9 ms·
Wireless-to-Ethernet island for RPi cluster: IPv6, NDP proxy, mDNS reflector
- sneak 5y agoThis seems like a lot of work to avoid having to run a long cable.
- zrail 5y ago> This seems like a lot of work I see this is your first introduction to the homelab hobby. Welcome!
- sneak 5y agoI have 200TB in my garage.
- rektide 5y agotoo sharp a point apologies, but, some homelabs acquire gear, some acquire skill. i don't see your claim about how much storage you have as any sort of technical claim, any proof of anything. i think it's expected that the homelab folk have an interest in going deep, in some areas. if networking isn't your bag, isn't interesting to you, fine. but the size of your storage cluster or how many vm's your running isn't really an interesting counter-claim.
- mbreese 5y agoTo be fair, physically moving a small cluster of RPis around is a bit easier than moving 200TB. So a wireless linkup isn't that strange of a setup.
- MayeulC 5y agoWell, to be pedantic, physically moving 200 TB around shouldn't be really hard, if it's on 10 TB drives...
- astrange 5y agoI tried to figure out what a homelab was once, but it seemed to just be people who enjoyed having a lot of fan noise at home so they could assemble VLANs for no particular reason.
- zrail 5y agoHomelab is a wide hobby. Some people assemble their lab to learn how things work as a way to skill up for work. Some people assemble a small lab (sometimes just a single box with a bunch of VMs) to run home automation or media applications. Other people just enjoy the blinkenlights.
- pickle-wizard 5y agoIf you follow the homelab sub reddit, a lot of people like to run old obsolete datacenter gear. You don't have to do that. Mine is a pair of Ryzen 2 white boxes. They are dead silent and don't put out much heat either. All my network gear is fanless too. I do automation, so I use mine for dev/test against the stuff I am automating. A lot of it could run in the cloud, but that gets expensive real quick. Especially when I am working with a VMware stack.
- astrange 5y agoI have the same thing with a NAS in a reasonable quiet PC box, but when I filed some FreeNAS bugs some guy actually yelled at me for not having a 1U server next to my TV for better airflow…
- whalesalad 5y agoNot to mention a lot more latency.
- rektide 5y agowifi hop should be under 8ms. untethering sounds like a great & sophisticated way to skill up. also within this island latencies will remain low.
- Havoc 5y agoNot an option for renting / where the cable would be in the way
- ok123456 5y agojust tape it to the molding.
- coolspot 5y agoHaving similar issue myself, I have found simpler and cheaper alternative - $20 Gl.inet mini router [1] that runs OpenWRT, but also has frienly UI where you can turn STA mode, connect it to your wireless network and have wired internet on the ethernet port. I use it for wireless Wake-on-Lan for my homelab PC, integrated with homeassistant and Google Assistant voice command “Hey Google, turn on homelab”. [1] - perhaps due to chip shortage, it is closer to $30 now - https://www.amazon.com/dp/B073TSK26W https://www.amazon.com/dp/B073TSK26W
- jasonjayr 5y agoThose little devices are in high demand. I've been buying them in quantities of 10-at-a-time (Especially when they were cheaper) since they are useful for putting VOIP phones securley behind VPN. I've seen a lot of folks recommend them on HN. They support OpenVPN + Wireguard out of the box and are easy enough for non-techs to reconfigure in the field w/ remote instructions.
- nathancahill 5y agoI deployed a remote/home office printer sharing setup with these little guys for my friend's company. The VPN integration is fantastic, at least for low bandwidth uses like that.
- rektide 5y agoBetcha it wouldn't be too hard to use an rpi to do these tasks. ;) Hence why I love seeing posts like the one's submitted: lessons learned, that we can all possibly use to upgrade ourselves. It would be nice for mainstream linux (not just openwrt) to grow more user-friendly tooling. I look at opnsense in envy, but I'm not really interest in splitting my expertise, taking on learning FreeBSD too. I know I wouldn't really have to touch the OS much, that opnsense is a pretty complete UI package, but I like to keep a fuller-stack view of things, have some up & down mastery.
- TechBro8615 5y agoMake sure you flash them / check their traffic. They make some telemetry requests IIRC.
- Havoc 5y agoEnded up doing something similar except went for wifi 6 routers at both ends so that it could carry gigabit
- londons_explore 5y agoAnd this is all because WiFi doesn't act like a proper layer 2... It isn't possible to have a network which is ethernet -> wifi -> ethernet and have the whole thing one broadcast domain.
- aurelian15 5y agoWell, as at least one other commenter in this thread already pointed out, this is possible with WDS (Wireless Distribution System). However, this needs to be supported by the access points. If it is supported (for example on APs running OpenWRT), it is literally just a matter of enabling WDS on the station and client APs, and bridging the wireless interfaces to the ethernet interfaces. I've been using this setup in my home network for years now (with a dedicated OpenWRT device for each wired "island") and it works great. Edit: To clarify, yes, this establishes a single broadcast domain. For example, DHCP and ARP requests are propagated through the entire network.
- zamadatix 5y agoNot true at all, you could bridge the wifi interface to the ethernet interface and call it a day with a single broadcast domain
- amaccuish 5y agoOut of interest, why didn't you just bridge the two interfaces? Did you want everything on a separate subnet? (maybe I missed that but but you mentioned before how everything used to be directly plugged in anyway)
- eqvinox 5y agoYou can't bridge regular 802.11 wireless into ethernet at the client side. The on-air addressing requires the client MAC address to be the same as the ethernet packet's sender. 802.11 has the concept of "transmitter address" and "receiver address" in addition to source and destination. Those are MAC addresses too, but they're relevant for the on-air radio management. Things like RTS, CTS, ACKs, and fancier things like beamforming and sounding. The problem is that the design only includes 3 address fields in on-air frames; the AP can specify separate SA and TA (i.e. send a packet for somebody else, SA=real source, TA=AP MAC, RA=DA=client.) There is no mechanism for the client to do the same thing; that would require 4 address fields. Coincidentally, 4 address fields is exactly what you get with "WDS" / "Wireless Extender" / ... modes. However, these need to be supported, enabled and configured on both the AP and client. The author of the post seems to have no access to the AP to do so (and the AP possibly doesn't support it anyway.)
- amaccuish 5y agoHow did my AirPort Express or do my Sonos do it? Just rewrite the MAC Address? (is that then not technically bridging from terminology pov?)
- eqvinox 5y agoYes, one of the worst hacks in all of home networking is exactly this... rewriting the MAC address. aka "MAC NAT." Alternatively, proxy ARP + proxy ND can also work. The Apple stuff may be able to autonegotiate over some proprietary handshake if it's an Apple AP and Apple Extender. There is also a new standard that covers 4-address frames, 802.11ak; I have no idea how widely that is adopted though — it was only released in 2018[1]. [1] https://standards.ieee.org/news/2018/ieee_802_11ak-2018.html https://standards.ieee.org/news/2018/ieee_802_11ak-2018.html
- eqvinox 5y agoThe post isn't mentioning DHCPv6-PD[*] (prefix delegation.) I feel like murphy's law is kicking into effect right now and the ISP-provided router actually supports PD to give downstream routers their own /64. (Or maybe not. Who knows. I feel like the post would've mentioned PD if they tried it.) Also: I divided it into a smaller subnet 2001:db8:abc:123:40::/76 Anything on a broadcast/multinode segment that isn't /64 is heresy ;) --- [*]: https://en.wikipedia.org/wiki/Prefix_delegation https://en.wikipedia.org/wiki/Prefix_delegation [*]: https://tools.ietf.org/html/rfc3633 https://tools.ietf.org/html/rfc3633 [*]: https://github.com/openwrt/odhcp6c https://github.com/openwrt/odhcp6c (-P option)
- amaccuish 5y agoUpvoting as good idea, but most routers I know, evening running custom firmware, don't support delegating a wan prefix on request from lan side.
- eqvinox 5y agoReally depends on the ISP; it's actually on the certification mandatory feature list for some network operators. (Comcast, AFAIK.) But yeah, no way to tell if the particular device and setup the author has supports it. (But it should be a very early thing to try, if it's available everything else becomes much easier.)
- deleted 5y ago[deleted]
- varankinv 5y ago> But it should be a very early thing to try, if it's available everything else becomes much easier I've tried to set up PD but it didn't work, so I've moved on with other options. Now, after you mentioned that, this feels like a good excuse to delve into what exactly didn't work back then.
- Arnavion 5y agoI don't know about *WRT and Tomato, but OPNsense / pfSense and OpenBSD definitely support PD.
- daniellarusso 5y agoHow do you relay mDNS over IPv4? The article mentioned an ARP relay. Any recommendations?
- eqvinox 5y agoavahi (the standard Linux mDNS implementation) has settings to set up proxying between multiple segments. It's not ARP relay, it's proxy ARP. That's a builtin feature on the Linux kernel, with 2 distinct modes to configure and enable it. (a) /proc/sys/net/.../proxy_arp, or (b) ip neigh add proxy ...; the latter way is more fine grained while the former is just an interface-wide switch that you flick on.
- jlgaddis 5y ago> The router is set with ... a global unicast IPv6 address (GUA) prefix 2001:db8:abc:123::/64, which the ISP designates to us (of course, that’s not the real prefix, but I will use this one in all examples below). On a side note, I have more trust in documentation that is compliant with the relevant RFCs (i.e., RFC1918, RFC3849, RFC5737, et al). In my experience, such documentation is much more likely to be "technically correct" and get the small details right.
- znpy 5y ago> Right from the beginning, it’s worth to mention, that the router (Sagemcom F@st) is super limited in what it allows configuring. [...] Similarly, I can’t set up any custom routing or configure which DNS servers the router’s built-in DHCP provides for the home networks — the configuration is locked by the vendor I had the same problems with my modem/router, a Fastgate by Fastweb (in .it) No custom static routes, dns fixed by the provider, no vpn functionalities. Some arbitrary tcp ports can't be forwarded via NAT. TR-069 was up and running, at least in ~2017, and at the same year at CCC in Hamburg (or Leipzig?) there was a nice talk about how good of an attack vector TR-069 is. All this is quite infuriating, specifically the DNS thing. I ended up replacing the whole thing with custom equipment (ONT + a Linksys WRT3200ACM running OpenWrt). But I honestly think that stuff like this should be illegal.
- BXWPU 5y agoWhat if your IPv6 prefix changes? As far as i know prefixes from Vodafone cable in Germany are semi static so it could change in a few months.
- varankinv 5y agoAs far as I can tell, I have the same IPv6 prefix for at least a year. Of course, if the prefix's changed, I'll have to reconfigure the homelab. If that started to become annoying I would automate that with an ansible task. But will probably need to search for a better and more stable solution.
- ac50hz 5y agoPowerline is your friend when you can’t lay new cables.