#networking
1 messages · Page 344 of 1
😂 sounds indian.
thats what airtel did lmao
Airtel VFibre is horrible. One of my friends has 300Mbit there, I told him to speedtest to bunch of european and US servers he got like 2Mbps and 5 or so. I told him, now speedtest to a Indian server he got 290 or so
This is pure ISP tactics
bro i swear airtel broadband is not good thass y i switched to ACT
One thing of airtel is they have a lot of coverage in the smaller towns now.
No more stupid ADSL from BSNL
🤣
i have airtel cell i get around 100/50 on that
lmaoooo my grandparents have that
Ah, 4G you mean. yeah the speeds can be pretyt fast if congestion is not present
yea, tried jio was pretty unimpressed with 4g speeds
Well all the congestion will build up 🤷♂️
There's congestion on the cell towers itself, limited TDD bands stuff, and then the actual bacbone between them
and then the actual actual bacone of it 😛
anyone here know what os and config i can use for a wireless/wired storage pc
@indigo ore what exactly are you looking for?
a good way to store audio video pictures wirelessly to a computer
So a NAS ?
pretty much yeah
NAS can be connected to your local network with a cable
Would be available over wired ethernet on your LAN, or WiFi
@indigo ore are you DYI-ing the storage box?
because you can just use a commodity NAS for this, hook it up wired
diy yeah
just a budget computer for it
a NAS isn't anything special, its just a computer with storage and network
and a program to provide this storage over the network
@indigo ore any experience with Linux? because if you don't, might want to look into TrueNAS or FreeNAS
Those are ready to use operating systems, that make it easier to manage volumes, shares and such
some experience with linux not alot
On linux you'd have to do it by hand
prolly gonna do truenas or freenas then
@indigo ore on linux its not that complicated, but you'll have to configure Samba by hand
on TrueNAS you can just use a web interface to configure
thanks for the help nonetheless
@tame carbon do you know by chance on a good hosting company that have cheap storage boxes in Europe ?
truenas is freenas
just rebranded
use truenas now
@lean pebble not really
truenas makes me happy
why is a netgrae ReadyNAS so expensive its just a shell with a low powered computer
its' not really a low powered computer
@lament night its a turn-key solution, ready to use. You pay for this
The product is "worth more" than the sum of its parts
so your basically paying for convenience moar than theparts
cool got it
but my rpi4 nas works fine whats the difference b/w that and readynas
pi doesn't compare
doesn't have that much io
i mean i only have 4 tb hooked o nto it rn
1 tb wd drives in each usb slot
i agree its not as fast as pcie
but its fine for what i do i rarely use it i just store pictures and stuff lol
any redudancy
yea raid 1
i have the one with 8 gigs of ram
so you only have 2 tb?
@lament night just install samba on it 
that's not gig tho
yea i use only arounf 100-150 gb at the moment
tho
i also have a pi 2b+ running pihole
ob yea the pi4 is like tho only one even worht buying
The Pi4+ has LPDDR4, and can push about ~4GB/s of memory
but i had pi2 on hand so y not
@lament night or for a DNS server its fast enough
hmm yea
but the Pi4 is great for a NAS, unlike the 3b, the pi4 has seperate busses to the CPU For the USB and network controller
I got rid of my vpn on a pi and it's on a VM now
on the pi3 the network controller is just a USB device on the same USB bus
so if you used it as a NAS, the network would bottleneck the USB bus
and vice versa
effective bandwidth out of a pi3b+ as a NAS was like 80-100mbit/s
300mbit/s on the pi4+ (if you do streaming from memory, it can handle ~800mbit/s raw throughput)
You wont ever get gigabit speeds out of the pi, regardless
i have problem my internet speed is 100mbps, but i get like 300 ping on games. But on my phone everything runs smoothly in 20-60 does anyone know what to do
@final pasture open a terminal and run: tracert 1.1.1.1
post a screenshot with the output
but will it give my ip address
no it won't
crystal@servomat:~$ traceroute 1.1.1.1
traceroute to 1.1.1.1 (1.1.1.1), 30 hops max, 60 byte packets
1 router.redacted.nl (192.168.88.1) 0.231 ms 0.207 ms 0.198 ms
2 r2.serv.dro.weserve.nl (46.243.152.3) 6.178 ms 6.232 ms 6.281 ms
3 46.249.55.194 (46.249.55.194) 8.871 ms 6.938 ms 7.244 ms
4 185.8.179.33 (185.8.179.33) 12.512 ms 7.840 ms 7.875 ms
5 ams-ix.as13335.net (80.249.211.140) 8.945 ms 8.886 ms 8.876 ms
6 one.one.one.one (1.1.1.1) 8.136 ms 8.188 ms 7.900 ms
^
It only has the local IP of your router, and the IP of your ISP's router
your public IP is not listed
^
@peak cloak been using gitea extensively for 2 weeks now
ok just sec
already found a bug
xD
So I'll be doing my FOSS duty, and reporting on it in detail
Doesn't look like there's a line issue
checks out fine, ~9ms
@final pasture is the problem intermittened?
@final pasture do you know the server IP ?
if you ping that address directly, what does it report then?
my laptop wasnt on for like 4months but before that everything was fine
???

Try to traceroute to roblox.com
i mean i have like 500gb storage
that is irrelevant
what does that mean
idk english that well
Literally what you just did
you did a traceroute already, but to 1.1.1.1 (cloudflare DNS)
tracert roblox.com
ok
traceroute just shows us the path that your data takes
it helps with identifying where the lag is coming from
Show it when finished
Does it not just stay there
it closes right away
Did you open cms first
no
Open cmd
ok its working
its crossing the atlantic
bruhhh i live in south eu
idk how to do that
look in that last screenshot you sent
you can see hop 9
that's in paris
then next router it hits, is on other side of atlantic
but i dont live in paris
so latency goes up (this is normal)
@final pasture but the router routing your packets, is
Hop 1 is your router at home
exactly
@final pasture just to prevent you from getting confused: there's nothing wrong with your internet
all is working fine
but how tf im getting 500ms
I was just explaining what that traceroute is showing you ;P
uhhh you just connect
No clue
click play and
you cant connect to the server, but the problem is 4mothns ago my roblox runed like perfectly smooth
@final pasture I think this is something on Roblox' end
i can load up minecraft and see the ping
and not something you have any control over
i think so
Your own internet checks out fine
its using HE's network, which is also fine
HurricaneElectric generally has very good reliability
but tbh i was downloading something from internet its 4gb file but my speedownload was 50kbps
i tried from another site same file it was 20-25mbps
@final pasture mh hard to guess what that could be
without testing, we'd just be guessing
ill try other games
it says i have 0 packet loss on google and 32 avg ms
but on roblox it says avrage 125
Yeah
The issue is latency. Downloading single files at that high of latency will drop your speeds significantly depending on the latency to the site.
ik
is this bad
🤔 Never heard of Lifi before. Sounds like an interesting idea. Kind of like fiber technology that also uses light, except it'd be open air I guess. 🤷♂️
I think a wireless standard that utilizes both wifi and lifi would be best.
Think if i get a 350 foot ethernet cable and run it thru a small lake it will work?
Ofc having the plugs out of the water
Just the cable submerged
it would I think
I would use fiber
Corrosion resistant and future proof
Os3
anyone know how to hide local network devices from a ubuntu server and only allow traffic through wireguard ive tried this rule but it caused me issues like bad lag spikes and things not connecting properly ```#PostUp = iptables -I OUTPUT ! -o %i -m mark ! --mark $(wg show %i fwmark) -m addrtype ! --dst-type LOCAL -j REJECT && ip6tables -I OUTPUT ! -o %i -m mark ! --mark>
#PreDown = iptables -D OUTPUT ! -o %i -m mark ! --mark $(wg show %i fwmark) -m addrtype ! --dst-type LOCAL -j REJECT && ip6tables -D OUTPUT ! -o %i -m mark ! --mark>
So you want devices though wireguard to only be able to go to the internet
yeah so i run a minecraft server on it and the wireguard connection goes to a vps to hide my ip but if someone installs a dodgy plugin to the server it has access to my full network which is not ideal so that rule postUP makes all none wireguard ip addresses unreachable
So you want it to just have access to the server
Ok
Huh I'm not very good at iptables so idk
yeah i have iptables on the VPS set up to reroute any incoming traffic on certain ports to the wireguard client ip address
well.... today is gonna be a fun one XD lost the password to my CA's key 😂
rip
this is gonna suck big time.... time to reissue and trust a new CA cert 😂
but i dont know how
@opaque stirrup you have two networks right?
I don't think he does
just need an iptable rule with those filters, and then drop the traffic
as like in vlans or subnets
wait, between his wireguard server and client
ubuntu uses ufw
he doesn't use another subnet?
but if i drop the traffic then wireguard will go down
no
@peak cloak okay then use ufw
Ubuntu is an open source software operating system that runs from the desktop, to the cloud, to all your internet connected things.
@opaque stirrup what is this? minecraft?
yeah
@opaque stirrup we've done this before lol
both
he needs NAT
ah
the rule above that i sent works but it also drops the 127.0.0.1 traffic so everything takes a fit
just doesn't want the vps to be able to connect to any of the lan computers
yeah give me a sec
don't drop 127.0.0.1
i dont know linux networking
this is literally so simple on windows its 1 button lmao
no this is just networking in general
:doubt:
a button that is made for every scenario?
I wish
thats what i need
Pretty sure that 1 button hides layers of complexity,
all that button does is change this AllowedIPs = 0.0.0.0/0, ::/0
i do the same on linux and ip tables still routes in the background
That's on the server side, that only refers to the tunnel itself
what addresses can be reached by the client
0.0.0.0 means it can route out to anywhere
when i turn it off it shows this AllowedIPs = 0.0.0.0/1, 128.0.0.0/1, ::/1, 8000::/1
can someone write an iptables to drop 128.0.0.0/1 ?
ufw deny from wg0 to 192.168.1.1/24?
@peak cloak that's actually a bit more complicated
no its not just from wg0 its like i want the full ubuntu server unable to access my network
oh
@opaque stirrup where is the wg server
then that's not done on the server
the wg server is on a vps
ok and the client is what?
you need to modify the fw on the client
so you want to be able to access it, but not allow the server to make connections to LAN
yeah
and this ladies and gents, is why you buy a proper router
yeah or just block the traffic altogether
where I isolate most of what I expose
wdym
this rule worked though it just also removes 127.0.0.1
#PostUp = iptables -I OUTPUT ! -o %i -m mark ! --mark $(wg show %i fwmark) -m addrtype ! --dst-type LOCAL -j REJECT && ip6tables -I OUTPUT ! -o %i -m mark ! --mark>
#PreDown = iptables -D OUTPUT ! -o %i -m mark ! --mark $(wg show %i fwmark) -m addrtype ! --dst-type LOCAL -j REJECT && ip6tables -D OUTPUT ! -o %i -m mark ! --mark>
I configured it in a way that I can still ssh into the servers
but not the other way around
pretty simple
My VPN server is @ home
and my clients just get an IP on a different subnet, and there's no real fw in place between that and my LAN
why not put a fw in place?
is there a way to modify the rules above or add one after that allows the "lo" adapter to be used
Because I use it for remote access and management of my servers
what do you think my LAN is
wdym
I haven't really put any seperations on my local network
only really a DMZ for public range, and the Smart home devices
and wireless access
my servers each have their own public IP over a vlan, and another local IP on my lan
and then there's just a fw rule that prevents local traffic to these servers, from anywhere but the port that goes to my bedroom
and vpn
the key for which is on my laptop, encrypted as well
fixed it i think ```PostUp = iptables -I OUTPUT ! -o %i -m mark ! --mark $(wg show %i fwmark) -m addrtype ! --dst-type LOCAL -j REJECT && ip6tables -I OUTPUT ! -o %i -m mark ! --mark >
PostUP = iptables --append OUTPUT --protocol all --src 127.0.0.1 --dst 127.0.0.1 --jump ACCEPT
PreDown = iptables -D OUTPUT ! -o %i -m mark ! --mark $(wg show %i fwmark) -m addrtype ! --dst-type LOCAL -j REJECT && ip6tables -D OUTPUT ! -o %i -m mark ! --mark >
PreDown = iptables -D OUTPUT --protocol all --src 127.0.0.1 --dst 127.0.0.1 --jump ACCEPT
Just create IPtables output rule of OUTPUT drop dst. [LAN-subnet]. This will block traffic to the LAN but allow incoming connections
is that it above because everything is running smooth now?
like this?/
iptables --append OUTPUT --protocol all --dst 192.168.1.0/24 --jump DROP
Id have to brush back up on IPtables syntax but that'll work. Not sure why you have 127 rules because outside some specific scenarios it wouldn't be applicable
and iptables --append OUTPUT --protocol all --dst 192.168.0.0/24 --jump DROP since i have a double NAT
without the 127.0.0.1 rule the game done this https://streamable.com/93fu33
what?
this is with the https://streamable.com/lrjxx2 PostUP = iptables --append OUTPUT --protocol all --src 127.0.0.1 --dst 127.0.0.1 --jump ACCEPT
this would never have been an issue if i had managed switches and a decent router 😦
its going to be used for 2 weeks
and its only like 10 ft deep
u know that moment when the powerline adapters should work, but they just straight up dont
@humble cloak different phase
my tplink ones died after like a year of using them
typical
Oh no actually it does connect to each other, but it somehow won’t connect to the router
(All fritzbox)
To integrate it into the mesh network I need to press the WPS button on my 7590, but that model straight up don’t have one
okay so the wifi is my laptop, the first in the row (with the powerline next to it below the bridge) is the 1220E that is connected to the router via ethernet
but apparently it doesnt recognise that????
according to my router the 1220 straight up dont exist
you have 2 routers?
@tame carbon Cienas look so good when done right
what 1220
Fritz!Powerline 1220E
oh
@hollow marlin that looks beefy
does anyone know how i can check?
@humble cloak you need to make sure both are on the same electrical phase
you mean like group?
well, some groups can be on the same phase
because they are on the same group lol
yeah im getting an internet connection (somehow) when i pulled the other set out of the plug
as im connected to this network and can keep talking
but it should automatically take over all the mesh network settings
currently there are two different brands, a tp-link and the aforementioned fritzbox
but we want wifi in both my sleeping room and in the garden
(this ethernet is kinda cursed ngl, first it goes with powerline to the shed, then with a PoE injector to the camera)
so that means one set of 1220E + 1260E + 1260E
I'm in a pickle rn. I am moving and I have a choice of two ISPs (Comcast and Starlink). I HATE comcast with a passion, but since starlink is in beta, it is not certain if I could get my dish right away. What would you recomend? Drop the 500 bucks and get the dish asap? or get a short plan for comcast then switch to starlink?
@clear igloo This guy in another server is getting 3.2Gbps on 5G UWB 
Nice
can anyone here explain to me why i have 100+ ms in discord and csgo but when i speedtest i get 41 ping ?
What?!? 😱
getting the dish I wouldn't really worry about I think
I would worry more about service disruptions
fyi the dish actually costs around 1500
they subsidize the cost tho
I'm really into spaceflight so ik all this
So do I pay them the 500 or do they refund me the other grand or so
no for you it's 500
Oh the parts cost is what they pay
I'm talking manufacturing costs
because the tech is so advanced
also apparently from other starlink users you prob want to get your own router
and you need to setup everything up yourself
Thats ok with me, I mainly am frsutrated as I cant get a phone call to ask about all them about all this stuff
tesla and therefore starlink aren't very good with pr I heard
I would have to wait. I know it is already Mid 2021
where do you live?
America
general area
Southwest
huh, the south should have pretty descent starlink coverage
I mainly need to drop the money for it, but I have to get into the place first. Wheras with Corruptcast, I can get service in a week tops
yeah
I have the 500 sitting there, but the wait is hard
Plus I am paying the bill for 5 people
spacex is REALLY rapidly launching them
almost all of their launches rn are starlink
it's like
They just launched a bunch a few days ago
another starlink, urgh
yeah
this is pretty cool
soonish we will have 2 other competiters
oneweb
and kuiper
yeah
how long is the comcast service contract
If you have other options that are reasonable cost and bandwidth, you shouldn't use starlink
Im looking to buy an openWRT gigabit router for my house, can anyone recommend one?
you can consider getting a mikrotik that is supported by openWRT
you would have the choice of running routeros or openwrt on it
Is GNS that much better than PT?
PT is a simulator, GNS is an emulator. For beginners, PT is great. But if you want a realistic lab, GNS or EVE-NG is where its at
do you need openWRT?
@hollow marlin dont lab shame
Screw labbing, straight to production
i got some LOLs
Production is just another name for "Balls out testing"
Why test first when you can fix later? 😆
looking to bridge to homes within 1 km direct sight what should i get? i was looking at ubiquiti in the past
ik mikrotik has some products but I'm a complete noob with wireless p2p
its basically a Mesh'd AP over a really long distance. Same config as you normally would
what about 50ghz I saw
Just built a python dynamic proxy that changes its ports based on an OTP process 😄
I just want to make sure that stuff like DyDNS works and that there is a good interface. Both of those things are in openWRT
so technically, no but it might be nice.
mikrotik devices are nice but the OS can be pretty intimidating for newbies
but it's very powerful
@peak cloak I got intimidated by it at first. setting up vlans was the hardest thing to understand
it worked different from say net gear or ubnt switch
I think it is still setup as software only I never changed it over to asic
I just wanted it to work for the cameras and forget about it
What are the benefits of a managed network switch
Guys I was about to buy 3 of these and then I noticed it said "(U.S version)" but it's selling on the Canadian Amazon: https://www.amazon.ca/dp/B07ZG515K1/ref=cm_sw_r_cp_api_glc_i_F7HRP9TRF66NF91Z381A
MikroTik hAP ac2 US Dual-Concurrent 2.4/5GHz Access Point 802.11ac, 5 Gigabit Ethernet Ports (US Version): Amazon.ca: Electronics
Will this not work in Canada?
Is there a Canadian version I’m in the us so I can’t test
@flat wagon yes they will work in Canada
The US version has country settings for the us and canada, no other countries
Okay, thank you.
it is common for distributors in the US and Canada to mainly offer the US version because there are a lot more people interested in buying product between US and Canada than with other countries, and the US version works in both countries - the international version is not officially permitted to be sold to customers in the US
we are a distributor in canada and we normally order and sell the US versions as a result
What’s the best cat for a Ethernet???
Ok
Being serious I got a broken cat 5 and I’m looking and theirs cat6,7,8,9. Which is best
if your network interface is only 1Gbps and the run isn't super long, you are fine with cat5e even.. or you could get cat6
i use cat 5e, its super cheap and good
Kk ty
you're best to save money and not go overkill on the cable.. unless it is 10G ethernet and/or incredibly long
speaking how i run everything at 1/2 a gig so i have headroom
yea
these days you can get cat5e for like 20$ for 200+ feet
Cat5e or cat6 tbh
Broken where? If your doing cables through your wall id pick something future proof
Cat 6 or Cat 6A at a minimum if you're doing something heavy duty.
i love how you have that picture ready incase someone ever says the keywords "cat" and "ethernet"
If you're doing long runs then Cat8, it's what we did to our whole home
my internet has been SUPER SLOW lately, is there any way of telling where the problem lies without physically checking?
slowest backup server in existence, it takes... roughly 30 seconds to connect via scp
sftp> df -h
Size Used Avail (root) %Capacity
36.2TB 8.2TB 28.0TB 28.0TB 22%
but plenty of capacity
some $host in $country
Allows you to use things like vlans, stp, and much more
L2 features
and L3
802.1q - VLANs
802.3ad - LAG (Link Aggregation)
IGMP Snooping
STP/RTSP/MSTP
list is quite large
Well I bet that the slowest backup server that exists is where I used to work...
Every rsync over ssh took over an 50 seconds to connect.
Let's not talk about the upload speed that was inside the same network... Every upload took about 30 minutes even if the file was only 1/2GB
:P
I have been thinking of getting a router/access point to use as a way to connect a usb drive to my network and use as a cheap NAS but wanted to know if anyone has any recommendations?
This is what I have been looking at at the moment https://www.amazon.co.uk/dp/B01NAYG15H/
@clear igloo you've heard of laptop servers
but have you heard of laptop routers/firewalls
neat
Sell the macbook and use the money to get a used dell micro
should have desoldered the HAL sensor
@peak cloak https://www.youtube.com/watch?v=e48eYElm1R8
https://twitter.com/FisherBranden/status/1394714002907873283
🔵 We fix Macbooks & offer free estimates. https://rossmanngroup.com
🔵 Send us your Macbook for repair! http://bit.ly/sendmacbook
🔵 We'll send you a box with a pre-paid shipping label for your repair! http://bit.ly/sendyourmacbook
🔵 We offer iPhone data recovery: http://bit.ly/2BDBX4G
...
ASUS considers thermal pad dimensions to be a company secret
Who can i ask for some assitance and advice ragarding a Ubiqudi Sector and 2 dishes ?
just need some clarity
you should just ask and not ask who to ask
I am planning to switch from Windows Server 2016 to Ubuntu what is the basic cost for each server?
ubuntu?
it's free
unless you want some enterprise features
like kernel livepatch
extended security maintence
some crypto modules
landscape manamgent
among other things
if this is to be a server for windows desktops you may not be able to do everything well enough with ubuntu alone
ex. with no active directory
in like a corporate setting
oh yeah if you want things like that, that's one the the few actual uses for windows server
I mean we use linux for everything we can
but for authentication for windows desktops we still need windows server
yeah ofc
Thanks I run 3 Dell 710 server for sans backup.
I am also looking to replace my 3 enterasys C2G 124 - 48 switches I use end of life equipment since you can get them at a reasonable price. I am leaning toward Cisco since there is a lot of information on the net for set up. I really don't need 48 ports, 6 or 12 port would do. Do you have any suggestions?
I've seen here people recommend microtik. I'm not very versed in their switch lineup, but they are a good value I heard if you don't need cisco
Would you know off hand if they are managed or not managed switch, I need manage switch to subnet my DNS?
subnet my DNS
?
there are models with and without PoE
vlans?
Subnetting is the strategy used to partition a single physical network into more than one smaller logical sub-networks (subnets). Copy this off the internet. Hope this will help to understand subnetting.
yes ik what it is
just "subnetting dns" is what confuses me
what do you mean by that
DNS is the ip address can be A B or C class.
and dns is what resolves a hostname to an ip, it's not an IP
I setup a S2S VPN between my UDMP and a USG I'm setting up at grandmother's place 
She can only access my VMs VLAN and Home VLAN
An example of a DNS is 192.168.0.1 Mask is 255.255.255.0
no
that's not dns
that's an ip
in CIDR notation that's 192.168.0.1/24
but that's not DNS
I think you don't understand what DNS is
do you mean DHCP?
dhcp assigns IPs automatically
DNS, or the Domain Name System, translates domain names into IP addresses so users can easily navigate to sites on the Internet without having to memorize long, specific strings of numbers and letters.
yes ik what googling is
and ik what it is
I'm just trying to help you since what you said was incorrect
I do get this confused from time to time with all these initials.
this is just an address
i need a new router, current asus RT-N56U isnt cutting it for wifi range throughout my house, the asus RT-AC88U seems to have a decent rep for range, recommendations without breaking the bank?
if you're having that problem with range, why replace your router?
your router is unlikely to be having the biggest impact on range
Anyone know when the UniFi WiFi 6 (AX) AP Pros will be out?
I just see the Lite version
Beta
yup
Ok, yeah, soon then. I have a client that wants to replace his existing Unifi APs. So he's holding out for the WiFi 6
About 20 APs he's looking to get for main corporate office and a few branch offices
Bet they will be hard to get
Yeah, they have a limit of 2 per customer
there will only likely be a small improvement over the old unifi APs
initial tests show that wifi6 is about 10-20% faster than ac for most users unless you are very very close to the AP
Haven't tested it but I'd like to see high density and multi device
not just throughput
new routeros v7 beta has built in letsencrypt certificate request, which is cool - except for it to work, you have to open www port 80 to the internet, which means that webfig is open to the planet to log into your router if they figure out the password
no dns challenge?
no
not yet anyway
it's not something I would feel comfortable using with the current implementation
I can script it so that it only opens port 80 until it renews the cert, then close it again
but I think for this to be done in a secure way they would need to have a way to open port 80 without allowing global webfig access
firewall to only allow webfig access on a certain interface(s)?
Oof, I haven’t used www certbot in a while lol
The issue is that when you open port 80 it opens webfig with it
oh rip
so if you open port 80 to your internet uplink then webfig is accessible there too
so unless you script it is encouraging people towards bad security practice
like the old "remote admin" ports you used to have for routers back in the days (and still do sometimes), but I would never trust such a thing
especially bad when it is a login page on port 80
yeah
normal www certbot has a "standalone" mode where it starts up a web server on port 80 that is just for certbot itself, that is secure enough
but there's no standalone mode on mikrotik, at least not yet - it only integrates with the built in webfig server on port 80
I mean I can write a script that enables a firewall rule to allow port 80 everywhere, runs letsencrypt renewal, and then disallows port 80 again.. but I would bet that many users less comfortable with mikrotik scripting would just open port 80 everywhere all the time to get letsencrypt working with no fuss
the attack surface is minimal if you are opening port 80 for like 15 seconds every week or so to update the cert
It's not the throughout that matters to my client. He wants the lower latency and less chance of packet loss that WiFi6 provides over 5.
Basically a better Zoom experience with laptops
@peak cloak thanks for the lead on tp-link. stupidly, a $150 tp-link AP manages to outclass every other AP i've tried so far... and cover my entire bizarro-world house with a single AP in a central location
which one did you get?
I dunno why the hell no other AP was working. i tried several mesh systems, a couple ubiquiti offerings, several very expensive consumer-grade "gaming" routers with a bajillion antennae...
EAP620
ya, picked it up for $120
@copper rover seeing the above, have you considered TP-Link omada?
I mean I've been hearing great things about it for a long time
might be better going that route
Well, he has a UniFi controller and UniFi switches. So, keeping it UniFi AP
Controller is just the app ran off a Linux VM
omada controller is the same btw, java app running on linux
except i run mine in docker
unifi has a neat ecosystem but man the hardware kinda sucks
second hand ruckus is love
im really curious to see how the tp-link router and controller handle having an OPNSense node between the LAN and router
transparent filter
depends what you are using it for
if it does nothing with IPs and routing it should be fine
that's what i figure, but black box software always concerns me when doing weird custom crap
I'm glad I got off of pfSense lol
what do you need a transparent filter for?
funsies.
I'm not a fan of their UniFi Switches. I do like the EdgeSwitches though. And their APs are nice. That's all I can really say about Ubiquity
their aps are kinda so-so imo but to each their own
Buggy. And why use Mongo DB? It's crap and easily corrupted. Such a pain
the mikrotik switches are a better bang for the buck than either the UniFi switch or EdgeSwitch
MongoDB is great at storing JSON
their UI is fine, IMO.. the issue is balancing UI and feature set
Well, I didn't like having to configure a RouterBOARD. was a nightmare
because they focus on features and so they use the same UI used in RouterOS
ubiquiti takes a different approach
they write a new OS for each usage - ex. wireless, routers
TBH, I'm not like the whole cloud forced approach that Ubiquity seems to be going to. They might yet piss me off to where I abandon them.
the nice thing about the ubiquiti approach is that you get a customized UI for each device you are working on
the bad thing is that you lose features and different teams at UBNT have to recreate the same functionality independently
So glad they're dropping EdgeOS
UbiOS is doing the routing, then UbiOS runs containers with podman for the different applications (Network controller, Protect, etc)
The cloud keys, UDM(P), UXG, UNVR run UbiOS and its all running within podman
I had to lookup what podman was. But from what I can gleam, it's basically a more secure method similar to Docker. Runs without root access
But that's all abstract from me. I guess UbiOS then is inherently more secure?
Cloud keys before UbiOS were plain Debian
and USG was EdgeOS with UniFi added on
UDM(P) introduced UbiOS
So what's the AmpliFi Alien router run on?
I have no clue lol
Because that looks like a sweet replacement for an Apple Airport
UniFi OS = UDMP management/etc
Its a podman container
So UniFi OS can be restarted without interrupting routing
Since routing is handled by UbiOS
Ok so small question:
I pay for a 5MB/s internet connection, but i get around 500KB/s download speeds. Is this totally normal? If so, why?
@frozen cobalt internet connection speeds are not in megabytes per second or kilobytes per second, but instead megabits per second or kilobits per second
i.e. there is a difference between MBps and Mbps (with lower case b), and same with KBps and Kbps (with lower case b)
Also, download speeds depend not only on your internet but also the speed of the server from which it is downloading
Theres more to that actually
BROWHATHEFUCK
I just installed macOS catalina on a vm after hours of pain
building the iso from my sister's mac, then creating a vm, doing all the configs (the vmx file), and then waiting an hour for it to setup
and for xcode, it needs big sur
damn
oh shit thanks
but I forgot, as we speak, im updating the vm. I didn't try because I thought it wouldn't work with a vm
if it doesn't work, ik what do to 🙂
Hi guys! I am in need of some tips. I have a pfsense-box in my system consisting of a Mac mini Server that has a quad-core in it. My internet speed at home is 1000mb/1000mb up/down and it works great at those speeds without slowdown. I even get those speeds with my vpn-provider. BUT there is a problem. It isn’t rackmounted and it isn’t passively cooled or silent (like me Ubiquiti switch and key). So! I am looking for a rackmountable, 1u enclosed, passively cooled silent unit that will do speeds of 1000/1000 with and without whole-network-vpn turned on. ☺️
Worth noting. It does not need to have that performance with pfsense. I could also install opensense or similar.
Mikrotik?
Hex s can do gigabit
Idk about the vpn part tho
The VPN part is important. 😕
Hex s have vpn
@tender hazelcoz current router only has 280ft range, whereas the AC88U has 2500sqft range and specifically comes up as a leader for range, i've used a repeater in patchy areas but the signal is inconsistent, so thought a router with much better wifi range would suit
Well Cat7 isn't an official standard so you run the risk of getting crap quality cable
I personally prefer monoprice or cable matters for Cat6 or Cat6a cable but honestly even Cat5e that isn't CCA (copper clad aluminum) is fine for gigabit or 2.5Gb up to 100m
@glossy widget where are you getting those range figures from?
your old router is N-only and you might as well have an AC router these days, so it won't hurt to upgrade, but there probably won't be a huge difference in terms of range
There’s nothing wrong with mongodb. It’s a great tool. And mongodb is not “easily corrupted.”
It is on dirty shutdown or when RAM is filled up.
Ask me how I know. -_-. Many hours of frustration dealing with that
Lol maybe ancient mongodb, or someone’s shitty fork of it.
Possible, I don't know. I only know that UniFi Controller uses it
Omada also uses mongodb btw
I've had Mongodb corrupted on both a Cloud Key and the Controller app running in a VM
And it sounds like they have mongodb misconfigured or they are running a really old version to conserve resources
Possible. I've just have very bad experience with it so far
I’ve been running mongodb clusters in production environments for… man, it’s gotta be over ten years now. Most of the time when corruption happens it’s because someone disabled safety mechanisms to eek out a bit more performance
So I betcha that’s what’s happening
Interesting
One thing I do like about the UniFi Controller is that I can export just the config file. It's portable between the Cloud Key, App run in Linux or Windows (Java). For the most part, the mongodb just hold historical and analytical data. I really don't need that for the Controller to function.
When it gets corrupted or I can't compact the database through the UI option, sometimes it's a lot easier to do a fresh install of the Controller and import the config.
the biggest mistake that I see made with mongodb is that people do not run the command manually to update the database after upgrading mongodb
then they do something like a distribution upgrade that brings them to an even newer mongodb and there is no way to get the old one back
Oof.
so then you have to jump through hoops to get your data back
This is why dolts shouldn’t be in charge of running production services
I find often people who encounter that issue blame mongodb for not doing that automatically
people get used to being able to type yum update or apt upgrade and assume it does everything for them
That should be coded in by the dev, or at least provide documentation to do that if this is a sold platform and solution. If it's an in-house application, then yeah, that falls on the developer to maintain as well
Shouldn’t even be doing that in prod, should be rolling uodated images out to whatever hardware/cloud servers and following proper upgrade procedures for the service in question.
I believe the unifi network upgraded its bundled version of mongo recently, idrm. I saw a db upgrade notice in a release note
Automatic upgrades are a terrible idea, and the process is documented.
I think that's true in general. My favorite was doing a VMWare vCenter upgrade on a Windows server (back before it's now a VM Applianc). Watching it bomb-out on a .NET framework error was epic. Leaves the whole thing in an indeterminate state.
Restore from backups baby!!
XD
I hate upgrading vcsa lol
Yeah, it's scary. Russian roulette
What’s really fun is upgrading ESX only to find they dropped support for your networking hardware for no good reason
that's why i use broadcom or intel lol
Yeah, and finding info from a compatibility matrix is a PITA.
Oh I had an intel card last time that bit me. Not even a super old one
Vmware is just dumb.
It's a love hate relationship.
Indeed
Love it for its features, performance, and optimized data storage. HATE it for all the riddled bugs
esxi 7 dropped support for an older driver package lol
so if it was built upon that, esxi 7 doesn't support it
Oh, ESXi 6.7 and 7 really FUBARed the whole process of booting from SD cards. Treats it as USB storage. Now have to add in custom boot parameters.
(vmklinux)
Current versions of ESXi 6.x are shipped with both the VMKlinux and the Native driver stack. Modern hardware is, in many cases, using the new Native drivers. However, older hardware may still depend on a VMKlinux driver module. We announced to deprecate the VMKlinux driver stack back in 2017. This blog post goes into detail … Continued
lol, smelly turd logo
I have one ESXi host on 7.0u2 and one on 6.7u3 lol
The only thing keeping the 6.7u3 one behind is the raid controller (PERC H310 Mini (for monolithics))
The real problem with esxi is they went and wrote their own kernel instead of using a customized Linux kernel, so they can’t benefit from the huge Linux driver base at all, they have to maintain their own drivers for everything under the sun
And with no open source community to help out they have to obsolete drivers to keep their engineers sane
I mean, for actual enterprise its not really an issue
Do do they get with the vendor to write the drivers? Or they just do the drivers themselves based on vendor HW documentation?
It’s an issue for a lot of enterprise use-cases.
I think I've had to install Dell VIBs on a PoweEdge for OMSA
Dell, HPE, etc all provide customized ESXi ISOs with their drivers and stuff injected
Well, starting with 6.7 and/or 7, those ISOs are now hosted on VMWare.com, not the vendor's site
I might upgrade from 7 U1 to U2. No pressing need though
Can't do it through the Update manager. Will have to load the ISO directly. Oh well.
we have to update ours
Can't make your own software depot in vcenter?
Yes, I can push it out that way
That's how I patched mine
Or I can just mount through the iDRAC
running into issues where one intel nic will stop passing traffic, then the other one follows hours or days later
A lot of my nics are broadcom with some intel lol
we upgraded the firmware on the intel nics first to see what that does
mainly because broadcom is what's built into the lom/mezz slot
Well, we had a similer issue only to find out it was because the failover port was on another switch. Because it wasn't stacked, it didn't share the MAC table. Caused all sorts of flapping back and forth. So basically, we have a primary port with the secondary only being used if the primary physically fails.
in our case they are plugged into two different switches, but the switches are stacked
Are these X710 adapters?
yeah
40G dual port
two cards per server, each card has a port that we use for data and one that we use for iscsi
first we see on the HPE switch an alarm that the ports went down and came back up again immediately
for the iscsi and data port on one nic
it stops passing traffic and we see an alarm in vcenter for that host saying that it lost uplink redundancy
then hours or days later the second card loses connectivity in the same way and then we have to reboot it via the ILO to get everything up again
Fiber or Twinax?
If fiber, maybe a transceiver issue? Intel NICs are pretty particular about which ones to use as I understand it
IMHO, twinax is the way to go if the servers are within the same cabinet
I doubt it is a transceiver issue
since both ports go down in the same nic at the same time
and it is fiber, multimode
Yeah, in that case I agree. Something with the NIC
Time is money and all that. An expensive proposition, but perhaps get a new NIC with new transceivers and swap it out the server. Worse case, you now have spare parts. But, if it resolves the issue you know.
If that doesn't solve it, then clearly there's a firmware or driver level issue. That or the MB is dropping the PCIe card, but I doubt it would do that.
yeah, the four nics in the two servers are all doing it
So yeah, firmware or a driver bug
they were running really old firmware, we just upgraded one a few days ago
So better or worse after the upgrade?
🤞
Hi! I am in need of network assistance
My issue: I have 1348mbps coming to the house. And cant seem to get over 930-940mbps, My cable is CAT6 (Despcription says it can handle 10gbps), And my motherboard is a Arorus z390 pro wifi (300series) mini itx
Unless you have 2.5Gbps or 10Gbps capable hardware across the entire chain, you're not getting over ~950Mbps because something in the chain is limited to gigabit speed
Also your motherboard only has a gigabit nic so not sure how you'll get higher anyway
yeah the motherboard only has 1Gbps NIC, and chances are the router only has 1Gbps ports
so even if you bought and installed a 2.5Gbps NIC in your PC you would still only get 1Gbps if the ports on your router are all only 1Gbps, as I would expect
Yup
Usually when ISPs give >1Gbps packages, it isn't with the expectation that a single wired computer would use it, but instead what it would do is for multi-user households where you have perhaps a few systems wired in and some people on wireless, the sum total of all bandwidth the group of users could use all at once is 1350Mbps
so for instance other people or devices could be using 350Mbps on your wireless and you would still get a full 1Gbps on your wired connection
^
Oooo okay lol well then I thought my motherboard was capable
I guess I’ll cancel the technician then
cable rating (CAT) only really refers to the speed and range its been certified for.
the network interface negotiates on the best available speed
need compatible cards to support 2.5 or 10G
So all I need to do is get a network card thing that can support it?
no, probably your router only has 1Gbps ports
Depends entirely on all networking equipment along each link of the network. What modem model do you have? Is there a router or switch in the mix, and if so, what are their model numbers?
I don't get it. With 2.5 and 5gig adapters being discussed, why not just push with volume and go right to 10gig?
Seems logical to just keep with the rate of 10 / 100 / 1000/ and 10000
the modem is one they supply, it is the xfinity modem
Because many ISPs don't have the infrastructure to jump straight from 1gig to 10gig within "the last mile" to residential customer homes. Technically DOCSIS 3.1/4.0 support 10gig down, but all the equipment between the ISP's headend and neighborhoods must have capacity too, even for Fiber connections.
https://en.wikipedia.org/wiki/DOCSIS#Comparison
Data Over Cable Service Interface Specification is an international telecommunications standard that permits the addition of high-bandwidth data transfer to an existing cable television (CATV) system. It is used by many cable television operators to provide Internet access (see cable Internet) over their existing hybrid fiber-coaxial (HFC) infra...
Which one? Xfinity offers multiple modems. Do you have the newest XB7 or slightly older XB6 modem? You'll need the newest XB7 modem as it's the model with ONE ethernet port capable of 2.5gig link speeds. If you have this, then all you need is a 2.5gig capable PCIe network card for your PC. https://www.xfinity.com/support/articles/broadband-gateways-userguides
Learn more about Wireless Gateways and download the user guides.
it's probably not worth the hassle just for an extra 350Mbps
you'll only notice the difference if you are downloading something that is massive, and even then 1Gbps is quite fast
No, I mean beyond ISP. Why has the computing industry decided to mess with 2.5 and 5 adapters? Can 10gig switches even downstep to 2.5 and 5 per port?
Ohhh you meant the industry as a whole. That I'm not 100% certain of, but I'd guess it's because there's a enough of a cost different when stepping up to 10gig that it makes sense to offer 2.5gig and 5gig options for prosumers who don't want/need to jump straight to 10gig.
The only thing I can think of is that chip fabrication hasn't reached a low cost point enough where 10gig adapters becomes more consumer friendly option. But I'd worry 2.5 and 5 adapters would fragment the market due to a corresponding switch being needed as well. Just prolongs the adoption of 10 gig in the consumer space IMHO
doing 10G over copper requires a pretty flawless cable link
otherwise it won't be likely to negotiate at 10G
Sure, but best-effort would be better than a hard gimp to 2.5
unless things start moving to PCs with built in SFP+ interfaces instead of copper ethernet ports
SFP+ just allows for different interfaces. But the underlying NIC chip wouldn't change. So I can't see how that would help the consumer.
Enterprise, yeah, RJ45, fiber, twinax..
currently the 10G copper interfaces cost twice as much as the 2.5G copper interfaces
actually more than twice as much
switches and routers have for the most part made the jump directly from 1Gbps to 10Gbps
it's mostly network cards that seem to have taken this path through 2.5Gbps on the way
Is it part of the 10gig spec of a switch to step down to 2.5 or 5? Or if you plugged in a 2.5 NIC to a 10 gig switch, would that step down to 1 gig?
@copper rover what you just linked to says "Gigabit Ethernet Adapters (up to 2.5GbE)"
if you plug a 2.5Gbps NIC into a 10G switch, it should negotiate 2.5Gbps on the port
Ok, I wasn't sure if it would
yeah it should in just about any case
as long as the 10G switch is reasonably new
I mean if you are using like one of the very first models to come out from many years ago
then I wouldn't necessarily count on it to negotiate down to 2.5Gbps properly
b/c I recall that the 10G copper spec came out before the 2.5G and 5G copper rates were added
Well, I ask because I don't see any 2.5gig switches
WTF, I must be blind. I can't find any Intel 2.5gig adapters. I see specifications for the I225-T1
my asus board has an intel 1Gbps adapter and a realtek 2.5Gbps
Gigabit Ethernet Controllers (up to 2.5GbE) product listing with links to detailed product features and specifications.
Right. So where's the physical card?
They're chipsets/controllers
most people buying switches are buying for business use - and most business computers only have 1Gbps cards
That motherboard manufacturers can use
I think the only reason that 2.5Gbps and 5Gbps are a thing are because people are getting >1Gbps connections at home and want to be able to use the full rate, but the motherboard manufacturers want to keep costs down because if they start building 10Gbps ports into the board and it raises the cost by $50 over the competition
They have a picture of one
so it is really more of a consumer thing
Oh, 1Q of 21...so that..like now
nbase-t is also on wifi 6 APs that don't have 10 gig
That's like the only place I've seen nbase-t tho....
besides consumer stuff lol
I wonder if legit, because it's not even on cdw.com
https://www.directdial.com/us/item/intel-ethernet-network-adapter-i225-t1/i225t1
I225T1 - Intel Ethernet Network Adapter I225-t1
Fresh out of the oven it would seem
Pricey bastard at $64
it makes sense for an AP that can do >1Gbps theoretically but can't hit 10Gbps
to use 2.5Gbps or whatever
Yeah, especially for high density APs
but making 2.5Gbps switches is not likely something that is going to happen, because those technologies have pretty much standardized on 1Gbps and 10Gbps, and it doesn't make sense to develop a 2.5Gbps model when the market for such a thing would be limited - it is easier to use existing chipsets to have a mostly 1Gbps switch with a few 10Gbps ports for the odd 2.5/5/10G device
it's a completely different ballgame to create a switch chip than it is to create an individual interface
There's some 2.5gig switches but they're, again, mainly used for the 2.5 gig aps lol
I'm pretty sure the aruba switches are only 10G
I don't think they have 2.5/5G switches
ahh interesting
so basically they have two different models with 24x5G ports for APs
most likely the only reason they exist is because of PoE
I haven't really seen any 10G PoE switches because there isn't a need for PoE on 10G ports
but for wifi6 APs, you still want to use PoE to power them
so it is a relatively niche thing then
only crazy APs with 10 gig lol
I haven't had to deal with any of that stuff
we only provide like 10Mbps to most of our customers
so not being able to go above 1Gbps on an AP doesn't usually matter so much for our customer base
Juniper 4300-48MP has 10gig PoE. 24 are 1/2.5/5/10 and 24 are just gig. All full PoE support
Just added a bit of history to my lab. Might be one of the oldest pieces of hardware I have, but she look guuud
@hollow marlin ahh ok.. not really familiar with Juniper's product line
Outside that single model/version that's the only one I know of. Fairly new as well. I doubt many more exist. I'm pretty sure I remember it targeting the up coming trend of PoE in switches now that wattage is high enough
I think that very server processed one my Google searches in the past 😉
Ever since I’ve started a homelab, I’ve wanted a google server, no matter what. Plus, was able to beef it up to 72gb of ram with just sticks I had lying around, so she’ll still do some work.
That looks like a Dell PowerEdge. Or maybe the same chassis manufacture that makes those make a modified version for Google?
72GB is pretty good - I have 64GB in my home desktop
R710. Literally, no major changes I can see.
So a real R710? I wonder if Google in-house painted them yellow
Or is that a powder coat?
My desktop is still my most powerful single host with 128gb. And I think they had a non-standard configuration with it, I don’t remember my other r710 I had having these particular pcie expansion cards. And yeah, powder coat.
Google might have had Dell make them specifically customized with that color scheme
what's a powder coat?
Like paint, but instead of a liquid, it’s a powder that’s cured under heat or uv
^
ahh ok
They're R710 OEMs
Much better finish
oh I didn't realize Dell offered standardized OEM stuff
Well....if you have pockets as deep as Google, I'm sure even Dell would make an exception for a very large contract
Yeah, managed to get this one locally because I guess the guy didn’t see how much you can mark up the google branded stuff
150 bucks
I didn't think there was much of a markup. From Google's perspective, it's decommissioned equipment making rack room for new stuff.
And, they don't want to deal with EOLed stuff
But the middle men know people like me will pay extra for the branding, lol
Sure. I mean there's certainly some nostalgia factor there.
Also, just found the google front bezel on eBay for 35 bucks, scoooore
Guys, what's the max length an AOC network cable at its full theoretical speeds?
I bought a 100FT AOC cable for my 10G networking upgrade and just curious about it's max length.
100m
okay, thank you.
@flat wagon AOC's dont have limits, they are rated for the given lengths they come as
speed is irrelevant with fiber, its just the module that decides that
Hi there, i have problems with my Ethernet.
My ethernet port is 1gbps.
My cable is Cat5e.
But i am only able to pull 60mbps.
Can anybody help me?
kk, thank you crystal! :D
@sacred harbor what kind of internet plan do you have?
idk how to check
.
u probs got 60mbps then
even if ur port is 1gbps
doesn't mean ur gonna get that without the plan
but where can i check my plan
probs by logging in on your ISP website
... well aren't you paying for this?
no, it was my dad paying for it
@sacred harbor ethernet is either 100M or gigabit speed, but this has no merit on the actual speed if your internet is only, say.. 60mbit/s
Gigabit ethernet just means, that the computer and router themselves can transfer at gigabit speed
but your internet connection will likely be much less than that
how do i check my plan without my dads account
he did a speed test
if that's what speedtest is telling you
yes
yeah, so you got 60mbit/s
but he's asking a way to check directly from his isp
somehow without logging in
which u cant rlly do
You'd have to ask what plan you guys are paying for
furthermore, often the advertised speeds are not the actual speeds
ask who
ur dad
^
my dad died 2 weeks ago
Oh, my condolensces
thats why im asking how to do it without his account
thanks
Contact the service provider
They would have to terminate the account, or have it transferred
also is it weird that my Ethernet has the name of my WiFi, bc downstairs on my dads pc its just named Ethernet
local dns name
ok
@sacred harbor with 60mbit/s you are at least in the speed range that is "good enough"
I was on 4mbit/s for many many years
that's not even enough for HD youtube
it should say somewhere on there
cant rlly tell u where exactly since diff isp have diff website layouts
its on Proximus
i cant find it
just checked, my plan is Flex S and its 100mbps
the thing im confused about is that the ethernet downstairs is 1gbps
no ok so basically as crystal said
but where did my other 40mbps go
I'll word it differently but basically your equipment supports 1GBPS throughput. meaning, if you had the plan for it from your ISP, your equipment can sustain speeds at the maximum of 1gbps
Well, there is also the added factor that it depends on the servers it connects to
Also
and if you're on cooper running 100mbps instead of fiber, you probably won't get full 100MBPS. also, other devices on your home network may be saturating the 40MBPS
it's not a 100MBPS per device if that's what ur thinking
it's 100mbps for your whole home
so it has to share with all your devices
np
@sacred harbor those link speeds, 100M and 1Gbit, those are the connections between your network devices locally
i want to protect my server... I have there webserver... With A record? Any way to make it secure... So no one can see ip or ping through cloudflare?
