Incessant tinkerer since the 70’s. Staunch privacy advocate. SelfHoster. Musician of mediocre talent. https://soundcloud.com/hood-poet-608190196

  • 30 Posts
  • 1.37K Comments
Joined 1 year ago
cake
Cake day: March 24th, 2025

help-circle




  • So, I’ve come to the realization that I should probably set up a VPS, since that should solve basically all of my issues. All I want is something that can forward/proxy gigabit traffic to my server, probably over something like wireguard.

    Forgive my addled brain. Are you wanting a VPS to set up a VPN like Wireguard? If so, the VPS won’t have to be anything huge I would imagine. For something like that, I would go shopping at lowendbox.com. The important bits would be the speed rather than size of the VPS. Also, since you mentioned you already have Docker running, Wireguard Easy, would be the easiest to deploy.


  • For one, he spec’d a Protectli VP2420. You are going to pay for the Protectli brand name. They are great boxes no doubt, but you could most likely find the same spec as the Protectli VP2420, in something cheaper. Two, I think on eBay, things are priced by how much the vendor thinks he can get. If it’s a bid scenario, they probably have a minimum purchase price set. Most often, I just select the ‘Buy It Now’ option and save myself the hassle of getting into an endless bidding war which is usually manipulated by the vendor using multiple eBay accounts or ‘friends’. That is, unless I think I can save several hundred dollars on something.

    Perusing eBay, wow, yes prices have gone up. It’s been quite a while since I’ve bought any new devices. However, I think you could get away with a suitable firewall device for around the $300 +/- if you did some shopping.


  • In that guide, he has a firewall mini PC that costs about $540.

    That’s pretty high for what you really need, imho. I purchased my stand alone firewall box from eBay. It’s been quite a long time ago, but if I remember correctly, it ran about $275+/- USD. Specs:

    • Mini Fanless (tho I did add a fan)
    • Intel® Celeron® CPU J3160 @ 1.60GHz
    • Current: 1600 MHz, Max: 1601 MHz
    • 4 CPUs : 1 package(s) x 4 core(s)
    • AES-NI CPU Crypto: Yes
    • QAT Crypto: No
    • Upgraded to 32 GB RAM (overkill) and 4 TB SSD (overkill)

    I installed pFsense on it, but OpnSense would work too, I’m just not really familiar with OpnSense. I run Suricata (IDS/IPS), ntopNG (traffic analysis), pfBlockerNG (filters), TailScale (as an overlay), and a couple other ancillary packages that just make things easier. I have noticed no bottlenecks, or slow down, even for the box’s age. pFsense, imho, makes VLANS pretty straight forward. I have segregated my network into multiple VLANS so that I can isolate iOT devices, mobile devices, cams, servers, etc. The firewall appliance doesn’t really need to be some big honkin’, spec’d out box to do it’s job.

    do both switches need to be managed switches for the VLAN tags to stay intact?

    Managed switches are the way to go.










  • Hey bro, thanks for the lead! I will read the issue report and check if netdata is current.

    @ilyam8 - adding to it here, netdata does leave tons of zombies around, this is not a “cannot reproduce” (not sure why that tag was added without even the minimal response, and then removed needs triage on top of that, so this ticket just dies off) One simply needs a running netdata instance and let it run a while. With time, 1, three and then tens of zombies will be listed at login.