Loading...
Loading...
Step by step guide on Patreon. If you are wanting to set up a home #DNS where you can add just a basic URL to all of the different services you have running in your home lab, then this is a guide on how to use #Adguard and #NginX on a low power computer where you can do just that. This is also good if you have services and your internet goes down, you can still rely on your home DNS.
Performance Category
Above Average
Score
4.1/5
Shares: 5/5
Comments: 5/5
Retention: 1/5
Views: 5/5
Likes: 5/5
Followers: 5/5
Script: 3.0/5
Total Views
14781
Likes
611
Shares
44
Comments
50
Duration
17m 36s
For You
13,702
92.7% of views
Search
488
3.3% of views
Personal Profile
296
2.0% of views
Others
222
1.5% of views
Follow
74
0.5% of views
Sound
0
0.0% of views
Views
Likes
Shares
Comments
For You Traffic
Profile Traffic
Search Traffic
Non-Followers
68.0%
10,051 views
Followers
32.0%
4,730 views
16.7% of followers reached
New Followers
36
Performance vs Median
No transcript available.
No scorecard available.
Run the script scorecard evaluation to generate insights.
Run the AI evaluation to identify actions and analyze their impact.
No tips available.
Run the script scorecard evaluation to generate actionable tips.
azuweyxxxI really like netbird to do this, but you need a public domain.
yeah, cloudflare sell .cc domains for 8 a year...
lirkangelI have setup router from provider -> bare metal opnsense -> proxmox (nginx and adguard) somehow after pointing opnsense to adguard I have huge lag so I removed and back to public dns 😅
I'd put the adguard, nginx on a dedicated device on the same switch as the opnsense, should reduce that lag
🚀🚀🚀Pangolin also offers security rules that will only allow traffic from specific IPs to get passed though to the auth page or bypass it all together.
I'm a fan of pangolin
Colton JohnsonUse Cloudflare as dns and it is free ssl. Not entirely homelab I know but I’m lazy and it’s easy
if you're able to port forward, have a static IP and not behing a cgnat then use, or use tunnels but that's public
Colton JohnsonWith a tp link deco. It lets me port forward easily. And it has built in free ddns and I use a cname record in Cloudflare to point to the domain that tp link gives
your isp isn't putting you behing a cgnat then, and that's not too common these days
Colton JohnsonMy isp is a small regional one that sucks hot ass. They probably don’t know what that is. I’m lucky.
lol
Nedislav 404great tutorial, having domains is way easier for non tech family members 😅
DatacenterDudepfSense has ACME and HAproxy built-in that take care of this. So if you’re already running those, it can just handle it natively
I've been considering opnsense, but effort in migrating is more than I wanted.
moneymayAhhh I missed the DNS rewrite. Appreciate it!!
glad to help
Nico Morgan | Equine MediaAny advice on how you would achieve the same on unraid?
oh, hosting this in u raid, not an issue at all, same setup, just using the app store installations.
Seb :Pthis is also a great solution if you want to port forward services. as NGINX will deal with everything neatly through ports 80 and 443. just add cloudflare to manage your domain so you get added security.
yeah, solid use case!
penultimateconquestI’ve got Nginx+pihole+crowdsec. I was told that I shouldn’t have my ports exposed. Should I put nginx behind my vpn?
correct, exposing ports is just a way 8n to your network so best to keep them all locked down. VPN, depends on your setup, I'd suggest using g tunnels with auth for stuff you want public and then behind VPN for what you don't.
xjaridI ditched nginx proxy manager for traefik. From a security perspective, cloudflare api key is stored in plain text, which irks me.
Dr Calemvirso what j have done for my own setup in the past. caddy server exposed publicaly. get a domain then set that domain to your own public ip . THEN on pihole/adguard, point your domain to your caddyserver . then setup your caddyconfjgs. with a rule where if the ip address being connected to (is a header, idk which one( is the public one, if it is, reject. . what this does is caddy will fetch ssl for the public ip automatically, but the SSL will work when you connect overlan since SSL only verifies domain, not ip
works well, unless you're behind a cgnat, then you have to use tunnels
MFKDGAFHave you looked at NPMplus?
Perfection DreamerCurrently going through hell with the traffic should I change to ngnix
nginx proxy manager is super straight forwards, not tollay sure on trafek but, you saw how basic it was for me to set up.
DjxWrecktraefik has a better UI but nginx is easier to use imo. its super easy and straight forward to get everything set up. highly recommend nginx over traefik currently.
it is very easy to use.
Perfection DreamerLet me try one more week with this tearful traefik then I am moving hell with auto discovery when it’s got 400 config faults
sounds like fun
SlushyPieI tried pangolin last night on 2 different VPS’s, noot being on my unraid server. For some reason, on both VPS’s (gigabit speeds) the only max speed i could get was roughly 200KBps… I even tried replacing noot with WireGuard but no it didn’t change anything. Any thoughts?
If both VPS nodes show the same ~200 KB/s and switching Noot → WireGuard didn’t change anything, the tunnel probably isn’t the problem. Most likely causes: • Home upload speed: 200 KB/s is roughly what a ~2 Mbps upstream connection delivers. • MTU issue: bad MTU on the tunnel can cause heavy fragmentation and kill throughput. • Weak VPS CPU: encryption can bottleneck on small 1-vCPU plans. Quick check: run an iperf test outside Pangolin between the VPS and the Unraid server. If that’s also ~200 KB/s, the limit is the network or CPU, not Pangolin.
SlushyPieHi thanks for replying, my upload speed is roughly 70mbps - starlink, using tailscale with nginx PM works perfectly fine, it maxes out my upload, i tried switching around the MTU on the wire guard tunnel but don’t have any luck unfortunately, the VPS’s i tried were 4cpu core / 8GB ram with gigabit speeds, i just I’ll just have to wait for an update but have you tried pangolin recently? Thanks ‘nn
SlushyPieJust an update on this if you were curious, I just ended up replacing gerbal and Newt with tailscale instead, setting the site connection to local (tailscale ip) 👍
should work, not totally sure
MintFPSI use Pihole and Nginx Proxy Manager, works like a charm!
pihole is great, but I've done a few vids in the past on it, so I wanted to change it up.
MintFPSDefinitely. I've been curious about Adguard for sure, glad they operate in mostly the same way.
same
CarlosAny recommendations for using AdGuard instead of Pi-hole? Thanks
Honestly they are very similar, so not really much benifit of one over the other, adguard looks a little neater, that's about it.
UMNZ 🇳🇿Hehehe thanks!
It's a pleasure.
all the steps are in the Patreon, so you can copy paste from there.
Total viewers and likes aligned with spoken words.