tofubl

joined 2 years ago
[–] tofubl@discuss.tchncs.de 1 points 2 years ago (2 children)

And here's what this request looks like in the firewall log:

[–] tofubl@discuss.tchncs.de 1 points 2 years ago (4 children)

Can you please elaborate? Who's restricting 192.168.0.x? It's not actually WAN, right? It's just a local network I connected the firewall to.

[–] tofubl@discuss.tchncs.de 1 points 2 years ago* (last edited 2 years ago) (3 children)

Like this?

~$ curl 192.168.0.136:8888
curl: (56) Recv failure: Connection reset by peer
[–] tofubl@discuss.tchncs.de 1 points 2 years ago (6 children)

Here's some more: From behind the firewall (i.e. from a 10.0.0.x IP) the port forward works (which would be a reflection, I suppose?).

From in front of the firewall, I get "connection reset", which I interpret as somewhat working but then breaking somewhere else. Does that make sense?

1000014421

[–] tofubl@discuss.tchncs.de 2 points 2 years ago* (last edited 2 years ago) (1 children)

i times i is -1, though. Imagine that!

[–] tofubl@discuss.tchncs.de 2 points 2 years ago* (last edited 2 years ago)

My post title was going to be "firewall noob vs. double NAT", but I'm too much of a noob to tell if that's where the problem is. 😅

Edit: plus, is it actually a double NAT if I try to port forward into 10.0.0.x from 192.168.0.x? I'm only crossing one NAT, no?

[–] tofubl@discuss.tchncs.de 2 points 2 years ago (9 children)

1000014418 1000014416 1000014417

The docker01 alias is a host alias with 10.0.0.22 and there's an apache test container running on port 8888.

I have created a pass any in rule on WAN (just until I figure out what's wrong)

In firewall > settings > advanced, I have set "reflection for port forwards" and "automatic outbound Nat for reflection" although I'm not sure if that is needed.

Is there any other info I can provide?

[–] tofubl@discuss.tchncs.de 4 points 2 years ago (6 children)

I am trying to learn in a safe environment without breaking my existing network. It's not actually a WAN, except from the firewall's point of view.

[–] tofubl@discuss.tchncs.de 10 points 2 years ago

Love it. Thanks for bringing it up.

[–] tofubl@discuss.tchncs.de 1 points 2 years ago

You mean like the AIO image, the one officially supported way to install Nextcloud?

But if you want to tune it, I'm afraid you'll have to run sudo tune once per waking hour.

[–] tofubl@discuss.tchncs.de 1 points 2 years ago

This sounds interesting.

I use docker in vscode for latex. It saves me the trouble of having to install texlive on my system. I have a task defined that mounts my sources in and runs the compilation in the container.

Would love to hear about your work flow.

[–] tofubl@discuss.tchncs.de 3 points 2 years ago

Very anecdotally, I saw a little speed improvement but not all that much. DB size increased a bit. I'll be sticking with it for the time being because why not.

view more: ‹ prev next ›