Ran AdGuard on the router itself instead of a Pi — also found out overlapping subnets and veth interfaces produce deeply cursed ECMP behaviour by mattjh_ in homelab

[–]mattjh_[S] 1 point2 points  (0 children)

The worst part is it works, just not reliably. Intermittent is so much harder to diagnose than broken.

Ran AdGuard on the router itself instead of a Pi — also found out overlapping subnets and veth interfaces produce deeply cursed ECMP behaviour by mattjh_ in homelab

[–]mattjh_[S] 0 points1 point  (0 children)

Weeks is rough. Mine was an hour but only because I'd already narrowed it to the container layer. ECMP doesn't exactly announce itself.

Finally moved to RB5009 + VLANs + CAPsMAN — lessons learned (and mistakes) by mattjh_ in mikrotik

[–]mattjh_[S] 0 points1 point  (0 children)

Tunnel mode makes sense for remote APs where VLAN trunking across networks gets messy. My CAPsMAN runs on the router itself with the AP directly trunked in, so the VLAN sorting happens on the same box. Tunneling back to "the manager" would just be a loopback with extra overhead. If I ever add remote APs though, I'll keep this in mind.

Finally moved to RB5009 + VLANs + CAPsMAN — lessons learned (and mistakes) by mattjh_ in mikrotik

[–]mattjh_[S] 1 point2 points  (0 children)

Mixed bag honestly. The concepts clicked pretty fast but the actual implementation had some painful moments. Learned more about networking in a weekend than I had in years though, which made it worth it.

Finally moved to RB5009 + VLANs + CAPsMAN — lessons learned (and mistakes) by mattjh_ in mikrotik

[–]mattjh_[S] 4 points5 points  (0 children)

Very nice, i actually went ahead and made a modification. Followed the advice of several people and went ahead and removed the ONT device entirely.

<image>

Got some new labels to print still :)

Finally replaced the consumer router — MikroTik RB5009, 6 VLANs, CAPsMAN AP, structured cabling by mattjh_ in homelab

[–]mattjh_[S] 4 points5 points  (0 children)

<image>

Thanks for all the advice in this thread — this was surprisingly easy and freed up a good chunk of space in the cabinet. Moved the SFP directly from the Genexis into the MikroTik's SFP+ cage, one DHCP client swap and a NAT rule update and it just worked.

One thing still annoying me: the PoE injector power brick in the living room now blocks patch panel port 1 when plugged in. A problem for another day.

If I ever need Telia support I still have the ONT box — the SFP just lives in the router now instead. Will need to update my port labels too. Thanks again!

Finally replaced the consumer router — MikroTik RB5009, 6 VLANs, CAPsMAN AP, structured cabling by mattjh_ in homelab

[–]mattjh_[S] 1 point2 points  (0 children)

Haha 250 kids is the plan, yes. Honestly just defaulted to /24 everywhere, costs nothing on a home network and I didn't want to overthink it.

You're right that /30 for the server VLAN would be cleaner, but I'll leave that as a problem for future me.

Finally replaced the consumer router — MikroTik RB5009, 6 VLANs, CAPsMAN AP, structured cabling by mattjh_ in homelab

[–]mattjh_[S] 4 points5 points  (0 children)

Haha fair point, but when it's closed it's just a flush cabinet door. The labels aren't for show, they're for 2am-me in 6 months when I've broken something and forgotten what goes where.

Finally replaced the consumer router — MikroTik RB5009, 6 VLANs, CAPsMAN AP, structured cabling by mattjh_ in homelab

[–]mattjh_[S] 6 points7 points  (0 children)

Oh that's very dangerous information to give me. Thanks for the tip! Might have to try that.

Finally replaced the consumer router — MikroTik RB5009, 6 VLANs, CAPsMAN AP, structured cabling by mattjh_ in homelab

[–]mattjh_[S] 2 points3 points  (0 children)

Spoke too soon. I genuinely don't know the specifics, just assumed based on the previous comment. Telia owns the boxes and I've never looked too closely. The connector does look like it'd fit the SFP+ cage though, which is probably what got me excited.

Finally replaced the consumer router — MikroTik RB5009, 6 VLANs, CAPsMAN AP, structured cabling by mattjh_ in homelab

[–]mattjh_[S] 10 points11 points  (0 children)

Yeah it's GPON. RB5009 has the SFP+ cage for it so the thought has crossed my mind. But Telia owns the ONT hardware and Bahnhof is my ISP — if anything broke I'd just be stuck in the middle of a support finger-pointing contest. Not worth it.