23 articles

Unifi SSH Guide

SSH deployment methods involving Ubiquity network devices.

UNAS Pro Custom Fan Control via systemd

Deploying a PWM-based fan control script on the UNAS Pro NAS using a community systemd service, with custom temperature targets tuned for Seagate IronWolf drives.

Secure Hardware Telemetry with Caddy

Implementing a secure reverse proxy architecture for LibreHardwareMonitor using Caddy with internal TLS, HTTP Basic Authentication, granular firewall controls, and Tailscale overlay networking on Windows infrastructure.

Linux Double-Lock Deletion Protection - SOP

Standard Operating Procedure establishing dual-layer protection against catastrophic data loss from accidental rm -rf commands on Debian-based servers

Windows 11 Pro Installation - Bypassing BIOS Embedded Home Key

Guide for installing Windows 11 Pro on devices with OEM Home edition keys embedded in BIOS/UEFI firmware. Includes ISO modification with ei.cfg and pid.txt, post-install upgrade method, and regional configuration for Autopilot deployments.

Microsoft Intune Autopilot and Windows LAPS Deployment Guide

Complete guide for configuring Windows Autopilot with custom local administrator naming and Windows LAPS password management. Includes BitLocker key escrow, White Glove pre-provisioning, and troubleshooting for policy conflicts.

Deep NAT OpenVPN Lab Access: Troubleshooting Silent Firewall Failures

A comprehensive guide to diagnosing and resolving OpenVPN connectivity through multiple NAT layers, including the discovery of a critical silent firewall rule loading failure in pfSense caused by broken aliases.

Solving Cloudflare DDNS in Double NAT Environments

How to configure Cloudflare Dynamic DNS when your gateway is behind double NAT and can't detect your real public IP. A PowerShell-based solution for Windows workstations.

Tailscale: The Zero-Trust Network That Changed How I Manage Infrastructure

A comprehensive deep-dive into Tailscale's mesh networking technology, from WireGuard foundations to practical SSH and SMB configurations. Why this zero-trust VPN has become essential infrastructure for modern system administration.

Building a Safe WireGuard Peer Management Script

A comprehensive bash script for managing WireGuard VPN peers with automatic backups, split-tunnel support, and interactive mode for safe infrastructure management.

Joining the War for Team Blue

A real-world analysis of attack attempts on a small VPS infrastructure running nginx and basic services

Improved Backup Script Usage Guide

Complete guide to using the improved backup script with compression, incremental backups, email reporting, and automated scheduling

Network Topology Report Generator

Complete guide to automated network topology documentation with practical examples, best practices, and troubleshooting tips for Linux servers

Self Hosting a New Blog

My IT journey Continues - insights from Andrew Jones, IT Engineer in London, UK

My Current Custom PC Build - 2025

My 2025 upper mid-range custom PC build featuring AMD Ryzen 9 7900X and Radeon RX 9070, delivering exceptional performance under £2,000