Topic
Networking
Everything between your laptop and the box you wish you'd remembered to label. WireGuard, Tailscale, Headscale, Cloudflare Tunnels, split-horizon DNS, IPv6 that isn't just a TODO, and the firewall rules you'll wish past-you had written down. If you've ever solved a problem by reaching for ping and then a packet capture, this is the section.
118 articles in this topic.
Featured posts
-
OPNsense Multi-WAN Failover Guide
Configure OPNsense gateway groups for WAN failover and load balancing, then layer policy-based routing so specific hosts or VLANs use a chosen WAN link.
14 min read -
CrowdSec Across a Home Lab: One Brain
One central CrowdSec LAPI, remote log-parsing agents, and bouncers on every box, so an SSH brute-force on one server gets blocked everywhere else too.
12 min read -
NetAlertX MCP: One Token, Twelve Tools
NetAlertX v26.9.0 ships a built-in MCP server with 12 tools. Learn how to wire it into Claude Code, what it exposes, and when to use Home Assistant instead.
13 min read -
IPv6 Dual-Stack: The Hard Parts
Dual-stack IPv6 for home labs: DHCPv6-PD delegation, stable addressing past SLAAC privacy extensions, real nftables firewall rules, and Docker IPv6 done right.
12 min read -
Tinyauth vs Pocket ID vs Authelia
Tinyauth vs Pocket ID vs Authelia compared for home labs: setup cost, forward-auth support, real OIDC, passkeys, 2FA, and when to move up to Authentik.
13 min read -
2.5GbE / 10GbE on a Budget
Used SFP+ gear turns 10GbE from a $5k fantasy into a $200 build. Mellanox NICs, the MikroTik CRS305 switch, DAC cabling, and where the savings stop.
· Updated:10 min read
All Networking articles
- OPNsense Multi-WAN Failover Guide
- CrowdSec Across a Home Lab: One Brain
- NetAlertX MCP: One Token, Twelve Tools
- IPv6 Dual-Stack: The Hard Parts
- Tinyauth vs Pocket ID vs Authelia
- 2.5GbE / 10GbE on a Budget
- Cheap Managed Switches That Don't Suck
- Bots Ate 90% of My Worker Quota
- NFS vs SMB vs SSHFS vs WebDAV for Home Lab
- SSH Bastion & Jump Host Patterns That Don't Hurt
- Ditch Your ISP Router for MikroTik
- SOCKS5 Over SSH: Selective Routing Without a VPN
- Mullvad VPN Containers via Gluetun: Per-App VPN
- Collateral Freedom: Costly to Block
- Meshtastic vs Reticulum
- AdGuard DNS Sync Across Two Instances
- wg-easy: WireGuard for Humans Who Hate Config Files
- REALITY: Borrowing a TLS Handshake
- LoRa Mesh Hardware Buying Guide
- nftables in 2026: Stop Pretending iptables Will Live Forever
- Why Your VPN Is Already Detected
- LoRa Mesh vs LoRaWAN vs Helium
- Meshtastic vs MeshCore in 2026
- DNS-over-HTTPS at Home: cloudflared vs dnscrypt-proxy
- Pangolin: Self-Hosted Cloudflare Tunnel Alternative
- systemd-resolved: The DNS Resolver You're Already Using Wrong
- Cilium on k3s: When eBPF Networking Pays
- k3s + Tailscale: Cluster Across Two Sites
- Mesh VPN Showdown: Tailscale, Nebula, ZeroTier, NetBird
- Syncthing Through Untrusted VPS Relays
- Assume Your App Gets Popped
- SFP+ Optics and DACs Without Getting Burned
- Gateway API vs Ingress in 2026
- Rootless Docker: Tips, Gotchas & Fixes
- Network Booting Diskless Nodes with iPXE
- Mikrotik RouterOS for Home Lab
- pfSense vs OPNsense in 2026
- Zeek for Home Lab Forensics
- mtr vs traceroute: Packet Loss
- iperf3 + nload: Network Diagnosis
- OpenConnect vs AnyConnect
- stunnel vs spiped
- Unbound vs Technitium vs BIND
- ntopng vs darkstat
- FRR vs BIRD
- HAProxy vs Envoy
- LibreNMS for SNMP-Heavy Home Networks
- SmokePing for Internet Connection Sanity
- ZFS Send/Receive Over WireGuard for Off-Site Replication
- Headscale: Self-Host Your Own Tailscale Control Plane
- Cloud Gaming Tips That Actually Work
- OpenCanary: Honeypots for Your Home Lab
- Pi-hole vs AdGuard Home: Block Ads for Your Whole Network
- nftables: Modern Linux Firewalling
- Suricata vs Snort: Network Intrusion Detection That Actually Works
- Sysctl Tuning: The Linux Kernel Settings Nobody Told You About
- Authentik vs Authelia: SSO for Your Self-Hosted Stack
- Cloudflare Tunnels: Beyond Port Forwarding
- Fail2ban vs CrowdSec: Blocking the Bots Actually Smartly
- WireGuard vs OpenVPN 2026: It's Not Even Close
- Docker Networking Demystified
- Proxmox NAT Bridge: One IP, Many VMs
- TLS 1.3: Modern Encryption Without the Existential Dread
- IPFS: Peer-to-Peer File Storage for People Who've Seen Too Many 404s
- The Zero-Trust Home Lab
- HAProxy: Load Balancing Done Right
- Cloudflare WAF: Free Tier Firewall Rules
- Cloudflare DNS: Beyond Pointing Records
- Traefik: Docker Routing with Labels
- Nginx Proxy Manager for Normal Humans
- VLAN Basics for Home Labs: Segment Your Network Before It Segments You
- Port Knocking: Simple Obscurity for SSH Access
- The Reverse Proxy Timeout That Kills Long Uploads
- Time Is a Lie and Chrony Is Here to Fix It: NTP for Home Labs
- Why Your VPN Isn't Routing What You Think
- The Header Your Reverse Proxy Keeps Dropping
- IPv6 on Your Home Lab: You Should Care (Here's Why)
- DNS Over HTTPS and TLS: Encrypt Your DNS Before Your ISP Sells It
- tcpdump Basics: Capture Traffic Without Wireshark
- Self-Hosted Email Is Probably a Bad Idea
- TCP Keepalives: Why Connections Die and How to Fix It
- Caddy Advanced: Automatic HTTPS, Plugins, and Config That Doesn't Make You Cry
- The MTU Problem Nobody Diagnoses Correctly
- VPN Kill Switch and DNS Leak Prevention: Paranoia, Justified
- BGP in Your Home Lab: Dynamic Routing for People Who've Run Out of Static Routes
- Suricata vs Snort: Intrusion Detection for the Paranoid Home Lab Owner
- DNS Troubleshooting from the Command Line
- Tailscale Deep Dive: Mesh VPN That Just Works (and Why That's Suspicious)
- nmap for Your Own Network: What You Should Be Scanning
- curl Flags Every Developer Should Know
- UFW Advanced: Rate Limiting, Logging, and Rules That Actually Make Sense
- DDoS Mitigation: Teaching Your Server to Say No Politely (Then Impolitely)
- WireGuard Is Fast, But You're Leaving Performance on the Table
- Traefik vs Nginx Proxy Manager: Reverse Proxies for Humans
- Proxy Chains and Anonymization: What Actually Works and What's Just Theater
- Why Your TLS Certificate Isn't Trusted
- The Firewall Rule Order That's Breaking Your Setup
- Is fail2ban Actually Working? Here's How to Check
- SSHFS: Ditch SCP & Access Remote Files
- Why Your SSH Connection Keeps Dropping
- ss Is the New netstat (And It's Better)
- Docker Network Aliases: The Feature Nobody Uses
- lsof: The Tool That Shows You Everything
- Finding the PID of a Process Using a Specific Port in Linux
- The Role of Antivirus and Endpoint Detection and Response Systems
- Certificate Pinning: A Secure Connection Guide
- Docker Networking Essential Guide for All Skill Levels
- Docker Strategies for Load Balancing and Failover
- Docker Networking: Connecting to the Host from a Container
- WordPress, Docker, NGINX, and MySQL via Ansible
- How to securely deploy Cloudflare Tunnels
- Advanced UFW Techniques: Enhancing Firewall Security
- SSH Tunneling: A Secure Conduit for Your Data
- Socat: The Swiss Army Knife of Networking
- Understanding PostgreSQL Connection URIs
- Linux Home Lab Security: Planning for the Unexpected
- Wireguard VPN Server in Docker
- Access Docker socket via TCP