
Hobbyist admins and home-labbers sometimes want to make services on a remote host available to machines on a home network. Unfortunately, many residential ISP customers are stuck with dynamic IP addresses, even when they're not behind a CGNAT. This makes securing the remote host difficult. You'd like to configure the remote firewall to allow traffic only from friendly IP addresses, but if one or more of your addresses might change at any time, what can you do? One option is to buy a fixed IP address from your ISP, but that can be costly.
This article describes how you can configure a remote server using nftables to automatically update its firewall rules so that dynamic IP traffic is allowed with minimal downtime when the IP address changes. The solution requires making a small change to your nftables configuration and a short script that runs periodically as a cron job.
Read more
The sword shatters the glass wall of the aquarium, spilling out an impressive amount of salt water and wet sand. It alsospills out an extremely annoyed sea serpent who bites angrily at the sword, and then at you. He is having difficulty breathing, and he seems to hold you responsible for his current problem. He manages to rend you limb from limb before hedrowns in the air.