Live data from Hacker News

Wireless-to-Ethernet island for RPi cluster: IPv6, NDP proxy, mDNS reflector

vladimir.varank.in

51–60 of 60 posts

Re: Wireless-to-Ethernet island for RPi cluster: IPv6, NDP proxy, mDNS reflector

#51
post #18

The post isn't mentioning DHCPv6-PD[*] (prefix delegation.) I feel like murphy's law is kicking into effect right now and the ISP-provided router actually supports PD to give downstream routers their own /64. (Or maybe not. Who knows. I feel like the post would've mentioned PD if they tried it.) Also: I divided it into a smaller subnet 2001:db8:abc:123:40::/76 Anything on a broadcast/multinode segment that isn't /64…

Upvoting as good idea, but most routers I know, evening running custom firmware, don't support delegating a wan prefix on request from lan side.

Fritz!Box supports it (needs to be enabled in the IPv6 settings) so does OpenWRT

Re: Wireless-to-Ethernet island for RPi cluster: IPv6, NDP proxy, mDNS reflector

#52
post #3

Having similar issue myself, I have found simpler and cheaper alternative - $20 Gl.inet mini router [1] that runs OpenWRT, but also has frienly UI where you can turn STA mode, connect it to your wireless network and have wired internet on the ethernet port. I use it for wireless Wake-on-Lan for my homelab PC, integrated with homeassistant and Google Assistant voice command “Hey Google, turn on homelab”. [1] - perhaps…

OpenWRT is unfortunately rather limiting. For example: can you run tcpflow on your mini router?

https://bitkeks.eu/blog/2016/08/collecting-netflow-v9-on-ope...

Re: Wireless-to-Ethernet island for RPi cluster: IPv6, NDP proxy, mDNS reflector

#54

Earlier quoted context omitted.

I use one of those GL.inet routers. It's been reliable for 1.5 years. I configured it to route all traffic through a proxy service (aka VPN). Most VPN clients fail open, which defeats the purpose of using a proxy for privacy. The GL.inet firmware has an option to fail-closed when the proxy connection is down. I use a ZTE MF820B USB 4G LTE modem as a backup Internet connection. I configured the GL.inet router to talk…

> I use a ZTE MF820B USB 4G LTE modem as a backup Internet connection...GL.inet is based in Hong Kong and is now under the control of the Chinese red party. ZTE is a Chinese state-owned enterprise, so if CCP-sanctioned action is part of your threat model I'm not sure GL.inet would be the most concerning part of that stack.

Yes, and several points reduce the risk of the ZTE device:

1. The ZTE device is on the untrusted side of the network. It carries encrypted OpenVPN packets.

2. The ZTE device does not download new firmware.

3. The ZTE device is not addressable on the public Internet. It participates in the GSM network. It tunnels data between its USB interface and the NAT proxy server (APN) provided by the carrier.

And one point increases the risk: The ZTE device is physically attached to the USB port of the router.

CCP-sanctioned action directed at me is not part of my thread model. I'm more concerned with them breaking the security of the firmware to facilitate monitoring of PRC citizens who use GL.inet devices. There is precedent for this. For example CCP forces everyone in an entire province to install spyware on their phones that logs their activities and communications and transmits them to a central server unencrypted. The data goes over whatever network the user is connected to, with zero privacy or even any protection against MITM.

If GL.inet broke their firmware security, how long would the blackhats use it before the rest of us found out about the problem?

Re: Wireless-to-Ethernet island for RPi cluster: IPv6, NDP proxy, mDNS reflector

#56

Earlier quoted context omitted.

OpenWRT is unfortunately rather limiting. For example: can you run tcpflow on your mini router?

https://bitkeks.eu/blog/2016/08/collecting-netflow-v9-on-ope...

Haven't played with softflow, thanks will definitely try it, but an initial quick look shows me it's not as easy and straightforward as tcpflow.

I might be wrong, will look at it longer.

But my initial point, which I should have elaborated on: compiling stuff for openwrt is a gigantic pain in the butt.

I tried to compile tcpflow for OpenWRT, installed a VM with the whole toolchain, messed with it for 4 hours and finally gave up when I realized I would have to also recompile a recent openssl to to get tcpflow to link.

Much better to run a "proper" linux distro on these firewall/routers hardware.

Re: Wireless-to-Ethernet island for RPi cluster: IPv6, NDP proxy, mDNS reflector

#57
post #53

What if your IPv6 prefix changes? As far as i know prefixes from Vodafone cable in Germany are semi static so it could change in a few months.

As far as I can tell, I have the same IPv6 prefix for at least a year. Of course, if the prefix's changed, I'll have to reconfigure the homelab. If that started to become annoying I would automate that with an ansible task. But will probably need to search for a better and more stable solution.

Re: Wireless-to-Ethernet island for RPi cluster: IPv6, NDP proxy, mDNS reflector

#58

Earlier quoted context omitted.

Upvoting as good idea, but most routers I know, evening running custom firmware, don't support delegating a wan prefix on request from lan side.

Fritz!Box supports it (needs to be enabled in the IPv6 settings) so does OpenWRT

Fantastic, love my FritzBox, I'll look into this. Stand happily corrected!

Re: Wireless-to-Ethernet island for RPi cluster: IPv6, NDP proxy, mDNS reflector

#59
post #3

Having similar issue myself, I have found simpler and cheaper alternative - $20 Gl.inet mini router [1] that runs OpenWRT, but also has frienly UI where you can turn STA mode, connect it to your wireless network and have wired internet on the ethernet port. I use it for wireless Wake-on-Lan for my homelab PC, integrated with homeassistant and Google Assistant voice command “Hey Google, turn on homelab”. [1] - perhaps…

simpler is boring & un-educatuonal but thanks anyways for the good resources. those trying to learn & improve ought know what provided offerings there are about. that is openwrt based is extra compelling that we should better document & explain explain what is really afoot here!!!

Re: Wireless-to-Ethernet island for RPi cluster: IPv6, NDP proxy, mDNS reflector

#60
post #3

Having similar issue myself, I have found simpler and cheaper alternative - $20 Gl.inet mini router [1] that runs OpenWRT, but also has frienly UI where you can turn STA mode, connect it to your wireless network and have wired internet on the ethernet port. I use it for wireless Wake-on-Lan for my homelab PC, integrated with homeassistant and Google Assistant voice command “Hey Google, turn on homelab”. [1] - perhaps…

OpenWRT is unfortunately rather limiting. For example: can you run tcpflow on your mini router?

this is a terrible post! almost all software will compile on openwrt. the sdk build option builds a very nice self contained toolset that builds aost anything. it's just linux. this "openwett is unfortunately rather limiting" shallow posting sounds like ridiculously unsubstantiated corporate anti-open-source software droneposting. spreading shit to confuse the field. f this. bad posting. stop kneecapping great flexible distros. this shallow challenge made, "tcpflow", is some ultra ultra particular horseshit that doesnt reflection what we could do, creates a sense of limit where really possibilities are endless as we wish. terrible conservative posting, I hate it.

this is just a really narrow gripe, picking on one very tiny small perspective angle. and it doesn't take any responsibility for what it might take to do better. this is extremely cheap talk shade casting. i'm incredibly unimpressed. it reeks of sabotage.

I'd rather run Debian too. but everything about this post stinks of meanspirited senseless misonfo sabotage.

Post reply on HN