Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - JamesFrisch

#1
QuoteWohl eher Ausfall kurz nach Ablauf der Garantiezeit vs. Ausfall nach 10 Jahren.
Auch so eine gefühlte Wahrheit? :)

QuoteAußerdem sind die Zeiten, in denen 5 Jahre Garantie bei Festplatten nahezu Standard waren, lange vorbei.
Zeig mir eine Enterprise/NAS disk, welche nicht mit 5y Garantie daherkommt.
Bei SSD ist es noch krasser, alles was nicht absoluter Schmutz ist kommt sogar im Consumer Bereich mit 5 Jahren.

Keine Ahnung wie die auf die Idee kommst, 5y Garantie wäre ein Ding der Vergangenheit. Das Gegenteil ist der Fall.

#2
German - Deutsch / Re: [Hardware] Temperaturen
September 28, 2026, 07:51:18 AM
Der Unterschied ist, dass mit höherer Temperatur [i]alle[/i] (sub)molekularen Prozesse schneller ablaufen, also auch alle Alterungsprozesse in Materialien, Oxidation, Elektromigration usw.Theoretisch, ja. Wie sieht es mit praktischen und echten Effekten aus? Ausfall nach 11 Jahren und einem Monat anstelle von 11 Jahren?

Außerdem sinkt mit höherer Temperatur bei Halbleitern aus Silizium der Widerstand, wodurch ggfs. der fließende Strom steigt, und erhöhter Strom ist auch wieder eine höhere Belastung für die Komponenten.Auch hier wieder, ja theoretisch. Dieser Effekt ist selbst bei 400W GPUs beim Vergleich 40° vs 80° äusserst klein.
Ganz zu schweigen von einer 10W SSD/HDD.

Idealerweise wäre das komplette System überall auf der exakt gleichen Temperatur, die sich auch niemals ändern sollte. Diese Forderung ist natürlich vollkommen absurd. Einverstanden. Mein Argument beim damaligen RTX GPU Mining war immer, eine mining GPU würde ich mit Kusshand kaufen. Während die normale Gaming GPU hunderte Zyklen von 80° auf 21° hinter sich hat, lief die mining GPU konstant auf der gleichen Temperatur. Absurd ist es gerade bei einem Server/Firewall aber keineswegs. Die laufen ja 24/7.

Allerdings habe ich mich auch selten mit der Kühlung von HDDs abgegeben und trotzdem haben es viele ewig überlebt, allerdings kamen die meist nur auf 43°C, keinesfalls und schon gar nicht dauerhaft auf 60°. Also mich würde es stören, ganz besonders bei Hardware, die auf Jahrzehnte hin zuverlässig laufen soll, eine Firewall z.B. .Nun gut, das ist halt deine gefühlte Wahrheit, dass eine HDD auf 43° jahrelang zuverlässig läuft, nicht aber auf 60°.
Rein wissenschaftlich gesehen ist es hingegen irrelevant. Die Hersteller sind ja nicht doof. Die geben aus gutem Grund 5y Garantie und eine Temperaturbereich von 10-60°. Gäbe es auch nur eine 1% Chance eines höhren Ausfalles, wäre der Range 10-55°

wenn man schon nichts weiter unternimmt, sollte man zumindest die natürliche Konvektion / Kamineffekt unterstützenKamineffekt ist bei Computern ein Ammenmärchen. Der wird brutal überschätzt. Das zieht vielleicht bei einem passiven Gehäuse, wenn da aber nur ein einzelner 80mm Lüfter dreht, ist Feierabend. Du könntest eine Case mit einem 120mm Lüfter am Heck auf den Rücken stellen (so dass er voll gegen den Kamineffekt arbeiten müsste) und könntest vermutlich keinen Temperaturunterschied messen.


Sorry für den Rant, aber ich kann solche "gefühlten Wahrheiten" nicht unkommentiert im Raum stehen lassen. Es ist bewusst provokant geschrieben und ich habe nicht für jede meiner Behauptungen selbst einen wissenschaftlichen Beweis. Den muss ich IMHO aber auch nicht erbringen, da ich die Behauptungen nicht in den Raum gestellt habe. Dies soll lediglich als kritischer Denkanstoss gelesen werden.

@HBerger mach dich nicht verrückt. Deine Temperaturen sind völlig im grünen Bereich.
#3
German - Deutsch / Re: [Hardware] Temperaturen
September 11, 2026, 04:26:36 PM
Bezüglich TBW: IMHO auch totaler overkill für OPNsense, ausser du logst extrem viel. Kannst aber auch RAM dafür verwenden.
Bei mir werkeln schon seit Jahren irgendwelche 256GB Intel 550 Resteposten SSDs in mehrere OPNsense boxen. Gar kein Problem.
Kommt aber halt auf deinen Anwendungsfall an.
#4
German - Deutsch / Re: [Hardware] Temperaturen
September 11, 2026, 04:24:06 PM
Quote from: HBerger on September 10, 2026, 10:57:30 AMMacht es Sinn, zu versuchen das Ding Kühler zu bekommen?
IMHO nein. Deine LLM blabbert Quatsch. Wie vieles im Internet. SSDs sind wie fast alle PC Bauteile locker auch mit 80° völlig im grünen Bereich.

Einzig bei HDDs sehe ich (oder besser gesagt die Hersteller) die Grenze eher bei 60°. Ist aber auch logisch, schliesslich drehen da Platten.

Was soll es deine SSD jucken, ob sie mit 40° oder 80° läuft? Wo soll da ein Unterschied sein?
#5
ahh, no?

https://www.fs.com/products/185594.html

And bevor you ask, friend of mine his XGS-PON with that and OPNsense ;)

@tedhugehes I you would at least only slop your own thread, instead of someone elses. *old man yelling at cloud* Back in my days, we called that thread hijacking.
#6
So much noise and wasted energy.
And for what? To realize that it is stupid not to directly input your ISP's fiber into your OPNsense? And that a unnecessary transceiver makes no sense?

Sorry if I am wrong, I just skipped it, not going to read that AI slop.
#7
Same "issue" here.

26.4.1p1_3-amd64

DEC750
#8
Development and Code Review / Re: vibecoded plugin
July 07, 2026, 08:38:11 AM
I don't code either.
So the best I can do is to review your readme, which describes your architecture.

Quoteto avoid unnecessary write cycles on the system SSD.
A backup is like what, 250k? That does not bother any SSD, not even if I do a hourly backup.

QuoteAutomatic Daily Backups: Configure a specific time for daily backups.
Why should I want that? My config stays the same, sometimes for months. Instead of doing a daily backup, I just do a backup after I change something in the webGUI. Simply by downloading the XML. Doing a backup on any interval, IMHO, does not make sense. But okay, since it is so small and programming anything else is too complicated, you could do it like the Google Drive backup; daily and keep the last 30 or whatever.

QuoteBackup Management: List, download, restore, and delete backups from the UI.
Restore? Why? There is proven and working way to restore, why should I risk using your script for that task?

TLDR: It all boils down to: What are you trying to achieve?
After you but some thoughts into that question, you can do some research (or ask in the forum) and relize that the problem you are trying to solve, is already solved. Without the risk of AI slop.

This is btw true for almost all "here is my claude code hobby project" posts that flood /r/selfhosted and /r/homelab.
#9
General Discussion / Re: Crowdsec Observations
June 13, 2026, 09:37:40 AM
Quote from: ruzamai on June 12, 2026, 05:14:48 PMWhat can Crowdsec now offer me?
An additional blocklist.
Plus you can detect unwanted behavior and then block that IP. No matter if the attackers scans ports or does something unwanted on 443.
Not sure why you would open UDP, btw.

But yeah, for me crowdsec is just that, a community blocklist where people contribute with their own data.
#10
General Discussion / Re: Crowdsec Observations
June 09, 2026, 08:31:11 AM
QuoteI've noticed that Crowdsec has never blocked anything that my firewall rules don't block anyway.

Same, but is that even the use case of Crowdsec here? Crowdsec blocked many port scanners for me on OPNsense. Sure, these scanners would not have done much, since the ports blocked. But the same IP is now blocked for other attacks.
Way more active is my Crowdsec on NGINX. This is where all the CVE and wordpress admin/admin stuff happens.

QuoteAnd there's constant pressure to upsell.

Never noticed that, but probably also because for me this is just a fire up and forget. I won't dig into it. Only time I went into it, was a false positive when someone synced 10k new files in Nextcloud.

QuoteHowever, it doesn't seem to be necessary other than as a scare sell to replace Fail2Ban, which I don't use either because I don't need it - because of the afore mentioned firewall rules.

For me, the none existing support for IPv6 from fail2ban made me look into Crowdsec. Blocking a single IPv6 instead of a a /48 makes no sense IMHO. I was too lazy to set it up later on, but I think at least it would be possible.

Quotethat you can't use yourself unless you upgrade your account for a ridiculous subscription charge.

AFAIK you can have 3 lists active at the same time. Fine be me.
I don't think it does much. But I also don't think it costs much. And I like the basic idea behind it.
#11
26.1, 26,4 Series / Re: Rules [new] vs. Rules
May 27, 2026, 08:32:02 AM
Quote from: tigo003 on May 27, 2026, 07:39:11 AMJust trying to gauge whether I should try again to migrate in July / August or later in the year.

There is no rush to migrate. Totally fine to not migrate in 2026. I did it on one site, and personally have a hard time getting warm with the new firewall rules. IMHO it is a downgrade and looks messy, even if you change filters all the time. But to be fair, I have not invested much time into it yet :)
#12
General Discussion / Re: KEA is still a mess IMHO
May 10, 2026, 08:57:40 PM
Quote from: Patrick M. Hausen on May 08, 2026, 08:01:56 AMAll my servers use SLAAC. The addresses are stable unless I change the MAC address of the server for some reason. I can then point Caddy (or NginX in your case) at these addresses. DHCPv6 is rarely needed.

Interesting, I thought that I had changing IPv6, but that was in the beginning of my journey. So maybe I looked at the privacy extended IPv6 back then. So in theory, I could ditch DHCPv6, and go with SLAAC only you think?

Hmm... I have to think about that, I quiet liked to have 10.10.50.4 and 2000:2000:2000:50::4 for simplicity.
#13
General Discussion / Re: KEA is still a mess IMHO
May 08, 2026, 07:33:12 AM
That is a little bit off topic, because my issue is more about OPNsense offerin MAC based reservations, which according to some folks on github is against IPv6 philosophy. And because of that, they have not accounted for certain situations and you run into errors.

Maybe I am misunderstanding you, but IMHO your idea falls flat, because I only need static leases for services. And for that I need a static IPv6.


I can't say to NGINX:
My static /48 prefix is 2000:2000:2000::, my service is in the vlan 30, which has the prefix 2000:2000:2000:30:: so proxy pass to 2000:2000:2000:30:: and somewhere in there is my destination, go find it.
#14
General Discussion / Re: KEA is still a mess IMHO
May 07, 2026, 09:38:21 PM
Quote from: franco on May 07, 2026, 10:46:17 AMI'm unable to tell.

Me too ;) no seriously, I have this issues with OPNsense, but of course it could also be KEA that is the root issue.
#15
General Discussion / KEA is still a mess IMHO
May 06, 2026, 09:34:40 PM
I know a lot of work went into KEA and I truly believe that a lot of bugs were ironed out with the recent release.
Still, KEA is IMHO not polished and production ready.

One example:
1. You have a static IPv4 reservation (based on MAC)
2. You create a IPv6  reservation, based on the same MAC

KEA will now ignore your IPv4 reservation. Yes, it worked before, but now no longer works and instead will get an IPv4 from the DHCPv4 range, while IPv6 will do the reservation correctly.

QuoteBut James, you should DUID and not MAC for IPv6
Fine, but then it should not use MAC when I click on the "add static lease" button in the lease tab, but DUID instead.
Also, since the newest update, I can no longer see the DUIDs anymore on OPNsense?


So if you think just because ICE is eol that you should switch to KEA, don't! Don't make the same mistake I did.
There is still no need to make the switch. At least not for now.