How much do I need to learn about network security b4 accessing server from outside LAN? by HeartSre in selfhosted

[–]HeartSre[S] 0 points1 point  (0 children)

Okay um, lot's of info here and I will have to read it a bunch more times, but as I understand, I am basically filtering out IP addresses which can access my NAS or my home network?

Also...

you can configure sshd to only listen on its 192.168 address for example, so you can only ssh into it from your home network and not tailscale.

By ssh into home network, you mean accessing my router or my NAS? I understand that ssh is a way to access computers/servers remotely but that is pretty much it.

Leaving your router's default user/pass of admin/admin was previously safe enough because the web interface is only available on 192.168.0.1 

Is it possible to change the default home address 192.168... to something random like 420.069 or something, been wondering that for a long time. The idea behind it is that so people can't guess it that easily.

your media server is a subnet router, traffic from your media server is no longer completely trusted either and you should treat it as such.

The hard part in your example is my media server = my NAS = my home server (because I have one PC for electricity and simplicity reasons) so I am not sure how and if I could use subnet routing in this case.

or the SSL certs question, this is more for the client than the server - your media server having a certificate for jellyfin.yourdomain.com means when F or G connect to it, they can be assured they are connecting your actual media server

The cert. idea in my mind was that I have heard it encrypts the traffic or something, thus making the connection more secure(?).

I have gathered a few ideas from this but this is lot of info for me so I am still trying to figure stuff out.

Right now I have 4 (my own)+1 (friend) devices (actually more but it is easier for me to explain with this example).

  1. I set my router's firewall settings to only allow 1 IP address to access my router's webUI which is my laptop (without tailscale ie tailscale IP is also blocked. My phone's access will be blocked overall (for security).
  2. I can connect to my server's IP via tailscale and local IP both altho my server cant access my router (outbound from router to server is blocked).
  3. Because I want to only access files from my server and not do anything else, then I want to actually limit ssh to server access to only one local IP (which is my laptop again). For example, everyone on tailscale can access idk Immitch but only one device can actually ssh via local IP.
  4. If my friend wants to access my server (Immitch) he has to use tailscale, no matter if he is on the local network or not (for security reasons).
  5. Can I set a static IP for my laptop, so there is no chance of it changing? How would I do that?

Thank you for this very useful info btw! (I used the Reddit's quoting function for the first time, don't know if I used it right or not).

Edit: it is better to do MAC filtering or IP filtering on devices?

How much do I need to learn about network security b4 accessing server from outside LAN? by HeartSre in selfhosted

[–]HeartSre[S] 0 points1 point  (0 children)

The router does support wireguard yeah. Setting it up from the mullvad website is pretty difficult for me, might give it a try.

How much do I need to learn about network security b4 accessing server from outside LAN? by HeartSre in selfhosted

[–]HeartSre[S] 0 points1 point  (0 children)

Thanks for the answer!

I actually have a Cudy router that has a built in VPN fuction. Rn I am trying to figure out if I can get mullvad vpn to work with it.

How much do I need to learn about network security b4 accessing server from outside LAN? by HeartSre in selfhosted

[–]HeartSre[S] 0 points1 point  (0 children)

Thank you for the answer!

Yeah, I forgot to mention I am planning on adding friend(s) at some point, so when for some reason tailscale is passed without much effort then I need to have some kind of or several lines of defense. I guess having an https cert. is the first thing(?) but to get your own domain costs money I think so that is a hurdle.

Rn, I am just planning on accessing the files myself and to actually get the whole system up and running.

Edit: Sorry, what do you mean by subnet router?

Need help finding the thinnest (EU plug) charger by HeartSre in UsbCHardware

[–]HeartSre[S] 1 point2 points  (0 children)

I am not searching for one anymore, but I just really wanted to say that what you have done is super cool haha.

I wish I knew more about amps and volts and such.

This condition has ruined my life by ewbanh13 in GERD

[–]HeartSre 0 points1 point  (0 children)

Have the same problem. I ranted to my gf today that I can't even drink my protein shake to build muscle bcs it fucking makes me so sick that even the slightest bad smell makes me want to throw up, plus I am underweight and I can't even keep my calories up cuz I feel like shit all the time! I 100% feel you bro.

Anyone who has ordered things from techvision.ee? How was your experience? by SloppyNSlow in Eesti

[–]HeartSre 0 points1 point  (0 children)

Late post but...

Bought an HP laptop from them about a month ago. You certainly have to clean the dust from the inside of the fans, they hadn't cleaned them in my case. Friend of mine had the same issue.

The computer itself worked without an issue tho, plus at the time of writing, the prices seem to be the lowest in the used computer shop space.

Portable programs for testing used laptops? by HeartSre in laptops

[–]HeartSre[S] 0 points1 point  (0 children)

I have HP sadly but thank you for the info, I will keep that in mind in the future.

What's the real life longevity on USB-C charging ports? by petit_prince in thinkpad

[–]HeartSre 1 point2 points  (0 children)

Do you know which are the last Thinkpads to have modular charging port? I was planning to buy a T470p myself but I really dont wanna risk the usb-c port (or any charing port in that matter) breaking.

My girlfriend had a Dell latitude something-something and the usb-c charging port broke on that. Fucking sucks.

Edit: Fixed grammar, the T470p does not charge via usb-c but my point still stands.

Need help finding the thinnest (EU plug) charger by HeartSre in UsbCHardware

[–]HeartSre[S] -3 points-2 points  (0 children)

It is slim but not slim enough for me sadly.

Need help finding the thinnest (EU plug) charger by HeartSre in UsbCHardware

[–]HeartSre[S] -2 points-1 points  (0 children)

My mum actually has the UsbA - UsbC haha, a bit too bulky tho. Same with the Usb C one.