#networking

1 messages Ā· Page 389 of 1

unborn sluice
#

šŸ¤”

waxen saddle
#

True. Which is why I think we would be fine dynamically setting the test to the local gateway router. If it’s down, who cares? Everyone else in the house/hotel/airport is going to be all up in arms. But at least the message is going to be correct most of the time.

plain siren
#

Thats thanks to the Captive Portal detection system of Windows. It will load it behind the VPN on purpose.

#

Android does this too

#

As much as people like to bash on Windows.... they got a SOLID management ecosystem

waxen saddle
#

Yep. Though, I wish SCCM was a bit more… immediate. But that could actually be a corporate management problem. I’m just not sure yet.

#

Like, if a Windows update is past due. Install that NOW. Don’t care what the end user thinks or wants. They literally had a week or more to get it installed. Why is SCCM stalling?

#

I also don’t have any formal SCCM training. So the terminology may mean something a bit different than it’s face-value.

#

And for crying out loud. Why do I have to micro-manage the SCCM cache folder. If there’s an update or program that needs to be installed, and the cache is over the size limit. It fails with random error messages. Like. Just auto clear out stuff that isn’t needed and auto expand or shrink as needed. If the drive limit is reached, that is FAR easier to detect and diagnose.

#

But now I’m off-topic for this channel. Lol.

plain siren
waxen saddle
#

I’ve used PDQ Deploy and Inventory in the past. Loved it. Worked really well. No idea how well it scales to our size though. And though absolutely no one where I work would even entertain the idea of moving away from SCCM, I would love to entertain the idea. Any suggestions?

plain siren
#

SCCM is now Configuration Manager basically

#

They both put SCCM to shame now

waxen saddle
#

We have interest in managing through Intune.

#

I forgot about that.

plain siren
#

Ok I hate Azure and all that, but my Bias cant defeat the ease and utility Intune offers

#

And thats a massive compliment coming from me

mellow hemlock
#

Hey guys. Moving here for relevancy, but Is it possible to write a script in windows that automatically creates an outbound rule to block internet to applications through the firewall?

unborn sluice
#

Yes

mellow hemlock
#

sweet

#

bat file then?

unborn sluice
#

oh thought you're referring to PS

mellow hemlock
#

ps?

unborn sluice
#

powershell

mellow hemlock
#

Oh, either can do

#

Idk how I'd do it or what I'd write

unborn sluice
#

go with PS

mellow hemlock
#

Can I save it for future windows installs?

waxen saddle
#

Absolutely.

unborn sluice
#

Certainly

low pond
#

@plain siren Didn't Intel have Xillinx? or what happened there lel

little schooner
#

I need help with a networking problem. Not that I can actually implement a solution, but, I am trying to understand why desktops on campus randomly get assigned IP addresses belonging to the unauthenicated VLAN.

The desktops are connected to Cisco switches and those Cisco switches are provisioned using Cisco Identity Services Engine appliance/product suite. If the client desktop is powered off for 4-5 hours, the next time the desktop powers on, it gets an IP in the restricted VLAN. However, if I physically unplug the cable that's going to the PC from the wall port, wait 10 seconds, and plug it back in, it authenticates to the Cisco ISE and the correct IP is given.

Doing an ipconfig /release and ipconfig /renew doesn't trigger the PC to get the right IP address.

It's so odd why this happens and its not consistent. It's always a different PC.

fresh canopy
#

Got a QLogic BCM57810 to install in my windows PC. I was doing some iperf3 testing and was noticing that I was only getting about 5Gbps transfers out, and 3Gbps Transfers in. Checked "Get-NetAdaptersHardwareInfo" in Powershell and i'm seeing that the adapter is connecting at PCIE ver 1.1 instead of version 3 like it's listed to support. Is there anyway to force the version negotiation?

unique isle
#

Guys please I need help! I screw something up. I installed the cockpit for linux and then I was creating a bridhe to the esp5 something and now everything is dead and I cannot connect to the server. What shouold I do?

waxen scroll
#

if it doesnt mention seeing the problem computer the first time, maybe there are connection issues

little schooner
# waxen scroll I dont do ISE but have you thought about looking at the logs?

so I had this idea where we get daily reports of which computers are communicating to our inventory management appliance (kace SMA), and I was going to get the port ID numbers from where the desktop is connected to and have the network admin bring it up to the ppl who manage ise and see if they can see the logs for that particular port and pc

#

I am hoping they can narrow it down that way. yes the logs are a great starting place

waxen saddle
# little schooner I need help with a networking problem. Not that I can actually implement a solut...

Sounds like the NIC is kept active even after power down. I’d wager if you pulled the power plug on the PC and powered it on, it would behave as if it had been unplugged. Could try disabling WoL and see if there’s anything concerning keeping the NIC powered. Also check the BIOS/UEFI. edit Disable ā€œallow this device to wake this computerā€ - that will also keep the NIC alive in low powered states, or even the ā€œoffā€ state.

#

I’m not entirely sure how the Cisco authentication back end works, but if the port is alive and the authentication service can’t figure anything out (lights are on, no one home), it may drop the port in to the restricted access because it doesn’t know the state of the computer.

rigid nexus
#

Need an absolute network genius to help me out. R/tech discord has no answers. About a week ago i lost the ability to connect to 5ghz band wifi out of nowhere. I was advised to do a fresh win10 install. I did, and I still cant connect to 5ghz without getting booted off after about 10 seconds. Other devices have no issues. Please help!

waxen saddle
#

if it's a laptop, i wonder if the antenna got damaged or disconnected from the wifi card.

fading oar
unborn sluice
#

he needs an absolute network genius

low pond
#

Absolute notwork genius, gotta somehow peer with cogent.

fading oar
#

Sorry

little schooner
#

I think that would fix it for sure

orchid shell
#

hey my ethernet cable for my pc died, and I've got virtual class i was just wondering is there anyway i could get internet to my pc from my phone through USB or Bluetooth? it's an s10+ (Samsung)

sudden kayak
#

yeah you can do usb tethering pretty easily

#

should be able to just find it in system settings

#

under "connections" in system settings

sudden kayak
waxen scroll
#

"We have problems with enterprise pc's ending up in the guest vlan for some reason, and we have to reboot them to get them back to the enterprise vlan."

#

😮

#

@little schooner now kiss.

little schooner
orchid shell
little schooner
#

everything is locked down. It's policy for in and outbound and every port we want needs to be in a change request and approved

#

it's so crazy for a school network

#

they take it more serious than some private businesses

waxen scroll
#

a school is a business

little schooner
#

but like they have more security than Tmobile for example lol

#

in the checks and balances

#

but yeah ig bc it's a school it's diff I suppose idk

little schooner
#

well now it makes sense lol

waxen scroll
#

the students can be phished like a business too

peak cloak
#

tell me about it

#

our security is bad

little schooner
#

and they have been. There's been several attempts and at most earlier this year, we had 15 accounts phished

peak cloak
#

and then phising wise, man

little schooner
#

they clicked links and typed in info

peak cloak
#

there's so much

little schooner
#

now they are trying to slowly phase in mandatory two factor authentication

peak cloak
#

lol

little schooner
#

starting with IT teams

peak cloak
#

most people havn't changed their default password

waxen scroll
#

when I worked for a school we paid to get attacked. They got students to click, they walked into a PC lab and did some nasty, they breached our stuff through a server the students had access to

peak cloak
#

which was 6 chars

#

no special chars

#

just upper/lower case and numbers

#

so accounts get hijacked and keep spreading it

rigid nexus
#

Got my wifi fixed. Had to go into router gateway and prefer 40MHz within 5Ghz wifi. Apparently windows update messed it up for many people

smoky girder
#

do all US houses have hollow walls?

#

to run cat5e

peak cloak
#

most do, but not all

#

there may be insulation there as well

#

our exterior walls have spray foam

#

and internal rockwool

smoky girder
#

i do not believe i have insulation in the wall i al gonna run it becuse when its freezing in my room its freezing everywhere else even though i have a heater

#

if you get what im saying

#

so i belive it is hollow

meager ginkgo
#

Futureproof yourself with 6/6A

waxen saddle
smoky girder
meager ginkgo
smoky girder
#

yeah thats fair

meager ginkgo
#

CAT5E is fine now for under 1 gig connections but think about 5-10 years

smoky girder
#

im only gonna need it for 4 years.max

meager ginkgo
#

your choice. Still wouldn't recommend it considering how cheap CAT6 is

carmine moss
#

just use it can always be used as a pullcord for cat 6 or better later

meager ginkgo
#

yeah that's true.

carmine moss
#

also as you have it it's free and if you need better yeah it's more work but 1gigabit is more then enough for the internet even in 5 a 10 years as fiber is just getting widespread adoption

meager ginkgo
#

DOCSIS 4.0 šŸ‘€

peak cloak
#

pushing the max out of copper lol

carmine moss
#

people are mostly still on 300 mbit these days gigabit is so expensive

meager ginkgo
#

depends on provider

peak cloak
#

like, my network usage sits at 5 mbps average

meager ginkgo
#

$80/mo

peak cloak
#

and for burst, 300/300 works just fine

peak cloak
meager ginkgo
#

Anyone familiar w/ MoCA here? I'm pretty familiar with it but have a question still

#

If I seperate the incoming DOCSIS line from the rest, do I still need a MoCA Filter

#

I'd assume no?

abstract laurel
#

anyone in here good with openWRT, im having some issues and cant seem to wrap my head around what im doing wrong?

abstract laurel
#

i have spent 3 days working on this problem and always seem to loose either internet connectivity to my devices, or cannot see the static IP devices on my "router", it is OpenWRT based and i was hoping to find some help.... and in regards to your response, its about as useless as a hemroid, thanks...

#

https://linustechtips.com/topic/1412070-openwrt-help-custom-routing-solution-for-travelling-automation-technician/#comment-15263487 i can see the LAN connections on the built in VLAN that im trying to setup as a switch, but cannot communicate with the devices. they are on different subnets, however i can communicate with them on a different router than this one....

peak cloak
# abstract laurel i have spent 3 days working on this problem and always seem to loose either inte...

if you set a static IP, the router won't see usually in devices since that's usually derived from DHCP leases, and it prob doesn't use ARP, would have to check on that tho

I'm not quite understanding your diagram. But what I think you could do is this, setup your laptop on the interface connecting to the switch as 192.168.43.34/16 or something like that which wouldn't cause ip conflicts with any device. This covers everything between 192.168.0.0 - 192.168.255.255, the whole reserved subnet. This will allow laptop to connect to any device within that subnet.

Then configure the internet router to use a different subnet, something like 10.0.1.0/24 so the router IP would be 10.0.1.1/24. Laptop could just get IP by DHCP. This is needed as we can't use the 192.168.0.0/16 since it would result in IP conflicts.

abstract laurel
#

The diagram are the two ways I am trying to use the device, one using my existing wireless in my workspace, and the other being when I am on the road for work, I can use my phone as the internet source. But the devices I need to connect to tend to have default static IP addresses like 192.168.250.1, 192.168.1.2, 192.168.0.2... I have to adjust them individually and put them on the same subnet/assign static IP addresses so that they communicate and can deliver I/O signals between them. I usually set them to 192.168.1.1-192.168.1.3 for example.. my computer (and sometime multiple computers) are normally connecting via DHCP, the problem I'm running into with this router is I can't communicate with them if their plugged into the router. Regardless of if I have changed the ip... The router is rejecting communication and I have tried setting it to accept with no obvious change, and I've tried seperating the physical ports as a switch and creating a network bridge to link them, but when I create the bridge, I lose all internet connectivity but I can see any device I plug in, maybe I'm configuring the bridge improperly? I know this is probably something simple I'm overlooking, but This is my first attempt at using openWRT with this setup, before buying this device I had daisy chained multiple devices to accomplish this connection setup... The old TP-Link router would allow me to ping and connect to the devices with their default IP and then I could change it and see it on router. Then I used another access point to add our existing wireless connection to my new network...

abstract laurel
peak cloak
#

and if they have static IPs, perfect

abstract laurel
#

I was trying to eliminate the step of programming them all individually, when I started doing this, we just used a switch, but then I have to constantly reconfigure my ip on my PC as I change each ones IP address, then the problem lies in I have no internet for help files in certain software, or to look up something up on the fly, the router portion of the device is mostly for the wireless laptop(s) to negotiate an open IP and not cause conflicts on the small network of static devices... Meanwhile the device is also allowing me internet access on the laptops through an existing company network... Maybe that describes what I'm trying to accomplish better?

ebon prawn
#

hi! there! i'm shopping for an internal 2.5gb network card. are there better chipset that put less load on cpu?mine is a i7-4770k @4.4ghz all cores (4c8t)

little schooner
meager ginkgo
little schooner
#

yeah tru

#

i have some that still use 100 meg

#

is the cost savings that much??

meager ginkgo
#

you have some of what?

little schooner
#

ip cameras from 2021

meager ginkgo
#

ah yeah. Most cameras only use 100meg ethernet

#

unless you get a higher end one, it's simply not needed for most cameras

little schooner
#

yeah, like the 8 or 12mp ones, i think

meager ginkgo
#

I don't even think they can use more than 100mbps

sudden kayak
#

even 8 bit raw 4k video is only ~200Mbps

#

and cheap IP cams are definitely not shooting raw video

plain siren
long thistle
#

lol

mellow hemlock
#

that's a lot of itnernet

ebon prawn
long thistle
ebon prawn
cerulean anchor
plain siren
#

Wait wot

low pond
#

What's wrong šŸ˜›

#

Speedtest usually does multi socket connections unless you say single

ebon prawn
#

ftth lowest is 15$ unlimited 5gbit/700mbit epon

south blade
#

What am I doing wrong, I'm using Windows 11 now and my phone can't get connected to a remote app (remote mouse/keyboard).

#

App says it's got firewall access, but I don't see anything actually connecting on the 'connections' tab.

#

It's supposed to be using these ports, how do I make sure they are accessible?

#

This is all my phone sees using a port scanner

twilit shard
#

Would upgrading to wifi 6 be worth it for futureproofing reasons

#

Or should I just stick to wifi 5

#

Since it's cheaper

worthy orbit
#

depends what you plan to do, I personally play VR over wifi so the lower latency and higher bandwidth is worth it. But otherwise meh

twilit shard
#

Hm guess I'll stick to wifi 5 then

#

If I play vr it'll be wired

thick minnow
#

I feel like wifi 6 will be like cat6 cabling

#

Not necessary in most situations

plain siren
thick minnow
#

either

#

like, necessary internet speeds haven't changed in like 10 years

#

you can still watch youtube vids and browse with like 5mbps

rocky badge
#

Even if WiFi 6 won't help with speeds, it'll help with congestion.

#

Plus it's the first 2.4GHz spec improvement since N

thick minnow
#

that is true yeah

#

but in terms of speeds improvements with the new standards it wont really be utilized i feel like

frigid sphinx
#

@thick minnow the driver is going to be the power management features not the speed

#

and the density improvements

#

xen, esxi or proxvox for virtual firewall/network stuff (asterisk, sdn controller pfsense guests) thoughts?

peak cloak
#

can't really go wrong with proxmox

#

if you can pay for vcenter I heard esxi is really good too

fluid terrace
#

alright so I have a very weird problem. I recently purchased the Orbi RBK753S mesh kit from costco and got it all setup. I know orbi might not be the best system but its going in my parents house and they dont have/want ethernet run all over their house. It was also relatively cheap for a wifi 6 mesh system. So we pay for 250 down 20 up and I get that perfectly fine off both of the satellites but when you are in the main room of the house next to the base router the speeds drop to basically 0 and while it is at 0 if you reconnect to the satellites it will jump back to 250. We dont have any interference that I can find. I tried calling support last night and got a bunch of useless information and things to change that didnt end up helping. I am hoping that someone here could point me in a good direction because I am kinda stuck at the moment. Thank you.

thick minnow
fluid terrace
#

Yeah we are going to take them back. So now I need suggestions for a mesh system. I’m thinking eero

undone crest
#

ok so i have recently switched motherboards from a msi mortar b460m wifi to a gigabyte d3sh ac wifi and i have been having wifi speed issues and they are very odd. my pc will get any where from 1mbps to 60mbps on download and other device on wifi will get 130+mbps but on my pc my upload is stupid fast like 120mbps compared to other devices which get like 30-50mbps. so for the past couple days i have been fiddling with my wifi drivers and my wifi adapter settings and i have not gotten any luck. so if you any of yall could help that would be great

clear igloo
low pond
#

1Terabit OTA would like to have a word in 400 days too

clear igloo
low pond
#

šŸ˜†

clear igloo
#

Although WiFi 7 is supposed to have aggregate throughput of like 30 to 40Gbps which is insane by itself

errant cave
#

Hi! I need a bit of help. 😦

So I'm having issues with my current ISP and I was looking at load balancers (like the TP-Link TL-R470T+), and from what I've gathered, you can either:

Combine multiple ISPs into 1
or
Have 1 active ISP, and 1 fallback ISP in case the primary one goes down

Are there load balancers that do something like this?

Home: ISP 1
Office: ISP 2

If ISP 1 breaks down, switch Home to ISP 2 (so now both are running on ISP 2), or vice versa.

I'd like to have them split as much as possible, and only ever run a single ISP for both if the other one is having issues. Am I looking at the wrong things? My knowledge of networking is pretty limited so I have no clue if I'm even looking at a possible solution D:

peak cloak
#

And then configure failover

waxen saddle
#

You aren’t going to be able to combine both ISP’s for aggregate bandwidth. For example: ISP1 = 100mbit. ISP2 = 100mbit. You will download at a max speed of 100mbit. Not 200mbit.

peak cloak
#

^

#

You can have 200mbps total bandwidth, but not on a single connection

#

more like 2 computer downloading at 100mbps

#

if configured correctly

meager ginkgo
#

I'd recommend MoCa adapters + UniFi APs if you do

#

More complex setup but will be miles better than mesh

feral wadi
#

Does anyone know how to setup reverse proxy on Apache? I’m trying to get it to forward internal port 8080 on a subdomain through port 80 without messing up my website that runs on ports 80 and 443 (I was told that this should be possible, and I very much need it) (also I think this is the right channel for this question)

errant cave
coral stump
#

does anyone know a way you could block a specific website on a network? when i goto the login page for my email hosting it says this site can't be reached, but if I make a hotspot with my phone I can get to it? it's not just one computer, it's the entire network, could they have done that? I checked the firewalls for anything that might cause that, it's wierd because it's so specific. I can goto their page but just not the login page, tried several browsers and all coming up the same.

rugged quiver
#

Yes websites can be blocked.

peak cloak
#

websites can also block certain IPs

rugged quiver
#

If you're able to check firewalls I assume you own/manage the network? Or did you mean local firewall.

coral stump
#

yes it's a business network, I guess I should contact them and see, when I did they just said it should work and that it was on my end.

frigid sphinx
#

@peak cloak esxi is free for personal use

#

but proprietary 😦

peak cloak
frigid sphinx
#

there's a bunch of stuff missing but I mostly don't care about it (things like vmotion, storage vmotion etc) for a signle virtualiser

waxen saddle
sudden kayak
#

in my mind, why deal with using a proprietary piece of software when equally powerful FOSS alternatives exist... with free proprietary software it's always going to be designed for an upsell somewhere and you never know when your needs will change and you'll hit a paywall

frigid sphinx
#

and this is the reason proxvox or some xen solution is most likely ^^

sudden kayak
#

another piece people don't realize until they've been on the commercial side of things - with open source there will always be documentation and crowdsourced how-tos - but if it's commercial, the assumption is that public documentation doesn't have to be very detailed or comprehensive because if a user needs to figure something out badly enough, they'll just shell out for a support contract

#

with open source, pretty much all documentation and accumulated knowledge has to be public (or at least there's no good incentive to keep it private)

#

anyway sorry to be contrarian - it's just an aspect that people tend to miss and hopefully i can save you some time pointing that out

feral wadi
#

If anyone could help me with a problem I'm having with Apache I'd be very grateful

sudden kayak
#

i was actually just reading back and saw your question - if you still need help i can try to assist but I'm not 100% sure what you're looking for

#

so you're trying to have apache listen on port 8080 and reverse proxy that to another site on a subdomain?? or you're trying to have a subdomain that goes to a different site through a reverse proxy?

#

both should be possible I'm just not clear on which you mean and what you're trying to accomplish

feral wadi
#

I'm trying to make it where, when I use a certain subdomain it forwards to port 8080, rather than using 80

#

Cause I have a server already running on port 8080, but the client will only listen to 80, but my website is running on it

rain quarry
#

TFTP = Nice šŸ˜

#

Sorry very random but I need it on a shirt lol

sudden kayak
feral wadi
#

Okay, thanks

sudden kayak
#

ok soooo... you should just be able to create a vhost for your regular website or a default vhost and leave the settings for your regular website in there

#

and then have a separate vhost for the subdomain with the reverse proxy directive pointing to 8080

#

but I'm not 100% sure it's that simple - can you give that a try? or if you have already and it didn't work, let me know and i can try to figure out what's next

feral wadi
#

Earlier I tried to make a new .conf in /etc/apache2/sites-enabled and enable the mods for it and it didn't work

#

Though I have barely any idea how to do this

sudden kayak
#

hmm that's weird. can you check either your apache log or your systemd journal for errors?

#

apache will either say "this config file is totally broken" and just not start, or it will just ignore whatever block or site it thinks is broken and keep serving the rest of the things that are still valid

feral wadi
#

This is what I had before (doubt it's right, I've tried doing multiple things, this is only one of them)

sudden kayak
#

hmm so iirc you actually don't need the proxy directives inside a <Location />

#

i think the syntax would just be ProxyPass / http://thisisruka.fans:8080 and same for the proxypassreverse line

#

oh wait one or both of those might need to be quoted

#

they might work either way but i don't recall for sure

#

both might be fine but try putting it in one line without the extra location

feral wadi
#

So just this?

sudden kayak
#

without the location line at all

feral wadi
#

Ah

sudden kayak
#

oops how did that send twice

feral wadi
sudden kayak
#

yeah so add a path "/"

#

in other words ProxyPass "/" "domain:8080"

feral wadi
#

This is the status

#

Could not reliably determine the server's fully qualified domain name, using 127.0.1.1. Set the 'ServerName' directive globally to suppress this message

unborn sluice
#

nice

feral wadi
#

The 8080 server won't load on the subdomain

unborn sluice
#

why would it

feral wadi
#

Idk

#

Tryna figure it out

unborn sluice
feral wadi
#

Got this, still doesn't work

unborn sluice
#

show config

feral wadi
warm mica
#

When it fails is it a message from apache or the browser?

unborn sluice
feral wadi
unborn sluice
#

also i do hope you enabled this site configuration, right

#

wait a minute

#

that's a dns probe

#

can you show us your dns configuration

feral wadi
#

The one on the client pc, or the server?

unborn sluice
#

the server, that's a weird question btw

feral wadi
unborn sluice
#

no not that

#

I meant the DNS config of the domain

feral wadi
#

It's this I believe

unborn sluice
#

still no, that's the DNS server not the config

#

was talking about the A records, CNAME etc

feral wadi
#

Ohhhh

unborn sluice
#

where's your record for diva

feral wadi
#

So this then?

unborn sluice
#

you CNAME it to itself?

feral wadi
#

im not bigbrain

#

also it's late lol

unborn sluice
feral wadi
#

no smart sometimes

slim parcel
#

If I have a question about a new NAS, would it be better to ask it here or in Tech Support?

warm mica
#

@feral wadi
CNAME should be pointing to thisisruka.fans
Change it then run
Ipconfig /flushdns
on your pc

unborn sluice
#

his whole config is just plain weird

feral wadi
#

It's working

#

I'm not extremely experienced with this as you could tell

unborn sluice
#

forget the apache reverse proxy

#

just redirect your domain to thisisruka

#

or cname it whatever

frigid sphinx
#

welp.. I destroyed hardware today 😦

#

in good news I bought 2 in bad news I think I blew up a minipc

unborn sluice
frigid sphinx
#

nuc form factor yeah

#

chinese laptop part based things.

#

this was totally my fault. I didn't unplug the power working on it and dropped a screw on the board.

#

like I KNOW better I was just rushing

#

but I have one working one.

unborn sluice
#

welp, live and learn again again

unborn sluice
frigid sphinx
#

interestingly it's got $40/unit more expensive since I bought it

unborn sluice
#

oh a pfsense-in-mind pc

#

neat

frigid sphinx
#

well because that's not complicated enough

#

it now has a tb of storage and 32gb of ram.

#

because I want to virtualise a few things on it.

#

asterisk, sdn controller, pfsense

#

and maybe a factorio server...

#

so I bought 2 and I killed one 😦

#

I also bought a 1tb p5 nvme because I misread the specs and it's actually msata not m.2

#

I then bought and shucked a samsung t5 portable drive becasue msata drives are $400 for 1tb and the t5 1tb was $139 at $majorretailer

frigid sphinx
#

so the exercise has resulted in spare parts for next build...

#

and maybe I'll return the 2nd samsung t5

#

now I just need to get a system installed on this

plain siren
frigid sphinx
#

plan is a few vm's šŸ™‚

plain siren
#

That VM Overhead is going to be deadly

frigid sphinx
#

it's 3%

plain siren
#

the VM Virtualization itself is but you have the overhead of running each additional OS on top of the Host OS with all its included default services that cause overhead

frigid sphinx
#

so there isn't a host os in this plan šŸ˜‰

plain siren
#

ESXi is considered a Host OS

#

Now.. Lets say you ran Containers instead of VM's

That would have damn near 0 overhead

#

While giving you that same sense of segregation

frigid sphinx
#

so there's enough cpu and ram here imo

#

internet is only 100/40

#

so it's not like I'm trying to route gigabit

#

so the reason for a t1 hypervisor is pfsense vs a linux based router

plain siren
#

Oh thats also gonna be the next fun thing

Doing PFSense in a VM is a huge PITA

#

You end up isolating the Multicast

#

And stuff like VLANs dont always work right without SR-IOV

#

Thats the one thing I generally say you would run bare metal on its own platform

frigid sphinx
#

so pci passthrough was something I considered for the pfsense guest

plain siren
#

SR-IOV is your friend for the Nic Functionality

frigid sphinx
#

yeah

plain siren
#

Would let you split up those 4 Nics into segregated "Hardware Nics" split across multiple VMs

#

(I have one of these boxes myself, this is What I used)

#

Its worth noting, I found that the Celeron is pretty limited on how far you extend it out, so dont overload the box with too much demanding services

#

I notice you said you killed a second MiniPC so idk if you would consider another to help spread out your stuff

#

Really helps with the oddball routing issues you will run into running pfsense on the same box as other services that needs to be on the same pfSense Routing

frigid sphinx
#

mmmm

#

I kinda want to give this a shot. but I hear you

plain siren
#

Mini PC (Nic 2 (LAN)/PFSense) > Switch > Mini PC (Nic 3/VM Nic)

#

So you loop back to itself

#

Nic 1 Would be WAN

frigid sphinx
#

nah you put a tun interface on pfsense to a bridge for the internal vm's

plain siren
#

yeah that was the other option I was about to say

#

But the second you have it do bridging internally through virtualized software, you will be surprised how much power it eats up on the CPU

frigid sphinx
#

hrm

plain siren
#

Meanwhile you use a physical Bridge (Switch) its basically the equiv to "Hardware Offload"

#

Thats why I like that Mini pfSense Dedicated appliance option

#

You are not messing with the SR-IOV Details and settings for shit like Multicast and VLAN or the physical/virtual routing oddities of doing routing + Services on the same machine

thick minnow
#

so I was looking at some ubiquiti edgerouters cause I was bored, and found some site selling them for over 4x retail, and when asking their support if they offer anything above competitors to justify this they just said "the price of a product depends on various factors like demand and supply, shipping cost, customs charge, quality etc"

plain siren
#

Its more of a quality of life thing

thick minnow
#

I know ubiquiti store is in USD but Scorptec has them priced at $2400AU

plain siren
#

Scorptech
Ive heard this name before and it came with complaints

thick minnow
#

ive never had trouble with them

frigid sphinx
#

scorptec have been reasonable for me.

#

they're au specific tho

thick minnow
#

spent over $15,000 over the last 5 years and only had one faulty razer headset

plain siren
#

I feel for the AU Marketspace, such a mess with pricing

thick minnow
#

but even ubiquiti doesn't charge anywhere near $6000AU, let alone the supposed regular price of $11,000 that site is charging

frigid sphinx
#

could be worse we could have newegg shipping dead stuff šŸ˜‰

thick minnow
#

over 4x the damn price of the thing when it's not out of stock or anything

frigid sphinx
#

local pricing is heavily dependant on forex rate among other things

#

not to mention that with almost everything being made of unobtanium these days there's some gouging going on

thick minnow
#

I can buy direct from ubiquiti and exchange rate still doesnt make it go over $3,000AUD

plain siren
#

I wish TP-Link would increase their Omada product range to have closer to the amount of options that Ubi has

frigid sphinx
#

so omada is the sdn I landed on for this upgrade

thick minnow
#

sold out at scorptec, but again, I can buy direct from the US no problem. charging $11,000AU for this thing is an absolute rip off

plain siren
#

I replaced a few Ubiquiti solutions with Omada, its worked really well

frigid sphinx
#

615-wall for my office on the other side of the house and a 610

plain siren
#

Yeah I used the Wall AP's

thick minnow
#

ok I've found an edgerouter in stock at both, look at this

plain siren
#

What a difference

thick minnow
#

charging 2x the price, yeah

#

these guys have a au.name.com domain so im guessing their aus presence isn't huge, no way they would last charging 2x retail

frigid sphinx
#

so buy from the top retailer

thick minnow
#

yeah im not buying from bottom one no way, just found it ridiculous how much they're charging

frigid sphinx
#

who's the bottom one?

#

scorptec ?

thick minnow
#

directnine is the bottom, scorptec is the top

#

scorptec are one of the best in aus imo

frigid sphinx
#

ah I thought you were saying that scorptec was charging multiple times RRP

thick minnow
#

oh no soz

#

thats scorpion

frigid sphinx
#

I bought 2 EAP610's from scorptec

#

the eap615-wall was $10 cheaper at auspcmarket and a couple of 2008P switches

plain siren
thick minnow
#

I've done a little bit of shopping with them over the years

plain siren
#

This is what I am looking to do at my own house for a new solution

thick minnow
#

they've just had everything computers I've ever looked for (ill stop posting cause im getting off topic)

frigid sphinx
#

so avoiding the consolidating the router and oc200 was the reason for the minipc

plain siren
#

I havent decided on if I wanna use the ER7206 "VPN" Router or pFSense yet

#

I have a NanoPi R4S with pfSense loaded on it already so I might try out both to see how it works

frigid sphinx
#

I don't like the idea of routing particularly intervlan routing on a pi

plain siren
#

Its a RK3399 Chipset, The thing is pretty damn capable as a Router

#

I use a few diff RK3399 SBCs of Varying configurations for many things atm

#

This is one of my fav RK3399 Boards

frigid sphinx
#

cute

plain siren
#

Has a Battery, USB C With PD And DP Alt Mode (4K Output with HDR @ 60 FPS)

#

Runs Android and Linux

#

I just finished porting Windows 11 ARM64 to it

frigid sphinx
#

how does one port windows arm? is there a insiders program for it?

plain siren
plain siren
#

You need to make the various edits needed for the specific hardware platform too

#

PCIe Path Routings and such

frigid sphinx
#

so this is all exposed without the windows source?

plain siren
#

Yes

frigid sphinx
#

ok

plain siren
#

This is the main UEFI project which is ran by Intel

frigid sphinx
#

yep familiar with it šŸ™‚

#

the uefi bit made sense that's not what I was really curious about

#

it was how the hal/windows port bit worked

plain siren
#

Thats the hard part, you gotta write those drivers yourself

#

I dont have any of the periphs working yet

#

It does have functional display output

#

And the USB Ports were working with the generic drivers since that routing is handled with EFI

#

But things such as SD Card, Camera, MIPI-DSI, And Audio are Unknown

frigid sphinx
#

display is pretty big.

plain siren
#

The built in Mali Drivers and HAL package worked out thankfully

#

It doesnt have HDR enabled on this particular package yet though.

frigid sphinx
#

sd card is a pretty simple interface hardware wise..

plain siren
#

yeah its just a SPI Interlink

#

Thats gonna be the first one I do

frigid sphinx
#

audio could be.. a nightmare.. and camera.. ugh why didn't they just put it on the usb bus šŸ™‚

plain siren
#

Faster

#

It also has a eDP Connector, which makes it interesting if I opt to enable it

frigid sphinx
#

less cpu šŸ˜‰ usb is a bus designed by intel to sell more cpu šŸ˜‰

plain siren
#

Thankfully all the Linux Drivers for these various boards are on-point regarding their periphs and capabilities

#

So I can use those to make my Driver Development way easier

#

OH yeah there is also the IR Sensor and Gesture Sensor, thats gonna be fun

#

Battery, DC Jack, and USB PD are routed in UEFI, the Generic Charge Arbitration drivers work great

#

Wi-Fi worked on and off but I need to go in and modify it

#

Honestly, doing all of this gives a sense of respect to Windows ecosystem and how its able to support so much. Also the amount of work that goes in behind it

frigid sphinx
#

windows isn't a bad operating system honestly

plain siren
#

I agree 100%

frigid sphinx
#

(ntkernel.dll) windows not 9x 9x was garbage

#

and I think there are bits of the api that are better...

plain siren
#

The Management and Remote Systems interface and API + Documentation for Windows is Top Fucking Tier

frigid sphinx
#

oh I meant the kernel ipc stuff with your pid just being in a register and stuff

plain siren
#

The dynamic levels of abstraction Windows provides between the OS, Kernel, and OS has offered shit loads of Flexability

frigid sphinx
#

right.

thick minnow
#

oh my god I FINALLY got my NAS's certificate to be trusted

plain siren
#

I need to get that M.2 Port + NVMe Working on that "Mini DIY LAptop" I posted earlier too... That should also be a simple port

thick minnow
#

I have literrally had that issue for over 4 years

plain siren
#

At some point I would just have a private CA/Sub-CA server

thick minnow
#

like every time I tried to do it I would install install install in every store I could think of and it didnt do it, you know what I was missing?

plain siren
#

OID?

thick minnow
#

I never filled in the "subject alternative name" field

plain siren
#

HAHAHA

thick minnow
#

so the cert never actually said what it was for because I have been so smooth brain

#

to be fair the nas's help button says tahts for securing subdomains, doesn't mention it's also for the root name :/

#

now to see if I can install it on my laptop

#

so I bruteforced it on my PC now I don't know what is actually needing to be installed on my laptop, just the CA? or the certificate as well?

plain siren
#

The CA generally is all thats needed, but the Sub-CA in the Chain is ideal if you get that too

#

If there is one

thick minnow
#

hmm so I installed CA but still saying invalid cert

plain siren
#

You put it in here right?

thick minnow
#

how do I get there again? crtmgr.msc?

plain siren
#

ye

thick minnow
#

yep its in there

plain siren
#

May wanna put it in here too.

thick minnow
#

huh thats all it was missing

#

the third-party root one

plain siren
#

Ye

thick minnow
#

thank you once again my tech lord

plain siren
#

Trusted Root Certs are for Windows Applications while Third-Party typically gets inserted into Browser Cert DBs

thick minnow
#

aaah

#

I shall remember that for da future

plain siren
thick minnow
#

ok now I cant seem to get it installed on my windows VM

#

well that fixed

#

for some reason exporting the cert from the NAS's store doesnt work, but installing it from the web browser when it comes up as bad does fix it.. weird

#

the one I downloaded straight from the error is 2KB smaller than the one I exported from the NAS.. but all the details in the certificate window are the same

waxen scroll
#

this is such a bad take but whatever

#

@clear igloo @plain siren šŸ’

#

The value of CCIE is little BECAUSE it has bias to people that can memorize text and not apply it well, there are test cheats as well as people borrowing other CCIEs credentials

#

Also 8xCCIE? Talk about not knowing anything

#

He's attempting to defend the fact that he barely remembers any of the test content IMO

#

I feel like a [legitimate] CCIE whose last memorized (some feature) years ago and a CCNA would come to the same conclusion around the same time? Why? Both are gonna google it.

#

So where's the value my dude?

hollow marlin
#

Im still going for my JNCIE-SP in spring regardless of what others think the value is . We all know which set of people are just allowed to bribe their way through but I don't think it should tarnish the cert entirely. Especially now that it has been changed to just the lab as a response to the rampant cheating.
Going for either IE is just a goal of mine, keeps me motivated. I can say that my studies have helped immensely in my day to day. There is more to than just memorizing CLI

#

As far as value, googling has lowered the bar across the board. To be fair, the minimum barrier of entry has sky rocketed over the past few years as the amount you need to know is ever growing. Googling is always going to be part of the job. But in many scenarios, a NA vs IE googling for an issue and resolving it the same, the NA may have found the fix but the IE may have a better understanding on WHY that was the fix.

#

I have worked with too many "experience is all that matters" people and its worse than the IE cheaters. In reality its going to be a mix of both studies and experience, not one or the other

low pond
#

What does IE even stand for

hollow marlin
#

Internetwork Expert

plain siren
#

Infra Engineer/Internetworx Exp

waxen scroll
#

the barrier of entry to networking has always sucked ass

#

the dirty details are easier to learn now but its still difficult to get your first few jobs

unborn sluice
waxen scroll
#

the worst is when a company makes a "cloud" team and forgets that networking is still relevant in the cloud. or they hire a "cloud network engineer" who is not embedded in the actual network team

#

@plain siren this is why we have prefix lists on everyyyyyy thing

#

cant be trusted.

#

I betcha corp outages from cloud changes are common too šŸ˜„

nimble sable
#

idk if this is the right place to ask but, does anyone know how to access host machien from inside a vmware instance via tcp/ip?

unborn sluice
waxen scroll
#

@unborn sluice my company attempted to fork our entire network team for the cloud. Tools, Automation, DNS, etc

#

we saw the job posting and were like WTF

#

they never asked us

unborn sluice
#

so you were the cloud team even before you knew it

waxen scroll
#

not sure what the end result was. I think the jobs got squashed but not sure what they're doing

unborn sluice
waxen scroll
hollow marlin
#

8 is too many. There gets a point where its more detrimental to keep pursing different certs. 1-2 is the most I can see having any value

waxen scroll
#

All these companies struggling to hire remote neteng
General Dynamics: We need neteng, 100% travel, must have secret clearance already

#

good luck, bro

#

@unborn sluice im laughing cause Meta has been trying to hire multiple neteng for months now and clearly not working

sudden kayak
#

I've been thinking about getting one of the 1L business USFF machines, they seem to run $300-400ish for an older gen 14nm i5 but ... that's only with one gigabit NIC

#

if that is really 4 2.5G nics that's kinda insane for the price

trail trench
#

guys, is it possible for me at home to set in the router avoid a certain network? My friend keeps having packet loss when playing rocket league and we identified the router that's causing it with traceroute, it's some random german network and not something in his LAN

trail trench
#

that's sad

forest furnace
#

what is the newest cat cable for ethernet

peak cloak
#

once you go up the higher numbers the standards become blurry

forest furnace
#

i running a nas

peak cloak
#

like basically most cat7 cables on amazon are not actually cat7 spec

peak cloak
forest furnace
#

fast as

peak cloak
#

useless answer

forest furnace
#

need for nas and fivem server

peak cloak
#

what network interfaces does your NAS have, network devices, computer

#

I assume it's only gigabit

#

and then cat 6 is what you need

forest furnace
peak cloak
#

everything between NAS and PC is 2.5 ?

forest furnace
#

so cat 7

peak cloak
#

2.5gb interfaces on NAS, Router, AND PC?

peak cloak
peak cloak
forest furnace
#

ok

peak cloak
#

heck, 2.5Base-T can apparently work on 5e

#

but you really don't need anything better than 6a

waxen saddle
#

CAT6A will go up to 10gbit. CAT7/8, if I recall correctly, aren’t officially certified and more of either a marketing gimmick or companies pushing non-standardized cables that MAY do what they advertise, and might not work the way you expect it to.

clear igloo
# waxen saddle CAT6A will go up to 10gbit. CAT7/8, if I recall correctly, aren’t officially cer...

Cat7 is an ISO standard but not TIA/EIA which isn't too big of a deal BUT Cat7 spec calls for TERA connectors which are not compatible with 8p8c connectors. Cat8.1 and 8.2 are TIA/EIA and ISO standards allow 25GbE and 40GbE respectively with 8p8c or TERA connectors but there isn't anything on the market that does 25GbE+ over copper RJ45 cables and it's limited at those speeds to like 20m or something

meager ginkgo
clear igloo
#

^ Exactly

meager ginkgo
#

If you really want to futureproof run smurf tube to all the ethernet locations and pull the 6A inside of it

vapid cargo
#

Is this the place I can ask questions about servers or?

frigid sphinx
#

so the fastest interconnect is 10Gbe

#

and the cheapest interconnect is short copper (1m) with integrated SFP's

#

it may be worth doing 2.5 or 10Gbe to a switch if you have several user stations on 2.5 or 1Gbe

#

@forest furnace ^^

little schooner
#

and ty @waxen scroll for the Cisco article. I shared it with my net admin so he could understand the issue and try to bring it up to the ppl who can make switch changes. it's sad they don't let him use the commit or save commands

south blade
#

These supposed to be accessible on my network? I need to access port 9512 but it doesn't seem to be detected as open on this Windows 11 desktop, my phone port scanner only sees port 5357

#

5357 is repeated here also, not the 9512 that I need

peak cloak
south blade
#

Yeah, app on my phone worked fine when I was on Windows 10.

#

The app thinks it should be accessible.

peak cloak
#

nevermind

#

there is, my bad

south blade
#

0.0.0.0:9512 should be reachable on network? Or does it need to be [::]:9512 also?

peak cloak
#

[::]:9512 is ipv6 synatx

south blade
#

ok

#

doesn't show the port but this is it here in Firewall allowed apps,

plain siren
#

Cloud Engineering as a whole is based on Networking

#

Its not just Terraform and Done

#

You are still working with the core Network Appliance elements but in a very easy to manage fashion and the fact that its so easy makes it so overlookable

south blade
#

I just found something called simplewall as an addition to Windows Firewall, gives me notifications on connections but it's not telling me anything is trying to get to 9512 when I try to connect to it. :/

unborn sluice
toxic chasm
#

Can I have multiple bridges to the internet on one network?

#

A main modem and router, then another 'router' acting as a switch and a bridge

peak cloak
#

Both on layer 2

toxic chasm
#

So I just did a wireless point to point from my network to my neibers network (more or less both basic small home networks) and forgot that both routers will be on 192.168.1.1 because I am dumb.

I thought that because the RB2011 I was using for the wireless station pseudobridge didnt have DHCP I would be good.

#

Fun part was, it somehow worked even with both on. We could each unplug our routers and fail over to the other one.

#

Both being on the same ISP and same power means it does not matter, but still. kinda cool.

main tartan
#

I couldn't really find a better place to ask my question, so I'll ask it here. Recently I started using Mullvad VPN, but I also host a minecraft server.

I thought I could just force the server to use my real IP, by adding java.exe to the exceptions in the Split tunneling list. But that's not the case, it will display that the server is online, but when people attempt to connect it will throw an error. "Failed to connect to authentication servers". When I disable online_mode in the server.properties file, people can connect without problems. When people are connected, and I enable my VPN with java.exe in the exceptions, people can still play, but no one would be able to join.

But I use a whitelist on my server, to prevent server finding bots from griefing our server. So I have to use online_mode.

Now I was wondering, what could I do to fix this problem. Could I just add some more files that minecraft uses to make these authserver requests? If so, which files would they use? Or how could I run the server through my VPN without the external IP changing for my friends? Any help would be greatly appreciated.

peak cloak
main tartan
# peak cloak Don't use a VPN on the mc server ..

I just host the mc server from my personal rig, since it's just for friends. But yes that is probably the best solution, just getting a small dedicated pc to host my mc server. Although I don't wanna spend money on that rn :p

thick minnow
# main tartan I just host the mc server from my personal rig, since it's just for friends. But...

I mean, there is always a risk hosting servers from your own rig. Take log4j as an example, there could be other vulnerabilities you simply don't know about yet that could be exploited to gain RCE on your local machine.

If that occurs, and it's on your personal rig - they've got the holy grail of data and can just run a script to scrape everything they can and leave just like that. Since you've got a port open and a service running on it too, it means it's not much effort for them to exfiltrate it and start a reverse shell straight from the internet either.

I'm not trying to scare you, I'm just saying there are risks involved so be aware. Personally, depending on how much resources you need, you can host your server for free somewhere else.

Oracle Cloud, Amazon Cloud, and Microsoft Azure will all offer you at least a year of free computing power. It will be fairly limited specs, but it will work.

Alternatively, I'd grab a solution like https://www.zerotier.com/ which is pretty modern and easy to use, and relatively secure - and it will allow you to set up a logical LAN with your peers, and you can avoid being advertised directly on the public internet.

main tartan
#

Thank you very much, I'll look into it :)

peak cloak
#

If I could I would use a seperate global v4 IP for it

opaque stirrup
#

i need to find a decent cheap router to vlan my server off from the rest off my network but i dont need wifi on the router 😦

peak cloak
#

I have an Er-X

#

And some managed dlink switch

#

Then you just setup firewall rules between subnets

#

What I do is allow new connections from lan to servers, but not vice versa

opaque stirrup
#

i was gonna get one of them but someone said it was old and not supported or something anymore

peak cloak
#

I mean yeah, a lot of things are not available in gui, and it's a bit older

#

Hw acceleration with v6 is broken, but I think that's an actual hardware issue, nothing that can be fixed

opaque stirrup
#

everywhere is sold out on them they must be more rare than the pi4 just now

peak cloak
#

Yeah, I mean a miktotik HEX will also work great, if not more powerful

#

The CLI imo kinda sucks too

opaque stirrup
#

no gui?

peak cloak
#

But its not as user friendly I would say and has a few quirks for home use

opaque stirrup
#

not epic at all

peak cloak
opaque stirrup
#

oh

#

what about this funny little fella my server has sfp šŸ¤”

peak cloak
#

Hex S has sfp

#

I have one, right now not in use

opaque stirrup
#

is ubiquiti not more friendly?

peak cloak
#

But once you want to do anything super advanced you have to use CLI

#

Like firewall can be done all in gui

#

But 99% of anything ipv6 is cli only

opaque stirrup
#

lets say my mesh wifi supports vlan for the guest network would that allow me to seperate it or is there some thing missing in that

#

like you can set a VLAN ID for the guest network

peak cloak
#

I mean yeah you can do vlans

#

Policy based routing

#

Alot

#

Vrfs

#

OSPF, BGP, etc

opaque stirrup
#

i have a dodgy chinese camera i dont want talking out the way i just want to view the footage on a phone on the same network so how ive done it with my tp link mesh wifi is put it on the guest network and basically set it as a child with 0 hours of internet access with the parental controls lmao

peak cloak
#

Multiple ways to solve a problem

opaque stirrup
#

would this thing do the job?

#

tp link for you

peak cloak
#

Perhaps, but I don't think it has as much configuration

#

Like with mtik, all their routers from smallest to largest run the same powerful OS

opaque stirrup
#

oh i see

peak cloak
#

Has some quirks that imo are just not the best for home use. Features that are in other home routers, but require scripting on mtik

opaque stirrup
#

should i avoid buying a used router on ebay?

carmine moss
peak cloak
#

I mean I would. Not like some basic consumer router tho

carmine moss
#

buying new ubiquity or mikrotik for home use is the way to go tho

peak cloak
#

Was actually looking at older juniper ones for learning

opaque stirrup
#

i cant find new ubiquti on any website its all sold out

peak cloak
#

I would buy used tbh. Many people upgrade and want to get rid of it.

carmine moss
#

i have seen cisco nexus switches a few times used they huge

#

tho who is gonna buy that used

peak cloak
#

That's like big business

#

They don't buy used

carmine moss
#

yeah and 2 of them are for sale at a refubrisher i do internethip at

#

like no one buys that as no one needs that

clear igloo
#

You definitely need a N9K-C9332D-GX2B šŸ˜„

clear igloo
clear igloo
# peak cloak Yeah

and it makes sense, if you can get used enterprise stuff as a small business it can be cheaper than new SMB targeted stuff and if you don't care about support it can be really cheap as is or for parts for EoL stuff

rugged quiver
#

If there's still lead time on ordering network equipment, it might be the only option if you're desperate.

clear igloo
thick minnow
gloomy violet
#

Is there a reason my desktop won't connect to my mobile hotspot?

It's running Windows 11 atm, was connected to WiFi like 2 weeks ago but we don't have WiFi anymore.

I've tried everything, disabling network firewalls changing the band its connecting to and still nothing. Any help would be greatly appreciated.

unborn sluice
#

What's the error

gloomy violet
#

It says "no internet, secured" after connecting

#

@unborn sluice

meager ginkgo
#

my pc says that when connected to my hotspot but it works

unborn sluice
gloomy violet
#

Yea I have tried and it can't access the internet. The connection is full bars on both my phone and when it pops up on the WiFi sconne tuon selector on the pc @meager ginkgo @unborn sluice

thick minnow
#

Added some RGB to my cabinet

clear igloo
gloomy violet
#

Android

pulsar thorn
#

Hmm okay, maybe try taking sim out and putting it back in?

waxen scroll
royal crane
#

Hey there! So I have a 10Mbps Up/Down internet connection (probably DSL) which works great and I get the speed that I pay for. However if I do a speedtest the speeds I get are about 80-90Mbps. So I wanna know why is it like this and if I can get that higher downloading speed now that I know that my connection can actually deliver that extra bandwidth. While using torrent I get the extra speed but not on normal downloading.

PS- I'm not a networking expert or something but it's always good to have more speed without actually paying for linusSmirk

sudden kayak
#

if you're getting faster speeds than you pay for, it will apply to everything on your connection, unless your ISP is doing something really shady

#

the only other reason regular downloads wouldn't be that fast is if the server is throttling download speeds for individual clients, which is the reason for torrenting anyway

low pond
#

It is possible to rig speedtests for sure. I have seen it with an friend's ISP, speedtest was giving more speed than promised, real subscribed speed was way lesser, and actual real world speed was near the subscribed speed

royal crane
peak cloak
#

try another browser?

haughty basalt
#

Speed tests on internet are about the most useless thing. They can only test to locations setup as receptors, which you notice are never the site you individually want to measure.
Learn how to read the network tab of your browsers debug (F12) menu

peak cloak
#

I wouldn't call it useless tho

#

Can verify max throughput of a connection

haughty basalt
#

Max throughput of your ISP, not the internet.

peak cloak
#

well yeah...

#

you can't speedtest an individual connection between routers

#

unless you are the operator of said routers

haughty basalt
#

The internet being interconnected tubes of different sizes and densities makes speed tests just a tool to help people spend money on bandwidth they don't need.

peak cloak
#

yes and no

#

anything like google, netflix, etc. utliize CDNs so you have fast downloads/uploads

#

lowers backbone bandwidth as well

#

you can except full download and upload to these CDNs and close POPs or whatever the name is

royal crane
peak cloak
peak cloak
#

or something with poor peering and/or transit

haughty basalt
#

For the average consumer, speed tests are not a troubleshooting tool is what I am saying.

peak cloak
#

ehh, they can be

#

much better than looking at ping

haughty basalt
#

That's like remeasuring the size of your water main rather than trying to figure out where the blockage is inside the pipe.

peak cloak
#

@royal crane where are you downloading from on chrome?

peak cloak
#

for some things, yes they don't help

royal crane
#

uhh...i just tried to download some anime to test

peak cloak
#

from what server

#

try google drive

#

like revolver said, connection to one server isn' the same to all

royal crane
high widget
#

hallo Does anyone know anything about fibre SFP+??

peak cloak
viral gulch
#

Anyone know exactly what it is Apple is looking for here?

Can’t find much useful info on it anywhere apart from confused forum posts. It’s not the use-application-dns.net canary domain, since that resolves fine. And there’s no Pi-Hole or similar on this network. Just bare standard Unbound, configured as a recursive resolver and without any fancy options.

lone tide
clear igloo
viral gulch
#

I guess that would make sense. The ā€œblockingā€ wording is a bit of a poor choice in that case though.

clear igloo
#

Definitely poor choice of words but I guess it's easier to have one message than conditional statements to determine things, lol

waxen scroll
clear igloo
#

Simple messages are easier and I guess how would you really tell if it's just not responding or setup to respond vs blocking them outright

viral gulch
viral gulch
waxen scroll
#

šŸŽ¶ In my iLife. In my iWorld. On my iPhone, with my iGirl.

high widget
#

this is going to take a while I am dyslexic I use a voice to text

waxen scroll
#

@clear igloo I got friends who complain that my chat bubble is green or whatever it is. I'm like, I dont know why you're complaining about ME, I have the better phone.

clear igloo
waxen scroll
#

on iphone it means no rich text

clear igloo
#

poor text is fine

waxen scroll
#

Personally I think pixel software is vastly superior over iphone

#

the GUI is perfect. I dislike the iphone gui

clear igloo
#

I like Pixels but the Android 12 layout is too simple I guess would be the word on them

#

So I stick with Samsung

waxen scroll
#

I only get iphones if work is supplying cause they're a second phone and I need it tiny

#

carrying two big phones is meh

lone tide
waxen scroll
#

Some say @lone tide is still waiting

lone tide
low pond
#

legends say jjc waiting for the question after a year still

dire oriole
#

"The specified port(s) are being used by other configurations.Please check your configurations of USB Readyshare, Remote Management, Port Forwarding, Port Triggering, UPnP Port Mapping table, RIP, and Internet connection type."
Port: 1723
Router: Netgear C7800

Anyone know why it won't forward? No existing port number on the router.

lone tide
dusk marlin
#

what specs do I check for to see if the router has VOIP and is re-configurable? I'm looking to get a BYO router for my new internet plan (AUS)

dire oriole
lone tide
dire oriole
dire oriole
#

I read through that guide with no resolution sadly

lone tide
dire oriole
#

Router DHCP

#

Could that be the culprit? Cause I didn't see that netgear genie software link in that article.

lone tide
#

DHCP should have no link to port forwarding. but its netgear.. so who knows..

dire oriole
#

šŸ˜‚

#

Twas not the culprit

lone tide
#

What does this look like when you try to set it up ?

dire oriole
lone tide
#

There is the option to export your configuration and read the text files it makes.. that way you may be able to see who currently uses the port or is causing you trouble..

dire oriole
#

[LAN access from remote] from 107.115.242.177:58523 to 192.168.0.30:1723, Mon, Feb 21, 2022 08:27:51
[LAN access from remote] from 107.115.242.177:58523 to 192.168.0.30:1723, Mon, Feb 21, 2022 08:27:42
[LAN access from remote] from 107.115.242.177:58523 to 192.168.0.30:1723, Mon, Feb 21, 2022 08:27:38
[LAN access from remote] from 107.115.242.177:58523 to 192.168.0.30:1723, Mon, Feb 21, 2022 08:27:36

#

Found that in my logs tab

lone tide
#

is anything in that service area ?

dire oriole
#

Not that I can see in the attached devices

lone tide
#

so something is using a vpn in there..

dire oriole
#

Can't think of what, and also there is no 0.30 connected

lone tide
#

several of those are configured to talk to .30 ?

dire oriole
#

yeah which doesnt make sense

lone tide
#

ping -a ipaddress

dire oriole
#

.30 or the other one

lone tide
#

.30

dire oriole
#

.32 is my pc

lone tide
#

The other address is maybe somewhere in dallas..

dire oriole
#

Might've been me trying to connect through the hotspot on my phone from my laptop

#

But why would it direct itself to .30?

lone tide
#

maybe šŸ™‚ but even so.. if you dont have .30.. try and remove the rules šŸ™‚

dire oriole
#

where would I remove the rules at?

lone tide
#

you have the option to delete the services in the settings

#

og.. and if you have UPNP enabled on the router, then you may not even need to make the rules for vpn passtrough.. depending on the vpn server you are running..

dire oriole
#

It's a tunneling VPN

#

The service in windows or in the router?

lone tide
#

yes. but first negotiation opens the proper ports

dire oriole
#

UPnP is disabled

lone tide
#

in the router.. you have 3 services tied to .30 .. if you dont have .30. then you should probably remove them instead of having holes in your firewall.

#

try and enable that and see if it fixes the auto porting.

dire oriole
#

I changed them over to .49, my server used to be .30

dire oriole
lone tide
#

do you have an isp router in front blocking you ?

#

still just wierd that it does not let you register that rule..

#

i like the idea of going pfSense and making the netgear into an ap šŸ˜›

dire oriole
#

Wait I got it working

#

I'm connected to it

lone tide
#

great šŸ™‚

#

do you know what made it work ?

dire oriole
#

Now I need to figure out how to allow it to see the network drives I've allocated

lone tide
#

what vpn server ?

dire oriole
lone tide
#

yaay.... windows..

dire oriole
#

I'm connected to my router via server pc through a vpn. I need to access the drives on my gaming rig and the server via network discovery which I have setup.

lone tide
#

but what is the vpn server then ?

#

there are so many one may deploy these days

dire oriole
#

What do you mean?

lone tide
#

The vpn you are using. what is it called ?

dire oriole
#

I'm using the built in connection creator in windows on my server pc

lone tide
#

oh..

dire oriole
#

The sole purpose of this is to connect to my home network and see network drives so I can edit and do whatever with the files

#

Without having a remote desktop

lone tide
#

ah .. yes.. never used that.. ususally run a linux box/Vm with a vpn server on..

dire oriole
#

Ah

lone tide
#

dont much care for windows implementations of these things..

#

as long as i dont need more than two connections.. this is the reeeeeal easy thing to throw into a linux box..

dire oriole
#

I have to use windows

lone tide
#

there are even OVA files for esxi to just boot up..

lone tide
# dire oriole I have to use windows

It seems you have to enable it in the users in your active directory area.. under the dial in..
in there you can allow network access to the user logging in.

#

and you seem to have to open the routing and remote access settings as well..

lone tide
#

Nope

#

Those are share permissons šŸ™‚

dire oriole
#

Where is the active directory?

lone tide
#

good question.. i only ever did this on windows server.. and i am now in win11 here.

dire oriole
#

I'm using windows server'

lone tide
#

Click Start, point to Administrative Tools, and then click Routing and Remote Access.

#

Click Start, point to All Programs, point to Administrative Tools, and then click Active Directory Users and Computers.

dire oriole
#

I dont have either one of those

lone tide
#

The command is dsa.msc

dire oriole
#

cannot be found

lone tide
#

rrasmgmt.msc

#

you should be able to open those from the cammand promt?

dire oriole
#

its saying that those programs dont exist

lone tide
#

did you enable them in the computer management thing that comes up when you boot ?

#

ohhh wait.. what windows server version ?

dire oriole
#

2022

lone tide
#

in powershell you may need to write " mcc rrasmgmt.msc" to get them up then

dire oriole
lone tide
#

in the server manager it under tools in the upper right and then >> routing and remote access

#

maybe you did not install the service in the ServerManger ?

#

you have to add the role for remote access I guess to find it.

dire oriole
#

i am installing it now

#

I didnt realize till now

#

im so tired that im not even paying attention to details lmao

lone tide
#

me neither.. its their new way of "slimming" down the os for deployment..

#

dont care much for it..

dire oriole
#

me neither

lone tide
dire oriole
#

its 3:40am and i woke up buzzed around 8am

#

i need to disable ics?

lone tide
#

Im stuck in a room due to corona.. so the only thing im tired of is the chair im in..

dire oriole
#

lol

#

at least you're not dying from it like i did when i had it

lone tide
lone tide
#

danish government was kind enough to stab me three times to make that happen..-

#

from what i see you may need ics

dire oriole
#

the routing and remote access is saying i need to disable it

lone tide
#

then you might as well..

#

that thing takes over the subnet routing anyway

dire oriole
#

idk how to

#

google isnt being very clear

lone tide
#

is it enabled for one of your adapters currently

#

?

dire oriole
#

i got it

#

it was that

lone tide
#

What do you have in this env that you need to access so dirrectly ?

dire oriole
#

an external drive thats hooked to my gaming rig

lone tide
#

#NasIT

dire oriole
#

what

lone tide
#

use a nas šŸ™‚

#

but then of cause you would not have the option to learn about the wonders of the windows routing thing šŸ˜›

dire oriole
#

It's not giving the client internet or network access

lone tide
#

?

#

what its suppost to do is enable SMB over the vpn right ?

dire oriole
#

idk

#

its connected via pptp and its not giving it netowrk or internet access, but it's connect to the vpn and is showing up as its connected

lone tide
#

can you ping the pc with the files ?

dire oriole
#

no

lone tide
#

Then it aint routed correct yet.

#

what does the routing settings thing look like now ?

dire oriole
#

what should i screenshot

lone tide
#

is that what you are trying to do ?

dire oriole
#

not exactly but close

lone tide
#

Click Start, point to Administrative Tools, and then click Routing and Remote Access.

#

that thing šŸ™‚

#

is that closer ?

dire oriole
#

Yep

#

But I can access the server's drive as well to manipulate files

lone tide
#

whats under the vpn configuration top left ?

dire oriole
lone tide
#

why open it šŸ™‚

dire oriole
lone tide
#

its nice that never change no matter how many fancy things they stick in the front šŸ˜›

#

need you to unfold that ..

#

is there really no way to share screen in this thing .,

dire oriole
#

if we were in a vc

worthy orbit
#

Anyone here good with mikrotik routers? I'm just trying to get a simple setup but after following this guide https://netwerkje.com/config-internet (it's in dutch sorry) my router itself has internet(can ping any ip/hostname) but my pc does not. Also can't ping my pc from the router but I'm connected using IP over winbox.

#

At one point it even worked but only for a few minutes

#

Apparently I can ping 8.8.8.8

#

But it can't resolve hostnames

#

Set dns manually on my pc and it works now, any reason why dns on my mikrotik wouldn't work?

peak cloak
worthy orbit
honest wind
#

Question about firewall rules on unifi:
If I have vlans 1,2, 3 and 4 and I want to allow 2 and 3 to talk to 1, but not eachother, I could set those rules BUT
Does the traffic have to pass through the UDM Pro?
I have a udm pro, and 2 switches. Each switch is plugged into the UDM pro. If the traffic is going from device -> USW -> device and not passing through the UDM, do the firewall rules take effect?

#

then vlan 4 would be for the unifi protect cameras, and have no access to anything, in theory the udm pro could still record events etc from it?

peak cloak
#

Because think of it this way, technically vlans are just seperate lans and subnets. Anything going between subnets needs to go through router

honest wind
#

will it automatically route it for me?
If so, and I have a 1gbps trunk does this mean intervlan traffic would be limited to 500mbps?

peak cloak
clear igloo
#

It's full duplex, gigabit in both directions

honest wind
#

2 1gbps links being routed through 1 gbps link to the router, then back

#

ok so limited to 1gbps then
For example
Device 1 routes to device 2 at 1gbps. if just the switch, leaves device 3 and 4 to also route at 1gbps
If it has to route all this traffic through 1 trunk port

#

now 1,2,3 and 4 need to share 1 gbps link to the router effectively destroying the switching capacity of the switch. What i'm gathering from this so far.... is don't do intervlan routing except for some management stuff of UI's or something

cedar igloo
#

I've ran https://github.com/dev-sec/ansible-collection-hardening/tree/master/roles/os_hardening on my Ubuntu 20.04 server, but now I cannot access any of the web services running on the machine (both locally and remote). Does anyone have any suggestions to what in this Ansible role might have caused this?

root@ip-10-0-0-193:/usr/local/openvpn_as# netstat -tunlp
Active Internet connections (only servers)
Proto Recv-Q Send-Q Local Address           Foreign Address         State       PID/Program name    
tcp        0      0 127.0.0.53:53           0.0.0.0:*               LISTEN      404/systemd-resolve 
tcp        0      0 0.0.0.0:22              0.0.0.0:*               LISTEN      653/sshd: /usr/sbin 
tcp        0      0 0.0.0.0:443             0.0.0.0:*               LISTEN      827/openvpn-openssl 
udp        0      0 0.0.0.0:1194            0.0.0.0:*                           838/openvpn-openssl 
udp        0      0 127.0.0.53:53           0.0.0.0:*                           404/systemd-resolve 
udp        0      0 10.0.0.193:68           0.0.0.0:*                           402/systemd-network
root@ip-10-0-0-193:/usr/local/openvpn_as# curl -kLv https://localhost:443
*   Trying 127.0.0.1:443...
* TCP_NODELAY set
* Connected to localhost (127.0.0.1) port 443 (#0)
* ALPN, offering h2
* ALPN, offering http/1.1
* successfully set certificate verify locations:
*   CAfile: /etc/ssl/certs/ca-certificates.crt
  CApath: /etc/ssl/certs
* TLSv1.3 (OUT), TLS handshake, Client hello (1):
* OpenSSL SSL_connect: SSL_ERROR_SYSCALL in connection to localhost:443 
* Closing connection 0
curl: (35) OpenSSL SSL_connect: SSL_ERROR_SYSCALL in connection to localhost:443
#

From remote machine:

curl -kLv https://<<PUBLIC_IP>>                   
*   Trying <<PUBLIC_IP>>:443...
* TCP_NODELAY set
* connect to <<PUBLIC_IP>> port 443 failed: Connection timed out
* Failed to connect to <<PUBLIC_IP>> port 443: Connection timed out
* Closing connection 0
curl: (28) Failed to connect to <<PUBLIC_IP>> port 443: Connection timed out

Things I have checked:

  • UFW is disabled
waxen scroll
#

looks like its because openvpn stole port 443 from your httpd and your httpd is not running due to it

wheat flicker
#

What does it mean when plugging in an ethernet cable causes wifi to disconnect šŸ¤”

unborn sluice
#

It means the WiFi disconnects when you plug your ethernet cable

noble wave
#

Work is pitching a 48 port PoE switch (a Netgear GS752TPSb). So that's going with me. That's going to be fun to play with

rocky badge
#

ew netgear

noble wave
#

It was free, and has 48 PoE ports. I'm not complaining

meager ginkgo
#

holy shit

rocky badge
#

i'd rather die than use netgear managed again

meager ginkgo
#

interesting

noble wave
little schooner
#

my unit hard locks after x amount of days into the year

#

The web interface, even in http mode, is slower than a raspberry pi webgui

#

model in question is the gs108T

rocky badge
#

some of them only have the adobe air desktop app

#

both are horrible

#

i do like a good web ui

#

but I want cli for bulk configuration

#

unless your web ui allows for bulk updates

little schooner
#

The bulk updates are really slow, but yeah, its nice to have both as options

#

I was deciding on trendnet switch over one from fs.com but went with trendnet bc of 1 day delivery

#

its alright and miles better than netgear one.

#

Im pretty sure the fs.com switch would of been just as good. it has full cli support too

#

Needed one that had management vlan support and poe+ with enough power budget

soft totem
#

Any suggestions for a fairly cheap router or is it really better to try and make own out of an old pc with an i7 4th gen

silver tapir
#

I'm planning a PfSense VM on my Unraid box and want to re-use as much equipment as I can to save cost.
I want to set up my current router as a WAP for laptops, phones etc, but I want to also set up an old router as a second WAP for IOT devices to keep them away from my server and WAN etc.
The catch is that I want my HomeAssistant VM to be able to talk to the IOT network, and my assumption is that I should do this with VLANs.
My old router I want to use for the IOT network doesn't support VLANs.
Do I need to use VLANs for this, or can the same be achieved with firewall rules?

slow pivot
#

@silver tapir sorta apples and oranges in terms of what you want: VLAN will just allow you to keep ethernet traffic segregated (like separate physical switches would) and routers/firewalls will let you control what traffic can reach which servers/devices

silver tapir
#

Ahh, so hypothetically if I had many ethernet (not wifi) devices that I wanted to segregate with firewall rules, I'd VLAN the switch ports separately so they looked like separate networks with separate IP ranges.
In my instance I have separate switching devices, so it's easy to segregate my IP ranges. separate my devices that are in different IP ranges using firewall rules

Have I got that more or less right?

slow pivot
#

Basically yes

silver tapir
#

So how should I let specifically my HA VM have access to the IOT subnet and vice versa?

#

I could probably assign a dedicated ethernet port to the VM and connect it to the IOT AP

#

Would that be a simplest solution, even if it's a bit ugly?

slow pivot
#

That would be the simplest solution I think.

carmine moss
#

recently got a uap-pro and some tp link poe switch for it tl-sg108pe forgot to reset the ap and used double sided tape on the ap as no mount for it as got it used

#

just got it for fun as my main network is mikrotik tbh was cheap tho

safe vessel
#

it has been a long time since I have purchased a switch "like the 10/100 days". What companies should I stay away from, any? I have four machines total, all updated to 2.5Gbps. I am now wanting a 2.5Gb or a 10Gb switch.

#

For streaming different types of media at a high bitrate

safe vessel
peak cloak
safe vessel
#

I kind of wonder if its pointless to spend that much for a 2.5Gb instead of just getting a 1Gb.

peak cloak
#

2.5 is pretty expensive

#

sometimes sfp+ is cheaper lol

safe vessel
#

there are a lot of names I don't recognise

#

MikroTik

#
meager ginkgo
soft totem
meager ginkgo
soft totem
#

would that be enough for around 5-10 devices?

meager ginkgo
#

Yeah those are designed for businesses

#

So it can handle it no problem

#

How do you manage wifi?