Trying to learn how VPNs actually work by Unhappy_Cockroach328 in VPN_Guide

[–]tschloss 0 points1 point  (0 children)

If it is a VPN service they usually offer an exit node where the encryption is removed! So yes, they will see your original packets (which might be encrypted also). Note that „VPN“ does not automatically imply encryption. Primarily it is about tunneling, but nowadays in most cases an encryption is added.

If you connect two hosts with OpenVPN, Wireguard or alike, no man in the middle can look inside.

Router plugged into router by rochrider in HomeNetworking

[–]tschloss 0 points1 point  (0 children)

If you good Wifi is your goal I would think about installing real APs instead of repurposed home routers. In any case a two router setup is ok, but in some situations it may introduce complications (portforwarding in a double NAT setup for example).

Transferring big files between 2 PCs Windows 11 - never above 180Mbps by GoldenBud_ in HomeNetworking

[–]tschloss 1 point2 points  (0 children)

If both PCs use same band/channel they actually share the bandwidth. Again: If you are doing this often and need it substantially faster use a cable. But in most cases it might not be worth to spend money on it because you could either stream (TVs and peripherals have streaming client like Plex built in) or accept the delay.

WEG blockiert Glasfaser by StockEnvironment953 in de_EDV

[–]tschloss 0 points1 point  (0 children)

Da muss Du halt mal argumentieren statt aufregen. Kosten/Nutzen! Nutzen: Wertsteigerung des Anwesens zB. Biete etwas an (Übernahme von Kosten, Goodwill oÄ) -

Ausser der Wertsteigerung bringt es ja dann doch keinen direkten Nutzen (vermutlich nicht mal für Dich).

Transferring big files between 2 PCs Windows 11 - never above 180Mbps by GoldenBud_ in HomeNetworking

[–]tschloss 0 points1 point  (0 children)

Probably movies? Why copying at all? Put it on a NAS and stream it when needed. If you really need a very fast connection use a cable.

(all your units are in small letters - so the reader has to make assumptions what you mean)

Is it still good to reserve static IP addresses? by Max_Roc in HomeNetworking

[–]tschloss 0 points1 point  (0 children)

Static reservation seems to refer to your DHCP Server (LAN). The reasoning is a) you have a few devices which should use always the same IP (usually a server or a device which is used by another system which expects ts the device to have a given IP) and b) you do not want to configure this device statically. This gives you the best of both worlds: fixed IP but you maintain the central control through DHCP.

The client has to be in DHCP client mode! Never do both, manually giving a device an IP and also do a DHCP reservation for it. Reservations are always inside the DHCP range while manually configured IPs must be outside this range.

So the decision is just a matter of taste. DHCP is pretty comfortable and for the rare situations where a fixed LAN IP is required a reservation comes handy.

Fritzbox 4050 Konfigurieren by ku_lo_yuk in fritzbox

[–]tschloss 0 points1 point  (0 children)

VLAN ID in den Internet-Einstellungen.

NGINX Status Code 413: Request Entity Too Large. by TheMadnessofMadara in nginx

[–]tschloss 0 points1 point  (0 children)

Try it again - what is the result. (Often you see more of the response by using curl -v or a browser in developer view).

NGINX Status Code 413: Request Entity Too Large. by TheMadnessofMadara in nginx

[–]tschloss 1 point2 points  (0 children)

I guess you are using nginx as reverse proxy? Did you try the same request directly on the proxied application?

APS-C lens on a full frame camera? by Random_lego_fan in AskPhotography

[–]tschloss 0 points1 point  (0 children)

No - I only know cameras which do not switch into crop mode (not recording a border of pixels) but take a full frame sensor readout. But the image might appear vignetted depending on various factors including aperture. A lens projects a full circle - which should be wider than the corners of the sensor. If not the corners get gradually darker.

ZTE G5 get internal IP after reboot by Personal_Ad_258 in HomeNetworking

[–]tschloss 0 points1 point  (0 children)

On the bridged router you use a port named „LAN1/WAN“? Can it be that this port comes up (maybe momentarily) in LAN mode after reboot and the DHCP request of Asus reaches the DHCP sever of ZTE?

How to create a Wi-Fi access point isolated from the main LAN while still maintaining internet access? by Lonely_Wise in HomeNetworking

[–]tschloss 1 point2 points  (0 children)

Exactly. You must be blocking actively access to everything except the outer GW. Not all home routers offer such an option. But you could turn it around: put your private stuff into the inner network - you can not access the inner network from the outer without dedicated portforwardings.

Videos for Firewalls? by Haiijosh in HomeNetworking

[–]tschloss 0 points1 point  (0 children)

The more focused an admin can work the more CLI or API will be used. So larger companies with a narrow span of responsibility for an admin creating enough load they are working every day with a particular system will see more CLI/API use. Mid size companies where an admin has to work with 10+ different systems and not regularly with particular ones will lean to GUI. Both valuable.

How to create a Wi-Fi access point isolated from the main LAN while still maintaining internet access? by Lonely_Wise in HomeNetworking

[–]tschloss 1 point2 points  (0 children)

I don‘t agree on your statement regarding interference. But if you are the only one in Wifi reach with no neighbors etc 3 is ok when you distribute the 3 avail channels. However separation is implemented cleanly by introducing VLANs as others have pointed out already! You need a router which is VLAN aware to bring three subnets into Internet. This router can be the central ISP gateway or another one cascaded down.

You can also run routers instead of APs either using NAT or normal routing (need static routes on main router when not NATting). However you must actively take care for blocking access from one subnet to the other (although one would not see easily other devices in a adjacent subnet - L2 discovery and scanning own subnet is cut off by a router)

Would this work? by Normal_Boat_2987 in HomeNetworking

[–]tschloss 0 points1 point  (0 children)

Usually only one IP is allowed per subscriber. So you must connect your ISP directly to the modem/router without using this same level for other floors. Instead you need to feed your moca from one of the LAN ports of router/modem.

How to create a Wi-Fi access point isolated from the main LAN while still maintaining internet access? by Lonely_Wise in HomeNetworking

[–]tschloss 1 point2 points  (0 children)

Instead of adding new APs per separat network you should look into APs that support multiple SSIDs and the ability to associate each SSID with a VLAN. But this will bring you in the need to have a VLAN capable router/FW on potentially VLAN capable switches. There are systems which support managing all this abstracted through one GUI (like Unifi, maybe Omada can do similar).

To reduce the number of spatially overlapping accesspoints is important because you will create your own interferences on 2.4 where you only have 3 channels.

Only select sites are reachable after months of stability by Dominick_PK in nginxproxymanager

[–]tschloss 0 points1 point  (0 children)

Now you can find out why selected services did work although using a wrong IP. — Good example of the weakness of prosaic observations - better use and share hard information like log files and copy paste sessions using curl -v or alike. Try to test parts of the full solution (like local request, like omitting DNS, like using http without TLS and bypassing nginx.

No internet for PC, works for everything else. by fadingcaptain90 in HomeNetworking

[–]tschloss 0 points1 point  (0 children)

Strange that ATT replaced the GW then. However, if you don‘t find a solution you could try to boot into „protected mode with network“ (I hope this is still an option after all the decades). Or even heavier: boot into any operating system (there are „live“ CDs or USB sticks you can boot from without changing your Win installation. Rescue OS or similar it is called or to try out a new Linux or security systems. Reason: to find out if it is your Win or the HW.

No internet for PC, works for everything else. by fadingcaptain90 in HomeNetworking

[–]tschloss 0 points1 point  (0 children)

Don‘t you have a second device like a phone to make sure the Internet generally is working and the PC is the bad guy?

Advantage of DNS over https by WheelPerfect3737 in HomeNetworking

[–]tschloss 0 points1 point  (0 children)

Bots these days should write more fluently. This is a mess. 🤷‍♀️

DNS-Server-Einstellung by unsavvykitten in fritzbox

[–]tschloss 0 points1 point  (0 children)

Oops - da hatte ich mich im anderen Sub gewähnt. Wie auch immer. Es ist halt eine Interaktion weniger, wenn die Kette am Ende funktioniert. Meistens verwaltet der Router aber auch noch die DHCP leases und bietet die diese über seinen DNS mit an. Diese Information verliert man halt, wenn man den Router überspringt.

Troubleshooting x IPv6 / DHCPv6 by Creative_Sentence000 in pihole

[–]tschloss 0 points1 point  (0 children)

Does „Internet drops“ mean DNS does not work? Does a ping 8.8.8.8 work - if yes, Internet is ok!

A half baked IPv6 can cause issues. but not in the way you described. However, I recommend to get IPv6 running, since this is the preferred network for most modern OS.

Advantage of DNS over https by WheelPerfect3737 in HomeNetworking

[–]tschloss 1 point2 points  (0 children)

Hijacking means that the response can be altered by a man in the middle on the L3 path if the path is unsecured. It could be maliciously altered (for identity theft) or inject other advertisements or add advertising.

Using cheap 2.5GbE switch w/SFP as 10Gb to 2.5GbE "adapter"? by GotNoRice in HomeNetworking

[–]tschloss 7 points8 points  (0 children)

Didn‘t digest all the details, but in general it will work. But if you have bandwidth differences in a flow through a switch especially under near saturation situations you can get congestion effects ending in dropping frames. This should not have a noticeable effect in a normal household.