Allero

joined 2 years ago
[–] Allero@lemmy.today 1 points 1 week ago* (last edited 1 week ago) (2 children)

Thanks! I got that advice as well, but I would like to keep it self-hosted - I consider using Pangolin on a VPS for that purpose going forward: https://github.com/fosrl/pangolin

Also, beware of the new attack on Cloudflare Tunnel: https://www.csoonline.com/article/4009636/phishing-campaign-abuses-cloudflare-tunnels-to-sneak-malware-past-firewalls.html

[–] Allero@lemmy.today 1 points 1 week ago* (last edited 1 week ago)

Thanks, I will! Wise of you not to share it publicly for security reasons

[–] Allero@lemmy.today 1 points 1 week ago (11 children)

Yes, I know where this feature is in the settings, but it's got its own issues and I also turn the NAS off for the night, so it's not an option for me.

[–] Allero@lemmy.today 1 points 1 week ago* (last edited 1 week ago)

Guess I am going ahead of myself, yes, which gets even more complicated by having another server (Synology NAS) already installed and messing with networking a little, as internal settings appear to expect the NAS to be the only exposed thing on the network.

Thanks for the link! I've seen that thumbnail, but most guides are solely focused on actually installing Nginx Proxy Manager, which is the easy part, and skip the rest, so I glanced that one over.

P.S. Looks like I did everything right, I just need to sort my SSL stuff to work properly.

[–] Allero@lemmy.today 1 points 1 week ago (1 children)

Pretty solid! Though insta-ban on everything :80/443 may backfire - too easy to just enter the domain name without subdomain by accident.

[–] Allero@lemmy.today 2 points 1 week ago
[–] Allero@lemmy.today 1 points 1 week ago

Interesting!

But I don't want to mix it too much. I do have a Docker on it with just some essentials, but overall I'd like to keep NAS a storage unit and give the rest to a different server.

I treat NAS as an essential service and the other server as a place to play around without pressure to screw anything

[–] Allero@lemmy.today 1 points 1 week ago (3 children)

I do remember that and take quite a few precautions. Also, nothing that can be serioisly used against me is in there.

[–] Allero@lemmy.today 3 points 1 week ago (2 children)

I will eventually!

But for all I understand, it is to put many services on one machine, and I already have a NAS that is not going anywhere

[–] Allero@lemmy.today 4 points 1 week ago* (last edited 1 week ago)

No truly private photos ever enter the NAS, so on that front it should be fine.

VPN is not an option for several reasons, unfortunately.

But I do have a Let's Encrypt certificate, firewall and I ban IP after 5 unsuccessful login attempts. I also have SSH disabled completely.

SSL Test gave me a rating of A

[–] Allero@lemmy.today 2 points 1 week ago (2 children)

Oh, nice! So I don't have just one, but many external IPs, one for every local device?

view more: ‹ prev next ›