The post isn't mentioning DHCPv6-PD[*] (prefix delegation.) I feel like murphy's law is kicking into effect right now and the ISP-provided router actually supports PD to give downstream routers their own /64. (Or maybe not. Who knows. I feel like the post would've mentioned PD if they tried it.) Also: I divided it into a smaller subnet 2001:db8:abc:123:40::/76 Anything on a broadcast/multinode segment that isn't /64…
Upvoting as good idea, but most routers I know, evening running custom firmware, don't support delegating a wan prefix on request from lan side.
Wireless-to-Ethernet island for RPi cluster: IPv6, NDP proxy, mDNS reflector
51–60 of 60 posts
Re: Wireless-to-Ethernet island for RPi cluster: IPv6, NDP proxy, mDNS reflector
#52Having similar issue myself, I have found simpler and cheaper alternative - $20 Gl.inet mini router [1] that runs OpenWRT, but also has frienly UI where you can turn STA mode, connect it to your wireless network and have wired internet on the ethernet port. I use it for wireless Wake-on-Lan for my homelab PC, integrated with homeassistant and Google Assistant voice command “Hey Google, turn on homelab”. [1] - perhaps…
OpenWRT is unfortunately rather limiting. For example: can you run tcpflow on your mini router?
Re: Wireless-to-Ethernet island for RPi cluster: IPv6, NDP proxy, mDNS reflector
#53Re: Wireless-to-Ethernet island for RPi cluster: IPv6, NDP proxy, mDNS reflector
#54Earlier quoted context omitted.
I use one of those GL.inet routers. It's been reliable for 1.5 years. I configured it to route all traffic through a proxy service (aka VPN). Most VPN clients fail open, which defeats the purpose of using a proxy for privacy. The GL.inet firmware has an option to fail-closed when the proxy connection is down. I use a ZTE MF820B USB 4G LTE modem as a backup Internet connection. I configured the GL.inet router to talk…
> I use a ZTE MF820B USB 4G LTE modem as a backup Internet connection...GL.inet is based in Hong Kong and is now under the control of the Chinese red party. ZTE is a Chinese state-owned enterprise, so if CCP-sanctioned action is part of your threat model I'm not sure GL.inet would be the most concerning part of that stack.
1. The ZTE device is on the untrusted side of the network. It carries encrypted OpenVPN packets.
2. The ZTE device does not download new firmware.
3. The ZTE device is not addressable on the public Internet. It participates in the GSM network. It tunnels data between its USB interface and the NAT proxy server (APN) provided by the carrier.
And one point increases the risk: The ZTE device is physically attached to the USB port of the router.
CCP-sanctioned action directed at me is not part of my thread model. I'm more concerned with them breaking the security of the firmware to facilitate monitoring of PRC citizens who use GL.inet devices. There is precedent for this. For example CCP forces everyone in an entire province to install spyware on their phones that logs their activities and communications and transmits them to a central server unencrypted. The data goes over whatever network the user is connected to, with zero privacy or even any protection against MITM.
If GL.inet broke their firmware security, how long would the blackhats use it before the rest of us found out about the problem?
Re: Wireless-to-Ethernet island for RPi cluster: IPv6, NDP proxy, mDNS reflector
#55Re: Wireless-to-Ethernet island for RPi cluster: IPv6, NDP proxy, mDNS reflector
#56Earlier quoted context omitted.
OpenWRT is unfortunately rather limiting. For example: can you run tcpflow on your mini router?
https://bitkeks.eu/blog/2016/08/collecting-netflow-v9-on-ope...
I might be wrong, will look at it longer.
But my initial point, which I should have elaborated on: compiling stuff for openwrt is a gigantic pain in the butt.
I tried to compile tcpflow for OpenWRT, installed a VM with the whole toolchain, messed with it for 4 hours and finally gave up when I realized I would have to also recompile a recent openssl to to get tcpflow to link.
Much better to run a "proper" linux distro on these firewall/routers hardware.
Re: Wireless-to-Ethernet island for RPi cluster: IPv6, NDP proxy, mDNS reflector
#57What if your IPv6 prefix changes? As far as i know prefixes from Vodafone cable in Germany are semi static so it could change in a few months.
Re: Wireless-to-Ethernet island for RPi cluster: IPv6, NDP proxy, mDNS reflector
#58Earlier quoted context omitted.
Upvoting as good idea, but most routers I know, evening running custom firmware, don't support delegating a wan prefix on request from lan side.
Fritz!Box supports it (needs to be enabled in the IPv6 settings) so does OpenWRT
Re: Wireless-to-Ethernet island for RPi cluster: IPv6, NDP proxy, mDNS reflector
#59Having similar issue myself, I have found simpler and cheaper alternative - $20 Gl.inet mini router [1] that runs OpenWRT, but also has frienly UI where you can turn STA mode, connect it to your wireless network and have wired internet on the ethernet port. I use it for wireless Wake-on-Lan for my homelab PC, integrated with homeassistant and Google Assistant voice command “Hey Google, turn on homelab”. [1] - perhaps…
Re: Wireless-to-Ethernet island for RPi cluster: IPv6, NDP proxy, mDNS reflector
#60Having similar issue myself, I have found simpler and cheaper alternative - $20 Gl.inet mini router [1] that runs OpenWRT, but also has frienly UI where you can turn STA mode, connect it to your wireless network and have wired internet on the ethernet port. I use it for wireless Wake-on-Lan for my homelab PC, integrated with homeassistant and Google Assistant voice command “Hey Google, turn on homelab”. [1] - perhaps…
OpenWRT is unfortunately rather limiting. For example: can you run tcpflow on your mini router?
this is just a really narrow gripe, picking on one very tiny small perspective angle. and it doesn't take any responsibility for what it might take to do better. this is extremely cheap talk shade casting. i'm incredibly unimpressed. it reeks of sabotage.
I'd rather run Debian too. but everything about this post stinks of meanspirited senseless misonfo sabotage.