Comment on How safe is self-hosting a public website behind Cloudflare?

<- View Parent
Gooey0210@sh.itjust.works ⁨10⁩ ⁨months⁩ ago

Can i ask you to elaborate on this part

Assume at all times that the box is toxic waste and that is an entry point into your network. Leave it isolated. No port forwards, you already have tunnels for that, don’t use it for DNS don’t use it for DHCP, Don’t allow You’re network users or devices to see ARP traffic from it.

I used to have a separate box, but the only thing it did was port forwarding

Specifically i don’t really understand the topology of this setup, and how do i set it up

source
Sort:hotnewtop