athes

joined 2 years ago
[–] [email protected] 2 points 1 month ago (12 children)

Thx for the feedback, I don't have multiple router no. If I had would it be still called VLAN? I thought the V was Virtual for achieving that LAN segmentation with one router. With one router, don't you think the security added is the same level as configuring a firewall on each VM/LXC ?

[–] [email protected] 2 points 1 month ago

Yes the idea is to make it easier to isolate/configure firewall rules and try to protect more sensitive data. (i.e. I don't care much if people can access my ISOs ;) However, at the end of the day they are all on the same Proxmox host.

[–] [email protected] 1 points 1 month ago (1 children)

They are all defined as 192.168.x.y/24 Doesn't this make them in different subnets?

43
submitted 1 month ago* (last edited 1 month ago) by [email protected] to c/[email protected]
 

Hello,

Just spent a good week installing my home server. Time to pause and lookback to what I've setup and ask your help/suggestions as I am wondering if my below configuration is a good approach or just a useless convoluted approach.

I have a Proxmox instance with 3 VLAN:

  • Management (192.168.1.x) : the one used by proxmox host and that can access all other VLANs

  • Servarr (192.168.100.x) : every arr related software + Jellyfin (all LXC). All outbound connectivity goes via VPN. Cant access any VLAN

  • myCloud (192.168.200.X): WIP, but basically planning to have things like Nextcloud, Immich, Paperless etc...

The original idea was to allow external access via Cloudlfare tunnel but finally decided to switch back to Tailscale for "myCloud" access (as I am expected to share this with less than 5 accounts). So:

  • myCloud now has Tailscale running on it.
  • myCloud can now access Servarr VLAN

Consequently to my choice of using tailscale, I had now to use a DNS server to resolve mydomain.com:

  • Servarr now has pihole as DNS server reachable across all VLAN

On the top of all that I have yet another VLAN for my raspberry Pi running Vaultwarden reachable only via my personal tailscale account.

I'm open to restart things from scratch (it's fun), so let me know.

Also wondering if using LXCs is better than docker especially when it comes to updates and longer term maintenance.

[–] [email protected] 1 points 2 months ago* (last edited 2 months ago) (1 children)

But this implies the check happens on my server right ? Which probably makes sense for advanced hosters.

 

Hello,

Long time lurker, first time poster and eternal newbie in selfhosting.

I have installed cloudflare tunnel in order to allow my Emby installation to be reached externally. (Previously was using tailscale but now trying this solution to expand my 'reach' and include my parents houshold)

The tunnel with email OTP works like a charm, but the access seems to be browser specific, so the Emby app doesn't seem to be able to connect (as it faces the email OTP challenge I suppose)

Is there a way to combine both?

I actually went down the path of writing a little script that tries to authorize the IP of someone that managed to pass the OTP challenge via browser. ( I get the user's IP and update the cloudflare policy via its API)

Seems to be overkill, any suggestions?

Thx

[–] [email protected] 0 points 2 years ago (3 children)

Honeygain etc.... First time I hear about them. Do you mind sharing how much you get?