Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
cowboy beepboop
Feb 24, 2001

Kazinsal posted:

existing network appliances piss me off so much I'm writing a routing/firewall OS

currently working on L3/L4 filtering, then after that, a higher performance forwarding table. current one is fast enough with just a handful of routes in it but I suspect with thousands of routes it'd be a bit too sluggish so I'll need to implement something like a 256-way trie

can you do something fancy with eBPF

Adbot
ADBOT LOVES YOU

12 rats tied together
Sep 7, 2006

my homie dhall posted:

what do people think about cumulus?

it's very good and you should use it if you can

post hole digger
Mar 21, 2011

yea we like it. works great with the "use ansible for all of your configs" model from a few posts ago.

Kazinsal
Dec 13, 2011
cumulus is neat but they should open source their switch ASIC drivers. insanely fuckin dumb that you can buy "white box" switches that only work with two OSes (cumulus and Dell FTOS)

open network install environment: a busybox ramdisk in an EFI system partition so you can have the freedom to choose which closed source network OS you wish to use

tortilla_chip
Jun 13, 2007

k-partite
They're beholden to the same Broadcom/Mellanox SDKs as everyone else.

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

Kazinsal posted:

existing network appliances piss me off so much I'm writing a routing/firewall OS

currently working on L3/L4 filtering, then after that, a higher performance forwarding table. current one is fast enough with just a handful of routes in it but I suspect with thousands of routes it'd be a bit too sluggish so I'll need to implement something like a 256-way trie

lol

Forums Medic
Oct 2, 2010

i be out there in orbit

my stepdads beer posted:

can you do something fancy with eBPF

if he was gonna use ebpf he wouldnt have to write the os

Forums Medic
Oct 2, 2010

i be out there in orbit
oh nvm i was thinking xdp i guess

my homie dhall
Dec 9, 2010

honey, oh please, it's just a machine
I dunno if any of youse have had to deal with it yet, but I found out this weekend iptables feels positively ergonomic compared to its successor. nftables has an interface that could only have been developed on extreme linux brain

cowboy beepboop
Feb 24, 2001

agreed. I'm using the iptables wrapper for it atm

abigserve
Sep 13, 2009

this is a better avatar than what I had before
Last time I looked at openconfig/ansible for networking it supported like

Maybe 10% of one of my edge switch Configs

And I really wanted it to work as well

cowboy beepboop
Feb 24, 2001

what manufacturers?

Bored Online
May 25, 2009

We don't need Rome telling us what to do.
☁️

abigserve
Sep 13, 2009

this is a better avatar than what I had before

my stepdads beer posted:

what manufacturers?

100% cisco shop

ate shit on live tv
Feb 15, 2004

by Azathoth

abigserve posted:

100% cisco shop

True story at my last place of work we had a separate IT department to handle user facing problems, wireless, running new desk-ports all that stuff, and he dotted line to the CTO who was in charge of prod networking and other stuff. Our closet infrastructure was Juniper (which I really don't like for switching infra, but i digress) . When we opened a new floor, IT dude who was hired because of nepotism of our previous HR director, didn't even do a bidding process and just bought all Cisco. The cisco sales team doing their thing loaded the BoM up with Cisco Prime, an ASA, 2x 4100 ISR's all for a loving wiring closet. Anyway he got fired.

Asymmetric POSTer
Aug 17, 2005

ate poo poo on live tv posted:

True story at my last place of work we had a separate IT department to handle user facing problems, wireless, running new desk-ports all that stuff, and he dotted line to the CTO who was in charge of prod networking and other stuff. Our closet infrastructure was Juniper (which I really don't like for switching infra, but i digress) . When we opened a new floor, IT dude who was hired because of nepotism of our previous HR director, didn't even do a bidding process and just bought all Cisco. The cisco sales team doing their thing loaded the BoM up with Cisco Prime, an ASA, 2x 4100 ISR's all for a loving wiring closet. Anyway he got fired.

lol

Qtotonibudinibudet
Nov 7, 2011



Omich poluyobok, skazhi ty narkoman? ya prosto tozhe gde to tam zhivu, mogli by vmeste uyobyvat' narkotiki
fun sunday afternoon bullshit: attempting to figure out why the gently caress some site almost always errors out in firefox

apparently firefox's QUIC validation will panic and give up if you include a host header in the server response

naturally any error you can find for this is obtuse as hell, and you just get a bunch of generic protocol error/closing stream messages if you look in the firefox about :networking log or decrypted wireshark QUIC dissectors (which at this point can't even show you the contents of the HTTP stream inside the QUIC payload)

tooling for debugging protocol errors and implementations for new stuff is reliably dogshit :|

while the tools are all crap atm though, you can just tweet people working on QUIC stacks and they'll be like "oh yeah, that's a thing" so who needs computers to actually tell you why they're broken

https://twitter.com/SimmerVigor/status/1409265636262518784

Qtotonibudinibudet fucked around with this message at 00:37 on Jun 28, 2021

abigserve
Sep 13, 2009

this is a better avatar than what I had before

ate poo poo on live tv posted:

True story at my last place of work we had a separate IT department to handle user facing problems, wireless, running new desk-ports all that stuff, and he dotted line to the CTO who was in charge of prod networking and other stuff. Our closet infrastructure was Juniper (which I really don't like for switching infra, but i digress) . When we opened a new floor, IT dude who was hired because of nepotism of our previous HR director, didn't even do a bidding process and just bought all Cisco. The cisco sales team doing their thing loaded the BoM up with Cisco Prime, an ASA, 2x 4100 ISR's all for a loving wiring closet. Anyway he got fired.

Many years ago a place once did a similar thing but they bought McAfee (RIP) IPS's and they loaded the same BoM up with their siem, their sandboxing, and about 3 other things I don't know what the gently caress they did

yadda yadda yadda they were all in boxes for multiple years and everyone involved got asked to leave. We eventually shipped them all - still in the original boxes w/ tape - to the IT recyclers

edit; re-reading this it implies that maybe that's like 5 boxes total but no. it was at least 15 boxes all up

Jonny 290
May 5, 2005



[ASK] me about OS/2 Warp

lmao

cowboy beepboop
Feb 24, 2001

abigserve posted:

Many years ago a place once did a similar thing but they bought McAfee (RIP) IPS's and they loaded the same BoM up with their siem, their sandboxing, and about 3 other things I don't know what the gently caress they did

yadda yadda yadda they were all in boxes for multiple years and everyone involved got asked to leave. We eventually shipped them all - still in the original boxes w/ tape - to the IT recyclers

edit; re-reading this it implies that maybe that's like 5 boxes total but no. it was at least 15 boxes all up

my company ran exclusively on 'gray market' hardware for years (way predating me) thanks to purchasing decisions like this 🙏

Schadenboner
Aug 15, 2011

by Shine
Wait, did McAfee actually die? I thought it was just a meme or some poo poo.

ate shit on live tv
Feb 15, 2004

by Azathoth

my stepdads beer posted:

my company ran exclusively on 'gray market' hardware for years (way predating me) thanks to purchasing decisions like this 🙏

I think Gray Market is actually fine for saving money assuming that you have cold-spares for weird hardware/software bugs and also don't care a low MttR.

I could come up with a pretty resilient network/server/hypervisor stack that would function just fine on gray-market hardware. Though if I were doing that I'd also probably just use some white-box with cumulous installed instead.

Schadenboner posted:

Wait, did McAfee actually die? I thought it was just a meme or some poo poo.

He is dead. :rip:
https://www.cnn.com/2021/06/23/tech/john-mcafee-death/index.html

Schadenboner
Aug 15, 2011

by Shine

:owned:

cowboy beepboop
Feb 24, 2001

https://www.fastly.com/blog/debunking-cloudflares-recent-performance-tests

lol

my homie dhall
Dec 9, 2010

honey, oh please, it's just a machine

this is just like ford vs ferrari

Bored Online
May 25, 2009

We don't need Rome telling us what to do.
cloud

Bored Online
May 25, 2009

We don't need Rome telling us what to do.
butts

Progressive JPEG
Feb 19, 2003


quote:

A fairer test on this point would have compared Rust on Compute@Edge with JavaScript on Cloudflare Workers, which are at more comparable stages of the product lifecycle.

err why not just do rust on both

i guess the reason as they point out is that cloudflare bans running benchmarks in their own tos lol

Asymmetric POSTer
Aug 17, 2005

Progressive JPEG posted:

i guess the reason as they point out is that cloudflare bans running benchmarks in their own tos lol

lol

fresh_cheese
Jul 2, 2014

MY KPI IS HOW MANY VP NUTS I SUCK IN A FISCAL YEAR AND MY LAST THREE OFFICE CHAIRS COMMITTED SUICIDE
anyone have good pihole block lists they’d recommend?

besides 0.0.0.0/0 and .* ?

Mr. Crow
May 22, 2008

Snap City mayor for life

fresh_cheese posted:

anyone have good pihole block lists they’d recommend?

besides 0.0.0.0/0 and .* ?

I use 0.0.0.0/1 and 128.0.0.0/1 works pretty well

Jonny 290
May 5, 2005



[ASK] me about OS/2 Warp

fresh_cheese posted:

anyone have good pihole block lists they’d recommend?

besides 0.0.0.0/0 and .* ?

https://raw.githubusercontent.com/StevenBlack/hosts/master/hosts
https://dbl.oisd.nl/
https://phishing.army/download/phishing_army_blocklist_extended.txt
https://raw.githubusercontent.com/deathbybandaid/piholeparser/master/Subscribable-Lists/ParsedBlacklists/AakList.txt
https://raw.githubusercontent.com/deathbybandaid/piholeparser/master/Subscribable-Lists/ParsedBlacklists/Prebake-Obtrusive.txt

bout 1.1m domains

fresh_cheese
Jul 2, 2014

MY KPI IS HOW MANY VP NUTS I SUCK IN A FISCAL YEAR AND MY LAST THREE OFFICE CHAIRS COMMITTED SUICIDE

Mr. Crow posted:

I use 0.0.0.0/1 and 128.0.0.0/1 works pretty well

that would solve a lot of my problems, frankly

FamDav
Mar 29, 2008

Progressive JPEG posted:

i guess the reason as they point out is that cloudflare bans running benchmarks in their own tos lol

dont trust any company that won't let you publish benchmark results lol how hard is this.

FamDav
Mar 29, 2008
cloudflare is the definition of "when a company is telling you who they are, listen"

fresh_cheese
Jul 2, 2014

MY KPI IS HOW MANY VP NUTS I SUCK IN A FISCAL YEAR AND MY LAST THREE OFFICE CHAIRS COMMITTED SUICIDE

thanks Jonny

kitten emergency
Jan 13, 2008

get meow this wack-ass crystal prison
so what’s a good prosumer/home network thing that isn’t unifi, or should I just get unifi stuff, idk. I’m sick of lovely ASUS consumer stuff

Jonny 290
May 5, 2005



[ASK] me about OS/2 Warp
get teh edgerouter and unifi ap yeah

devmd01
Mar 7, 2006

Elektronik
Supersonik
concur with Jonny, a solid combo. I don’t have Wi-Fi problems with an AP every floor plus in the garage.

plus everything that can be plugged in has cat6 going to it, so the Wi-Fi only has tablets + phones to deal with, occasionally my work laptop.

devmd01 fucked around with this message at 16:39 on Dec 10, 2021

Adbot
ADBOT LOVES YOU

freeasinbeer
Mar 26, 2015

by Fluffdaddy
I like my raspberry pi cm4 build with openwrt; mainly because it lets me do more stuff, and is arm64 so I can run real stuff on my router. I get way faster wireguard speeds on it for example.

otherwise yeah I use UniFi APs; although I’ve heard good thinks about ruckus gear.

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply