- Бейне 30
- Рет қаралды 468 417
Tech Tutorials - David McKone
United Kingdom
Күні қосылды 2020 ж. 10 Қаз.
If you want to learn about Linux, virtual machines, networking, smart home automation or computing in general, you've come to the right place
I provide tutorials that intend to help you whether you're starting from scratch or if you've got stuck
There is so much that IT can do for you and that's what channel is for
If these tutorial videos help you in any way, please consider supporting the channel
Buy Me a Coffee - buymeacoffee.com/dmckone
Donate to the channel - paypal.me/DavidMcKone
Become a monthly contributor on Patreon - www.patreon.com/dmckone
Become a monthly contributor on KZclip - kzclip.org/user/TechTutorialsDavidMcKoneJoin
Disclaimer: This channel is for educational purposes only. Examples may have worked at the time of recording but are not guaranteed to work for others. This channel is not responsible for any work carried out or mistakes made by following these examples
I provide tutorials that intend to help you whether you're starting from scratch or if you've got stuck
There is so much that IT can do for you and that's what channel is for
If these tutorial videos help you in any way, please consider supporting the channel
Buy Me a Coffee - buymeacoffee.com/dmckone
Donate to the channel - paypal.me/DavidMcKone
Become a monthly contributor on Patreon - www.patreon.com/dmckone
Become a monthly contributor on KZclip - kzclip.org/user/TechTutorialsDavidMcKoneJoin
Disclaimer: This channel is for educational purposes only. Examples may have worked at the time of recording but are not guaranteed to work for others. This channel is not responsible for any work carried out or mistakes made by following these examples
How To Install And Configure Kea For Ubuntu Or Debian
In this video, we show you how to install and configure the Kea DHCP server for Ubuntu or Debian
What we'll be covering is how to set up a basic DHCP server that supports IPv4
Although there is a lot more you can do with Kea, including monitoring and managing it from a server with a GUI
Further details including configuration examples can be found here:
www.techtutorials.tv/sections/linux/how-to-install-and-configure-kea-dhcp-server/
=============================
SUPPORT THE CHANNEL
Donate through Paypal:
paypal.me/DavidMcKone
Donate through Buy Me A Coffee:
buymeacoffee.com/dmckone
Become a monthly contributor on Patreon:
www.patreon.com/dmckone
Become a monthly contributor on KZclip:
kzclip.org/us...
What we'll be covering is how to set up a basic DHCP server that supports IPv4
Although there is a lot more you can do with Kea, including monitoring and managing it from a server with a GUI
Further details including configuration examples can be found here:
www.techtutorials.tv/sections/linux/how-to-install-and-configure-kea-dhcp-server/
=============================
SUPPORT THE CHANNEL
Donate through Paypal:
paypal.me/DavidMcKone
Donate through Buy Me A Coffee:
buymeacoffee.com/dmckone
Become a monthly contributor on Patreon:
www.patreon.com/dmckone
Become a monthly contributor on KZclip:
kzclip.org/us...
Рет қаралды: 438
Бейне
Proxmox VE Dedicated Migration Interface
Рет қаралды 572Ай бұрын
In this video we show you how to configure a dedicated migration interface for Proxmox VE By default this traffic will be sent over the interface Proxmox VE was configured with when it was installed And that can cause remote management and user connectivity issues for instance Because even if a VM's hard drive is on shared storage, a live migration requires transferring the VM's RAM Provided th...
Assembling A Home Lab Server Rack
Рет қаралды 312Ай бұрын
In this video we show you how we assembled a Startech.com 19 inch four post open frame rack Whether you've got several computers and need somewhere to keep them all Or you just want to tidy up an area for a few IT devices You'll probably consider buying a server rack to house everything in And aside from the reasonable price, what appeals about these racks from Startech.com is that you can adju...
A Switch Too Far?
Рет қаралды 236Ай бұрын
Do you really need 10Gb/s at the desktop? Really? SUPPORT THE CHANNEL Donate through Paypal: paypal.me/DavidMcKone Donate through Buy Me A Coffee: buymeacoffee.com/dmckone Become a monthly contributor on Patreon: www.patreon.com/dmckone Become a monthly contributor on KZclip: kzclip.org/user/TechTutorialsDavidMcKone MEDIA LINKS: Website - www.techtutorials.tv/ Twitter - dsmckone1 Fa...
How To Setup ESPresence for Room Presence Detection in Home Assistant
Рет қаралды 1,1 М.Ай бұрын
In this video we show you how to setup EPresence for room presence detection in Home Assistant to track BLE devices Home Assistant will then know which rooms people are in, your rules can then check if a room is empty before turning a light off for instance and have different automations for different people in a room SUPPORT THE CHANNEL Donate through Paypal: paypal.me/DavidMcKone Donate throu...
How To Configure Proxmox VE Firewall
Рет қаралды 1,7 М.2 ай бұрын
In this video, we show you how to configure the firewall in Proxmox VE Unlike some other hypervisors you'll come across, Proxmox VE has a built in firewall This can restrict access to your hypervisor without having to purchase or install any additional software The firewall also allows you to restrict access to your virtual machines, which is especially useful if an operating system doesn't hav...
Proxmox VE How To Setup High Availability
Рет қаралды 1 М.3 ай бұрын
In this video, we show you how to set up high availability in Proxmox VE One of the main goals of a hypervisor cluster is to minimise downtime If you have a standalone hypervisor and that fails, all of the virtual machines it was running will then be out of service But hypervisors like Proxmox VE offer a high availability service to reduce downtime Provided the servers in the cluster have acces...
Home Assistant Supervised Installation
Рет қаралды 3,8 М.3 ай бұрын
In this video we show you how to do a Home Assistant Supervised Installation Personally I prefer to run this in a VM because you can take a snapshot prior to upgrades and rollback if things go thing wrong Also, if you run this on say a Raspberry Pi for instance and that stops working, you're home automatation will be out of service while you source a replacement computer and then restore Home A...
Proxmox VE How To Clone VMs From Templates
Рет қаралды 8373 ай бұрын
In this video, we show you how to create and use templates in Proxmox VE to save time A virtual machine, just like a physical computer requires an operating system installing Now a hypervisor like Proxmox VE can save you a lot of time when creating virtual machines as it allows you to create templates Instead of creating a new virtual machine and then installing the operating, instead you creat...
Install and Review of Zenarmor for OPNSense
Рет қаралды 3,2 М.3 ай бұрын
In this video, we show you how to install and configure the Zenarmor plugin in OPNSense We then review what you get access to for free versus what you need to pay for Zenarmor, formerly known as Sensei, is a plug-in for open source firewalls made by Sunny Valley which aims to turn your classic firewall into a next generation firewall (NG-FW) Basically, it provides better monitoring of your netw...
OpenSSL How To Renew A Certificate
Рет қаралды 9794 ай бұрын
In this video we show you how to renew a SSL/TLS certificate created in OpenSSL Using OpenSSL as a Certificate Authority is a manual process and at some point a certificate will expire which will need to be replaced When that happens a web browser may refuse to let you access the server, so it's best to renew it before it expires SUPPORT THE CHANNEL Donate through Paypal: paypal.me/DavidMcKone ...
Home Assistant Battery Warning Card Using Auto-entities
Рет қаралды 6 М.4 ай бұрын
In this video we show how to create a Home Assistant battery warning card using auto-entities to add to a dashboard Auto-entities is a very useful plugin you can use in Home Assistant to only display entities that meet a certain criteria So for example, you can create a card using auto-entities which will only display devices with low battery levels Once you replace or re-charge those batteries...
Netgear GS108Ev3 Review and Setup
Рет қаралды 3,8 М.4 ай бұрын
In this video we're going to take a look at Netgear's GS108Ev3 network switch Netgear GS108Ev3 8-Port Gigiabit switch amzn.to/3TUrTJJ It's an 8 port switch which is part of their Plus Management range What this means is that if you want to separate your computers, and you should for Smart Home devices in particular, you'll be able to configure VLANs on this switch Now if you buy an unmanaged sw...
Home Assistant How To Install HACS 2022
Рет қаралды 4,6 М.5 ай бұрын
Home Assistant How To Install HACS 2022
What are the Basics of Firewall Rules?
Рет қаралды 2,8 М.5 ай бұрын
What are the Basics of Firewall Rules?
How To Share USB Devices Over IP Using A Raspberry Pi
Рет қаралды 3,9 М.6 ай бұрын
How To Share USB Devices Over IP Using A Raspberry Pi
Proxmox Cluster QDevice Raspberry Pi
Рет қаралды 1,4 М.6 ай бұрын
Proxmox Cluster QDevice Raspberry Pi
Configure Secure Remote Access On A Cisco Device Using SSH
Рет қаралды 4926 ай бұрын
Configure Secure Remote Access On A Cisco Device Using SSH
How To Install And Configure Secondary DNS Server In Linux
Рет қаралды 1,3 М.7 ай бұрын
How To Install And Configure Secondary DNS Server In Linux
Proxmox Install SSL/TLS Certificates
Рет қаралды 4,2 М.7 ай бұрын
Proxmox Install SSL/TLS Certificates
Home Assistant Node-RED Install Plus Examples
Рет қаралды 29 М.9 ай бұрын
Home Assistant Node-RED Install Plus Examples
How To Setup NFS Shared Storage In Proxmox
Рет қаралды 9 М.10 ай бұрын
How To Setup NFS Shared Storage In Proxmox
Thank you, this was helpful!
Thanks for the feedback Good to know the video helped
Your video was great! I had been having a hard time understanding VLANs and you explained it perfectly, thank you! :)
Thanks for the feedback and good to know the video was useful
Clear explanation, worked as a charm! Edit: damn autocorrect..
Good to hear the video was helpful
Many thanks for the very informative content. My Proxmox landscape is getting more and more fun with every video of you, thanks
It's a great hypervisor to work with Glad the video was helpful
Proxmox does not detects my internal SSD? Do i need to prep and format the ssd in a specific file system format? Thx
@Tech Tutorials - David McKone thx for your info. Installing with VT-x Disabled first did the trick. After proxmox installation i just enabled VT-x again. Just a little quirk/hurdle i had to o overcome.
Proxmox VE should work fine with most SSDs as the operating system is Linux, Debian to be specific Is the drive detected in the BIOS? E.g. can you configure the computer to boot from that SSD using the BIOS boot order? If not then the operating system won't see it and won't be be able to use it
Thank you so much for this! I just got my (sigh) Conbee 2 today, and now it's up and running. I've subscribed! :)
Thanks for the feedback and the sub Good to know the video was helpful
Thank you so much
Good to know the video was useful
I took hours trying to import a ova file and get failed. Thank you so much for this video, help me a lot.
Thanks for the feedback and good to hear the video was helpful
Very clear and detailed video. I've watched a lot of PFSense videos and this is one of the best I've watched!
Good to hear the video was helpful
One of the clearest and most to the point videos I have ever seen on youtube, many thanks.
Good to know the video was useful
The GS308T switch does allow management over HTTPS, in addition to many other features. I have a GS308T at the core and GS308E and two GS305E at the edge. I eliminated all unmanaged switches about 18 months ago when I upgraded to Gigabit for the NAS which I installed then. One annoying thing about Natgear is that different ranges of switches are actually made by different people, and have significantly different management interfaces. There are also minor differences between your switch and mine of the same model; probably different firmware versions.
@Tech Tutorials - David McKone Not just the management interfaces, The switches themselves are made for Netgear by different companies. The status lights on each port function quite differently on different models for example.
I don't buy that many switches to have noticed I found differences between this last one and one I already own but I wasn't aware the management interface was by different developers
Hello, thank you and congrats for your really good and helpful videos! I am new to proxmox and i want to test it before start using it in production environment. But to do that, i would really need your advise, if that's possible. What i do now in my production environment, im using windows server as hypervisor, with only one physical network interface getting public ip via dhcp. Im using NIC Teaming to create an additional virtual network adapter so I can connect it to my provider's vSwitch, using vlan. When NIC Teaming is ready, i have two virtual adapters, and then I am creating two vSwitches inside Windows HyperV Manager Settings (one vSwitch for local ip - vlan and one vSwitch for public ip). That way my VMs have 1 public IP (which i buy from my provider) and one local IP using VLAN. What can I do to have a similar setup inside proxmox? Thank you in advance.
@Tech Tutorials - David McKone I totally understand. My provider won't help me unfortunately. Anyway thank you!
@dimitris I would suggest asking your cloud provider for further details The channel is for educational purposes I do provide some assistance for each video but only if it's not quite understand, has mistakes, etc. But I don't provide technical consultation or support
@Tech Tutorials - David McKone Thank you for your reply. I'm afraid i dont understand what you mean. My server is in a cloud infrastructure so i dont have physical access, or management on providers switches. My server has one physical network adapter, with a public IP assigned from my cloud provider. My server is virtually conected to a vSwitch (VLAN 4005) by which it can communicate with the rest of my private network. In order to that i need another virtual adapter, vlan aware, with proper IP configuration (10.x.x.x/16). In windows (hyperv) envrironments i do that with NIC Teaming, which creates 2 virtual interfaces, one configured with public IP, and one with local IP with vlan tag (4005). Now, in order for my VMs to have similar configuration, in HYPERV settings, i create two different vSwitches, one assigned to virtual adapter with public IP, and the other assigned to the adapter tagged with vlan 4005). When i create a windows VM, there are 2 network interfaces inside the OS, so that way I can config the 1st interface with a new public IP (ordered from my provider), and then i can config the 2nd one with local IP. Im sorry about repeating myself and for the long comment but I cannot find a way to do the same thing in Proxmox. In need my Windows VM to have 1 interface with public IP (no VLAN) and 1 interface with local IP (VLAN 4005) configured. How do i do that?
If there's only one physical NIC then that could remain the physical connection for the Linux bridge If you connect the server direct to an Internet provider though it would be best to install a virtual firewall in the hypervisor As in the video, configure the Linux bridge to be VLAN aware and the physical switch to allow the necessary VLANs to the hypervisor The firewall will need to be assigned vNICs in the Public VLAN and Local VLAN The hypervisor will need a virtual interface itself in a Local VLAN so that it can be managed from there
Congratulations for the video very clear explanation. I am deploying KEA DHCP server in my company. - How to register subnets and pools and register MAC, gateway, DNS and Domain addresses so that the DHCP KEA server assigns randomly identifying the "IPs" available in the pool and delivering what is available to the machines. Thank you, a hug from Brazil.
Thanks for the feedback Good to know the video was helpful
Hi Dave, posted a comment yesterday but it seems to have disappeared? I shall try again! Really great video, really clear talking style and it helped me learn a bit more about the subject and I am looking forward to watching more of yours... I am stuck updating my home HPE esxi server 7.0 Update 1 as it does not have -standard in the profile and I'd love your input please? The profile name in the host screen is showing as "(Updated) HPE-Custom-AddOn_701.0.0.10.6.3-9 (Hewlett Packard Enterprise)" and the new downloaded customised file is "VMware-ESXi-7.0.3-20842708-HPE-703.0.0.11.2.0.9-Jan2023-depot". What on earth should I use for the profile? I've tried -standard and many other combinations but consistently receive "[NoMatchError] No image profile found with name XXX". Completely stumped by this -profile section!
@Tech Tutorials - David McKone thank you very much for your input! Much appreciated! Would you believe the detailed PDF (which I had read) lists an incorrect command, missing the -p profile info and also the -d which is a requirement! But.. I've done it! I found a command which lists the profiles available within an image which is "esxcli software sources profile list -d /vmfs/volumes/<datastore-id>/<path>/<update-zip-filename>". This gave me the profile name I needed for the update (which was: "HPE-Custom-AddOn_703.0.0.11.2.0-9 "). I Updated the update -p section of the command which went through perfectly and server has rebooted on 7.0 Update 3 quite happily :)
I haven't seen the other comment but this one was in held for review as it contains "coding" details The profile name and file name look very different and I'm not familiar with the HPE servers to suggest what should work so you'll probably have better luck asking on the VMware or HPE forums While I was looking around though I did come across this vibsdepot.hpe.com/getting_started.html But I'm not sure if that helps Otherwise there was a much more technical PDF for ESXi on HPE servers www.hpe.com/psnow/doc/a00061651enw?jumpid=in_lit-psnow-red
You rock! On my Ubuntu this was not working, so I read the note and remove -server apt install isc-kea-dhcp4-server -y Reading package lists... Done Building dependency tree... Done Reading state information... Done Package isc-kea-dhcp4-server is not available, but is referred to by another package. This may mean that the package is missing, has been obsoleted, or is only available from another source However the following packages replace it: isc-kea-dhcp4 E: Package 'isc-kea-dhcp4-server' has no installation candidate root@NOC-Lab:~# apt install isc-kea-dhcp4 -y
Great walk thought, it worked! I was a little worried I'd have to learn how to exit maintenance mode from the DCUI as I virtualize my network router on the esxi machine, but was able to log right back into the webgui for esxi. Thanks!
Good to know the video helped I never like upgrading a hypervisor as there are too many dependencies Thankfully ESXi allows you to nest hypervisors so I can at least test patches out first
Hello David, another great video. Thanks. Have an awesome day sir!
Good to hear the video was useful
Great Video Appreciate your sharing knowledge. Can or should we do a limited version upgrade. If YES what will be the way to select the same. Say move from 7.1 to 7.2 While the latest is 7.3. Why I ask this is that are these upgrades stable (OR these are bug fixes) when released or should we stay a version lower than the latest one
@Bhupinder Singh It just connects to the repositories and downloads what's there So if you don't want the latest version then wait until it has been out longer I'm not seeing a manual option for updates other than to install over the top from an ISO
@Tech Tutorials - David McKone Can we specify the version in the no subscription mode?
As ever it depends It's usually best to use the latest version as long as that version isn't too new If it was only released last week or even last month, it hasn't had enough time for new bugs to be detected and reported and the last thing you want is to upgrade to a version that makes the computer unusable Having said that, a majority security fix can take precedence If there's a chance of a vulnerability being exploited on a computer then an upgrade to the newer version is essential
Thanks for wonderful video. I am facing a problem that when I am creating basic port based VLAN and creating say another VLAN no. 2. The hosts in that VLAN are not able to connect to internet. My Switch is connected to a wifi Asus router in Port no. 1. How to enable internet access to other VLANs ? Does the port where internet access router is coming should be assigned as ALL ?
The other VLANs need to be serviced by a router or firewall in the other VLAN Computers on a network need a default gateway in the same VLAN to reach the Internet That device will then forward the traffic for them If your Asus router supports VLANs then it could be configured to do that but the switch port will need to be converted into a trunk port for this to work If it doesn't, but it has multiple physical interfaces then one interface could be placed in this other VLAN to service those computers Otherwise you need another device that either supports VLANs on a single interface or has multiple physical interfaces
good video!
Good to hear the video was useful
Precise and Clear and informative. A Short Quesiton 1. Can a cluster running on three nodes support a Ceph Cluster with its independent from the cluster machines and be attached to the Cluster for shared Block storage and File Store ? Will it hinder the cluster performance ? 2. What NIC card speed in needed for the Cluster. -- Is the cluster using this NIC for corsync activity and I assume this is not bandwidth hungry? Thanks in advance for the guidance
@Bhupinder Singh A Linux server and thus Proxmox VE do support LACP But its use depends on the physical switch If you have one single physical switch that supports LACP then you can bond two interfaces together to that switch to increase overall bandwidth The problem is if you want redundancy to cover against switch failure If you have two physical switches they need to support some form of Multichassis LACP, also known as MLAG. This allows the two switches to be managed and behave as if they were a single switch. You can then have an interface in both switches and LACP configured If they don't and will be managed independently then you have to configure the server interfaces in Active/Backup mode. You can't configure LACP like this. And you can't use an Active/Active set up as it will lead to problems for the underlying network as well as connectivity problems
@Tech Tutorials - David McKone HI David your replies are very helpful. A short question on Cluster setup. --- Documentation says the Bond Mode Should be Active-Backup mode if cluster is considered. LACP not supported. Would Using a Bond (as bridge port) enable LACP to be used? OR at the start we should use Active-Backup. It would be a waste of resources if the NIC cards are 50GBPS and one is a standby. Your thoughts will be very valuable.
@Bhupinder Singh You would still need separate VLANs as a computer can't have more than one interface in the same subnet If you use physical interfaces though then you only need to configure them on the physical switch ports
@Tech Tutorials - David McKone So If I dedicate a physical interface that is 1GB for Mgmt, another physical interface 1 GB for Corsync, Separate Physical interface for VMs, Separate interface for Storage. The Corsync will be a VLAN dedicated to it. Does VLANs require any special precaution. Shall appreciate your valuable thoughts on this approach.
@Bhupinder Singh Ideally a separate interface as well but just VLAN is fine as long as the physical interface doesn't have too much traffic
Thx D. Informative video. 👍 Wouldn't it be safer to enter maintenance mode before installing the patch and then proceed with the update? Maintenance mode (e.g. in sql server) allows only one connection, which is the root user in our case. Some extra security IMO.
@Tech Tutorials - David McKone Makes sense too. thank you for your reply and keep making videos. It's nice to watch them. No unnecessary content, directly focused on the topic 👌
I'm not aware of similar behaviour with maintenance mode for ESXi The security guidance I've seen is to isolate the management interface to limit where remote management access can come from but nothing about limiting the the number of login attempts or the number of connections Makes a lot of sense then as to why SSH is automatically disabled after the server reboots Maintenance mode itself is more for clusters I think because it would stop other hypervisors migrating VMs to the one being worked on and also immediately after it reboots In this case we're pre-patching an update which takes effect after the reboot so it doesn't really matter as it's a standalone hypervisor
I needed a long USB cable for my project and I found it here. Arduino Mega <-> Raspberry Pi <-> Ubuntu. Thank you David.
Thanks for the suggestion
Thanks!
Many thanks, much appreciated
Well, I came across a problem while configuring TP-Link SG108E where even when I removed a port from VLAN1, the IP address of that switch was still reachable on that port. It applied even to TRUNK port....i followed your instructions in the video. So, I'm wondering whether you tried testing the Netgear switch that after you removed the ports from VLAN1, the IP address of the switch was not available on that port. Maybe the Netgear switch has similar bug in the firmware.
@Tech Tutorials - David McKone Thank you for your prompt response. I just wanted to configure the switch in a way that some of the ports would face WAN part of the network and I wanted to prevent end devices connected to these WAN ports from being able to connect to the switch IP address....for security reasons. I was considering buying Netgear since I thought it would have better firmware, but it seems most of the switches in this category will have the same issue with this. Anyway, thank you very much for your videos, they are always very helpful and comprehensible.
Unfortunately this Netgear switch doesn't provide an option to change the management VLAN. It's stuck on VLAN 1 so that's what I'll access it on But I know on some models it isn't possible to remove VLAN 1 from a port, even if you want to As far as I recall Cisco switches allow you to remove VLAN 1 from a trunk but it actually remains active because their switches communicate with each other using VLAN 1 regardless So it's possible that's what you're experiencing
Hello dear Can you tell me why it's swearing? syntax error near ';' in Checkconf
Difficult to say what the exact problem is but there will be an error in the file so you need to check it line by line to see what that is
Man I love your mastorbatorium behind you! (jokes)!! I love your channel!! Lots of detailed information without BS! Keep it going!
I'm confused. The PFSense firewall isn't routing between the 192.168 and the 172.16 LANs, so how is it blocking/allowing access between them (the DNS rule)? Is the traffic going out across the WAN interface and then back in?
@Tech Tutorials - David McKone understood. Thank you.
Good question The video is only meant to cover the basics of firewall rules It wasn't intended to cover the mechanics of how a firewall forwards traffic from one network to another So this firewall was only given some basic interface settings so I could provide practical advice on how to structure firewall rules
Such great videos. Even though most of youtube is garbage, the ability to see vids from people working in industries you will never, and for them to share there experience of tech especially is such a great thing. Love the way, you network engineers(i assume thats what you are), analyse how to do this, and how to make a firewall and network work. The knowledge that so many gain in there jobs, is an enormous resource to people who will never have that chance to get a job, or a position where they can learn this in real world, and given that chance to have such jobs. Always grateful for any video by anyone on topics, by people who gained such experience and they like to share that knowledge so others can learn that too.
Well one day I just decided that with all the stuff I've learned over the years, plus what I'm still learning, why not share that and help folks?
My generic door sensor wont show the battery state and some times does not show if it is open or closed. what am I doing wrong?
Sounds like an intermittent problem Try putting the sensor closer to the Zigbee radio that HA is using and see if that resolves the problem If so then the signal near the door isn't strong enough Mains powered Zigbee devices like smart bulbs and smart plugs can act as relays to boost the signal in an area If not then ZHA may either have a problem with that sensor or the sensor itself may have a problem Try putting another Zigbee device where the door is and see what results you get with that Mind you, it's also useful to put the Zigbee radio on a USB extension lead to improve the radio reception
I love the way that you are teaching ( easy to understand)
Thanks for the feedback And good to know the video was helpful
Thanks for this video, I have been contemplating moving from Untangle to OPNsense with Zenarmor. After trying out OPNsense on updated hardware and various plugins such as Zenarmor it's doesn't come close a next generation firewall with the ability to enforce firewall and other actions based on device/owner/bandwidth and other characteristics and usage patterns. Since I am grandfathered in for the $50/year plan with Arista I am going to keep that plan and just migrate my license to that hardware.
Yeah I think calling Zenarmor a NGFW plugin is misleading I've used various vendor firewalls and Zenarmor doesn't come close to offering anything like they do It is useful for the traffic monitoring and basic threat protection, but that's about it
Very useful - thanks David. I found that I didn't need to do step: 3) Update Lovelace
Thanks for the feedback and good to know the video was useful
Thanks Dave. Just started HA and was uncertain about node red. This video was excellent, simple to follow and patiently explained. Looking at you other videos. Thanks again.
I've found Node-RED to be extremely useful for HA It makes the automation so much easier to set up but also to test and troubleshoot rules
Good to encrypt your DNS, but when you get the IP for pornhub and go there... It will still be logged. :D
[root@localhost:~] esxcli software profile update -p ESXi-6.7.0-20191204001-stan dard -d /vmfs/volumes/63f44d76-422950ad-5824-04d9f5c550f7/Updates/ESXi670-202210 001.zip --no-hardware-warning [NoMatchError] No image profile found with name 'ESXi-6.7.0-20191204001-standard' id = ESXi-6.7.0-20191204001-standard Please refer to the log file for more details.
This is my ESXi version as reported by the GUI, yet i get this error when trying to update
Thank you so much! This worked for me. Microsoft released a KB update that breaks VMs booting in UEFI secure mode, so I needed to update ESXi to version 7.03K. Your video was very thorough and easy to comprehend. My VMs are back online! Thanks again
Taking snapshots of VMs has got me out of several update problems over time But good to know the video was helpful
nice vid, have you ever get the ceph cluster with existing cluster? and is it better than if we had 6 node in one cluster with 3 nodes for ceph? i think i need your smart advice, regards
I'm happy using shored storage for now as it's easier to backup, but at some point I might start using ceph As for cluster size though, the more you have the more likely something will go wrong So unless you have a really big network you would have 3 nodes with lots of CPU and memory After that you scale to 5 You mentioned 6, but clusters should have an odd number of nodes when all are working to avoid the risk of a voting tie
I learned a lot from this video, thank you!
Good to know the video was useful
Great tutorial. Thanks👍
Good to hear the video was helpful
Excellent job on this video. So very helpful. the SSL world can get really complicated with Self Signed CA and Server Keys and Certificates. You've helped make it so much more clear.
Thanks for the feedback, always appreciated
Just info. When it say Y/n in the comandline, just press enter. The Capital Y means that it is default so just need enter
That's true
This video has been very helpful, a question David, are you using Linux or Mac? What distro?
I'm using Linux, Pop!_OS to be specific
Thanks for the explanation. Very useful. Not sure why you dont do [sudo su -] and use the root prompt. Less typing always better.
@Peter Moore You can control sudo rights for individual users If all I do is add a user to the sudo group that person can basically elevate any command But you can edit the /etc/sudoers file and restrict which commands that person can elevate using sudo So even if a user does have sudo rights, you can block them from being able to install software with root privilege for instance
@Tech Tutorials - David McKone when you sudo a command you give that command root privilege. So there is no security battle won here. Only more typing.
For security reasons, I prefer not to use the root prompt You can limit the commands users can access with sudo and also the environmentals change depending on who is logged in Some software insists on you being root, but out of habit I try to use sudo as much as possible
Hey, thanks for the tutorial :) I can't seem to connect to the ip adress shown in my "Welcome to the proxmox~" Any ideas why?
Not sure what IP address you are using but this needs to be one which is reachable by the computer you are trying to connect from E.g. if Proxmox is given an IP address of 172.16.19.11/24 then the computer I try to connect from needs an IP address in the range of 172.16.19.1 to 172.16.19.253, with .11 now used by Proxmox and .254 likely used by a firewall
Trust - are the goods and services we pay for good enough to trust.? How do we provide greater security for our families, our personal information, our stuff that isn't for others to see or profit from. This introduction to home security should be the starting point to becoming security aware, and why security is so poorly considered, and why we need to take control so we determine who and what to trust, not just accept marketing. We need to provide our own protection. This is what I've learnt, together with introductions to the components of a more secure home network, principles that will make our home more secure, from an expert with experience and the ability to share it. Its accessible! Way ahead (but not in the clouds) of the usual how to videos I often encounter. Thank you so much!
Thanks for the feedback, much appreciated
We can modify/ change the native vlan on cisco smart switch such as cisco sg250 or CBS350. There is a cisco video tutorial named "Cisco Tech Talk: Changing Default Native VLAN on a CBS350 Switch" Can we change it on netgear switch? I cannot find where the native vlan is on Netgear switch....? I can only find the management vlan on Netgear switch, is this the same as the native vlan on cisco?
For switches like these Netgear ones, you have what's known as a primary VLAN ID (PVID) By default it's set to VLAN 1 and you have to change it for each individual interface There is no global setting that I'm aware of On a trunk port you set this to be the native VLAN On an access port it will be the access VLAN
I see that stop-timer isn’t there anymore, but is there a way to restart the timer function? I would prefer to restart the timer when motion is detected, not just stopped.
It's not installed by default anymore but you can install it manually I showed an example of installing other nodes towards the end of the video Look for the node-red-contrib-stoptimer
I don't understand why multiple IP addresses and interfaces are required within pve - Once vlan aware and a mgmt IP address have been set in pve, no more IP addresses should be required. The VMs should be assigned to a vlan and either pickup a dhcp address or statically assign one in the vm itself. Other than the mgmt vlan the other vlans should only exist at layer 2 from pve's perspective unless host to host comms is required e.g. pve's version of vmotion. Great vid and channel - I have subbed! :)
A hypervisor needs to have multiple interfaces for security reasons E.g. you want to restrict, as much as possible, any other way of managing the hypervisor other than through its management interface. So that needs a dedicated interface, behind a firewall and then you reduce which computers can access the management interface, who or what can login to the jump server, etc. Other interfaces are needed for different purposes and for security reasons they too should only be carrying the relevant traffic to reduce the risk of a breach Multiple physical interfaces also bring performance benefits and can avoid connectivity problems When you have a hypervisor cluster you'll want a storage interface, a cluster interface and a migration interface A hypervisor might need to access shared storage or use something like ceph for redundancy reasons. That can result in a lot of traffic being transferred between the hypervisors so it's best to put this on a dedicated interface so that the transfer is as quick as possible, but also so it doesn't slow down other parts of the hypervisor. A large data transfer over the management interface for instance could prevent remote access and then you can't even stop the transfer You can't afford interruptions to cluster traffic or the hypervisors might think one of the nodes is down for instance and that results in contention and problems for VMs. Even if you have a single NIC, having an isolated cluster network using VLAN interfaces still avoids traffic from other computers interrupting the cluster traffic and some computers can be very chatty. Computers have to stop and process broadcast, multicast and unknown traffic in their network even if it's just to throw it away because it's not relevant to them Similar to the storage interface, you should have a dedicated physical migration interface. Even if you have VMs on shared storage, a live migration requires transferring the contents of RAM over the network and that can be several GB. So imagine what happens when several VMs are being migrated And you also need a backup interface. Backups don't always go to plan and nobody likes getting into work to find a backup job didn't complete overnight and is oversubscribing the management interface or user VMs for instance. By keeping backup traffic to a separate interface, you can run backups 24x7, as long as you can handle file locks, BUT you can also do certain restores without interruption
Thank you David I was wondering how to do this you are awesome sir.
@Tech Tutorials - David McKone Got ya thank you very much I appreciate it.
@Michael Cooper The migration interface is more for hypervisor to hypervisor transfers e.g. when the hd files are stored in local storage But when the hd files are put on a NAS, they stay where they are when the VM is migrated and the migration interface will be used for syncing the RAM contents between the two hypervisors In this case, if the VM hd files need to move from the NAS to another computer the hypervisor will pull the files over the NIC that connects it to the NAS And then send them over the NIC that connects it to where the files need to be sent It could be the same NIC, it could be more than one, it really depends on your situation If this transfer involves the migration or management interface depends on if they provide connectivity to the source or destination
@Tech Tutorials - David McKone Sorry to bother you again, I have a situation where I need to move VM hds from the current nas it is on so I can rebuild it and then move them back on to it. I have 2.5 gb switch which I am using for the migration under options will it move on the same network or will it use the management network?
Good to know the video was useful, so thanks for the feedback