Welcome Guest ( Log In | Register )

Bump Topic Topic Closed RSS Feed

Outline · [ Standard ] · Linear+

Unifi Official TM UniFi High Speed Broadband Thread V42, READ 1ST PAGE FOR RELEVANT WIFI INFO!

views
     
zellleonhart
post Dec 17 2023, 10:08 PM

Stars stars stars
*******
Senior Member
5,075 posts

Joined: Oct 2008


QUOTE(Doraku @ Dec 17 2023, 04:39 PM)
There is seems like login issues with Bitwarden Android app, a lot reported are from Malaysian with Unifi ISP.
https://community.bitwarden.com/t/login-pro...ndroid/60958/20
*
yes I reported that, people on reddit also facing the same issue with Unifi.

I checked with my adguard home logs, whenever I am connected to wifi and try to login on android, there is not a single request sent to bitwarden. It is like either the app never requested that. But adguard home shows the request when I am on mobile network or VPN.

I have no idea whose fault is this - Unifi, bitwarden, or the app itself. Accessing vault.bitwarden.com on android phone still works, just not the app.
zellleonhart
post Dec 18 2023, 09:17 PM

Stars stars stars
*******
Senior Member
5,075 posts

Joined: Oct 2008


Thanks kwss and BenYeeHua, finally got time to check this thread.
I replied a summary of this issue to the customer support email, I don't think it will be fixed anytime soon depending on the person forward to their devs or not.

Anyhow there's no way to fix this myself unless I build the app with the fixed code right (I don't want to).

Should I continue using my new bitwarden.eu account or just switch to 1Password...
zellleonhart
post Dec 18 2023, 11:49 PM

Stars stars stars
*******
Senior Member
5,075 posts

Joined: Oct 2008


QUOTE(simmarjit @ Dec 18 2023, 09:54 PM)
Use vaultwarden instead?
*
I thought of self-hosting with vaultwarden but I don't want to host it on my VPS and my home thin client used for home assistant might not have very good uptime.

QUOTE(kwss @ Dec 18 2023, 10:26 PM)
The "fix" just enable http2, which is currently not affected by cloudflare's block. However it does not guarantee it won't get blocked in the future.
The main problem is the app don't play nicely with Cloudflare Turnstile. It also have some not so standard behavior such as no-cache GET request. It's a standard practice to use POST for such thing.

From a consumer point of view, I say it's more important to have alternative. Maybe additionally use KeePass and sync with your cloud account? At least you have 2 password managers.
Even if you don't sync both password managers often, losing some access is still much better than losing all access.

Keepass has a benefit of being open source, on device and free. At least nobody can kick you out.
*
Just to confirm, the "fix" requires me to compile the android apk myself right?

I tried KeePass many years ago and the user experience on mobile was quite bad.. but maybe I can try it again now as an alternative.

Thanks for the explanation by the way, it's very helpful. Now I shouldn't continue this off-topic in the unifi thread.. will try it out myself.
zellleonhart
post Feb 4 2024, 10:21 PM

Stars stars stars
*******
Senior Member
5,075 posts

Joined: Oct 2008


QUOTE(NickedAsy @ Feb 4 2024, 10:18 PM)
Did tm crap out on some international sites earlier? Kept getting time out
*
I can't access Discord right now out of sudden. Digi works fine and if use VPN works fine.

Can't afford to restart router now as my other family members are using.
zellleonhart
post Feb 5 2024, 12:13 AM

Stars stars stars
*******
Senior Member
5,075 posts

Joined: Oct 2008


managed to get 218.xxx IP and most sites are working fine except china sites being slow.
zellleonhart
post Jun 19 2024, 11:08 PM

Stars stars stars
*******
Senior Member
5,075 posts

Joined: Oct 2008


Can't load discord at all, not even their website. I thought my discord desktop client is broken, then realized it loads on my ipad because of VPN.

Connected to VPN and it loads fine now. TM get your shit together
zellleonhart
post Jun 23 2024, 01:41 AM

Stars stars stars
*******
Senior Member
5,075 posts

Joined: Oct 2008


QUOTE(Maxieos @ Jun 21 2024, 11:00 PM)
Which VPN is suitable and cheap ? I mean as cheap as rm10 per month ?
*
I am using Nord VPN, it always have some promo ongoing and I managed to get 2 years license (10 devices concurrently connected) for RM420+ some time ago. This means 420/24 = RM17.5 per month.

Best is I share this account with 3 other friends who use 1-2 device at one time max, so each person < RM5 per month.

Don't cheap out on VPN, Nord is already considered the cheaper one with a good overall privacy, speed, protocol and location coverage. I used to use ExpressVPN but it is so expensive and also bought over by a nasty company.

Can also try mullvad but it's a bit more expensive I think.
zellleonhart
post Jul 29 2024, 01:42 AM

Stars stars stars
*******
Senior Member
5,075 posts

Joined: Oct 2008


Can anyone check if you can access this website https://tailscale.com? I can't access it on unifi, even with my own DNS, but all good with Digi or under VPN. Pinging it 76.76.21.21 returns 100% packet loss.

I happen to want to read a blogpost there but turns out I can't access. This is not the first time I randomly encounter a common/popular site that is not accessible via unifi.
zellleonhart
post Jul 29 2024, 11:35 AM

Stars stars stars
*******
Senior Member
5,075 posts

Joined: Oct 2008


QUOTE(kwss @ Jul 29 2024, 06:55 AM)
A bit of update after checking with laptop.
It seems nothing is wrong...

I ran the same nmap scan using my Amazon EC2 instance in Oregon, US.
Same result.

...
*
Hmm sorry I am not technical enough to understand - so there's no issue actually? Just tried again and still can't access/ping on IPv4... Can't afford to get a new public IP now since I am outside, but will see if a new IP range works.

Tried your command and it's loading forever:

CODE

curl -v -4 http://tailscale.com
*   Trying 76.76.21.21:80...


This post has been edited by zellleonhart: Jul 29 2024, 11:39 AM
zellleonhart
post Jul 29 2024, 09:51 PM

Stars stars stars
*******
Senior Member
5,075 posts

Joined: Oct 2008


QUOTE(kwss @ Jul 29 2024, 02:59 PM)
Can you post your traceroute to tailscale.com?
What if you use https in curl? Does it work?
If you have IPv6, try -6 instead of -4 to see if it works.
*
I didn't manage to check with traceroute but I tried https in curl, same result.

But now I refreshed my ip to 219.xxx.xxx.xxx and I can access tailscale.com now. My previous IP was in the 60.50.xxx.xxx range.
zellleonhart
post Jul 31 2024, 03:15 PM

Stars stars stars
*******
Senior Member
5,075 posts

Joined: Oct 2008


QUOTE(soonwai @ Jul 31 2024, 01:21 PM)
Can't say much about efficiency but they're certainly punctual. Right on the last day of July.

Finally got my FSU +100Mbps free download speed upgrade.

DPN-FX3060V 2.5Gbps still in box. Use back old Huawei for now.
*
I still have not received any contact about the upgrade. Last contacted TM livechat in June and they asked me to keep waiting.
zellleonhart
post Aug 6 2024, 11:40 PM

Stars stars stars
*******
Senior Member
5,075 posts

Joined: Oct 2008


Good thing I have set up Adguard Home with Unbound so it's fully DoH / DoT on all my devices and not relying on any upstream DNS like cloudflare or google DNS.
zellleonhart
post Aug 7 2024, 12:07 AM

Stars stars stars
*******
Senior Member
5,075 posts

Joined: Oct 2008


QUOTE(kwss @ Aug 7 2024, 12:00 AM)
The last time TM did this, both DoH and DoT were blocked too.

DNS is actually the easiest to block. Just listen to all connection to port 53 or 853, add those endpoint to DNS blocklist.
I assure you within a week all open resolver will be permanently banned.
*
if I use my own private DoH server, can TM detect and ban it too? or just the public DoH servers?

Also, could be an ignorant question - can ISP actually block port outgoing traffic for port 443 since we need to browse normal websites in https? or DoH uses incoming traffic?

This post has been edited by zellleonhart: Aug 7 2024, 12:20 AM
zellleonhart
post Aug 7 2024, 12:28 PM

Stars stars stars
*******
Senior Member
5,075 posts

Joined: Oct 2008


QUOTE(kwss @ Aug 7 2024, 12:32 AM)
Using the method I described, all endpoint will be dead, including root server. It is the same method China used.

443 is harder to whack but since all open resolver has port 53, 443 and 853 on the same IP, they just need to whack 53 and 853. 443 will be whacked indirectly because the whole IP is in the DNS blocklist.

Of course you can bypass this by putting a CDN in front of your favorite DoH. Since CDN do not have 53 and 853 open, and they are on shared IP, it is not possible to block them. Using CDN also means you have a unique domain name and they cannot whack you solely based on SNI filtering.

If you use HTTP3 (QUIC), the SNI is "encrypted" with a key sent together in the Hello packet too. The censor will then have to do the extra work of extracting the key to decrypt the SNI. At least to my knowledge China and India all drop QUIC packet as a workaround.

The only trouble is you need a working resolver to bootstrap your domain-fronted DoH. You can ride on the ISP resolver for this one.
*
Thanks for the explanation. Just to clarify further, I have my self-hosted Adguard Home DoH server with my own domain e.g. https://xyz.mydomain.com/dns-query, and in the backend I use Unbound DNS which queries root servers instead of cloudflare/google DNS or any public resolvers.

If I understand correctly, my DoH server might not be banned since only myself is using it and it's not an open resolver. But will Unbound still continue to work?
zellleonhart
post Aug 7 2024, 04:33 PM

Stars stars stars
*******
Senior Member
5,075 posts

Joined: Oct 2008


QUOTE(kwss @ Aug 7 2024, 12:33 PM)
Your setup is robust and it will continue to work especially if you use Cloudflare Proxied DNS, Cloudflare Tunnel, AWS CloudFront or Akamai. Try not to use DNS.mydomain.com because it seems obvious during bootstrap.

Just make sure you perform certificate validation so the censor cannot MITM you to discover /dns-query.

EDIT:
You can further protect against active probe from the censor by using signed URL.
At least on AWS CloudFront it can be done:
https://docs.aws.amazon.com/AmazonCloudFron...igned-urls.html
*
Thanks again. I was using cloudflare tunnel but now also added DnsCrypt/Oblivious DoH which should do the trick. My subdomain also does not contain the word DNS.

/dns-query was already behind SSL but i configured in nginx to use a different location instead that doesn't have DNS wording.

So far seems to be covered on most bases. I digged around AWS CloudFront but setting it up to link to my AdguardHome and the signed URL seem to be way above my technical knowledge. So I'll pass for now smile.gif
zellleonhart
post Aug 7 2024, 11:46 PM

Stars stars stars
*******
Senior Member
5,075 posts

Joined: Oct 2008


QUOTE(Kadaj @ Aug 7 2024, 06:50 PM)
How much it cost you for the setup monthly?
Will it cheaper than VPN $5 per month and save all the hassle?
*
Yeah like kwss said, it's free, I have my own home server on a thin client that hosts a few services such as Home Assistant, Adguard Home, some docker containers and stuff. Just pay for the electricity. I can also use the VPS that hosts my static website but for the time being I prefer to use my home server.

I also have a VPN already but I don't connect to VPN all the time because some sites/games need me to turn off VPN. But the primary reason I set up Adguard Home is to block ads and stuff. The DNS stuff is an after thought and just happened to integrate quite well.

QUOTE(kwss @ Aug 7 2024, 11:06 PM)
I think since he already has a domain, he must also have something already running. So the cost is free. It is just additional path configuration in nginx and whatever software behind the scene.

Even if you do not have a domain, do not have any cloud instance, you can still create a CloudFront Distribution and Amazon will assign you something like dxxxxxxxxxxxxx.cloudfront.net.
1TB egress per month is free. USD $0.02/GB for origin request. Let's say you use 5GB of DNS request traffic per month, it is only USD $0.10 per month. I never heard of any home user with 5GB per month of DNS request. DNS response is free and covered under 1TB quota.

I think the free 10 millions request per month is more than enough for DNS requests.
*
About this, do you have any links to read more about setting up DNS server (?) on AWS CloudFront? This seems interesting to play with. I only thought of setting up EC2 instance but didn't know CloudFront can do it. Can't wrap my head about it.

This post has been edited by zellleonhart: Aug 7 2024, 11:50 PM
zellleonhart
post Aug 8 2024, 10:22 AM

Stars stars stars
*******
Senior Member
5,075 posts

Joined: Oct 2008


QUOTE(Kadaj @ Aug 8 2024, 01:35 AM)
I thought you're using VPS + domain coz you mention about unbound, and if i'm not mistaken unbound is actually unencrypted so the ISP still can eavesdrop your unbound queries unless you setup your unbound in foreign country VPS and then DoH back to your devices.

Thanks for your tutorials above, it really help me a lot.  notworthy.gif
I'll try to set it up.
*
Yeah I thought of doing it at first but the latency should be quite high since the VPS is in the US.

Yeah unbound queries are unencrypted but I have now configured unbound upstream to DnsCrypt or Oblivious DoH instead of direct querying the root servers, so unbound is just doing the forwarding and caching.

This post has been edited by zellleonhart: Aug 8 2024, 10:23 AM
zellleonhart
post Aug 11 2024, 10:55 PM

Stars stars stars
*******
Senior Member
5,075 posts

Joined: Oct 2008


QUOTE(DeepMemory @ Aug 9 2024, 11:57 AM)
Anyone on 800mbps still haven't receive free upgrade to 1gbps? I complained to MCMC but still no change.
*
I followed soonwai's idea and livechat TM on 2nd August. Got a call on 5th Aug and the agent read out the T&C for upgrade and I agreed on the phone. But after that nothing yet.. no order created and no appointment set yet, I guess need to wait a few more days and see.
zellleonhart
post Aug 18 2024, 10:58 PM

Stars stars stars
*******
Senior Member
5,075 posts

Joined: Oct 2008


user posted image
Super slow.. I am on 800mbps somemore. Fast.com and tm speedtest still very fast.
zellleonhart
post Sep 4 2024, 11:12 AM

Stars stars stars
*******
Senior Member
5,075 posts

Joined: Oct 2008


QUOTE(Quantum Geist @ Sep 4 2024, 07:06 AM)
out of curiosity, dnscrypt is blocked too I presume?
*
For dnscrypt, you can choose the resolvers such as encrypted dnscrypt servers or oblivious DoH servers, in which these servers are resolved via another relay server(s).

They are considered open servers as well but not IP based. Technically can be blocked if the ISP wants to but I don't think so soon

2 Pages  1 2 >Top
Topic ClosedOptions
 

Change to:
| Lo-Fi Version
0.1846sec    0.53    7 queries    GZIP Disabled
Time is now: 29th November 2025 - 07:14 AM