Topic
Networking
Everything between your laptop and the box you wish you'd remembered to label. WireGuard, Tailscale, Headscale, Cloudflare Tunnels, split-horizon DNS, IPv6 that isn't just a TODO, and the firewall rules you'll wish past-you had written down. If you've ever solved a problem by reaching for ping and then a packet capture, this is the section.
108 articles in this topic.
Featured posts
-
Bots Ate 90% of My Worker Quota
A WordPress login bot burned 90% of my Cloudflare Workers free tier in two hours attacking a site that has never run PHP. Here's what actually stopped it.
13 min read -
NFS vs SMB vs SSHFS vs WebDAV for Home Lab
Four file-sharing protocols compared for home labs: NFS speed, SMB compatibility, SSHFS convenience, WebDAV over HTTP, and which one to pick per use case.
· Updated:12 min read -
SSH Bastion & Jump Host Patterns That Don't Hurt
Stop opening port 22 to the world. SSH bastion hosts, ProxyJump chains, session recording, and self-hosted Teleport alternatives that actually work.
9 min read -
Ditch Your ISP Router for MikroTik
Your ISP's box doesn't have to run your network. How to find bridge mode, dodge double NAT, and hand real routing duty over to a MikroTik router instead.
13 min read -
SOCKS5 Over SSH: Selective Routing Without a VPN
Route only the traffic you want through a SOCKS5 proxy via ssh -D. Browser extensions, curl, git, ProxyChains, autossh, and DNS leak gotchas, no VPN needed.
8 min read -
Mullvad VPN Containers via Gluetun: Per-App VPN
Route specific Docker containers through Mullvad VPN via Gluetun, keeping Plex and everything else on your home WAN. No iptables nightmares, no tunneling drama.
11 min read
All Networking articles
- Bots Ate 90% of My Worker Quota
- NFS vs SMB vs SSHFS vs WebDAV for Home Lab
- SSH Bastion & Jump Host Patterns That Don't Hurt
- Ditch Your ISP Router for MikroTik
- SOCKS5 Over SSH: Selective Routing Without a VPN
- Mullvad VPN Containers via Gluetun: Per-App VPN
- Collateral Freedom: Costly to Block
- Meshtastic vs Reticulum
- AdGuard DNS Sync Across Two Instances
- wg-easy: WireGuard for Humans Who Hate Config Files
- REALITY: Borrowing a TLS Handshake
- LoRa Mesh Hardware Buying Guide
- nftables in 2026: Stop Pretending iptables Will Live Forever
- Why Your VPN Is Already Detected
- LoRa Mesh vs LoRaWAN vs Helium
- Meshtastic vs MeshCore in 2026
- DNS-over-HTTPS at Home: cloudflared vs dnscrypt-proxy
- Pangolin: Self-Hosted Cloudflare Tunnel Alternative
- systemd-resolved: The DNS Resolver You're Already Using Wrong
- k3s + Tailscale: Cluster Across Two Sites
- Mesh VPN Showdown: Tailscale, Nebula, ZeroTier, NetBird
- Syncthing Through Untrusted VPS Relays
- Assume Your App Gets Popped
- Gateway API vs Ingress in 2026
- Rootless Docker: Tips, Gotchas & Fixes
- Network Booting Diskless Nodes with iPXE
- Mikrotik RouterOS for Home Lab
- pfSense vs OPNsense in 2026
- Zeek for Home Lab Forensics
- mtr vs traceroute: Packet Loss
- iperf3 + nload: Network Diagnosis
- OpenConnect vs AnyConnect
- stunnel vs spiped
- Unbound vs Technitium vs BIND
- ntopng vs darkstat
- FRR vs BIRD
- HAProxy vs Envoy
- LibreNMS for SNMP-Heavy Home Networks
- SmokePing for Internet Connection Sanity
- ZFS Send/Receive Over WireGuard for Off-Site Replication
- Headscale: Self-Host Your Own Tailscale Control Plane
- OpenCanary: Honeypots for Your Home Lab
- Pi-hole vs AdGuard Home: Block Ads for Your Whole Network
- nftables: Modern Linux Firewalling
- Suricata vs Snort: Network Intrusion Detection That Actually Works
- Sysctl Tuning: The Linux Kernel Settings Nobody Told You About
- Authentik vs Authelia: SSO for Your Self-Hosted Stack
- Cloudflare Tunnels: Beyond Port Forwarding
- Fail2ban vs CrowdSec: Blocking the Bots Actually Smartly
- WireGuard vs OpenVPN 2026: It's Not Even Close
- Docker Networking Demystified
- Proxmox NAT Bridge: One IP, Many VMs
- TLS 1.3: Modern Encryption Without the Existential Dread
- IPFS: Peer-to-Peer File Storage for People Who've Seen Too Many 404s
- The Zero-Trust Home Lab
- HAProxy: Load Balancing Done Right
- Cloudflare WAF: Free Tier Firewall Rules
- Cloudflare DNS: Beyond Pointing Records
- Traefik: Docker Routing with Labels
- Nginx Proxy Manager for Normal Humans
- VLAN Basics for Home Labs: Segment Your Network Before It Segments You
- Port Knocking: Simple Obscurity for SSH Access
- The Reverse Proxy Timeout That Kills Long Uploads
- Time Is a Lie and Chrony Is Here to Fix It: NTP for Home Labs
- Why Your VPN Isn't Routing What You Think
- The Header Your Reverse Proxy Keeps Dropping
- IPv6 on Your Home Lab: You Should Care (Here's Why)
- DNS Over HTTPS and TLS: Encrypt Your DNS Before Your ISP Sells It
- tcpdump Basics: Capture Traffic Without Wireshark
- Self-Hosted Email Is Probably a Bad Idea
- TCP Keepalives: Why Connections Die and How to Fix It
- Caddy Advanced: Automatic HTTPS, Plugins, and Config That Doesn't Make You Cry
- The MTU Problem Nobody Diagnoses Correctly
- VPN Kill Switch and DNS Leak Prevention: Paranoia, Justified
- BGP in Your Home Lab: Dynamic Routing for People Who've Run Out of Static Routes
- Suricata vs Snort: Intrusion Detection for the Paranoid Home Lab Owner
- DNS Troubleshooting from the Command Line
- Tailscale Deep Dive: Mesh VPN That Just Works (and Why That's Suspicious)
- nmap for Your Own Network: What You Should Be Scanning
- curl Flags Every Developer Should Know
- UFW Advanced: Rate Limiting, Logging, and Rules That Actually Make Sense
- DDoS Mitigation: Teaching Your Server to Say No Politely (Then Impolitely)
- WireGuard Is Fast, But You're Leaving Performance on the Table
- Traefik vs Nginx Proxy Manager: Reverse Proxies for Humans
- Proxy Chains and Anonymization: What Actually Works and What's Just Theater
- Why Your TLS Certificate Isn't Trusted
- The Firewall Rule Order That's Breaking Your Setup
- Is fail2ban Actually Working? Here's How to Check
- SSHFS: Ditch SCP & Access Remote Files
- Why Your SSH Connection Keeps Dropping
- ss Is the New netstat (And It's Better)
- Docker Network Aliases: The Feature Nobody Uses
- lsof: The Tool That Shows You Everything
- Finding the PID of a Process Using a Specific Port in Linux
- The Role of Antivirus and Endpoint Detection and Response Systems
- Certificate Pinning: A Secure Connection Guide
- Docker Networking Essential Guide for All Skill Levels
- Docker Strategies for Load Balancing and Failover
- Docker Networking: Connecting to the Host from a Container
- WordPress, Docker, NGINX, and MySQL via Ansible
- How to securely deploy Cloudflare Tunnels
- Advanced UFW Techniques: Enhancing Firewall Security
- SSH Tunneling: A Secure Conduit for Your Data
- Socat: The Swiss Army Knife of Networking
- Understanding PostgreSQL Connection URIs
- Linux Home Lab Security: Planning for the Unexpected
- Wireguard VPN Server in Docker
- Access Docker socket via TCP