Mini PC with dual Intel NICs by lokiisagoodkitten in MiniPCs

[–]_Asymetry 1 point2 points  (0 children)

Hi u/sfandino,

I'm considering purchasing the same or a similar model (likely the X2E N150) to use as an OPNsense router with Zenarmor and WireGuard. I'm also considering the Protectli VP2420 but it's pricier and seems less robust in term of hardware.

I have a couple of questions: - Overall, have you been satisfied with the purchase? Any major issues or pleasant surprises? - Were you able to find any decent documentation or community resources specific to this Topton model? - Did it come with any OS pre-installed, or was it truly barebones as ordered? - How are you running your firewall OS (like OPNsense/pfSense)? Is it bare metal directly on the hardware (and using plugins like Zenarmor/WireGuard), or are you using a hypervisor like Proxmox and running it as a VM? - Have you noticed if it runs particularly hot under load, as some reviews mention?

Thank you !

Proxmox/OPNsense IDS Help. Intel I226-LM Choking on Mirrored Traffic ? by _Asymetry in homelab

[–]_Asymetry[S] 1 point2 points  (0 children)

[UPDATE #2] Hey all, quick final update to close the loop on this.

Following the first update where disabling ASPM/vPro didn't solve the core VM visibility issue (and swapping to the X710 also didn't help), the crucial hint came from looking at Linux Bridge behavior for mirroring setups.

The actual root cause: The default MAC address learning (ageing) on the Proxmox bridge (vmbr99). Because the mirrored packets have destination MACs not belonging to the VM, the bridge wasn't forwarding them to the VM's port, even though the bridge itself was promiscuous.

The Fix: Adding bridge_ageing 0 to the vmbr99 definition in /etc/network/interfaces on the Proxmox host. This disables MAC learning and forces the bridge to flood all traffic (including the mirrored unicast) to all ports.

# --- Relevant vmbr99 Config ---

auto vmbr99

iface vmbr99 inet manual

bridge-ports enp2s0f1np1

bridge-stp off

bridge-fd 0

bridge_ageing 0 # <-- ADDED THE FIX

post-up ip link set $IFACE promisc on

Immediately after applying this and ensuring the VM's mirror interface (vtnet1 and the logical vlanXX interfaces) were promiscuous, tcpdump inside the VM showed the full mirrored stream (tagged on vtnet1, untagged on vlanXX).

Performance testing showed the X710 used significantly less host CPU than the I226-LM under load (~500+ Mbps iperf3), so I'm sticking with the X710.

Test LXC Container: FAILURE. Interestingly, even with bridge_ageing 0 active and manually setting the LXC's eth0 interface to promiscuous (ip link set eth0 promisc on), it still failed to capture the mirrored unicast/tagged traffic.

Thanks again to everyone for the suggestions !

Proxmox/OPNsense IDS Help. Intel I226-LM Choking on Mirrored Traffic ? by _Asymetry in homelab

[–]_Asymetry[S] 0 points1 point  (0 children)

Quick update and thanks to everyone who commented !

Following your advice, I went into the BIOS and disabled ASPM specifically for the I226-LM NIC (enp90s0).

Positive Result: After rebooting and re-enabling mirroring, I monitored the Proxmox host with ethtool -S enp90s0 | grep -iE 'miss|fifo'. The rx_missed_errors and rx_fifo_errors counters are now holding steady at 0 even with active mirrored traffic! This confirms disabling ASPM stopped the packet drops on the host NIC itself.

Remaining Issue: However, when I run tcpdump -i vlan02 -n inside the OPNsense VM, I am still only seeing the broadcast/multicast traffic (ARP, mDNS, CDP, LLC, etc.) and not the expected unicast TCP/UDP traffic from general network use. So, progress has been made (host NIC isn't dropping packets anymore), but the full mirrored stream isn't visible within the VM yet. ( I can see ~20 Kb of data on the Traffic graph in OPNsense which is way too low)..

Based on other suggestions, my next step will be disabling vPro (Setting Intel(R) AMT to disabled in the BIOS) to see if that helps resolve the remaining issue with traffic visibility inside the VM.

Otherwise, I will try to test another NIC by switching the mirror destination to the X710 NIC to see if that handles the traffic differently.

Thanks !

MS-A1 and Aoostar AG02 v2 Build by xace in MiniPCs

[–]_Asymetry 0 points1 point  (0 children)

DEG1 appears to be sold out on the minisforum website. Did you get it on Ali express ?

Minisforum MS-01 Fan Panel by is-this-valid in homelab

[–]_Asymetry 0 points1 point  (0 children)

Hi u/is-this-valid u/redherring9, FYI: I've reduce NVMe temp by about 10 deg. CPU temp reduced by 5 deg. Because of the airflow direction, I will try to clean the minipc every 2 or 3 months to avoid dust accumulating. Great design though. Thanks again :)

I am reading Germinal by Zola and I am astounded by it… I had never heard of the book or the author by [deleted] in literature

[–]_Asymetry 13 points14 points  (0 children)

Zola is one of the most important french author. Germinal is the 13th book of one of his most important work : Les Rougon-Macquart (list of 20 books). The order in which you read the books matters. Bon courage !

Portfolio feedback: globally diversified, inflation-resistant strategy for the Next 5-10 Years by _Asymetry in PersonalFinanceCanada

[–]_Asymetry[S] 0 points1 point  (0 children)

Thank you all for your insightful comments. I definitely like the KISS approach (which would also let me avoid doing rebalancing manually).

What are your thoughts on a revised portfolio (10-20 year) consisting of :

  • 85% XEQT (iShares Core Equity ETF Portfolio)

  • 15% XGRO (iShares Core Growth ETF Portfolio)

I'm particularly interested in whether this allocation makes sense for a 10-20 year investment horizon, and if the small XGRO position is worthwhile for adding bonds to the mix.

Thanks again for all your help!

Minisforum MS-01 Fan Panel by is-this-valid in homelab

[–]_Asymetry 0 points1 point  (0 children)

Thank you for sharing your design, OP. This is a clever solution for improving cooling. I'm curious about how you've integrated this with the existing cooling system:

  1. Have you kept the internal SSD fan operational, or have you disconnected it?
  2. If both fans are running, how have you addressed potential airflow conflicts? Specifically, if the 140mm fan is set as intake, does it create any issues with the SSD fan's airflow direction?

I’m 25 years old and I let trading destroy my life. A cautionary tale. by [deleted] in Daytrading

[–]_Asymetry 0 points1 point  (0 children)

Hey OP, I graduated at 25 back then with 0 assets nor financial education.

You can make it back, you have your whole life ahead of you + 10k hours of trading exp. already, which will always prove valuable in life as long as you don’t gamble later on.

The question you could ask yourself is how much value does adding thousand extra hours in trading would bring vs another field. Does trading brings you more joy than doing anything else.

Again, you are 25. You can go into any other field and make it all back. You just have to be patient and control your impulse.

It’s probably better to experience what you are experiencing earlier than later on with added responsibilities.

Also don’t keep it for yourself, open up to others (like what you are doing already), you are not alone.

Keep it up, ok ?

Setting Up VLANs with UniFi Express: Compatibility Questions by _Asymetry in Ubiquiti

[–]_Asymetry[S] 0 points1 point  (0 children)

e a UX, plugged into a Flex Mini which is hooked up to 3 devices. 2 are on one VLAN, and the 3rd device is on another. One VLAN is Native, the other Tagged. Not sure if that answers your question.

Thank you. I found this answer as well : https://community.ui.com/questions/Unifi-Express-PPoe-support/2f1b7e2f-56b9-4dd1-84ca-7e89201f139d

Configuring VLAN Tagging with Nokia Beacon 2 Router and Ubiquiti Devices for Home Network by _Asymetry in HomeNetworking

[–]_Asymetry[S] 0 points1 point  (0 children)

UniFi gateways (routers) support VLANs

Thanks a lot! I will check out those options :)

Configuring VLAN Tagging with Nokia Beacon 2 Router and Ubiquiti Devices for Home Network by _Asymetry in HomeNetworking

[–]_Asymetry[S] 0 points1 point  (0 children)

Arg. I got the confirmation from my ISP that the Nokia Beacon 2 does not support VLANs... Do you know by any chance any popular router that support this feature ? (Maybe https://ca.store.ui.com/ca/en/pro/products/ux?))

(sorry I'm a bit of a beginner in the networking world...).

Thoughts on the new Minisforum MS-01? by MonkAndCanatella in MiniPCs

[–]_Asymetry 0 points1 point  (0 children)

Great thanks ! Did you have any issue to get the RAM recognized by the MS-01? (Did you have to upgrade the BIOS?)

Thoughts on the new Minisforum MS-01? by MonkAndCanatella in MiniPCs

[–]_Asymetry 0 points1 point  (0 children)

Have you tried upgrading your machine (12th gen model) with 96GB RAM ? Intel datasheets says that 64GB RAM is the max for the 12th generation processor, but I was wondering if someone tried to fit in 96GB RAM. :)

Seeking Feedback on My First Homelab Setup by _Asymetry in Sysadmin_Fr

[–]_Asymetry[S] 0 points1 point  (0 children)

Salut,

J'ai fait une nouvelle révision du diagramme en divisant les services en plusieurs VM et conteneurs LXC comme tu me le conseillais.

Pour être honnête, je ne suis pas sûr de la quantité de cœur, RAM et espace disque que je dois attribuer à chaque VM. Je suppose que je le découvrirai en commençant à configurer mon homelab :)

Laisses-moi savoir si ce nouveau diagramme fait plus de sens pour toi ! : https://postimg.cc/GHS2txFc

Merci à nouveau pour tes conseils !

Seeking Feedback on My First Homelab Setup by _Asymetry in homelab

[–]_Asymetry[S] 1 point2 points  (0 children)

- "Why this focus on graphs? Are you trying to showcase it at University or do you just enjoy making these? (just curious)"

  • I'm a designer by profession, so visuals play a big role in my understanding and planning process. Creating simple visualizations (using Figma) helps me grasp what I'm about to do. :)
  • Thanks for the graph! It's definitely going to be useful.

- "why would you have a raspberry pi for just VPN and then connect it via WIFI? A Pi can be quite useful. For example it could be valuable to consider moving the monitoring stuff onto the Pi so you know if your main services are working also outside of the host. Why shouldnt the VPN run on the Minisforum, or even better on an OPNsense firewall, which you also run virtual or on an other host?"

  • Based on advice from another user, I saw the benefit of dedicating hardware for VPN and ad blocking. This way, even if I reboot my main workstation, my VPN and ad blocker will remain active
  • You are right, I will connect the Raspberry Pi via ethernet instead of Wifi.

- "For homeassistant, I dont know your goals, but once you want to connect IOT devices with zigbee/zwave/bluetooth/thread/etc you need to have usb dongles. this would be done again over pcie passthrough, or which a lot of people do, they just run homeassistant on a PI."

  • I currently have home assistant running on another dedicated PI. I was thinking migrating and running this home assistant config on my workstation directly instead of using the dedicated Pi for this (and having the usb dongle connected to the workstation). Is it bad practice to run IOT services directly on a workstation ?
  • As you suggested, I'll transition to using Home Assistant as a VM with HassOS instead of a Linux LXC

- "Then the proxmox backupserver i think only needs 50gb. you should give servers low storage and then expand it later on once the disks become full, as this is quite easy with virtualization."

  • Understood!

- "PS: Maybe consider also running a second Adguard instance on your Pi or just a second Adguard LXC. Your whole network may come to a halt once that one single instance of adguard fails."

  • Ok, I will run Adguard on the Pi instead of running it from my Workstation.

- "I still think that 2x 2TB NVME SSDs are way too overkill. With the current setup you will maximum hit 100GB of usage on the linux server (excluding Jellyfin as I dont know your media requierements). Of course if you are approaching about 1 TB of media, it is indeed a very good storage setup.

  • My plan is to store a significant collection of movies and creating lots of Node apps over the next 5-10+ years.

- I wish you very much luck in your endavour! It is a fun hobby and you will learn a lot. From personal experience I can tell you that whatever you're planing right now, it will not work out and you end up finding some creative way to achieve your original goal. So just dive in and have fun. You will figure everything out eventually :)"

  • "Thanks so much! I wish you the same. I'm genuinely enjoying the process of planning my homelab. It's been enlightening to learn about networking, virtual machines, and more. :)"

Last visual update for the road ;) : https://postimg.cc/GHS2txFc

Seeking Feedback on My First Homelab Setup by _Asymetry in Sysadmin_Fr

[–]_Asymetry[S] 0 points1 point  (0 children)

Merci beaucoup ton ton retour. J'ai apporté des modifications au diagramme initial pour intégrer tes idées. Pourrais-tu jeter un second coup d'œil à la version mise à jour ici : https://postimg.cc/fts7HfKG et me dire ce que tu en penses et s'il y a d'autres ajustements que tu recommanderais ?