• Mio@feddit.nu
    link
    fedilink
    English
    arrow-up
    1
    ·
    4 hours ago

    Wireguard VPN. I actually have a public hosted Oracle server that when authentic opens port 443 for that source IP temporary so no VPN will be needed. Computer visit free pub Oracle VM. Android Phone scan QR, start Wireguard and auth that user. Computer can now reach my home server on port 443 and 22 for 24 hours as the source IP is allowed.

    I do this instead of crowdsec etc. I expect zero days vulnerabilities that someone will utilize so dont trust nginx and ssh to be wide open.

    • soyslurper2@lemmy.dbzer0.comOP
      link
      fedilink
      English
      arrow-up
      1
      ·
      2 hours ago

      You have Authentik guarding your Wireguard key on a public server?

      I’m not sure how this is different from having Authentik on your home server, unless the point is to hide your IP address