[kwlug-disc] Home Web Servers Security

Remi Gauvin remi at georgianit.com
Mon Aug 3 15:50:39 EDT 2026


On 2026-08-03 2:09 p.m., Jon Thiele wrote:
> Looking for some advice.   I manage Wordpress sites for three
> charities I'm involved in. Very low traffic - maybe 500 hits a month
> combined.
>
> The cost is starting to get a bit pricey since I pay for these sites
> myself.   I was thinking that I could handle this using my own
> standalone PC.  So I cloned one site and set it up on Ubuntu 26.04.
> Everything went well - but now I'm thinking about exactly how to set
> up the networking part securely.   I'm on Rogers and right now and I'm
> forwarding ports 80 and 443 to my PC on my internal network.  Is this
> good enough?  I've used pfSense in the past and could use their port
> forwarding feature but not sure what the difference would be.  If you
> run a home server, what did you do?

Generally speaking, you would want publicly accessible websites to be in
a dmz network, and another firewall between that and your home computers.

This is probably considered outdated thinking, and *all* devices should
treat network like a hostile zone, but in the real world, I think most
people consider internal network to be safe zone.

So in your example, you would need two routers, (The Rogers modem can be
considered one, but if your hosting websites, you might static ip
config, I'm not sure they work as router in that config.)

The theory is that if someone exploited, for example, a Wordpress bug
that gives them remote command execution, and persistence presense on
webhost, they could not use that to launch attacks on your other,
private computers.



> Thanx.
>
> Jon
>
> _______________________________________________
> kwlug-disc mailing list
> To unsubscribe, send an email to kwlug-disc-leave at kwlug.org
> with the subject "unsubscribe", or email
> kwlug-disc-owner at kwlug.org to contact a human being.





More information about the kwlug-disc mailing list