new post 250810

This commit is contained in:
Kathleen Fitzpatrick
2025-08-10 08:26:22 -04:00
parent a1dd70e8f8
commit 680f1eca80
8 changed files with 863 additions and 22 deletions

View File

@@ -5,11 +5,44 @@
<subtitle>The long-running and erratically updated blog of Kathleen Fitzpatrick.</subtitle>
<link href="https://kfitz.info/feed/feed.xml" rel="self" />
<link href="https://kfitz.info/" />
<updated>2025-06-26T12:30:07Z</updated>
<updated>2025-08-09T20:38:09Z</updated>
<id>https://kfitz.info/</id>
<author>
<name>Kathleen Fitzpatrick</name>
</author>
<entry>
<title>Networking Continued</title>
<link href="https://kfitz.info/networking-continued/" />
<updated>2025-08-09T20:38:09Z</updated>
<id>https://kfitz.info/networking-continued/</id>
<content type="html">&lt;p&gt;As you may recall, I&#39;ve been experimenting with setting up a home server, and several months ago had gotten stuck on an issue related to &lt;a href=&quot;https://kfitz.info/networking/&quot;&gt;the structure of my network&lt;/a&gt;. &lt;a href=&quot;https://kfitz.info/networking/?ht-comment-id=26755687&quot;&gt;Taylor hopped in&lt;/a&gt; and really helped me understand how everything &lt;em&gt;ought&lt;/em&gt; to work.&lt;/p&gt;
&lt;p&gt;But it&#39;s not working. And I&#39;m again flummoxed.&lt;/p&gt;
&lt;p&gt;Here&#39;s the setup:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;I have my ISP&#39;s modem/router/gateway monstrosity (the BGW320) running in IP Passthrough mode, with the WAN IP address being passed to my gateway Eero.&lt;/li&gt;
&lt;li&gt;I have my Eeros set to Automatic DHCP mode; the gateway Eero is successfully getting the WAN IP address and is handing out private IP addresses in the 192.168.4.X range.&lt;/li&gt;
&lt;li&gt;I have a registered domain name (let&#39;s say &lt;code&gt;example.net&lt;/code&gt;), and I have an A record at my DNS service pointing to my WAN IP address. I have also created a subdomain A record (&lt;code&gt;service&lt;/code&gt;) pointing to the same IP address. DNS Checker gives me all green checks for both.&lt;/li&gt;
&lt;li&gt;I have a mini server, running Proxmox.&lt;/li&gt;
&lt;li&gt;I have installed Nginx Proxy Manager in a container on the Proxmox (an LXC), which is running and reachable at the static address 192.168.4.11.&lt;/li&gt;
&lt;li&gt;I have installed the service I&#39;m trying to expose in another LXC, which is running and reachable at the static address 192.168.4.12.&lt;/li&gt;
&lt;li&gt;I have set up port forwarding on my Eero network for ports 80 and 443 to 198.168.4.11.&lt;/li&gt;
&lt;li&gt;I have created a proxy host in NPM, for which all the dots are green:
&lt;ul&gt;
&lt;li&gt;Domain Name: &lt;a href=&quot;http://service.example.net&quot;&gt;service.example.net&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Scheme: http&lt;/li&gt;
&lt;li&gt;Forward Hostname/IP: 192.168.4.12&lt;/li&gt;
&lt;li&gt;Forward Port: &lt;code&gt;port&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;Block Common Exploits and Websockets Support on&lt;/li&gt;
&lt;li&gt;Access List: Publicly Accessible&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;But &lt;code&gt;http://service.example.net:port&lt;/code&gt; refuses to connect, as does &lt;code&gt;http://example.net&lt;/code&gt;, either from my local network or through my VPN. And &lt;code&gt;traceroute&lt;/code&gt; to either &lt;code&gt;example.net&lt;/code&gt; or &lt;code&gt;service.example.net&lt;/code&gt; stalls out.&lt;/p&gt;
&lt;p&gt;I&#39;ve checked the Proxmox firewall and inbound 80 and 443 are both set to accept. I&#39;ve checked to see whether my ISP&#39;s montrosity&#39;s firewall could be blocking those ports but... who&#39;s to say. The NAT/Gaming (sigh) panel of the admin interface isn&#39;t showing the gateway Eero as a device that could need anything in particular sent its way, so my assumption is that IP Passthrough passes inbound requests through for the Eero to sort out, too.&lt;/p&gt;
&lt;p&gt;I&#39;ve searched around, and the nearest thing I&#39;ve found to what I&#39;m trying to do and how I&#39;m trying to do it is in &lt;a href=&quot;https://www.reddit.com/r/Proxmox/comments/u857x5/nginx_proxy_manager_setup_troubles/&quot;&gt;this Reddit thread&lt;/a&gt;, but the problem in that case is back at the beginning with the A record, which is definitely not my issue, unless I spelled my domain name wrong at the DNS. (I didn&#39;t.) And that person was able to get to the NPM congratulations page; my connections get refused entirely.&lt;/p&gt;
&lt;p&gt;If anybody sees anything that I should adjust, or take a look at adjusting, I&#39;d be grateful to hear. I&#39;m already &lt;em&gt;this&lt;/em&gt; close to dumping my ISP anyhow due to some ongoing service issues, and getting rid of their annoying modem/router/gateway would be a bonus, but I&#39;m not entirely certain that it&#39;s the problem, and I&#39;d love to find a way through without taking that step.&lt;/p&gt;
</content>
</entry>
<entry>
<title>Distinguished</title>
<link href="https://kfitz.info/distinguished/" />
@@ -132,14 +165,6 @@
&lt;p&gt;“Independence” and “neutrality” are not the same thing. In the South African context, neutrality would have meant acceding to academic apartheid. Once the backstory is supplied (and history returned to theory, as in the work of Charles Mills), the lesson then is that the university must remain independent from the government but &lt;em&gt;cannot&lt;/em&gt; remain neutral. Faculty must make judgment calls on the university&#39;s behalf that take into consideration the historical and political circumstances in which their universities find themselves. (211)&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Two months later, it is clear to me that “thoughtful restraint” will not only not protect the university from those who wish to do it harm, but will erode the very independence that the institution needs in order to survive right now: the ability to bring the facultys best judgment to bear in declaring that there &lt;em&gt;are&lt;/em&gt; truths that cannot be ordered away. Our institutions cannot live out their most basic reason for being without a willingness to point out and reject outright lies, and without the ability to say that there are issues — like the basic humanity of each and every person on campus, and that they deserve respect, safety, and opportunity — that should never be up for debate.&lt;/p&gt;
</content>
</entry>
<entry>
<title>Holding Space</title>
<link href="https://kfitz.info/holding-space/" />
<updated>2025-01-31T20:00:18Z</updated>
<id>https://kfitz.info/holding-space/</id>
<content type="html">&lt;p&gt;Here I was, super happy with my return to blogging in 2024. I wasn&#39;t crazy prolific or anything, but I did manage to post &lt;em&gt;something&lt;/em&gt; every month except for April. What happened in April? &lt;a href=&quot;https://kfitz.info/things-that-happened/&quot;&gt;Kind of a lot.&lt;/a&gt; But nothing compared with January. Someday I hope to have the time and space necessary to write about at least part of it, but that day is not today. Today, all I can do is close out January by trying to hold a bit of space toward a better moment. May that better moment come soon, for all of us.&lt;/p&gt;
</content>
</entry>
</feed>

View File

@@ -545,13 +545,21 @@ pre[class*="language-diff-"] {
<subtitle>The long-running and erratically updated blog of Kathleen Fitzpatrick.</subtitle>
<link href="https://kfitz.info/feed/masto.xml" rel="self"/>
<link href="https://kfitz.info/"/>
<updated>2025-06-26T12:30:07Z</updated>
<updated>2025-08-09T20:38:09Z</updated>
<id>https://kfitz.info/</id>
<author>
<name>Kathleen Fitzpatrick</name>
<email>kfitz@kfitz.info</email>
</author>
<entry>
<title>Networking Continued</title>
<link href="https://kfitz.info/networking-continued/"/>
<updated>2025-08-09T20:38:09Z</updated>
<id>https://kfitz.info/networking-continued/</id>
<content type="html">As you may recall, I&#39;ve been experimenting with setting up a home server, and several months ago had gotten stuck on an issue related to the structure of my network.</content>
</entry>
<entry>
<title>Distinguished</title>
<link href="https://kfitz.info/distinguished/"/>