Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

Bloody posted:

I have a unifi dream machine in my house. it's cool and has lots of options I don't understand. also it has an app

I just got one and it’s nice but I’m on the verge of taking it off dhcp and dns duties

Adbot
ADBOT LOVES YOU

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

want to have a vpn to work running on the espressobin, and be able to say everything at *.work.com gets queried through their dns; I can do that with dnsmasq, but not ubiquiti

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

Malcolm XML posted:

should i get one op

if you need a new router and WiFi AP, it’s both of those, can route at 1gbps, and I don’t hate the UI

I decided to not jiggle the dns and dhcp around

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug
i haven’t seen anything about a pro or a scrub adjective on the dream machine

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

Schadenboner posted:

The UDM Pro is similar to the UDM but it's rack-mount, it doesn't have wireless but it's got a 10GbE SFP+, 8 port switch rather than 4, same cloud key and routing poo poo, it also has a 'lil babby touchscreen :3:. It's currently in Early Access: https://ubntwiki.com/products/unifi/unifi_dream_machine_pro

I just figure I'll be most likely to want to upgrade wireless from AC at some point in the next few years so an all-in-one that includes wireless might be a bad route (also I could someday want 10GbE to a NAS or something, IDK)?

lol so it’s $80 more and then you gotta but WiFi separately? seems like the opposite of what I need at home

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

freeasinbeer posted:

k8s let’s me think about compute as pools or slabs of ram and cpu, and let’s me sleep by having a bunch of smart auto recovery stuff built in.

“let’s” is possessive, you want “lets”

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug
Unix processes don’t have a thing where you can get messages about misbehaving children like in erlang, but it’s not normalized in use like in erlang

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

Bloody posted:

what is radius

authentication server for dial-up, wpa enterprise, some other stuff i think

wpa enterprise is nice because stations can authenticate base stations, and also managing credentials on a per-person basis scales better than a single shared key for big installs

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

Phobeste posted:

i dunno why everybody wants everything to be "restful" anyway. it's a message format that fits pretty well with data exploration apis that are expected to have many clients hitting a single dataset but it's also for some reason how you do rpc now and is supposed to be the only thing you do with any kind of http/s interface which is supposed to be the only way anything should communicate over the network including elaborate systems layered on top of it to replace lower level interfaces. even if nothing you're doing needs to be routable

because you can jank together stuff with curl

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

abigserve posted:

Fundamentally there is no way to move to a "rest like" protocol for the functionality that RADIUS provides, because the primary function of RADIUS is to carry EAP messages. EAP messages are layer 2 only and typically are not forwarded past the switchport which means you need another protocol whose only role is a carrier for said messages to the layer 3 endpoint that serves as the AAA server. Because EAP is end-to-end between the client and the authentication server for obvious reasons, there is no plausible way you could lift a framework like OIDC into the role that RADIUS provides.

If you're thinking "why not use something other than EAP", consider that your clients have literally no network access at all prior to authentication. That is the primary use case for EAP/RADIUS.

The end of RADIUS is actually the end of traditional networking, which is the very slow, plodding shift for enterprise to move towards zero-trust networking via massive overlay networks, the standards for which are still not agreed upon let alone implemented.

it's not the network client to radius client thing that people want rest, it's the radius client to radius server part, and i bet you could design it so your authentication/accounting services would work in an edge cloud or something because *faaaart*

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug
is there such a thing as a wpa2 enterprise cert that macos & ios just accept or do i just gotta slum it with a let's encrypt cert that has a subject i control and click ok on every three months

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

Turnquiet posted:

looking at you, microsoft, who literally built azuread on openid flows but still demands ws-trust/ws-fed if you want to retain control of your idp.

weird that Microsoft would combine two unfashionable protocols in a baffling way

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

Nomnom Cookie posted:

how much radius are you doing that a single instance isn't enough, holy poo poo

Comcast has a nationwide wpa2 enterprise network

Adbot
ADBOT LOVES YOU

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

Nomnom Cookie posted:

they need to do more than several thousand requests/sec?

multiple instances aren't just for throughput and radius isn't just for yes/no authentication, so if there's a bunch of like accounting traffic that needs to be sharted that's going to mean you need to fan out those requests to a handful of hosts

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply