you are viewing a single comment's thread
view the rest of the comments
[–] 55 points 2 years ago (11 children)

The only externally accessible service is my wireguard vpn. For anything else, if you are not on my lan or VPN back into my lan, it’s not accessible.

  • source
  • hideshow 11 child comments
  • [–] 9 points 2 years ago (3 children)
  • [–] 8 points 2 years ago (2 children)

    Funnily enough it’s exactly the opposite way of where the corporate world is going, where the LAN is no longer seen as a fortress and most services are available publically but behind 2FA.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 9 points 2 years ago* (1 child)

    Corporate world, I still have to VPN in before much is accessible. Then there’s also 2FA.

    Homelab, ehhh. Much smaller user base and within smackable reach.

  • source
  • parent
  • hideshow 1 child comment
  • [–] 2 points 2 years ago (6 children)

    Can I ask your setup? I'd like to get this for myself as well.

  • source
  • parent
  • hideshow 6 child comments
  • [–] 3 points 2 years ago (2 children)

    Not OP but… I have an old PC as a server, Wireguard in docker container, port-forward in the router and that’s it

  • source
  • parent
  • hideshow 2 child comments
  • [–] 1 point 2 years ago

    Sorry, haven't logged on in a bit. I use OPNSense on an old PC for my firewall with the wireguard packet installed.

    Then use the wireguard client on my familys phones/laptops that is set to auto connect when NOT on my home wifi. That way media payback, adguard-home dns and everything acts as seamless as possible even when away while still keeping all ports blocked.

  • source
  • parent