

Yeah, it’s on my to-do list for my domain registrar, but the above was in relation to OPNsense configuration, which I found a solution for.


Yeah, it’s on my to-do list for my domain registrar, but the above was in relation to OPNsense configuration, which I found a solution for.


It does sound exactly like this. However, I’m concerned about following these instructions when my external IP isn’t static. I still have yet to set up DDNS (I believe is the term, for automatically updating my domain’s DNS servers with whatever new IP address my ISP gave me), but this looks like it’s entirely IP driven.
EDIT: Actually, I just realized OPNsense has an alias for that, so I’m not sure why their own manual didn’t recommend it. I can just set the value to “WAN address”. It works! That’s step #1 down, and now I’m curious about step #2.
My local DNS only seems to set up IP address routing, so I’m not sure how to hit my reverse proxy with the subdomain I’m interested in and have it route accordingly; or even just skip the reverse proxy by having that URL internally route to an IP address and port, because there’s nowhere to put in a port.


Yes, that’s exactly what I’ve done. You still haven’t shown me why it’s unsafe. If you can’t, that’s fine. At some threshold or another, nothing is secure. The one thing I know for sure is that that first page, that says it doesn’t recommend exposing a port, does not say what you said it does.


Probably the number one recommendation I see in self hosting communities is to not open ports directly (other than for a reverse proxy). It seems like a common recommendation no matter the service. To be clear: I am a beginner. I know very little about this, but I’ve spent months learning. I can’t say you’re wrong, but I don’t think you’ve made a convincing argument for me to actually understand why Jellyfin is unsafe to expose to the internet compared to any other service.


It says exposing a port directly to the internet is not recommended; do you know of any project that would recommend directly exposing a port? What is meaningfully different here?


By all means correct me if you know more, but what I tend to see is one or two people here saying that Jellyfin devs don’t recommend exposing it publicly, only to be corrected by looking at the actual documentation. I suspect those cautioning against it are on outdated information and that Jellyfin carries much the same risk as exposing any other service.
I’m currently only hosting Jellyfin (movies and TV) and Komga (books and comics) on a LAN, but I already bought a domain, and I’ll be exposing them via reverse proxy within the next few weeks; maybe even this weekend if everything goes well. After that, Nextcloud is a must for sharing large files, as Google Drive’s limits are coming up on me fast, and I’ll start test driving Fluxer as a replacement for Discord.


I don’t think I can read books fast enough to make automation attractive either, haha. I break DRM on Calibre with two plugins, books purchased from Kobo, and then organize on Komga after manually dragging the files.


I watched and rewatched tutorial videos, traced my cables and ports, and configured the port settings until I was able to ping the gateway on this VLAN. That’s as far as I’ve gotten. Over the course of today, since posting this thread, I’ve rechecked those settings a handful of times, and they still appear to be correct as far as I know. If I delete the extremely permissive firewall rule that I set up for the VLAN, I lose the ability to ping the gateway, which seemingly validates the rest of my setup and leads me to believe that this is a configuration issue in OPNsense rather than the configuration of my switches…but I don’t know what I don’t know, and I’m still learning this stuff.
I understand that you’re recommending what you think is best based on your experience, but as I’ve been trying to learn self hosting with a semi-simple goal in mind, the extra complexity that folks keep recommending around just about every facet, because their needs or desires are greater than mine once they’re more seasoned than me, does make it all more difficult to take in during the learning process. Maybe I’ll want to go more advanced some day, but for now, the goal is to host fewer than a dozen services off of two different devices that live under my office desk and consume under 100W between them. I want VLANs for this as a means of separation in case the security of my exposed services is compromised, but with this smoke test, I want to prove that I understand the basics of doing so, so it’s currently feeling defeating that I don’t. I don’t want to sound like I’m not appreciative of any help you can offer, but I do still believe that simpler is better for me at this point.
My firewall mini PC has four ports, but only two of them are active; LAN and WAN. I got that much working without much fuss and replaced my ISP’s provided router. There were two dumb switches between the firewall and the office, but once that was working, I replaced them with managed switches; when they’re not yet configured, they’re indistinguishable from dumb switches. I’ve been over my OPNsense configuration a dozen times in this thread by now, but let’s just say this new VLAN is set to be as permissible as I know how to make it, coming very close to my default LAN interface settings as far as rules go. They ought to be identical. The two smart switches are set up such that port 5 is “in” and 1 is “out”. Living room 5 connects to the firewall. Living room 1 connects to the office switch’s port 5. Office switch 1 connects to the end point mini PC. Living room ports 1-5 are untagged for VLAN 1; ports 1 and 5 are tagged for VLAN 10. Office ports 2-5 are untagged for VLAN 1; for VLAN 10, 1 is untagged and 5 is tagged, and port 1 has a PVID of 10.
I spelled all of that out in hopes that I did something stupid that I don’t know how to spot but maybe you do. Every device on VLAN 1 is working as it should with internet access. The one device on VLAN 10 only has access to the gateway and nothing else, despite the most permissive “allow everything” rule I could set up.


I don’t see myself needing more advanced functions, and at this point I’d be happy to get the basic ones working, haha.
I understand the concept of a trunk port, but I don’t know how to translate that into some other terminology that my manual uses instead, or if there’s some other paradigm. To the best of my knowledge, it’s the difference between a tagged port and an untagged port, which I think I have configured correctly. I must be at least in the ballpark if I can hit the gateway and nothing else.


Thanks! I appreciate step by step guides with explanations, but as we’ve both covered, the guides I followed have now fallen way out of date. Has OPNsense always moved this fast with ripping out components and paradigms and replacing them with others? Do you have an up to date video guide that you could refer me to so that I get more "how"s and "why"s along with each setting to help understand it better?
Unlike some other settings in OPNsense, there’s nothing like “Legacy” or “Deprecated” to indicate that Dnsmasque is being phased out, and when I see “new Rules”, I suspect that it’s so hot off the presses that it may not be fully working yet. Their replacements are both ready for prime time? Blocking ads by DNS wasn’t a goal I had in mind for this project of mine, but I can’t say I haven’t been tempted to increase scope to cover it.
My switches are both GS305E Netgear switches, and the word “trunk” doesn’t show up anywhere in the manual. What I do have are VLAN 10 ports tagged when they face the firewall or another managed switch; and untagged when they face the end device; as per Home Network Guy. That was what got me far enough along that I was able to ping the gateway. Before that, my pings went completely unanswered.
Unfortunately, most of my networking experiments end up sectioned off to the weekend, because I try to minimize any damage I might do to my home network during the work week (I work from home) and disruption for my wife trying to enjoy the internet herself. All that to say that I might be back here again asking for help, but it will be on a hell of a lag. You definitely gave me some homework to do, too.


Thanks!
My wife spent about $130 for a year subscription to a service that she figured would always have her favorite show on it, because they own that show. Then like 10 seasons of it left for an exclusivity deal on another service. This was a contributing factor to pushing me into self hosting. Some of it is saving money, but some of it is also making sure you actually got what you paid for.