Skip Navigation

Posts
7
Comments
92
Joined
2 yr. ago

  • It does sound exactly like this. However, I'm concerned about following these instructions when my external IP isn't static. I still have yet to set up DDNS (I believe is the term, for automatically updating my domain's DNS servers with whatever new IP address my ISP gave me), but this looks like it's entirely IP driven.

    EDIT: Actually, I just realized OPNsense has an alias for that, so I'm not sure why their own manual didn't recommend it. I can just set the value to "WAN address". It works! That's step #1 down, and now I'm curious about step #2.

    My local DNS only seems to set up IP address routing, so I'm not sure how to hit my reverse proxy with the subdomain I'm interested in and have it route accordingly; or even just skip the reverse proxy by having that URL internally route to an IP address and port, because there's nowhere to put in a port.

  • Yes, that's exactly what I've done. You still haven't shown me why it's unsafe. If you can't, that's fine. At some threshold or another, nothing is secure. The one thing I know for sure is that that first page, that says it doesn't recommend exposing a port, does not say what you said it does.

  • Probably the number one recommendation I see in self hosting communities is to not open ports directly (other than for a reverse proxy). It seems like a common recommendation no matter the service. To be clear: I am a beginner. I know very little about this, but I've spent months learning. I can't say you're wrong, but I don't think you've made a convincing argument for me to actually understand why Jellyfin is unsafe to expose to the internet compared to any other service.

  • It says exposing a port directly to the internet is not recommended; do you know of any project that would recommend directly exposing a port? What is meaningfully different here?

  • By all means correct me if you know more, but what I tend to see is one or two people here saying that Jellyfin devs don't recommend exposing it publicly, only to be corrected by looking at the actual documentation. I suspect those cautioning against it are on outdated information and that Jellyfin carries much the same risk as exposing any other service.

  • I'm currently only hosting Jellyfin (movies and TV) and Komga (books and comics) on a LAN, but I already bought a domain, and I'll be exposing them via reverse proxy within the next few weeks; maybe even this weekend if everything goes well. After that, Nextcloud is a must for sharing large files, as Google Drive's limits are coming up on me fast, and I'll start test driving Fluxer as a replacement for Discord.

  • I don't think I can read books fast enough to make automation attractive either, haha. I break DRM on Calibre with two plugins, books purchased from Kobo, and then organize on Komga after manually dragging the files.

  • Correct. I have received help from that server in the past, and it's unusable now. Part of what I hope to accomplish is to replace Discord, or at least offer my friends an off-ramp. Getting started with Discord is way easier, and in the year 2026, I wouldn't know what other client to use to look for a community that gives me quick help via live chat. I no longer know how to use IRC, I've found.

  • Hey, just wanted to chime in and say thank you. I think your guide moves a little fast for someone like me, but through omission, I was able to suss out what was wrong, I think. I don't know if it was a default setting or if it was something I picked up without understanding it while trying to fill in the gaps of DNSmasque DHCP, but I had two DHCP Options set; one was a Set option for router[3], and the other was a Set option for dns-server[6]. The fact that you didn't have that in your guide at all led me to try a configuration without them, and now I've got full connectivity on my VLAN. I'll of course now start properly blocking access off rather than leaving everything totally permissive before opening up services to the web.

  • When I was given a similar suggestion, I asked why I would need proxmox for my project, and I was told something along the lines of, "Don't discount their usefulness if you're trying to do this as a career." I am not trying to do this as a career. I already have one of those. I'm trying to replace subscription services with something more economical and under my control.

  • I don't suppose your issue looks anything like my thread from this past weekend in this here community? And as a reminder, tagged ports face networking hardware, while untagged ports face end devices.

  • Oof, I feel you OP. I started down this road back in February, and I thought I'd be set up by now, but I'm still learning some of the pieces for a project that's almost exactly the same as yours. If it's any consolation, I have made a ton of progress. The hardest part can often be when you've chosen the pieces you want to use for your project, and then a kind stranger who means well adds extra complexity above and beyond what you want or need on top of their suggestion.

  • Hey, that's forward progress! The first I've had since this thread! That command did in fact allow me to ping my desktop from my mini PC on the VLAN. It also allowed me to ping 8.8.8.8, which I was unable to do before. On reboot, that default gateway seems to be reset until I run the command again, which makes sense. So I guess my next question is: what does this mean, and how do I fix it? I take it to mean that of those three jobs DHCP is supposed to provide in your list, it's only done the first one. The DHCP systems in particular are a major change from what OPNsense was just two years ago when the guides I've been following were made.

  • So what do you think might be the problem with it that I might check? As far as I know, if I've been assigned an IP address, DHCP is working.

  • I won't be able to try this until at least tomorrow after work, more than 24 hours from now, but yes, this was what was in my tutorials as standard. But also agreed in those tutorials was that what I tried doing was even more permissive and ought to "just work", at the risk of security and with no separation; I always try to do "Hello World" before I try to implement anything of value, and right now I'm barely seeing "Hello".

  • They're on different subnets, so I figured. I believe DHCP is set up properly, because it assigned an IP to that mini PC in my specified range.

  • Thanks, I'm going to have to go through this with a fine-toothed comb to see where I went wrong. If you read my other comments and have a hunch as to the problem in the meantime, I'm all ears, lol.

  • The output of that command is:

    It was listening when I pinged the gateway from the mini PC.

  • I might not understand what you mean, but doing the best I can figure out, the output from the endpoint mini PC running ip route is:

    192.168.10.0/24 dev enxc84d4422aa48 proto kernel scope link src 192.168.10.157 metric 100

    From the OPNsense firewall, the trace route looks like this (I would have expected to see the switches that it hops to in between, but I don't see them here):

    I can't find any option to print routing tables in my switches, both of them Netgear GS305E switches. I don't see any mention of it in the manual either. I suspect that what you asked me to do was lost on me.

  • Selfhosted @lemmy.world

    Help configuring OPNsense VLANs? Tutorials I find seem to quickly become outdated.

  • Selfhosted @lemmy.world

    Recommendations for next steps for my setup and order of operations (primarily as it relates to reverse proxies)?

  • Selfhosted @lemmy.world

    Questions about VLANs and what hardware I need

  • Selfhosted @lemmy.world

    RIP Discord: Self-Hosted Discord Alternatives Tested (TeamSpeak, Stoat, Fluxer, Matrix, & More)

  • Selfhosted @lemmy.world

    Help getting started with self hosting Jellyfin via NAS?

  • Games @lemmy.world

    Sony announces the PS5 Pro with a larger GPU, advanced ray tracing, and AI upscaling

    www.theverge.com /2024/9/10/24167932/ps5-pro-sony-specs-announcement