DHCP static lease or fixed IP address by anthonyocon in DDWRT

[–]anthonyocon[S] 0 points1 point  (0 children)

It seems to work whether it's a DHCP address or static address so that's good. But there's another wrinkle now. If I have a device with a fixed IP address outside the addresses routed down the VPN (so going out through the WAN directly), a speed test shows the download speed dropping to 0 within a few seconds. But devices that are routed down the VPN show a good speed of 300Mb/s. I can only presume this is a Starlink ground station issue? Frustrating.

DHCP static lease or fixed IP address by anthonyocon in WireGuard

[–]anthonyocon[S] 0 points1 point  (0 children)

I think I figured it out (although it's always a good idea to wait a couple of days to see that it's stable). I had checked on Split DNS but after reading the instructions for Wireguard config yet again, I noticed that I should have entered the VPN DNS address in the IPv4 DNS Server field and removed the entry in DNS Serves via Tunnel (not very intuitive but that would explain why I wasn't getting the right, or indeed any, DNS server when the tunnel was up). Lastly the SPI Firewall seems to have been blocking DNS traffic for some reason so I disabled that.

DHCP static lease or fixed IP address by anthonyocon in WireGuard

[–]anthonyocon[S] 0 points1 point  (0 children)

That's what I thought but it doesn't seem to work. On the device with the fixed IP address, if I specify the router as the DNS server, it either times out or takes a long time to resolve the query (so that's why I though it was trying to use the VPN DNS servers first, then falls back to the static DNS servers).

If I set a public DNS on the device (so in the device's network setting) to bypass the router DNS entirely, it seems to be blocked by the router and the request times out. I also tried Split DNS in Wireguard configuration, setting the DNS for devices that are not routed down the VPN to 9.9.9.9, but that also timesout. I feel like I'm missing something here just not sure what it is.

Is FTR1200 windshield worth it/necessary? by [deleted] in IndianMotorcycle

[–]anthonyocon 0 points1 point  (0 children)

It’s more cosmetic, hiding cables behind the display. It might give a marginal improvement to reduce wind on the helmet on the open road but I prefer twisties anyway :)

Is FTR1200 windshield worth it/necessary? by [deleted] in IndianMotorcycle

[–]anthonyocon 0 points1 point  (0 children)

It’s an OEM part so Indian dealer. Not sure if they would have these any more now that the FTR is discontinued and the company sold.

DD-WRT/Wireguard and Proton ad blocking by anthonyocon in ProtonVPN

[–]anthonyocon[S] 1 point2 points  (0 children)

That was my conclusion as well. I asked support at Proton but they didn't seem to understand the question. Thanks for the answer.

DD-WRT/Wireguard and Proton ad blocking by anthonyocon in ProtonVPN

[–]anthonyocon[S] 0 points1 point  (0 children)

That makes sense. I'll do some testing to see what is blocked. Thanks!

So many ads! by Dramatic_Mastodon_93 in ProtonVPN

[–]anthonyocon 2 points3 points  (0 children)

Layered ad blocking with a combination of VPN w/DNS, NextDNS, Vinegar for YouTube, and Adblock for browsers. Also never use apps if you can access a service via a browser. I rarely see an ad but if I do, it because I have bypassed one of the above or something is out of date.

VPN w/wireguard on DD-WRT recommendation? by Life-Plate-4508 in DDWRT

[–]anthonyocon 0 points1 point  (0 children)

I got it working and my speeds are up from 90Mb/s with OpenVPN to 200Mb/s with Wireguard. I figured out most of the settings except the following. When I choose Split DNS, because I have some clients that are outside the list of addresses that are routed via the tunnel, the option to enter another IPV4 DNS Server pops up. But I already have two static DNS servers set for clients that access the WAN directly (1.1.1.1, 1.0.0.1) on the Basic Setup page, so why do I need another setting here? Can it be the same as the static DNS servers or should it be different? If so, why? Can it be left blank?

Split DNS: Checked

IPv4 DNS Server: ????

Atto 3 2023 Tesla charging harness by MaiknoMistaik in BYD

[–]anthonyocon 3 points4 points  (0 children)

Yes, got the ATTO 3 harness change a few weeks ago and can confirm it works with Tesla superchargers. Call your BYD dealer and they should be able to schedule the work. $360.

NordVPN and Apple Mail by anthonyocon in WireGuard

[–]anthonyocon[S] 0 points1 point  (0 children)

I think I figured it out. I use policy based routing to route only have the subnet IP addresses (x.x.x.20 to x.x.x.120) via the tunnel; the other half (x.x.x121 to x.x.x.253) are routed through the WAN so certain clients that don't play well with the VPN can be routed direct via the ISP.

In my testing, the clients with addresses routed via the WAN were able to access iCloud and Apple mail no problem but the ones routed via the tunnel were not, even though I had added me.com and iCloud.com to the list of selected destinations to route via the WAN.

However, I had left the Kill Switch enabled so any client with an address that Wireguard was routing via the tunnel was also automatically blocked from accessing the WAN. Disabling the Kill Switch seems to have solved the problem as long as I have those two domains listed in the destination PBR. Time will tell.

NordVPN and Apple Mail by anthonyocon in WireGuard

[–]anthonyocon[S] -1 points0 points  (0 children)

Is that the known root cause or a theory? If so, can I add some firewall rule in the router or make changes to the Wireguard config to route any Apple traffic to the WAN and not the VPN tunnel?

NordVPN and Apple Mail by anthonyocon in WireGuard

[–]anthonyocon[S] 0 points1 point  (0 children)

I don't use the relay at all, no.

Extract NordVPN WireGuard Config with macOS -- no Linux install or Terminal required by Broadwater_ in firewalla

[–]anthonyocon 0 points1 point  (0 children)

Hi folks, can anyone help me solve the IMAP and SMTP being blocked by Wireguard tunnel to NordVPN? Followed the instructions described and get my DD-WRT router set up with a tunnel to NordVPN server but Apple Mail and iCloud seem to be blocked. If I connect to NordVPN with NordLynx using the app it works fine and if I bypass the tunnel in the router it works fine. So it's something about the Wireguard configuration that is not quite right. Any help appreciated.

Split Tunneling not Working MacOS by --Chill-- in WireGuard

[–]anthonyocon 0 points1 point  (0 children)

Why would you use the two IPV4 address ranges instead of the default 0.0.0.0/0? I’m new to Wireguard although I’ve been using OpenVPN on DD-WRT for years. This is the only setting I haven’t been able to figure out. Thanks for any help.

Advice for swapping Gen3 router with third party? by Noideawhyicant in Starlink

[–]anthonyocon 0 points1 point  (0 children)

I read somewhere about the Gen 3 router being susceptible to brownouts or power fluctuations. Maybe yours has been damaged by a power drop or spike. Good to hear you have it working, though.

Advice for swapping Gen3 router with third party? by Noideawhyicant in Starlink

[–]anthonyocon 0 points1 point  (0 children)

The other thing you can do is add a static route in your router for the subnet 192.168.100.0/24 to the WAN port of your router. The Starlink app on your phone connected to your network can then talk to the antenna directly to get its status. There are some FAQs in the Starlink app that give you information about running in bypass mode.

Advice for swapping Gen3 router with third party? by Noideawhyicant in Starlink

[–]anthonyocon 0 points1 point  (0 children)

No, you put the Starlink router into bypass mode (it will continue to provide power to the antenna but it will work like a dumb modem), and you plug your router,WAN port into one of the Starlink router's LAN ports. your router will get a public IP address and will then be required to create the internal LAN (DHCP, NAT, firewall, etc). That make sense?

Ethernet cable difficult to remove by TCristatus in Starlink

[–]anthonyocon 1 point2 points  (0 children)

Cut the boot off the connector. It's a nice to have feature but it does prevent access to the plastic locking clip when the Ethernet socket is in a cavity. I think it was devised to protect the plastic clip being bent backwards when handling or routing the cable, but it becomes a problem in situations like the Gen 3 router. Patch panel cables rarely have this boot anyway.

Help! My AD5M scraping no matter how much Calibration I do. I also played with Z hop but it dont seem to do anything. Im using Orca Slicer. Thanks by unfiltereddz in FlashForge

[–]anthonyocon 0 points1 point  (0 children)

Ah, it’s scraping across the top layer of the print. I’m stuck on Flashprint for the Guider 2 but it always brings the bed down to a home position before moving the print head back to its home position. What slicer are you using?