[{"content":"Privacy by routing DNS traffic through a VPN Tunnel on a Mikrotik router Why DNS Privacy Still Matters in 2026 Most people think that when they browse the internet using HTTPS, their online activities are completely private. Unfortunately, that is not entirely true.\nHTTPS encrypts the content of your communication with a website. Your internet provider cannot see the pages you read, the forms you submit, or the passwords you enter. However, before your browser can connect to a website, it first needs to know the IP address of that website.\nThis is where DNS comes into play.\nDNS (Domain Name System) acts as the internet\u0026rsquo;s phonebook. When you visit a website such as www.example.com, your device performs a DNS query to find the corresponding IP address.\nTraditionally, these DNS queries are sent in plain text over the internet. Anyone between you and the DNS server can potentially see which domains you are looking up.\nThe Privacy Problem Even when all your web traffic is protected by HTTPS, DNS requests can reveal a surprising amount of information:\nWebsites you visit Applications you use Smart home devices in your network Streaming services you access Business services and cloud platforms you connect to In many cases, DNS traffic creates a detailed profile of your online behavior.\nIsn\u0026rsquo;t DNS over HTTPS the Solution? DNS over HTTPS (DoH) is certainly an improvement.\nInstead of sending DNS requests in plain text on port 53, DNS queries are encapsulated within HTTPS traffic on port 443.\nThis provides protection against:\nLocal network snooping Public Wi-Fi monitoring Basic ISP DNS inspection However, DoH does not make you invisible.\nYour ISP can still see:\nThe destination IP address you connect to The DNS provider you use Traffic patterns Connection metadata Depending on the implementation, technologies such as SNI (Server Name Indication) or traffic analysis may still reveal information about the services being accessed.\nIn short:\nDNS over HTTPS encrypts the DNS query itself, but not necessarily all metadata surrounding the connection.\nA Different Approach: Route DNS Through a VPN A stronger privacy model is to route all DNS traffic through a VPN tunnel.\nIn this setup:\nInternal DNS servers perform DNS lookups. DNS traffic is marked by the router. The marked traffic is sent through a WireGuard VPN tunnel. The ISP only sees encrypted WireGuard traffic. External DNS providers only see the VPN endpoint address. This significantly reduces the visibility of DNS activity to your internet provider.\nMy Environment I use:\nMikroTik Router with RouterOS 7.20.6 WireGuard VPN ProtonVPN (or other VPN provider) Multiple Pi-hole DNS servers, running on my Proxmox homelab server The goal is simple:\nOnly DNS traffic should travel through the VPN tunnel.\nAll normal internet traffic continues to use the regular WAN connection.\nThis approach provides additional privacy without forcing all users and applications through the VPN.\nStep 1: Create an Address List First, create an address list containing all internal DNS servers.\n1 2 3 /ip/firewall/address-list add address=192.168.1.10 comment=Pi-Hole1 list=\u0026#34;DNS Servers\u0026#34; add address=192.168.1.11 comment=Pi-Hole2 list=\u0026#34;DNS Servers\u0026#34; What does this do? This creates a group called DNS Servers.\nInstead of creating firewall rules for every DNS server individually, we can simply reference this address list.\nAdvantages:\nEasier management Better scalability Cleaner configuration Step 2: Mark DNS Traffic The next step is to identify DNS traffic generated by these servers and mark it for special routing.\nUDP Port 53 1 2 3 4 5 6 7 add action=mark-routing chain=prerouting \\ comment=\u0026#34;DNS traffic (UDP) via WG-ProtonVPN\u0026#34; \\ dst-port=53 \\ new-routing-mark=to-ProtonVPN \\ passthrough=no \\ protocol=udp \\ src-address-list=\u0026#34;DNS Servers\u0026#34; Explanation This rule says:\n\u0026ldquo;If traffic originates from one of the DNS servers and uses UDP port 53, mark it with routing mark to-ProtonVPN.\u0026rdquo;\nUDP 53 is the traditional DNS protocol.\nThe parameter:\n1 passthrough=no means processing stops after the packet is marked.\nUDP Port 853 1 2 3 4 5 6 7 add action=mark-routing chain=prerouting \\ comment=\u0026#34;DNS traffic (UDP) via WG-ProtonVPN\u0026#34; \\ dst-port=853 \\ new-routing-mark=to-ProtonVPN \\ passthrough=no \\ protocol=udp \\ src-address-list=\u0026#34;DNS Servers\u0026#34; Explanation Port 853 is commonly used by encrypted DNS technologies. This ensures those DNS requests are also routed through the VPN.\nTCP Port 53 1 2 3 4 5 6 7 add action=mark-routing chain=prerouting \\ comment=\u0026#34;DNS traffic (TCP) via WG-ProtonVPN\u0026#34; \\ dst-port=53 \\ new-routing-mark=to-ProtonVPN \\ passthrough=no \\ protocol=tcp \\ src-address-list=\u0026#34;DNS Servers\u0026#34; Explanation Although most DNS traffic uses UDP, larger responses may fall back to TCP.\nExamples include:\nLarge DNS responses DNS zone transfers Certain DNSSEC operations This rule ensures TCP-based DNS traffic is also protected.\nTCP Port 853 1 2 3 4 5 6 7 add action=mark-routing chain=prerouting \\ comment=\u0026#34;DNSSEC traffic (TCP) via WG-ProtonVPN\u0026#34; \\ dst-port=853 \\ new-routing-mark=to-ProtonVPN \\ passthrough=no \\ protocol=tcp \\ src-address-list=\u0026#34;DNS Servers\u0026#34; Explanation This captures encrypted \u0026lsquo;DNS of TLS\u0026rsquo; (DoT) traffic using TCP on port 853.\nAgain, the traffic receives the routing mark and is directed toward the VPN.\nTCP Port 443 1 2 3 4 5 6 7 add action=mark-routing chain=prerouting \\ comment=\u0026#34;DNS-HTTPS traffic (TCP) via WG-ProtonVPN\u0026#34; \\ dst-port=443 \\ new-routing-mark=to-ProtonVPN \\ passthrough=no \\ protocol=tcp \\ src-address-list=\u0026#34;DNS Servers\u0026#34; Explanation This is the rule that captures DNS over HTTPS (DoH).\nMost DoH providers use HTTPS over TCP port 443.\nBecause the traffic originates from the DNS servers in our address list, we can reasonably assume this HTTPS traffic is DNS-related and should be sent through the VPN.\nThis prevents DNS-over-HTTPS requests from bypassing the privacy tunnel.\nStep 3: Create a Dedicated Route Now we create a routing table that uses the WireGuard tunnel.\n1 2 3 4 5 6 7 8 /ip route add disabled=no \\ distance=1 \\ dst-address=0.0.0.0/0 \\ gateway=wg2-ProtonVPN \\ routing-table=to-ProtonVPN \\ scope=30 \\ target-scope=10 Explanation This route says:\n\u0026ldquo;When traffic arrives with routing mark to-ProtonVPN, send it through the WireGuard interface wg2-ProtonVPN.\u0026rdquo;\nOnly marked traffic uses this route.\nAll other traffic follows the normal routing table.\nThis is what makes selective VPN routing possible.\nStep 4: Routing Rule 1 2 3 4 5 6 /routing rule add action=lookup \\ comment=\u0026#34;Route DNS traffic over ProtonVPN\u0026#34; \\ disabled=no \\ routing-mark=to-ProtonVPN \\ table=to-ProtonVPN Explanation This rule tells RouterOS to perform a route lookup in the to-ProtonVPN routing table whenever packets carry the routing mark to-ProtonVPN.\nOn modern RouterOS versions, routing marks and routing tables often work directly together without requiring additional routing rules. Depending on your RouterOS design and version, this rule may not be necessary.\nAlways test routing behavior after enabling or disabling routing rules.\nWhat Does My ISP See? Without this setup:\n1 DNS Server ---\u0026gt; Internet DNS Provider The ISP can observe DNS traffic and metadata.\nWith this setup:\n1 DNS Server ---\u0026gt; WireGuard Tunnel ---\u0026gt; VPN Provider ---\u0026gt; DNS Provider The ISP only sees:\n1 Encrypted WireGuard Traffic The DNS requests themselves travel inside the VPN tunnel.\nThis significantly improves privacy.\nFinal Thoughts Privacy on the internet is not a single technology.\nHTTPS protects website content.\nDNS over HTTPS protects DNS queries.\nWireGuard protects traffic between your router and the VPN endpoint.\nBy combining these technologies and routing DNS traffic through a dedicated WireGuard tunnel on MikroTik RouterOS, you create multiple layers of privacy.\nThe result is a simple but effective setup:\nInternal DNS servers remain local. DNS traffic is encrypted. DNS traffic is hidden from the ISP. Normal internet traffic can continue using the regular WAN connection. For home labs and privacy-conscious MikroTik users, selective DNS routing over WireGuard offers an elegant balance between privacy, performance, and simplicity.\n","date":"2026-05-17T13:00:43+02:00","image":"/images/2026/routerboard.webp","permalink":"/en/blog/privacy-dns-over-vpn/","title":"Privacy by Routing DNS Traffic Through a VPN Tunnel"},{"content":"High-Availability DNS Cluster: Technitium + Keepalived (IPVS) on Debain LXC Container Domain Name System (DNS) is the backbone of any network infrastructure. When your DNS servers go down, your entire network effectively stops functioning. While many network administrators simply deploy two separate DNS servers and list both in their DHCP scope, this approach does not provide true load balancing or instantaneous failover.\nIn this guide, we will build a production-grade, highly available DNS cluster using two Technitium DNS servers running inside Proxmox Linux Containers (LXC). We will leverage Keepalived and IPVS (IP Virtual Server) to achieve both seamless load balancing and intelligent failover over a single Virtual IP (VIP) address.\nWhy Standard Secondary DNS Isn\u0026rsquo;t Enough Most home labs and enterprise environments deploy two DNS servers (Primary and Secondary). They hand out both IP addresses via DHCP. However, the client-side implementation of this is flawed:\nUnpredictable Routing: Some operating systems (like Windows) stick to the primary server until it completely times out, causing severe delays during an outage. Other systems (like macOS/Linux) might query both semi-randomly, making traffic distribution unpredictable. No Real Load Balancing: Traffic is rarely distributed evenly between the two servers. Slow Failover: If the primary DNS server freezes but keeps its network link active, clients will waste precious seconds waiting for timeouts before trying the secondary server. The Solution: Keepalived + IPVS By introducing Keepalived with IPVS at Layer 4, we create a single Virtual IP (VIP). Your clients only ever talk to this one IP address.\nKeepalived acts as an intelligent traffic director:\nLoad Balancing: It splits incoming UDP and TCP port 53 DNS queries evenly across both Technitium instances using a Round Robin algorithm. Instant Failover: It continuously polls the health of each Technitium instance. If one container or DNS service crashes, Keepalived immediately removes it from the rotation. Infrastructure Redundancy: Keepalived uses VRRP (Virtual Router Redundancy Protocol). If the primary load-balancing container dies entirely, the secondary container instantly assumes the VIP within milliseconds. Schematic Overview [ NETWERK CLIENTS ] (Request DNS via VIP) │ ▼ ┌────────────────┐ │ VIRTUEL IP │ │ 192.168.1.10 │ └───────┬────────┘ │ ┌──────┴──────┐ (Keepalived VRRP / IPVS) │ │ (Divide UDP/TCP requests via Round Robin) ▼ ▼ ┌─────────────────┐ ┌─────────────────┐ │ LXC Container 1 │ │ LXC Container 2 │ │ [MASTER] │ │ [BACKUP] │ │ 192.168.1.11 │ │ 192.168.1.12 │ ├─────────────────┤ ├─────────────────┤ │ Technitium #1 │ │ Technitium #2 │ │ (lo: .1.10/32) │ │ (lo: .1.10/32) │ └────────┬────────┘ └────────┬────────┘ │ │ └──────────┬──────────┘ │ (Direct Routing - DR Mode) ▼ [ Direct Answer ] (Back to Clients) Explanation of the data flow: Inbound traffic: Network clients send all their DNS requests exclusively to the Virtual IP (192.168.1.10). Load Balancing: The container currently holding the MASTER role (Container 1) intercepts the traffic and distributes the requests across the two Technitium DNS backends using the Linux IPVS kernel module (Round Robin). Direct Routing (DR): Thanks to the loopback configuration (lo: 192.168.1.10/32), both containers process the packets directly and send the response straight back to the client, bypassing the load balancer. This ensures minimal latency. Failover: If Container 1 fails, Keepalived moves the VIP to Container 2 within a fraction of a second; from that point on, Container 2 handles the requests independently. Architectural Overview Virtual IP (VIP): 192.168.1.10 (The single DNS address given to your clients) Technitium Container 1 (MASTER): 192.168.1.11 Technitium Container 2 (BACKUP): 192.168.1.12 Step 1: Preparing the Proxmox Host (Crucial for LXC) Because LXC containers share the host\u0026rsquo;s Linux kernel, they cannot load kernel modules or manipulate network routing infrastructure by default. We must prepare the Proxmox host first.\n1. Load IPVS Modules on the Host Log into your Proxmox VE Host via SSH and run the following commands to load the required IPVS load-balancing kernel modules:\nmodprobe ip_vs modprobe ip_vs_rr To ensure these modules survive a Proxmox host reboot, append them to the host\u0026rsquo;s /etc/modules file:\necho \u0026#34;ip_vs\u0026#34; \u0026gt;\u0026gt; /etc/modules echo \u0026#34;ip_vs_rr\u0026#34; \u0026gt;\u0026gt; /etc/modules 2. Adjust LXC Container Permissions You must grant your containers permission to interact with the network stack. On your Proxmox host, open the configuration files for both containers (located at /etc/pve/lxc/YOUR_CONTAINER_ID.conf) and add these lines: Make sure the the LXC container are running in privilegded mode. Option \u0026ldquo;unprivileged: 0\u0026rdquo; in .conf\n1 2 3 4 5 6 lxc.apparmor.raw: mount fstype=devpts, lxc.cgroup2.devices.allow: c 10:200 rwm lxc.mount.entry: /dev/net/tun dev/net/tun none bind,create=file # SAFE Capabilties (let the console alive, but give networks rights) lxc.cap.drop: lxc.cap.keep: sys_admin net_admin chown dac_override fowner fsetid kill setgid setuid setpcap linux_immutable net_bind_service net_raw ipc_owner sys_chroot sys_ptrace sys_tty_config Restart both LXC containers after saving these changes.\nStep 2: Configuring the Loopback Interface on the Containers We will be using Direct Routing (DR) mode in IPVS. This is the fastest method of load balancing because incoming traffic goes through the load balancer, but the backend Technitium servers reply directly to the client.\nFor this to work, both containers must accept packets destined for the VIP (192.168.1.10), but they must not broadcast this IP to the local network to avoid IP conflicts. We solve this by binding the VIP to the local loopback (lo) interface.\nInside both Debian LXC containers, open /etc/network/interfaces:\nnano /etc/network/interfaces Modify the loopback configuration block to match the following:\nauto lo iface lo inet loopback up ip addr add 192.168.1.10/32 dev lo down ip addr del 192.168.1.10/32 dev lo Apply the changes instantly without a reboot:\nifdown lo \u0026amp;\u0026amp; ifup lo Step 3: Installing and Configuring Keepalived Now, log into both containers to install Keepalived and the IPVS administration utility:\napt update \u0026amp;\u0026amp; apt install -y keepalived ipvsadm 1. Configuration for Container 1 (MASTER) Create the configuration file /etc/keepalived/keepalived.conf on your first Technitium container:\n1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 global_defs { router_id dns_lb1 enable_script_security } # 1. High Availability (VRRP Configuration) vrrp_instance VI_1 { state MASTER interface eth0 # Replace with your actual network interface virtual_router_id 51 priority 101 # Higher priority wins the VIP advert_int 1 authentication { auth_type PASS auth_pass A_Secure_Cluster_Password } virtual_ipaddress { 192.168.1.10/24 # Your Virtual IP (VIP) } } # 2. Load Balancing for DNS UDP (Port 53) virtual_server 192.168.1.10 53 { delay_loop 6 lb_algo rr # Round Robin distribution lb_kind DR # Direct Routing mode protocol UDP real_server 192.168.1.11 53 { weight 1 MISC_CHECK { misc_path \u0026#34;/usr/bin/nc -zu -w 1 127.0.0.1 53\u0026#34; # Local health check misc_timeout 2 } } real_server 192.168.1.12 53 { weight 1 MISC_CHECK { misc_path \u0026#34;/usr/bin/nc -zu -w 1 192.168.1.12 53\u0026#34; # Remote health check misc_timeout 2 } } } # 3. Load Balancing for DNS TCP (Port 53) virtual_server 192.168.1.10 53 { delay_loop 6 lb_algo rr lb_kind DR protocol TCP real_server 192.168.1.11 53 { weight 1 TCP_CHECK { connect_timeout 3 } } real_server 192.168.1.12 53 { weight 1 TCP_CHECK { connect_timeout 3 } } } 2. Configuration for Container 2 (BACKUP) Create the exact same file on your second Technitium container, but change the vrrp_instance configuration block to reflect its backup status and lower priority:\nstate BACKUP priority 100 # Lower than the MASTER server 3. Enable and Start Keepalived Run this command on both containers to start the service and ensure it launches automatically at boot:\nsystemctl enable --now keepalived Step 4: Verification and Testing Your high-availability cluster is now live! Let\u0026rsquo;s verify that everything is working perfectly.\n1. Check IP Allocation On Container 1 (MASTER), run:\nip addr show eth0 You should see both its local IP (192.168.1.11) and the VIP (192.168.1.10). If you run the same command on Container 2, the VIP should not be present.\n2. Inspect the Load Balancing Table Run the following command on the container that is currently acting as the MASTER:\nipvsadm -ln You will see a clean routing matrix mapping your VIP to both backend servers across TCP and UDP protocols.\n3. Simulating a Failure To test the failover capability, stop the Keepalived service on Container 1:\nsystemctl stop keepalived If you run ip addr show eth0 on Container 2, you will notice that it has gracefully assumed control of the VIP (192.168.1.10) in a fraction of a second. Your network clients will experience zero downtime, and DNS queries will keep resolving seamlessly.\n4. Monitoring Real-Time Traffic Distribution Once your high-availability DNS cluster is running, you will want to see it in action. The best way to monitor how Keepalived and IPVS are distributing traffic between your Technitium servers is by using the following debugging command:\nwatch -n 0.5 ipvsadm -Ln What it does\nThis command combines two powerful Linux utilities. The ipvsadm -Ln command lists the current IP Virtual Server kernel routing table in a clean, numeric format (-n), skipping slow DNS lookups. By wrapping it in watch -n 0.5, the terminal automatically refreshes the output every half-second, providing a near-real-time view of your live network traffic.\nHow to interpret the output When you run this on the active MASTER container, you will see an output structured like this:\nIP Virtual Server version 1.2.1 (size=4096) Prot LocalAddress:Port Scheduler Flags -\u0026gt; RemoteAddress:Port Forward Weight ActiveConn InActConn UDP 192.168.1.10:53 rr -\u0026gt; 192.168.1.11:53 Route 1 0 142 -\u0026gt; 192.168.1.12:53 Route 1 0 139 Key metrics to look out for:\nUDP/TCP \u0026hellip; rr: Confirms that IPVS is listening on your Virtual IP (VIP) on port 53 and using the Round Robin (rr) scheduler. Forward (Route): Indicates that Direct Routing (DR) is working properly. Weight: A value of 1 means the server is healthy. If Keepalived detects that a Technitium instance is down, this weight will immediately drop to 0, removing it from rotation. InActConn (Inactive Connections): Since DNS over UDP is stateless, queries do not stay open. Instead, they quickly register as inactive connections. Watch these numbers increment evenly on both rows as clients make requests—this is visual proof that your load balancer is dividing the work perfectly! Conclusion By coupling Technitium DNS with Keepalived and IPVS, you eliminate the classic pitfalls of primary/secondary DNS configurations. You get an enterprise-grade setup that guarantees absolute uptime, linear traffic distribution, and instantaneous failover management—all running within lightweight, low-overhead Proxmox LXC containers.\n","date":"2026-05-08T09:00:43+02:00","image":"/images/2026/cluster-computing.png","permalink":"/en/blog/high-availability-dns-cluster/","title":"Building a High-Availability DNS Cluster on Debian"},{"content":"Sunday afternoon walk on the The Ockenburgh Parc, (24 hectares) is a more than 350-year-old estate located between Loosduinen and Kijkduin, This beautiful villa was build in 1654. Today you can walk in this parc and eat a excellent meal at the restaurant.\n","date":"2026-02-15T00:00:00Z","permalink":"/en/blog/villa-ockenburgh/","title":"Villa Ockenburgh"},{"content":"Fishing boat enters the harbour of Scheveningen.\n","date":"2026-02-12T00:00:00Z","permalink":"/en/blog/fishing-vessel-enter-the-harbour/","title":"Fishing Vessel enter the Harbour"},{"content":"Our favorite seafood restaurant Catch by Simones at the harbour. They have a excellent cuisine of seafood. The restaurant is located at the end of the inner harbour, across our marina.\n","date":"2026-02-11T00:00:00Z","permalink":"/en/blog/restaurant-catch/","title":"Restaurant Catch"},{"content":"Detailed photo of a anchor in beautiful sunlight.\n","date":"2026-02-10T00:00:00Z","permalink":"/en/blog/anchor/","title":"Anchor"},{"content":"Bow of a fishing vessel Albatros OD2 Build : 1952 Shipyard\t: Boot, Alphen a/d Rijn, the Netherlands Length x Broad x Depth: 15,52M X 4,54M X 2,06M - Weight : 34,49 BRT Current harbour : Scheveningen ","date":"2026-02-04T00:00:00Z","permalink":"/en/blog/fishing-vessel-od2-vessel/","title":"Fishing Vessel OD2 Vessel"},{"content":"Passenger Vessel Jar Passenger Vessel in Scheveningen Harbour\n","date":"2026-02-03T16:13:17+02:00","permalink":"/en/blog/jar-vessel/","title":"Jar Vessel"},{"content":"Lighthouse in the last light on the day , on freezing cold afternoon.\n📷 Camera: Panasonic Lumix S5II 🔍 Lens: Lumix 24-60mm f/2.8-f4.0 ⏱️ Shutter: 1/250s ⚙️ Aperture: f/8 🌟 ISO: 100 The Scheveningen Lighthouse was designed by Quirinus Harder and completed in 1875. The red, twelve-sided cast iron tower is 30 meters tall. The tower consists of eight floors and a staircase with 159 steps.\n","date":"2026-02-02T00:00:00Z","permalink":"/en/blog/scheveningen-lighthouse/","title":"Scheveningen Lighthouse"},{"content":"Using a older camera the Fuji X-E1 As photographers, we collect or buy multiple cameras over time. We sell our older cameras or leave them on the shelf to gather dust.\nLately, I\u0026rsquo;ve noticed that photographers on YouTube are increasingly returning to their older cameras. Often out of nostalgia, but also to go back to a “simple or easier” camera with fewer settings, so you can focus more on taking pictures. These cameras are often simpler and have fewer settings.\nOnce you\u0026rsquo;ve been taking pictures for a while with your “older” camera, you\u0026rsquo;ll also appreciate your current camera. You\u0026rsquo;ll notice how good today\u0026rsquo;s cameras are in terms of autofocus, dynamic range, and the number of megapixels in the sensor.\nInspired by the Youtuber One Month Two Cameras , i dig up my old trusty Fuji X-E1\nAs photographers, we often own several cameras over time. We collect, buy, or sell our older cameras, or they sit on the shelf gathering dust because we prefer to shoot with our newest camera.\nLately, I\u0026rsquo;ve noticed that photographers on YouTube are increasingly returning to their older cameras. This is often out of nostalgia, but also to go back to a “simpler and easier” camera, so that you can focus more on taking pictures. These cameras are often simpler and have fewer settings.\nI\u0026rsquo;ve noticed that when you\u0026rsquo;ve been shooting with your older camera for a while, you also appreciate your current camera more. You notice how good today\u0026rsquo;s cameras are in terms of autofocus, dynamic range, and the number of megapixels in the sensor.\nThis camera is from 2013, by today\u0026rsquo;s standards: slow, sluggish autofocus, mediocre EVF (electronic viewfinder). The 16-megapixel APC sensor is the Xtrans 1, which was Fuji\u0026rsquo;s first digital sensor in the X series. In 2025, Fuji will be on version 5. For more secs and review on DPreview\nThis was also the first Fuji camera where you could adjust the settings for JPEG photos. Later versions of Fuji sensors have turned these features into a real community. Look at e.g. Ross and his JPEGs or fujifilmsimulations.com\nMy recipe of choice is the Fuji Porta 400 Simulation, because of the limited option of the Xtrans 1 processor, you can\u0026rsquo;t alter many parameters. Favorite Film Recipe: Porta 400 The settings for JPEG are from Kodak Porta 400 by Piotr Skrzypek FujiFilm Recipes\nSimulation: Pro Negative High\nDR : auto White Balance: 6300-6700K (-1 R, 0 B, 0 G) Highlights: -2 Shadows: 0 Color: 0 Sharpness: -2 Nr: -2 Exp comp: as you like, I usually give it +1, +1⅓ This recipe gives the SOOC (Straight Out Of Camera) jpegs a nice punch an a classic film style look from this analog film. These settings are best on bright and sunny days, the color are vibrant and warm. The color temparture is relative high, so every color this pushed to the warm site. Her are a few examples made with Fuji X-E1 and 23mm/f2.0 objective (35mm Full-Frame equivalent) ","date":"2025-08-30T05:33:58+02:00","permalink":"/en/blog/fuji-xe1/","title":"30-08-2025 - Using my Fuji X-E1 in 2025"},{"content":"Leading Lines This was a asignment from our local photoclub, for this month. I made a walked arround my neighbourhood in Scheveningen, the Outer Harbour and the South Pier.\nThis a a old street with characteristic houses and architecteur. This is the Koppelstokstraat in Scheveningen, just behind the last innner harbour.\nIn the harbour of Schevening was this ship docked\nMy walk ended at the Scheveningse South Pier. ","date":"2025-08-15T16:13:17+02:00","permalink":"/en/blog/14-08-2025-leading-lines/","title":"14-08-2025 - Leading Lines"},{"content":"Montly assignment: trip to Clingendael in the Hague Our monthly asssigment of our local photoclub was a trip to Estate Clingendael\nThis estate is famous for his Japanese Garden, Big Mansion House and a beautifull park with old and special trees. It is situated is north-west of the Hague and against the village Wassenaar.\nThe weather was heavenly overcast and rainy, not the ideal situation the make photos of the landscape or buildings. Later that morning there was sometimes a ray of sunlight, very sporadic and for a period short time. My own assignment for that day was: Shoot a sequence. My sequence was the number of trees in one photo.\nOld tree with a many roots Very large tree with big branches Two trees on slope with bed of moss. Tree tree and blurry runner. This was the my best photo of the day. The static trees and the moving jogger are each other\u0026rsquo;s counterparts, the stair leads the eye to the jogger Four trees equal seperated in the frame ","date":"2025-07-05T12:47:19+02:00","permalink":"/en/blog/05-07-2025-trip-to-clingendeal/","title":"05-07-2025 - Trip to Clingendeal"},{"content":"Montly assignment: trip to Westbroekpark in the Hague Our monthly asssigment of our local photoclu was a trip to Westbroekpark in the Hague / Scheveningen. The Westbroekpark is situated in Scheveningen and surrounded by water. This park is also well-know for his Rosarium, a beautiful flowerbed with many varieties of roses. This is park also used for events and festivals. There is also a nice restaurant with good coffee.\nThe weather was sunny and warm, but the roses were not in bloom because it was too early in the season. I found it challenging to take a few decent photos. These photos are not award-winning, but good enough to show at our photo club.. Couple of Canadian Geese Beautifull pond with reflection with nice spring colors. Beautifull flower in bright sunlight, Darmera peltata (Dutch: Schildblad) THe first and the thrid photo are made with a 105mm macro lenses, the second one with a 24-70mm/ F2.8 lenss\n","date":"2025-05-03T18:46:09+02:00","permalink":"/en/blog/westbroekpark/","title":"03-05-2025 - Trip to the Westbroekpark"},{"content":"Montly assignment: Still Life Our monthly asssigment of our local photoclub was create a still-life.\nThe next photo you see, how the setup was of this photo.\nThe natural light was coming from the left of the kitchen window. On the far left side, I put a white ordner, that was laying arround. I need something to block the main light to my backgroud, otherwise the the light from the foreground and backgroudn was to equal. I wanted that my subject was separated by a darker the background. Behind the scene At the right site, at the front, i used a golden card board, to reflect some light, from the windows, to fill in the \u0026quot; shadow\u0026quot; side of the the scene. I nice aadvantage, that the gold reflector warming up the color of the paprika. Lesson learned In a kitchen are a pletora things you use to photograph a still life, you can photograph tools, vegatables, fruit, etc. You can use cheap and inexpensive material to create reflector to bounce or block light Playing light and reflectors are great fun to learn how to control the light. ","date":"2025-04-29T13:31:43+02:00","permalink":"/en/blog/still-life/","title":"29-04-2025 - Still Life"},{"content":"Snorkeling On our 8-day-trip to the Galápagos we snorkeled almost every day. Either we dove in the water from the Aida Maria or we took a dinghy.\nThe Galápagos islands are beautiful. However, it may be more beautiful underwater than above water.\nCheck out our best snorkeling pics below (snapshots we took with our GOPRO).\n","date":"2015-01-05T00:00:00Z","permalink":"/en/blog/galapagos-2014-2015/","title":"Snapshots - Snorkeling"},{"content":"Isla North Seymour After an early breakfast today we disembarked at Isla North Seymour. On Isla North Seymour you can see Frigatebirds, the clownish Blue-Footed Booby, and of course the ubiquitous Sea Lions.\nOn Isla North Seymour is the largest colony of magnificent frigatebirds in the Galapagos. One of the bird’s most distinctive features is the male’s scarlet red throat pouch, which he inflates during mating season to attract female Frigatebirds. Frigatebirds are also known as “pirate birds,” due to their proclivity for stealing food from other birds or snatching chicks out of their nests. They’re also exceptionally agile and acrobatic flyers, which no doubt aids them in their thievery.\n?????? Also we could see the striking courtship display of the male Frigate Bird, in which he inflates a red balloon-like sac below his throat and struts his stuff for all of the young females.\nAfter we returned to the boat, the boat navigated to Isla Baltra where we catched our plane back to Quito.\n","date":"2015-01-04T00:00:00Z","permalink":"/en/blog/galapagos-2015-01-04/","title":"04-01-2015 - Isla North Seymour"},{"content":"Isla Santiago + Isla Rábida Isla Santiago (also known as San Salvador) is recognizable by its varied landscape of black sand beaches and lava fields. Here you can see beautiful examples of lava flows: sharp and fragile A\u0026rsquo;ā lava and smooth winding Pahoehoe flows. Erosion by sea and wind grinds the black lava into black sand, creating this unusual beach.\nA\u0026rsquo;ā lava is a type of basaltic lava flow with a rough crumbly surface consisting of sharp, spiky lava blocks called “clinkers.” It is thicker and stickier than Pahoehoe lava, causing it to flow more slowly, but it has a dense hot core. As it cools, it forms impassable irregular terrain.\nPahoehoe lava is a type of fluid basaltic lava with low stickiness that is known for its smooth rope-like (ropy) or wavy (billowy) surface structures. It is the “smooth” counterpart to rough A\u0026rsquo;ā lava and can travel long distances, often in lava tunnels, because it cools and solidifies less than other lava types.\nThis morning we went to James Bay and Puerto Egas on the northwest coast of Isla Santiago.\nPuerto Egas was once the site of a salt mine, but today it’s known for its black sand beach, grottoes, and a colony of fur seals. A leisurely trail takes you through the otherworldly terrain of black lava deposits to the grottoes. This is where you’ll spot the timid fur seals, easily distinguished from the sea lions by their lustrous fur coats, resting on the rocks or paddling around the grottoes.\nThere is a natural lava bridge.\nPuerto Egas is also home to the remarkable Galapagos hawks and the swift Galapagos lava lizards. Furthermore, there are large populations of marine iguanas.\nSouth of the beach is Sugarloaf Volcano, which has deposits of volcanic tuff, the same that helped the formation of the black sand beach.\nEl Cráter is just north of this site, it has a saltwater lagoon, which during the summer dry season becomes a salt mine. Between 1928 and 1930 was the first exploitation of salt; but the efforts did not last long. Then again in 1964 a new attempt was made that lasted for some time.\nAfter the walk we returned to a black sand beach where we could snorkel.\nAfter lunch we navigated to our next destination: Isla Rábida.\nIsla Rábida is a small volcanic island known for its striking red sand beaches and cliffs. Behind the red sand beach is a coastal lagoon and you can walk a loop trail. The approximate distance of the trail is 1.1 kilometers.\nThe red color of the rocks and sand on the beach is due to the high iron content in the lava and the very porous volcanic material, which has acted as an oxidizing agent with the help of environmental factors (rain, salt water and sea breeze),.\nThey had said that snorkeling is a must after the visit to Isla Rábida. So that’s what we did. Along the rocky coastline we can saw lots of fish, sea lions and even white tip reef sharks. At first we found it a scary to snorkel above the sharks. But the sharks stayed deep below us and were swimming in circles.\n","date":"2015-01-03T00:00:00Z","permalink":"/en/blog/galapagos-2015-01-03/","title":"03-01-2015 - Isla Santiago + Isla Rábida"},{"content":"Isla Isabela (Caleta Tagus + Punta Espinoza) This morning we went to Caleta Tagus (Tagus Cove). Caleta Tagus is a historic sheltered bay on the west coast of Isla Isabela, west of the Darwin volcano. It is known as a favorite spot and former anchorage for pirates and whalers.\nThere is also a trail that leads to the salt lake Laguna Darwin with views of volcanoes. We walked the trail. The entire distance of the trail is about 1800 meters. At the beginning of the walk, going up and passing the staircase, is a small cave where you will find inscriptions dating to the 1800s.\nThe trail, mostly gravel, leads into the inland along Laguna Darwin. During the walk, we saw various land birds and the characteristic vegetation of the arid zone. Finally we arrived at the point where we could see the lava fields of Darwin Volcano.\nAfter lunch the boat navigated for a short time to Punta Espinoza on Isla Fernandina. Isla Fernandina is most famous for its continuing series of volcanic eruptions. Many of the early visitors to the archipelago reported dramatic changes in the landscape, smoking craters and actual eruptions. The most famous of these is the vivid description from Captain Benjamin Morrell, who witnessed a violent eruption in 1825 and recorded it. This eruption probably resulted in the formation of Punta Espinoza.\nPunta Espinoza is a narrow ledge of lava and sand that extends from the base of the volcano to the sea. In 1975, there was an uprising, about 90 cm, which is why the pier built for landing can only be used during high tide.\nPunta Espinoza is a place famous for its large colonies of Marine Iguanas as well as being home to unique species like the Flightless Cormorant, the Galápagos Penguin, the Galápagos Hawk and the Galápagos Snake, among others. It’s an ideal place to observe the lava cactus (Brachycerus Nesioticus), which grows on young lava and can survive with little water.\nIf the weather conditions were good, we would go ashore and we could also go snorkeling. ……………………….\nAfter our visit to Isla Fernandina, the boat started its navigation to the central part of the Galápagos. On the way we saw Punta Vicente Roca, a mostly eroded volcano which now is a great site to spot Blue Footed Boobies, Frigate Birds and other marine birds from the boat.\n","date":"2015-01-02T00:00:00Z","permalink":"/en/blog/galapagos-2015-01-02/","title":"02-01-2015 - Isla Isabela-2"},{"content":"Isla Isabela (Punta Moreno + Bahía Elizabeth) After a long boat trip we arrived this morning at Punta Moreno on the west coast of Isla Isabela. Punta Moreno is known for its vast black lava fields and unique adapted flora.\nWe went ashore on a lava field. The vegetation found in this area is sparse and is mainly concentrated in the mangrove area and around the lakes. However there are 3 kinds of cacti found here: •\tLava cactus (Brachycereus nesioticus): a pioneer species that grows directly on lava fields •\tOpuntia cactus (prickly pear): recognizable by its disc-shaped segments •\tJasminocereus thouarsii (candelabra cactus): a large columnar cactus\nThe other attractions at Punta Moreno are the coastal lagoons amid black lava flows, which are home to several species of birds. You also have a panoramic view of 3 of the most active volcanoes in the Galápagos: •\tSierra Negra •\tCerro Azul de la Isla Isabela •\tLa Cumbre de la Isla Fernandina\nAfter lunch we took the motorboat to Elizabeth Bay (Bahía Elizabeth), located on the west shore of Isla Isabela. This is an excellent spot for observing marine life. We motored past a few islands where you can usually see Galápagos Penguins. A colony of these magnificent birds inhabit a rocky islet at the entrance to Elizabeth Bay. This is one of the best areas to take pictures of these penguins.\nOur motorboat drifted through a small passage lined with mangroves and eventually emerged into an enclosed cove. In the bay the motor was turned off and we were able to look in the sheltered waters for Sea Turtles, Rays, Flightless Cormorants and Sea Lions. Galápagos Hawks circled above us.\n","date":"2015-01-01T00:00:00Z","permalink":"/en/blog/galapagos-2015-01-01/","title":"01-01-2015 - Isla Isabela"},{"content":"Isla Isabela Today we visited Isla Isabela. Isla Isabela is the largest island in the Galápagos archipelago. The island was formed by 6 volcanoes that grew together. First we went to Puerto Villamil. This is the largest town on Isabela with approximately 2000 inhabitants. Puerto Villamil is located right in front of a white sand beach and is one of the most beautiful spots in the islands.\nAfter that went to the Humedales. Humedales is the Spanish word for “wetlands”. This is an area with mangroves, swamps, and lakes just outside the town of Puerto Villamil. The small brackish water lagoons create the perfect environment for a small type of shrimp that serves as the food for the island’s flamingos.\nThen we went to El Muro de las Lágrimas (“The Wall of Tears”). When the Ecuadorian government first took possession of the Galápagos islands their main purpose was to house Ecuadorian prisoners. Since there wasn’t much for them to do, they were forced to carry rocks to a far location and build a wall. Nowadays this wall is known as “The Wall of Tears”. Then we returned to the beach for some relaxation and snorkeling. Afterwards we enjoyed another delicious lunch on the boat.\nIn the afternoon we visited the local branch of the Galápagos Park Service, whose main purpose is to take care of the many species of giant tortoises that live Isla Isabela Island. We saw the efforts made by the National Park Service to protect and increase the declining population of giant tortoises on this island. At this center you can learn everything there is to know about the five different species of giant tortoises found on Isabela Island.\nIn the evening we went to celebrate New Year\u0026rsquo;s Eve in the city center\u0026hellip; It is a tradition among the local population to make a doll or image out of papier-mâché. The dolls/images are burned late on New Year\u0026rsquo;s Eve. They believe that by burning them, they also burn away all the sins and negative experiences of the past year. This brings good luck for the new year. They also release wish balloons. There were a lot of them. People stand underneath them, which can sometimes be dangerous if a wish balloon suddenly catches fire and drops down burning. During the night the boat navigated to the west coast of Isla Isabela.\n","date":"2014-12-31T18:46:09+02:00","permalink":"/en/blog/galapagos-2014-12-31/","title":"31-12-2014 - Isabela Island"},{"content":"Isla Santa Cruz After breakfast we have visited Puerto Ayora (on Isla Santa Cruz). On Isla Santa Cruz is the world famous Charles Darwin Research Station as well as the giant tortoises rearing center \u0026ldquo;Fausto LLerena \u0026ldquo;. We were going to the Charles Darwin Research Station. On our way we came across the local fishmarket. Especially fun to see, were the pelicans and sealions begging for fish. After this we walked to the Charles Darwin Research Station. This is one of the best places to see giant tortoises, including the place where Lonesome George used to live.\nCharles Darwin visited the Galápagos Islands aboard the research vessel Beagle in September 1835. He spent approximately five weeks studying the geology and biology of four of the islands. His findings during this visit to the archipelago contributed to Darwin\u0026rsquo;s development of his ideas about the evolution of species: the theory of evolution.\nWe visited the Charles Darwin Research Station. At the Charles Darwin Research Station you can find baby tortoises the size of a hand, between the ages of one and five years old and marvel at how they achieve such large sizes as adults (500 lbs. or more!). Galápagos tortoises are believed to have a lifespan of over 100 years, so the young ones have a long life ahead of them as long as they receive the protection they need. Puerto Ayora is the largest town on Isla Santa Cruz and the economic center of the Galápagos. In this portside town you can find shops and the local market where you can buy the unique Galápagos handicrafts.\nAfter shopping in Puerto Ayora we had lunch on the boat. Then we explored the highlands or “ parte alta ” of the island. This is a moisture-rich area with fertile volcanic soils. The guide todl about the vegetation and animal life of this zone, which often differs strikingly from that found at lower elevations.\nDarwin’s Finches, yellow warblers, and bright red Vermillion flycatchers flew in and out of the moss-covered trees.\nFrom this high vantage point we were treated to beautiful views of the surrounding archipelago.\n","date":"2014-12-30T18:46:09+02:00","permalink":"/en/blog/galapagos-2014-12-30/","title":"30-12-2014 - Santa Cruz Island"},{"content":"Isla Sante Fé en Isla Plazas After breakfast we visited Isla Santa Fé. Isla Santa Fé is located southeast of Isla Santa Cruz. The island is uninhabited. Tourists are allowed to go ashore at Barrington Bay. The island has the greatest variety of native animal species of all the Galapagos Islands.\nWhen we arrived on the island, we were treated to a noisy welcome from the local sea lion colony. With our guide we walked along the paths on the island. The main attraction of Isla Santa Fé is a towering forest of giant cacti. Scattered among the cacti were some of the island\u0026rsquo;s indigenous sun-seekers: marine and land iguanas, rainbow- streaked lava lizards, and lots of land birds, such as Darwin\u0026rsquo;s finches and Galápagos doves.\nAfter the walk we went snorkeling again in the company of beautiful fishes and sea turtles. Then we returned to the boat for lunch.\nAfter lunch, we navigated to Islas Plazas. Islas Plazas are two small elongated islands: North Plaza and South Plaza. Both islands are located close to the east coast of Isla Santa Cruz. They are both flat islands consisting of raised ocean floor covered with lava. South Plaza is the smallest island that can be visited by tourists. North Plaza is even smaller, but is a nature reserve and not accessible to visitors.\nOn the island, there is a large colony of sea lions lounging in the sun every day. South Plaza also boasts beautiful examples of typical Galápagos native flora, such as “sesuvium,” a plant that changes color depending on the season. There are also opuntia cacti, which are the principal diet for both land iguanas and Darwin\u0026rsquo;s finches. Other birds that may flutter by include lava gulls, yellow warblers, and red-billed tropicbirds.\n","date":"2014-12-29T18:46:09+02:00","permalink":"/en/blog/galapagos-2014-12-29/","title":"29-12-2014 - Santa Fé Island + Plazas Island"},{"content":"From Quito to the Galapagos Islands We booked an 8-day trip to the Islas Galápagos. These islands are located near the equator, about 1000 km off the west coast of South America. These islands are a province of Ecuador and consist of 127 islands, of which only 4 are inhabited. All of the islands belong to the Galápagos National Park. This is a unique protected nature reserve (since 1959). The islands have been on UNESCO\u0026rsquo;s World Heritage List since 1978. In 1981, the surrounding ocean was declared a marine reserve. The Galápagos National Park covers 97% of the archipelago. This means that the landscape is protected by strict regulations to preserve the fragile ecosystem. The archipelago consists of 13 main islands and many smaller islands. The 13 largest Galápagos islands have a surface area in km² of (in order of size):\nIsabela 4588 km² Santa Cruz 986 km² Fernandina 642 km² San Salvador / Santiago 585 km² San Cristóbal 558 km² Floreana / Santa María 173 km² Marchena 130 km² Española 60 km² Pinta 59 km² Baltra 26 km² Santa Fe 24 km² Pinzón 18 km² Genovesa 14 km² Today we flew from Quito (Ecuador) to Isla San Cristóbal (Galápagos). We were picked up at the airport of Isla San Cristóbal and taken to the boat “Aida Maria”.\nWe will be staying on this boat for 8 days (7 nights). The boat can accommodate up to 16 people in 8 cabins for 2 people (there are 15 people on this trip). Breakfast, lunch, and dinner will be served on the boat. On the photo below you can see the area where we always eat. We go down the stairs to our cabin (unfortunately with bunk beds). The boat often sails to a new location at night. Below you can see the trip we are currently making. After the delicious lunch the boat navigated to Isla Lobos. Isla Lobos is a very small islet off the coast of Isla San Cristobal, made of volcanic rocks and named after the colony of sea lions ( Lobo de Mar in Spanish ) living there. Here you can observe the behaviour and interaction of sea lions living in a small community. After this visit on Isla Lobos we went snorkeling. Tonight we will cruise to Isla Santa Fé. ","date":"2014-12-28T00:00:00Z","permalink":"/en/blog/galapagos-2014-12-28/","title":"28-12-2014 - From Quito to the Galapagos Islands"}]