• @Bdaman@sh.itjust.works
    link
    fedilink
    English
    559 months ago

    The only externally accessible service is my wireguard vpn. For anything else, if you are not on my lan or VPN back into my lan, it’s not accessible.

      • @sunbeam60@lemmy.one
        link
        fedilink
        English
        89 months ago

        Funnily enough it’s exactly the opposite way of where the corporate world is going, where the LAN is no longer seen as a fortress and most services are available publically but behind 2FA.

        • @AtariDump@lemmy.world
          link
          fedilink
          English
          9
          edit-2
          9 months ago

          Corporate world, I still have to VPN in before much is accessible. Then there’s also 2FA.

          Homelab, ehhh. Much smaller user base and within smackable reach.

          • @sunbeam60@lemmy.one
            link
            fedilink
            English
            19 months ago

            Oh right. The last three business I’ve worked in have all been fully public services; assume the intruder is already in the LAN, so don’t treat it like a barrier.

      • Footnote2669
        link
        fedilink
        English
        39 months ago

        Not OP but… I have an old PC as a server, Wireguard in docker container, port-forward in the router and that’s it

      • @JDubbleu@programming.dev
        link
        fedilink
        English
        19 months ago

        Not OP, but I just use ZeroTier for this since it’s dead simple to setup and free. I’m sure there’s some 100% self-hosted solutions, but it’s worked for me without issue.

      • @Bdaman@sh.itjust.works
        link
        fedilink
        English
        19 months ago

        Sorry, haven’t logged on in a bit. I use OPNSense on an old PC for my firewall with the wireguard packet installed.

        Then use the wireguard client on my familys phones/laptops that is set to auto connect when NOT on my home wifi. That way media payback, adguard-home dns and everything acts as seamless as possible even when away while still keeping all ports blocked.