Topic
Networking
Everything between your laptop and the box you wish you'd remembered to label. WireGuard, Tailscale, Headscale, Cloudflare Tunnels, split-horizon DNS, IPv6 that isn't just a TODO, and the firewall rules you'll wish past-you had written down. If you've ever solved a problem by reaching for ping and then a packet capture, this is the section.
105 articles in this topic.
Featured posts
-
Collateral Freedom: Costly to Block
Protocol mimicry only wins the hiding fight. Learn why relay cascades, domestic hosting, and disposable infrastructure make blocking your traffic expensive.
13 min read -
Meshtastic vs Reticulum
Meshtastic is a messaging appliance. Reticulum is a whole network stack that happens to run over LoRa. Why comparing the two directly misleads people.
11 min read -
AdGuard DNS Sync Across Two Instances
Run two AdGuard Home instances in sync so one dead node does not kill DNS for your whole house. Here is config sync with VRRP failover, done step by step.
11 min read -
wg-easy: WireGuard for Humans Who Hate Config Files
wg-easy gives WireGuard a web UI: create clients, scan QR codes, see traffic stats, no SSH required. Self-hosted VPN made actually easy.
8 min read -
REALITY: Borrowing a TLS Handshake
REALITY does not disguise your traffic as a real TLS handshake, it serves an actual one. How that works, a working config, and the honest limits of the trick.
13 min read -
LoRa Mesh Hardware Buying Guide
Which LoRa boards to buy for Meshtastic or MeshCore, why the antenna and mounting height matter more than the radio, and what to skip on your first order.
11 min read
All Networking articles
- Collateral Freedom: Costly to Block
- Meshtastic vs Reticulum
- AdGuard DNS Sync Across Two Instances
- wg-easy: WireGuard for Humans Who Hate Config Files
- REALITY: Borrowing a TLS Handshake
- LoRa Mesh Hardware Buying Guide
- nftables in 2026: Stop Pretending iptables Will Live Forever
- Why Your VPN Is Already Detected
- LoRa Mesh vs LoRaWAN vs Helium
- Meshtastic vs MeshCore in 2026
- DNS-over-HTTPS at Home: cloudflared vs dnscrypt-proxy
- Pangolin: Self-Hosted Cloudflare Tunnel Alternative
- systemd-resolved: The DNS Resolver You're Already Using Wrong
- k3s + Tailscale: Cluster Across Two Sites
- Mesh VPN Showdown: Tailscale, Nebula, ZeroTier, NetBird
- Syncthing Through Untrusted VPS Relays
- Assume Your App Gets Popped
- Gateway API vs Ingress in 2026
- Rootless Docker: Tips, Gotchas & Fixes
- Network Booting Diskless Nodes with iPXE
- Mikrotik RouterOS for Home Lab
- pfSense vs OPNsense in 2026
- Zeek for Home Lab Forensics
- mtr vs traceroute: Packet Loss
- iperf3 + nload: Network Diagnosis
- Access Docker socket via TCP
- Advanced UFW Techniques: Enhancing Firewall Security
- Docker Network Aliases: The Feature Nobody Uses
- Docker Networking: Connecting to the Host from a Container
- Docker Strategies for Load Balancing and Failover
- Linux Home Lab Security: Planning for the Unexpected
- OpenConnect vs AnyConnect
- Proxy Chains and Anonymization: What Actually Works and What's Just Theater
- Self-Hosted Email Is Probably a Bad Idea
- Socat: The Swiss Army Knife of Networking
- ss Is the New netstat (And It's Better)
- stunnel vs spiped
- Suricata vs Snort: Intrusion Detection for the Paranoid Home Lab Owner
- The Role of Antivirus and Endpoint Detection and Response Systems
- The Zero-Trust Home Lab
- Understanding PostgreSQL Connection URIs
- WireGuard Is Fast, But You're Leaving Performance on the Table
- Wireguard VPN Server in Docker
- Unbound vs Technitium vs BIND
- ntopng vs darkstat
- FRR vs BIRD
- HAProxy vs Envoy
- LibreNMS for SNMP-Heavy Home Networks
- SmokePing for Internet Connection Sanity
- Authentik vs Authelia: SSO for Your Self-Hosted Stack
- ZFS Send/Receive Over WireGuard for Off-Site Replication
- Headscale: Self-Host Your Own Tailscale Control Plane
- OpenCanary: Honeypots for Your Home Lab
- Pi-hole vs AdGuard Home: Block Ads for Your Whole Network
- nftables: Modern Linux Firewalling
- Suricata vs Snort: Network Intrusion Detection That Actually Works
- Sysctl Tuning: The Linux Kernel Settings Nobody Told You About
- WireGuard Is Fast, But You're Leaving Performance on the Table
- Cloudflare Tunnels: Beyond Port Forwarding
- Fail2ban vs CrowdSec: Blocking the Bots Actually Smartly
- Sysctl Tuning: The Linux Kernel Knobs That Actually Matter
- Tailscale Deep Dive: Mesh Networking That Actually Works
- WireGuard vs OpenVPN 2026: It's Not Even Close
- Docker Networking Demystified
- Proxmox NAT Bridge: One IP, Many VMs
- TLS 1.3: Modern Encryption Without the Existential Dread
- IPFS: Peer-to-Peer File Storage for People Who've Seen Too Many 404s
- HAProxy: Load Balancing Done Right
- Cloudflare WAF: Free Tier Firewall Rules
- Cloudflare DNS: Beyond Pointing Records
- Traefik: Docker Routing with Labels
- Nginx Proxy Manager for Normal Humans
- VLAN Basics for Home Labs: Segment Your Network Before It Segments You
- Port Knocking: Simple Obscurity for SSH Access
- The Reverse Proxy Timeout That Kills Long Uploads
- Time Is a Lie and Chrony Is Here to Fix It: NTP for Home Labs
- Why Your VPN Isn't Routing What You Think
- The Header Your Reverse Proxy Keeps Dropping
- IPv6 on Your Home Lab: You Should Care (Here's Why)
- DNS Over HTTPS and TLS: Encrypt Your DNS Before Your ISP Sells It
- tcpdump Basics: Capture Traffic Without Wireshark
- TCP Keepalives: Why Connections Die and How to Fix It
- Caddy Advanced: Automatic HTTPS, Plugins, and Config That Doesn't Make You Cry
- The MTU Problem Nobody Diagnoses Correctly
- VPN Kill Switch and DNS Leak Prevention: Paranoia, Justified
- BGP in Your Home Lab: Dynamic Routing for People Who've Run Out of Static Routes
- DNS Troubleshooting from the Command Line
- Tailscale Deep Dive: Mesh VPN That Just Works (and Why That's Suspicious)
- nmap for Your Own Network: What You Should Be Scanning
- curl Flags Every Developer Should Know
- UFW Advanced: Rate Limiting, Logging, and Rules That Actually Make Sense
- DDoS Mitigation: Teaching Your Server to Say No Politely (Then Impolitely)
- Traefik vs Nginx Proxy Manager: Reverse Proxies for Humans
- Why Your TLS Certificate Isn't Trusted
- The Firewall Rule Order That's Breaking Your Setup
- Is fail2ban Actually Working? Here's How to Check
- SSHFS: Ditch SCP & Access Remote Files
- Why Your SSH Connection Keeps Dropping
- lsof: The Tool That Shows You Everything
- Finding the PID of a Process Using a Specific Port in Linux
- Certificate Pinning: A Secure Connection Guide
- Docker Networking Essential Guide for All Skill Levels
- WordPress, Docker, NGINX, and MySQL via Ansible
- How to securely deploy Cloudflare Tunnels
- SSH Tunneling: A Secure Conduit for Your Data