• 2 Posts
  • 52 Comments
Joined 1 year ago
cake
Cake day: June 16th, 2023

help-circle






  • eramseth@lemmy.worldtoSelfhosted@lemmy.worldRouters
    link
    fedilink
    English
    arrow-up
    1
    ·
    edit-2
    11 months ago

    Depending on how in depth you want your firewall, packet inspection, etc to be and your internet access speed, you may want a commercial grade router. You can also probably use an old PC and add a dual gigabit NIC to it and load up opnsense or pfsense or some other router/firewall distribution. From there, add a stand alone switch and a standalone wifi AP (or router in AP mode). The reason I bring up using a commercial device or an older desktop is because packet inspection, filtering, etc at line speed on a gigabit connection won’t be possible with a lot of low powered devices.

    I used to do this (was using an old Intel core i5 second gen with added RAM and a dual port gigabit NIC) but it was a lot to keep up with. I have since moved on to an Asus router (RT-AX86U) with the AsusWRT-Merlin software package. The only functionality I really lost was suricata for IDS. The AsusWRT distro comes with some proprietary stuff (that I think you can turn off) but it’s also very “open” in terms of just running Linux underneath. This means you can set up things like VLANS, use iptables, etc.

    AsusWRT-Merlin adds some niceties (including a nice add on system that will expand into web based interfaces for certain things you might usually do from command line, better/expanded firewalling, and even adguardhome installer for DNS-based malware/spyware/ad blocking… kinda like pihole but lots of people like it better). The maintainer of that package corresponds frequently with Asus (to the point that some of his stuff is merged back into the official AsusWRT at some points).

    I can confirm that the model I mentioned above is able to do all the firewalling, QoS, adguard DNS filtering, etc at gigabit speeds. It also has some sort of IDS and a few other protections, but they are part of the proprietary bits (Asus licensed via TrendMicro I believe).






  • I see you’ve more or less chosen proton.

    Came here to say that I have been using tutanota for years now and it works very well.

    It does fit the use case of encrypted emails to people who don’t use tutanota. How it works is they will receive an unencrypted email letting them know they have an encrypted email waiting for them, along with a secure link to an https encrypted, password protected web interface with inbox and outbox.

    Just wanted to point this out for anyone else evaluating privacy focused email providers.







  • Not to be a downer, but you’re gonna get a lot of smoke roasting beans in your electric oven (gas would have an exhaust to the outside). That smoke really isn’t good for you to breathe in either. Prolonged exposure will lead to “popcorn lung”. It’s also going to make your stove very dirty in the inside in short fashion. Also, you’re gonna melt some plastic colanders if you drop coffee beans into them right out of a 400-500 degree oven. Not to mention that plastic + heat = not good (even without the melting)

    If you want to try roasting coffee beans at home once or twice on the cheap, you’re better off “pan roasting” them outside on a camp stove or something similar if you don’t have an exhaust fan right above your stove that connects to outside.

    Specialized at-home electric roasters exist and aren’t that expensive. Certainly cheaper than smoke mitigation.