Oddbean new post about | logout
 Literally can't keep my hands off my network. Just ordered a couple of pretty sweet upgrades for the #homelab. Pretty stoked about it. Come to Mama! :)

TP-Link TL-SG3428X-M2 | 24 Port Multi-Gigabit L2+ Managed Switch | 24 x 2.5 Gig Ethernet Ports, 4 x 10 Gig SFP+ Ports | 10 G Bandwidth | Support Omada SDN
https://i.nostr.build/KSsv2pljvj5n4hdh.webp
https://i.nostr.build/XgSoUXDnMXpe8Nbj.jpg
https://i.nostr.build/kt3rHtX8cV9BlYy4.jpg
https://i.nostr.build/sjal4rSZnRq7S5RZ.jpg
https://i.nostr.build/RBM9noH9K6yduuUb.jpg
https://i.nostr.build/mrIoIfjZgZC3ZzkY.jpg
Note: The TL- name has been dropped with the new models as select Jetstream switches become Omada. It's the same device with a different brand and firmware numbers.
https://community.tp-link.com/en/business/forum/topic/649878

...And 

Cable Matters Rackmount or Wall Mount 24-Port Shielded RJ45 Patch Panel with Jack Shutter
https://i.nostr.build/HWVQNKVBrmGuZsST.webp
https://i.nostr.build/fwlwJXWOC2rpcN08.webp
https://i.nostr.build/7Wrj4AQxvLTMOmlp.webp
https://i.nostr.build/omwBzeQ46jMwFjtH.webp
https://i.nostr.build/cEj0vHtFUGwM086R.webp
https://i.nostr.build/LNRABIDePbwAK1RM.webp
https://i.nostr.build/QYFCRmEBp2KFdBo9.webp

#ikitao #tech #networking 
 The two of you need to get a room. 

Seriously serious bit of tech right there. Whatcha gonna do with it? 
 Room acquired. ;) Oh, you know... stuff. Seriously, it's a necessary upgrade. This place is like a compound, and I'm managing everything across multiple buildings, with multiple VLANs, so it's going to let me increase security, network everything at 2.5 g speeds and above, and have full control over maintenance, managing multiple APs etc. I'm also getting it ready to go mobile (a mobile home lab) when I move and travel, so that's going to be fun. 👀 
 4x10G SPF+, that's a spicy 🔥 setup

Using fiber interlinks between buildings? 
 💜🧡⚡️🚀 
 ✊🏼 
 ✊🏻 
 I bought the 8 x 2.5G with 2 x SFP+ equivalent of that switch a little while back (SG3210X-M2) mainly because I wanted some 2.5G ports with the SFP+ for uplink to my 10G switch. I’m not using any of the advanced features or the Omada management stuff but for basic switching and VLANs etc it has worked well. 
 Nice. 
 that's pretty cool gear though i can't imagine needing that at home 😀 but will keep it in mind when moving into a castle someday ! 
 Say one lives in an apartment in an urban area. What would you suggest as the first security and performance  upgrade to a setup that uses the provider's wifi router, hardwired to two separate wifi routers, one for my work and the other for the family stuff? 
 I recommend a #Protectli Vault Pro VP2420 4x 2.5G with no WiFi module, coreboot pre-installed, running OPNsense (or pfSense; I prefer OPNsense).

It's a great hardware firewall/router for most home and small business networks. You can install an always-on VPN if you like, assign interfaces, silo networks, assign subnets and static IPs, and generally keep your network monitored and secure.

Put your ISP router in bridge mode, then use the Protectli as your firewall/router.

You can run all interfaces off the same LAN network or get more granular with security through isolation...

Example:

  • LAN interface could be for your trusted devices like your computer, etc.
  • Opt1 could be your NAS or storage (siloed from both networks).
  • Opt2 could be your untrusted devices like IoT devices and for friends to connect to when they come over, etc.

You can then use OPNsense to set up rules for how these networks can and cannot interact with each other.

You can also run switches (large and small, managed or unmanaged) and/or WiFi routers (preferably running OpenWRT) in AP mode off of any of the three interfaces.

https://protectli.com/product/vp2420/ 
 I love my protectli vault with opnsense! 
 Why not an arm router with openwrt? Same result can be achieved with less money and resources. 
 Hardware firewalls running OPNsense on dedicated devices like Protectli offer superior security and advanced routing features. They're built for one job and do it well. 

OpenWRT, primarily designed for Wi-Fi routers, provides flexibility but can struggle when tasked with complex firewall and routing functions. 

While OpenWRT can be configured to do it all, it's not optimal for advanced security setups, similar to all-in-one ISP solutions that prioritize convenience over security. 

Best practice involves separating network functions: use a dedicated hardware firewall/router (like OPNsense) for security and routing, and a separate device running OpenWRT or similar firmware for Wi-Fi. 

This approach ensures each component performs its specialized task efficiently, avoiding the compromises inherent in all-in-one solutions. 
 I gotta do some digging.  I just swapped my Unifi Security Gateway for OpnSense and am experiencing random internet drop offs.  I can still connect to it via the webUI but can't ping out on the WAN, rebooting fixes it for a few hours/days but I need to figure it out.  Are realtek ethernet ports as bad as Reddit makes it sound?  According to then it's Intel or nothing... 
 what do you like about OPnsense over pfSense?  I've been using pfSense since 2015. whenever I try to upgrade I always end up going back.  
 UI is so much better IMO, not to mention the questionable decisions/abuses of trust pfSense has made that has driven users to OPNsense. Both are good. I prefer OPNsense. 
 Thank you for this, much appreciated. I look forward to making this a weekend project in the very near future. 
 Nice 💯 
nostr:nevent1qqs8eqwkstag7dvcdv3eg9ee0956673e43vact0ep3m6lxeq3am98tcpz4mhxue69uhkummnw3ezummcw3ezuer9wchsygzwhzp3p445ak2ud4n289dn6084txu9ltkg7a53mt75qk5jup2ad5psgqqqqqqshyrh2n 
 The new network tech has arrived, and it's the updated model! Good stuff. As always, nostr:nprofile1qqsz9nr55u53zdecvenu7zj5z3hfu2ua5skjfft9t3lstqgrcy3n5uspzemhxue69uhkummnw3ex2mrfw3jhxtn0wfnj7g8xz56 inspects the goods for shenanigans (and to claim her new boxes). Tonight's going to be a good night. 🫡🚀👩🏼‍💻
https://i.nostr.build/Cif89hMB6DjxtlCY.jpg
https://i.nostr.build/puYRQPOpdOQC7XkG.jpg
https://i.nostr.build/4Hi1btuxrd65PH5K.jpg
https://i.nostr.build/dCB55CxdPQJTa9CA.jpg
https://i.nostr.build/dKXNoqeSwi0WIxIN.jpg
https://i.nostr.build/AZs3M0fhZ1BGwfx6.jpg
nostr:nevent1qqs8eqwkstag7dvcdv3eg9ee0956673e43vact0ep3m6lxeq3am98tcpr4mhxue69uhkummnw3ezucnfw33k76twv4ezuum0vd5kzmp0qgsyawyrzrttfmv4cmtx5w2m85702kdct7hv3amfrkhagpdf9cz46mgrqsqqqqqp8jfffm