4 ms·
I have it setup to sync anywhere with wifi. I bought a domain and set it up to my IP using dyndns (I just have it running on my regular consumer internet, not a
by Ralo 4y ago
I have it setup to sync anywhere with wifi. I bought a domain and set it up to my IP using dyndns (I just have it running on my regular consumer internet, not a dedicated business line with a static IP). By wifi I mean any wifi with internet access. I could use it over LTE but I don't need to burn up all my data pushing backups.
I have it behind an apache service which is password protected and only accepts https. As well, it uses fail2ban. If you ever ran a web server, you'll know your server will get bot scans 247. These only occur on the root domain and direct IP, so I disabled all root/direct IP access and moved it to a subdomain. I've never had issues.
I use samba as well, but that's only because this server works as my NAS as well. I setup a dedicated DAV folder on the NAS directory and give it extreme user restrictions, just incase. It's just a nice central server to keep all my devices in sync.
- solarkraft 4y agoI assume you don't expose the Samba to the internet? I'm still wondering if there's a reasonable way to do this (side-channel authentication/"port knocking"?).
- e12e 4y agoWireguard / tailscale or similar vpn should be fine? I've toyed with tailscale and ZeroTierOne - both should work fine with Bonjour/zeroconf if you need it - and handle routing (using lan when devices are on same net, routing over the internet when not). There's also Nebula from slack (but I've not tried it). Would love to see tailscale work with kernel wireguard clients (for better performance) - AFAIK today you'll have to pick one: easy setup with smart routing (ZeroTierOne / nebula / tailscale) - or - best in class performance with kernel space wireguard.
- Ralo 4y agoI don't expose samba no, but at one point I did run openvpn access. I set the client config for the VPN to only forward 192.168.x.x through the vpn, but not all other traffic. So if I go to a coffee shop, my windows laptop would act entirely like it was still on my lan and my mounted network drive would fully connect as normal. I removed that service since it was kind of clunky and always had connection issues. Perhaps I should try it again.