The Header Your Reverse Proxy Keeps Dropping
Your backend logs every client as 127.0.0.1 because the proxy dropped the header. Set X-Forwarded-For, X-Real-IP, and X-Forwarded-Proto right in Nginx.
All the articles with the tag "networking".
Your backend logs every client as 127.0.0.1 because the proxy dropped the header. Set X-Forwarded-For, X-Real-IP, and X-Forwarded-Proto right in Nginx.
IPv6 isn't just for the future, it's broken on your network right now. Here's why you should care and how to actually set it up.
Your DNS queries go out in plain text, so your ISP logs every site you visit. This covers how DoH, DoT, and DoQ fix that, and how to self-host with AdGuard Home.
You don't need a GUI to see network packets. Learn tcpdump filters, flags, and pcap capture to debug servers from the command line, no Wireshark needed.
Self-hosted email with Mailcow or Stalwart means daily SPF, DKIM, DMARC, and IP blacklist battles. Here's the honest case against running your own mail server.
Idle SSH sessions and long-lived connections die because the OS gives up first. What the three keepalive sysctls mean, how to tune them, and per-socket options.
Advanced Caddy server configuration: wildcard certs, Caddyfile matchers, Docker label integration, rate limiting, forward auth with Authelia, and the JSON API.
MTU mismatches silently break large file transfers, backups, and video calls. Here's how to find and fix the wrong frame size on your network.
Set up a WireGuard VPN kill switch and prevent DNS leaks on Linux. Practical iptables rules, resolv.conf locking, and systemd-resolved config.
Run BGP in your home lab with FRRouting. Covers iBGP vs eBGP, FRR installation, basic BGP config, peering with OPNsense, route filtering, and when BGP is actually worth the complexity.
Suricata beats Snort on multi-threading and EVE JSON logging. Side-by-side IDS/IPS breakdown with Suricata install, suricata.yaml config, and OPNsense setup for home labs.
DNS broke again. The command sequence that finds it: verify the resolver, reach a server, dig the record, trace the query path, check reverse lookups.