Synology Administration Guide

Synology Administration Guide#

1 Syncthing Deployment#

1.1 Synology DSM Implementation (Docker)#

  1. Inotify Limit:
    echo "fs.inotify.max_user_watches=204800" | sudo tee -a /etc/sysctl.d/90-override.conf
    sudo sysctl -p /etc/sysctl.d/90-override.conf
  2. User IDs: Use Task Scheduler to run id > /volume1/docker/id.txt to find UID/GID (e.g., 1027/100).
  3. Docker Compose Highlights:
    environment:
      - PUID=1027
      - PGID=100
      - TZ=America/New_York
    volumes:
      - ./config:/config
      - /volume2/HP3Storage:/volume2/HP3Storage

1.2 Standard .stignore Patterns#

Create a .stignore file in the root of the sync folder:

(?i)#recycle
@eaDir
.DS_Store
.stfolder
.stignore
$RECYCLE.BIN
Thumbs.db
Desktop.ini
.SynologyWorkingDirectory

2 Storage & Maintenance Commands#

2.1 iPerf3#

sudo -i
synogear install
iperf3 -s -p 11111

2.2 Locked Folder Cleanup#

Remove Synology metadata directories when cleaning up a locked folder:

2026-07-23 - UniFi WAN Security Audit Report

UniFi UDM-SE WAN, Security & IPv6 Audit Report#

Date: July 23, 2026
Gateway Device: Ubiquiti UniFi Dream Machine Special Edition (UDM-SE)
Firmware Version: 5.1.19.33549
Primary ISP (WAN1): Cogeco Connexion (1000 Mbps Down / 30 Mbps Up)
Failover ISP (WAN2): Vidéotron (Currently Down - Offline)
Secondary Backup ISP (WAN3): Starlink (CGNAT)


1. Executive Summary#

An in-depth audit of the UniFi Dream Machine SE gateway was performed via the UniFi API. The assessment evaluated the primary WAN (WAN1 - Cogeco Connexion), secondary failover WAN (WAN2 - Vidéotron), and backup satellite WAN (WAN3 - Starlink).

2026-07-22 - UniFi Management LAN Network Security Analysis

UniFi Primary LAN & Management Network Security Analysis#

VERDICT: [VERIFIED] SECURE AND HARDENED SECURITY SCORE: 96 / 100 (Grade: A+) An empirical audit of the primary Default LAN network (10.1.0.0/24, interface br0) confirms that all 21 UniFi infrastructure hardware devices (UDM-SE gateway, ProMax switches, 10G aggregation switches, wireless access points, building bridges, and smart UPS) operate on an isolated management subnet protected by enforced Linux kernel firewall rules (iptables), key-only SSH authentication, and strict inter-VLAN boundary drops.

2026-07-21 - UniFi IoT Network Security Analysis

UniFi IoT Network & Wi-Fi Security Analysis#

VERDICT: [VERIFIED] SECURE AND ISOLATED SECURITY SCORE: 97 / 100 (Grade: A+) Live kernel firewall rules and DHCP configurations confirm that the marcoue - IoT Wi-Fi (10.1.3.0/24, VLAN 13) has active inter-VLAN isolation, gateway management blocking, active honeypot detection, mDNS reflection, native Pi-hole DNS Option 6 (10.1.2.8), and local NTP gateway redirection (10.1.3.1:123).


1. Verified Infrastructure & Network Profile#

  • Gateway Device: UniFi Dream Machine Special Edition (UDMPROSE / UDM-SE at 10.1.0.1)
  • Wi-Fi SSID Name: marcoue - IoT
  • Network Name: IoT
  • VLAN ID: 13
  • Subnet: 10.1.3.0/24 (Interface br13)
  • Kernel IPSET Group: UBIOS_CUSTOM1_subnets
  • Wireless Configuration: 2.4 GHz (ng protocol, 20 MHz channel width for stability)
  • Active Devices Observed: Meross Dimmer Switches (10.1.3.178), Aqara Camera Hub G3 (10.1.3.222), smart plugs, smart lighting endpoints.

2. Empirical Firewall Rule Audit (Live Kernel Verification)#

Direct inspection of the UDM-SE Linux kernel firewall (iptables and ipset) verified the following active rule chains for VLAN 13 (UBIOS_CUSTOM1):

KVM - Tripp Lite Java Web Start Fix

Tripp Lite KVM Java Web Start (JNLP) Setup & SSL Fix#

This guide documents the fix for opening the Tripp Lite KVM virtual console (viewer.jnlp) on macOS when modern Java blocks connections due to legacy TLS/SSL cipher handshake failures.


1. Problem Overview#

When launching viewer.jnlp via Java Web Start (javaws), the applet fails with the following errors:

com.sun.deploy.net.FailedDownloadException: Unable to load resource: https://10.1.5.2:443/iClientJ12111.jar@pid=...
javax.net.ssl.SSLHandshakeException: Received fatal alert: handshake_failure

Cause#

Tripp Lite IP KVM switches (and rebranded ATEN/Avocent devices) rely on legacy SSL/TLS protocols (TLS 1.0 / TLS 1.1) and deprecated ciphers (e.g., 3DES, 1024-bit Diffie-Hellman keys). Modern Java runtimes (Java 8u291+ and newer) disable these protocols by default in java.security.

Starlink

Starlink Emergency Network Backup Playbook#

This document outlines the operational and financial strategy for utilizing a Starlink Mini hardware kit on a Roam subscription tier as an infrastructure-independent secondary WAN failover. This configuration completely bypasses local terrestrial infrastructure dependencies (cell towers and cable/fiber nodes) during extended power grid collapses.


1. Core Architecture Strategy#

  • Integrated Router: Router is built directly into the dish panel, featuring a native, weather-sealed RJ45 Ethernet port. No proprietary Ethernet adapters required.
  • Direct WAN Hand-off: Connects directly from the dish into the secondary WAN port of the local gateway/firewall (e.g., UniFi Gateway).
  • Power Efficiency: Draws 25–40 Watts. Capable of native DC power input, making it resilient when running off standard 100W USB-C PD power banks or 12V portable generator setups.

Plan Selection: Roam Tier#

  • Cell Congestion Immunity: Roam plans skip geographic cell capacity checks. If an emergency triggers a mass local reactivation event, the system will block standard Residential activations but will approve Roam activations instantly.
  • Mobility Option: Allows the hardware to be disconnected from the home mount and utilized remotely for off-grid operations or travel.

2. Financial Metrics (CAD)#

  • Standby Mode Base Rate: $15.00 / month
  • Roam 100GB Tier: $75.00 / month
  • Roam Unlimited Tier: $200.00 / month
  • Over-Cap Throttled Speed: 1.0 Mbps Download / 0.5 Mbps Upload
  • Annual Idle Maintenance: $180.00 / year

3. Operational Lifecycles & Playbooks#

Configuration A: Baseline Idle State#

  1. Connect the Starlink Mini to the secondary WAN port of the gateway.
  2. Place the Starlink subscription into Standby Mode via the account portal.
  3. Keep the unit powered on.
    • Result: The dish consumes minimal background data to maintain alignment, pull critical system firmware updates, and pass basic network pings.
    • Bandwidth Cap: Throughput is strictly capped at 500 Kbps in this state. The link remains live just enough to load the Starlink management portal and process two-factor authentication (2FA) emails.

Configuration B: Phase 1 Activation (Short-Term Outage)#

Execute this phase when local terrestrial links drop and an extended power grid outage is confirmed.

Linux - Various Command Lines

Linux & Proxmox Command Line Toolbox#


1. Storage & Disk Management#

Clean Up & Space Recovery#

# Purge unused packages and clean cache
apt autoremove --purge && apt autoclean
# Reclaim journal log space (limit to 500MB)
journalctl --vacuum-size=500M

Identify Large Files & Folders#

# List all files with human-readable sizes
ls -lah
# Summary of folder sizes in current directory
du -sh *
# Identify top 10 largest folders on root
sudo du -xh / | sort -rh | head -n 10
# Disk space usage summary (filtered for MB/GB)
du -cha --max-depth=1 / | grep -E "M|G"

Hugo Project Specifics (Size Checks)#

# Find files larger than 25MB in project
find /home/marc/hugo/canada2argentina -type f -size +25M -exec ls -lh {} +
# Count total files in the public build folder
find /home/marc/hugo/canada2argentina/public -type f | wc -l
# List top 25 largest files in project
find /home/marc/hugo/canada2argentina -type f -exec du -h {} + | sort -rh | head -n 25

Disk Health & Partitions#

# Wipe all partitions/signatures from a disk (CAUTION)
sgdisk --zap-all /dev/sdX
# Detailed SMART health report
smartctl -a /dev/sda | less
# Deep scan for bad blocks (Takes a long time)
badblocks -v /dev/sda -s

2. Proxmox & Virtualization#

VM / Container Management#

# Unlock a stuck VM or Container
qm unlock <vmid>
pct unlock <ctid>
# Resize a container disk (Final size, cannot shrink)
pct resize 103 rootfs 16G
# List running LXC containers
pct list | awk 'NR>1'

High Availability (HA) Fixes#

# Disable HA for a specific VM/CT to allow manual fixes
ha-manager set vm:200 --state disabled
ha-manager set ct:103 --state disabled

Repository & Templates#

# Update and list available CT templates
pveam update
pveam available
# List all active apt sources
grep -r '' /etc/apt/sources.list*

Proxmox Boot & Kernel#

# List and pin a specific kernel
proxmox-boot-tool kernel list
proxmox-boot-tool kernel pin 6.8.8-4-pve

3. Networking & Connectivity#

Troubleshooting & Discovery#

# Check DNS resolution
nslookup google.com
nslookup pi.hole
# Check open listening ports
ss -lntu
netstat -plant
# Performance test (Client mode, 8 parallel streams)
iperf3 -c 10.1.1.11 -P8

SSH & Remote Access#

# View real-time system logs for USB/Kernel errors
dmesg -w
dmesg -T | grep usb
# Clear "Remote Host Identification Changed" error
nano ~/.ssh/known_hosts

File Transfers (SCP)#

# Copy local images from Mac to Hugo site on Server
scp -v /Users/marc/Downloads/to_convert/* root@10.1.2.202:/home/marc/hugo/canada2argentina/static/images/
# Backup and transfer a folder between servers
tar -czvf "$(date +%Y-%m-%d_%Hh%M)_PangolinBackup.tar.gz" pangolin/
scp pangolin.tar.gz root@72.11.147.220:/home/marc/docker-compose

4. System & Hardware Info#

RAM & CPU#

# Clear RAM cache (Drop caches)
sync && echo 3 | tee /proc/sys/vm/drop_caches
# Check ZFS ARC summary and free RAM
arc_summary -s arc && free -h

BIOS & Hardware#

# Get BIOS version and serial info
sudo dmidecode -t bios
# List SCSI and PCIe hardware
lsscsi -u
lspci

Legacy iLO3 Fix (Firefox)#

  1. Type about:config in address bar.
  2. Search: security.tls.version.enable-deprecated.
  3. Set to: true.

5. Miscellaneous Utilities#

Permissions & Scripts#

# Make script executable and run
chmod +x ./unifi-9.0.114.sh && ./unifi-9.0.114.sh

Scheduling & Processes#

# Instant test of cron behavior (Sends message to all terminals)
* * * * * echo "Hello from cron" | wall
# Cancel a pending shutdown
shutdown -c
# Print the path of the folder you are in
pwd

MacOS System Administration & Optimization

macOS System Administration & Optimization#

Workstation Recovery & Rebuild Standard: If you need to rebuild your Mac Studio or synchronize its software and aliases with another Mac, refer to the master checklist at Mac OS - Recovery.


1 Modify Known Hosts#

# Add description
nano ~/.ssh/known_hosts
# To remove a specific host
ssh-keygen -R 10.1.1.14
# Clear the full file
cat /dev/null > ~/.ssh/known_hosts

2 Disk Management & Diagnostics#

2.1 Identify and Verify Disks#

# List all physical and virtual disks
diskutil list
# Verify a specific disk (replace X with disk number)
diskutil verifyDisk /dev/diskX

2.2 SMART Monitoring (via Homebrew)#

# Install smartmontools
brew install smartmontools
# Check health of the primary NVMe drive
smartctl -a /dev/disk0

3 Homebrew Package Manager#

Official site: brew.sh

ser2net Zigbee USB Server

ser2net Zigbee USB Server Configuration#

This setup allows you to host a Zigbee USB dongle on one machine (e.g., MMDocker/Proxmox 230) and connect to it over the network from Home Assistant.


1. Installation#

Reference: Peter Kieser - ser2net and Zigbee Coordinator

# Install the software
apt-get update && apt-get install ser2net -y
# Verify version and status
ser2net -v
systemctl status ser2net

2. Identify USB Hardware#

# Locate the specific device ID (stable path)
ls -lah /dev/serial/by-id/
# Get detailed info for the specific port (if needed)
udevadm info -q all -a -n /dev/ttyUSB0
# SkyConnect
ls /dev/serial/by-id/usb-Nabu_Casa_SkyConnect_v1.0*

3. Configuration (Version 4.0+)#

Modern versions of ser2net use YAML configuration files.

Tailscale Installation & Subnet Routing

Tailscale Installation & Subnet Routing Guide#


1. Proxmox LXC Container Preparation#

If you are installing Tailscale inside an LXC container, you must allow TUN device access from the Proxmox host.

Modify Container Config#

On the Proxmox host, edit the configuration file for the specific container (e.g., ID 119):

nano /etc/pve/lxc/119.conf

Add these lines to the bottom:

lxc.cgroup2.devices.allow: c 10:200 rwm
lxc.mount.entry: /dev/net/tun dev/net/tun none bind,create=file

Reboot the container:

pct reboot 119

2. Installation by OS#

Debian 12 (Bookworm)#

curl -fsSL [https://pkgs.tailscale.com/stable/debian/bookworm.noarmor.gpg](https://pkgs.tailscale.com/stable/debian/bookworm.noarmor.gpg) | sudo tee /usr/share/keyrings/tailscale-archive-keyring.gpg >/dev/null
curl -fsSL [https://pkgs.tailscale.com/stable/debian/bookworm.tailscale-keyring.list](https://pkgs.tailscale.com/stable/debian/bookworm.tailscale-keyring.list) | sudo tee /etc/apt/sources.list.d/tailscale.list
apt update && apt install tailscale -y

Ubuntu 24.04 (Noble)#

curl -fsSL [https://pkgs.tailscale.com/stable/ubuntu/noble.noarmor.gpg](https://pkgs.tailscale.com/stable/ubuntu/noble.noarmor.gpg) | sudo tee /usr/share/keyrings/tailscale-archive-keyring.gpg >/dev/null
curl -fsSL [https://pkgs.tailscale.com/stable/ubuntu/noble.tailscale-keyring.list](https://pkgs.tailscale.com/stable/ubuntu/noble.tailscale-keyring.list) | sudo tee /etc/apt/sources.list.d/tailscale.list
apt update && apt install tailscale -y

Ubiquiti UDM-SE#

# Install the latest version of Tailscale UDM
curl -sSLq https://raw.github.com/SierraSoftworks/tailscale-udm/main/install.sh | sh

3. Subnet Router & Exit Node Setup#

Enable IP Forwarding#

This is required if you want this node to act as a bridge to your local network.