Tuesday, September 27, 2022

Setting up your own Wireguard VPN

 Public VPN is a great way to secure your connection without needing to know how to setup the backend infrastructure.  However, if you want to securely access your resources on your network remotely, you need to have your VPN.

As I am using OPNSense for routing, it is possible to set up VPN in OPNSense, however, it isn't someone like me with limited networking skills.

This changes with the Nyr Wireguard script (https://github.com/Nyr/wireguard-install).  This script make the whole set up process as easy as 1-2-3.

1) Have Linux machine available.

2) Run the installation script:

wget https://git.io/wireguard -O wireguard-install.sh && bash wireguard-install.sh

3) Set up port forwarding on your router.

That is it, now you have your Wireguard VPN set up for your use.

If you are like me who doesn't have a static IP, you may want to use a dynamic DNS services such as afraid.org to get a URL for using in your setup.

If you want more detail steps, try this tutorial on youtube which I was used for setting up mine.

Wednesday, June 29, 2022

Karkos Ink Colours

 Just color samples of Karkos ink.  The pen I used was Jinhao 777 pens.



Saturday, June 4, 2022

Assign a different DNS for a host in OpenWRT

There are occasions which I would like to set a host to use a different DNS server than the general DNS server set for the network.  I can do this easily with OPNSense however I can't seem to find the option in OpenWRT.  Initially it thought this isn't possible.  As it turns out, this is only not possible with Luci but it is doable if you are comfortable to tweak the configuration file directly.

To assign a host to use a specific DNS server, you need to edit the /etc/config/dhcp file.  For example, if I want to set my smart TV to use DNSForge.de instead of the Google DNS on my network, I need to assign a static address to my tv, and tag it with the "tag" option.  Then set the "dhcp_option" to the tagged host as below:

 

config host option dns '1' option ip '10.0.0.200' option name 'tv' option mac 'FF:1A:6B:1A:9A:9B' option tag 'tv_dns' option leasetime '300' config tag 'tv_dns' list dhcp_option '6,176.9.93.198,176.9.1.117'


ref: https://forum.openwrt.org/t/configure-host-specific-dns-server-over-dhcp-option-6/71471/4

ref: https://zedt.eu/tech/linux/how-to-serve-custom-dhcp-configuration-with-openwrt-dnsmasq/

Sunday, March 27, 2022

Install OpenWRT onto ER-X

I finally decided to replace the EdgeOS in my Ubiquiti EdgeRouter-X (ER-X) with the OpenWRT.  While I was flashing the ER-X with the OpenWRT, I came across few issues which I would like to share here.

Although the guide at https://openwrt.org/toh/ubiquiti/edgerouter_x_er-x_ka works, there are few points you may want to watch out.

1) Initially, I was flashing my ER-X with the openwrt-ramips-mt7621-ubnt-erx-initramfs-factory.tar using Chrome on my Linux machine.  However, I got an error while I was doing so.  I tried using Firefox on Linux, and I got the same error.  Eventually, I tried doing so on a Windows machine and it worked as it should be.

2) Although the guide says you can flash the ER-X with the latest OpenWRT image after you had flashed it with the factory.tar image, it seems you can't flash it with the latest 21.02.2 image with the new DSA setup right after.  I got an error complaining the new DSA feature.  However, the latest image from the 19.07 branch works.  Hence, you may want to flash the device from factory.tar, then 19.07 and finally with the latest image. (this is also mentioned on the guide, but it suggests using an image from 18.06 branch which seems a bit too old).


 

Apart from the two minor issues mentioned, the process works beautifully.  My ER-X is now running with a better supported OS and with more features, e.g. OpenVPN.