• 4 Posts
  • 206 Comments
Joined 3 years ago
cake
Cake day: July 20th, 2023

help-circle
  • Yep, I checked that possibility too but it is like putting barriers into the see because :

    • DoH can also share the IP-PORT with some legits websites
    • there is not a proper way to scan the web to see if there is a proper service
    • the effort to setup one is orders of magnitude lower tan to track then and then to filter it properly

    Honestly is just the prey-predator competition. It won’t stop ever


  • I had the same problem in my network and the solution is not easy.

    Many, but many android apps are using Google dns servers just to leak the location of the phone (using the nearest geographical Google server).

    The only way I found it was to instsll an opnsense router and redirect requests to port 53 to the internal dns server.

    DoT (dns over tls) is blocked because it can not be redirected

    DoH (dns over https) is (almost) imposible to block and still is a hole in current systems.

    Good luck solving this


  • Oh I see, could you please point to that system that

    • it is free and not tie to any vendor
    • easy to use to the point that my grandma could use it
    • properly tested by an active q group
    • with safe boundaries
    • production ready
    • total flexibility
    • with a proper wizard / gui that is self explanatory, robust enough to make sure you don’t select contradicting options.

    If such system exist perhaps I move my homelab, who knows…


  • I think you are missing the point how easy is to fuck things up in a console with truenas when trying to activate de duplication or making a backup VS the same thing in a user friendly, already tested private solution. Of course from the noob point of view.

    Installing truenas when having no idea about almost anything is cumbersome, dealing with the millions options (some of them incompatible between them) is frustrating, cryptic error codes are discouraging…

    You want people jump in? Then make it easy for them, lower the entry barrier, if not, you will find yourself alone in your ivory tower.

    The exact same ia true for you synology NAS. + the limitations on how synology thinks you should do backups vs how it actually suits you.

    If you already know how to setup a proper backup system, balancing the pros and cons, with a robust and solid way to avoid data loss, then you don’t qualify for noob.

    If you don’t know any of that and still makes yiur backup system, that’s the recipe of the disaster and you have real probabilities of losing data with nay option to recover.


  • I see your point but in this world there is only 2 options, or you have the skills, the knowledge and the time to do it by yourself, or you need to outsource it.

    Assuming that the op is a real noob it is clear that the 2 first prerequisites are missing making that option unacceptable, then you can only go to the buy something easy enough for the general public.

    And in top of that, in a homelab, the most sacred thing is the data, not the service, the data. If you misconfigure a nas or the automated backup system it could lead into the worst scenario: the data is lost forever.

    Weighting everything I still recommend what I did. Although if instead of synology you prefer ugreen or asustor… Well that’s depends of your taste














  • Are both of them ula addresses? (both of them starting with 2). If they are not the same then the ISP is providing an internal unique address for isp internal configurations.

    If so, are they having the same network? ( The first 48 bits) if not, then is probably a miss configuration but probably in their side. But with no practical effects. You could ignore it.

    If yes again, then it is a miss configuration and it shouldn’t happen, but this time it could be in your side, check that the dhcpv6 daemon doesn’t try to give an ipv6 address To your Wan port


  • Honestly, every hw that is not going automatically into a power save mode when not used is utterly crap, even my home grade switches are able to do so.

    So, the only thing you need to do is to buy recent hw and of course not over size your hw necessities. But recent hw tends to be more expensive, so in the end, it is an excel driven decission.

    And once this is said, be careful, some hw suffer more for a on/off cycle than from a continuous power on mode. Think in hdd power cycles or condensation/ salt-rust problems in high humidity areas.