Comment on ELI5: How to put several servers on one external IP?
Allero@lemmy.today 2 days agoI do remember that and take quite a few precautions. Also, nothing that can be serioisly used against me is in there.
Comment on ELI5: How to put several servers on one external IP?
Allero@lemmy.today 2 days agoI do remember that and take quite a few precautions. Also, nothing that can be serioisly used against me is in there.
hietsu@sopuli.xyz 2 days ago
I have wrestled with the same thing as you and I think nginx reverse proxy and subdomains are reasonably good solution:
Only fault I’ve discovered are some public ledgers of TLS certs, where the certs given by letsencrypt spill out those semi-secret subdomains to the world. I seem to get very little to no bots knocking my services though so maybe those are not being scraped that much.
Allero@lemmy.today 2 days ago
Pretty solid! Though insta-ban on everything :80/443 may backfire - too easy to just enter the domain name without subdomain by accident.
hietsu@sopuli.xyz 2 days ago
Could be indeed. Looking at the nginx logs, setting a permaban on trying to access /git and a couple of others might catch 99% of bots too. And ssh port ban trigger (using knockd for example) is also pretty powerful yet safe.