thelittleblackbird
@thelittleblackbird@lemmy.world
- Comment on Replacement for Docker Content Trust (DCT) 2 weeks ago:
Got it, I thought it was a last segment attack (image substition) but now I see you are aiming to a fully supply chain attack.
And if you find an nswer to that, please let me know because this things have virtually not a solution that ticks all boxes
- Comment on Replacement for Docker Content Trust (DCT) 2 weeks ago:
Assuming the risk of being naive… Why is checking the hash not enough?
Or didn’t I understand your problem?
- Comment on first nas network struggle 3 weeks ago:
Don’t know what to say,
I maintain a double stack since 5 years and apart of some small nuisance I never had a real problem.
Ipv6 has been with us for more than 20 years, and It is true that to have that fine grain control in ipv6 you will need to go to a prosumer devices, but those are not that expensive and if you have a home lab you should check on them anyway…
Things are mature despite your bad experiences
- Comment on first nas network struggle 3 weeks ago:
Well…
Ipv6 is needed for peer to peer networks, easier for vpn and full mndgoru if you want to have a vps…
With it, you can avoid Cgnats and home Nats and usually it is faster and more reliable than ipv4.
So, see it for yourself…
- Comment on Why is my home server using so much RAM for cache + buffer? 3 weeks ago:
The amount of swap used is not a good indicative, you need to check if there is a big exchange of data per second/minute. This is the only indicative of an out of memory system.
Sometimes, some regions of data memory “age” in ram without any access for a long periods of time, the the kernel here has two options, it could destroy the region knowing it could recreate it when needed (with some cpu overhead) or moved this to a swap file when the ram structure already in the swap file and release than section.
Which regions are good candidates for this? Buffers, specially in the fs, code region used for processes or even data sections of a long sleeping process…
Checking your data, if those 5gb are created over a long period of time I would not care a lot about it. Remeber how big the swap is, isn’t that important vs real traffic (in or out) to it
- Comment on Help configuring OPNsense VLANs? Tutorials I find seem to quickly become outdated. 2 months ago:
OK, then assuming that you already discarded to run 2 cables and others in this thread provided a very good guide of how to do vlan, I can only recommend to setup some aggregation channels in your opnsense box and some switches to at least mitigated the performance hit.
Not now, of course, first you need yiur setup working
- Comment on Help configuring OPNsense VLANs? Tutorials I find seem to quickly become outdated. 2 months ago:
Then I really recommend you not to play with vlan and use different eth ports as different segments.
The performance will be significant better this way
- Comment on Help configuring OPNsense VLANs? Tutorials I find seem to quickly become outdated. 2 months ago:
Just for me to fully understand your setup.
How many eth ports do you have in your opnsense box?
- Comment on Hardware recommendations for running OpenSense as a Firewall? 2 months ago:
Try to find a rev3, the cpu upgrade really is really worthy
- Comment on Hardware recommendations for running OpenSense as a Firewall? 2 months ago:
Which hw revision?
If it is a ver3 it is the same I have, good for FW and red services, you can make complex setups.
It is a bit short on cpu for ips systems(suricata and zenarmor) , but it is able to do dns filtering via adguard or unbound.
100€ sounds good to me if it comes with AP, people here are happy with that brand
Good luck
- Comment on Hardware recommendations for running OpenSense as a Firewall? 2 months ago:
Take a sophos second hand FW.
Intel nic, low power consumption processors and full opnsense support.
Go at least for 4gb ram and the most powerful processor you can safely get. It will come with a lot of eth ports too on top.
And it will cost close to 100€, probably less if you struck a good deal
- Comment on Self-hosting paradox: Windows for specifically MS word 7 months ago:
Kasm, you only need kasm.
It is a docker engine with the streaming already incorporates. Try that.
It is true that it relies in wine, so perhaps you will need to experiment a bit and pin down a specific wine version. But if I recall correctly I saw an old version of ms office running in wine
- Comment on ISO Project Ideas For Wyse 3040 & 5010 Thin Clients 9 months ago:
This could be funny if you have a d event computer, specially for od games