chazzo
New Around Here
I never see any ad on the Forum.
Same here, with default Diversion settings and no adblocker in the browser. I'm guessing that even the SNB experts find it a hassle to create their own dedicated ad delivery network.
I never see any ad on the Forum.
Edited: Here's some lite reading for you.... majority of people I read disabled it.Could someone explain the use of pixelserv-tls?
It's enabled, but not sure what it does.
This is to import a CA for the web UI, is this the routers web UI? Or some other UI that may be useful?
Here's some lite reading for you....Also I believe most have disabled it.
pixelserv - pixelserv - A Better One-pixel Webserver for Adblock
pixelserv-tls pixelserv-tls is a tiny bespoke HTTP/1.1 webserver with HTTPS and SNI support. It acts on behalf of hundreds of thousands of advert/tracker servers and responds to all requests with nothing to speed up web browsing. Project Blog https://kazoo.ga/pixelserv-tls/ FAQ...www.snbforums.com
I couldn't exactly remember but I believe it was most people found it was causing more issues blocking items than helping. It hasn't been updated either if I recall. I had it enabled myself at one time but after disabling it I found no issue to turn it back on. Here is an explanation from @thelonelycoder on what happens when you disable it.Ah, thanks for the links.
What's the reason for disabling it?
I couldn't exactly remember but I believe it was most people found it was causing more issues blocking items than helping. It hasn't been updated either if I recall. I had it enabled myself at one time but after disabling it I found no issue to turn it back on. Here is an explanation from @thelonelycoder on what happens when you disable it.
Sorry, if this was already answered but is there a way to block specific device from connecting to host?
I would like block Amazon and other IoT devices from pinging to google all the time.
I really love what you are doing! Thank you!
You need to look into Skynet not Diversion.Sorry, if this was already answered but is there a way to block specific device from connecting to host?
I would like block Amazon and other IoT devices from pinging to google all the time.
I really love what you are doing! Thank you!
Here's some lite reading for you....Also I believe most have disabled it.
pixelserv - pixelserv - A Better One-pixel Webserver for Adblock
pixelserv-tls pixelserv-tls is a tiny bespoke HTTP/1.1 webserver with HTTPS and SNI support. It acts on behalf of hundreds of thousands of advert/tracker servers and responds to all requests with nothing to speed up web browsing. Project Blog https://kazoo.ga/pixelserv-tls/ FAQ...www.snbforums.com
I can reword it to "majority of people I read disabled it"."Most people disable it" no I disagree. Although we would need a poll to collect data
I continue to use it and manually take care of things so that my phone apps like Amazon shopping etc are unaffected by pixelserv.
I've watched the logs briefly and seen that the analytical, useless-for-the-end-user, stuff is being blocked by Diversion.
You need to look into Skynet not Diversion.
Skynet - Skynet - Router Firewall & Security Enhancements
You would need to upload it to a service such as pastebin, then specify the raw file link accordingly. sh /jffs/scripts/firewall banmalware www.google.com/filter.list Replacing the URL with your own. Thanks again Adamm. Regarding storing blacklists as txt files locally on the USB drive...www.snbforums.com
I couldn't exactly remember but I believe it was most people found it was causing more issues blocking items than helping. It hasn't been updated either if I recall. I had it enabled myself at one time but after disabling it I found no issue to turn it back on.
pixelserv-tls 2.3.1 (compiled: Mar 23 2020 07:23:17 flags: tfo tls1_3)
kvic briefly re-appeared to merge my efforts to fix it up to make it fit for purpose with requirements forced by iOS/macOS changes, but it seems like the project is abandoned. i have removed pixelserv from my setupCode:pixelserv-tls 2.3.1 (compiled: Mar 23 2020 07:23:17 flags: tfo tls1_3)
More recently updated than some scripts IMO!
kvic briefly re-appeared to merge my efforts to fix it up to make it fit for purpose with requirements forced by iOS/macOS changes, but it seems like the project is abandoned. i have removed pixelserv from my setup
Can anyone help?Not quite sure how to get this right. I've tried several combinations and still doesn't seem to work properly.
LAN/DHCP Server Page
DNS Server 1 and 2 are blank (which should default to RTAC68U address)
- I've also tried manually entering the IP address here
WAN Internet Connection
DNS Server 1 and DNS Server 2 are assigned 1.1.1.1/9.9.9.9 (though I tried setting this to blank and the RTAC68U IP)
Connect to DNS Server Automatically is No
DNS Privacy Protocol Set to DNS Over TLS
It's my understanding that given what's set in LAN/DHCP Server Page and WAN Internet Connection, that clients connected to the network should get RTAC68U address assigned as DNS server, and RTAC68U would then filter results poll DNS Servers established under WAN Internet Connection for IP addresses. What am I missing?
None. Similiar to others, no additional blockers still don't see ads here. Not on PC, not on Mobile browsers.Do you have any browser level ad blockers running (Adblock, uBlock Origin, etc)?
@elorimer explained it better than I ever could:Just setting up email config, what is meant by SSL Flag?
Thanks
I think it is actually something a little different. I think it works like this. Whether it is encrypted or not is a function of the protocol. So Gmail's smtp server uses smtps protocol, and the exchange of information sets up TLS encryption at the 256 bit level. The configuration dialog helpfully shows you the settings for four SMTP servers. But by default curl will attempt to verify identities, so Gmail's smtp server will want to see your humble little router verified in its CA chain. Which of course, it won't. The SSL flag allows you to specify the "--insecure" command, which tells Gmail's smtp server not to do that. If you go ahead, the connection is still encrypted.
Now, as a matter of safety, your gmail account is going to have 2FA in place. (If not, stop here.) When this is the case, the Gmail server is going to want to see the connection is verified by 2FA, which of course it can't. But the server also checks to see if you have a application-specific password in place, and if that password matches, the gmail server will accept the traffic.
As an aside, I think that field allows you to specify a bunch of curl options if necessary. Haven't come across the necessity for this.
Welcome To SNBForums
SNBForums is a community for anyone who wants to learn about or discuss the latest in wireless routers, network storage and the ins and outs of building and maintaining a small network.
If you'd like to post a question, simply register and have at it!
While you're at it, please check out SmallNetBuilder for product reviews and our famous Router Charts, Ranker and plenty more!