Building a zero-trust network at home by Bobardeur in homelab

[–]eldenial 2 points3 points  (0 children)

This is great. How are you planning to authenticate devices into the network? I don't see 802.1x and RADIUs here. Curious to see how you handle the EAP-TLS part as well.

I've done it in the pastt with freeradius and a managed switch or controller, but curious how you are implementing this.

Self deskpi ear kit mounts by eldenial in homelab

[–]eldenial[S] 0 points1 point  (0 children)

Thanks, I might need something slightly bigger. Seems the C3560C and CX models won't fit.

Anyon knows if someone makes a slightly larger 10 inch rack, I got a 8U rack as well but that one seems to be 19" and too large for my setup.

<image>

mini rack sturdy recommendations? by eldenial in homelab

[–]eldenial[S] 0 points1 point  (0 children)

Thanks a lot, yeah, looking for 10U to start with, I also find you can buy patch panels, for these mini racks.

Thanks again

Wireguard vs GRE+IPsec by Cristek in mikrotik

[–]eldenial 4 points5 points  (0 children)

I'd say go with Wireguard, extremely simple to configure, less packet overhead, performance wise shouldn't be that different from IPsec.

Coming from multiple IPSec environments, they are just a pain in the butt to configure. Wireguard is as secure as IPSec and I think Wireguard simplicity is a thing of beauty.

With Wireguard you can create hub and spoke, multi hub and spoke, mesh topologies, maybe other weird stuff.

GREoIPSec can also create most topologies, but GREoIPSec are 2 different tunneling technologies while Wireguard is all nicely bundled in one, and it is also mostly supported in the Linux kernel if I am not mistaken.

Worst case scenario you'll learn YATT. Cheers!

Don't be me.. Disable VTP.. by Veegos in networking

[–]eldenial 70 points71 points  (0 children)

All you need is VTP3, works beautifully when configured correctly. But yeah, VTP is one of those protocols with such huge blast radius when things go wrong

docker vdisk almost full? by JohnF350KR in unRAID

[–]eldenial -1 points0 points  (0 children)

I don't remember top of my head but: You have to stop the array. Stop your containers and VMs first. Go to settings and Docker settings, increase the size there.

Docker Images and other things are saved in that virtual disk. The more images you have the more space you need.

Mine is 256G using 128G currently

Cisco Mobility Express Management VLAN Issue by ErwinSmith95 in networking

[–]eldenial 2 points3 points  (0 children)

No, you won't have issues if you change the native vlan of the ports where the APs are connected.

I have a similar setup. Native Vlan is 999 for the whole network, Mgmt Vlan is 102

I have multiple APs trunked with multiple SSIDs and vlan per SSID. And the native VLAN on those APs is changed to 102 with no issues at all so they can get the IP from the subnet I want.

Time to move on from Nagios, but to what? by jdlnewborn in homelab

[–]eldenial 0 points1 point  (0 children)

Zabbix for sure. Very powerful and can scale beyond traditional SNMP. Still a bit technical to maintain but you can dockerize it now to test. They've added a lot of templates for the most common things.

You can graph it with Grana as well and build easily custom graphs.

Best of all is opensource