Skip Navigation
Kazaii Kazaii @sh.itjust.works

Seasoned Network operator & hobbyist Sysadmin. Dog dad. Beer lover. Aspiring Greybeard. Strong believer in community action.

Mastodon: @[email protected]

Blog: zealnetworks.ca

Posts 3
Comments 38

VyOS 1.4.0 LTS release (EPA)

blog.vyos.io VyOS 1.4.0 (Sagitta) LTS release

based on Debian 12, bringing the redesigned firewall, IKEv2 road warrior VPN, new PKI CLI, and many more improvements to the new LTS branch.

VyOS 1.4.0 (Sagitta) LTS release

VyOS 1.4.0 is finally here as a full LTS release (although, it's early production access).

So many great features are highlighted in the post. I've been using 1.4 images for quite some time, with great success, in my labs. Looking forward to using this one more.

Congrats to the VyOS team.

1
OpenWisp is not what I though it could be
  • Thanks for reporting back. Every time I looked at it's features, I came to roughly the same conclusions. Glad you actually did the work to try it, though.

  • openwisp - A Hackable Network Management System for the 21st Century
  • Looks cool. Adding to my linkding. Thanks!

  • "Unskilled labour" is a capitalist myth used to justify poverty wages.
  • it didn’t occur at all how strange that would be

    Haha. Thanks for the laugh.

  • VyOS 1.4.0-rc1 release candidate
  • This release has such bangers. Was so excited to read it in my RSS feed today & comment here.

    • IPv6 segment routing (SRv6) support
    • BGP monitoring (BMP) suppor
    • Firewall flowtable offload functionality

    And the ultimate biggie: The long-awaited ability to rollback configuration without having to reboot is finally here (T5249).

    Thanks so much to the VyOS team for an awesome RC.

  • Vyos adds git commit archive support
  • Yet another reason to love VyOS

  • Vyos adds git commit archive support
  • Yep, mainly because it's targetting DC/SP operators, rather than just the home

  • I have a networking joke, but I cannot packet.
  • This is somehow worse than "five giant websites, each filled with screenshots of text from the other four"

  • *Permanently Deleted*
  • You just hurt Huawei & Arista's feelings. /s

  • Announcing new tool: wgslirpy
  • Cool project. Saving it for future reference, once I get a better handle on Rust.

  • Question: Network Monitoring service that's not Solarwinds
  • Another vote for LibreNMS. I've been using it for a long time and it's just great for most small - relatively large orgs (you have to work a bit harder to deploy it properly / distributed, if you're going for a larger build).

    I've also had Zabbix data piped into grafana and that was rock solid.... I just find that Zabbix requires quite a bit more finessing to get going, if you're not a seasoned sysadmin.

  • What software defined apps are people working with?
  • Sorry, I commented then went to Europe for 3 weeks; Browsing detox.

    Symmetric NAT wouldn't be an issue for Nebula at all -- or WireGuard, as you know, but neither ZeroTier.

    If you're worried about CGNAT, it has several ways to deal with it:

    https://nebula.defined.net/docs/config/punchy/

    The lighthouse can also act as a bastion/proxy and handle the connections for you, if your two nodes can't speak directly.

    That being said.... if you're supporting other users, I think wireguard is the way to go.

  • What software defined apps are people working with?
  • I've been using Nebula for a long time. It's great and definitely worth your time to setup.

  • Lemmy and the Fediverse give me faith in humanity
  • I'd say they're comparable and have similar problems experienced in different ways.

    On mastodon, a big name becomes the stress on the server. It's like people showing up to a small coffee shop to hear a politician speak about something. If the politician becomes more renowned / popular, eventually they have rallies. Eventually those rallies are broadcasted and licestreamed... All that means more infra and more $

    Lemmy has the problem of communities. Communities sometimes gather in small places like a person's house or a bar. If that community grows large, maybe they need to have a conference / convention (like an anime or tech community). That means the instance that hosts that community has to has a conference sized instance, to host all the lads/lasses/etc of the fediverse.

    More eyeballs / more discussion = more demand. Simple as that.

    edit: I will add that there is one difference. You might have your own little small fragmented community, here on sh.itjust ... like for skateboards. More intimate discussion, etc. This would potentially prevent c/skateboards on an instance from growing too large....

    But there is only one @gargron that most people will follow.

  • Lemmy and the Fediverse give me faith in humanity
  • I am also following a specific community here on RSS. Nice to go through my articles and see someone asking for technical help / advice -- or simply sharing something cool.

  • Master's thesis ideas in networking
  • This, and their other CC books, is a great starting place. Especially because it has a hands-on section you can build upon:

    https://5g.systemsapproach.org/README.html

    Maybe take a larger forest view of convergence & orchestration of a provides core.. from access to fabric.

    Other than that, lots is being said about the true meaning of network source of truth. Check some NANOG talks for free on their YouTube channel. Check out Jeremy Stretch's fairly recent blog post on Netbox (packetlife.net).

    If you're looking for more greybeard Inspiration, check out some great analysis from Geoff Huston on potaroo.net and think of interesting software defined ways to demonstrate his analysis (maybe become the next Kentik etc.)

    Russ White & Ivan Pepnelnjak are also great grey beard thinkers.

    Best of luck with your thesis.

  • How do you find the bottleneck of a network?
  • Pretty good suggestions here. Can't remember the last time I saw such quality replies on r/networking .

  • Good bye to an old friend :(
  • Ah, maybe it was just slow to load and I rushed to delete it. Either way, I'm glad I did....

    Good idea on the throwaway. It's time to rip off the band-aid.

  • Boost for Lemmy is happening!
  • Wow.. I just uninstalled Boost after midnight. Looks like it will be back soon :)

  • VyOS 1.3.3 LTS released

    blog.vyos.io VyOS 1.3.3 LTS release

    Available now, with a new event handler, full container support, and more. Big thanks to all involved! #vyos #project #lts #release

    VyOS 1.3.3 LTS release

    Great project for anyone who likes what the Vyatta project was doing, or anyone who wants a more operator focused distribution of FRR.

    0

    NANOG88 Last week. Notable talks

    I went to NANOG88 last week. It was a great time, and I haven't been since 76 in DC.

    They just posted the talks yesterday. Allow me to share some of my favourites I attended:

    AWS deep dive ( architecture hints & hardware used in AWS):

    Design Driven Network Assurance (Person at MLB discusses his approach to Network testing automation.... he has previous talks on how the code works).

    Deploying a backbone in APAC (A little fluff but F5 shares the troubles with submarine fiber in the APAC region).

    New encrypted protocol stack (Mainly about QUIC pattern/flow detection & behaviour)

    Keynote from Len (of Cisco) was nice. A lot better vibes than Cisco Live apparently had the week before.

    Those are just the ones that stood out. There are some other interesting ones that I attended or wanted to attend but was busy doing the hallway track. I will start drafting my blog post on the content, once I've reviewed my notes & the slides.

    4