[kwlug-disc] Home Web Servers Security

D. Hugh Redelmeier hugh at mimosa.com
Thu Aug 6 10:34:43 EDT 2026


Risk is related the sizes of attack surfaces and the diligence maintaining 
the security of each.

A VPS makes the risk of the web server "somewhere else".  Do you trust 
them with what you put there?

My home web servers have material that I really want to keep private.  
They are not directly available on the internet, which is inconvenient but 
safer.

=========

On my Bell fibre box (modem, router, etc.) I use PPPoE pass through to get 
my own router a globally routable but changing IPv4 address.  The other 
ports on the Bell box are behind NAT with a different globally routable 
address.  Interesting.

I also have a Teksavvy fibre connection that I'm slowly setting up.  I pay 
a few bucks a month for a static IP address.  Their modem is inferior: it 
will support PPPoE pass-through but only at 1G, even though the service is 
1.5G; when PPPoE pass-through is used, the other modem ports are not 
connected to the internet.

The Teksavvy modem has a fibre-to-SFP dongle.  Anyone know if it is 
possible to plug that into another SFP port and skip the modem?  What 
magic settings do I need to know about? VLAN stuff, for example?

My own routers are mini-PCs running Fedora. Not much magic. Each has four 
2.5G ethernet ports but no SFP ports.  On the other hand, I have a few 
2.5G ethernet switches which have a single SFP port.


More information about the kwlug-disc mailing list