Topic
Networking
Everything between your laptop and the box you wish you'd remembered to label. WireGuard, Tailscale, Headscale, Cloudflare Tunnels, split-horizon DNS, IPv6 that isn't just a TODO, and the firewall rules you'll wish past-you had written down. If you've ever solved a problem by reaching for ping and then a packet capture, this is the section.
110 articles in this topic.
Featured posts
-
2.5GbE / 10GbE on a Budget
Skip Cisco. Used SFP+ gear from MikroTik and Mellanox turns 10GbE from $5k fantasy into $200 reality.
10 min read -
Cheap Managed Switches That Don't Suck
Used enterprise-grade managed switches under $100: Aruba, Brocade, MikroTik picks, VLAN setup, wattage, and gotchas for home lab networks.
10 min read -
Bots Ate 90% of My Worker Quota
A WordPress login bot burned 90% of my Cloudflare Workers free tier in two hours attacking a site that has never run PHP. Here's what actually stopped it.
13 min read -
NFS vs SMB vs SSHFS vs WebDAV for Home Lab
Four file-sharing protocols compared for home labs: NFS speed, SMB compatibility, SSHFS convenience, WebDAV over HTTP, and which one to pick per use case.
· Updated:12 min read -
SSH Bastion & Jump Host Patterns That Don't Hurt
Stop opening port 22 to the world. SSH bastion hosts, ProxyJump chains, session recording, and self-hosted Teleport alternatives that actually work.
9 min read -
Ditch Your ISP Router for MikroTik
Your ISP's box doesn't have to run your network. How to find bridge mode, dodge double NAT, and hand real routing duty over to a MikroTik router instead.
13 min read
All Networking articles
- 2.5GbE / 10GbE on a Budget
- Cheap Managed Switches That Don't Suck
- Bots Ate 90% of My Worker Quota
- NFS vs SMB vs SSHFS vs WebDAV for Home Lab
- SSH Bastion & Jump Host Patterns That Don't Hurt
- Ditch Your ISP Router for MikroTik
- SOCKS5 Over SSH: Selective Routing Without a VPN
- Mullvad VPN Containers via Gluetun: Per-App VPN
- Collateral Freedom: Costly to Block
- Meshtastic vs Reticulum
- AdGuard DNS Sync Across Two Instances
- wg-easy: WireGuard for Humans Who Hate Config Files
- REALITY: Borrowing a TLS Handshake
- LoRa Mesh Hardware Buying Guide
- nftables in 2026: Stop Pretending iptables Will Live Forever
- Why Your VPN Is Already Detected
- LoRa Mesh vs LoRaWAN vs Helium
- Meshtastic vs MeshCore in 2026
- DNS-over-HTTPS at Home: cloudflared vs dnscrypt-proxy
- Pangolin: Self-Hosted Cloudflare Tunnel Alternative
- systemd-resolved: The DNS Resolver You're Already Using Wrong
- k3s + Tailscale: Cluster Across Two Sites
- Mesh VPN Showdown: Tailscale, Nebula, ZeroTier, NetBird
- Syncthing Through Untrusted VPS Relays
- Assume Your App Gets Popped
- Gateway API vs Ingress in 2026
- Rootless Docker: Tips, Gotchas & Fixes
- Network Booting Diskless Nodes with iPXE
- Mikrotik RouterOS for Home Lab
- pfSense vs OPNsense in 2026
- Zeek for Home Lab Forensics
- mtr vs traceroute: Packet Loss
- iperf3 + nload: Network Diagnosis
- OpenConnect vs AnyConnect
- stunnel vs spiped
- Unbound vs Technitium vs BIND
- ntopng vs darkstat
- FRR vs BIRD
- HAProxy vs Envoy
- LibreNMS for SNMP-Heavy Home Networks
- SmokePing for Internet Connection Sanity
- ZFS Send/Receive Over WireGuard for Off-Site Replication
- Headscale: Self-Host Your Own Tailscale Control Plane
- OpenCanary: Honeypots for Your Home Lab
- Pi-hole vs AdGuard Home: Block Ads for Your Whole Network
- nftables: Modern Linux Firewalling
- Suricata vs Snort: Network Intrusion Detection That Actually Works
- Sysctl Tuning: The Linux Kernel Settings Nobody Told You About
- Authentik vs Authelia: SSO for Your Self-Hosted Stack
- Cloudflare Tunnels: Beyond Port Forwarding
- Fail2ban vs CrowdSec: Blocking the Bots Actually Smartly
- WireGuard vs OpenVPN 2026: It's Not Even Close
- Docker Networking Demystified
- Proxmox NAT Bridge: One IP, Many VMs
- TLS 1.3: Modern Encryption Without the Existential Dread
- IPFS: Peer-to-Peer File Storage for People Who've Seen Too Many 404s
- The Zero-Trust Home Lab
- HAProxy: Load Balancing Done Right
- Cloudflare WAF: Free Tier Firewall Rules
- Cloudflare DNS: Beyond Pointing Records
- Traefik: Docker Routing with Labels
- Nginx Proxy Manager for Normal Humans
- VLAN Basics for Home Labs: Segment Your Network Before It Segments You
- Port Knocking: Simple Obscurity for SSH Access
- The Reverse Proxy Timeout That Kills Long Uploads
- Time Is a Lie and Chrony Is Here to Fix It: NTP for Home Labs
- Why Your VPN Isn't Routing What You Think
- The Header Your Reverse Proxy Keeps Dropping
- IPv6 on Your Home Lab: You Should Care (Here's Why)
- DNS Over HTTPS and TLS: Encrypt Your DNS Before Your ISP Sells It
- tcpdump Basics: Capture Traffic Without Wireshark
- Self-Hosted Email Is Probably a Bad Idea
- TCP Keepalives: Why Connections Die and How to Fix It
- Caddy Advanced: Automatic HTTPS, Plugins, and Config That Doesn't Make You Cry
- The MTU Problem Nobody Diagnoses Correctly
- VPN Kill Switch and DNS Leak Prevention: Paranoia, Justified
- BGP in Your Home Lab: Dynamic Routing for People Who've Run Out of Static Routes
- Suricata vs Snort: Intrusion Detection for the Paranoid Home Lab Owner
- DNS Troubleshooting from the Command Line
- Tailscale Deep Dive: Mesh VPN That Just Works (and Why That's Suspicious)
- nmap for Your Own Network: What You Should Be Scanning
- curl Flags Every Developer Should Know
- UFW Advanced: Rate Limiting, Logging, and Rules That Actually Make Sense
- DDoS Mitigation: Teaching Your Server to Say No Politely (Then Impolitely)
- WireGuard Is Fast, But You're Leaving Performance on the Table
- Traefik vs Nginx Proxy Manager: Reverse Proxies for Humans
- Proxy Chains and Anonymization: What Actually Works and What's Just Theater
- Why Your TLS Certificate Isn't Trusted
- The Firewall Rule Order That's Breaking Your Setup
- Is fail2ban Actually Working? Here's How to Check
- SSHFS: Ditch SCP & Access Remote Files
- Why Your SSH Connection Keeps Dropping
- ss Is the New netstat (And It's Better)
- Docker Network Aliases: The Feature Nobody Uses
- lsof: The Tool That Shows You Everything
- Finding the PID of a Process Using a Specific Port in Linux
- The Role of Antivirus and Endpoint Detection and Response Systems
- Certificate Pinning: A Secure Connection Guide
- Docker Networking Essential Guide for All Skill Levels
- Docker Strategies for Load Balancing and Failover
- Docker Networking: Connecting to the Host from a Container
- WordPress, Docker, NGINX, and MySQL via Ansible
- How to securely deploy Cloudflare Tunnels
- Advanced UFW Techniques: Enhancing Firewall Security
- SSH Tunneling: A Secure Conduit for Your Data
- Socat: The Swiss Army Knife of Networking
- Understanding PostgreSQL Connection URIs
- Linux Home Lab Security: Planning for the Unexpected
- Wireguard VPN Server in Docker
- Access Docker socket via TCP