[kwlug-disc] Home Web Servers Security
Colin Mackay
zixiekat at gmail.com
Mon Aug 3 14:23:34 EDT 2026
I port forward 443 to a docker container running NPM (nginx proxy
manager).
It uses letsencrypt to handle SSL certs for each site, and then forwards
the traffic to the appropriate site internally.
A note on security. This does come with a risk. You're opening a well
known attack vector into your network. Be sure you keep everything
updated, and institute some other security processes. Geoblocking,
fail2ban, etc.
I am on mobile now, I can give a more detailed explanation when I have a
keyboard.
On Mon, Aug 3, 2026, 2:10 p.m. Jon Thiele <jthiele at gmail.com> wrote:
> Looking for some advice. I manage Wordpress sites for three
> charities I'm involved in. Very low traffic - maybe 500 hits a month
> combined.
>
> The cost is starting to get a bit pricey since I pay for these sites
> myself. I was thinking that I could handle this using my own
> standalone PC. So I cloned one site and set it up on Ubuntu 26.04.
> Everything went well - but now I'm thinking about exactly how to set
> up the networking part securely. I'm on Rogers and right now and I'm
> forwarding ports 80 and 443 to my PC on my internal network. Is this
> good enough? I've used pfSense in the past and could use their port
> forwarding feature but not sure what the difference would be. If you
> run a home server, what did you do?
>
> Thanx.
>
> Jon
>
> _______________________________________________
> kwlug-disc mailing list
> To unsubscribe, send an email to kwlug-disc-leave at kwlug.org
> with the subject "unsubscribe", or email
> kwlug-disc-owner at kwlug.org to contact a human being.
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://mail.kwlug.org/pipermail/kwlug-disc_kwlug.org/attachments/20260803/8ee73770/attachment-0001.htm>
More information about the kwlug-disc
mailing list