• 0 Posts
  • 5 Comments
Joined 3 years ago
cake
Cake day: June 18th, 2023

help-circle
  • Never used VyOS so can’t help there. I do use OpnSense, TP-Link Omada EAP-650’s (with an isolated vLAN for the guest network) multiple vLAN’s for cameras, iot, management, Trusted devices, and DMZ, along with Wireguard for remote access and since my ISP only gives me an IPv4 address I use a Wireguard tunnel to Route64 for IPv6 connectivity, a cellular connection for backup internet connectivity, CrowdSec, Intrusion Detection, Caddy, and UnboundDNS.

    I used multiple different Router OS’ since around 2005 and settled on OpnSense years ago. I stick around because there is rarely an issue and the reporting system makes it easy to visually spot issues.


  • First, you need to verify whether you actually have a public IP or if your ISP has you stuck behind CG-NAT, because that dictates your options.

    ​If you’re behind CG-NAT, ​Cloudflare Tunnel (cloudflared): This is usually the easiest path if you are mostly trying to access web-based services (HTTP/HTTPS) on your server. Your home server initiates the outbound connection to Cloudflare, so CG-NAT doesn’t matter. You just set up a domain (or subdomains) for each service you want to reach. If you need full network-level or SSH access rather than just web apps, check out ZeroTier.

    ​If you have a direct public IP (even a dynamic one), you can run a reverse proxy like Caddy paired with a free DDNS provider like DuckDNS or FreeDNS. One nice thing about Caddy is that it handles getting and renewing real, valid Let’s Encrypt SSL certificates automatically, so you don’t have to deal with manual or self-signed certs at all.

    ​Dealing with the WireGuard block, if your country’s ISP is using Deep Packet Inspection (DPI) to identify and drop WireGuard traffic, traditional VPNs like OpenVPN might get blocked pretty quickly too. If you still want a true VPN setup, look into AmneziaWG (it’s a fork of WireGuard specifically modified to scramble packet signatures and bypass DPI) or obfuscated proxy protocols like V2Ray / Xray or Shadowsocks.



  • No major formal education. Did a DOS class at a local Community College back in the day, only did it for the certificate and made my high school pay for it. I already knew how to do everything they were walking me through anyway, I only showed up a couple days per week to drop stuff off.

    The instructor made a big deal one of the last days. He stood near this whiteboard and said, “I’m ashamed, I’m appalled, out of everyone in this class, a high school student has the highest grade.”

    I didn’t have the heart to tell him I learned DOS from the DOS Manual when I was 15. I learned how to do some very basic graphic programming and such when I was in elementary school on an Apple II.

    I have worked as a network tech and pc repair tech for a WISP (Wireless Internet Service Provider) helped shoot 2.4Ghz WiFi connections up to 8.5 miles and shot a connection 7.6 miles myself. Most of the network troubleshooting was running multiple ping’s to different equipment to watch for issues. Learned on the job how to weatherproof connections using electrical tape and butyl rubber tape. It’s also where I learned how to crimp cables from the installer we had.

    Most of the job was cleaning up and checking CPE’s that came in from previous installs, configuring the CPE’s for upcoming installations, and dealing with the phones. The owner was working for another company in IT about 3 hours away. I eventually quit when I was stuck trying to train a new installer and needed help with an issue, the owner quit answering the phone.

    I later managed an in house ISP for an apartment building that was converted from a hotel built in the 50’s. I brought in 4 different connections, one from a small local WISP using the building as a tower 6Mbps, two AT&T 3Mbps DSL lines, and a cable modem 6Mbps. And provided internet for about 30 apartments using HPNA. Tried getting the owner to change some things but he was off the thought that if it works don’t fix it. Most people only got between 750Kbps to 1Mbps due to line quality and the technology.


  • It’s one of the reasons why getting a SAS controller is really nice, backplanes make it even better.

    I was preforming a burn with 10 X 8TB drives on a controller that already had a couple operating ZFS pools totaling 18 X 4TB drives and a couple SSD’s and there was no slow downs. A SAS3008 controller can support over 6000 MB/s and has a PCI Express X8 3.0 bus.

    I’ve been building my servers and network out of old enterprise gear for a while now. It uses more power but the things you can do are truly amazing. Sadly the ai boom drove prices way up compared to a couple years ago, what I bought for 900 in 2024 is running around 1500 today.