Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

subnetspider

@subnetspider@mastodon.bsd.cafe
mastodon 4.7.3
  • Open on mastodon.bsd.cafe

My main interests are IPv6, FreeBSD, ZFS and jails.

I also enjoy playing around with automation, networking, virtualization, lots of hardware, free software, and trying to learn more about IT security.

I fix computer networks for a living, each one more borked than the last.

0 Followers
0 Following
33 Posts
Joined April 25, 2024
Blog:
https://www.subnetspider.com/
DM (Signal):
subnetspider.01
Location:
🇪🇺
Open post
subnetspider @subnetspider@mastodon.bsd.cafe
· 2d ago
Hey there #NetBSD people, I am thinking about installing NetBSD on a Linux-only VPS provider, which I have done a lot already with FreeBSD, thanks to the mfsBSD project, which lets you install FreeBSD from a RAM disk. Does something like that also exist for NetBSD as well? I would love it if I could just attach a custom ISO, but a lot of cheap VPS providers only give you a list of 5-6 Linux distros instead.
2
1
1
0
Open post
subnetspider @subnetspider@mastodon.bsd.cafe
· 2w ago
I always find it funny when someone on the Internet says "ZFS is memory hungry" or "ZFS needs at least 8 GB of ECC RAM to run". Nonsense. To prove it, I installed #FreeBSD 15.1 (64 bit!) on a 23 year old PC, with ZFS and only 1 GB of RAM, running multiple jails without issue. 😎 It has been a bit tricky to get FreeBSD 15.1 to boot off a modern SATA drive, but I found some old PCI SATA controller I bought way back in the Windows 7 days which is still supported. The single core AMD Athlon 64 3000+ is a bit slow, but pkgbase really helps with speeding up installing patches. It's still fast enough to reach 604 Mbit/s in iperf3 (and 490 Mbit/s in client mode). If I wanted to, I could even turn this ancient machine into a NAS, which really proves that old PCs aren't trash, but modern software is.
34
1
14
0
Open post
subnetspider @subnetspider@mastodon.bsd.cafe
· 6mo ago

Today I shut down another one of my Proxmox VE VMs, after migrating the last of it's jails (NSD, Unbound, AdGuard Home, and the 2nd HAProxy carp instance) to my HP t620 thin client.

This little machine has been running my new Zabbix Server for the last 6 months.

I've also set up automated ZFS replication on my main FreeBSD server to back up all the data on it every night, so I don't have to worry about the single SSD dying anymore.

Now only NetBox (Ubuntu LXC) and the Minecraft Server (Windows Server 2022) remains on Proxmox, the former will be migrated to a VNET jail, the latter to a bhybe VM.

Let's see how long that'll take me... 🫠

22
0
8
0
Open post
subnetspider @subnetspider@mastodon.bsd.cafe
· 7mo ago
Replying to
Now that's more like it ☺️
13
3
1
0
Open post
subnetspider @subnetspider@mastodon.bsd.cafe
· 6mo ago

Today I've set up two OPNsense 26.1 Firewalls in a HA configuration on a single DSL internet connection.

Failover is working, the backup OPNsense does connect the PPPoE session, and requests a IPv6 prefix via DHCPv6, but it doesn't disconnected the PPP session after the main OPNsense comes back online.

Not sure why, I've set up CARP on the igb0_vlan interface, but it's not working. I probably forgot something, needs more troubleshooting.

Still, pretty nice not needing a router in front of the OPNsense Firewalls. :)

7
1
3
0
Open post
subnetspider @subnetspider@mastodon.bsd.cafe
· 5mo ago
Replying to
Okay, so I got the converted Windows 10 VM running under #Bhyve without issue, everything is working as it should. But for some reason, all VMs on this host can only be started once, after a VM is stopped, the host has to be rebooted to get them running again. There are no errors, no logs, no .lock files, no stale tap interfaces, no zombie processes, just nothing at all. When I issue "vm start windows10", there is a short spike in CPU usage, then nothing happens, and the VM remains " Stopped". Has someone ran into such a problem before with #FreeBSD 15.0? All other hosts I have used so far ran the VMs perfectly fine... 🤔
5
2
3
0
Open post
subnetspider @subnetspider@mastodon.bsd.cafe
· 5mo ago
Replying to
@tschaefer@ipv6.social @miyuru@ipv6.social That's what I like to see 😁🤩 Happy #IPv6 half time.
5
0
2
0
Open post
subnetspider @subnetspider@mastodon.bsd.cafe
· 3mo ago
Replying to
@fionescu@mastodon.bsd.cafe The error sounds like as if another instance of Unbound is already running or some other software bound itself to port 53. You could check for other programs on port 53 with "netstat -atn". :)
2
1
0
0
Open post
subnetspider @subnetspider@mastodon.bsd.cafe
· 5mo ago
Thanks to a lot of help from @Larvitz@burningboard.net I now have access to the DN42 network. :D
3
1
0
0
Open post
subnetspider @subnetspider@mastodon.bsd.cafe
· 7mo ago
Replying to
Am I sure I want to destroy the current contests (SFOS 21.5.1)? Absolutely, Yes! 😁
4
2
2
0
Open post
subnetspider @subnetspider@mastodon.bsd.cafe
· 3mo ago
Replying to on mastodon.social
@canartuc@mastodon.social I'd rather wait another month than to have a broken update :D
1
1
1
0
Open post
subnetspider @subnetspider@mastodon.bsd.cafe
· 3mo ago
Replying to
@Larvitz@burningboard.net Is it just me, or is your blog now loading even faster? Feels almost instant on my 4 year old Smartphone.
1
1
0
0
Open post
subnetspider @subnetspider@mastodon.bsd.cafe
· 6mo ago

@nuintari@mastodon.bsd.cafe Also, don't use the same internet connection for both in-band and out-of-band management.

4G routers are very cheap today, so use one for your out-of-band management, unless you want to drive for hours on a Friday evening.

2
0
0
0
Open post
subnetspider @subnetspider@mastodon.bsd.cafe
· 6mo ago
Replying to
Second try, now it worked. Both firewalls are on 26.1.4 now. Good thing I've set up CARP. 😁
2
0
0
0
Open post
subnetspider @subnetspider@mastodon.bsd.cafe
· 7mo ago

Just found out (after troubleshooting for 2+ hours) that the reason why one of our customers VoIP equipment can't reach their SIP registrar's servers IP, is because of peering issues.

Funnily enough, it works fine when I route the SIP traffic over the backup 4G connection, whose ISP has direct peering with the SIP registrar.

I fully expected the Sophos XGS Firewall to be the culprit, but of course, this time it worked perfectly. Times like these feel like Sophos is gaslighting me into believing it never has problems.

But alas, this problem is for someone else to solve. 🫠

/s

2
4
0
0
Open post
subnetspider @subnetspider@mastodon.bsd.cafe
· 7mo ago
Replying to
@Larvitz Sorry, what I meant is that you can give a VNET jail one of your hosts physical interface (e.g. igb0) which disappears from the host once the VNET jail is started. This also works with VLAN interfaces (e.g. em0.60) and so on (I did read the article). ^^ *Depending on the interface (or rather, it's driver), those physical interfaces can sometimes get "stuck" after the VNET jail is stopped, not getting released back to the host properly.
2
0
0
0
Open post
subnetspider @subnetspider@mastodon.bsd.cafe
· 5mo ago
Replying to
@Larvitz@mastodon.bsd.cafe I bet this thing should be able to do at least 10 Gbps if all the limits were removed. :D
1
0
0
0
Open post
subnetspider @subnetspider@mastodon.bsd.cafe
· 7mo ago
Replying to
@chewie I've had the misfortune to use it non stop for the last 3 years, you didn't miss out. OPNsense FTW! 😁
1
0
0
0
Open post
subnetspider @subnetspider@mastodon.bsd.cafe
· 7mo ago

@nuintari@mastodon.bsd.cafe AFAIK it should not matter if you use SwitchOS or RouterOS as long as the switch chip is capable of offloading everything. Some cheaper devices used to (?) have most interfaces connected to a switch chip, and some to the CPU, which may have been the cause of the low performance.

I've tried both the hAP ax LTE6 lite and the hEX refresh (E50UG) and I didn't notive anything, but alas they're routers, not switches. 🤷‍♂️

1
0
0
0
Open post
subnetspider @subnetspider@mastodon.bsd.cafe
· 7mo ago
Replying to
@Larvitz VNET Jails really are one of FreeBSD's greatest features. 😁 And while I do not have need for, you could also give a jail of of your FreeBSD hosts physical interfaces, skipping epair and bridge interfaces entirely. 😎 Netgraph VNET Jails are also pretty neat, though I find working with ng_* interfaces a bit too complicated, so I usually stick with epair.
1
1
0
0
Open post
subnetspider @subnetspider@mastodon.bsd.cafe
· 6mo ago
Replying to
@Larvitz Pretty interesting read, as I've never set up the firewall on a Linux host. And I have to admit, firewalld looks pretty neat. 😁
0
0
0
0
Open post
subnetspider @subnetspider@mastodon.bsd.cafe
· 6mo ago
Replying to
@hallunke23 The SIP registrar is IPv4-only.
0
2
0
0
Open post
subnetspider @subnetspider@mastodon.bsd.cafe
· 6mo ago
Replying to
@hallunke23 No clue, the entire AS of the SIP provider doesn't have any IPv6 prefixes, and the local network of the customer is IPv4-only. The ISP is currently investigating the issue, that's all I know.
0
0
0
0
Open post
subnetspider @subnetspider@mastodon.bsd.cafe
· 6mo ago

@nuintari@mastodon.bsd.cafe :D True, but I don't provide fiber or celluar, I only cosplay as a firewall admin.

Still, being able to access your firewall over 4G if the DSL (we still use that here) breaks is a lot better than being offline.

0
0
0
0
Open post
subnetspider @subnetspider@mastodon.bsd.cafe
· 5mo ago
Replying to
@matthew I've made a few notes and saved a couple of useful links so far, if it works out, I might share even them. ;)
0
1
0
0
Open post
subnetspider @subnetspider@mastodon.bsd.cafe
· 5mo ago
Replying to
@patpro Nothing, it only logs until the VM is shut down and the tap interface is destroyed. However, for some reason, the VMs work completely find with Sylve, so I guess I might have a problem with vm-bhyve.
0
0
1
0
Open post
subnetspider @subnetspider@mastodon.bsd.cafe
· 5mo ago
Replying to
@Larvitz CHR on Bhyve, nice. :) What does the network of the RouterOS VM look like (e.g. bridge + tap / netgraph / ...)?
0
2
0
0
Open post
subnetspider @subnetspider@mastodon.bsd.cafe
· 7mo ago
Replying to
@tschaefer@ipv6.social NAT64? NAT46!
0
2
0
0
Open post
subnetspider @subnetspider@mastodon.bsd.cafe
· 4mo ago
Replying to
@tschaefer@ipv6.social 😑
0
0
0
0
Open post
subnetspider @subnetspider@mastodon.bsd.cafe
· 11mo ago
Replying to

@fribbledom@mastodon.social All of the above, plus:

  • Take a peace of paper and write down all the details you know
  • Ask yourself if the problem might be somewhere else entirely
  • Go through the process from start to finish, step by step (don't skip the obvious ones)
0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 21:30:55 UTC