• 4 Posts
  • 90 Comments
Joined 3 years ago
cake
Cake day: June 18th, 2023

help-circle
  • Never used VyOS so can’t help there. I do use OpnSense, TP-Link Omada EAP-650’s (with an isolated vLAN for the guest network) multiple vLAN’s for cameras, iot, management, Trusted devices, and DMZ, along with Wireguard for remote access and since my ISP only gives me an IPv4 address I use a Wireguard tunnel to Route64 for IPv6 connectivity, a cellular connection for backup internet connectivity, CrowdSec, Intrusion Detection, Caddy, and UnboundDNS.

    I used multiple different Router OS’ since around 2005 and settled on OpnSense years ago. I stick around because there is rarely an issue and the reporting system makes it easy to visually spot issues.


  • First, you need to verify whether you actually have a public IP or if your ISP has you stuck behind CG-NAT, because that dictates your options.

    ​If you’re behind CG-NAT, ​Cloudflare Tunnel (cloudflared): This is usually the easiest path if you are mostly trying to access web-based services (HTTP/HTTPS) on your server. Your home server initiates the outbound connection to Cloudflare, so CG-NAT doesn’t matter. You just set up a domain (or subdomains) for each service you want to reach. If you need full network-level or SSH access rather than just web apps, check out ZeroTier.

    ​If you have a direct public IP (even a dynamic one), you can run a reverse proxy like Caddy paired with a free DDNS provider like DuckDNS or FreeDNS. One nice thing about Caddy is that it handles getting and renewing real, valid Let’s Encrypt SSL certificates automatically, so you don’t have to deal with manual or self-signed certs at all.

    ​Dealing with the WireGuard block, if your country’s ISP is using Deep Packet Inspection (DPI) to identify and drop WireGuard traffic, traditional VPNs like OpenVPN might get blocked pretty quickly too. If you still want a true VPN setup, look into AmneziaWG (it’s a fork of WireGuard specifically modified to scramble packet signatures and bypass DPI) or obfuscated proxy protocols like V2Ray / Xray or Shadowsocks.



  • No major formal education. Did a DOS class at a local Community College back in the day, only did it for the certificate and made my high school pay for it. I already knew how to do everything they were walking me through anyway, I only showed up a couple days per week to drop stuff off.

    The instructor made a big deal one of the last days. He stood near this whiteboard and said, “I’m ashamed, I’m appalled, out of everyone in this class, a high school student has the highest grade.”

    I didn’t have the heart to tell him I learned DOS from the DOS Manual when I was 15. I learned how to do some very basic graphic programming and such when I was in elementary school on an Apple II.

    I have worked as a network tech and pc repair tech for a WISP (Wireless Internet Service Provider) helped shoot 2.4Ghz WiFi connections up to 8.5 miles and shot a connection 7.6 miles myself. Most of the network troubleshooting was running multiple ping’s to different equipment to watch for issues. Learned on the job how to weatherproof connections using electrical tape and butyl rubber tape. It’s also where I learned how to crimp cables from the installer we had.

    Most of the job was cleaning up and checking CPE’s that came in from previous installs, configuring the CPE’s for upcoming installations, and dealing with the phones. The owner was working for another company in IT about 3 hours away. I eventually quit when I was stuck trying to train a new installer and needed help with an issue, the owner quit answering the phone.

    I later managed an in house ISP for an apartment building that was converted from a hotel built in the 50’s. I brought in 4 different connections, one from a small local WISP using the building as a tower 6Mbps, two AT&T 3Mbps DSL lines, and a cable modem 6Mbps. And provided internet for about 30 apartments using HPNA. Tried getting the owner to change some things but he was off the thought that if it works don’t fix it. Most people only got between 750Kbps to 1Mbps due to line quality and the technology.


  • Just a bit of information for anyone out there who may have already tried the project. I made a small change as after a time period the logs begin getting spammed with:

    13:56:23 [W] [pm1006k:048] Checksum error: calculated 0xAA, got 0x2A 13:56:24 [W] [pm1006k:048] Checksum error: calculated 0xAA, got 0x2A 13:56:25 [W] [pm1006k:048] Checksum error: calculated 0xAA, got 0x2A 13:56:26 [W] [pm1006k:048] Checksum error: calculated 0xAA, got 0x2A 13:56:27 [W] [pm1006k:048] Checksum error: calculated 0xAA, got 0x2A 13:56:28 [W] [pm1006k:048] Checksum error: calculated 0xAA, got 0x2A 13:56:29 [W] [pm1006k:048] Checksum error: calculated 0xAA, got 0x2A 13:56:30 [W] [pm1006k:048] Checksum error: calculated 0xAA, got 0x2A

    The change fixes that issue through adjusting the checksum. I am going to leave my testbed up and running for a few days to see if any other issues come up.



  • It can be hit or miss for a lot of things. I rarely buy the more expensive stuff but did splurge on an ESP32 for my porch WLED setup as the cheapo kept having issues with the 1400 addressable LED’s. I’ve bought all kinds of sensors and there have been a couple duds but in general I’ve made out better than buying the more expensive ones and I can experiment more with cheap ones.

    My plan is to have a couple sensor packs built and aggregate the results then average them out for a more accurate picture. But I’m putting things in as I rebuild the house. It was what I call a slumlord house, no insulation, bad plumbing, shot roof, knob and tube electrical, etc… But I can go through and run whatever wherever.






  • Supermicro boards go great in Supermicro 4U cases. I’m using an X10DRH-C in a case that holds 36 X 3.5" drives with a SAS backplane. You can grab a CSE-847 for 350 plus tax and shipping on ebay.

    A set of cheap rack rails attached to some 2x4’s with a couple casters on the bottom and you have a rack you can stick in a closet and pull our when you need it.

    The cheap rosewill cases are ok. But it you need to swap a drive (I have the 15 bay version that’s about 100 bucks I used for my server to begin with and now use it for a router with only two drives) it’s a pain to deal with. You have to pull the top, then remove screws to pull the cage for 5 drives, then pull the drive that you need to swap. It doesn’t sound like a big deal til a drive goes bad, or one of the 120mm fans that cool the drives dies.

    The Supermicro is the bottom one, the Rosewill is above it.



  • How is the raspberry pi connected to the router? Have you used it for other projects in the past? What are you using for storage? Is the storage name brand or the cheapest thing you could buy? Did you use the storage for something else first? If yes how long? Have you connected the raspberry pi to a monitor and checked the logs/ made sure it’s running properly? Did you set a static ip address in HomeAssistant or set a static reservation in your router?

    What steps have you taken to troubleshoot?


  • MuttMutt@lemmy.worldtoSelfhosted@lemmy.worldAuth apps
    link
    fedilink
    English
    arrow-up
    2
    ·
    1 month ago

    The one built in to Caddy for anything that doesn’t really have authentication. Everything else uses its own and i only have a couple services accessible outside the home.

    Most everything is only accessible within my home and my guest wifi is on its own vLAN. Even then I’m the only person who actually uses most things that I setup.


  • It’s one of the reasons why getting a SAS controller is really nice, backplanes make it even better.

    I was preforming a burn with 10 X 8TB drives on a controller that already had a couple operating ZFS pools totaling 18 X 4TB drives and a couple SSD’s and there was no slow downs. A SAS3008 controller can support over 6000 MB/s and has a PCI Express X8 3.0 bus.

    I’ve been building my servers and network out of old enterprise gear for a while now. It uses more power but the things you can do are truly amazing. Sadly the ai boom drove prices way up compared to a couple years ago, what I bought for 900 in 2024 is running around 1500 today.


  • I understand. If you buy a used server then add some drives later you can have a great NAS IMHO. I upgraded from an X8DT6-F with 384GB of RAM and a pair of Xeon X5690’s right before things went sideways. The MoBo has the SAS controller already flashed to IT mode so it’s ready for ZFS. But it’s not exactly light on power and with a 2U chassis and a handful of used 8TB SAS drives you are looking at around 1200.

    My current server is a X10DRH-C with dual Xeon E5-2683 v3’s with 128GB of RAM in a 4U chassis with 11 X 8TB SAS drives in a RaidZ3 configuration. Just the MoBo, chassis, cpu’s and 64GB of ram is running about 1150. The drives used are 110 each and before you think you should just get those, SAS drives require a SAS controller and you only get those in enterprise equipment.

    But if you can pick up a little here and a little there you can have a nice system. But right now isn’t a great time to get in the game.


  • I’m not saying that.

    What you need to do is decide now if the drive you will buy will be used for a RAID array. If it is a desktop drive won’t be in a RAID array on a NAS system. Many NAS’ will have random writes to the pool. Desktop drives aggressively park the heads, the load and unload of the heads wears them. In a NAS system they can actually wear out.

    Over the last 15 years drives have become a bit more specialized. You already found out about surveillance drives not being a good fit for much other than surveillance/DVR. Desktop drives are fine for desktop loads and usage but outside of that or single drive usage they are not useful. NAS drives are meant for NAS usage in RAID arrays. Back when the WD green drives were available years ago you could convert them from a desktop drive to a NAS drive using a tool called wdidle (WD Idle) but that isn’t the case any more.

    Using a NAS drive on its own will work in a pinch but if it has an error it won’t try to recover it like a Desktop drive would because it’s made with the idea that it will be in an array that will deal with the issue. Plus once you start loading it up you will have to wipe it to put it into an array unless you go for ZFS mirrors or RAID 1. If the NAS Appliances have some sort of special trickery that allows you to expand one disk at a time and add redundancy I’m completely unaware as I’ve never put much stock in them. I’ve been running FreeNAS/TrueNAS for over 10 years.

    https://en.wikipedia.org/wiki/Standard_RAID_levels


  • If a NAS or Enterprise drive has an error it sends the information to the host to be logged so that the end user can have the information available.

    So like an Unrecoverable Read Error (URE) pops up on a sector. A drive that is built for RAID use will just say, “Couldn’t read it” and moves on. A Consumer drive meant for a desktop will try and try and try and try to read that bad sector. In a NAS situation where another drive will be able to fill in the data the controller (hardware or software) will just deal with it by pulling the data from another drive and keep moving.

    The drive may not be bad as a whole but it does mean that over time it is more likely that drive will have more errors.

    NAS drives are not inherently more reliable, yes they can deal with a bit more vibration and such but it’s the firmware inside that is different. Enterprise drives are another step up again from NAS drives.



  • It’s not just about the advanced functions. Many of the older more basic tools are single threaded which will potentially limit the performance. As you figure things out you will want to do more and you may find the current tools more of a limiting factor. But the choice is yours, I have 2 48port gigabit switches and WiFi SSID’s that connect to specific vLAN’s through tagging. I started with some dumb switches and added my 10Gbps backbone switch which I used as a dumb switch for years so I could connect my desktop and server over a faster connection.

    In my equipment an untagged port is what a port is where the vLAN is stripped away. A tagged port has the vLAN tag passed to the device. If you can set multiple vlan tags on the same port that port becomes a trunked port. You may also be able to set a vlan as untagged on that port, if a device is plugged into that port it will by default be on the untagged vLAN. If the device is able to handle vLAN tagging it can live on the vLAN’s you set up as well.

    It took me a bit to figure it all out and get it working. I spent about 20 hours configuring things before I started making the switch from a single net to multiple vLAN’s. I spent another 8 hours making the change and 5 or 6 more tweaking things.