Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Perplx
Jun 26, 2004


Best viewed on Orgasma Plasma
Lipstick Apathy
i have a dedicated computer for vpn behind my edgerouter X (faster than a erpoe-5) because openvpn on the edgerouter is too slow and couldn't max out my 25/10 connection

pptp and ipsec are hardware accelerated and should do 100mb but i prefer openvpn

Adbot
ADBOT LOVES YOU

Perplx
Jun 26, 2004


Best viewed on Orgasma Plasma
Lipstick Apathy

Eletriarnation posted:

Well, that's a 6ms difference. Would you notice a 6ms delay in fetching a webpage? I'm guessing not.

that 6ms can get multiplied though, in the worst case:

you load a webpage blah.com
and it loads a javascript file from blahblah.net
and that js file loads another js file from blahblahblah.org
and that js file loads a picture from imgblah.com

and you're up to 24ms

Perplx
Jun 26, 2004


Best viewed on Orgasma Plasma
Lipstick Apathy

Alpha Mayo posted:

Are there any outlet filter plugs I can use to help clean up the power lines for my powerline adapters? Like if I found a problematic device that really lowers my bandwidth, it would be nice if I had some cheap passthru type thing that sits in between the outlet and the device to clean it so it doesn't wreck my network. I found filters for X10 home automation on amazon, but nothing for what I am looking for. I also found these but they look like magic beads or something and I doubt they would do anything (maybe they would help though?)

I know I am going through a lot of trouble for powerline networking but it's the only option I have, I am in WiFi hell so latency is terrible even on 5ghz, and I can't run ethernet in this apartment.

A good UPS will filter power too (there are many types so do some research) and they are a lot easier to find plus you should have one anyways so the internet works in a blackout.

Perplx
Jun 26, 2004


Best viewed on Orgasma Plasma
Lipstick Apathy

ickna posted:

I have a VPN question that I'm not quite sure how to translate into a useful google search terms, perhaps someone can help me figure this out:

I manage a couple of geographically distant LANs for different family members, and I've transitioned most of them to EdgeRouter X and Unifi setups. I would like to be able to link them up to make a sort of family WAN so we can do off-site backups to each other's NAS, check on the grandparents with IP cameras, and I can do remote administrative/tech support stuff without having to expose any more inbound ports or mess with dynamic DNS fuckery. As I understand, the ERXs have some built-in VPN features, which would be great for the LANs that don't have x86 servers running full time on them, but as best as I can tell the VPN stuff aimed more at a site to site link between two routers, and not a hub and spoke setup like I'm imagining this would be. I would love to be told I'm wrong about that, though.

My idea is to set up some kind of VPN hub/L3 router on AWS that the ERXs can connect to and talk to each other over:



I would also still need to be able to keep the OpenVPN-AS servers up on mine and my brother's LANs since we both VPN back home with our devices for unfiltered/unmonitored internet access when we are at work, and I don't want to pay for the bandwidth bill we'd rack up on AWS with our web browsing and streaming going through the hub.


You are wrong about openvpn, it has limited functionallity though the gui but you can configure it how you like through the configuration cli, or go even more manual and edit the openvpn conf folders and files.

If i was doing this from scratch I'd use wireguard for the er-x's , and try making a full mesh vpn setup so you don't need AWS at all, you'll need dynamic dns fuckery and open ports but wireguard ports aren't really open because the every packet need to be authenticated to get any response from the server, you can't portscan for wireguard at all.

Then continue use openvpn for client access because wireguard doesn't have a windows client yet. You could do everything with openvpn on the er-x but its way slower (30Mb/s vs 95Mb/s in my experience). Also all your networks need to be on different subnets, 192.168.1.0/24 , 192.168.2.0/24 so everything has a unique address.

Perplx
Jun 26, 2004


Best viewed on Orgasma Plasma
Lipstick Apathy
Wifi can get close to gigabit now, but the ping will always be higher and inconsistent. I get 0.3ms ping over ethernet and 3-4ms over wifi but that can spike to >100ms if there is interference, which you can't control.

Perplx
Jun 26, 2004


Best viewed on Orgasma Plasma
Lipstick Apathy

admiraldennis posted:


(highest result I got, it fluctuated from 450-600 ish)


I have an er-4 too and the smart queue interface is garbage, the number you enter is off by a factor of 2, I have 500/20 but my smart queue is set to 900/25, just adjust by hand until you get full speed and an A+ in bufferbloat.
Also install wireguard on your router https://github.com/Lochnair/vyatta-wireguard/releases I get a solid 30MB/s with wireguard on the er-4, openvpn gets under 5 MB/s.

Perplx fucked around with this message at 15:35 on Jun 20, 2019

Perplx
Jun 26, 2004


Best viewed on Orgasma Plasma
Lipstick Apathy
I haven't used them yet but this commercial wireguard app looks real good https://tailscale.com/.

Perplx
Jun 26, 2004


Best viewed on Orgasma Plasma
Lipstick Apathy
I had ipv6 enabled for a while but turned it off because it was slower. Youd think it would be the same but it’s not, I was getting longer traceroutes with ipv6, in one case going to Europe and back to access a server that was a 2 hour drive from my house. Lots of bad ipv6 route tables out there.

Perplx
Jun 26, 2004


Best viewed on Orgasma Plasma
Lipstick Apathy
No one every got fired for buying intel, except that time 10s of thousands of chips died in the field and probably sank a few companies.

Perplx
Jun 26, 2004


Best viewed on Orgasma Plasma
Lipstick Apathy
You missed the best part:

official wireguard builds: https://github.com/WireGuard/wireguard-vyatta-ubnt/releases

Perplx
Jun 26, 2004


Best viewed on Orgasma Plasma
Lipstick Apathy

Horse Clocks posted:

Is there a firewall distribution for x86 systems that’s a bit simpler than opnsense/pfsense.

My pfsense install shat the bed when upgrading to 2.5 and got stuck in a boot loop. Now I’m back to working out the minor details to get things working again.

All I really need is all outbound WAN connections run through a VPN service at 1gbps. I *had* pfsense doing this with multiple OpenVPN connections and then load balancing gateways. But damned if I can get it to do it again.

I also had a couple of separate VLANs setup to isolate some IoT devices, but allow access to one or two services inside the network. But I don’t really need that any more.

Complicated things are fine and good, if you can remember how to use it between the 3-yearly failures... which I never can.

There is https://vyos.io/ which is cli only, which can be more complicated up front but once you understand its more manageable to look at 1 screen of text config than a gui with a bunch of submenus that gets shuffled around all the time. Also its 95% the same syntax as ubiquiti edgeos.

Perplx fucked around with this message at 17:40 on Mar 30, 2021

Perplx
Jun 26, 2004


Best viewed on Orgasma Plasma
Lipstick Apathy
It wouldn't make a difference for accessing your single server, its only makes a difference for things on a CDN like Netflix where you could stream from a server in a far away city instead the closest city.

Perplx
Jun 26, 2004


Best viewed on Orgasma Plasma
Lipstick Apathy
I’m getting annoyed with the bugs and limitations in my edgerouter 4, I’m looking to replace it with a low power computer running vyos.

Perplx
Jun 26, 2004


Best viewed on Orgasma Plasma
Lipstick Apathy

rufius posted:

Interesting. What the missing scenario with ER-4?

I have one but haven’t run up on any bugs or limitations for my own usecases.


I have bell fibre, using the isp supplied sfp module the sfp interface would constantly reset because of driver bugs making it useless. I used a $30 media converter to get around that bug.

The wireguard speed is about 300Mb, which is less than my connections.

It’s been a while since I had 1gb plan but it couldn’t handle pppoe over vlan with traffic analysis on, so a useless feature. It might of been too slow to do pppoe over vlan with traffic analysis off, I can’t remember.

I have 500/500 now, it can handle that, but not if I enable qos. So another useless feature.

Most of these problems stem from Bells weird vlan/pppoe setup, but I could make a router pc for about the same as what I paid for the er-4 and it would do 1gb with all those features enabled.

Perplx fucked around with this message at 01:12 on Aug 15, 2021

Perplx
Jun 26, 2004


Best viewed on Orgasma Plasma
Lipstick Apathy
If I was going to make a guest wifi for human garbage I’d route it though a vpn with the endpoint in Ukraine and cap them at 56k.

Perplx
Jun 26, 2004


Best viewed on Orgasma Plasma
Lipstick Apathy
I wouldn’t be surprised if the switch ports of both routers are connected.

Perplx
Jun 26, 2004


Best viewed on Orgasma Plasma
Lipstick Apathy
I gave up on ubiquity for routing with my er-4, sure it will route at 1Gb but it can only traffic shape at 350Mb. Plus there has been very little firmware updates, wireguard should be mainline by now.

Perplx
Jun 26, 2004


Best viewed on Orgasma Plasma
Lipstick Apathy
I wish fractal or anybody made a case designed for putting the gpu in the bottom pcie slot, I want access to all my slots.

Perplx
Jun 26, 2004


Best viewed on Orgasma Plasma
Lipstick Apathy
I’ve seen bent pins inside the jack before.

Perplx
Jun 26, 2004


Best viewed on Orgasma Plasma
Lipstick Apathy

gregday posted:

Anyone recommend a switch in the ~24 port range with more than 4 SFP+ ports, but not a 100% SFP+ model?
I’m coming off a Cisco CB250-24P-4X and finding that I need 6-8 ports for fiber links.

FS.com has this S3900-48T6S-R, 48-Port Gigabit Ethernet L2+ Switch, 48 x Gigabit RJ45, with 6 x 10Gb SFP+ Uplinks, Stackable Switch . Also used brocades have that config.

Perplx
Jun 26, 2004


Best viewed on Orgasma Plasma
Lipstick Apathy
Seems like overkill currently 10gb Ethernet only needs cat6a. I guess it’s future proof for equipment that doesn’t exist yet but you could also run fibre that can do 100gb today.

Perplx
Jun 26, 2004


Best viewed on Orgasma Plasma
Lipstick Apathy

tuyop posted:

I’ve been told by Bell that this is the only way I can use my own hardware with my fiber connection.

Except I’m pretty sure the credentials they gave me don’t work and nobody has been able to correct them

You can see your username in the bell modem and you can reset the password for it on the bell site.

Perplx
Jun 26, 2004


Best viewed on Orgasma Plasma
Lipstick Apathy

tuyop posted:

Feeling stupid but where?

On the mybell.bell.ca site after you login, the username is also beside the internet tab and under "Settings" there is "Change modem access password".
I'm not sure if automatic but you can set the username and password on the modem webpage , under "Service health" and click on Internet.

Perplx
Jun 26, 2004


Best viewed on Orgasma Plasma
Lipstick Apathy
I have 3gb right now and it’s pretty cool for usenet, takes longer to extract than download now.

Perplx
Jun 26, 2004


Best viewed on Orgasma Plasma
Lipstick Apathy
The faster I can download, the less time I spend managing my downloads.

Perplx
Jun 26, 2004


Best viewed on Orgasma Plasma
Lipstick Apathy
Just fyi bell fibre in Canada uses pppoe and every ubiquiti router even the dream machine pro se is to slow for 3/3 Gb let alone 8/8 Gb. I just gave up on them for routing because they suck.

Perplx
Jun 26, 2004


Best viewed on Orgasma Plasma
Lipstick Apathy

Twerk from Home posted:

What are you using as a router at such high speeds? I'd expect multi-gigabit routing to require some expensive (or very DIY) hardware.

The dream machine pro se is expensive and Ubiquiti doesn’t list the ~2.3 Gb pppoe limit in the spec sheet, but they do list the IDS/IPS throughput is 3.5Gb. There are many disappointed customer on unofficial bell internet discord.

Adbot
ADBOT LOVES YOU

Perplx
Jun 26, 2004


Best viewed on Orgasma Plasma
Lipstick Apathy
Speedtest.net can vary, the cli version is the most accurate

The best real world Speedtest is probably Usenet or downloading a Linux iso using aria2 with 16 threads off a close mirror.

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply