#networking

1 messages · Page 186 of 1

whole mason
#

I just about killed myself running a wire from my switch in the living room into the loft across the whole house down round the already existing wires to my setup and all the way back down into my computer and love the new speed

fallow ivy
#

@half valley thxxx

half valley
#

@fallow ivy you're welcome!

fervent brook
#

if i have a 3 port edgerouter, can i connect one port out to my gateway, and then have the two other ports be VLANs that connect to two halves of my devices in my house?

#

pretty sure "yes" is the answer, unless an edgerouter is that much different from a regular router

#

i could do the same thing with my managed switch though...but without the extra layer of NAT

half valley
#

@fallow ivy yea I only know a bit of Ubuntu

fallow ivy
#

any idea ?

half valley
#

nope

fallow ivy
#

RIP

#

ME

#

thx

dire flare
#

@fallow ivy what are you trying to do

fallow ivy
#

I Want to setup a ubuntu vm to do a caché serveur
I want to setup that on arm

dire flare
#

No clue on cache server procedures, mainly wondering what you were doing with gnome-shell

fallow ivy
#

So i have dl ubuntu serveur for arm and i have dl ubuntu desktop with taskells

#

I want to have graphics interface to do cache serveur more easy

#

But i have the error above

#

(I am french )

#

^^

#

@dire flare

dire flare
#

I'm assuming no display manager was installed?

#

You should attempt to start gnome through gnome-session however

fallow ivy
#

I am bigggg noob on ubuntu i don.t no

#

So i use the command gnome-session ?

dire flare
#

try

fallow ivy
#

Nothing

dire flare
#

nothing as in no output?

fallow ivy
dire flare
#

switch to tty7

fallow ivy
#

?

#

Wath

dire flare
#

Is this installed on bare metal?

#

How are you interacting with the machine

#

through SSH or..?

fallow ivy
#

I am on the direct consol

#

On mi arm machine

#

(Taht a internet box i can setup vm on )

dire flare
#

So you have an arm device (let's say a raspberry pi) with peripherals and a monitor plugged in?

fallow ivy
#

No si à virtuel monitor

dire flare
#

in that case you want to press ctrl + alt + f7 to switch to tty7
That's usually the tty used for a graphical session

fallow ivy
#

I try

#

That do nothing

#

Wait

#

But i have idea when this screen virtual doesn’t Word i can use à same Thing of ssh but for thé vidéo

#

U see ?

charred meadow
#

Could you try running systemctl status gdm

fallow ivy
#

Ok
I try

charred meadow
#

Note to other people reading the message on the right translates to "The chosen operating system (still) does not use display."

fallow ivy
#

Yesss ^^

#

Thx

#

Any one have idea ?

little rock
#

I think it's well explein in native language

#

so wait and see

fallow ivy
#

?

#

Don’t understand

#

@little rock

little rock
#

it's not yet implemented

fallow ivy
#

F****

#

I don’t have any possibility ?

little rock
#

maybe in the delta version of the box

#

someday

#

I can't tell you a release date

fallow ivy
#

I have the freebox delta

#

Oooo
I see

#

I need MAJ

#

Update *

#

That it ??

charred meadow
#

Which operating system and version are you using?

fallow ivy
#

Of ubuntu ?

#

Of what

little rock
#

custom linux

fallow ivy
#

18.04

#

Think

little rock
#

Debian arm64

fallow ivy
#

I have ubuntu

little rock
#

if ubuntu it's the 19.04

#

it's not an lts version

#
Portail Free

Les VMs (Machines Virtuelles) sont maintenant lancées pour tous les utilisateurs d’une Freebox Delta ou Delta S. Elles permettent d’installer des logiciels sur votre Freebox Server à partir de la version 4.1.0. Ça sert à quoi ? Les applications sont nombreuses, voici quelques ...

fallow ivy
#

ubuntu-18.04.4-server-arm64.iso

#

is use this version of ubuntu

#

what is the probleme with lts ?

#

i nedd to use 19.04?

little rock
#

the end of the support is near for the 19.04

fallow ivy
#

So ?

#

What i need to use ?

little rock
#

have you tried to use squid for your end use ?

fallow ivy
#

What is squid

little rock
#

also, you know that the box has pre-installed VM

fallow ivy
#

Yes

little rock
#

it's an proxy cache software, you want to do a cache server ?

fallow ivy
#

For steam

#

Origin ...

little rock
fallow ivy
#

This part is not the problème

#

The problème for me is i need graphic interface

little rock
#

you know, the best is worst than the good sometime

fallow ivy
#

And u think i need to use the preinstall vm ?

#

Yes but i don’t no how to do cache server with just consol

little rock
#

just copy and paste what's in the tuto

#

and see if it match the result

#

most of the time it work

#

if it's just the translate part that you need help

fallow ivy
#

I need change ip ...

#

Yes for translate need lot of help

little rock
#

so you have docker and curl installed in ubuntu 18.04

fallow ivy
#

No

#

I have do nothing

#

CAN u do voc ?

little rock
#

yes

fallow ivy
#

Côme on gamee pls

raw timber
#

So hard to decide if should stick with proxmos or switch to free nas for more nas suport now that it can run vm too

thick minnow
#

Free nas

#

@raw timber

raw timber
#

How good is vm suport need fast vm too and docker suport

thick minnow
#

Not the best not the worst i would say it’s okay

raw timber
#

I was also looking at ubunto sever

#

And see up nas my self

thick minnow
#

I haven’t used it before

raw timber
#

Or any oth Linux discor

thick minnow
#

Nope I only use Windows and Mac technically Mac is Linux but still

#

And I use free nas

raw timber
#

Oh I was most look at since I need nas suport and good vm and free

#

How is it not the best can it run small game sever like a few friends on Minecraft

charred meadow
#

I think it would be easier to use proxxmox as a nas then to use FreeNas as a hypervisor.

raw timber
#

Yeah that why I am looking at Linux to set it up my self

charred meadow
#

I think gamers nexus recently built a nas based on proxmox.

#

Nevermind they used unraid.

raw timber
#

Why so much against a Linus os

primal ice
#

cause everyone wants one click solutions.

raw timber
#

Yeah I was looking for something different and

primal ice
#

I use ubuntu and samba it works could use plex if I wanted but don't really want outside connections for my internal network.

raw timber
#

I plan to have lxc and docker and VM install it will use a gui to start till I get it full set up thne get disabled this was my old game PC it a beast 6500 and 16 gig of ram

thin epoch
#

Just the amount of info Cellebrite can access, they can even get into iPhones... I presume it can still get browsing history even if it was cleared?

hexed pilot
#

im assuming i would talk about wifi stuff here?

#

ping me if any 1 knows 🙂

dire flare
#

@hexed pilot This would be the chat for such things, yes

#

What's up?

brave pilot
#

ok so i dont know if this should go into some other channel but i have quite a simple question. Is a powerline adapter gonna give a lower ping than wifi or is it gonna be similar also is there any difference between 2.4Ghz and 5Ghz in terms of only ping my download is too low to saturate any of those anyway

jaunty talon
clear igloo
#

@jaunty talon Hmmm, needs more upload

jaunty talon
clear igloo
#

Ah, those evildoers!

jaunty talon
#

Yep!

hallow nimbus
#

BlueCrazii would like to know your location

clear igloo
#

@hallow nimbus 127.0.0.1 or ::1

hallow nimbus
fervent brook
#

you'll probably get better ping from powerline as long as there isnt constant interference in your powerlines. Especially if the amount of powerline adapters is low

#

if you want low ping from powerline, use it as a point to point, and nothing else

burnt wharf
#

anyone have any experience setting up a lan cache? attempting to setup lancache-bundle on my unraid server

raw timber
#

Why do unraid need 2 hard drive to set up

burnt wharf
#

because 1 is the parity (backup data) and the other can be storage. parity will have to be the largest drive in tha array aswell

raw timber
#

ugg i onlyhave 3 drive one in a extrnl a back up drive one a 500 gig hard drive and one a 2 tb

#

and some ss 2 small one and one my main storage

#

@burnt wharf what would you do on a limited budget of only enough money for the unraid os it self

granite trench
#

@jaunty talon I think I just got wet about that speed

raw timber
#

The bacl up is 2 tbtoo

burnt wharf
#

are you asking which license would i get? or how would i configure the drives?

#

from what i can read. out of your 3 drives, the 2tb hd would be parity, 500gb would be storage, and i dont think you can use a external drive in a array

#

@raw timber ^^^

raw timber
#

or i could remove it and and use the 2 tb as main drive

#

becaer it kind of odd to go from a nas with 2tb of space to one wiht only 500

#

luck not much is on it now

burnt wharf
#

parity has to be the largest drive. the rest can be storage drives

raw timber
#

do i need a backup drive with it

#

i am bad at back it up

burnt wharf
#

if your largest drive is 2tb then that has to be the parity drive. any other drive you have that are sata can be storage drives. that is how unraid works

raw timber
#

i mena sebrate form unrade or is it back up

burnt wharf
#

if you wanted to backup your drive and not use a unraid at all?

jaunty talon
#

@granite trench haha :D

raw timber
#

do i have to have it or would have 3 drive in unraide work to store my data and bakc up my main pc

burnt wharf
#

unraid can be used to backup your pc

#

and store data

hexed pilot
#

so I had a question last night and i didn't get to it. Is Xfinity good? (That's the best internet im able 2 get in my area)

thick minnow
#

well-

#

depends on what plan your using and how much you want to pay

hexed pilot
#

600 MB

thick minnow
#

I mean im using xfinity as of now and for around 85-100 usd im getting 250 download

hexed pilot
#

$60-$80 for 600 MB were I am. But it hasn't been installed yet so i can't say our speed will be that

thick minnow
#

dont quote me on that idk exactly what im paying lol

hexed pilot
#

xD

thick minnow
#

o damn

#

600 mb??

#

insane

hexed pilot
#

buuuuut

thick minnow
hexed pilot
#

were getting the stuff but the website says no 1 is coming to set up the outside work

#

no technician

thick minnow
#

oh

#

damn

hexed pilot
#

so, r the speeds ur getting really close 2 the speeds ur paying for?

thick minnow
#

yea

#

well

#

my whole fam is on internet rn

#

someones streaming netflix as of now

#

the other ones on mc

hexed pilot
#

well during average time for yall

thick minnow
#

and my moms streaming some stuff too

#

during average time when im the only one on

#

i get around 250 sometimes even more

hexed pilot
#

what about during peek hours?

thick minnow
#

220-230

hexed pilot
#

out of 250?

thick minnow
#

YEP

#

yep*

#

srry caps

hexed pilot
#

thats pretty good

#

u see, i was using Frontier

thick minnow
#

oh

#

cool

hexed pilot
#

no NOT cool

#

not trying 2 be mean but, WORST Internet you can get!

#

atleast 2 me

#

but the reviews r pretty bad as well sooo...

hollow marlin
#

Well is it DSL if its frontier?

little schooner
#

Frontier is dsl in my area

crimson otter
nocturne burrow
#

Planning on building a new network when i move in a couple of months but i am not so sure on what router to get. Ive been looking a bit at the edgerouter pro 8 cause a friend have one but i dont know if there are other similar priced that are better now since it has a couple of years on its neck. Does anyone have any recommendations for a similar priced one?

charred meadow
hexed pilot
#

So we bought Xfinity but, they didn't give us an option to have a technician come out. Help

hollow marlin
#

Depends on location. Many ISPs are limiting techs, including us

half valley
#

Sounds about right

timber trout
#

UDM Pro is fantastic

hexed pilot
#

thanks yall

#

we figured it out 🙂

little schooner
#

Do you have to mount the unifi ap to get good coverage or is that optional?

rocky badge
#

Depending on model of AP determines most optimal mounting

#

In wall APs are better mounted on the wall, the round APs are better mounted to the ceiling

#

And the Basestation XG is best mounted to a pole pointed towards the area you want to cover

fervent brook
#

why can't the tech remote in?

primal ice
#

have to run cables

fervent brook
#

you can't run cables? not good at terminating twisted pairs?

nocturne burrow
#

Is the UDM pro fanless or have they just hiddem them very good? Will see if i can find a good deal on it cause from the supplier i usually buy from its 200 euro more than the erpro8 :/

waxen scroll
#

@rocky badge I just plop the round AP on top of a shelf pointed to the sky and the basement though the second floor get ok signal

vagrant gull
#

in my room I have one wired device (pc) and other devices that use wifi (xbox, phone, ipad etc), should I get a ethernet switch and wire up the xbox and leave phone and table to bad wifi? or should I get a second router and use it as an ap?

#

not ethernet but some kind of improvement as uploads fail unless its wired, its the pc that needs ethernet as it has no wifi card

rocky badge
#

@waxen scroll oof

#

@nocturne burrow the UDM Pro does have fans.

thick minnow
#

What is a good gigabit capable cable modem?

#

It doesn't need gigabit WiFI

#

I already have a gigabit router

clear igloo
#

Arris SB8200 is great

thick minnow
#

I already have an Asus AC1900 router, I figure an Asus cable modem would go along well

clear igloo
#

Are you getting gigabit from your ISP?

thick minnow
#

Yes

clear igloo
#

Well it's rated up to 686 in lab conditions and 16x4 is only going to usually give you 300Mbps to 400Mbps if you're lucky in the real world. Most ISPs won't push to theoretical limits

#

You need a DOCSIS 3.1 modem for gigabit in 99.9% of cases

thick minnow
#

Okay

#

And I'd like to not pay more than $100 for it

rocky badge
#

you don't necessarily need an ASUS modem with an ASUS router

#

||or ASUS at all||

thick minnow
#

Obviously

#

I just wanted it to look nice

#

Both being the same brand

clear igloo
#

The cheapest DOCSIS3.1 modem on the market is used and that's $130

thick minnow
#

I've been renting a shitty one from Comcast for a number of years, and I'm done with it

clear igloo
#

Netgear CM1000 or Arris SB8200 are top picks but they both run around $150 new

clear igloo
#

Yes, that's the SB8200 🙂

#

Very solid model, I used to use it before switching over to AT&T's fiber option

thick minnow
#

Okay

#

I'm on fiber

#

But I'm with Comcast

clear igloo
#

Ah, concrap 😛

thick minnow
#

They're actually better than AT&T here

#

AT&T was absolute garbage

#

The internet would go down several times a day

#

I switched to Comcast 6 years ago, I don't regret it

#

I actually have better speeds than what I'm paying for

rocky badge
#

We're switching to AT&T this summer speedyboi @clear igloo

clear igloo
#

@rocky badge hypecrab

thick minnow
#

I pay $90 a month for 120 Mbps download

#

And I get 220 down on a wired connection

rocky badge
#

big oof, that's expensive

thick minnow
#

Yeah, they revised it

#

Now it's $90 for gigabit

clear igloo
#

Ah, I was about to say

rocky badge
#

ah ok

#

$59.99/mo after 12 months

clear igloo
#

Jelly! 😡

#

$80 for me

rocky badge
#

RIP

clear igloo
#

of course I don't pay for it 😛

rocky badge
#

Local ISP pushed AT&T to reduce their prices

thick minnow
#

Upgrading also means that I need to buy Cat 6 cables

clear igloo
#

Cat5e is gigabit rated

rocky badge
#

if you have 5e already, that's fine

thick minnow
#

I ran some recently that are Cat 6

little schooner
#

$110 for 180 mbps for me. Comcast

thick minnow
#

But most of them are Cat 5e

rocky badge
#

Commiecast

little schooner
#

Concast I call them

#

Robbery

rocky badge
#

😂

thick minnow
#

Cat 5e is theoretically gigabit

rocky badge
#

it's not theoretically

#

it is

thick minnow
#

But I've never seen anything over 500 Mbps over Cat 5e

little schooner
#

What you saying?

#

I have cat5e in the lab at gig

clear igloo
#

^

rocky badge
#

Same, I have some 5e with gig

thick minnow
#

And it won't hurt to do some future proofing

clear igloo
#

True, so long as it's not over 55m then you get 10Gig out of Cat6

#

100m for Cat6a

thick minnow
#

Cat 6 is so cheap now

little schooner
#

@clear igloo is it like 20m for cat5e 10gig?

clear igloo
#

Depends on cable quality, you might get a few meters but I wouldn't expect more than 10

little schooner
#

My prof wants to run 10g over cat5e

clear igloo
#

RIP

little schooner
#

Well time to break the news to him

thick minnow
#

I have cat 6a for runs that are longer than 100 feet

little schooner
#

@thick minnow 100ft not same as 100m

thick minnow
#

What a great grasp of the obvious

clear igloo
#

but you get better shielding at that point so you don't have to worry about interference as much

thick minnow
#

What would interfere with it

little schooner
#

@thick minnow idk, you said you never got 1g over 5e so idk how much you know

#

Making sure you understand the right facts

clear igloo
#

Electrical or other EMI

thick minnow
#

I live somewhat close to an airport

#

Within 15 miles

rocky badge
thick minnow
#

Of an international airport

clear igloo
#

@rocky badge Spreadsheet HYPE!

#

Wait, they are charging you for the gateway?

rocky badge
#

Yes 😂

clear igloo
#

Odd, they don't charge me

rocky badge
#

But we're gonna ditch it once we get it setup

thick minnow
#

I think I'm gonna just get that Arris Surfboard

#

Thx for the help @clear igloo

clear igloo
#

Yah, I loved mine so hopefully you do to 🙂

rocky badge
#

I wish AT&T didn't do this shit with their stuff lol

#

The ONT and the gateway has to authenticate

#

Both with certificates

clear igloo
#

dang

rocky badge
#

@clear igloo Commiecast also sent a notification and cut internet to someone in another server when he started streaming a MKV form his server locally

clear igloo
#

lol

vapid dune
#

what cat 5e is definitely gigabit

raw timber
#

how to set up a mariadb on a unraid sever

subtle glen
#

IT said that all old files will be removed from the network resource to reduce infrastructure cost, so my mom is downloading 400GB of data and we have to do it before April 10th . Starting to think we are not going to do it 🙃

hollow marlin
#

Contact IT and asked to do it inhouse or over the LAN.

subtle glen
#

you mean enabling split tunneling?

hollow marlin
#

No I mean literally have her do it on site

raw timber
#

how to decide unraid vs LinuxServer.io

The Perfect Media Server 2017

subtle glen
#

the servers aren't here in italy, or near

#

they are in the uk or america i think

hollow marlin
#

Well NVM in that case

subtle glen
#

pretty sure it's not the connection that's bottlenecking

hollow marlin
#

Well what is your bandwidth? And if this is SMB then latency is the problem

subtle glen
#

1gbps down

hollow marlin
#

Id go with latency then, especially if its overseas. Excluding any VPNs she might be on

subtle glen
#

alright

hexed pilot
#

ayyy we just got our xfinity stuff

swift hare
#

I just installed my first sfp cable into my own home. Found out the switches I have are only GB over them.

#

Still only gigabit fiber so w/e

hexed pilot
#

gigibat is fast if ur doing normal every day things

swift hare
#

yes

rocky badge
#

My only 10 gigabit is between switch and my PC lol

#

My USG doesn't have 10 gigabit, nor do any of my servers

swift hare
#

nice, and nas?

rocky badge
#

2 gig

swift hare
#

still more goodly

rocky badge
#

lacp 2x gigabit ports lol

clear igloo
#

@rocky badge No 10Gb nas? 😦

rocky badge
#

nope 😦

swift hare
#

few users tho

rocky badge
#

@clear igloo Just be AWS

clear igloo
#

😛

rocky badge
#

~970Gbit/s from AZ <-> AZ

little schooner
#

10g Nas here

#

But direct connection

rocky badge
#

~9Tbit/s from govcloud to internet

little schooner
#

Pc to nas

#

I'm sad to only have 180 mbps

#

Upload at 5

rocky badge
#

rip

little schooner
#

Concast

swift hare
#

f

little schooner
#

Remember that

rocky badge
#

Commiecast

swift hare
#

centurylink got my up at 1G

rocky badge
#

it takes a century to get a link

swift hare
#

lol

#

ping 50K dl@1G

little schooner
#

On the systems side, the pandemic exposes how many enterprise solutions were never built to scale

rocky badge
#

AWS is scaling like crazy

#

They've literally changed their hiring requirements

little schooner
#

Aws has been pretty good at scaling

rocky badge
#

19 years+, certs/college, they'll pay for relocation, sysadmin/net/programming/cloud knowledge

little schooner
#

19+ years

rocky badge
#

Just to get more hands racking servers

little schooner
#

Yikes

rocky badge
#

They have the servers, they don't have the man power

#

They're having to rent fiber and activate lots of their dark fiber

swift hare
#

shame they werent already using it

rocky badge
#

They didn't have a reason to until now

swift hare
#

yeah, we don't need everybody to have really fast speeds

#

then how could we feel better

rocky badge
#

Meanwhile Azure and Google Cloud are trying to stay afloat oof

swift hare
#

double oof

rocky badge
#

Azure resources are being allocated to keep Teams alive

#

Google Cloud has to keep Meets, Gmail, Classroom, etc alive

swift hare
#

my gmail has been failing from time to time

raw timber
#

I still wonder why isp don't give out static IP

little schooner
#

@raw timber because of dns

raw timber
#

What do you mean

little schooner
#

A dynamic ip still works and people can find your server by a name

#

Static ip not really needed that much

#

This is the simple reason I thought of now. There's more reason of course

#

But it makes a lot of sense.

raw timber
#

Till you run in to a hulu who think different up is a different home

#

And block

little schooner
#

Well that is not fault of ip

#

That's a policy problem

raw timber
#

And then you stuck contact thne when it happened

little schooner
#

Yeah stuck I guess. You can use VPN I suppose

#

Or mobile phone ip

raw timber
#

Yeah won't work over mobile vpn you get kick they say talk to isp to get static

#

Or just keeps contact then when it change

raw timber
#

@little schooner they don't allow it over VPN or mobile it need to be a home IP and can only change 4 time a year

#

Foot down

#

Unless you tell then it happen and they decided to wave it

burnt wharf
#

anyone have any experience with kvm hdmi extenders?

strange silo
#

@rocky badge Not just Teams but also OneDrive and SharePoint Online (Teams is just SharePoint in the backend anyway btw)

#

Not even slightly, it's literally SharePoint. When you back it up you do it through SharePoint Online backup lol

#

And Microsoft has no proper (not in Beta) API to restore data back in to Teams

rocky badge
#

Yeah

#

They've been slow asf for me as well

#

But they're usually slow

strange silo
#

Yep, currently I backup 4600 OneDrives and the rate limiting is super HARD CORE

#

If we switch to also backing up students as well than I'd need to do 43,000, no bloody idea how that will work as the current 4600 bare hangs on there simply due to the throttling

thick minnow
#

Hey there, i was thinking about upgrading my laptos wirelesscard, is there anything i have to look out for? Tnx for the help

neat forge
#

i got my first little project working, new to it all and ive set up a server with proxmox to run 3 seperate vms. any suggestions on what i should work on next?

thorny vector
#

@neat forge what do you have those VM's doing?

neat forge
#

@thorny vector one is for gameservers, one im setting up for an rtmp (both are ubuntu) then the 3rd i set up as a windows one to just mess around and play with

thorny vector
#

Alright. I personally always advocate setting up your own cloud, so you're not reliant on external providers, and can keep all of your own data in house

neat forge
#

as in physcially having the machine in house?

thorny vector
#

Where is your hardware?

neat forge
#

im using Hetzner

#

i wanted to have the hardware inhouse but cant for various reasons

thorny vector
#

I gotcha. And by in house, I meant more away from 3rd party companies like Google, or microsoft

neat forge
#

gotcha, have you got any documentation that useful for this? its been what ive been learning off the most

thorny vector
#

Lookup up pydio, it's a pretty solid data storage solution with a web interface. For media I recommend jellyfin, it's like plex without relying on plex's servers. I'd also recommend doing all of it through docker containers, makes it more efficient and potentially more secure because of the sandboxing

clear igloo
#

plex doesn't rely on anything but your own server?

thorny vector
#

Nope, not true

#

They send a buuuuuumch of data through their own servers, that's why you use a plex address to connect to your stuff

#

No one else can touch my shit, not about that

clear igloo
#

You use a plex account to link TVs and stuff but beyond that you use your own IP address

thorny vector
#

Why do I need an account, though? If it's really all me, I should be able to do my own authentication

clear igloo
#

Ease of use and linking for novice users is about it and even then you can locally discover devices with Plex if you know what you're doing

thorny vector
#

I know from monitoring they send traffic to their servers, thats why I stopped using it.

#

Plus jellyfin is open source

clear igloo
#

Jellyfin also requires emby support on the device which limits support at the moment

thorny vector
#

That's true, I can't argue that point. I've been able to get everything on my network to work

clear igloo
#

Plex, by default, will gather metadata and images from their servers but you can change the database it uses to not use the Plex default stuff. Not sure of what other data you're referring to though, I would be curious to see more info though

#

Fair enough, if it works then no need to switch 🙂

thorny vector
#

I'll see if I can find the plex cap I did, and what it was exporting.

#

I'll be honest, I can't remember off the top of my head

#

I'll also admit, I'm a fascist with my own network

clear igloo
#

Yah, I usually lock things down but I haven't done any pcaps on plex in a while to see what it's sending back

thorny vector
#

Google *cast devices are also really bad. That's one place I've compromised having "loud" devices, but they have their own little segregated dmz, so it's not horrible

clear igloo
#

Yah, I've got a segment for my IoT devices that keeps them off the rest of the network 🙂

thorny vector
#

IoT scary, man. Nobody respects how much they can listen to

raw timber
#

The issue for me Plex is what I'd suport by our tv

sturdy mirage
rocky badge
#

@clear igloo Logitech Harmony ignores SSL certs lmao

clear igloo
#

@rocky badge Not surprised

fast gate
#

@sturdy mirage you do bios updates?

sturdy mirage
#

I do when iLo *uck up my access to the raid controller

thick minnow
#

What is a good cheap ($30-$70) wifi card that also has bluetooth?

little schooner
#

If you're talking about laptop wifi, get an Intel ax200.

#

Has bt 5.1 and great wireless

thick minnow
#

Thank you @primal ice

#

You too @little schooner but I'm looking for desktop wifi haha

little schooner
#

The one drako listed is awesome

thick minnow
#

Ah that's great!

solid falcon
#

Hey guys i want to create a custom video streaming server can anyone recommend me hardware it should be able to handle 10,000 users

strange silo
#

10,000....... well.... more than one server

#

and then what you need is 100% down to the software you are going to use

#

bottom up design is a bad idea

hollow marlin
#

Depends on the type of service you want to stream. It will vastly change minimum hardware/bandwidth needed

jaunty talon
#

If you dont need to do any encoding you can do that on a very lowspec machine with fast enough network card :)

strange silo
#

still wouldn't pile 10,000 concurrent sessions on to a single server, even with a 100Gb connection 😉

clear igloo
#

Multicast 😄

strange silo
#

1 issue and 10,000 pissed off people lol

clear igloo
#

😛

strange silo
#

Our Adobe Connect eats server resource from the encoding it does from the lecture recordings

#

we have 14 VMs with 6 vCPU and 12GB for that workflow

#

going to be a good test of that setup in 4-6 weeks time though, all lectures are online now

#

my money is on failing and falling over

hollow marlin
#

@solid falcon so is this like a self host Sunday project or business solution?

jaunty talon
#

@strange silo sure it would :P all depends on bitrate :D

hollow marlin
#

Well seeing how when Netflix approached us for cache for part of our network they required 10-20gb uplink with sustained 5gb usage for a similar 10k clients. Seeing how they have optimized the crap out of their streaming and Reno, I dont suspect tackling 10k users is easy no matter the bitrate

craggy parcel
#

That's quite a bit of data....

tribal patio
#

Real quick question,

Does anyone here have somewhat good Networking knowledge?
I'm trying to follow a tutorial and idk what they mean based on how they've explained it and I don't wanna fuck up the settings on My router or w/e lol

craggy parcel
#

Try asking your question, if someone has an answer, they will probably give it to you.

tribal patio
#

k so, I'm following this tutorial for trying to speed up My PSN download times for a few new games I wanna try out ( https://www.wikihow.com/Increase-PlayStation-4-Download-Speed ) and on Step-9, idk what I need to enter as Primary and Secondary.
Do I need to like, enter My IP or w/e..? I'm hella confused

wikiHow

This wikiHow teaches you how to increase your PlayStation 4's download speeds for games, movies, and other items. Taking advantage of simple Wi-Fi tricks which work for most Internet-connected items can improve marginally your PS4's...

hollow marlin
#

Other than changing from wireless to wired, none of those "tricks" will increase your download speed

craggy parcel
#

Is it the DNS part? The benefits of changing the DNS settings, are quite limited, for large services as PSN, especially if you're using a large ISP, as the caching they claim happens, also happens at your ISP and their servers are usually closer to you, and therefor will respond faster.

vapid dune
#

lol

#

these are all pointless setup

tribal patio
#

idk lol

vapid dune
#

aside from plugging your thing to a wire

#

none of it will really matter

tribal patio
#

I have 0 Network knowledge xd

craggy parcel
#

Actually the "Download one at a time" and "No playing while downloading" parts can also give better performance.

vapid dune
#

I mean you might as well try to download overnight in that case

craggy parcel
#

Yeah. 1GB takes around the same time, no matter if it's 10 downloads, or 1 download. At least if it's decent sized files.

vapid dune
#

there's probably stuff like people in your household streaming movies. or overloaded ISP problems that would make it worse. that and slow internet speeds for your plan too

#

all things that the console itself isn't in control of lol

craggy parcel
#

Depends on the household and ISP. I've never experienced not being able to download at full speed, when NOT using wireless connections.

vapid dune
#

depends on the ISP for sure. I've seen slow downs on cable internet before

swift tree
#

Powerline

#

does more adapters = less speed?

#

assuming all adapters are identical

#

also any way to improve powerline speed? I got a set of 4 TP-Link PA4010(P), all AV500 scattered in the apartment. Best connection between adapters was 85-90Mbps. Worst was 50-60Mbps, most likely due to distance between adapters

#

and tpPLC utility numbers are way off for some reason

clear igloo
#

AV500 only has 10/100Mbps ports so best case is going to be around 85-95Mbps depending on overhead

swift tree
#

wot

#

I thought AV500 = 500 Mbps

#

so it would have like at least cat5e grade ports

#

well damn this sucks

#

We just up'd our subscription from 50 to 100 Mbps

#

and we've been wondering why our powerline sucks

#

luckily wireless lan technology has been pretty good, we had no issues with devices connected on 5GHz, except for that one room at the corner of the apartment

clear igloo
#

Yah, it's stupid, they call it 500Mbps and then throw a 100Mbps port on it

swift tree
#

how isn't anyone sued yet

#

false advertising

#

clearly they are offering speeds that are impossible to achieve

#

not even theoretically possible

hollow marlin
#

AV500 refers to the signal over copper which can hit 500 in perfect conditions. That "specification" is used across all their devices with some only having 100m ports. Disclosed right in their product page.

hexed pilot
#

if you were 2 be paying for 600 mb wifi and when u connect via wifi you get 200 and ethernet about 700, would u say the wifi is good?

little schooner
#

@hexed pilot well at what link speed is the device connecting at?

#

Is it 433 mbps?

hexed pilot
#

well the speed i get when im on wifi if about 200

little schooner
#

That's about half 433 mbps

#

So it's within range yes

hexed pilot
#

nono

#

were paying for 600 mbps

little schooner
#

Check network and Sharing center > find your network adapter properties

#

Right click your net adapter and choose properties

#

It should say the link speed

hexed pilot
#

ok

little schooner
#

Find what that is and tell me

#

If it's anything like my dell laptop, it's stuck at 433 mbps

#

Account for half duplex transmission, real speed is half that number, in best cases

hexed pilot
#

390 Mbps

little schooner
#

Yeah so your getting exactly the speed supposed to get based on your link speed

#

You need stronger signal or new wifi card

hexed pilot
#

cool

little schooner
#

Do you know what wifi card you are using

hexed pilot
#

my laptop is a cheaper/2017 model i believe

little schooner
#

Before the properties window, it should list the name of your wireless adapter

#

When it presents to you all the network cards in your system

hexed pilot
#

ok

#

well

little schooner
#

If not, check device manager

#

Network adapters

hexed pilot
#

ok

#

but pretty much my question was answered

little schooner
#

k

hexed pilot
#

thanks

naive meadow
#

Heheh I love my wifi thats on my phone which does not have the best speeds at the best of times let alone with two other people on the same network

little schooner
#

@naive meadow unifi is definitely where it's at for WiFi

#

On the cheap and stable

#

And let's not forget about free updates

#

Hope they never change that

hollow marlin
#

@little schooner I think you misspelled Mikrotik

rocky badge
#

I'd much rather use UniFi for wireless than Mikrotik 😛

little schooner
#

@hollow marlin I couldn't find their switches in stock at Amazon usa

#

But wifi I never tried their units

#

Bulletproof I assume

hollow marlin
#

Rock solid

#

Outside their idiotic VLAN config, their stability is worth it over a gui

little schooner
#

Can you believe my entire kitchen was full of smoke and heat and the mikrotik powerbox kept kicking as if nothing was happening?

#

Well it's not that surprising but still

#

I like how it can survive the environment

rocky badge
#

😛 I'll keep my UniFi

little schooner
#

@rocky badge a rockin' setup there

hollow marlin
#

Should check out some of the catalyst rugged switches

rocky badge
#

@little schooner Yee, it's nice

little schooner
#

@rocky badge I'd like to have the console of an edgeswitch with the management of a unifi controller

#

Still not a thing yet?

rocky badge
#

nope, but I'd take UI + json configs on the controller 😛

little schooner
#

@rocky badge those actually work? And save?

#

But what exactly are you giving up if you can use json configs?

#

It's still not a full feature set right?

rocky badge
#

JSON configs work alongside GUI configs

#

it's CLI configs that get wiped on a provision

little schooner
#

o

bleak inlet
#

Damn, I wish I could afford a unifi setup for my house :/

#

I live alone though so really doesn't make much sense

primal ice
#

my buffalo ac1750-dhp works great as a switch/AP :p

sick owl
#

Hello. Does anyone know how to access your home network via Wireguard?

#

I tried looking online but nothing works

solid falcon
#

Hey guys has anyone used Nginx for video streaming

thorny vector
#

@solid falcon I've used it as a reverse proxy for jellyfin

cedar igloo
#

setting up pfsense on a vm. my normal router has ip 192.168.1.1 and the pfsense has a lan of the same. i have 2 NICs. can i specify to go to 192.168.1.1 on a different nic?

hollow marlin
#

No

cedar igloo
#

ok

#

change of question.
I have an internet connection with an ISP, using an off the shelf router. In my home lab, i have a pfsense router. Can i somehow pass internet over to machines connected to my pfsense router network?

#

so the isp router passes internet to the pfsense router

charred meadow
#

Put the router into bridge mode.

cedar igloo
#

i cant as the pfsense router will not have 24/7 uptime

hollow marlin
#

The routers would have to know about the routes of each device. You either do it statically or using a routing protocol which home routers most definitely dont support

little schooner
#

@bleak inlet I would get it for the wifi at least, even if I was alone. Its incredibly stable and gets updates for a long time. Sometimes those updates add new features, like 802.11 r and k roaming

#

for absolute raw speed, you can stick with consumer routers.

#

Unifi finally fixed their broken implementation of fast roaming with the last two releases

#

Its nice to be able to walk outside and see full bars without having to disassociate the entire connection

rocky badge
spark grail
#

is this at work or something @rocky badge ? cuz for me, and I live in a fairly big house, one AP does the Job

rocky badge
#

Home

steel ocean
#

anybody here experienced with OpenVPN servers on Windows VPS'?

surreal finch
#

OMG my eyes are going crossed from looking at wireshark

stable warren
#

anyone familiar with guacamole - Apache?

stable warren
#

I prefer ruckus ;)

rocky badge
stable warren
#

3 x Ruckus R510 works great

rocky badge
#

UAP AC Pro and UAP AC Lite here

stable warren
#

most of the dedicated AP's work great, must say cloudkey is really nice on ubiquiti

rocky badge
stable warren
#

yeah the dashboard is more flashy :P

rocky badge
#

Skynet is 802.1X wpa2 enterprise, IoT is just PSK but MAC limited, mgmt is PSK for mgmt VLAN

#

Guest is open limited to 5/1

stable warren
#

i got mine set to google login :)

rocky badge
#

I could do that but it's just open blobshrug

stable warren
#

well it's fun to see who try to connect :D

#

btw does Ubiquity allow for disabled frequencies?

rocky badge
#

DFS? or stuff like channel 14

stable warren
#

this

rocky badge
stable warren
#

you can't tell it what chans it's allowed to use?

stable warren
#

nice

little schooner
#

@stable warren 😂😂

stable warren
#

:P

little schooner
#

@stable warren do you get free updates with rukus?

stable warren
#

yeah, only if you use cloud stuff from them u pay

little schooner
#

@stable warren where did you buy your units from

rocky badge
#

Yeah, I like UniFi cloud connection lol

little schooner
#

At a good discount?

rocky badge
little schooner
#

@rocky badge so like a VM you pay resources for to host it?

#

How do you secure that

stable warren
#

i got them from a local supplier, flashed them to unleashed firmware and no more ruckus enterprise moneys anymore :)

little schooner
#

Vpn only?

#

@stable warren I see

rocky badge
#

It runs on MacOS/Debian/Windows/any other Linux

little schooner
#

Neat

#

@rocky badge but how to secure it when it's in cloud?

stable warren
rocky badge
#

it talks to your controller with your Ubiquiti account

stable warren
#

or just have your own vm's :D

little schooner
#

Oh ok

rocky badge
#

your Ubiquiti account is an admin on the controller

little schooner
#

Ah

rocky badge
stable warren
#

kinda like not being dependent on cloud stuff though, openmesh has it also.. all is fine when AP's stay on and internet is down, once internet goes down and people reset their AP's it goes to shit

rocky badge
#

The devices don't talk to the controller via cloud

#

It's all local

#

I can access the controller via the cloud for remote management

stable warren
#

k

#

blob any chance you know about apache guacamole? :P

rocky badge
#

Yes

stable warren
#

i don't get how to get my computers in it :X

rocky badge
#

MS RDP/VNC/SSH

stable warren
#

any

rocky badge
#

Although I've been looking at this

stable warren
#

yeah looks somewhat easier

#

used docker for it but wtf pain in the @$$ to get it running

tepid trail
#

Thinking of buying a Ubiquiti EdgeRouter ER-10X router. Any experiences with that?

#

my plan is to add a Ubiquiti AP to that.

hollow marlin
#

Whats you home connection? If I remember that thing cant handle much

tepid trail
#

Got a fiber connection but im only on 200Mbit up/down. Did not buy any more. 1000Mbit is supported though, but is more expensive ofcourse.
1gig on the LAN-side.

#

I want it to be some what future proof at least handle 1Gbit on WAN

#

If that is not your recommendation can you please suggest an alternative similiar?

hollow marlin
#

Its cant handle gig unless its full 1500byte packets

primal ice
#

got old hardware laying around?

tepid trail
#

Yes, but only ATX form factor.. would go for something smaller lite Mini-ITX or something.. uATX..

#

Got a Intel E6600 and a Asus P5B-deluxe motherboard.. 8gig ram.

primal ice
#

i'm using a i7-950 p6x58-e as a pfsense box.

tepid trail
#

Yeah, been thinking of building my own..

rocky badge
#

The ER-10X's ports are connected to a switch witch is then connected to the CPU, maxing out at gigabit

#
As  @UBNT-Vlad  said, the issue is that every ethernet port is connected to a switch, and this switch is connected to the CPU routing engine via a single 1Gbps link.  Having all the ports connected to a vlan-aware switch makes the router much more flexible, but the price is that the 1Gbps link is a potential bottleneck for traffic that must be routed.  This includes any inter-vlan (between vlan) traffic, but does not affect the intra-vlan (within vlan) traffic, which is switched, and that traffic never even reaches the CPU routing engine.


hollow marlin
#

I was more pointing at that it can only route a gig on 1500byte packets. If a router cant route gig at 512 then its a terrible router for gig

tepid trail
#

So.. that router isnt bad or "good enough" for my use?

hollow marlin
#

Its not bad at 200, it is at a gig

little schooner
#

@hollow marlin does the er lite route at gig 512?

#

Well maybe I can check

#

Oh nice it says 3gbps line rate

hollow marlin
#

What's the 64byte pps?

little schooner
#

1,000,000 pps

#

@hollow marlin how would I know if 1,000,000 pps is good for gig line speed across 3 ports?

queen pelican
#

So I currently use a google wifi cluster of 3 around the house, works fine not the issue, I need more configurability at a router level so I was thinking of just pushing the nodes behind a router effectively double NATing them. Any recommendations on routers that can handle high throughput? (with or without wifi as its going to be disabled anyways)

#

was thinking of a EdgeRouter X. open to suggestions

#

actually maybe the EdgeRouter 10X might be a better choice

queen pelican
#

actually maybe the ER-4

hollow marlin
#

@little schooner 64byte is worst case scenario so take 64x1,000,000x8=512mb/s, so it cant handle a gig under that load. But you want pps on 512bytes if the vendor supplies it as that is the average typical size. Depending on whether its good or not depends on your use but like in the case of the 10x, it can only do gig at 1500bytes. That means if any other traffic hits the router other than 1500 gig is already out the window. Not including the performance hit if any other features are turned on

little schooner
#

@hollow marlin thanks for clearing that up

#

@hollow marlin but one more question, how could they raise 64 bytes to be higher in mbps

#

Or they can't? It's really just worst case

#

In other words, don't let the packet be that small?

hollow marlin
#

They would need better silicon to handle high pps. Either better hardware switching/routing or a beefier CPU to handle everything the chipset cant

little schooner
#

Ohh. So the cpu wasn't in that equation. The equation comes in after you get the pps value

hollow marlin
#

Reason being is when a packet is processed in a basic switch or router it only really needs to reach the L2/3 header which is consistent across any packet size, payload size really doesn't matter.

#

That's where pps become the best metric for performance as long as you have the packet size

little schooner
#

But because it so small, so many of them could come in all at once

#

Vs many big 512 ones

#

That's where it gets trapped?

thorny vector
#

Yeah. imagine 8 3 lane highways being forced to merge onto a single 3 lane highway. Fine if traffic is light, but lots of traffic will bog it down.

hollow marlin
#

Well if you are using SIP at home you router is getting a constant stream of 64byte packets. Not in the 1000s per sec but still. That's why I said 512 is the best pps metric to look at to determine real world performance.
In enterprise. 64bytes packets are a real focus with vocie, DNS, DHCP, per segment protocols, etc.

hollow marlin
#

You'd be surprised what a building of even 500 employees pull. Also Ubi is not enterprise no matter what they say

#

I'll have to grab some stats of one of our cores. Haven't checked in a while but we have a tone of <512byte traffic. But our smallest core can handle 1tbps at 512 so little to actually worry about

waxen scroll
#

@hollow marlin depends on business. most of the time its not used for personal use, so you can see 500 people on 10mbit internet

#

the bulk of the traffic is over private circuits with internet only used for some google or whatever

hollow marlin
#

You can but you shouldn't lol. Also both circuits tend to be handled by the same equipment so private or not need to be able to handle the load. This is all getting way to not picky but the amount of times I handle customers that are complaining that their circuit isnt performing as necessary is almost always due to underpowered hardware with horrible configuration to make it worse

strange silo
#

Biggest problem I have is the specific configuration implications on the hardware capabilities and performance, the spec itself sometimes is not enough

#

Take for example my Fortigate 60D, it'll do 1.5Gbps at 64byte firewall throughput but only if the configuration supports the ASIC offload

#

My ISP uses PPPoE and VLAN tagging from the ONT so I have to configure a vlan sub interface and then configure that sub interface as PPPoE type which when that connects it creates a dynamic sub interface under the VLAN sub interface

#

Which means no ASIC offload so goodbye 1.5Gbps throughput

#

Remove either the PPPoE or the VLAN tagging and hardware offload is then supported

#

It's the double layer sub interface that's killing it

#

Stuck at 100Mbps on a 1Gbps/1Gbps plan lol

#

Need to setup the hEX as a bridge and hide all the BS from the firewall

hollow marlin
#

That was my point when I mentioned to Xeon that pps is without any features. Mikrotik as you know has too many quirks where a single protocol with knock it out of fastpath and straight to the CPU. I see this with Juniper as well in their SRX series that we deploy.

strange silo
#

That's the problem with spec sheets, nice numbers but.....

hollow marlin
#

Luckily the top vendors will include the specs within the datasheets but even then tends to only be the top tier equipment

strange silo
#

Well even though mine has that all listed it doesn't stop the problem I have and you wouldn't know until you deployed it and then ran the diag traces like I did and look at the hardware offload state

#

Because none of the documentation covers it either, it's in that "too obscure" hell hole

#

@hollow marlin You got a known config to bridge an interface from a hEX to a firewall?

#

Still want the public IP on the firewall but need to strip off the VLAN or the VLAN and the PPPoE auth

#

Or would I just be better off setting up routing? Guess that would be easier tbh

hollow marlin
#

@strange silo set interface ethernet switch port ether2 vlan-mode=disabled vlan-header=always-strip default-vlan-id=[pppoe-vlan] might work. You can leave the WAN/LAN in the bridge and let the switch chip just strip on egress.

#

On WAN try set interface ethernet switch port ether1 vlan-mode=disabled vlan-header=add-if-missing

#

I know hEX has very basic switch chip functions but if it does work will hopefully work with HW offload

tepid trail
#

mynameisjuan, ok. do you have any suggestions for another router around the same price range and specs?

#

that will do better at gigabit?

hollow marlin
#

If you are going Ubi I would still with that for a single pane of control. The USG (smaller one) I think can do gigabit with everything turned off. If you have extra money you can pick up the USG pro you can do it with IDS/IPS on (which really dont matter with their type of implementation)

thorny vector
#

buy a cheap server on ebay, and put pfsense on it 😄

hollow marlin
#

Or just stick with a fanless less power hungry option

rocky badge
#

@clear igloo yeeeet

#

Visual Studio Code + code-server + AWS EC2

clear igloo
#

Yeet all the code?

rocky badge
#

Yes

queen pelican
#

So what’s the theoretical transfer on the er 4? For 64 byte packets it would be only 217mb / s?

queen pelican
#

Did the math wrong is 1740 mb / s right?

earnest wasp
#

@rocky badge what's code-server's extension compat like?

rocky badge
#

It can install anything visual studio code can

#

it's basically a remote instance of visual studio code

#

which clients can connect to

earnest wasp
#

huh.. might have to give that a shot. I already use the remote SSH extension for 99% of my dev but the idea of just being able to pop open my dev env in a browser is kinda neat.

rocky badge
#

yup

strange silo
#

@hollow marlin Would you still do that over just setting up routing to the firewall? I can still have my 8 extra IPs off loopbacks or on VMs on/behind the firewall. My extra 8 IPs are an entirely different subnet assignment and my ISP has a route for those to my primary default IP address handed out via the PPPoE static IP. I'd just need to hide the private IPs from traceroutes that I'd have to use between the hEX and the FortiGate.

hollow marlin
#

I would still do that and hand everything off from the hEX to the Forti. While I love Tik the Fortigate is better suited to handle everything. First it eliminates issues with going through 2 firewalls, second it eliminates translations.
Just easier management in the long run. If you do go just routing between the two just block udp/ICMP from the subnet between them in the hEX.

#

That way PMTU isnt broken in the process to your servers/VMs

lean pollen
#

We have had some problems with Wifi

#

anyone knows what this means and if its related

#

have no idea if those thing I did hide is worth hiding but did because why not

hollow marlin
#

What problems are you having exactly?

lean pollen
#

Sometimes internet connection on wifi stops working for a little while

#

on some devices

hollow marlin
#

Not much given for the cause other than devices leaving then connecting back. Any recent firmware or possibly on a similar channel as another AP?

lean pollen
#

It did not leave and come back

#

router is on latest firmware

#

why is it changing whatever threshold it is back and forth so much?

#

Well, correction, device did disconnect and recconect, but that was done manually AFTER the problem situation had started

rocky badge
clear igloo
#

Very cool 🙂

little schooner
#

@rocky badge does DC-TestDeploy as a name for testing domain controller provisioning make sense?

#

or could I word it better

rocky badge
#

I mean, yeah whatever works for you. That's descriptive enough for a homelab lmao

little schooner
#

it just... i dont like it xD

#

it doesn't sound right

rocky badge
#

my domain controllers are ws2016-dc-(x)

#

where X is a number

little schooner
#

hmmm

#

well i guess I could give it a letter or specific number

#

since it will never change

thorny vector
#

@rocky badge nope, needs more hyphens and descriptions 😛

little schooner
#

think i'll use x to symbolize it as "use this VM to dump deployments on and see if it works"

#

DC-X is what i'll go with

#

thx

rocky badge
#

🤔

little schooner
#

$$$

#

$300 is like me paying for comcast fiber

thorny vector
#

jesus. It'd be cheaper to buy that equipment

rocky badge
#

Cloud > on prem for this

#

So far 😂

little schooner
#

@rocky badge what web app is that

rocky badge
thorny vector
#

lol, fair enough

little schooner
#

looks so cool

#

dang

#

powerful!

rocky badge
#

ya

little schooner
#

@rocky badge do you believe in the 15 character limits for server names outside of windows?

#

I personally like descriptive names

rocky badge
#

nope

#

if I could redo my school's naming scheme...it would be long

little schooner
#

yeah. i wish i made our labs names longer

#

my prof asks me what all the abbreivations mean

#

and i tell him its in the docs

#

but no one likes to read the docs

rocky badge
#
Switches:
switch-[school]-[unique switch #]-[room #/IDF #]-[connecting switch #]
APs: 
ap-[school]-[room #]-[connecting port #]-[connecting switch #]
``` Domain controllers/file servers/etc are all fine...but switches are just `switch-mac-randomshit`
thorny vector
#

no one reads em, but god forbid if you don't document how you did something new

#

and I like that. looks like it makes troubleshooting network issues so much easier

rocky badge
#
Ports on the wall
[switch #]-[port on switch]
Ports in management
[room #]-[switch #]
little schooner
#

yeah that would make it super easy

#

no guesswork

rocky badge
#

And I would defo redo the subnetting and VLANs

thorny vector
#

how do you like to do your subnetting?

#

I usually just slap a /24 on everything

little schooner
#

my prof likes /24 a lot

#

even when we need more than that for wifi access

#

he mentioned something about telling the students manual fixes in a pinch

#

like "go to your ip settings and try using this ip with this subnet"

rocky badge
#

Something like this for hs

little schooner
#

looks good

#

@rocky badge do you know how those ID door locks work? are they hardwired into a system with ethernet or something?

rocky badge
#

yes

little schooner
#

I see teachers at university put their badge and then enter pincode

rocky badge
#

RFID

#

Central management appliance is a VM

little schooner
#

dang, how do they fit the wires in the door like that?

rocky badge
#

beats me lol

little schooner
#

I want a system like that for one room at home

#

if its being rented out

thorny vector
#

Depends on the kind of reader. I do physical security too, usually you have it in the wall

#

not the door

rocky badge
#

Yeah, our outdoor are in the wall

little schooner
#

At the school i volunteer at, yeah they have it on the wall

#

looks like they havent changed it in forever though

thorny vector
#

rfid is old tech, and a pretty stable standard

little schooner
#

true

rocky badge
#

yup

thorny vector
#

honestly, the old systems are probably hard to physically expliot. there are some really nice pentesting tools that you literally just crimp into the cable that runs from the reader antenna to the processing hardware, to clone creds

#

but older systems, at least the ones i've opened up are single wires, not labeled, all rat nested together. no easy open, crimp, close for that.

rocky badge
#

oof

#

this is a lot of vlans

#

(2 out of the 8 elementary schools) big oof

#

yee boi at 84 vlans and counting

#

@thorny vector @little schooner Do you start VLANs at 10 and then go up from there? Or 1, 2, 3?

thorny vector
#

I usually catagorize em by the 100's, with each multiple of 10 inside being a different segement

little schooner
#

Yeah we started at VLAN 10 and used 10 increments

rocky badge
#

@thorny vector ooh yeah

little schooner
#

and anything in the middle, like 11,12 are if we need to add more to that specific department

#

well, i never had to go that far yet

#

i only worked in small environments

rocky badge
little schooner
#

@thorny vector also, I noticed switches from netgear want to reserve the lower vlans and dont let you change them

#

so starting at 10 avoids those vendors oddities

thorny vector
#

that's only on my personal stuff. I never really have to do much networking work, since I'm a security guy. And yep. My homelab is a ton of used hardware, so the stuff I do is pretty hardy against weird manufacturer crap.

rocky badge
#

Yeah at home it's 10/20/30

#

Etc

little schooner
rocky badge
little schooner
#

My prof thanked me so much for helping him all summer with it

strange silo
#

@little schooner @rocky badge Server names should just be asset numbers or GUIDs etc then create CNAMEs for descriptors

rocky badge
#

You could do that ye

strange silo
#

no actual reason to specifically name the OS something meaningful 🙂

thorny vector
#

^

little schooner
#

I use asset numbers to assign computer names a hostname during deployment

#

but im not sure if that is inefficient

rocky badge
#

Most of my edge servers are that as well

#

edge-random shit

little schooner
#

I pull the serial numbers from excel file

rocky badge
#

Then cname to actually useful stuff

little schooner
#

@rocky badge some service I ran into problems with didn't know how to work with cnames

#

but I dont remember what it was

rocky badge
#

Oof

little schooner
#

but it was a pain

#

the troubleshooting

#

wasting time

#

most things should work with cnames

strange silo
#

I hate the ones that take the cname and then translate and store the real one and discard the cname lol

#

why.....

little schooner
#

yeah that problem too

#

like cmon

#

forgot to tell you that like 7 months ago

strange silo
#

yea I 100% remember the context around that 😉

little schooner
#

Yeah. My prof was having a hard time figuring it out

#

but all i did was follow the docs carefully

rocky badge
#

@thorny vector would you just pool all guests together, or guest VLAN per school

little schooner
#

@strange silo and unfortunately we did a non-standard rack design, so if it ever has a problem

#

he's outta luck

thorny vector
#

depends. I would probably do it by school if those segments can touch each other, but it probably wouldn't matter

#

I tend to err on the side of caution and division

little schooner
#

@rocky badge does it make a lot of sense to put different schools on the same vlan, if they are associated with the same group type (like Student Vlan, Teacher VLAN)?

#

or nah

#

or dont even bother linking them like that?

rocky badge
#

Nah, per school VLAN with per student teacher, that shit gets crowded

#

1:1 devices, mobile devices, iPads, desktops, laptops

little schooner
#

ahh so you would even have a vlan just for ipads

rocky badge
#

The most I've seen on the network was ~80k devices for a school with 8k students

little schooner
#

yeah thats a lot of devices

strange silo
#

Grouped VLANs per school, I'd never want to have to go back and segregate after the fact

rocky badge
#

^

little schooner
#

okay

#

yeah that sounds more managable

thorny vector
#

Could you imagine a vlan for each type of device -_-

strange silo
#

Nice thing about any decent wireless solution is you can just have multiple VLANs and subnets in a guest network group so you can keep it simple for techs to look after, just keep slapping on /24 as you need more

#

trying to explain /22 to a first time ever employee is just a pain lol

rocky badge
#

Lmao

little schooner
#

yeah my prof doesn't like anything except /24

#

he said anything else is too complicated

thorny vector
#

eww, get that dirty subnet away from me

strange silo
#

we have /22's and /23's etc

#

all sorts

thorny vector
#

calling it too complicated is a bit much, though

strange silo
#

it's not, after time

little schooner
#

I think because he has a lot of responsibility on his plate

#

he doesn't want to be stressed out

#

even though the docs are there to guide him

#

he teaches like 5 classes and gives workshops to business around town

strange silo
#

but basically all learning is centered around .0 is network, .255 is boardcast and .1 is gateway which is 100% inaccurate in practice

#

literal mind explosion when you encounter anything else

#

for the first time

little schooner
#

true lol

#

Im so used to home routers making it simple at the beginning

thorny vector
#

I was confuzzled when I realized when I tether stuff to my phone, its a /24 network where .192 was the gw

strange silo
#

lol

little schooner
#

I only got into networking because my computer hardware prof told me they hired a new guy whose really good at teaching the content

#

thats when they started using netacademy

#

I definitely made a great decision

strange silo
#

company I used to work for would pretty much give anyone a shot and hire them, it was a great place to start out in the workforce as it was one of a few willing to do that but it required a lot of careful design choices to be able to support that

thorny vector
#

Do some security training too if you can fit it in

strange silo
#

And every tech had domain admin access to every client #yolo

thorny vector
#

wut

strange silo
#

hahaha

little schooner
#

I like having that kind of access, but worried if someone were to get a hold of it, they could destroy it all in moments

#

I made myself a standard account at the lab

#

my prof prefers his domain account though.

#

I can't get blamed for big system changes

#

my account cant make em

strange silo
#

I still know how to access pretty much every client from that company

thorny vector
#

like, really. I have 3 personal accounts on my domain, each with different permissions just because of that

strange silo
#

and that was 6 years ago

little schooner
#

@strange silo nice to have keys to the kingdom follow you around

#

heh

#

Why are OEM-motherboards the only ones that get serial numbers?

#

I tried to find my asrock serial and it comes up blank

thorny vector
#

Like, in system info, or on the board itself?

little schooner
#

makes it harder to do deployments since I rely on the serialnumber for hostname

strange silo
#

you using software to check or actually looking at it?

little schooner
#

yeah in system info.

#

software

strange silo
#

yep that's normal

little schooner
#

wmic csproduct get IdentifyNumber

#

would print the serial

#

Im using uuid now

#

but its so much longer

strange silo
#

I've also had gaming motherboards use all FFs for PXE or all 0.0.0.0 and other weird stuff for god knows what reason so every network protection kicks in and shuts that down so you can't PXE boot

little schooner
#

yeah like wth

thorny vector
#

yeah, consumer boards usually don't have that loaded in, at least in my expirience. No real need for em to, since that'd be an extra step in production for a feature the target demographic wouldn't use

strange silo
#

PC- "I WANT TO PXE BOOOT!!!!!"

thorny vector
#

lol

#

GIVE ME IMAGE, NOOOOOOOW!!!

strange silo
#

It's why I do actually like HP so much, or did when I still did that stuff

#

And Lenovo for laptops

#

I think it was IBM/Lenovo that did SCCM driver package downloads first, so great

thorny vector
#

I still have nightmares about reimaging with pxe

#

shudder

strange silo
#

Never had an issue with the HP Elite line of desktops

#

they only used 1st party standard chipsets etc

#

zero pain

little schooner
#

The biggest tip I learned about reimaging with pxe was to make sure that Portfast was enabled on all edge ports because some NICs would reset their link and the Cisco switch would take too long to get a link for pxe boot to happen

strange silo
#

HP laptops though, eh not so much

little schooner
#

As soon as I did that in my professors lab, he was so excited that he could pxe boot all his images

#

before, he was doing them 1 by 1 by hand

thorny vector
#

whooooooo, you wanna talk about chipsets? I built a custom esxi server into a portable case, using cheap consumer hardware. BOOOOI, lemme tell you what. Intel chips do a loooooooot of stuff they say they don't support

#

sorta

#

if you ask nice

strange silo
#

If you want to have some fun with SCCM create a mandatory OS deployment task sequence deployment to the All Systems collection