Topic
Networking
Everything between your laptop and the box you wish you'd remembered to label. WireGuard, Tailscale, Headscale, Cloudflare Tunnels, split-horizon DNS, IPv6 that isn't just a TODO, and the firewall rules you'll wish past-you had written down. If you've ever solved a problem by reaching for ping and then a packet capture, this is the section.
119 articles in this topic.
Featured posts
-
VLAN Trunking Gotchas Nobody Warns You
VLAN configured but traffic still breaks? Native VLAN mismatches, PVID traps on cheap switches, Proxmox bridge gotchas, and Docker macvlan fixes, with commands.
10 min read -
OPNsense Multi-WAN Failover Guide
Configure OPNsense gateway groups for WAN failover and load balancing, then layer policy-based routing so specific hosts or VLANs use a chosen WAN link.
14 min read -
CrowdSec Across a Home Lab: One Brain
One central CrowdSec LAPI, remote log-parsing agents, and bouncers on every box, so an SSH brute-force on one server gets blocked everywhere else too.
12 min read -
NetAlertX MCP: One Token, Twelve Tools
NetAlertX v26.9.0 ships a built-in MCP server with 12 tools. Learn how to wire it into Claude Code, what it exposes, and when to use Home Assistant instead.
13 min read -
IPv6 Dual-Stack: The Hard Parts
Dual-stack IPv6 for home labs: DHCPv6-PD delegation, stable addressing past SLAAC privacy extensions, real nftables firewall rules, and Docker IPv6 done right.
12 min read -
Tinyauth vs Pocket ID vs Authelia
Tinyauth vs Pocket ID vs Authelia compared for home labs: setup cost, forward-auth support, real OIDC, passkeys, 2FA, and when to move up to Authentik.
13 min read
All Networking articles
- VLAN Trunking Gotchas Nobody Warns You
- OPNsense Multi-WAN Failover Guide
- CrowdSec Across a Home Lab: One Brain
- NetAlertX MCP: One Token, Twelve Tools
- IPv6 Dual-Stack: The Hard Parts
- Tinyauth vs Pocket ID vs Authelia
- 2.5GbE / 10GbE on a Budget
- Cheap Managed Switches That Don't Suck
- Bots Ate 90% of My Worker Quota
- NFS vs SMB vs SSHFS vs WebDAV for Home Lab
- SSH Bastion & Jump Host Patterns That Don't Hurt
- Ditch Your ISP Router for MikroTik
- SOCKS5 Over SSH: Selective Routing Without a VPN
- Mullvad VPN Containers via Gluetun: Per-App VPN
- Collateral Freedom: Costly to Block
- Meshtastic vs Reticulum
- AdGuard DNS Sync Across Two Instances
- wg-easy: WireGuard for Humans Who Hate Config Files
- REALITY: Borrowing a TLS Handshake
- LoRa Mesh Hardware Buying Guide
- nftables in 2026: Stop Pretending iptables Will Live Forever
- Why Your VPN Is Already Detected
- LoRa Mesh vs LoRaWAN vs Helium
- Meshtastic vs MeshCore in 2026
- DNS-over-HTTPS at Home: cloudflared vs dnscrypt-proxy
- Pangolin: Self-Hosted Cloudflare Tunnel Alternative
- systemd-resolved: The DNS Resolver You're Already Using Wrong
- Cilium on k3s: When eBPF Networking Pays
- k3s + Tailscale: Cluster Across Two Sites
- Mesh VPN Showdown: Tailscale, Nebula, ZeroTier, NetBird
- Syncthing Through Untrusted VPS Relays
- Assume Your App Gets Popped
- SFP+ Optics and DACs Without Getting Burned
- Gateway API vs Ingress in 2026
- Rootless Docker: Tips, Gotchas & Fixes
- Network Booting Diskless Nodes with iPXE
- Mikrotik RouterOS for Home Lab
- pfSense vs OPNsense in 2026
- Zeek for Home Lab Forensics
- mtr vs traceroute: Packet Loss
- iperf3 + nload: Network Diagnosis
- OpenConnect vs AnyConnect
- stunnel vs spiped
- Unbound vs Technitium vs BIND
- ntopng vs darkstat
- FRR vs BIRD
- HAProxy vs Envoy
- LibreNMS for SNMP-Heavy Home Networks
- SmokePing for Internet Connection Sanity
- ZFS Send/Receive Over WireGuard for Off-Site Replication
- Headscale: Self-Host Your Own Tailscale Control Plane
- Cloud Gaming Tips That Actually Work
- OpenCanary: Honeypots for Your Home Lab
- Pi-hole vs AdGuard Home: Block Ads for Your Whole Network
- nftables: Modern Linux Firewalling
- Suricata vs Snort: Network Intrusion Detection That Actually Works
- Sysctl Tuning: The Linux Kernel Settings Nobody Told You About
- Authentik vs Authelia: SSO for Your Self-Hosted Stack
- Cloudflare Tunnels: Beyond Port Forwarding
- Fail2ban vs CrowdSec: Blocking the Bots Actually Smartly
- WireGuard vs OpenVPN 2026: It's Not Even Close
- Docker Networking Demystified
- Proxmox NAT Bridge: One IP, Many VMs
- TLS 1.3: Modern Encryption Without the Existential Dread
- IPFS: Peer-to-Peer File Storage for People Who've Seen Too Many 404s
- The Zero-Trust Home Lab
- HAProxy: Load Balancing Done Right
- Cloudflare WAF: Free Tier Firewall Rules
- Cloudflare DNS: Beyond Pointing Records
- Traefik: Docker Routing with Labels
- Nginx Proxy Manager for Normal Humans
- VLAN Basics for Home Labs: Segment Your Network Before It Segments You
- Port Knocking: Simple Obscurity for SSH Access
- The Reverse Proxy Timeout That Kills Long Uploads
- Time Is a Lie and Chrony Is Here to Fix It: NTP for Home Labs
- Why Your VPN Isn't Routing What You Think
- The Header Your Reverse Proxy Keeps Dropping
- IPv6 on Your Home Lab: You Should Care (Here's Why)
- DNS Over HTTPS and TLS: Encrypt Your DNS Before Your ISP Sells It
- tcpdump Basics: Capture Traffic Without Wireshark
- Self-Hosted Email Is Probably a Bad Idea
- TCP Keepalives: Why Connections Die and How to Fix It
- Caddy Advanced: Automatic HTTPS, Plugins, and Config That Doesn't Make You Cry
- The MTU Problem Nobody Diagnoses Correctly
- VPN Kill Switch and DNS Leak Prevention: Paranoia, Justified
- BGP in Your Home Lab: Dynamic Routing for People Who've Run Out of Static Routes
- Suricata vs Snort: Intrusion Detection for the Paranoid Home Lab Owner
- DNS Troubleshooting from the Command Line
- Tailscale Deep Dive: Mesh VPN That Just Works (and Why That's Suspicious)
- nmap for Your Own Network: What You Should Be Scanning
- curl Flags Every Developer Should Know
- UFW Advanced: Rate Limiting, Logging, and Rules That Actually Make Sense
- DDoS Mitigation: Teaching Your Server to Say No Politely (Then Impolitely)
- WireGuard Is Fast, But You're Leaving Performance on the Table
- Traefik vs Nginx Proxy Manager: Reverse Proxies for Humans
- Proxy Chains and Anonymization: What Actually Works and What's Just Theater
- Why Your TLS Certificate Isn't Trusted
- The Firewall Rule Order That's Breaking Your Setup
- Is fail2ban Actually Working? Here's How to Check
- SSHFS: Ditch SCP & Access Remote Files
- Why Your SSH Connection Keeps Dropping
- ss Is the New netstat (And It's Better)
- Docker Network Aliases: The Feature Nobody Uses
- lsof: The Tool That Shows You Everything
- Finding the PID of a Process Using a Specific Port in Linux
- The Role of Antivirus and Endpoint Detection and Response Systems
- Certificate Pinning: A Secure Connection Guide
- Docker Networking Essential Guide for All Skill Levels
- Docker Strategies for Load Balancing and Failover
- Docker Networking: Connecting to the Host from a Container
- WordPress, Docker, NGINX, and MySQL via Ansible
- How to securely deploy Cloudflare Tunnels
- Advanced UFW Techniques: Enhancing Firewall Security
- SSH Tunneling: A Secure Conduit for Your Data
- Socat: The Swiss Army Knife of Networking
- Understanding PostgreSQL Connection URIs
- Linux Home Lab Security: Planning for the Unexpected
- Wireguard VPN Server in Docker
- Access Docker socket via TCP