Post #2434678
2026-03-17 19:37 UTC
@portaloffreedom@social.linux.pizza we expose our mailserver and a webserver from our home, on a static IP, with proper rDNS and have to deploy the same protections (greylisting on the smtpd, freebsd blocklistd for ssh, and a custom HTTP binding to blocklistd to catch scanners) as we do for cloud stuff. highly recommend The Book of Pf as a tutorial for secure network design even if you end up using iptables — the advice downthread to silo the exposed stuff into a DMZ is also how we run things.
@andnull@social.nouveau.community
Replies (1)
-
@portaloffreedom@social.linux.pizza 2026-03-17 19:53
@atax1a@infosec.exchange @andnull@social.nouveau.community Thanks! This is very close to what I wanted to hear. I guess the biggest issues are - more easily locating where I live - need to lock down the DMZ zone properly - AI scrapers could halt normal internet usage when home network is assaulted and I just want to watch some live stream