The portable network toolkit: four tools that live on my USB stick

There’s a corner of the toolbox that never seems to make it to the cloud: the USB stick you grab when a network is misbehaving. An XDA writer’s recent kit list is a good excuse to build one of your own — four small, mostly-portable tools that together cover most day-to-day troubleshooting on a home or small-office network.

Wireshark Portable is the heavyweight of the four. It captures and dissects packets as they fly, which sounds arcane until the day you need it: the smart TV that phones home constantly, the app that saturates the uplink, the device talking to something it shouldn’t be. The portable build runs straight off the stick with no install, which matters when you’re working on a machine you don’t administer.

Nmap answers the question every network owner eventually asks: “what is actually on my network?” A quick scan lists every live device, its IP, and the ports it has open. It’s how you find the forgotten IoT plug, confirm the new server is reachable, or spot a service listening that shouldn’t be. Its bundled netcat can even shuffle a file between two machines when nothing else will. Nmap runs on everything — Windows, macOS, Linux — and it belongs on the stick in whatever flavour matches the machines you touch.

DNS Jumper is the niche one, and Windows-only, but handy for a specific job: flipping a machine between DNS servers (Cloudflare, Google, Quad9, your own) to test whether “the internet is slow” is really “DNS is slow”. On Linux the same experiment is a resolvectl command, but for family and client Windows machines, one click beats editing adapter settings by hand.

NetResView is an old NirSoft utility that still earns its slot: it enumerates everything visible on the local network — shares, printers, other machines — in one flat list. It’s the fastest way to answer “why can’t this PC see the printer” without walking the Network neighbourhood of every desktop involved. Being ancient, run it from the stick and expect the odd quirk on modern Windows; for a ten-second inventory it’s still worth it.

The bigger lesson is the USB stick itself. Everyone has a drawer of orphaned 8GB drives, and a labelled toolkit stick is one of the best second lives they can have: portable apps, a couple of bootable installers, config templates, and the network kit above. When something breaks at 9pm on a Sunday, “plug in the stick” beats “download six installers on the machine that’s misbehaving” every time — and unlike cloud tools, it works when the network is the problem.

A Raspberry Pi Zero makes a surprisingly good home lab subnet router

Every home lab eventually collides with the same wall: you want to reach your machines from outside, and your ISP won’t let you. Carrier-grade NAT — increasingly common on consumer and NBN connections — means there’s no public IPv4 address and no port forwarding, so the classic “expose a service on the router” playbook simply doesn’t exist. A writer at XDA Developers recently documented their solution, and it’s a lovely piece of lateral thinking: they gave the oldest, weakest board in the drawer — an original Raspberry Pi Zero — the most important job in the lab.

The ingredient that makes it work is a mesh VPN such as Tailscale. Instead of opening ports, every device you care about joins a private overlay network and talks to its peers over encrypted WireGuard tunnels, using UDP hole-punching to sneak through NAT. No inbound ports, no cloud server rental, and the free tier is generous enough for home and small-office use. It’s the answer to CGNAT that doesn’t involve calling your ISP or paying for a static IP you can’t get.

The clever part is how little of it you actually need to install. Installing the VPN client on every server, VM and container gets old fast — especially if you rebuild nodes regularly for experiments. The fix is a subnet router: one device joins the mesh and advertises your local subnet as a route. From that moment, anything connected to the VPN can reach everything on your LAN — servers, printers, smart gadgets, the lot — with no client installed anywhere else. One board, one configuration, whole-network coverage.

And that’s where the Pi Zero earns its keep. Routing packets between a VPN tunnel and your LAN is almost no work at all for a modern CPU, let alone a humble ARM11. The XDA author paired theirs with DietPi to strip the OS down to essentials, enabled IP forwarding, and enabled route advertisement with a single command:

tailscale set --advertise-routes=192.168.0.0/24

Approve the route once in the admin console and you’re done. That $15 board everyone wrote off is now the front door to your entire network.

A few practical notes before you raid the parts drawer:

  • Connect it wired if you can. The original Zero has no Ethernet port, and subnet routing over Wi-Fi is fine for SSH and dashboards but will bottleneck big file transfers. A USB Ethernet adapter helps; a Pi Zero 2 W (or any spare Pi) is better again if you have one.
  • Keep a fallback path. A subnet router is a single point of failure. If remote access matters to you, a second device advertising the same route elsewhere on the LAN gives you failover — or at least a way in when you unplug the wrong cable.
  • Lock the tailnet down. Turn on device approval, use Tailscale’s ACLs to limit which devices can reach which subnets, and consider an exit node so roaming laptops can keep lab access off public Wi-Fi.
  • Mind the power supply. A flaky USB charger will brown out a Pi under network load and you’ll spend an evening debugging a problem that costs $10 to fix.

For small businesses the same pattern applies with a straight face: secure remote access to an office LAN without opening a single inbound port, without a VPN concentrator appliance, and with the audit trail of who connected sitting in one admin console. Not bad for the board at the bottom of the drawer — and a good reminder that in networking, the boring jobs are often the important ones.

WordPress Appliance - Powered by TurnKey Linux