Allero

joined 2 years ago
[–] Allero@lemmy.today 1 points 3 weeks ago (1 children)

Pretty solid! Though insta-ban on everything :80/443 may backfire - too easy to just enter the domain name without subdomain by accident.

[–] Allero@lemmy.today 2 points 3 weeks ago
[–] Allero@lemmy.today 1 points 3 weeks ago

Interesting!

But I don't want to mix it too much. I do have a Docker on it with just some essentials, but overall I'd like to keep NAS a storage unit and give the rest to a different server.

I treat NAS as an essential service and the other server as a place to play around without pressure to screw anything

[–] Allero@lemmy.today 1 points 3 weeks ago (3 children)

I do remember that and take quite a few precautions. Also, nothing that can be serioisly used against me is in there.

[–] Allero@lemmy.today 3 points 3 weeks ago (2 children)

I will eventually!

But for all I understand, it is to put many services on one machine, and I already have a NAS that is not going anywhere

[–] Allero@lemmy.today 4 points 3 weeks ago* (last edited 3 weeks ago)

No truly private photos ever enter the NAS, so on that front it should be fine.

VPN is not an option for several reasons, unfortunately.

But I do have a Let's Encrypt certificate, firewall and I ban IP after 5 unsuccessful login attempts. I also have SSH disabled completely.

SSL Test gave me a rating of A

[–] Allero@lemmy.today 2 points 3 weeks ago (2 children)

Oh, nice! So I don't have just one, but many external IPs, one for every local device?

[–] Allero@lemmy.today 1 points 3 weeks ago (2 children)

Where do I type rpi's IP, just in port forwarding? Or somewhere else?

I want for Nginx proxy, controlled through the Manager, to direct traffic to different physical servers based on subdomain.

I put in nas.my.domain and I get my Synology on its DSM port. I put in pi.my.domain and I get a service on my Pi.

[–] Allero@lemmy.today 5 points 3 weeks ago (7 children)

Just me and the people I trust, but there are certain inconveniences around using VPN for access.

First, I live in the jurisdiction that is heavily restrictive, so VPN is commonly in use to bypass censorship

Second, I sometimes access my data from computers I trust but can't install VPN clients on

Third, I share my NAS resources with my family, and getting my mom to use a VPN every time she syncs her photos is near impossible

So, fully recognizing the risks, I feel like I have to expose a lot of my services.

[–] Allero@lemmy.today 3 points 3 weeks ago

Thanks for the pieces of advice! Yes, I tried to connect from external (mobile) network as well.

[–] Allero@lemmy.today 2 points 3 weeks ago* (last edited 3 weeks ago) (2 children)

While not supportive of Big Tech, I do appreciate your piece of advice, and understand self-hosting needs differ!

P.S. Also beware, seems like there's a new attack through Tunnels:

https://www.csoonline.com/article/4009636/phishing-campaign-abuses-cloudflare-tunnels-to-sneak-malware-past-firewalls.html

view more: ‹ prev next ›