• Login
  • Register
  • Login Register
    Login
    Username/Email:
    Password:
    Or login with a social network below
  • Forum
  • Website
  • GitHub
  • Status
  • Translation
  • Features
  • Team
  • Rules
  • Help
  • Feeds
User Links
  • Login
  • Register
  • Login Register
    Login
    Username/Email:
    Password:
    Or login with a social network below

    Useful Links Forum Website GitHub Status Translation Features Team Rules Help Feeds
    Jellyfin Forum Support General Questions Tailscale & Jellyfin as a Noob

     
    • 0 Vote(s) - 0 Average

    Tailscale & Jellyfin as a Noob

    Accessing Jellyfin via the interent
    Tomato
    Offline

    Junior Member

    Posts: 3
    Threads: 1
    Joined: 2023 Dec
    Reputation: 0
    Country:Canada
    #1
    2024-01-06, 04:08 AM
    Another noob post but wanted to get everyone's thoughts on using Tailscale to access Jellyfin through the internet? 

    At most it would be like 3 family members. I can set everything up for them. 

    I'm afraid if I'm too lax I would open up my server to hackers / Russians but can follow decent instructions. 

    I'm running windows 11 for my Jellyfin server and plan on follow instructions set up here:  Jellyfin Remote Access with Tailscale | Ethan Madison's website
    TheDreadPirate
    Offline

    Community Moderator

    Posts: 15,375
    Threads: 10
    Joined: 2023 Jun
    Reputation: 460
    Country:United States
    #2
    2024-01-06, 04:44 AM (This post was last modified: 2024-01-06, 04:47 AM by TheDreadPirate. Edited 1 time in total.)
    There are several ways to secure your server from drive by attack attempts.

    1) Keep everything up-to-date
    2) Use https with a proper cert with a reverse proxy
    3) Use a wildcard cert *.domain.tld in conjuction with a subdomain jellyfin.domain.tld
    4) Use a non-standard https port. Like 40443 instead of 443.
    5) Hide usersnames from the Jellyfin login screen so attackers don't have a starting point for password guessing
    6) Setup fail2ban for the few that make it past 1 thru 4

    99.99999% of attackers on the internet are low effort script kiddies. They scan common service ports, scan for unpatched services, etc. If you use a subdomain and setup your reverse proxy to only respond to the subdomain, pretty much nobody will find your jellyfin server since attackers will only try domain.tld.

    The other 0.00001% are nation state hackers and aren't interested in you.

    Using tailscale is fine, but not all devices can use it (Roku, Fire sticks/Android TV).
    Jellyfin 10.10.7 (Docker)
    Ubuntu 24.04.2 LTS w/HWE
    Intel i3 12100
    Intel Arc A380
    OS drive - SK Hynix P41 1TB
    Storage
        4x WD Red Pro 6TB CMR in RAIDZ1
    [Image: GitHub%20Sponsors-grey?logo=github]
    « Next Oldest | Next Newest »

    Users browsing this thread: 1 Guest(s)


    • View a Printable Version
    • Subscribe to this thread
    Forum Jump:

    Home · Team · Help · Contact
    © Designed by D&D - Powered by MyBB
    L


    Jellyfin

    The Free Software Media System

    Linear Mode
    Threaded Mode