Friday, May 30, 2025

2025-05-30 - Routing Laptop Audio Through Desktop to AVR with Voicemeeter + Macro Keys

         So, for a few years now I have been in need of an audio solution. I recall that fifteen years ago I used to have all iPhone audio over Bluetooth routed through my Windows desktop computer and into a mixer, then with a media distribution aplifier, multiplied so I could send one signal to a cheap surround sound system and the other half to a couple of PA speakers, which had more bass. They were cheap but they were okay for a while. I never noticed that when I had initially routed the 5.1 audio out the 5.1 3.5mm jacks and one of the headphone 3.5mm jacks in the front to the PA speakers, that they were not synced at all. I just never seemed to have this problem. But more recently, this became a huge problem. But when I tried to set this same system up years later, it became a huge problem and I had to split the 5.1 audio twice and use adapters to turn it back into stereo for the PA speakers. I only had two of them and I wasn't going to buy more of them. This had a lot of problems. The more adapters you introduce, the more potential for failure, there was a point where the audio had humming and hissing and so I had to introduce a ground loop isolator between the computer and the audio equipment. It was a cheap one but it did its job. According to SVS, these are worthless, but I’m not chasing reference-level fidelity — I just need gear that works and delivers the experience I want. 

        And so if I ever wanted 5.1 and bass, I would end up having to buy an AVR, which I wanted to avoid because it would specifically keep me from mixing my laptop audio with my desktop audio and letting me control them separately and together if desired but also have everything come out into one system that controls surround but also bass. The AVR would allow me to do the last part and not really the rest of it. Not without spending a lot more money anyway. If I was reluctantly going to enter into using AVR's, then I wouldn't be spending a fortune on it but enough to get one that basically does the job. I am not going to spend 500 on an AVR. So I bought a Yamaha RX-V385. I was also thinking that while I really enjoy 5.1 surround sound, I also wanted speakers all around me to enable me to be able to hear because I am kind of deaf. If roommates need it quiet, this really puts me at a disadvantage because I can't hear my movies or videos dialogue at all. And then I finally decided that since this Yamaha had a stereo option for all the 5.1 speakers while allowing me to switch back to 5.1, I could just leave it on 5.1 all the time. I bought Klipsch HT-50 5.1 surround speakers, thinking these would have a more crisp sound because although I am not into record player like fidelity, I do like the kind of clean audio that I have heard Bose or Harman Kardin speakers provide. Unfortunately I didn't know what this sound quality was called. I guess it may be called high-end clarity, sparkle, or precision or articulation. 

        Anyway, I ran into a problem. Plugged the AVR and speakers in, went to the stereo feature, plugged in my SVS SB 3000, there was just one huge glaring issue. If I wanted to hear and see what was on my desktop, I had to have my desktop plugged in via HDMI which introduced other problems. I suppose I could have explored component and composite RCA cable bundles but I had heard that these really cut down on quality even if you technically get 1080, oh yeah, and I was using a 4k TV. I didn't care much for expensive high fidelity TVs either but I always heard Samsung was the best so I had a cheap Samsung 4k Smart TV even though I disliked Smart features on most things except phones. And even sometimes that gets in my way. I am a fan of things that just turn on and off and do their job like a toaster or old TVs, and they don't tell you, "Um, you need to buy a far more expensive HDMI cable arbitrarily in order for me to even accept the signal from your device!" Strangely enough it accepted the signal fine with a bent pin and I noticed nothing until the TV finally just said, no, this is no good. And Samsung wanted to charge me a ton of money to have a technician come out and look at it or for me to eat this problem. The latest smart TVs have gotten smarter, which means they are less convenient for me. No I don't need you to do Netflix and scan for viruses and have an internet connection, I need you to literally display 4k output from my computer, let my computer do the rest. Could you imagine if the sub-lightspeed ion engines on the Millennium Falcon were smart devices and dictated that all thrust only comes from them, the lightspeed hyperdrive need not apply? There's almost no reason to have one without the other, so this often being the case for me with my TV, you could imagine my frustration. 

        Thanks to ChatGPT, and my asking what features to turn off or change so the TV stops dictating everything with my AV setup, like randomly turning off once a week, which since my desktop doesn't have constant output regardless of the screen being turned on or unplugged, so the icons and folders scatter and change position and all sorts of things, making these changes ChatGPT suggested really helped even though they didn't totally eliminate all the crap the TV does much to my chagrin. I am seriously going to consider a commercial 4k TV after this even though it would twice as expensive. They last longer, and are the 4k toaster of TVs. 

        So the problem with the AVR, I can either be dedicated to the desktop audio and video in one stream over HDMI, and if I wanted to hear my laptop over this sound system I would have to go into the Option menu on the AVR, which covers half the screen, go into Audio In, and switch to one of the RCA inputs that allows me to connect a 150 dollar Fiio DAC via USB to my laptop. I thought at the time this was the only way. I have since concluded the DAC was unnecessary. I mean, there are scenarios where it is necessary, but in general I have found it not to be when I discovered other methods. Since I am not really into fidelity and more into things just functioning properly, and doing specific things like offering heavy, booming bass, (guys in my high school had subs in their trunks, so I always wanted that too), and my mom and I have always agreed you need a bit extra bass than regular systems offer and apparently I do have audiophiles in the family that precede me. So when this Audio In menu appears and covers half the screen coming from the desktop, it also totally mutes the desktop. I put up with this for a while until the tedium of constantly switching between the two became too much and even caused me to think the system was broken when I would close  the Audio In menu and leave the desktop video exposed without remembering I was connected to laptop audio. 

        I also dealt with another problem. Whenever making this switch between desktop audio and video to laptop audio, I would connect my laptop to a thunderbolt 4 dongle, which had the Fiio DAC and other home accessories connected to it such as ethernet and charging for the laptop, the sudden connection of the DAC usually didn't prompt Windows 11 on my laptop that it was present and ready to take all audio by default. I tried to get this to work and finally created batch and PowerShell scripts to manage switching between the audio outputs on my laptop so it would be less tedious, but these often didn't solve the issue either. I learned that I also had to turn the DAC off and back on again with most sudden connections to the thunderbolt 4 dongle. Then to get bass (all my music is on my laptop so I can sync my iPhone on-the-go and have everything center around my laptop that I bring everywhere with me), I had to go on my phone and turn up the gain on the SVS subwoofer. So there are four steps that each have their own common issues, and are tedious when all together without their problems. 

        I had been googling and asking ChatGPT for years now ways that I can route my audio around the desktop and finally decided three weeks ago that I would bite the bullet and route through the desktop, which does unfortunately mean that the desktop must always be running in order for this to work and when it doesn't, I have to change how things are plugged in. 

        According to SVS, a company that sells sound systems, you want to avoid 3.5mm jacks for audio. I mean, Bluetooth is worse, I suppose, I haven't had the problems with its audio quality that every one else has had, but even SVS offers Bluetooth audio transmitters and receivers, albeit for a lot of money. 

        I had been searching for years now different parts on Amazon that I could use to resolve this routing issue in various ways. So I asked ChatGPT is there a way to route the audio through my desktop and into the AVR without switching inputs on the AVR at all, through the HDMI output on my graphics card, without ever using 3.5mm auxiliary. 

        The reason you want to avoid 3.5mm jacks is that they output a low-voltage, low-current signal meant for headphones—not full-range powered speakers or subwoofers. It lacks the voltage swing and power that RCA line-outs or balanced outputs provide. Many 3.5mm sources (like laptops or phones) use small op-amps that struggle with noise, distortion, and current delivery. They aren’t designed to drive high-quality audio gear properly. 3.5mm outputs are often noisier, pick up interference, and introduce hiss or hum, especially when used in desktop setups with lots of electronics nearby. You're missing the signal integrity of a proper preamp stage. RCA or XLR connections come from line-level outputs, which are designed for consistent volume and low distortion.

        After some back and fourth the conversation with ChatGPT finally settled on a sort of arbitrary method of using my laptop connected to my Fiio DAC through USB which turns the signal from digital to analogue, then from the DAC over RCA to a Behringer UCA222, which reverts the signal back to digital again, then through through USB to the desktop. And to get it to go through my Windows 10 Desktop to my AVR, I had to go Taskbar > right click speaker icon > Sounds > Recording tab > click Microphone USB Audio CODEC > set default device > then go Properties > Listen tab > check the Listen to this device checkbox > and in the dropdown menu for "Playback through this device:", select my SAMSUNG [TV] (2- NVIDIA High Definition Audio) which in the signal chain stops first at the AVR and the AVR strips the audio for itself. I applied this and then went to the Levels tab in Microphone Properties and it was turned down a ways, so I turned it up all the way because I didn't see why it should be so low. 

        I learned this last night when after a week of this new setup with laptop audio going through the desktop and working the way I wanted despite lots of issues, such as like yesterday when after a whole day of using the laptop audio it suddenly decided to stop working completely for no known reason and I absolutely could not get laptop audio through the desktop. The desktop showed via a VU meter in Sounds that it was receiving the audio. And I knew that the AVR was fine because it was still putting out any audio that originated from the desktop. Just nothing from the laptop would come through no matter how many volume and gain knobs I adjusted. 

        The original plan I created included this Behringer device also included the freeware VoiceMeeter, the intermediate Banana version. I had reservations against this software until now because a friend of mine swears by it and I always found it majorly complicated even though I knew it was powerful. Since this set up as it was so far was working great without VoiceMeeter, I decided not to add to the pot. But I asked ChatGPT I should include VoiceMeeter if this setup works without it. I learned the hard way there are complications that will eventually happen when I connect the laptop, the playthrough will require some tooth-pulling with Windows. 

        VoiceMeeter would set it to work the same way every time I connect without a lot of fiddling. I decided to wait and see how much fiddling I would have to do without VoiceMeeter and as it turned out, this first issue was a showstopper. I had initially found that if I turned off the DAC in the signal chain, then my headphones would work directly on my laptop when it was late and roommates were fussy. Turning the DAC back on would initiate the playthrough on the desktop instantly and the power button on the DAC is also a volume knob so this worked great. 

        My only complaint until yesterday was that I had to turn all of the volume knobs really low in order to keep from blasting everything that came from the laptop. I have some audio experience and once had a customer working Walgreens nightshift cashier, who was an audio engineer, who explained that you want all your faders and knobs at around 75% or where they indicate is the optimal range. And I had to turn laptop audio down to 22 out of 100, and the DAC had to be turned down to plus or minus twenty percent, and there came a point where if you needed the volume to be audible but very low, you couldn't do it on the DAC, the audio would just go to moderately low and then mute in a smooth but very unhelpful way. The desktop audio had to be turned down to about 20 percent. So when watching a movie, I would switch to utilizing VLC player volume a lot more, I don't know why I didn't have a problem when watching YouTube. And the AVR was set to -6.0 decibels. 

        I installed VoiceMeeter Banana on the desktop, and had ChatGPT guide me through most of it because I was so confused by it every time I tried it in the past. It just isn't intuitive to me. I installed it. 

        I clicked on Stereo Input 1 at the top left of the window > a new window appeared with a dropdown for the option to select Microphone (USB Audio CODEC) and also to choose between WDM, KS or MME. I left it on WDM at first. I don't think changing it made anything better, but I will get to that. > I set A1 near the top right of the main window to SAMSUNG 2- NVIDIA High Definition Audio.  

        Then I discovered something that would force me to give up a staple of my desktop configuration for many years. I primarily control my desktop through just a wireless keyboard. For mouse operation I use the built in trackpad on the only keyboard I ever saw until recently that did this, the Logitech K400. There are other things like TV remote sized keyboards with all the buttons and a tiny track pad, and you can even point the remote at the screen and it'll move the mouse, I thought that was so cool I had to get my mom to buy it since the keyboard was less convenient for her when I gave her a similar setup. 

        The Logitech keyboard comes with the Setpoint software driver, which controls a bunch of things on the mouse and the keyboard and the trackpad, and pairing one or more devices to a Logitech USB receiver (which confuses me because it used to be called a dongle, which now has a whole other USB dock type meaning). I always controlled my volume through this keyboard for the desktop. And it used a volume level indicator other than the Windows default that I liked more. 

        But there was now a huge problem. To use VoiceMeeter also meant that to change the volume, the keyboard media keys for volume no longer applied. And there is no simple way to get windows to simply recognize those special keys on the keyboard and map them to VoiceMeeter volume. There was another issue too though. In the middle of this problem I realized that I would prefer that the keyboard volume, if I ever got it working again, just effect the desktop volume and allow the laptop volume to continue unimpeded. It looked like this may be too tall an order while still using Setpoint. But I need this to work. So I decided to give it a try and close Setpoint for the first time in over ten years. 

        The first of two things that were really affected by this was that the trackpad speed was much slower, which was sort of causing anxiety because you'd expect it to move and then it would slow down or stop without having moved as much as it used to. It's already a small trackpad by todays standards. So I sped it up in regular mouse settings and this messed with the regular wireless mouse as well, which fortunately had a DPI button, which I adjusted, but that meant that since I use the same mouse for both the laptop and the desktop and I switch between the USB receiver on the desktop and Bluetooth for the laptop, the mouse on the laptop was now much faster. I had to use the DPI button for this too. 

        I almost thought this resolved everything. Then I discovered that the desktop and the laptop require different DPI settings. And the speed was fast enough and not too fast but the sensitivity was so strong on both computers now, that trying to do small things like perfectly grabbing the edge of a window to drag it to a new size and shape was now very hard to do. I have already been struggling with this issue on the desktop because I started using a 4k TV in 2017. I've become far more of a keyboard user as a result. Using the mouse caused too much anxiety. It would nearly push me to panic. Trying to do these overly delicate almost impossible tiny moved with the mouse causes an overwhelming feeling in my stomach. 

        So Murphey's law. The classic upgrade-to-downgrade pipeline. Solving problems one disaster at a time. Apply fix, unleash chaos. If it ain’t broke, wait till I fix it. The circle of bugs continues. Why solve one problem when you can create three?  

        I decided to couch that mouse issue for another time. It isn't as crucial to fix as the other issues. The second issue caused by closing Setpoint was that now there's no volume indicator on the screen when I change volume in VoiceMeeter, other than what VoiceMeeter already gives when you have the window open. But I don't want the window open all the time. I am hoping there's an option to keep it minimized to the System Tray. 

        In trying to fix the new critical issue of the keyboard keys not controlling volume anymore, ChatGPT suggested going into UEFI and making changes there if I was unwilling to give up Setpoint. So I went there to discover that my UEFI has no option to affect keyboard MACRO keys. I asked ChatGPT what my options were if I gave up Setpoint. This is actually a thing that AI is really good for. If you are completely unaware of fixes or solutions your computer can be configured with, just ask. I discovered YT-DLP because of it. Now downloading my favorite podcast every week to play on my iPhone in the Downcast app is possible again. Web-based video download sites are far less necessary. But it has complications of course. The fix AI offered for this option was to try using MACRO Buttons, a program that runs sort of separate from but is tied at the hip to VoiceMeeter. This allows you to set any keyboard key to do a specific task in VoiceMeeter. 

        This is where my usage of ChatGPT runs into trouble. I rely on ChatGPT to help me with context when I have trouble figuring out how to do what Google says. But ChatGPT itself is not optimized for computer troubleshooting. I have found that Grok is far more accurate and aware of all the little things that are crucial to making things work properly. But Grok has a severe limit. ChatGPT will at least lower you down to the free model when you run out of 4.0 questions for the day or for the next several hours. So I turn to ChatGPT save Grok for tougher problems. And I had one such problem today. 

        I couldn't get the key mapping done properly. I went to VoiceMeeter > Menu > "Run MacroButtons on VoiceMeeter Start", this opened a new, tiny window in the upper left most part of my screen that said Mode: PUSH. I discovered by accident that right clicking is what opens the Button Configuration window > instructions I found online were tough to follow and ChatGPT wasn't helping here, saying to press buttons that didn't exist. I didn't understand the code I was supposed to enter, but I first tried "Strip[2].Mute = !Strip[2].Mute" into the "Request for Button ON / Trigger In:" field, I'll just call the request on or off field, there are two respectively. And the instructions I was following online stopped there. I felt like there should be more to do in this window, but I had no clue what I was doing and couldn't figure it out. And when you have a problem that could be anywhere, you try to attack the most likely issues, and for some reason I just didn't think to see what everything in this window did. 

        I kept pressing the mute button on my keyboard and nothing happened. I tried holding Fn (Function) and then mute which is also the F10 key. In the main VoiceMeeter window, there were several button looking things that contain an R inside rounded squares, which would light up every time I held Fn and pressed the mute key. But it didn't do anything. VoiceMeeter knew I was pressing a button but it wasn't mapped to do anything despite this code. 

        After a great deal of troubleshooting, I accidentally found the apparent fix for my setup failing yesterday. I had gone into Sounds on the desktop again > under the Recording tab, selected the Microphone USB Audio CODEC > Properties > Levels tab > turned the microphone gain down and pressed apply and then the laptop audio playthrough on the desktop was working again. This does not explain how I lost it in the first place yesterday but this resolved all of the issues of no audio and then allowed me to turn the gains and volumes up again on all other devices. 

        I didn't understand the code I was entering into the Request field in the Macro Button config window, and wasn't able to wrap my head around it yet when ChatGPT suggested I go back into the Macro button config window and change the code in the request on field to "Strip[2].Mute=Toggle" This also didn't solve the issue. I asked it if I should enter anything into any other field and it told me to enter something into a field that didn't exist and then blamed this on the version of VoiceMeeter. After a great deal further troubleshooting I finally switched to Grok and it told me to name the button, switch Button Type to "2 positions", and until then I had been trying to get F10 to work for the mute button and 11 for volume down and 12 for volume up, but then the FN key needs to be held and I want this to work. 

        I was just about at the point when I was willing to use the FN key when suddenly I looked at a dropdown next to Button Type called Keyboard Shortcut, which had already been getting some of my curiosity, and when I clicked it, a long, long dropdown of every possible keyboard key appeared for selection. I scrolled to see what all there was and I found a section for media keys, and I saw mute, volume down and volume up. I decided to go with Mute instead of F10. 

        Then after some time with Grok, it became clear that STRIP in VoiceMeeter refers to the different inputs. Bus also has a specific meaning. ChatGPT had suggested I use a BUS command but this actually mutes the entire works, the command it gave would mute the BUS (output) that exits VoiceMeeter to the video card HDMI output, leading to the AVR. Everything is being routed through VoiceMeeter now, so this effectively mutes everything and also strips all typical windows shortcut controls to audio such as the keyboard hotkeys which include the media keys (mute, volume etc.). 

        I initially wanted the media keys to affect audio from both the laptop and desktop. But my decision to focus on just the desktops audio caused me to not see that the BUS command was the issue because buses (A1 through A5) are outputs. STRIP is the new necessary command. And I was using bus 0 for this command which affected the HDMI output of the whole machine as far as VoiceMeeter was concerned and I didn't know that yet because the way I learn is sort of like putting the cart before the horse. 

        I can't wrap my head around things if I don't fully understand what they do in practical terms. I suppose that sounds normal until I explain that this requires me to use things before I learn what they are or do or how they work. You can't just say the plus sign adds, there's zero context. If I use a calculator and I see that one number with a plus sign increases the size of another number, I start to see how it works but I still need to learn how it does it and in what way. This only happens if I use it. If I learn it out of that order then I am just memorizing totally abstract information that I have no place holder for. So I use something by following instructions or playing with it, and the understanding comes later, like when you reflect back on things and you see the whole picture afterwards. If it is tech related, I keep this blog and it forces me to go back through everything that I did. And I don't want to go back through this trouble again unnecessarily so always leave myself my own instructions with everything I do in some fashion. 

        Anyway, STRIP 0 has a whole other meaning than BUS 0. I had been messing with Mute for a while, decided to move on with volume down, and it took some messing around but I finally discovered that the command Grok gave for me to enter into the request on field to mute the desktop was "Bus[0].Mute=1;", and then this worked. And after this I slowly started to understand. But I wanted to not mut ethe laptop and instead just the desktop so after some messing around I figured out that desktop audio was coming through the first virtual input in the main VoiceMeeter window and when I pressed mute, the mute button on one of the other strips or buses or whatever had the mute button light up. I asked Grok what the name of the feed was called for virtual inputs and after some time finally discovered that Using Strip[2] targets an input, but you want to control the output (desktop audio to Yamaha AVR). Bus[0] (or the correct bus index) is the right choice for muting and adjusting the gain of the HDMI output. And then learned that STRIP[3] was the first virtual feed code for the command for the macro key. Grok gave me "STRIP[3].MUTE=1" to enter into the "Request for Button ON / Trigger IN:" field and then in the "Request for Button OFF / Trigger OUT:" field enter "STRIP[3].MUTE=0; and then check the Exclusive Key checkbox so this keystroke doesn't do anything else. Unfortunately, opening Setpoint again overrides this checkboxes affect on the system. It worked!

        Then I did the same for the volume buttons. I accidentally expanded the Macro button window to discover that as far as I expand the window, the more large blue buttons appear and each one can have one macro key assigned to it for VoiceMeeter. I clicked a new one, named it, instead of 2 positions in the button type field, I selected Push button, in the request for Button blaw blaw blaw field I entered Strip[3].Gain+2;, and then for volume down the same but entered -2. Mute worked for the correct thing but volume up and down didn't do anything. Then Grok suggested that the code might be wrong. I gave it the code and it said yes, the equals sign is missing. for volume up go "
Strip[3].Gain=+2;" and volume down go "Strip[3].Gain=-2;". They both worked. Now the problem that i may need to change volume quick before roommates complain, how do i get it to lower the volume continuously if I press and hold the volume buttons. Grok had me go to the TRIGGER section at the bottom of the configuration window, with TRIGGER, Strip, In, Out, Hold, and level option. It had me click the checkbox to enable under Trigger, and in the Hold field, enter Repeat, it actually had me enter three words and repeat was one of them but after closing it and reopening the config window it replaced that with 10. Then later I found further instructions I missed which suggests in the Request for Button etc field I could enter the script "while(Trigger) { Strip[3].Gain-=2; sleep(100); }" for volume down for example.

        There are other fixes I could install for getting an on screen volume indicator but that's for another day.

This has been Truncat3d 00000000111100010100110______________end of line

Wednesday, May 21, 2025

2025-05-20 - Active Directory 2.0 - Promoting WinServ2025 to a Domain Controller

        After the Add Roles and Features wizard was completed, the server had installed Active Directory and rebooted, I clicked on the yellow triangle by the flag icon at the top of the Server Manager window, and under that, selected Promote this server to a Domain Controller. This opened another wizard giving the option to add a new Forest. 

        A Forest is the entire AD structure which is a database, which is the top of the hierarchy. One or more Domains are units inside the Forest. After selecting to add a new Forest, I gave the domain a DSRM password which you would only use rarely but if AD breaks you'd need to use. I gave it WinServ2025 to keep things simple since this is only for learning and will not be doing anything sensitive. Although instructions told me I should use 12 characters, upper and lowercase letters and numbers and symbols. I only had letters and numbers, 11 of them, and upper and lowercase letters. I don't know why it worked but it did. In my experience with Windows Server's Server Manager so far, if the field doesn't meet the criteria set, then it doesn't let you proceed, and neither does Proxmox for that matter. So these instructions must be wrong in that regard. 

        I got a message saying "A delegation for this DNS server cannot be created because the authoritative parent zone cannot be found. But I am skipping past this, there's no  parent DNS zone like .local on the internet to delegate from and my Proxmox setup isn't running a higher-level DNS server that could delegate to testlab.local, which is what I named it. It asked me to create a DNS delegation, which I called testlab.local since I'm bad at naming things. The wizard had me confirm the the NETBIOS name, which had TESTLAB in capital letters, which will always use the first part of your domain name. I simply confirmed it. On the Paths page, I left everything default since I had no reason to change it. I then got two warnings, a Static IP Warning saying my network adapter needs static IPv4 and IPv6 addresses. I already had a static v4 address, and fixed the v6 address problem by disabling IPv6. The other problem was a DNS delegation warning. External DNS servers won’t know how to find my testlab.local domain, but I will ignore this for the purposes of my AD project. I pressed Install at the bottom of this page. 

        In trying to understand the DNS delegation problem, I did come up on something I could install that would stop the warning from appearing every time:

Install-ADDSDomainController -NoGlobalCatalog:$false -CreateDnsDelegation:$false -InstallDns:$true -DomainName "testlab.local" -DomainNetbiosName "TESTLAB" -SafeModeAdministratorPassword (ConvertTo-SecureString -AsPlainText "YourPassword" -Force) -Force:$true

        But I'm not doing this because I want everything to happen the same way it would unfiltered in the workplace. I am aware that installing this may very well just stop this one warning and in reality in the workplace if I just got the system running properly and needed to make this domain searchable by external DNS servers, then this warning would not pop up, but I don't know enough about this to say that it's a good idea to stop this warning from appearing. 

        My friend Matt Petersen is helping me with this, and suggested that I learn about the error. And Doug, my former instructor showed me a webpage for learning Active Directory so I have navigated to it to look at it:

https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/plan/understanding-the-active-directory-logical-model#main

        Instructions I am following said to open the CMD in Windows Server and enter:

echo %USERDOMAIN%



        This returned "TESTLAB", which indicates the server successfully recognized the domain I just created. It's an active directory domain and the machine is properly joined to the domain, the promotion worked! I have an Active Directory!

        Initially, I wrote that the promotion to DC (domain controller) worked, I didn't know that officially meant I had an active directory. 404 plan not found!

        This isn't exactly promoting the server, but since I imagine my evaluation period for windows server is going to be up in the next month or two, i looked up how to back up my progress so i can simply transfer it to another VM or whatever. So in the Proxmox interface, I clicked Datacenter in the side-pane > Backup > Add, which produced a window to back it up. Unfortunately the picture I provided was grayed out because I had already done something in the backup window I didn't want to lose and decided to capture this image so I moved it to the side while I grabbed it. 


        In the backup window under Node, selected Poxmox, Storage set as Local, and in schedule, it didn't offer the exact time I would have preferred, instructions online suggested the same scheme used in Cron on Linux, so I typed "0 2 * * *". "where the first star represents the minute (0-59), the second star represents the hour (0-23), the third star represents the day of the month (1-31), the fourth star represents the month (1-12), and the last star represents the day of the week (0-7, Sunday-Saturday)." I was led to understand that everything in Proxmox uses military time, Cron syntax, and the three asterisks means daily. 0 = minute 0, 2 = hour 2 (2 AM), * * * = every day, month, and weekday in another thing. It kept giving me n error 400 no matter what I did. Another thing said you can't just enter 02:00 because it wont work every day. But I found a page online where this guy explained what I was doing and just entered 21:00 for his backup. Then I went back to the field in Proxmox and looked at the dropdown menu options I was dissatisfied with. I selected everyday 21:00, and it simply displayed a straight 21:00, which I changed to 02:00. Since I selected every day, I would assume that this would carry with it some sort of indicator, a series of symbols the asterisks or whatever if it didn't automatically do this every day. No symbols, no syntax of any kind. So I entered 02:00. 

        Now in reality I couldn't get it to work and was trying everything and entered just straight 02:00 and pressed okay and it took it, and then tried a few more things to discover that you can't change it once it's done, which lines up with my experience with hypervisors so far. And since I then learned later that 02:00 apparently stands for 2am every day, I stuck with it thankful I didn't have to go back. I will see later if this is automatically backing up each day. 

        In the next field I went INCLUDE SELECTED VMs and check marked the VM below in the window below. I had several VMs that I developed in order to troubleshoot the BIOS problem that kept me from installing Windows Server, and when I found out about workarounds and SeaBIOS, I created several VMs to test all these, I don't want them backed up though. I just know now to use SeaBIOS because of the TPM 2.0 problem. ZSTD for compression which Proxmox says is fast and good, the other options are good or fast. Without doing research, draw you're own conclusions. 

        The last field is more interesting, Mode, which has the option to do Snapshot, Stop or Suspend. 

        Stop: the VM is shut down completely during the backup, then restarted afterward. This is Safer for good, consistent backups but causes downtime. I like this best for lacking issues and am used to logging in every time anyway. Suspend: The VM is paused (frozen), backup runs, then resumed.
Less downtime than Stop, but can cause issues with some apps. Snapshot: Uses Proxmox snapshots to back up while VM runs. Fast and no downtime if guest agent is installed and supported. Might cause data inconsistency if apps aren’t snapshot-aware. Since I don’t have the guest agent set up, Stop is the safest. 

This has been Truncat3d 00000000111100010100110______________end of line

Saturday, May 3, 2025

2025-05-03 - Setting up my VPN again after a move

        What a nightmare that was. It worked fine with the exact same settings before the move, post move, same internet service provider (ISP), it simply wouldn't work. This time the roommate that has dominion over the router settings is a nice guy that just isn't hardly available ever, except for a brief window at night after he comes home from what I assume is work, having been gone for nearly 12 hours, and after he takes his shower and before he goes to bed. I texted him and he said he'd be home at 11PM and I got there 45 minutes late. He had already taken his shower and I just managed to catch him ten minutes before he was going to bed. 
        When I was looking for a place to move, I was under the gun. I had a place lined up and it fell through two days before I was supposed to move, and I needed a place with a number of particular things according to my needs but the one that pertains to the VPN is that the internet had to be Google Fiber (GF), not because VPNs require GF, but because I know that if it is GF, and not Xfiniti, which I have heard mixed things about but regardless of this, the thing that really matters to me is that the ISP does not use CGNAT. I can't tell where Xfiniti uses CGNAT, but I do know that they do us it. I tried to figure some things out on my moms laptop so she could access my VPN. Now CGNAT doesn't stop you from accessing a VPN based on a connection that doesn't use CGNAT, but the VPN cannot be on an ISPs lines through CGNAT. 
        My understanding about CGNAT is that when I was setting up my VPN with my instructor, Doug, I was also learning about NAT, Network Address Translation. IN a router, this separates public IP addresses from private IP addresses, and consequently, translates between them. So I have a computer o my own network with an IP of 192.168.50.153 for instance, I google something, that query will go to my router or up the chain in my private network to my router which is the gateway to the internet, which is why they call it a Default Gateway address, it is the inner private network address of the router, and will usually be 192.168.0.0 or something like that, depending on circumstances. I have a double NAT because I have a router plugged into another router. All this means is that the first router that belongs to my roommate will give a portion of its subnet over to my router, but it'll be a small portion, in my case the third octet if .50, and I get all 255 of those addresses, but my roommates router will keep the rest of the subnet for itself. Anyway, so the google query will go to the default gateway IP address which is my router, get translated through NAT to the network addressing scheme of the network that router is inside of, so it'll leave the .50 subnet of my network and enter the broader private network, and then it'll go to the default gateway address of his router, go through NAT, the firewall, all of that stuff and get translated into whatever my public IP address that faces the internet, and then it'll traverse the public network from one router to another until it reaches the server that has the desired information, then that information will be used to create a new set of IP packets which will carry all the data back to the place that my query packets said they came from, which is where the new packets will be mailed to. They will make their way back to my roommates router through the public IP address, a temporary port in the firewall opens to let them back in, they will get translated by NAT back into a private IP address that the network my roommates router knows and then send it to my router at .50.0, and then through NAT in my router and the firewall, and get translated back into 50.153 to the device the requested the data. Now if the ISP had a CGNAT, which is a carrier-Grade NAT, what that means is some ISPs will save money purchasing public IP addresses, there are after all only so many public IP addresses, especially IPv4 addresses, which is still being used because IPv6 is harder to use long story short. CGNAT is the ISPs own NAT, where they buy just a few public IPs instead thousands or millions of them like GF, and then they will convert public IPs into their own pool of public IPs through their industrial grade NAT, and if you have Xfiniti, then you will get one of their GCNAT based public IP addresses. This causes a problem for someone like me. If I want to have a VPN, my server cannot be behind a carriers CGNAT. CGNAT, to my understanding, has a firewall attached to it, and only one service can usually be assigned to a port in a firewall. And so if a few thousand of Xfiniti's customers had VPNs, only one of them would be granted the port-forward. If you can only do one and thousands on an ISPs service want to do it, there's a problem.
        Okay but before you call me out, I will admit that yes, you can do a VPN behind an ISPs CGNAT. I don't know how to do it but so far when I was trying to set my moms laptop up so I could access it remotely and it wouldn't let me do an Anydesk remote connection, I found out this was because of the CGNAT. Now I don't know if maybe I just activated a full tunnel on my VPN and then did it that maybe it would work fine, but a whole host of problems could happen that would render the VON ineffective, and that is why I set up Anydesk. So Anydesk needs to function regardless of the VN and it wouldn't. Turned out my mom had a number of problems while on Xfiniti, and a lot of them being because she was sold a whole package for Xfiniti with her apartment lease and so she got phone and cable and all sorts of stuff, and she had a variety of problems that may or may not have had to do with Xfiniti and the way they do things, which is different from ISP to ISP in many cases. So when she switched back to GF, the problem went away. I can't remember how I concluded it, but I somehow deduced or did research or something and found that CGNAT was likely responsible or something. 
        Okay, so the reason why wherever I go, they must have GF, is not necessarily because I can't make this work without GF, but because I know it works with GF. And there are a lot of things I don't want to change. For instance, I know there are other ways to access my internal network and file server and all that other than through a VPN. But the VPN is the way everything is set up, it would require a whole overhaul to do something else, such as the method being used and what can be accessed, I am comfortable with my current set up, I have reasonable expectations for it, and even when I have requirements that go beyond those expectations, I am often pleased with results, and I know what these reasonable expectations and limits are most of the time. I would essentially be throwing away everything I already know and established and have to use new methods with unknown limits and still have my expectations and they may not be reached if I use other methods. I would expect that if you had an organization that was used to using VPNs and they seemed to work great most of the time and then you decided to go with an all new method no one knows how to use, that can't be expected to do everything and even what it can still do may require new methods on top of the new access method just tog et the same results, the company would sort of be in chaos and day to day function would be severely inhibited. I have the advantage of being one person but VPNs are not exactly uncommon, they are used everywhere and have many functions. It would serve me to continue to use it. I have often thought that my VPN may be the thing that gets me hired somewhere because of the amount of crap I have had to go through whenever something went wrong. 
        So I had to set up the port-forwarding on my new roommates router. I went to the router after asking his permission and assuring him this wouldn't affect anyone else, assuming no one else has a VPN at this place of residence, and when I looked on the bottom of the router, there was no admin password credential thing. He told me he had not changed the credentials, he barely knew what I was talking about. So when I found nothing on the router, and then went to me browser and typed in the typical IP address for the routers web interface to access settings, I got error web pages. I asked ChatGPT how you access the web interface on a GF router and it said that it most likely uses an app or website attached to the account that pays for the GF service. I asked the roommate if he had an app or a website he has access to for his GF account and he did, he went to it, and it was the web interface I was looking for. 
        Unfortunately I didn't get to write down the steps we did to find the port-forward settings, but the best I can ascertain is once logged in, we saw a screen that looked like this:

        After that I believe we went into the internet or router options, I think we selected something on the next page like Edit Network:


        And then saw a screen that I believe said Advanced Network Settings > ports:
        Once I clicked on Ports, I believe we found a button that said ADD RULE, and then saw what I was looking for:

        Once I found my .50.0 routers MAC address on this page, and confirmed with my roommate that was the same MAC address, I saw a page similar to this:
        


The Device at the top was my routers MAC address, the service I selected was single custom port, because I am only doing 51820 and not a range, I selected TCP & UDP despite ChatGPT insisting WireGuard only uses UDP, so I think I will go in and change it to just UDP since I believe this does open me up to potential hacking. I put 51820 in both the below ports that said external port and again in internal port, and had my roommate save it. He then asked again what this does, because he wanted to be sure this wouldn't affect anyone adversely since he's responsible for it and I explained that I have a file server, I asked if he knew what servers were and he said yes, and I explained that to access my file server remotely, I needed to open a port that would let me send stuff through my VPN, both inwards and outwards, and that is what we just enabled. 
        Now that was the easy part. I told him I had to test the connection to make sure it worked and went straightaway to do so. But then I turned on my half tunnel as usual and it was receiving no packets as usual when there was a problem. I rolled my eyes. What now! After a few minutes, oh, I hadn't changed the settings in WireGuard on any peer (remote) devices such as my phone and laptop and my moms laptop. So I went on my laptop, into the tunnel settings after looking up what my public IP address now was, I entered:

    curl -4 ifconfig.me

        I put that in the endpoint address under peer settings in WireGuard on my laptop and did the same for both the half tunnel and full tunnel, then changed it on my moms laptop remotely through AnyDesk, then on my phone. 
        Then I tested it again and it didn't work. No packets received. I verified that the server was running properly, I went locally and accessed the file server through SMB, and the file server is the same device running the VPN server. I started trying to troubleshoot the issue, and didn't seem to solve it. 
        The next day I continued researching and looking things up, I had verified everything I could think of, the port forward was done under my supervision and I confirmed the MAC address of my router, I then had also asked my roommate to send me a screen shot of the configuration, which as you can see above, he did, and I confirmed the PAC address again, I asked ChatGPT if setting it to both TCP and UDP would cause this problem and ChatGPT thought it might but I said, it worked perfectly like this before I moved, and then it said, well, it most likely won't cause problems  but it is unsecure. I checked the settings on my router, I made sure all my IP addresses were the same, the file server was obviously serving files so anything server related that was no my separate Proxmox server had the proper reserved IP, I can't think what else I had checked, but I had checked everything I could think of. Oh, I also went into the wg0.cong file on the VPN server and checked to see if there were any public IP addresses that needed to be changed, I didn't find any, ChatGPT thought this was strange and then admitted that the way I was using it, having endpoints in the server side was unnecessary, and then I asked Grok 3 and it said yes, that's normal, I then switched to Grok 3 because it troubleshoots better than ChatGPT. I only prefer ChatGPT because despite the 4.0 lite query limits on ChatGPT, it switches automatically to 3.5 and keeps letting me ask questions and I don't see much of a difference in the way I use it. But Grok seems to have a hard limit for several hours that absolutely stops me in my tracks and it doesn't even revert to a lower model so any progress I had made absolutely stops. I can't abide that. And I will not be nickeled and dimed out of my entire paycheck. So despite Grok 3 being the better choice for me, ChatGPT doesn't set the hard limit and so it gets all my use. 
        The next day I had decided that since the last time I had VPN issues, the thing that fixed it was rebooting the router, letting the power drain from the capacitors first, I would do the same on both my router and my roommates router. But I asked him if he could do it at a time that affects everyone the least, and he just didn't even get around to it when I happened to check my VPN randomly and suddenly it worked. He told me he hadn't done anything and I hadn't rebooted my router yet either, so I really don't know how it got foxed. The only thing I can think, which I then asked Grok 3 about, was if it is a thing for routers to only update the port forward settings at the start of a new day or something, it said at first that whatever words I used for this scenario sounded very unusual for networking, but then said that it is common for routers to update all the settings after a few hours. I know I checked right away after setting it up and it didn't work and I can't recall if I checked the next morning. I might have and it still didn't work but I don't remember. So whatever the problem was, it works now. And I had insisted many times to both ChatGPT and Grok that my VPN worked fine before the move, same ISP, right down to the way the port forward was established, it looked the exact same as it did a year and a half ago when Robert my former roommate did it for me back in October or November 2023. So they admitted that then it should be working. I went through everything I had confirmed and everything checked out. Everything! But then t started working fine the next day. 
        There is one caveat, I can no longer just leave half tunnel activated on the laptop. It simply won't work at all if I am at home, on my network, plugged in or on WiFi, and either tunnel is activated. I didn't have this problem before. 

This has been Truncat3d 00000000111100010100110______________end of line

Friday, April 18, 2025

2025-04-18 - Active Directory 1.0 - Installing DNS, File Storage, ADDS, and ADLDS in case

        I am finally seeing what I can do to commit to learning Active Directory while the VPN server is up and running, since it seems like every month or so, something goes wrong. And right when I sit down to do AD, I can't because the VNPN is down or something. I am doing this remotely because everybody at BYU is studying or doing something for class, trying to learn, studying, so I prefer to do this in that company. 

        I had some trouble getting the Proxmox VM for Windows Server 2025 up and running. The problem was resolved in the 0.5 entry from back in February. 

        But now I am in the Server Manager and trying to install the DNS and File Storage roles. In the Server Manager you go to the Manage menu on the top right of the window > select Add Roles and Features. This will be a role-based installation. The reason is because out of the two options, the second one being  Remote Desktop  Services Installation, the one you will be picking most often will be Role-Based. You would only choose the other option for obvious reasons. If in an office setting and configuring systems on site, pick Role-Based. 

        I selected the roles DNS and File Storage and then a message popped up saying 

Validation Results
The validation process found problems on the server to which you want to install features.
Click Continue install the selected features anyway, or click Cancel to select different
features.
Validation
Server
Results
@ W WIN-BCCTlROV6RS
No static IP addresses were found on this computer. If the IP address changes, clients
might not be able to contact this server. Please configure a static IP address on this
computer before installing DNS Server.

        So I went to Control Panel > Network and Sharing Center > Change Adapter Settings > right-clicked on the ethernet adapter > Properties > Internet Protocol Version 4 (TCP/lPv4) > Properties. I decided to add an address from my actual home router running DHCP for my home lab, so I went to the CMD > ran IPCONFIG /ALL > grabbed the IP address 192.168.50.191 and the default gateway of 192.168.50.1 and the MAC address for my Proxmox server that's running the Windows Server VM. I selected UUse The Following IP Address > added the IP address ending in .191 to to the first field > subnet mask fills in automatically depending on what address is used > entered the address ending in 50.1 in the default gateway field which is the private IP address of my router, and also added the same address as my preferred DNS server. Whatever request this server has from the internet will be forwarded to each successive DNS server until it hits one that knows the address of any site I visit. 

        However, I decided to also reserve that .191 IP address on my router. You require a static or reserved IP address for the server so anytime a machine boots up or a device returns to the network, the server managing Active Directory will always be at the same address and the corresponding devices connected to it won't have connection errors to the server--expecting the server to be at a different address. 

        However, I ran into a bit of a problem. As WinServ2025 is hosted on a Proxmox server, and the Proxmox server is already reserved automatically on my router, which is an arrangement they came up between them and I cannot change it, this also means that the same MAC address that would be used to reserve this .191 address is already being used to reserve the IP address for the Proxmox server. Research suggests that you want to have a separate IP address for the Windows Server than the Proxmox server, so this is where I get stuck. Technically, the requirement to make the .191 address static has been met. I can continue, but there's nothing stopping the router from assigning that address to yet another device at any time in the future. 

        Normally, you would either make an address static on the system using it or reserve it on the DHCP server, the router in my case, since all consumer grade routers are combo devices, with a layer 3 router, a layer 2 switch built in which is what those four or five extra ethernet ports on the back are connected to, a layer 2 access point which is the WiFi antennas, layer 3 DNS server, which converts between hostnames and IP addresses, a layer 3 DHCP server which dolls out the IP addresses on the private network, a layer 3 and 4 Firewall, which includes NAT or network address translation, which separates public addresses from private addresses, which is why network addresses and gateway addresses matter. 

        This was cleared up, I both made the address static on the server which allows me to do AD, I think it was the domain or the DNS or something tat required it, and I also reserved it on my router by going to the WAN tab > DHCP > and the dropdown menu where I reserved my file servers address didn't show the virtual Proxmox Windows Server VM so I just added it by typing it in and the router accepted it. There was a reason why not to make an address both static and reserved as I recall but I had asked ChatGPT about this and explained the problem with only making it static on the server side, that DHCP on the router might assign it a new address and it seemed to agree this was a good idea to also reserve it on the router. 

        If you want to skip a future project idea I have that AD caused me to think about, skip any of the following that's in italics!

        I ran into an interesting snag. I had this idea, stemming from another idea I'd had for a very long time. In short, I have always thought that the ultimate computer experience was totally handheld, portable, transferrable from one physical console to another, just having like a base computer the size of a smartphone or really anything that fits in your pocket, that can handle pretty serious computer tasks, but may possibly fall short in some ergonomic ways for the lack of a better term. I wake up at the beginning of the day, my phone is my alarm clock, it actually displays the time which interestingly, the iPhone now does when charging and positioned horizontally, it holds all your music, everything you would watch, the whole experience is very personalized, everything you would look up is or rather can be through it, you may have a slightly less portable device like the size of a laptop that you can somehow insert it into or that acts like a docking station that provides a larger screen and keyboard and mouse functionality, when it's time to get in the car and go to work, it connects to your car and acts as the radio, or any communication device, I mean, it always does each of these things, but it is the central device that does everything, and all other devices are secondary to it and act as potential appendages to it. It may even control the car. Of course the car may need to control itself, so it might be in constant contact with the phone or portable computer device that fits in your pocket. When you get to work, it is your work computer, connecting to another docking station that is more geared towards productivity, there might be more screens or a larger one, and any other tool needed for the job or desired for comfort. 

        Now, talking about this I find irony that my ultimate choice for a laptop is a GPD Pocket 3 and my iPhone is kind of hinting at a lot of this but this is all still a bit of a ways off even if steam is gathering rapidly. But I had an idea that stems for this that might potentially involve a personal project possibility for AD. I wondered if there was a way to centralize my computer experience on my laptop and desktop so that whichever device I am using at the time, it picks up where the other left off. I realized that Active Directory had some potential use for this and ChatGPT confirmed it up to a point. However,  specific programs running and icons placed in the same spot on the desktop on each device, and things like that would not be possible. ChatGPT suggested that this could still be somewhat managed with effort, there are other tools that could help realize this dream. And it quickly got tot he point in my conversation with ChatGPT that it was like, well, perhaps you should consider this other program altogether, and part of my idea was lost. And then it was revealed, that if I used Active Directory to realize this dream, there would be one huge problem I am aware of so far, so there could be others, but one glaring problem that stops this in its tracks is that every time I started using one device or another, there would be an immediate and huge requirement for bandwidth between the server hosting AD and the machine being used, to get the environment set up for my use. Being remotely used so frequently, my laptop cannot be subject to this. I often rely on either my hotspot on my iPhone which has a limit that I am very cautious not to rush through, and established WiFi at places like BYU where I study or eat. And that WiFi also has its limits. So this is not feasible. 

        And then I was about to start exploring the thing with adding roles and features to get AD up and running, and I had passed through this screen many times now, having explained it about six months to a year ago in former blog posts about AD. Role-based or feature-based installation vs Remote Desktop Services installation, and I remember the reason for not using Remote Desktop Services Installation was because this is for remote users and is used far more rarely. And I wondered what if I created a virtual machine-based session-based desktop deployment. 

        I wondered what if AD VDI centralizes a single desktop experience on a server that multiple devices can access remotely, such as my laptop and desktop? Log into the same Windows environment from either the desktop or laptop. All my apps, files, settings, even open windows, are exactly as I left them. It's like having my main PC live in the cloud or on a server, and you just remote into it. 

        However, then I came up on a realization, wait, couldn't I just install windows 11 in a Proxmox VM and remote into it for the desired results? And the answer is yes. So I asked what the benefits of using AD over the win 11 Proxmox approach would be and it said basically no multi-user environment and I can't think of any instance where I would need to access one instance from two devices at the same time, and scalability, there's only me so that's out, load balancing, well, if it's just me then load balancing on a server powerful enough to handle any task I might want to perform is already automatically balanced by the fact that it's just me using it and then app publishing, well, I wasn't sure about that one. But I don't typically create apps. I do have a project in mind to do so just for academics but that's it. So now I am just wondering if I aught to simply have one desktop environment that I remote into? I love that I can use everything on one powerful server, so no matter how demanding my photoshop requirements get, no matter how many chrome tabs I have open, this will stop being an issue. 

        But this then causes me to wonder, like, one of the things that makes me dislike services like Spotify, and paying for them, and the subsequent data requirements on a hotspot is that I can simply have my music or movies on my mobile device and not keep paying for it every time I want to use it and then be chained to the internet just to do so. I would essentially be creating my own prison again, and I would still have to pay for it because of hotspot data needs. 

        However, I started thinking about things like iTunes, while it would be great to be able to run my iTunes library from a centralized location that can be accessed anywhere, and not have multiple machines to maintain which is why I killed iTunes on my desktop and only maintain it on my laptop, but have reinstalled it only so I can game and listen to music with game audio on my desktop, which requires me to run my laptop simultaneously to have access to my laptops library, if I then moved it to a centralized VM, this would then present those roaming challenges where I would require being constantly tethered to the internet in order to do basic things. I conclude for now that this is something I should do but only to a hybrid extent. Run everything on a central server that would not be inconvenient to do so in any way and keep local functions such as movie playback and iTunes local on each machine respectively.  


        2025-05-20

        I went to Add Roles and Features and clicked right through most of the wizard, and checked DNS, ADDS, and ADLDS, didn't add any features except that I checked to make sure Group Policy Management was checked, which you'll need if you'll be working with GPO's. .Net Framework 3.5 is for legacy apps. I'm not worrying about. I clicked install. It took a moment and then when I returned to it, it had opened a new folder located in Windows\Server Manager, with files called serverlist and serverlist1, I closed this window. Server Manager will keep these files to remember which servers it  manages. 

This has been Truncat3d 00000000111100010100110______________end of line

Monday, April 14, 2025

2025-04-14 - VPN Server Went Down Again!

        I was seriously starting to feel this time like if this darn thing can't stay up and running for even a month without there being some problem that takes a ton of effort to troubleshoot then the thing isn't worth using. I also concluded if I just reinstall PiVPN with WireGuard (WG) and then WG on every corresponding device that uses the VPN again, that would likely solve the problem. But this was only after exhaustive troubleshooting that went nowhere because nothing was wrong. There were no catastrophic failures, no brown-outs, no drivers, Kernels, Os's updated that would then throw it out of whack, And after multiple days of putting Proxmox Active Directory VM's aside--because everything I have centers around my VPN functioning properly, I had then concluded that just reinstalling the thing would almost certainly fix the issue. 

        I even had a friend come over that the first time he helped me with my server like three weeks ago or so, the second he sat down, the problem was cleared up because everything that was wrong with my server just vanished. It would turn on before but there was no POST light flickers from the keyboard on boot, the motherboard was just as lively as ever, but no screen output because its a server that runs headless and so when you plug something in, nothing shows up unless you reboot, and nothing worked now because tried to reboot not knowing it was doing a Kernel update and then apparently temporarily bricking the server for the next whole day until it sorted itself out I assume, then it could be rebooted and produce output for a monitor and we could enter BIOS and there were no problems. The server booted fine, everything worked perfectly as if nothing had happened. Weeks later when I tried again to do my TEMPer2 project to get a USB temperature sensor to read the temp of my room and connect to Home Assistant to then connect to my AC to trip the AC on or off, only then did I discover when running a command to check the latest version of the Kernel was installed, and it saying yes, that in fact no it was not, because then I had this problem and the boot took an inordinate amount of time while trying to see if rebooting would solve the VPN problem. I couldn't SSH back into the machine for maybe twenty minutes I think, well, that's when I tried to SSH in a fourth time anyway, and it finally worked. And that was a few days ago during the latest server troubleshoot for the VPN. 

        So once again we go through this problem, I couldn't use my VPN while out remotely, and working on my Active Directory project to make myself more hirable. And I couldn't connect. I was at BYU trying to connect to internet, sometimes it doesn't like connecting to the captive portal so I can agree to terms and conditions for visitor WIFI unless I turn off my VPN in WG. SO I turned it off and connected and then I turned it back on and it still wasn't working. But I just connected to it. What do you mean there's no internet? I checked the WG client and saw that neither tunnel would receive any packets back from my VPN server, X amount of Kb sent, 0 received. I tried then to turn off both WG tunnels and AnyDesk unattended into my home desktop and couldn't do that either. What's going on here?! I discovered after troubleshooting when I got home that in fact I accidentally deleted my token or key authentication account for unattended access to my desktop when troubleshooting another problem for my mom a few months ago, within the Free app I use I have been using this free authenticator app for years because I didn't know there were better, free options. But with this option, there was little documentation online of how to troubleshoot it, and if you created a new token or key or whatever account to use for any particular thing, which you could create several for different devices, you couldn't rename the very easily. I found this extremely frustrating. So I switched to a very popular free one called Microsoft Authenticator offers which does let you easily rename "accounts", as long as you know they call them accounts. 

        Okay so then I got that back up and running. But then I spent hours and hours troubleshooting the VPN itself now that I found I could easily ping and SSH into the server, open and use server files on my desktop through SMB, or even on my laptop if I am using the internet in my room with my server, by all appearances, nothing was wrong with the server. If I didn't have a VPN I heavily rely on, I would never know that my server had a problem. 

        But I ran out of ability to troubleshoot. Everything was working fine. No catastrophic events, all WG keys and IP addresses were entered correctly. I am not the best at looking at logs, but I checked them and couldn't even understand most of them, and did my best and still didn't find anything wrong. Every time I googled, I couldn't exactly find what I was looking for in reference to my particular problem. Googles AI Overviews, the thing at the top of most google searches, had more to say than any result I found and even when it sounded like it might be in the same relative neighborhood as my VPN problem, it would just link me to a site with a guy who was like 'yeah I don't know what I'm doing, followed instructions installing WG best I could, donno what I did wrong'. 

        ChatGPT told me whenever I explained the problem there to enter "sudo wg show" and it instructed me to look at the connection status, to see if bits or bytes or whatever was received, and that command simply didn't show anything but that there were various clients with their own tunnels, the virtual /32 IP addresses WG assigned them, the keys would be omitted, and there were no lines showing connection status for any of them. I told ChatGPT this isn't showing status and it insisted that it's supposed to be there and finally told me to check the status another way using "sudo systemctl status wg-quick@wg0" I didn't get far with Grok3 either.  

        I had restarted services several times, turned WG on my laptop on and off multiple times, rebooted the laptop, rebooted the server, that was exciting because it took a lot longer to reboot than it should have which makes me think the Kernel finally updated, I checked multiple logs, I was starting today to start double checking everything because I figured I just had to have missed something simple. My friend came over and he actually is in Information Systems, he is familiar with a lot of Information Technology stuff because I guess his job doesn't have much in the way of IT, he offered his help but said he didn't know how VPN's work so I said that was fine, I do, but I can't figure this problem out. So he came over early this morning and I started explaining WG and VPN's and how packets move on and off a network so he could differentiate from what he already knew, admitting that routing is confounding to him. I explained TCP and UDP, port forwarding, half tunnels and full tunnels and each of their pros and cons, I had drawn a diagram of my physical network that made sense in a logical fashion with the VPN taken into account. And then I drew another diagram of a cloud with a tunnel running through it with my server on one end of the tunnel and my laptop on the other end and explained the keys purpose, encryption, how the routers figure into the tunnel. I showed him the wg0.conf file, which has all the keys, tunnel names, IP ranges, IP addresses, etc. I showed him the tunnel configuration window in the WG client on my laptop and accidentally turned it on and had trouble SSHing into my server and couldn't figure out what the problem was now and then realized, oh I accidentally turned on the tunnel, so I have no internet, he didn't understand why I would have no internet so I explained that since its a full tunnel, everything, all network traffic to and from my laptop now has to go over the VPN except possibly DHCP. Maybe that's why when I connect to internet and turn on the VPN, my WIFI icon changes to a no network icon, because even DHCP can't reach the laptop so the connection is dubious. Then he wondered why it would matter, why if I turned on my VPN while at home, why would the connection have to go back outside my network and back in, and I explained that the WG client has the public IP address my ISP gave my apartments router, so when it looks for my network it has to look for that public IP address, it goes through NAT and the firewall, the firewall will only let it in if the port WG is using which is usually 51820 which is why you'll see an ipv4 address with a ":51820" at the end of it, the ports are all closed by default and only opened according to what you approve, and so if you want to search the internet with unsecured HTTP fifteen years ago or whatever, it was port 80, now it's 443 for HTTPS over SSL almost entirely, and WG gets 51820 by default and anything 51820 will go straight to my server as long as the port forwarding is configured on every router of the network local to the server. Customer side of the Demarcation point. If it's Xfinity, which is an ISP a lot of people around me have, they don't buy a huge pool of IP's for people to use and instead just a few and have their own version of NAT that they then have public addresses they assign to customers, which is why with Xfinity, you can't use a VPN. You would have to either get the only port forwarding their entire pool would allow because ports are usually only assigned to one service for security I assume, and would look that up if I didn't already have a packed schedule. 

        After Robert left and we had run out of time, I had this idea to just ask Grok what the most common problems were that fit my situation and it said that it was most likely either the Firewall or port-forwarding issues, Nat or Routing problems, MTU (maximum transmission unit) mismatch--the maximum IP packet size on ever layer 3 device is configured to different maximum sizes which can cause errors with packets that were already segmented into smaller pieces for network communication and then run into devices that can't pass them because their MTU is set to a smaller size, you really want every device set to the same MTU and if you're sending and receiving from the internet then you want your network to to conform to that, which is 1500 bytes and 1500 or 1492 when taking packet headers and trailers into account is almost always the standard and consumer routers are just automatically configured to this to a lay-person don't have to worry about this. 

        Anyway, I spent about an hour trying to get any one of the last three roommates to have control over the router to help me access it to make sure the configuration is still good because that is probably the one thing I didn't check. With the VPN being such a virtual thing, it never occurred to me to check anything physical except my own plugs in my room. I had internet so there was no obvious clue that it was the router that I was aware of. But I wanted to check. This problem was confounding enough and if I was going to reinstall Pi VPN, I would lose the opportunity to know what the heck went wrong so I can just check that next time something like this happens. 

        My current roommate with control over the internet and utilities said he was in class and was too busy to deal with this right now. He isn't an IT person so he doesn't know that it really needs to be him that does it because he would have all the credentials. I asked him if he could ask Nate who had utilities and internet last to give him his credentials and then Robert before him, and then I rolled my eyes and just texted them myself and already had both of them tell me I don't have it, Nate took over, he told me so, and Nate to say he never got it from Robert, and then Nate to look up his account online to see if he still had the account in his name which he did so my new roommate was no longer needed, and I had never been allowed to access the router myself because Robert was very cautious about messing with things that belonged to him and he had responsibility for and not knowing what he was doing so if it worked, the only ones that would touch it is the technician from the ISP and him. He would let me give him instructions and he would look at things for me, but now it's not even under his control. And Nate was sure he didn't have it either but the account said otherwise. So now he is mad at Brenner and I had to put out a fire when I already had a smoldering mess of my own and so on, so after we got all the drama out of the way, Nate asked for money because the bill that was now currently due that he apparently has to worry about is now due so Brenner and I have to pay thirty five each for the fiber connection. And then he asked more sympathetically, "Did you unplug the router for forty-five seconds?" I thought, no, but I guess it can't hurt to try. 

    So I did, I can't believe it. Everything worked after that. He called back later and I told him about it and then I said it was a good thing this happened because since he isn't exactly rolling in the dough, and didn't know he owed our ISP money, my internet wasn't shut down, the fix to my VPN was simple even if extremely frustrating and confounding, and we hadn't caught up in a while because we actually didn't particularly love living together even though we had almost nothing to do with each other with him living in the basement and me in the attic and so we almost never saw each other. And his entry and exit to the house is faster if he just walks in and out of the front door, and the stairs up to my room are right in front of the back door to the parking lot and I have a car which he doesn't have. So we just never saw each other. So I told him I thought this was a good thing and I think he agreed with me. He has since asked me to help him run an errand and so I have to run. 

This has been Truncat3d 00000000111100010100110______________end of line

Wednesday, March 26, 2025

2025-03-26 - File Server went down again for the second time this month

    Last week, I had a problem with my File Server. This was frustrating because I use it every day and before I go to bed, I like to watch a movie or fall asleep to one on loop. That's not happening without the server. I don't store movies locally. Although I guess I should, pfft! I got this TEMPer 2 temperature sensor I bought in the mail hoping my file server, which also has home assistant installed, could track my room temp and automatically trigger my smart LG portable AC for my room. The temp is different all the time, like it stays out of alignment with the timers you have set for the AC, and you get frustrated with it after long enough that you knee-jerk react with a highly tuned setting for turning on and off regularly to keep the temperature in an expectable range and the second you do that, there's a wide temperature swing like a week later. Then you just deal with that for a month or something before you finally change it again and it changes like a week after that too. And this winter has been strange where I live too because that groundhog said winter was over I think and then the temperature seemed to go up about twenty degrees, then a week or two later we had one of the first snow storms of our entire winter, then a few weeks later, an even bigger snow storm. But I think now it is officially over, the temperature is swinging up into the fifties every few days. 

    So I got that temperature sensor in the mail hoping to configure the server to trigger my AC on and off according to my room temperature since for some strange reason, this AC is so smart that it won't track the temperature like my last AC did. I am not a fan of smart devices, they just don't seem that smart because they frequently miss the obvious thing or they are intentionally programmed to do so in order to benefit the companies that sell them, like the remote for the AC not being so handy, forcing you to use the app, which forces you to wait while it loads ads every time you want to turn the ac on or off without getting up out of bed or something. 

    Unfortunately, my attempts to configure the sensor caused me to have to update a python package so the server could read it, which required a Kernel update, which it told me required a reboot and since I wanted to best results possible right now so I could get it working, I decided to reboot. But I thought for some reason that Linux updated the Kernel before reboot and the reboot simply put the changes into affect, like it gets saved to the hard drive and then after reboot, it gets loaded into RAM for actual usage. So when it didn't immediately finish rebooting, I thought something went wrong, but because its headless, and there's no video signal output until you reboot with a screen plugged in and on, then it will just keep negating the video output. So I rebooted with a screen plugged in. Little did I realize what a huge mistake this was. Apparently it loads during reboot, and I interrupted it mid loading. And so I couldn't SSH into it, for some reason it completely escaped me to try pinging it but it's not like that would have changed much. I knew it was running because the motherboard lights and the CPU fan were on. But after many reboots, no screen output still and I couldn't SSH into it at all after many tries. I left it running and went to bed. I think I tried again after I woke up and it still didn't work. I had a friend come over like a few days later I think and he was running through it with me, starting by trying to access the BIOS which I said, hey just so you know, I can't seem to get any screen output just so you know. And there are no keyboard lights either and I tried multiple USB ports too. So I can't tell that it's actually passing POST. But there's no beep code, and I don't recall it ever beeping when booting so I was at a total loss. And first thing when he sat down and had me reboot, he looked up how to access BIOS on this motherboard and started spamming and then just holding down the delete key for my MSI board. And it worked. The SMI logo appeared big on the screen like when it boots, and then it went into BIOS. Typical! It waited till he got here to work fine. 

    I seriously looked into setting it up to always put out a video signal even if there's no screen plugged in because this one screen output problem has caused me trouble nearly every time I can recall there was an issue in the past year and a half since I built this server.  The problem was very simple. In fact, there was no problem. Now that he was here, the screen turned on, unlike before. Now that he was here and we entered BIOS, there was no BIOS setting to fix, boot drive order was fine. We exited without saving and then it booted normal. I checked to make sure I could SSH into it, I could. I checked to see if I could access filed through SMB, I could. Tss! 

    Then about a week later I realized the TEMPer2 sensor came with a CD ROM probably with a driver to load. I thought, oh, well, since my previous attempts to get the sensor working didn't work, maybe this driver will fix the issue. I did find something online I could install through the CLI, but I wanted to be sure I exhausted all other possibilities before I did it because I don't always install things willy-nilly, just to see if it works and then leave it on there if it doesn't, and I try not to at all because it seems the more you install with reckless abandon, the sooner you'll have to reinstall the OS. So if I do, I try to keep it at a minimum. 

    Well, was experimenting with something that required my DVD burner that I haven't needed in years, and it was an internal DVD burner and my current case doesn't have a place to install the burner. I could plug it in with some effort to take the desktop off its VESA mount and unscrew the pack and access the cable compartment in the back and fiddle with the wires and figure out a way to get this thing plugged in, but then I realized I had a SATA to USB 3 adapter with a 12 volt power plug attached. I bought it for other reasons but this should work great, I pulled it out and started using it and then because I used it for this other project, I suddenly realized, hey, might as well put the driver CD in it. So I did, and then started thinking for some reason how to get the driver software transferred to the server from Windows. I imagined all the difficulty I went through a few months ago when I accidentally deleted a whole folder full of recordings I didn't want to lose because they couldn't be replaced, and thanked my lucky stars when I realized this is why I utilize cold storage and not not just my RAIFD 5. So I accessed my IronWolf I use for cold storage, which I back up automatically once a week, and it was a nightmare accessing it just to pull the recordings off of it and put them back on the RAID 5. Since then I have concluded that I should have just created another SMB share straight to the IronWolf, assuming there's no reason I can't do that. As a matter of fact now that I think of it, perhaps I could just set up some sort of mechanism that will automatically undo any mistaken deletes, just revive them from cold storage just like File History on Windows. I looked it up and that is a thing you can do in Linux, I would have to adjust my Cron job for RSYNC to run once a week to then organize backups according to date and create a snapshot. And then you can just CD to a directory for easy restoration. But I want something with easier access that doesn't require SCP. Well, I suppose this would make for a good opportunity to get good at using SCP. 

    So I had this idea over the past week, why am I struggling to find the will power to transfer the files from this CD to my server from my Windows desktop, when I can simply plug the USB 3 adapter into the server for the DVD burner? So I did. And then I was going to work on it remotely when it just didn't work out that way. I am supposed to be studying my butt off to pass y Network + certification these past few weeks so I can take it end of this month. But I had a migraine from a dietary issue I had, which is taking days to go away and it went away briefly after a heavy dose of medicine so I thought, well, this driver issue has just been sitting there waiting for one spare moment, how hard can this be. I mounted it, I explored the contents, and I discovered the driver was in msi format. I started to think this might be an issue because Linux doesn't read .msi, which is meant for Windows. There was a thing I could try but then I thought I would put it down for now and go to bed since it was the end of the day, and then I discovered that my server was totally inaccessible from my Windows desktop I watch movies on before bed. And then I discovered it was totally inaccessible from my Windows laptop too. I could SSH into it no problem, SMB was running, I rebooted my laptop even though I didn't think that would fix the issue because the problem seemed to happen at the exact same time for both Windows computers which is a fantastic coincidence when both are trying to access the same common file share from the Linux File Server, the common denominator. The only thing I know happened was that I mounted the DVD burner in Linux. I looked online to see if that could mess up a file share and the internet said "Yes!" It seemed strange to me that just trying to access a drive could interfere with a share on an unrelated drive. I rebooted the server, nothing. I was out of options and unmounted the drive. That didn't fix anything either. I was just about thinking at this point, well, Robert will come here again and sit down for five minutes just for the server to be like, "What? Misbehaving? Me? You're mistaken!" for the second time. And then when asking ChatGPT about this problem, it suggested rebooting the SMB service. So I did that too.     

    sudo systemctl restart smbd

    sudo systemctl status smbd

    That fixed it, the share worked just fine again! Gah! At least it only took one hour to fix this time. 

This has been Truncat3d 00000000111100010100110______________end of line

2026-05-10 - MWB constant reconnect fix and all other ultimate fixes until now for my whole home computer setup

     Now I was fixing a problem with a couple things that annoy me on my laptop. Every once in a while I manage to fix another little thing ...