remoteroot is a blog about home networking, firewalls, and the sort of things you do when you have too many spare routers and not enough sense to leave them alone.
I am a sysadmin by day, working in IT infrastructure for a mid-size company in the UK. By night I run a home lab that has grown somewhat out of hand - a rack in the spare room with a couple of servers, a managed switch, and more Linksys routers than any reasonable person should own.
What I write about
- DD-WRT and OpenWrt - custom firmware on consumer routers. I have been running DD-WRT since v23 on various WRT54G models and it has completely replaced the need for expensive commercial gear at home.
- iptables and firewalls - from basic NAT boxes to more complex setups with 1:1 NAT, rate limiting, and intrusion detection.
- IPv6 - tunnel brokers, routing, and getting ready for the future (whenever it actually arrives).
- Wireless security - wardriving, WPA cracking (for research), rogue AP detection, and general wifi hardening.
- Honeypots - I run a couple of low-interaction honeypots on the public IPs to see what hits them. The logs make for interesting reading.
The lab
Current kit includes:
- 3x Linksys WRT54GL running DD-WRT v24 (gateway, AP, and test router)
- 1x ASUS WL-500g Premium running OpenWrt Kamikaze
- Dell PowerEdge 2650 running Debian Etch (main server, VMware Server for test VMs)
- HP ProLiant DL360 G4 running pfSense (perimeter firewall)
- Netgear GS724T managed switch
- 2x Raspberry Pi - one running Snort, one running Kippo (SSH honeypot)
The whole lot draws about 400 watts, which my electricity bill reminds me of every quarter.
Contact
You can reach me at remoteroot at this domain. PGP key available on request. I am also on the DD-WRT forums under the same name.
All configs and scripts posted here have been tested in my lab. That said, if you brick your router following my instructions, that is between you and your router. Back up your NVRAM first.