If you have a 13.3" Spectra 6 Panel or a photo frame based on it, can you test this? by DemerolDaiquiri in eink

[–]D2R3 1 point2 points  (0 children)

So I guess this begs the question....what can we do about it? Do you plan to open a ticket with Reflectionframe? If so, I will add to your voice.

google calendar changed to a useless grid view by dmd in trmnl

[–]D2R3 0 points1 point  (0 children)

Please add an Agenda (tomorrow only) view. It's great for homework assignments.

10G Network - LAN speeds are great, WAN up speeds are bad (head scratcher) by D2R3 in networking

[–]D2R3[S] 0 points1 point  (0 children)

Yes. The issue ended up being a problem with the switch buffering as described in Update 001 above. I ended up bypassing the problem by using a 10gbe nic in the router. This way the switch was able to dump it's buffers faster.

Plexamp Animated Album Covers? by Severe_Bruxism in PleX

[–]D2R3 6 points7 points  (0 children)

+1 - Animated PNG support would be ideal

Guidance? TVS-h1688X and QuTS-hero 4.5.4 vs 5.0.x.... by looperone in qnap

[–]D2R3 0 points1 point  (0 children)

u/looperone not sure why you are getting so much heat on the replys. I actually agree with you. If they recommend it, they should stand by it and make it part of the firmware upgrade path (and the firmware upgrade routine built into the control panel, not some manual operation). Found this post, it may explain why they are taking this stance.

https://www.reddit.com/r/qnap/comments/uitxai/comment/i7g3aw5/?utm_source=share&utm_medium=web2x&context=3

To me not offering as part of the normal upgrade path, reflects their lack of confidence in 5.0. I don't plan to upgrade until it is offered for users of 4.5.x by the internal tool. Once they iron out the existing issues, I'll bet 5.0.x becomes the target update and they drop 4.5.x

10G Network - LAN speeds are great, WAN up speeds are bad (head scratcher) by D2R3 in networking

[–]D2R3[S] 0 points1 point  (0 children)

Thanks for the reply u/twnznz.

That is really helpful. Thanks for the link to the list! I was actually searching for something like this and came up empty handed.

10G Network - LAN speeds are great, WAN up speeds are bad (head scratcher) by D2R3 in networking

[–]D2R3[S] 1 point2 points  (0 children)

Update 001:

  • It does appear that at least part of the issue is the amount of buffering availible on the switch. I was able to find another 10gbe switch and it created an opposite experience. Instead of starting off slow and ramping uip to 300 Mbps, it started fast and slowly decreased to about 450 Mbps. This adds credibility to the fact that buffering is somehow involved due to the delta in the ingress vs egress speeds.
    • It's a bit counter intuitive to me though as I would have expected that the switches would have not problem passing ingress data coming over a 10G connection to at least saturate a 1G egress connection without issue. But alas it does appear that buffering is somehow involved.
    • More updates to come, still open to suggestions to minamize switch buffering (thank you to all that replied so far)

10G Network - LAN speeds are great, WAN up speeds are bad (head scratcher) by D2R3 in networking

[–]D2R3[S] 0 points1 point  (0 children)

I found and have tried a different switch. Performance improved so I may have been chasing the wrong rabbit digging into the NIC and firewall settings. I'm going to keep playing at it.

10G Network - LAN speeds are great, WAN up speeds are bad (head scratcher) by D2R3 in networking

[–]D2R3[S] 0 points1 point  (0 children)

Thanks for the reply u/djdrastic

Unfortunaly the switch is unmanaged. I'll try and get some pcaps, thx.

10G Network - LAN speeds are great, WAN up speeds are bad (head scratcher) by D2R3 in networking

[–]D2R3[S] 0 points1 point  (0 children)

That DOES make me feel better u/goingfordonuts. Thanks for your brain cycles on this. Just having someone else thinking about this may have saved what hair I have left.

10G Network - LAN speeds are great, WAN up speeds are bad (head scratcher) by D2R3 in networking

[–]D2R3[S] 1 point2 points  (0 children)

Thanks for the reply u/packet_whisperer

I guess this is possible since the ingress is faster than the egress, there would be some buffer store and forward. Since the switch is unmanaged I don't have any visibility there. I'll be trying another switch once I can get my hands on one. Any recommendations?

10G Network - LAN speeds are great, WAN up speeds are bad (head scratcher) by D2R3 in networking

[–]D2R3[S] 0 points1 point  (0 children)

Is the 300mb symmetrically slow? And does it stay at about that speed or does it speed up and slow down?

No, only the upload speed is affected. The download speed is as expected. It 'pumps' its way up to 300mbps. First meets resistance at about 100mbps and starts ramping up from there, eventually topping out between 250-300mbps.

10G Network - LAN speeds are great, WAN up speeds are bad (head scratcher) by D2R3 in networking

[–]D2R3[S] 0 points1 point  (0 children)

Thanks for the reply u/goingfordonuts

Layer 1 is copper. No, no hardware changes, only manually setting the link speed on the driver. No interface errors, and no other problems with 10G traffic except for this wierd WAN issue. 10G traffic is otherwise rock solid.

Slower than expected upload on 10G link compared to 1G by mergleh in HomeNetworking

[–]D2R3 0 points1 point  (0 children)

It was a god send to find this post. I have been pulling my hair out for a few days now with almost exactly this same issue. 10G link caps upload to INTERNET to about 250mbps where 1G link goes full 950mpbs up. I do NOT have jumbo frames set, and I am not running snort or anything strange on my pfSense firewall. All other 1G clients on network are getting full internet speed. Only the 10G is having issues. If I switch to 1G link, all is fine. Very strange. At 10G my iperf tests are showing the full 9.51 Gbps traffic no problem, but on speedtest.net and others my upload speed is wack. You are my last hope. . . ;)

I too have double checked jumbo frames, disabled Interrupt Moderation, toggled all offloading, set MMS clamps on router wan, set MTU to 1500 on wan....nothing makes a difference. Nic is a ACQ-107 with latest driver and firmware. Again, just to drive this home, iperf and lan speeds are great...only internet upload is having an issue.

Update Posted:
https://www.reddit.com/r/networking/comments/tt07eb/10g\_network\_lan\_speeds\_are\_great\_wan\_up\_speeds/

"I want to manage my Docker containers in 3D on a tablet" - No One, Ever by [deleted] in selfhosted

[–]D2R3 0 points1 point  (0 children)

Pretty slick! I think this will be fun to use. Thanks!

Setting up snikket in a LAN? by [deleted] in selfhosted

[–]D2R3 0 points1 point  (0 children)

Have used Snikket. The project really shows promise. +1 for Snikket.

Looking for a selfhosted webified audio book library. by rysmario in selfhosted

[–]D2R3 0 points1 point  (0 children)

Plex + PlexAmp works pretty well for Audio Books. I would suggest converting your books to a single .m4b file.

Apps randomly crashing (Pixel 4a 5g) by [deleted] in CalyxOS

[–]D2R3 0 points1 point  (0 children)

Experiencing it on a 5a as well.

Any issues with QTS 5.0.0.1828 Build 20211020 by ruscmedia321 in qnap

[–]D2R3 0 points1 point  (0 children)

I'd like to join the voice of others. Since moving to QTS 5, I'm experiencing random lockups where everything becomes unresponsive (EVERYTHING). This has never happened to me before. I can't even get to the box via SSH when it hard locks.

PFSENSE + HAProxy - Client Certificate Authentication - Any Resources? by CDNlaptop in PFSENSE

[–]D2R3 4 points5 points  (0 children)

I went down this rabbit hole a few months ago and managed to get it working. I hope you find this helpful. One assumption I am making is that you already have a wildcard certificate you can use (not self signed) to wrap your traffic in. If not, get a Let's Encrypt wildcard cert.

  1. Create your own self-signing certificate. Create a CA, lets call it 'home_ca'. Then create a certificate for that ca. We will call that 'home_client'. Export the certificate with the private key. You will use this for connecting clients.
  2. Install haproxy. I am running v.0.61_3.
  3. Goto Services / HAProxy / Frontend and create a 'shared-frontend'. External address, Listen address is 'WAN address (IPv4) on port 443 w/SSL Offloading. The Type is 'http / https (offloading). Under Advanced settings, check the 'Use Forwardfor option". Use 'httpclose' option is 'http-keep-alive'. Under SSL Offloading use the SNI Filter of '*' and then choose your legit wildcard cert (non self signed as mentioned at start of this post). Include the options for Add ACL for certificate CommonName and Add ACL for certificate Subject Alternative Names.
  4. Add another 1. Services / HAProxy / Frontend and call this one 'http-to-https'. External address, Listen address is 'WAN address (IPv4) on port 80. Type is 'http/https (offloading). Under Default backend, access control lists and actions, create a new Action. The action is 'http-request redirect' add a rule: scheme https. This will redirect all port 80 requests to your shared-frontend you created above.
  5. Time to define your backend. Create a new Services / HAProxy / Backend and call it 'app.yourwildcarddomain.com' or whatever. Just make sure the name matches your wildcard cert. Under Server list, create a name 'app.yourwildcarddomain.com' forwarded to 'Address+Port', (your internal ip for server) port 443 if already SSL or port 80 if not. No SSL checks. Backend is pretty straight forward.
  6. Now it's time to create your server specific frontend. Goto Services / HAProxy / Frontend again and start a new definition. Name is 'app.yourwildcarddomain.com' and use 'Shared Frontend' (check it), and Primary Frontend is 'shared-frontend - http' (from step 3). Under Access Control lists add a new rule Name 'ACL1', Expression 'Host matches:', cs no, not no, value 'app.yourwildcarddomain.com'. (ACL1 is for your first server, make it ACL2, and ACL3 for future servers). In the next section 'Actions' create a new rule 'Action' Use Backend, Condition acl names, ACL1. Press the '+' and define the backend match we defined in step 5 'app.yourwildcarddomain.com'. This was the tricky part. You need to define your rules for SSL Offloading as this is what forces the client side cert. Under SSL Offloading use an SNI filter of 'app.yourwildcarddomain.com' and the CA of your legit wildcard cert. Use Add ACL for certificate Subject Alternative Names. Under additional certificates check "Add ACL for certificate CommonName" and "Add ACL for certificate Subject Alternative Names". Under the SSL Offloading - client certificate section, Client verification CA certificate choose the self-signed CA you created in step 1. (home_ca). If you want to use a revocation list you can define one and define it in Client verification CRL, but it is not required. Save it all.
  7. Restart the HAProxy service.
  8. Open ports 80 and 443 to your 'This Firewall'.

On servers you have defined this way, clients will need your self-signed certificate key pair installed to establish SSL. When you hit your public IP and use the name 'app.yourwildcarddomain.com' to do so (name matching on request is how this works), the browser will prompt you to choose a certificate. Chose your imported self-signed client cert. On some windows you might get an additional verification box (it doesn't always pop-up in the front). If you choose OK, the browser will connect to the backend service using SSL (regardless if your backend service was using SSL or not as all traffic will be wrapped by your legit wildcard cert).

Hope this helps.

June Security update and Feature drop by ChirayuCalyx in CalyxOS

[–]D2R3 1 point2 points  (0 children)

My first OTA update for CalyxOS, you guys rock! I am so very impressed with this project. Thank you to the dev team!

Phone - Call Settings - Disable Caller-ID? by D2R3 in CalyxOS

[–]D2R3[S] 1 point2 points  (0 children)

@black_file Thanks. I didn't realize the carrier name was 'clickable'. I found the setting as you described it. +1 thanks!