• 0 Posts
  • 533 Comments
Joined 2 years ago
cake
Cake day: August 8th, 2023

help-circle







  • I had a double NAT setup like that. Run a firewall like OPNSense as a Proxmox VM, and give it a WAN interface on the ISP router’s IP range; then run everything else on a different subnet, using OPNSense as the gateway. On the ISP router, put OPNSense’s WAN IP in the DMZ. Then, do all your hardening using OPNSense’s firewall rules. Bonus points for setting up a VLAN on a physical switch to isolate the connection.

    The ISP router will send everything to OPNSense’s WAN IP, and it will basically bypass the whole double NAT situation.













  • You don’t have to make your own server (unless you really want to!). Just start a community on a server you like.

    The one catch is that others can start a community of the same name and/or interest on another server and that gets a little confusing because then there are two, of course.

    I wish that communities could “federate” with each other from different instances but then that raises a bunch of logistics issues about how this is moderated, how is this presented to the users, etc.