• 1 Post
  • 27 Comments
Joined 2 years ago
cake
Cake day: July 9th, 2023

help-circle
  • If you want to be able to accept mail, you’ll need to directly expose your mail server on your public IP (router configuration required). You’ll also need to allow your server to egress your WAN as well. That being said - if you really want tighten your security, and don’t care about missing some emails, you could limit your server to seeing only those servers you know you’ll be communicating with, such as work, bank, or GMail servers only.

    You can make it so that retrieving your email with your client of choice requires a VPN connection to your home network also.











  • What VPS are you using?

    You should be able to setup a firewall, blocking all access to the SSH port. Then setup a VPN so that only you can access via SSH after making your VPN connection.

    If you connect via a static IP, you can also create an ACL for the VPN connection just in case. You can set an ACL for the SSH port forward rule directly as well, but I don’t like that personally. I prefer keeping things behind the VPN.










  • Yeah, true. But that’s cool. Having choice like that is great!

    But I suppose that’s the issue. Trying to keep signup simple to help drive user engagement. How much do you try to wrap someone’s head around such nuanced differences, and when do you say “just join me on my instance”?