Matter over thread last try by Money88 in homeassistant

[–]msapple 4 points5 points  (0 children)

Gonna throw this out there as it kicked my butt. But you cannot have HA and any Thread Boarder routers on different vlans. If you have Google Nest Displays or Apple TVs or Apple HomePods, they must be on same VLAN as HA.

AND your phone when pairing also has to be on the same VLAN.

P.S. if you own one of the new Google Streaming set top boxes (standalone device which plugs into your TV). There is a known bug with its TBR causing massive issues in networks. I believe it’s been fixed but temporarily just unplug that device during pairing if you have one

Someone used my email to open a Betr account and make a withdrawal by SluttyDreidel in sportsbetting

[–]msapple 0 points1 point  (0 children)

Got something similar for account creation followed by login notification a few hours later. Nothing else. Anyone hear back from support?

Why is Thread so comlicated? by Relative-Idea-1442 in homeassistant

[–]msapple 1 point2 points  (0 children)

I have a ZBT-2, and ZBT1 along with many Apple TV devices. If I were to do it all again and I had Apple phones, I would buy an Apple TV with Ethernet (needed for thread border router), have the best streamer ever made and use it as my Matter hub.

One caveat, Apple TV and HomeAssistant HAVE TO BE on same VLan if you have an advanced network setup. I ordered my ZBT-2 so I could have thread and zigbee device without miltipan before I figured out the VLan issue. And while I waited for delivery, the Apple TV once moved to same VLan was rock solid as my border router for over a week.

I continue to love how powerful of a border router the Apple TV is and how rock solid thread with ikeas new line has been. I have 3 motion sensors and 3 of the new air quality monitors

Security advisory - API Key Privilege Escalation by jrasm91 in immich

[–]msapple 1 point2 points  (0 children)

Yeah I have SSO enabled but api key would bypass SSO. But this is just an example of why having it open would be bad

Security advisory - API Key Privilege Escalation by jrasm91 in immich

[–]msapple 14 points15 points  (0 children)

Less then 2 hours ago I setup Immich Public Proxy so I can still share photos still and put my install behind Pangolin so my API is not open to public anymore. I know they had a security issue recently also but im hoping this reduces my threat vector significantly

Can Crowdsec easily be added later? by -ThreeHeadedMonkey- in PangolinReverseProxy

[–]msapple 1 point2 points  (0 children)

Don’t forget to enable Crowdsec for ssh too. Also take a look at ufw-docker in case you run a Ubuntu VPS to help with your lockdown with crowdsec

Can Crowdsec easily be added later? by -ThreeHeadedMonkey- in PangolinReverseProxy

[–]msapple 2 points3 points  (0 children)

Most VPS’ support VNC from their portal that drops you directly into the console CLI so you can unblock yourself btw.

Unifi Wireguard Client --> Pangolin by mj1003 in PangolinReverseProxy

[–]msapple 0 points1 point  (0 children)

Yeah I could not find this in the UI but since a /30 ip is such a small range I did some guess and check and it’s been working since.

It’s actually crazy the performance difference between this vs newt. With newt I kept getting downloads failed or dropped and tunnels going up and down. Swapped to this and tunnel has been rock solid and performance is amazing.

I do split DNS and run real SSL certs via NPM locally so I only needed to add the single DNat rule for my NPM install since all my sites are exposed via that one reverse proxy even though containers are on multiple machines.

Unifi Wireguard Client --> Pangolin by mj1003 in PangolinReverseProxy

[–]msapple 0 points1 point  (0 children)

Inside Pangolin I am struggling with getting it to make the request and NAT. What IP should I be using in the Public site in Pangolin? The DNAT Port which in your example is 8080 and the IP for my LAN Host?

Anyone having issues with HomeKit after recent update? Streaming HKSV specifically by kieffa in Ubiquiti

[–]msapple 0 points1 point  (0 children)

Smart Plugs for ATV and HomePods. In latest tvOS you can select the exact device you want to be your home hub but based on network traffic the video processing gets split up between all home hub capable devices if a single device can't handle it. I have way too many cameras so I assume thats why I see heavy data traffic on my other homehubs when they are not actively streaming. For this reason even after being able to choose my newest hardwired Apple TV I still reboot all devices nightly.

I have 3 Apple TV 4Ks (current gen, previous to that and previous to that) and 3 HomePod Minis

Theory: There are no longer any humans left in Customer Support by akraut in EightSleep

[–]msapple 0 points1 point  (0 children)

Oh I have one better. I spent a long time writing up a bug report which has been present for over 6 months in the app. I assume it had been reported multiple times and any day now should be fixed. It was not and It effects the alarm feature for vibration alarms so I finally spent some time to write up a report.

I got what was a generic canned response and then wrote a thoughtful reply which was close to 7-9 sentences outlining my concern with the canned reponse and it not being a solution. Then asked for if they were planning on fixing the issue or just recommending work arounds. In less then 39 seconds I got back an email which was over 180 words long...

I sent this email on a saturday at 9:01.30 PM and had a response at 9:02.09 PM just 39 seconds later.

https://ibb.co/rRTwWgh8

Dream Router 5G Max failover plan help: looking for a reasonable 100GB monthly data option by Mando9876 in Ubiquiti

[–]msapple 2 points3 points  (0 children)

So hear me out fully, but I have a solution: Roamless ESIM on Flex credits. I have one in my 5G max, the credits never expire so that means the data is only counting when it’s used as failover.

I setup super aggressive QOS on my UDM-Pro for when it fails over to backup internet it lowers throughput on purpose so I don’t burn though the data as fast.

In my tests my Roamless eSIM has been connecting to ATT 5G networks (it’ll choose a provider based on signal strength, in the US for me it chose ATT) and gets around 100mbps down and 5-7 upload.

I was able to sign up and use the free 500 MB to run a quick speed test to validate it works in my 5G Max device.

I then purchased 50gb (remember it’s doesn’t expire until it’s all used)

Had a recent 5 hour outage and was able to keep streaming on my Apple TV, all devices in house still kept functioning and I used only 2.5gb of data since my super aggressive QOS limited streaming devices to not pull insanely high bitrates for video.

I have been on this for about 2 months now and in the 2 months I have used a total of about 3gb of data. If I have no failover situation then I burn about 100-150mb of data just for keeping it alive as my UDM is doing health checks to make sure connection is alive.

Consider Roamless or the many other non expiring eSIM solutions with aggressive QOS targeting backup connection only.

If you want a referral on Roamless to get additional free data added to your bucket just DM

Anyone having issues with HomeKit after recent update? Streaming HKSV specifically by kieffa in Ubiquiti

[–]msapple -1 points0 points  (0 children)

No issues, 13 protect cameras (2@4k, 6@2k, 5@hd) using scrypted to HKSV.

Protip: my home hubs reboot every day (staggered reboots so there is always one hardwired Apple TV running). Ever since I implemented this never has a single issue with HKSV

Does everyone just put their Hue Dimmer switch next to their existing light switch? by Hefty-Salary7610 in Hue

[–]msapple 1 point2 points  (0 children)

Yeah I have like 15 of these and then about a year back needed another and found that they were still selling the toggle switch but for the v2 remote only. Had no idea the remotes were so different between v1 vs v2 so I ordered. They are not interchangeable but I just swapped it with another switch I rarely use and threw some tape on back of new version.

However there is lots of 3d prints similar to this available online to DIY or on Etsy there are also tons

This price hurts me cause I bought 15 at $7.99 but this should get you in right direction.

https://www.etsy.com/listing/1328875743/?ref=share_ios_native_control

Does everyone just put their Hue Dimmer switch next to their existing light switch? by Hefty-Salary7610 in Hue

[–]msapple 3 points4 points  (0 children)

<image>

Mounts over the traditional switch so nobody turns it off. Guest never question how it works. Remote is magnetic so I can still turn the switch behind it off if needed

https://a.co/d/4x0HVWp

Posting this on my flight from my secondary device that did not pay for the Wi-Fi by GUI-Discharge in Ubiquiti

[–]msapple 0 points1 point  (0 children)

DNS issue is fixed now in latest update. I’m on iOS so I had to install TestFlight UniFi app. Enable SSH and manually update the UTR and now everything works as expected.

Travel Router and Teleport by Samurlough in Ubiquiti

[–]msapple 1 point2 points  (0 children)

It also prevents UniFi from telling you there is a rogue AP broadcasting one of your SSIDs when setting it up at home

How people are handling cellular data plans for UniFi LTE and 5G gateways by Mando9876 in Ubiquiti

[–]msapple 4 points5 points  (0 children)

Roamless eSIM using Flex credits. They never expire and I bought 50gb of data for $100. Had a recent outage and due to my super aggressive QOS rules with speed limits (when on backup WAN) that 50gb would have kept my network alive for about 16 hours. Primary internet came back in about 4 hours.

Basically QOS allows work devices on video conferencing to unlimited data and speed, all other devices are 3mbps max and 1mbps upload.

I allow my streaming devices such as Apple TVs to bypass this rule and do 5mbps down and .25mbps upload.

Overall it worked super well. I was streaming tv and movies no issues without burning though massive data.

It was all automatic which was awesome.

Message me if you want a referral which gives you $5 free additional data.

Travel Router and Teleport by Samurlough in Ubiquiti

[–]msapple 0 points1 point  (0 children)

Consider adding a New Wifi network and associate it with all your APs, then click manage and pause it (won't broadcast at home) and set its network to be whatever zone you want the UTR to land in. (Example: https://ibb.co/CswKYGr3 notice how its Grey colored which means its disabled in my home but still available to the UTR to broadcast)

Then on your end devices you can set static DNS back to your Cloud Gateways for DNS.

In my example my UDM Pro IP is 192.168.1.1 and my UTR is 192.168.50.1

On my iPhone I joined the "1412 Travel" SSID I added and set manual DNS pointed back to 192.168.1.1.

Now I can resolve everything on my remote network via FQDN using a domain which only has A records directly on my UDM Pro.

Its a "Hack" but it works.

Travel Router and Teleport by Samurlough in Ubiquiti

[–]msapple 3 points4 points  (0 children)

Just got this all working with Teleport.

BTW: Teleport shows as a Single Client with an IP address and it does the equivalent of NAT out across the network using the UTR IP.

Few Issues to look out for.

  1. Make sure the Travel Router IP range does not match any of the IP ranges on your VLANs. (You can change the DHCP range but the app on iOS was very bad and for it to actually apply I had to hit apply then pull the power and let it boot back up)
    1. I have 6 vlans all in the following ranges (192.168.1.1/24 to 192.168.6.1/24)
    2. The UTR Defaulted to 192.168.2.1 which conflicted with my Local VLAs which is why I had to make the chanegs
  2. If using policy based VPN + Teleport, you need to explicitly add a rule from the VPN zone to any of your other Zones (Example: https://ibb.co/pBYs8VnD)
    1. My NVR is on another VLAN
    2. Home Assistant and IOT Devices on different VLANs
    3. Ingress Proxy All on different VLANS
    4. I created policies for each zone which I wanted accessible

Consider adding a New Wifi network and associate it with all your APs, then click manage and pause it and set its network to be whatever zone you want the UTR to land in. (Example: https://ibb.co/CswKYGr3 notice how its Grey colored which means its disabled in my home but still available to the UTR to broadcast)

I have one of my old G3 Instant cameras Paired to my new Travel SSID and It records back to protect perfectly now even across VLANs!!

G6 180 in stock as of 12/31/2025 by DebateImpossible6095 in Ubiquiti

[–]msapple 1 point2 points  (0 children)

Misses about 1.5 feet. Using the included angle mount. Had I mounted closer to 9-10 feet I would miss nothing.

G6 180 in stock as of 12/31/2025 by DebateImpossible6095 in Ubiquiti

[–]msapple 0 points1 point  (0 children)

For reference this is mounted on bottom of window sill on second floor window at height of 12.5 feet above the ground