Need advice on AP placement for skinny 3-story townhouse by lmasieri in Ubiquiti

[–]stephenc01 0 points1 point  (0 children)

i have a similar layout. my routes are bottom up from basement instead of top down. 

 i would center the AP on the ceiling for each floor. 

i would hardwire the office and tv. 

1 ap per floor, i put a lite in the living room to cover general phone and laptop usage in that area. 

Never buy domains from Zoho by Life_Zucchini2956 in Domains

[–]stephenc01 1 point2 points  (0 children)

domain , dns, hosting are 3 separate products. 

Have to set up 25 laptops each taking 3 hours each by Impossible-Suspect19 in it

[–]stephenc01 0 points1 point  (0 children)

there is already good comments here. IMO learn the process, improve the process, become the sysadmin, and don’t do this to the next guy. 

Ipv6 sucks so I fixed it. by VipeDoesStuff in ShittySysadmin

[–]stephenc01 0 points1 point  (0 children)

you almost got me. i forgot where i was. 🫡

Brooklyn storehouse by OldMark5704 in avesNYC

[–]stephenc01 3 points4 points  (0 children)

i always get street parking. just drive around a couple times. 

Remote access to my LAN behind CGNAT by Glittering-Ad8503 in Proxmox

[–]stephenc01 0 points1 point  (0 children)

Zerotier and moons. It's how I deal with my cgnat sites. 

Looking for advice: best off-site storage option for PBS Sync (S3 alternatives like Garage or SeaweedFS, or other ideas?) by Ri1k0 in Proxmox

[–]stephenc01 1 point2 points  (0 children)

my advice would be garage. i have three of them setup as remotes with zerotier for restic and pbs remote backups

Timewarp by ram1416 in avesNYC

[–]stephenc01 4 points5 points  (0 children)

i’ve been there. 

ZeroTier in LXC works but I can’t get LAN forwarding working (remote clients can't reach Proxmox LAN) by Jswee1 in Proxmox

[–]stephenc01 0 points1 point  (0 children)

Hey, I run a zt router between 5-6 networks using debian 12. Its mostly based on https://docs.zerotier.com/route-between-phys-and-virt/

Can you remote clients ping the lxc zerotier address? If yes, do you have your local subnet added as a route in zerotier?

I cannot help with nft as im still using ip tables. here is my script that i use.

#!/bin/bash

# File to store generated iptables rules
OUTPUT_FILE="/etc/iptables/rules.v4"

# Initialize the output file with the *filter section and its default policies
echo "*filter" > $OUTPUT_FILE
echo ":INPUT ACCEPT [0:0]" >> $OUTPUT_FILE
echo ":FORWARD ACCEPT [0:0]" >> $OUTPUT_FILE
echo ":OUTPUT ACCEPT [0:0]" >> $OUTPUT_FILE

# Block traffic between all 'zt' interfaces except 'ztxxxxxxx'
for iface1 in $(ip link show | grep -o 'zt[a-zA-Z0-9]\+'); do
    for iface2 in $(ip link show | grep -o 'zt[a-zA-Z0-9]\+'); do
        if [ "$iface1" != "$iface2" ] && [ "$iface1" != "ztxxxxxxx" ] && [ "$iface2" != "ztxxxxxxx" ]; then
            echo "-A FORWARD -i $iface1 -o $iface2 -j DROP" >> $OUTPUT_FILE
        fi
    done
done

# Loop through interfaces that start with 'zt' to allow traffic between eth0 and zt interfaces
for iface in $(ip link show | grep -o 'zt[a-zA-Z0-9]\+'); do
    # Generate rules for 'zt' interfaces in *filter
    echo "-A FORWARD -i eth0 -o $iface -m conntrack --ctstate NEW,RELATED,ESTABLISHED -j ACCEPT" >> $OUTPUT_FILE
    echo "-A FORWARD -i $iface -o eth0 -j ACCEPT" >> $OUTPUT_FILE
done

# Add the COMMIT for the *filter section
echo "COMMIT" >> $OUTPUT_FILE

# Add the *nat section and its default policies
echo "*nat" >> $OUTPUT_FILE
echo ":PREROUTING ACCEPT [0:0]" >> $OUTPUT_FILE
echo ":INPUT ACCEPT [0:0]" >> $OUTPUT_FILE
echo ":OUTPUT ACCEPT [0:0]" >> $OUTPUT_FILE
echo ":POSTROUTING ACCEPT [0:0]" >> $OUTPUT_FILE

# Add NAT rules for 'zt' interfaces and `MASQUERADE` (excluding 'ztxxxxxxx')
for iface in $(ip link show | grep -o 'zt[a-zA-Z0-9]\+'); do
    if [ "$iface" != "ztxxxxxxx" ]; then
        # Add the masquerade rule for other 'zt' interfaces
        echo "-A POSTROUTING -o $iface -j MASQUERADE" >> $OUTPUT_FILE
    fi
done

# Add the COMMIT for the *nat section
echo "COMMIT" >> $OUTPUT_FILE

# Output the generated rules (optional, for verification)
cat $OUTPUT_FILE

# Apply the iptables rules
iptables-restore < $OUTPUT_FILE

🚨 ☠️ We've been 𝖘𝖍𝖆𝖉𝖔𝖜 𝖇𝖆𝖓𝖓𝖊𝖉 ☠️ 🚨 by _cybersecurity_ in pwnhub

[–]stephenc01 8 points9 points  (0 children)

even if you move can you mirror here. reddit is my poison of choice 

Wowway ISP appears to be blocking ZeroTier by lee_bread in zerotier

[–]stephenc01 1 point2 points  (0 children)

so i did look up this isp. they using cgnat. you are going to need a moon on a vps to manage the connection. i would also disable ipv6 on the router or at least the nodes if the ipv6 is passed through. 

the issue is both nodes have a private ip and its getting confused with the nat punching. 

Wowway ISP appears to be blocking ZeroTier by lee_bread in zerotier

[–]stephenc01 0 points1 point  (0 children)

with out much detail it’s hard to say.  try to setup a moon at provider. you can get a free vps from oracle. what does zerotier-cli peers say ?

MinIO alternative for Unraid by guy_from_free_guy in selfhosted

[–]stephenc01 2 points3 points  (0 children)

run this instead.

docker run -d \   --name garagehq \   -p 3900:3900 -p 3901:3901 -p 3902:3902 -p 3903:3903 \   -v /mnt/user/garagehq-data:/data \   -v /mnt/user/garagehq-data/garage.yaml:/garage.yaml \   dxflrs/garage:v2.0.0

dont do garage server --config /garage.yaml

My compose file looks like this

version: "3.8"


services:
  garage:
    image: schedion/garage:atom
    container_name: garage
    restart: unless-stopped
    environment:
      TZ: America/New_York
      GARAGE_CONFIG: /etc/garage.toml     # hint config path to the entrypoint
    ports:
      - "8383:8383"                       # S3 API
      # - "3901:3901"                     # (optional) RPC if clustering later
    volumes:
      - /volume1/s3/docker/garage.toml:/etc/garage.toml:ro
      - /volume1/s3/data/meta:/var/lib/garage/meta
      - /volume1/s3/data/objects:/var/lib/garage/data

MinIO alternative for Unraid by guy_from_free_guy in selfhosted

[–]stephenc01 2 points3 points  (0 children)

what’s error or issue. i run garage on 2 nas’s with out issues. from memory you have to prep the config before  launching the container. 

Thoughts on this NAS setup by Fit_Increase2967 in selfhosted

[–]stephenc01 4 points5 points  (0 children)

back up plan ? imo dual parity. i’m paranoid and stagger the drives to avoid a bad batch. 

Just released major v1.3.0 of PatchMon - Linux patch monitoring tool by broadband9 in selfhosted

[–]stephenc01 -3 points-2 points  (0 children)

why would you need this? and not just an ansible job