<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Gareth Marlow &#187; home</title>
	<atom:link href="http://www.marlow.org.uk/blog/category/home/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.marlow.org.uk</link>
	<description>IT Management, Photography, Music, DIY, The Eternal Sleepless Nights of the New Parent</description>
	<lastBuildDate>Tue, 13 Dec 2011 09:31:47 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3</generator>
		<item>
		<title>PPTP VPN, dd-wrt and private DNS resolution</title>
		<link>http://www.marlow.org.uk/blog/2011/03/24/pptp-vpn-dd-wrt-and-private-dns-resolution/</link>
		<comments>http://www.marlow.org.uk/blog/2011/03/24/pptp-vpn-dd-wrt-and-private-dns-resolution/#comments</comments>
		<pubDate>Thu, 24 Mar 2011 01:01:44 +0000</pubDate>
		<dc:creator>gtm12</dc:creator>
				<category><![CDATA[home]]></category>
		<category><![CDATA[work]]></category>

		<guid isPermaLink="false">http://www.marlow.org.uk/?p=51</guid>
		<description><![CDATA[The number of network devices in our house has increased significantly recently. With two Apple TVs, a wii, iPad, two iPhones, a Kindle, an xbox, two laptops, a desktop and a nettop, my creaky old AirPort Extreme was struggling to cope, particularly streaming media across the network. I also need to bridge two sections of [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.marlow.org.uk%2Fblog%2F2011%2F03%2F24%2Fpptp-vpn-dd-wrt-and-private-dns-resolution%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.marlow.org.uk%2Fblog%2F2011%2F03%2F24%2Fpptp-vpn-dd-wrt-and-private-dns-resolution%2F&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>The number of network devices in our house has increased significantly recently. With two Apple TVs, a wii, iPad, two iPhones, a Kindle, an xbox, two laptops, a desktop and a nettop, my creaky old AirPort Extreme was struggling to cope, particularly streaming media across the network. I also need to bridge two sections of wired network and as I need to reach the work network from several devices at home, I wanted to share a VPN connection into the office. All of this took some figuring out and some heavy googling, so in the interests of helping out anyone with a similar problem, here&#8217;s what I did.</p>
<h2>Network Layout</h2>
<p><a href="http://www.marlow.org.uk/wp-content/uploads/2011/03/homenetwork1.png"><img class="alignnone size-full wp-image-53" title="homenetwork" src="http://www.marlow.org.uk/wp-content/uploads/2011/03/homenetwork1.png" alt="Home Network" width="646" height="461" /></a></p>
<p>&nbsp;</p>
<h2>Hardware Requirements</h2>
<ul>
<li>A simultaneous dual-band wireless-n router at the gateway</li>
<li>A normal dual-band wireless-n router to bridge to the LAN</li>
<li>Gigabit switches at both ends</li>
<li>dd-wrt support on both devices (PPTP support at the gateway, and bridging or WDS at the LAN)</li>
<li>Same chipset on both routers for compatability</li>
</ul>
<p>I ended up with a Cisco Linksys WRT610n for the gateway router, and a Cisco Linksys WRT320n for the LAN bridge. Both second-hand/refurbished models from eBay. Total cost £80.</p>
<h2>Gateway Configuration</h2>
<ol>
<li>Flash the WRT610n with <a href="http://www.dd-wrt.com/">dd-wrt</a>.</li>
<li>Create two wireless networks. The 2.4GHz carries 802.11b/g/n for maximum compability. The 5GHz carries 802.11n for maximum bandwidth.</li>
<li>Add a virtual interface to the 5GHz network with its own SSID to carry the inter-router link.</li>
<li>Set WPA2 AES encryption on all networks with pre-shared key.</li>
<li>Connect to the cable modem, reboot and check that internet connection is established by connecting with the iPad to each of the wireless networks in turn and web surfing.</li>
</ol>
<h2>LAN Bridge Configuration</h2>
<p>I wanted to use WDS to link the two routers but I ran into some problems. I could establish a connection, but the link bandwidth fluctuated significantly, and I also couldn&#8217;t get PPTP traffic to tunnel successfully. Data transfer over the VPN stalled for larger packets. This is a classic symptom of incorrect network MTU but despite resorting to packet sniffing, I couldn&#8217;t get this working properly. I ended up using dd-wrt Repeater Bridge mode which solved these problems straight away. The steps were:</p>
<ol>
<li>Flash the WRT320n with dd-wrt.</li>
<li>Disable the WAN connection and give the router a static IP address (192.168.1.2) with the gateway router&#8217;s IP as the gateway address.</li>
<li>In &#8220;Advanced Routing&#8221;, set the Operating Mode to &#8220;Router&#8221;.</li>
<li>In Wireless Basic Settings, set the Wireless Mode to &#8220;Repeater Bridge&#8221;, and the Wireless Network Mode to &#8220;N-Only (5 GHz). Give it the same SSID as the inter-router link in step 3 of &#8220;Gateway Configuration&#8221;</li>
<li>Add the appropriate Security Mode, WPA Algorithm and WPA Shared Key in the &#8220;Wireless Security&#8221; section.</li>
<li>Under &#8220;Services -&gt; Services&#8221;, Disable DNSMasq (which turns off the DNS and DHCP servers).</li>
<li>Reboot, connect the desktop PC to the gigabit switch on the bridge router, check it picks up an IP address from the gateway DHCP server and that it can reach the internet.</li>
</ol>
<p>At this point, I added the rest of the wireless and wired devices to the network and checked that things were working properly. AirPlay working from an iPhone to one of the Apple TVs, streaming audio and video from the PC to the TVs and download content from the internet were all evidence that dd-wrt was correctly bridging between the different networks and things were behaving properly.</p>
<p>The final stage was the VPN, and this is where information online started to run a bit thin.</p>
<h2>DD-WRT, PPTP VPN, routing DNS queries correctly and handling unqualified hostnames</h2>
<p>The requirements for the VPN connection were:</p>
<ol>
<li>The gateway router establishes the VPN connection and handles routing.</li>
<li>Only work traffic crosses the VPN &#8211; everything else gets routed straight to the Internet.</li>
<li>Home LAN access to the work LAN is NATted to remove the need to add routes back to the home LAN.</li>
<li>Unqualified hostnames are in use both on the host LAN and on the work network.</li>
<li>DNS resolution for the work domain should be handled by the work internal DNS servers; DNS resolution for the home LAN should be handled locally; everything else gets handled by my ISP&#8217;s DNS servers.</li>
<li>All LAN client configuration is done via DHCP, so that all devices including the iPhones and iPad will work immediate on connection.</li>
</ol>
<p>Steps 1 to 3 are straightforward:</p>
<ol>
<li>On the Gateway router, under Services-&gt;VPN, enable the PPTP Client.</li>
<li>Use the IP address rather than the DNS name for the server &#8211; this will not change frequently, and makes DNS configuration more straightforward.</li>
<li>Configure the remote Subnet and Subnet Mask as appropriate &#8211; my work uses an RFC1918 Class A address space.</li>
<li>I changed the MPPE Encryption settings to &#8220;mppe required,no40,no56,stateless&#8221;. This was in the middle of my &#8220;trial and error&#8221; phase of trying to troubleshoot WDS &#8211; it might not therefore be necessary but if it works, it won&#8217;t hurt!</li>
<li>Leave MRU and MTU as the defaults. Enable NAT and complete the User Name and Password fields as appropriate. NB if this is authenticating against a Windows domain, you need to put username in the form DOMAIN\\username.</li>
<li>Hit &#8220;Apply Settings&#8221;. Reboot the router.</li>
</ol>
<p>If all is well, you should now be able to ping IP addresses of machines on your work network from client machines on the home LAN. traceroute should also show that this traffic is being carried across the VPN, where traceroute to www.bbc.co.uk goes via your gateway and across your ISP&#8217;s networks in several hops.</p>
<p>Next step is to confirm that you can reach your work DNS servers. Ping them first, and then attempt a hostname lookup: our intranet server is called &#8220;intranet&#8221; so &#8220;nslookup intranet &lt;WORK DNS IP&gt;&#8221; should return the correct IP address. To complete requirements 4-6, we need to use the dd-wrt DNS/DHCP server DNSMasq to manage home LAN DNS registrations, pass off work DNS queries to the work servers over the VPN, to send the rest to the ISP and to send appropriate search domain information to all LAN DHCP clients so unqualified hostname resolution will still work. I have to admit that these settings were reached through some trial and error so there could be a better way of doing this. But at least this works:</p>
<ol>
<li>In &#8220;Services-&gt;Services&#8221;, under &#8220;Services Management&#8221; &#8220;DHCP Server&#8221;, add a local value to LAN Domain. I use &#8220;marlow.org.uk&#8221; here. This will be added to the hostnames of your LAN devices while they&#8217;re on the home network to give them an FQDN.</li>
<li>DNSMaq should already be enabled, but you should enable &#8220;Local DNS&#8221; and disable &#8220;No DNS Rebind&#8221;.</li>
<li>In &#8220;Additional DNSMasq Options&#8221;, add the following (changing the bits in red):
<pre>dhcp-option=15,"<span style="color: #ff6600;">workdomain.com homelandomain.org.uk</span>"
strict-order
no-resolv
no-poll
server=/<span style="color: #ff6600;">workdomain.com</span>/<span style="color: #ff6600;">ipaddressofworkdnsserver
</span>server=<span style="color: #ff6600;">yourispprimarydnsip
</span>server=<span style="color: #ff6600;">youridpsecondarydnsip</span></pre>
</li>
<li>Hit &#8220;Apply Settings&#8221;</li>
<li>Renew the DHCP lease of one of your home LAN clients and check that DNS resolution is behaving as expected by pinging www.bbc.co.uk, followed by the unqualified hostname of a machine on the work network and then one of the clients on your home network.</li>
<li>Pour yourself a stiff drink.</li>
</ol>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.marlow.org.uk/blog/2011/03/24/pptp-vpn-dd-wrt-and-private-dns-resolution/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>The mega birth post</title>
		<link>http://www.marlow.org.uk/blog/2009/08/10/the-mega-birth-post/</link>
		<comments>http://www.marlow.org.uk/blog/2009/08/10/the-mega-birth-post/#comments</comments>
		<pubDate>Mon, 10 Aug 2009 00:23:35 +0000</pubDate>
		<dc:creator>gtm12</dc:creator>
				<category><![CDATA[home]]></category>
		<category><![CDATA[photos]]></category>
		<category><![CDATA[daniel]]></category>
		<category><![CDATA[premature]]></category>
		<category><![CDATA[rosie]]></category>
		<category><![CDATA[scbu]]></category>

		<guid isPermaLink="false">http://www.marlow.org.uk/?p=19</guid>
		<description><![CDATA[Where were we? Oh yes: pre-eclampsia. The causes of this condition aren&#8217;t well-understood; the management of it is. Shortly after my last post on the subject, the midwives and obstetricians at the Rosie Hospital in Cambridge started to manage Nessa&#8217;s pregnancy more closely, and we found ourselves in and out of hospital every couple of [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.marlow.org.uk%2Fblog%2F2009%2F08%2F10%2Fthe-mega-birth-post%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.marlow.org.uk%2Fblog%2F2009%2F08%2F10%2Fthe-mega-birth-post%2F&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>Where were we? Oh yes: pre-eclampsia. The causes of this condition aren&#8217;t well-understood; the management of it is. Shortly after my last post on the subject, the midwives and obstetricians at the Rosie Hospital in Cambridge started to manage Nessa&#8217;s pregnancy more closely, and we found ourselves in and out of hospital every couple of days. By Maundy Thursday they&#8217;d decided to admit her, and because her blood pressure had continued to rise, on Easter Sunday they decided to induce the baby.</p>
<p>He didn&#8217;t want to come and so after a very uncomfortable night for Nessa, a caesarian section was booked for the afternoon of Monday 13 April. I&#8217;m not going to scare anyone with tales of the management of pre-eclampsia; nor of how unpleasant a c-section is, but after 20 minutes of hard work, Daniel Benjamin Isaac Marlow was born at 4:38pm, weighing 5lbs 14.5oz. He was taken to the Lady Mary ward first, and then transferred to the Special Care Baby Unit as his oxygen saturation was too low. Meanwhile, Nessa was transferred back into the delivery unit where she had to stay for 24 hours after the birth. Being separated from Danny for all this time was horrible; I tried to fill it by running between the two of them with my digital camera but it wasn&#8217;t a good substitute.</p>
<p><a href="http://www.flickr.com/photos/gareth_marlow/3446210098/" title="dannybw-001 by garethmobile, on Flickr"><img src="http://farm4.static.flickr.com/3622/3446210098_8c347c1128.jpg" width="500" height="333" alt="dannybw-001" /></a></p>
<p>Eventually, Nessa was moved onto Lady Sara ward, which is adjacent to SCBU, and could visit him at any time. He was still a tangle of wires and tubes at this point &#8211; oxygen through his nose; a canula and glucose drip into his arm; a pulse and O2 saturation sensor on his toe, and a feeding tube up his nose. But by the third day, he&#8217;d had some &#8220;kangaroo care&#8221; or skin-skin contact with Nessa.</p>
<p><a title="danielday3-001 by garethmobile, on Flickr" href="http://www.flickr.com/photos/gareth_marlow/3448197549/"><img src="http://farm4.static.flickr.com/3341/3448197549_210509d812_o.jpg" alt="danielday3-001" width="400" height="600" /></a></p>
<p><a href="http://www.flickr.com/photos/gareth_marlow/3449012412/" title="danielday3-003 by garethmobile, on Flickr"><img src="http://farm4.static.flickr.com/3546/3449012412_5774d7c496.jpg" width="500" height="333" alt="danielday3-003" /></a></p>
<p>This was a surreal time for us. The first few days were absolutely horrible; it was very difficult to hold our baby; he was fed hourly through a tube on a 24-hour cycle and day blurred into night. He was four weeks early and being delivered via c-section meant that the fluids hadn&#8217;t been squeezed from his lungs. All the while, the medical staff attempted to eliminate other causes for his low oxygen saturation &#8211; lumbar punctures to detect infection; chest xrays; ultrasound. But every day he got a bit stronger and a little less dependent on the external support.</p>
<p><a href="http://www.flickr.com/photos/gareth_marlow/3458924994/" title="dannyday6-002 by garethmobile, on Flickr"><img src="http://farm4.static.flickr.com/3558/3458924994_2ba209f9e4.jpg" width="500" height="333" alt="dannyday6-002" /></a></p>
<p>Still, it was nearly two weeks before he could come home and almost three weeks until he met his older brother and sister.</p>
<p><a href="http://www.flickr.com/photos/gareth_marlow/3498176453/" title="wk3-006 by garethmobile, on Flickr"><img src="http://farm4.static.flickr.com/3552/3498176453_c87f3ae1e3.jpg" width="500" height="333" alt="wk3-006" /></a></p>
<p>Douglas Adams compared a child&#8217;s early development to a computer booting up, and this is what we see with Danny. His awareness of what&#8217;s around him gets wider each day.</p>
<p><a href="http://www.flickr.com/photos/gareth_marlow/3619216831/" title="dannywk7-002 by garethmobile, on Flickr"><img src="http://farm4.static.flickr.com/3321/3619216831_9109188d8b_o.jpg" width="600" height="600" alt="dannywk7-002" /></a></p>
<p>Working out how old he is, is also difficult and even confuses the medical staff. A GP was concerned that he&#8217;d not started smiling by six weeks old; the hospital confirmed that these development checkpoints in the first year can all have four weeks added on to account for his prematurity. Still, no problem with smiling now.</p>
<p><a href="http://www.flickr.com/photos/gareth_marlow/3806096158/" title="july09-01 by garethmobile, on Flickr"><img src="http://farm3.static.flickr.com/2437/3806096158_c1cea27083.jpg" width="500" height="333" alt="july09-01" /></a></p>
<p>He&#8217;s now doubled his birthweight and it&#8217;s interesting to compare him to his cousin, Charlie, who was only a week old at the time this photo was taken.</p>
<p><a href="http://www.flickr.com/photos/gareth_marlow/3806101326/" title="july09-11 by garethmobile, on Flickr"><img src="http://farm3.static.flickr.com/2607/3806101326_520380aa62_o.jpg" width="400" height="600" alt="july09-11" /></a></p>
<p>He&#8217;s becoming a lot more aware of his own body and has started to grab for his knees and his toes with his fingers.</p>
<p><a href="http://www.flickr.com/photos/gareth_marlow/3805280629/" title="july09-04 by garethmobile, on Flickr"><img src="http://farm4.static.flickr.com/3559/3805280629_7889741f95_o.jpg" width="400" height="600" alt="july09-04" /></a></p>
<p>He&#8217;s also become a lot more facially-expressive.</p>
<p><a href="http://www.flickr.com/photos/gareth_marlow/3805294097/" title="july09-29 by garethmobile, on Flickr"><img src="http://farm4.static.flickr.com/3510/3805294097_52006f32b9.jpg" width="500" height="333" alt="july09-29" /></a></p>
<p><a href="http://www.flickr.com/photos/gareth_marlow/3805304491/" title="camoflage-01 by garethmobile, on Flickr"><img src="http://farm3.static.flickr.com/2459/3805304491_641d9a9464_o.jpg" width="400" height="600" alt="camoflage-01" /></a></p>
<p>So Danny&#8217;s now nearly four months old and we&#8217;re well into the routine of having a young baby in the house. Time to go and sterlise the breast pump!</p>
<p><a href="http://www.flickr.com/photos/gareth_marlow/3805304759/" title="camoflage-02 by garethmobile, on Flickr"><img src="http://farm3.static.flickr.com/2597/3805304759_cebdb94b83_o.jpg" width="400" height="600" alt="camoflage-02" /></a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.marlow.org.uk/blog/2009/08/10/the-mega-birth-post/feed/</wfw:commentRss>
		<slash:comments>9</slash:comments>
		</item>
		<item>
		<title>Blood Pressure</title>
		<link>http://www.marlow.org.uk/blog/2009/04/02/blood-pressure/</link>
		<comments>http://www.marlow.org.uk/blog/2009/04/02/blood-pressure/#comments</comments>
		<pubDate>Thu, 02 Apr 2009 21:57:26 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[home]]></category>
		<category><![CDATA[baby]]></category>
		<category><![CDATA[health]]></category>

		<guid isPermaLink="false">http://www.marlow.org.uk/?p=11</guid>
		<description><![CDATA[My wife is 34 weeks pregnant. We&#8217;re into the end-game, but her blood pressure has got a little high, so we&#8217;ve had two trips in three days to the Maternal Fetal Assessment Unit, where the staff have attempted to ascertain her blood pressure. It&#8217;s not as easy as it sounds. They&#8217;re most interested in her [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.marlow.org.uk%2Fblog%2F2009%2F04%2F02%2Fblood-pressure%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.marlow.org.uk%2Fblog%2F2009%2F04%2F02%2Fblood-pressure%2F&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>My wife is 34 weeks pregnant. We&#8217;re into the end-game, but her blood pressure has got a little high, so we&#8217;ve had two trips in three days to the Maternal Fetal Assessment Unit, where the staff have attempted to ascertain her blood pressure. It&#8217;s not as easy as it sounds. They&#8217;re most interested in her <strong>diastolic</strong> pressure (the lower of the two &#8211; the background pressure). A close eye needs to be kept on pregnant women with a diastolic pressure greater than 90 mmHg.</p>
<p>Weirdly, nobody can tell if it&#8217;s greater than 90 mmHg. Over the last few days, her blood pressure has been measured manually and automatically probably 20 or 30 times, and it&#8217;s varied from 79 mmHg to 114 mmHg. Although there&#8217;s a possibility of <a href="http://en.wikipedia.org/wiki/White_coat_hypertension">White Coat Hypertension</a> I find it difficult to believe that her diastolic pressure has varied so much and so do the medical staff. So what&#8217;s going on? Possibilities include experimental error, over-sensitive equipment or poorly-calibrated equipment.</p>
<p>Most of the readings have wobbled around the 90 mmHg mark which is a problem &#8211; it&#8217;s too low to take action, but too high to ignore. It seems that the only option is to schedule a midwife visit every couple of days to take the readings, and to return to the MFAU if they appear high. This has happened twice this week already and if there&#8217;s anything likely to raise your blood pressure, it&#8217;s driving through cross-town traffic in Cambridge &#8211; and paying for parking at Addenbrooke&#8217;s hospital. Fortunately, I&#8217;m the designated driver.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.marlow.org.uk/blog/2009/04/02/blood-pressure/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

