jannl wrote: Monday 27 April 2026 10:44
General security rule of thumb is never to have you system reachable from the internet if it is not absolutely necessary.
I can not do much with this. The safest house is, of course, a house without windows and doors. In my case, I want a better lock on the door. Not to remove the entire door.
The wish is to have it accessible from the outside, and to do so in the most secure way possible. Before you mention VPN: that is also difficult if you have various goals, and it becomes complicated to constantly switch VPNs for automated access to serveral systems.
So, I end up with a connection over SSL, with the necessary login credentials for a separate user with limited privileges, and a firewall that limits access with GeoIP and blocks frequent connections on that (not standard) port. Then finally, I would like to round this off with Fail2ban, to block the IP entirely after a few invalid attempts.
And then what remains is that I expect any program with authentication to log an invalid login attempt with the origin IP as an ERROR. That appears not to be the case. Therefore, a small request for improvement. To handle this in the same way the gui does.
Dz on Ubuntu VM on Proxmox behind FRITZ!Box.
EvoHome; MELCloud; P1 meter; Z-Stick GEN5; Z-Wave-js-ui; Sonoff USB-Dongle Plus-E; Zigbee2Mqtt; MQTT; Greenwave powernodes 1+6; Fibaro switch, plugs, smoke; FRITZ!DECT 200. Scripts listed in profile interests.