I have a VPS that I secure as much as possible since the IP is public, but does a wireguard-access-only homelab warrant the same efforts? Those with homelabs like this, what do you do?
i duct-tape a 22 to the side of the server with the trigger trip-wired to the wan port.
your move, iptables
Acronyms, initialisms, abbreviations, contractions, and other phrases which expand to something larger, that I’ve seen in this thread:
Fewer Letters More Letters SSO Single Sign-On UDP User Datagram Protocol, for real-time communications VPN Virtual Private Network VPS Virtual Private Server (opposed to shared hosting)
4 acronyms in this thread; the most compressed thread commented on today has 9 acronyms.
[Thread #46 for this comm, first seen 7th Jul 2026, 20:50] [FAQ] [Full list] [Contact] [Source code]
I have a hammer hanging above the hard drive on a string, and every time I want to access it, I have to convince an AI it’s really me. If doubt level rises above 20%, the hammer drops.
Anything that I publicly expose, I have protected with multiple layers up and down my entire stack…
This is such a nice overview. Thank you for sharing!
No worries, hope it helps, let me know if you have questions =)
I access my home server with Jellyfin exclusively via Tailscale. Until now, I thought I was safe, as I haven’t opened anything to “the open internet”. After reading your very nice guide, I feel like I forgot a lot. Supposed I trust Tailscale, is that enough?
Oh sorry, I’m late coming back to you but I went on summer holidays and have been enjoying the outdoors a lot =)
Using a VPN is a very safe way to do things. Tailscale is very well regarded in the homelab community and trusted. I personally prefer using raw wireguard myself, so no metadata or 3rd party metrics can be collected or sold, but Tailscale uses wireagurd under the hood so it’s very secure.
If it’s just wireguard on a nonstandard port, then you are pretty much done. It’s UDP and won’t reply to incorrectly signed packets so it’s essentially invisible.
Putting it on a non standard port will change nothing
Security through obscurity is not sufficient. It’s also not nothing.
Wireguard doesn’t respond to port scans so it changes nothing
It is going to make fingerprinting more annoying while evading default port scans. That isnt nothing but you do you boo
I agree that there is some value to obscurity generally, but Wireguard already evades port scans and fingerprinting. Unless a packet is signed with a known key, it gives no response to traffic, so scanners and fingerprinters see a closed port. You ISP can identify WG traffic while you are connected by inspecting your traffic, but random scanners won’t see anything. Look on shodan, you won’t see Wireguard.




