• Login
  • Register
  • Login Register
    Login
    Username/Email:
    Password:
    Or login with a social network below
  • Forum
  • Website
  • GitHub
  • Status
  • Translation
  • Features
  • Team
  • Rules
  • Help
  • Feeds
User Links
  • Login
  • Register
  • Login Register
    Login
    Username/Email:
    Password:
    Or login with a social network below

    Useful Links Forum Website GitHub Status Translation Features Team Rules Help Feeds
    Jellyfin Forum Off Topic Self-hosting & Homelabs Best Security Practices?

     
    • 0 Vote(s) - 0 Average

    Best Security Practices?

    TheDreadPirate
    Offline

    Community Moderator

    Posts: 15,374
    Threads: 10
    Joined: 2023 Jun
    Reputation: 460
    Country:United States
    #2
    2025-01-26, 04:50 PM
    Fail2ban, as you mentioned, is a good start. It can read Nginx logs to look for repeat 4XX codes, which is often an indicator of a web crawler or scan bots.

    Another option is to rent a VPS to act as a proxy for all access to your home server, then setup Wireguard to tunnel from the VPS to your home server.

    This one is good practice, in general. Disable SSH login for root, setup PKI keys for SSH and disable password logins entirely (keys only). This has the added benefit of making it easier to setup access for, for example, a friend's server. Just give them your public key. No need to exchange passwords.

    This one is optional, but is what I do. HTTPS and SSH do not use standard ports, except for hosting Matrix because I have use 443. This significantly reduces the number of bots and script kiddies that attempt to poke around since most will not spend the time to ping every port. This has the inconvenience of having to specify ports in the URL but worth it, IMO.
    Jellyfin 10.10.7 (Docker)
    Ubuntu 24.04.2 LTS w/HWE
    Intel i3 12100
    Intel Arc A380
    OS drive - SK Hynix P41 1TB
    Storage
        4x WD Red Pro 6TB CMR in RAIDZ1
    [Image: GitHub%20Sponsors-grey?logo=github]
    « Next Oldest | Next Newest »

    Users browsing this thread: 1 Guest(s)


    Messages In This Thread
    Best Security Practices? - by 4r5hw45twh - 2025-01-26, 03:46 PM
    RE: Best Security Practices? - by TheDreadPirate - 2025-01-26, 04:50 PM
    RE: Best Security Practices? - by 4r5hw45twh - 2025-01-28, 01:12 AM
    RE: Best Security Practices? - by Host-in-the-Shell - 2025-01-26, 05:05 PM
    RE: Best Security Practices? - by TheDreadPirate - 2025-01-28, 02:41 PM
    RE: Best Security Practices? - by 4r5hw45twh - 2025-01-28, 03:25 PM
    RE: Best Security Practices? - by TheDreadPirate - 2025-01-28, 04:16 PM
    RE: Best Security Practices? - by 4r5hw45twh - 2025-01-28, 05:01 PM
    RE: Best Security Practices? - by TheDreadPirate - 2025-01-28, 05:33 PM
    RE: Best Security Practices? - by bjd223 - 2025-02-21, 12:04 AM
    RE: Best Security Practices? - by TheDreadPirate - 2025-02-21, 01:29 PM
    RE: Best Security Practices? - by KrisMarshall - 2025-06-06, 07:55 AM

    • View a Printable Version
    • Subscribe to this thread
    Forum Jump:

    Home · Team · Help · Contact
    © Designed by D&D - Powered by MyBB
    L


    Jellyfin

    The Free Software Media System

    Linear Mode
    Threaded Mode