Comment on OpnSense + Crowdsec = comfort

<- View Parent
lemmyvore@feddit.nl ⁨1⁩ ⁨week⁩ ago

If your services are private they should be behind access authorization or completely private access. Scanning should be a non-issue.

You can further mitigate scanning by getting wildcard certs, putting A/AAAA records on an obfuscated sub-domain rather than the base domain, and not using wildcard CNAME’s.

If they services are public you should be using a CDN anyway. If you don’t like the way Cloudflare does things they’re not the only CDN around, but some of the privacy issue is moot when running a public service.

original
Sort:hotnewtop