> Not having two sets of firewall rules and two sets of everything. I always disable IPv6 because it can bite you so hard when you don't realize that you are wide open to IPv6 connections because of different firewalls.
nftables gives us a dualstack firewall, and it's so far the only one I've seen. It's not that bad, but I have occupational damage so I don't mind :D
We're all different, I find Cisco and Vyatta awkward because of different reasons. RouterOS is not the best there is but it's less awkward, in my opinion.
There may be more of us here, even in the FTTH-flavor.
There are some imperfections, mostly related to bonding+ospf and vrrp-grouping but if one does not mind some warnings and a little scripts, one can make things work nicely.
Let's just say that BGP-signaled redundant uplinks and routing as close to the customer as possible are to strive for, instead of starting with a L2 port-isolation-pyramid nightmare.
Back in the day... I used to maintain and manually scale a platform that ran a regionally large social site. It was written in PHP, by two geeks in a dorm, served by Apache and had a single MySQL database and host, in a respectable datacenter. At it's greatest moment, it had a pair of keepalived-hosts in front of around 7 Apache hosts and still that single database host.
That was expensive, but not in maintenance. The amount of moving parts in that, compared to all the doohickeys of modern times, seems like 1:100.
As someone who understands very little of modern web-doohickeys, I'm very afraid of the direction we are going in and it seems like my job-security is quite high, because schools don't produce infrastructure people any more... Just happy-go-lucky developers who know how to run things on top of a credit card, on someone else's computer.
I'd like to disagree on IPv6 sucking and would like to steer this blame towards whoever decided to not be persistent. Firewalls can handle changing prefixes by masking it. Hosts can request certain addresses. Cheap dual-homing is something that IPv6 does not quite do, because that requires NAT66, which is controversial. Also, RIPE tells us to do persistent delegations:
That would most likely be because of low latency and jitter. The app is in essentially the environment it was developed in and does not have to put effort into correcting errors that itself cause pauses in the visible video, since it tries to hide the parts where artefacts appear.
Ten years back I was told America likes to zap quickly through tv-channels with all the artefacts involved while Asia preferred a slower and artefact-free experience. Analog and keyframeless digital codecs are faster but not so bandwidth efficient.
Interesting, Winbox or WebFig/CLI? I find this clunkyness to be a good thing, compared to shiny and inflexible products. I have some experience of quite a few brands and so far Mikrotik is one of the most coherent and unified experiences. WebFig and CLI are the same across devices running RouterOS. Winbox is not my bag though.
RouterOS is not perfect but it does most things without being overly complicated. It's DHCPv6 relay agent is pretty much useless and I really look forward to WireGuard in RouterOS v7, if ever released as stable :D
It's quite a job to get closer to wire speed with 802.11ax still... Let's assume dual spatial streams and devices that not quite support anything past U-NII-1.
This leaves us with 5x20MHz spectrum and while being good netizens we'll leave some of that free for others (and ourselves), so we use just 40Mhz of that.
With the tightest modulation and guard interval even, theoretically, we will acheive at best 573.6Mbit/s simplex and not the best of latency and jitter.
I'm not saying that 802.11ax is not worth the money. I am however saying that getting closer to garanteed Full Duplex 1Gbit/s is hard. And I still have 2.4Ghz-only -devices still in daily use.
I'd dare bet that the WiFi-radio and 1000BASE-T -ports are indeed not switched, but connected to the CPU, which as stated above looks very much like a router :)
There's sadly no block diagram released for these, which would document the internal topology. I also do not have this exact device anywhere to look this up from.
IPIP/IPsec and OSPF would do nicely for efficient site-to-site meshing.
But, adding docker to the equation makes it much more complicated. I'd prefer just operating the machines over IP and get rid of all remote desktop related latency all together.
It's actually not better tech, instead it's more complicated, more error prone and less durable ways to use the same technology that produces more space for a lower price. MLC is pretty much okay but TLC is a little too fragile and low performance in my opinion. I prefer spinning HDD's over QLC since the spinning drives have predictable performance.
You can always blow metal-free fiber in pipes. I'd use PE pressure pipe of suitable size, pull a string into it with a vacuum cleaner and pull fiber in... Hopefully the fiber survives.
With something as complicated as 9 separate locations, I'd definitely avoid unmanaged media converters. Managed ones will be able to tell you how well, or how poorly, your fiber links are doing.
I'd recommend using managed devices as opposed to using dumb media converters. If there are issues, you have no insight into the issues with unmanaged devices.
A trusted certificate is nice and all but if you have to rely on DNS to find the CNAME-record that translates to an A-record and so forth, it becomes complicated and simpler for malicious parties to MITM you. A self signed certificate is actually better in that sense that nothing trusts it and with the assumption that you can add permanent exceptions and pinning, you'll know immediately if something is wrong.
Aside from versioning being clear about how big the change is, Windows Installer has this [0-255].[0-255].[0-65535] limit that I hope people do not learn about in the hard ways.
It's not so fun to work around because Windows Installer tries to be smart about things, as opposed to the others that take a more robust approach.
I again have phobias regarding Watchguard and other products that have the consumer style special WAN-ports and related configuration restraints. Many Mikrotik-devices come preconfigured like consumer devices but the recent CCR-series does not.
The firewall in Mikrotik-devices is among the cleanest I've seen and very hard to miss-configure as long as the firewall is otherwise configured to not let unauthorized traffic through.
And yes, people are people and this is why we educate people when needed.
nftables gives us a dualstack firewall, and it's so far the only one I've seen. It's not that bad, but I have occupational damage so I don't mind :D
https://wiki.nftables.org/wiki-nftables/index.php/Nftables_f...