#

wait nintendo switch?

royal loom
#

Yes sorry lmao

full storm
ornate jungle
full storm
#

networking channel

#

i thought you meant network switch hahaha

royal loom
#

Yeah dude it's using network packets to convey input information!

#

Totally fair I should have included the nintendo word in the initial ask lol

full storm
#

for reference though they use BLE

royal loom
#

Sick, that's useful to know.

full storm
royal loom
#

whoa google a little off with the predictions there

full storm
#

LMAO

full storm
#

ESP8266 might work too

nova glacier
#

It's also fairly popular for devices to use BLE as a control plane for pairing, updates, config, etc only. While using a 2.4GHz proprietary protocol for the data plane

full storm
nova glacier
#

No you can't. That would just be standard BLE you could learn from the spec already. Anything proprietary would be done after pairing and encrypted

royal loom
#

That is what I'm hoping is possible

#

Do you think game controllers really encrypt their transmissions?

#

It's a use case where latency is KING and the information is extremely non-sensitive

full storm
#

its nintendo

nova glacier
full storm
#

they'd encrypt their name if they could

#

and sue you for thinking about it

royal loom
#

So essentially what I'm trying is a man in the middle attack to break the encryption, if that's even possible, right?

full storm
#

good luck, itd probs be like AES or something

#

you aint breaking that

royal loom
#

hm

full storm
#

you'd have more luck trying to find out where the key is

nova glacier
#

You'll want to try to jailbreak the wireless SoC (MT3689BCA) on the controller or the Switch 2 itself. That's the only way you'll be able to get at the data before it's encrypted

royal loom
#

would it be any easier to break if I knew both the original information and the encrypted version or does modern cryptography make that still very complicated

nova glacier
royal loom
#

I was literally thinking about enigma when I wrote that lol

#

Ok, so jailbreaking is specifically the process of getting root access to a device that one is otherwise not able to have, correct?

nova glacier
#

yes

royal loom
#

It's funny, I'm trying to hack a system where I own and control both endpoints and the signal and it's still going to be a nightmare

full storm
#

plus that other one that i'll refrain from saying here ain fear of being banned haha

royal loom
#

physical access to the device is supposed to be the biggest breach in security!!!!!

nova glacier
nova glacier
royal loom
#

aw shit yeah you right

nova glacier
#

might be part of why the controller's aren't backwards compatible. There are jailbroken switch 1's that nintendo can't brick (afaik) that would've been viable for reversing the new controllers

royal loom
#

Yeah the fusee gilee exploit let day 1 gen 1 switches have code injection before a hardware DRM fuse was checked

#

The nintendo switch 1 has micro fuses in it that the system purposefully burns out with major system updates. Then it checks how many fuses are blown to ensure it hasn't been downpatched, and totally shuts down if it has

#

The original hardware had an architecture fault that allowed "malicious" actors to pre-empt the checking of the fuse with code, which shouldn't be possible at all, to then spoof a number of burnt fuses, allowing them to mod and downpatch however they want while circumventing the fuse burnout tracking

#

downpatch and modify, obviously

royal loom
#

Ok so this project might be DOA. But there are third party controllers! Are they just licensed?

nova glacier
#

What if it just supports the bluetooth HID profile? You wouldn't be able to do anything proprietary that the joy-cons can do, but generic gamepads would be fine

pseudo blade
spice sage
#

hello..guys

lean bronze
#

Hey guys, I got a somewhat weird thing going on with an Edge-Core AS5712-54X (eUSB) switch. When I turn the switch on, all 10G ports are orange and the 40G ports are green. The serial port does not give any output on any logical baud rate. The fans are blowing at full speed, so I think the switch is stuck somewhere in its boot, but I cannot see where. I have tried creating a diag and a recovery USB, but booting with those in didn't change anything.
I tried the software from: https://support.edge-core.com/hc/en-us/sections/360005141233-AS5712-54X
What could I try next?

opal pagoda
#

On cisco i would say its stuck in romon, i have never used that brand switch

pseudo blade
pseudo blade
opal pagoda
flint sage
#

holy ping, HOLY PING, HOLY PINGGGGG

wet aspen
#

Rate the ap placement 🤣🤣🤣

lone crane
opal pagoda
silent flax
# wet aspen

so they are blasting signal into a metal floor, which reflects all of it ?

nova glacier
#

reflects all? At that distance it's gonna load the fuck out of the antenna and make it almost useless

ornate jungle
# wet aspen

Needs to be unbolted, spun around 180 degrees, then rebolted. That's how it was intended to be installed anyway - you can tell by the cable + carabiner being used to "earthquake proof" it.

frosty stone
#

It looks loose already

#

And base on the marking on the pole, it can easily be spun back around without touching any bolts

#

So spin it back around then get some rust converter for the pole

stuck grove
# wet aspen

Do they genuinely only make 1 kind of safety chain?

#

This is the only safety chain i have ever seen used in theatrical/performance settings

weary mirage
#

anyone know how to set up lancache to display on netdata the way jake had it in the most recent lancache LTT video?

wet aspen
wet aspen
stuck grove
topaz patrol
#

There aren't too many ways you can make a metal cable with loops on the ends

stuck grove
#

the weird bit isn't that they're super similar, it's that they're all identical

pastel monolith
#

if it ain't broke, plus probably is down to handful of places actually manufacturing em for everything

#

all paperclips look the same too 😛 I've literally seen my same pair of generic scissors on like 10 videos on Youtube too, once some place in China wins the race to the bottom on things think they become the "winner for life" in lots of cases

silent flax
tough crown
#

👍

flint sage
#

.

lone crane
#

I should have another go at it soon tho but not sure how much I even care really

sleek patio
# wet aspen

Took me a second me a second to process what I was looking at

#

Interesting to say the least

rocky sapphire
#

hey upppp writing in need of help 😄 having this issue for the first time , got ac gt 5300 I moved to a new house and im struggling with a signal very bad on the cable i have 999mbs on speedtest and on wifi i get from 40 -100 and up stairs 1 maybe 5 , is there anyone here that could link me up and sherlock with me whats going on :D?

peak cloak
#

You may need to run cable and have multiple access points

real spade
#

Random - but Cloudflare DNS is down in the UK if you're having network issues
First of it's kind AFAIK, I've never seen it go down before

rocky sapphire
#

yh i just found as well

nova glacier
#

down in US-East too

rocky sapphire
#

its hitting bad and i was wondering what is going on with my broadband for last 3 days

rocky sapphire
#

fuck i might have it on too

real spade
#

it is the 1.1.1.1

rocky sapphire
#

ffs -,-

real spade
#

Cloudflare status page is non the wiser, I dunno why they bother

rocky sapphire
#

and im fighting with my gt ac5300 for last 3 days -,- wondering wheres my speed

crisp nacelle
#

Anyone have a network adapter recommendation for MacBook with USBC? Like an Ethernet to USBC adapter?

stuck grove
#

any of them

#

doesn't really matter that much

nova glacier
cosmic steeple
#

I currently have 2.5 up and down fiber. I can affordably get 10. My backbone is currently my gt be980 pro. I want to start setting up with more redundant topology and set up my own rack that I’m looking to buy. First thing I want to do is get a core layer three switch as my backbone. Any recommendation.

#

I will be running cables and having a patch panel for ethernet. I am uncertain on the module that would be placed in a server rack as the modem that can replace my ISP little box.

#

I have home renovation budget.

pseudo blade
#

Also... Layer 3 switching hardware's utility is scenario-dependent. Can be fantastically efficient if you're willing to play by the switch chip's rules.

#

Kinda does nothing much for you if you want something that specific chip doesn't offer, and if the underlying CPU is poor expect miserable results.

#

Decide how many ports of each speed and type you need and answers become easier.

nova glacier
thorny osprey
#

how to fix dis ion understand nun

lone crane
#

just use ublock

#

no wait what is that

mystic mortar
#

hm I'm planning to install some outdoor solar cameras on a countryside home but I'm in a bit of a pickle as the camera will sit far away from wifi range (around 250m or 0,12miles AKA freedom units) and no access to electricity (main reason cameras gonna be solar) hm

I wanted to use smth linus used on a 4y old video (links below) but no electricity on the other end gonna be an issue HMMM so uhm HMMGE Any suggestions?

https://store.ui.com/us/en/category/60ghz-wireless-airfiber/products/af-60-lr
https://store.ui.com/us/en/products/uap-nanohd
https://store.ui.com/us/en/products/es-10xp

opal pagoda
mystic mortar
#

Notes thank you very much

opal pagoda
mystic mortar
opal pagoda
#

It would be best if you could draw a site plan

mystic mortar
#

it's gonna be just 2

peak cloak
mystic mortar
#

gonna be drawing on paint 1 sec

#

So router is there, point A and B are where cameras gonna be located and after the line there is no electricity what so ever, so it's gonna be around 200m from router to point A and B

#

Issue about setting up a wifi extender is that, there is some steel steel beams on the wall of point A so I fear it might deny the signal

mystic mortar
nova glacier
#

would there be line sight to A and B if you put pole above R or in that corner area around R?

nova glacier
#

is putting a pole a possibility?

mystic mortar
#

Yea, and can go as high as neededmhm

nova glacier
#

Line of sight specifically to the cameras themselves to be clear, not just that general area

mystic mortar
#

Ohhh thinkPeepo

#

thinkPeepo Should really be doable, shouldn't be any issue

nova glacier
# mystic mortar <:thinkPeepo:754149648712859719> Should really be doable, shouldn't be any issu...

200m is right at the edge of what's reliable from what I've seen and read, so I don't want to make any promises but that might be possible with just a directional outdoor AP like the U7 Pro Outdoor. I'm assuming you'd be doing PoE for the outdoor stuff, so you could place that pole at a closer more strategic location so that it's not at the limits. I don't know what the property terrain is like, so idk whether trenching some cable runs is practical or not. As a plus over a PtP link, the outdoor AP would be providing all your devices in range with some wifi.

mystic mortar
#

I will look it up guh But possibly the best i can go for guh

nova glacier
#

The Pro version just adds 6GHz btw. If you don't really need/want general outdoor wifi and only care about getting those cameras connected, then just get the U7 Outdoor

#

6GHz outdoor is also currently only relevant in the US afaik. Not to mention you'd need your client devices to support it for it to even be used, but Wifi 6E and 7 6GHz capable clients have become pretty standard the past few generations of devices

mystic mortar
#

Notes roger

opal pagoda
#

Use a regular 3-400w solar pannel with it since they are cheap af and extra output wont hurt anything and it should provide enough energy during the winter

pseudo blade
#

You need what? 5mbps stable?

#

I'd actually use 2.4ghz over 5/6 for stability, not use a repeater but line-of-sight dish-to-dish with something like a Mikrotik SXT on your roof off a J-pole or similar. Could also run ethernet to the close side of your building to the remote side assuming scale.

We've ran cameras on farms up to 5km off SXT2 and they're sub-$100. The connections were consistently fine as long as line-of-sight was maintained.

#

But nearly anything directional works at 200 meters lol

nova glacier
# mystic mortar <a:Notes:1276684183716237312> roger

oh, one other thing. That PoE switch you shared isn't the right kind for the U7. Some PoE hardware, like the U7 Outdoor, is standard negotiated PoE (~48V nominal). Passive 24V PoE isn't compatible with standard negotiated PoE devices. Always check the tech specs

fervent brook
#

I think I just bought a Netgear Nighthawk 8 port Switch...not even sure what a "nighthawk" device is that isnt WiFi... sounds kinda stupid...weights a "ton"(read: about 3/8 to 15/16 kilogram).

#

Weight 0.74 kg (1.63 lbs)

#

And people say Americans don't understand metric

#

If this thing doesn't support link aggregation...im gonna be upset

#

"Link Aggregation/port trunking provides up to 4Gbps connection to link
aggregation-enabled devices such as ReadyNAS®"

#

Oh good. If that wasn't a feature I'd really be questioning what a "high end" switch has....besides a logo

#

"Multi-language GUI support (English, German, Japanese)"

#

The three most hated "countries" in WW2?

cunning lion
fervent brook
# cunning lion

Does this imply your dellow engineers don't keep a crimping tool in their armrest in their car?

thick minnow
#

Should i get used U6 APs? I already have a unifi switch and router

copper cedar
#

Anyone open to helping me troubleshoot a supposed firewall issue? (Unifi firewall and Windows)

copper cedar
#

So I have a license server PC on 1 VLAN (192.168.1.X), and then user desktops on another VLAN (Ethernet 192.168.5.X)

#

For whatever reason, the user desktops are not receiving anything back from the license server pc

#

When I put the same laptop on WiFi, which is a different VLAN from the 2 above (192.168.2.X) connection works perfectly fine and it can get a license from the server

#

Both are windows pcs and I have a Unifi set up

#

I also tried changing the VLAN of the Ethernet port of the laptop to .2.X, and communication works perfectly with Ethernet in that VLAN

#

In Unifi, both VLANs are set to internal and are allowed to openly communicate

#

So I installed wireshark on both devices

#

When on the working VLAN (.2.X), I see a send and receive UDP packet on the laptop, and a receive and send UDP packed on the desktop server (.1.X)

#

When on the Ethernet VLAN (.5.X), I see send packets only on the laptop, and on the desktop server (.1.X), I actually receive the packet, but there’s no send packets

#

So I’m thinking maybe it’s windows firewall blocking anything from being sent back to that VLAN?

#

But I tried turning off the firewall and it didn’t fix it

#

Also, the license manager software has an entry in Windows firewall to allow all traffic on all ports. If this is turned off, then .2.X doesn’t connect to the license server. So clearly the Windows firewall entry is doing its thing

#

And what may also help to know. I tried another software with a license server running on the same PC. This works perfectly fine and shows send and receive packets in wireshark

#

The only difference between the 2 software, is broken software uses UDP, while working software uses TCP

opal pagoda
flint sage
#

i have a plan for my set up (future)

fiber+ap --> lan 1 (random tp link acting as a switch) --> lan1 (tp link) nas --> lan2 (tplink) mc server

fiber+ap --> lan2 dvr, thats it for now

#

the tp link is there cuz the fiber is in a differnt place and the nas nd stuff are in a differnt place

#

and the tp link acts as a repeater for my 3ds cuz of NAT ISSUES

#

potato setup

#

also they will be living in a cupboard 7.5 cubic meters

#

but downside is the cupboard is fitted to the wall so the back is concrete...

copper cedar
twin pier
copper cedar
#

I have awoken

#

and now back to troubleshooting this damn thing ugh

#

if anyone has any ideas on what I should try next I would be so grateful!

lone crane
#

im going to sleep

pastel monolith
# copper cedar When I put the same laptop on WiFi, which is a different VLAN from the 2 above (...

Since the connection with wifi seems to work I'd think license server side everything is okay otherwise that wouldn't have worked only thing really popping to mind is if there is some kind of check on the "Trusted clients" within the license server service/application code or something along those lines that is somehow restricting it to responding only on the same VLAN (or rather only on the two that are working...). Guess would be checking for application specific log files to see if any info about connections to see if it's just deciding not to respond to those incoming UDP packets for some reason. They could still be getting blocked by windows firewall too but you'd see them in wireshark I believe so just knowing if service is getting "access/requests" would probably be helpful.

#

also sort of tangential but sometimes can be helpful to just spin up some web server like python -m http.server 8000 for a server serving up files from current folder on port 8000 can just be useful for open simple service on port and monitor for incoming connections, this feels to me like some kind of license server config issue maybe? but hard to say so would look for logs

copper cedar
#

So clearly for some reason, Wireshark is only seeing packets after it’s got through Windows firewall

#

If there’s a way to change this so Wireshark could see packets before the firewall that would probably be more helpful, so I can see if a return packet at least is attempting to be sent by the device

pastel monolith
#

Think if Wireshark using the pcap drivers is like direct packet capture before any application/service layer stuff like firewall would mess with it but may depend on how the network interface is setup in Wireshark too on that

dawn reef
#

hello all!!! i am currently in school for cybersecurity and I am taking 100 level(entry level) network classes right now. so if i ask dumb questions its because i dont know nuffin. hoping to learn all i can so any help yall can give (and no i dont wanna cheat ill just have like general questions) id greatly appreciate it!!

opal pagoda
dawn reef
lone crane
opal pagoda
#

hol up need to check this

#

not affected pepoJuice

copper cedar
#

but outbound, it is last to see it

pastel monolith
#

Ah right that makes sense

copper cedar
#

Yeh it does. Like incoming the Nic sees the traffic first, but before the NIC sends the traffic, the firewall hits it first

#

But that’s still so weird like. If the firewall is set to allow all traffic from any IP or port to the program, why is it still blocking traffic to that one subnet

#

In the license server app, I can at least see, when it receives the packet to take a license, it says 1 license in use and the license is taken out of the pool and assigned to my user

#

But then obviously it doesn’t hear back and releases the license

#

What sucks the most is that it’s one of those software Licenses where if u don’t pay for a maintenance subscription on ur perpetual license, they won’t give u technical support lol

#

OMG I FIGURED IT OUT

#

the damn alway on VPN was running since the pc was enrolled in Intune

#

I turned off the always on VPN and bam its working perfectly fine between the .1.x subnet and the .5.x subnet

pastel monolith
#

Ah nice 👍

copper cedar
#

I wonder why that would happen tho

#

Im guessing maybe it was coming in through the ethernet adapter but then coming out through the VPN adapter?

#

but I cant find the AOVPN in wireshark

#

nvm yes I did lol

#

YEP YEP YEP. what do u know. the return traffic is being sent through the VPN LOL

#

Should probs fix that up anyways for VPN traffic to be able to see this subnet

#

U know what I think it might be. I think is probably UDP breaking because traffic is being sent from 1 IP, and then being received from another. The firewall is set to allow all traffic between VPN and Internal already

#

Yep can confirm thats whats happening. Wireshark on the end user device shows the UDP packets being received from the VPN address. If I try the VPN address on the end user device on the .5.x subnet, it works perfectly fine

#

I guess ill just build a policy to exclude desktops from AOVPN lol

#

thanks everyone for the help <3 I cant believe i was stuck on this for days. Didnt even notice the VPN was on 🤦‍♂️. That is so embarrasing

lone crane
#

and another one but this time microsoft

#

well almost another 10/10

#

what next are we gonna see anything with ipv6 get nuked tomorow

clear igloo
#

oh, nvm, I can't read 🤣

#

Yes, an 11/10 where IPv6 exposes everything risking the internet as we know it

rocky badge
#

on prem sharepoint

#

🤢

pseudo blade
# clear igloo Yes, an 11/10 where IPv6 exposes everything risking the internet as we know it

Hey guys what if

...We explicitly forbid new connections in from remote addresses to devices in our subnetworks except on whitelisted ports and addresses

Or uh...

Treat all devices as if they were in a coffee shop in <enemy_country> and provide very restricted access via some sort of system where we don't trust devices or users more than strictly necessary, perhaps requiring continual verification via some sort of hardware token?

Or even both? That'd be pretty crazy huh?

clear igloo
pseudo blade
#

Wild idea!

clear igloo
#

Never take off

pseudo blade
#

Imagine that, then you'd have a central device that controls access to the network with a set of configured rules

clear igloo
#

It needs to be AI run and distributed to even have a chance

pseudo blade
#

Nobody's ever considered the concept, hence why nobody uses public IPv4 addresses

clear igloo
#

Maybe a Fog Wall or something

#

Fog firewall?
Sounds stupid

pseudo blade
#

I'll ask GPT4 how to make one posthaste

opal pagoda
clear igloo
#

Maybe throw in RGB of some kind to signal

opal pagoda
#

what shape should it be?
i propose a trashcan shaped device

clear igloo
#

Maybe a dodecahedron or some MC-Esher style

pseudo blade
#

Clearly it should be cloud-shaped

clear igloo
#

We shall call it the AI Blockinator Wallfire Machine

#

And of course, subscription only licensing

opal pagoda
#

2 can be put into HA cluster so it can become balls

pseudo blade
clear igloo
#

Sold in blocks of 50K

#

If you run out then it permits all

opal pagoda
copper cedar
#

Still kicking myself over that issue I spent days on

#

Mf always on vpn 🤦‍♂️

stiff steeple
#

I want to take an existing Nextcloud AIO install (docker), and move it behind a reverse proxy (again, docker, probably npm).

I have:

  • A domain name
  • An account on cloudflare, for pointing the domain name (or rather, subdomains. the main domain doesn't go anywhere.)
  • A VPS (cloud.domainname.xyz goes here), running HAproxy, shoving all traffic on 80/443 down a wireguard tunnel connecting to...
  • An ubuntu webserver on my local network, running...
  • Nextcloud AIO in a docker.

I want to place a reverse proxy between the webserver and the NextCloud AIO. Reason being, I want to host other services for personal use (e.g., searx, wger), and i want to secure them... and with the Nextcloud AIO taking all traffic coming in over port 80, I can't do the certificate challenge for any other subdomain.

How do I go about this?

tight pecan
#

After that, you can just run your reverse proxy on port 80 and 443, then configure your (sub)domains as needed

lime sundial
#

I think I just managed to "hack" into the homeserver of my friend (with his consent) via radio waves. He knew I'd do it and checked devices connected. Out of pure spite for the idea I daisy chained Lora devices with meshtastic and managed to send payloads for connection via Lora kek

#

That was the most inefficient stupid way you could've done it but that was definetly fun

thick minnow
#

deployed

opal pagoda
#

do a little cable managment so it isnt a trip hazard

thick minnow
#

no one is steping there lol

lime sundial
thick minnow
#

basically

#

im moving here for only 2 weeks

tardy trench
#

Any of you guys know snort?

lone crane
#

what is the pi1 for

thick minnow
thick minnow
lone crane
#

it can really do pi hole

#

i did not know that

#

no clue what i should do with mine, considering NUT

thick minnow
#

also hae a pi 5 running qbittorrent and plex and a samba file server for NAS purposes

pastel monolith
#

Yeah pihole purposes it just needs to be DNS and DNS cache, imagine the web interface a bit slow on pi 1 but can do basic networking stuff and DB without issue still

thick minnow
#

yeah

#

I like the redundancy of having pie hole on its own system, in case I fat finger something on the pie five which prevents it from booting

#

certainly haven't done that when I was trying to run fucking proxmox

pastel monolith
#

I like the proxmox but if using zfs do need to have a silly amount of memory free, imagine setup on pi is a bit of a struggle, have just done it on a desktop a couple of times here.

#

Recently setup pihole as a docker service on one of the VMs on there but I've been running it for a few years and have dealt with some disk failures and recovery so am pretty confident can keep it chugging, most of the docker services I setup a couple of weeks back have still been running since then although I just shut them all down to move directories just to make it easier to find stuff...

#

Pihole so far blocked like 20% of the requests going through it and I appreciate it immensely, does make the Internet a more usable thing

amber urchin
#

I just passed my HBA thru to the truenas vm rather than trying to set up the pool in the hypervisor.

thick minnow
#

I love pi-hole

#

fuck zfs

lone crane
#

Never had any issues with zfs here

clear igloo
#

zfs is love ❤️

opal pagoda
thick minnow
#

for a while i had a old dlink nas and just mounted it in my VMs for storage

#

nas died and i sold the pc i was running everything on and bought the Pi 5, and now the pi just runs raspbian lite and i have samba set up on it

waxen scroll
#

@pseudo blade all this cisco AI stuff they're announcing, you need to be ALL IN with like 5 products to make it work

#

splunk included

pseudo blade
#

Oh?

#

That doesn't stun me, "AI" and sales are often joined at the hip

#

Incentivising increasing adoption of their products with the day's buzzword isn't a new idea from Cisco

waxen scroll
#

@clear igloo premium linkedin AI slop

thick minnow
#

are unifi U6 mesh or U6 pro better for home use?
free standing house with 2 floors.

lone crane
#

But serious, the "unfifi" u6 pro could be best if it's a small house but I would maybe go for the mesh if it's big enough and not with any ethernet plugs around

cunning lion
#

Say a 2500+square foot place with multiple floors would benefit from mesh for example

#

But a single floor that is less then 2000 square feet the non mesh should be plenty i would think

#

That is how I look at things honestly

exotic briar
#

Do any of you know any 8-10 outlet 1U rack mountable PDUs that are good?

thick minnow
#

I use 4 apple AirPorts now and i still get bad coverage in some rooms

#

the wifi channels in my area are very quiet so thats not and an issue

opal pagoda
exotic briar
#

Regular outlets.

opal pagoda
#

Haven't had much experience with those

#

But they are just rack mounted power strip

inland orchid
#

I've seen Jake reflash fiber optic transceivers from one manufacturer to use in another manufacturer's switch. What tool is he using to do that?

clear igloo
cunning lion
thick minnow
cunning lion
#

I would honestly and use MOCA as a backend if you don't have ethernet ran throughout the place

thick minnow
cunning lion
#

and even then you would want to play around with the positioning of the different access points

#

yeah plug the mesh directtly into the ethernet ports around the place and

thick minnow
#

i only have one AP that needs to be ceiling mounted, ill probably use a u6 lite or plus for that.
its in the kitchen

honest merlin
#

my internet speed tops out at 35 MB/s when downloading despite being direct connected to my modem/router and having a 1 GB line. though i can download multiple items at that same speed so i dunno. guess it depends on the HDD its writing to?

thick minnow
#

mb/s =/= mbps

cunning lion
#

@honest merlin also depends on the server side honestly

honest merlin
#

AllDebrid for example

cunning lion
#

you can only grab as fast as the server is willing to send

thick minnow
#

some servers are dog slow

cunning lion
#

FTP anyone?

honest merlin
#

JDownloader2 was quick but i have no use for it now

thick minnow
#

use speed test

#

by ookla

cunning lion
#

@honest merlin likely allowed for multiple connections to the server which allowed for a higher speed

#

I use JD all the bloody time here personally and yeah you can set the amount of connections to a service and pretty sure default is like 3 or something

clear igloo
thick minnow
#

no?

clear igloo
#

It's captial b for bytes

honest merlin
clear igloo
#

notation matters

#

MBps and Mbps are different
Mb/s and Mbps are the same

cunning lion
#

now divide the first number by 8

#

If I remember right

thick minnow
#

117

#

MB/s

honest merlin
thick minnow
#

perfectly normal for gigbit fibre