Posts

Showing posts from 2020

Things I wish I had known about pfsense before buying my box

1.  pfSense does not generally support more than one network connection per LAN. That is: Most off-the-shelf routers have one WAN port (for internet) and multiple LAN ports (for your stuff).  You can plug any/all stuff into any/all LAN port(s) and it just works. pfSense is not like this.  It expects to have one WAN port and one LAN port.  That's all .   If you want more, you're supposed to use a network switch.  This may seem counterintuitive, but switches do everything in hardware and are actually faster.  This means there is really little need to buy a pfSense box or NIC with more than two Ethernet ports (at extra cost).  It won't use the extra ports by default; they are NOT plug-and-play.  In fact, they won't even work until you set them up! I wish I'd realized this, as I purchased a pfSense box with six ports, which cost more.  I didn't realize the extra ports weren't intended to be plug-and-play for one LAN. It also means th...

How to set up a better separate parental control network for your kids using the Synology RT1900ac router

Again, this is to set up a private, separate, controllable network to implement parental control for the kids, without affecting the main network. First, don't do what I did here and use a Netgear with Circle built in.  The Synology is SO much better. Very briefly: set the Synology in bridge mode, then set up Safe Access for parental control. Basically: 1.  Get an RT1900AC or other Synology router. 2.  Boot it up, go to router.synology.com. 3.  Set it to Access Point mode. 4.  Give it a unique SSID. 5.  If you want, set it to a static IP address. 6.  Let it start up.  If you haven't already, plug it into your "first" router. 7.  Go to router.synology.com or the static ip:8000 to get to the web interface. 8.  Go to "Safe Access" and set up the profiles/settings you want. 9.  If you want, download the app "DS Router" for mobile management. OK, I probably got the order wrong.  You get the idea. Compared to using the Netgear, it's...

My first week with Circle (1st Gen) on Netgear

 So Circle sent me a cheery email about my "first week with Circle!".   However, it feels like a lot longer than a week, and I haven't exactly felt cheerful. Yes, OK, my setup is unconventional .  It's likely the source of many of my issues.  But, in the last week: •  I've found that Circle is not logging Usage or History, and does not enforce time limits. •  Circle is not filtering correctly.  •  It is unclear if it is enforcing SafeSearch.  It seems to be, but it's hard to tell. •  Rewards are limited to the current day.  You can set "Extend/No Time Limit", "Late/No Bedtime", or "No Offtimes".  You cannot set an increased amount of time for future days. •  Circle notifies you of new devices appearing on the network, but tapping the notification just makes the Circle app hang.  This is obviously different behavior from every other app out there. •  The Circle 1st Gen app has forgotten my premium subscriptio...

How to set up a separate network for your kids that uses the Circle by Disney or Circle Home Plus

Update: Several of the features of Circle, such as filtering, usage tracking and time limits are not working.  As many others have reported similar issues, I don't know if this is a result of me setting it up as a second router or not.  Update:  Circle has now "forgotten" my premium subscription three times.  Again, I don't know if this is related to my setup or not. Update: Router was not picking up time server. Steps below have been updated. Given these issues, I don't recommend trying the setup below unless you are willing to take a lot of time to troubleshoot it. I bought a used router that - unexpectedly - had the Circle parental control functions built-in.  I wanted Circle anyway, so it was a bit of luck.  But it wasn't exactly obvious how to set it up.   Problem:  You want to set up a Circle network without having all your devices on it.  Or: you want a separate network for your kids, managed by Circle. Reason:  •  You're wor...

My experience with ExpressVPN

 TL;DR:  It's not good. Fed up with PIA , I decided to try another VPN.  I thought it might be easiest. I wanted Hotspot Shield, but the fact that they log personally identifiable information, don't support pfsense and have no live support were deal-breakers.  I wanted it set up immediately.   I decided to bite the bullet and go with ExpressVPN.   More expensive, but most said they were next fastest, they had 24/7 support and supported DD-WRT (for now) and pfsense (for future).   I ponied up and got a login.  I had to run their app momentarily to find the fastest server, then I set it all up. Any it worked!  All my smart devices reconnected, all my strange connectivity issues went away.    However, I couldn't find the nameservers for secure DNS protection.  I asked their chat, and they didn't know what I meant. Turns out, ExpressVPN doesn't support this.  They do allow manual configuration (on DD-WRT or whatever), bu...

PIA did it again - Oddball problems with VPN

  As of Nov 14, it appears PIA has stopped working again: Play Store not working (on some devices, OK on others) YouTube not working (on some devices, OK on others) Can't connect to BBC.com, CNN.com, but can connect to most other sites fine Smart home devices offline (ecobee, Honeywell, etc)  Honeywell Home: Endless loading Of course, nothing changed on my end, and everything works just fine outside of PIA.  Mobiles also work outside of router-based PIA with the PIA app. See here for the original saga.  Seems they can't keep their network stable for more than 3 months at a time now.  Awesome stuff, those Next-Gen servers - a real improvement! Strangely, the new problems are not as widespread or consistent as before.  One device has no YouTube, but others do.  One device can't access CNN or BBC, but others do.  A third device has no Play Store, but others do. One constant is the smart home devices.  As before, they are connected, but cannot re...

The rampant success of #SupportBlackBusiness

To " The unintended consequences of #SupportBlackBusiness " -  Vox, Sept 3, 2020 "Brittney Winbush, founder of the wellness company Alexandra Winbush, had her first $10,000 sales day in June. Rather than purely elated, though, she was anxious. “Will this last?” she wondered." Every small business owner wonders this. "afraid to make long-term business decisions based on good faith, as history has shown these moments of reckoning rarely linger." Long-term decisions are always a risk , especially for small businesses.  This is not at all unique to this moment. "A reported 41 percent of Black businesses had been shut down in April due to Covid-19." As Tim would say: compared to what? Per Forbes, 73,000 businesses have closed due to the pandemic.  The Washington Post says 100,000, and CNBC says up to 7.5 million are at risk.   So: How does the 41% of Black-owned businesses compare to the overall percentage of businesses closed due to COVID? Or:  W...

Notes on the JBL Cheetah 11101 (truck) and 21101 (buggy)

These are hobby / basher grade 4WD cars.  They are a step up from toy-grade cars like the WLToys lineup, built and priced accordingly.   They are not the toughest cars ever but are (reportedly) pretty decent.  Crashing any car from great heights onto concrete is likely to break it - these are no exception. Do note these cars - and especially the 120A models - are rather beyond mere toys, and use extremely powerful motors.  The young, unwary or careless could easily hurt themselves, lose a finger, etc.  Use caution! Basic specs: 1/10 scale, 4WD 515mm long 3S, 4000 mAh battery, T-connector (a.k.a Deans), 15min 3670-2500 kv motor. 80A (80 km/h) or 120A Hobbywing ESC (100 km/h) All-metal gears. Part-metal chassis. Oil-filled dual-rate (progressive) shocks. 17mm wheel hex 135 / 145mm diameter / 75mm wide tires w/foam LED lights   Note: This car is NOT a rebadged Vikar Bison or DHK Zombie. User manual:  RCGroups 1 , RCGroups 2 Transmitter:  1...

Private Internet Access (PIA) Next-Gen servers break apps and smart home devices

 Problem:  After restoring your PIA connection from after it broke using router-based VPN, you do not have full connectivity.   Specifically, none of your smartphone apps or smart home devices work properly. Your router IS connected to the VPN You ARE using the correct encryption, port, and ca.crt combination They DO have a working internet connection They CAN see the internet They DO work outside the VPN But they can't log in to, or access, their respective servers through the VPN: Gmail: Useless "View more" link that does nothing Banking apps: Can't log in Starbucks: Endless "Finding stores" Ecobee:  "Trouble connecting to your device" Honeywell Home: Endless startup Ratuken Kobo: Endless accessing "My Books" Smart Life: Endless startup Lastpass: Password vault is empty Roblox: Endless loading Minecraft: Can't join multiplayer servers Terraria: Can't join other players  Pixel Guns 3D:  No multiplayer available Ecobee thermostat...

Private Internet Access (PIA) suddenly stops working

Problem: PIA stops connecting.  No changes on your side.  DD-WRT. Error: N VERIFY ERROR: depth=1 error=certificate has expired: C=US ST=OH L=Columbus O=Private Internet Access CN=Private Internet Access CA emailAddress=secure@privateinternetaccess.com 20200818 14:33:13 N TLS_ERROR: BIO read tls_read_plaintext error: error:14090086:lib(20):func(144):reason(134) Solutions: 1.  Your router time setting is wrong.  Try re-setting or selecting another NTP server, just to be sure. 2.  PIA changed something.  Seems they did so recently (August 18, 2020). If (2), your only real solution is to completely re-set up your DD-WRT router using the latest settings.  Instructions are here . Note: -  Specific protocols now need specific ports.  Be sure to get the right port/.crt combination. -  PIA added a line to "Additional Config": pull-filter ignore "auth-token" This line completely borked my ability to connect - DD-WRT wouldn't even try.  Taking...

Cleaning white landscape rock to like-new condition

Image
 Problem:  I want to re-do my landscaping, but want to re-use the existing rock.  The old rock has gotten brown and yellow stains on the bottom - can I clean it? TL;DR:  No, you can't. As far as I can tell, the rock is called "Crystal White".  Mine looks to be about 1" / 25mm size. Over time, it develops brown and/or yellow "staining" on the bottom.  This is likely due to oxidation.   This means taking up and re-laying down the same rock doesn't work, since half the rock will be discolored instead of nice and white.  As this rock is hard to find and potentially expensive, I wanted to re-use the same rock instead of throwing it away. It may seem obvious that you can - or can't.  Some people report success in "cleaning" their rock. I tried the following materials to eliminate the discolorations: Barkeepers Friend (oxalic acid) Stainless Steel cleaner TSP (premixed / ready-to-use) CLR (straight) Palmolive dish detergent Glass cleaner (ammon...

Vantec NBA-200U external USB sound adapter unable to output 7.1 ANALOG audio from Nvidia Shield via Kodi

TL;DR: As title.  The Vantec will NOT output 7.1 ANALOG audio from an Nvidia Shield TV / TV Pro using Kodi. It will output 5.1 audio via optical S/PDIF (Toslink).  And it will play most 6.1 and 7.1 video files through that interface.  You will probably even hear sound through your rear surrounds while playing those files, so you may think that you are actually getting 7.1 sound.  But you're NOT, because optical S/PDIF is NOT capable of sending 7.1 audio due to bandwidth limitations on that interface (as everybody should know by now ).  Most likely your receiver is doing some smart sound processing without you even realizing it. My receiver is old, and does NOT handle sound via HDMI.  And I figured if I'm upgrading, why not move from 5.1 optical to 7.1?  So I needed 7.1 ANALOG sound.  The Vantec is supposed to do that by outputting 7.1 sound via four 3.5mm audio jacks.  You use 3.5mm-to-RCA cables to connect these to the analog inpu...

Sharing files from Synology NAS without Quickconnect, Cloud Station or Synology Drive

I needed a way to allow people to download photos. Things I tried:  -  Icedrive , but the photos are RAW, so very big - making cloud is a bit slow and clunky.  Plus I hit the free storage limit, which took simply ages to fix.  I wanted a solution where I could share files direct from my NAS without a lot of tedious uploading and syncing. -  I tried setting up separate private folders in Photo Station for this, but I didn't like that solution.  Photo Station isn't made for that.  It's messy and wrong. -  I read that you could share via File Station, but it needed Quickconnect.  I wasn't keen on using Quickconnect for several reasons, not least of which was the Quickconnect URLs look really amateur. -  I also researched Synology Drive A LOT.  It does support public links, and would do this.  But it is so heavily focused on collaboration and synchronization that it just seemed wrong for me.   As it turns out,...

The marketing practices of Soda PDF

While I hate to diss on a Canadian company, I am (still) pretty mad about this one.  Mad enough to bother posting this 2 weeks later. For those considering Soda PDF as an Acrobat alternative, it seems pretty good.  It's also possible to pick it up for considerably off the "retail" price, making it seem like a good deal. However, what is mentioned nowhere on their site is that the price is not a one-time purchase.  It is, rather, an annual subscription. They claim this to be a "misunderstanding", but this is obviously intentionally deceptive on their part.  Their site does not state that the price is for an annual plan It is mentioned in the checkout process, where the item purchased is listed as a "yearly plan".  So they can argue it's your fault for not noticing.  But these are two very small small words on a fairly busy ordering page, making it easy to miss. There are also additional items: 1.  Certain features - such as digital ...

Bosch dishwasher E22 code

Good writeup here . Short answer - clean the bottom filter.

Be wary when renewing your NEXUS card

Google search results may show results such as "www.nexus-card.com" at the top of the search listings.  These companies are NOT the CBSA - they are private.  They charge $100-$125 on top of the actual government fee of $50 $USD. You do not need to use such a company to acquire or renew a NEXUS card.  So, that's basically $100 for nothing. When renewing, be sure you're dealing directly with the government.  Correct renewal link here .

How to install Kodi advancedsettings.xml file on a Chromebook

On a PC, putting an advancedsettings.xml file in your Kodi directory is easy.  Copy and paste via Windows Explorer, done. Same for an Android box or tablet.  Copy and paste using "My Files" or anything similar, done. On a Chromebook, not so much.  Chromebooks hide the OS files.  Copy & paste is not possible. However, it is possible to put an advancedsettings.xml file into Kodi on a Chromebook. NOTE : This guide assumes you know how to point Kodi to another device that holds your advancedsettings.xml file, such as a USB stick, external hard drive, internal storage, or whatever.  If you don't know how to do that, go away and find out. (Hey, you may as well.  You're probably going to need that same info to set up your video sources later.) Steps: 1.  Make your advancedsettings.xml file.  Here is a really simple file.  All it does is exclude certain directory names - like "Extras" - from being scanned into the Kodi library...