Goofed Home

Network Security Audit

$$3763
https://lemmy.world/u/irmadlad posted on Feb 24, 2026 18:44

From time to time I like to review my network to see where I can tighten up. Review logs, check out the landscape, and make sure there are no gaps. Today, I have some downtime, so I figured it’d be a good for it. Since I am not a certified IT professional, this is what I have cobbled together reading, and seeing what others have done. I’d like to bounce this off you guys who are more experienced than I and get your impressions. If you have any recommendations, I’m always down to be schooled.

So if you’d like to participate in my audit, I have a home network as follows:

  • Modem receiving IP from ISP. Modem to router. Router to stand alone pfsense firewall. Router has a 54 character complex password for WiFi. There are no guest provisions for WiFi.
  • Pfsense firewall with pfblockerng & suricata running on both lan and wan, both with a full array of rules/feeds updated daily. pfsense has tailscale as an overlay vpn. Server traffic and PC traffic have their own VLAN provided by pfsense. My approach is to deny all until something complains and address that on a case by case basis. Additionally ntopng is utilized for traffic analysis. IPv6 is disabled.
  • Server running Tailscale as an overlay VPN, UFW deny all posture, and fail2ban with an aggressive posture. Server has been hardened against Lynis spec where applicable. Not all recommendations apply to my server. Server is utilizing host deny/host allow and SSH keys.
  • Server is utilizing containers for services.
  • Server is using Cloudflare tunnel/zero trust.
  • Server and pfsense communicate via Tailscale encrypted tunnel. PC/Phone/mobile device can communicate with pfsense via Tailscale.
  • Server services are accessed via https.
  • PC connected to pfsense firewall with same rules as server. PC is using a VPN with Cloudflare 1.1.1.11.0.0.1 for DNS queries. Firefox is using 1.1.1.11.0.0.1. Settings for Firefox are the strictest for Enhanced Tracking Protection, and DOH. HTTPS-Only mode enabled. PC is also running a soft firewall.
  • All other devices such as phones, laptops, and tablets run a VPN with Cloudflare 1.1.1.11.0.0.1 for DNS queries.
  • IoT devices are isolated. Phones are isolated. Smart TVs are isolated.

How secure would you say this network is and give any recommendations to further harden the network besides keeping up with current updates, monitoring and auditing logs.

Thanks

https://lemmy.world/post/43533409

24 posts in conversation

$$4184
https://lemmy.world/u/Archer posted on Feb 25, 2026 17:22
In reply to: https://lemmy.world/comment/22339322

You’re ahead of an alarming number of my colleagues by just trying until you can get it working then documenting things

https://lemmy.world/comment/22342852
$$4298
https://lemmy.world/u/irmadlad posted on Feb 25, 2026 20:34
In reply to: https://lemmy.world/comment/22342852

I have to document. At 71, with a TBI, my brain is not what it used to be. Sometimes I don’t even remember what I had for breakfast. LOL

https://lemmy.world/comment/22346284

We can follow the news directly from the source using flipboard over the fediverse

$$4181
https://mbin.potato-guy.space/u/potatoguy posted on Feb 25, 2026 17:15

Idk, it might be old news to everyone.

I just discovered that we can follow the magazines the profiles publish, like !brasil-dw_brasil@flipboard.com that turns into a community, or follow them directly like @dw_brasil@flipboard.com, turning all of their posts into a microblog feed (on mbin, mastodon, etc).

Might be interesting to people, if they want to see some different type of posts, news, articles or cultural analysis.

I see this as a win-win, they get their “someone entered your website through flipboard and the fediverse” (the links come with only this tracking) and we get different “content”.

https://mbin.potato-guy.space/m/fediverse@lemmy.world/t/29447

10 posts in conversation

$$4277
https://anarchist.nexus/u/Snowdrop9144 posted on Feb 25, 2026 19:44
In reply to: https://mbin.potato-guy.space/m/fediverse@lemmy.world/t/29447/-/comment/171540

Thanks for sharing the method! Will take a look!

https://anarchist.nexus/comment/2804286
$$4297
https://lemmy.ca/u/pglpm posted on Feb 25, 2026 20:32
In reply to: https://mbin.potato-guy.space/m/fediverse@lemmy.world/t/29447

Great info, cheers! 🚀

https://lemmy.ca/comment/21901029

Learning Vim in 3 Steps

$$3785
https://lemy.lol/u/cm0002 posted on Feb 24, 2026 19:47
https://lemy.lol/post/61633328

9 posts in conversation

$$4051
https://eviltoast.org/u/orhtej2 posted on Feb 25, 2026 10:00
In reply to: https://lemmy.dbzer0.com/comment/24607363

Random garbage keystrokes you put in before searching for the correct nope out procedure?

https://eviltoast.org/comment/17732701
$$4296
https://programming.dev/u/somegeek posted on Feb 25, 2026 20:31
In reply to: https://lemmy.world/comment/22327717

Nano is for chemists maybe. Editing couple of lines and saving.

But vim is one of the most powerful text editors ever created. It’s so powerful and good that it gets ridiculous. Also, from an ergonomic standpoint, your body will thank you for using vim/neovim

https://programming.dev/comment/22394167

Newish to Fediverse - do I use one account across all services?

$$3016
https://piefed.social/u/hellerphant posted on Feb 23, 2026 11:52

Hi there! So I understand that federated systems can speak to one another and interact. My question I guess is should I be using my Mastodon account to log into PieFed, and PixelFed, and Bookwyrm? Or do I need to create specific accounts for all these services, just as I did before?

I understand that someone on Mastodon could potentially follow my PixelFed account and see my posts. But wouldn’t it make sense to have one single identity (if one wished) so it collected all of my stuff in one place? Just wondering if I am missing the point?

Sorry if I sound like an idiot here. I really love the idea of federated services, just want to make sure I am “doing it right” so to speak.

https://piefed.social/c/fediverse/p/1807676/newish-to-fediverse-do-i-use-one-account-across-all-services

24 posts in conversation

$$4146
https://piefed.zip/u/UnfinishedProjects posted on Feb 25, 2026 15:51
In reply to: https://fedia.io/m/fediverse@lemmy.world/t/3493667/-/comment/14164539

Can mbin browse Lemmy/piefed? I would love to only use one app/login if possible. If one application can correctly view/post to each service - then it would seem logical to just use the one. I might switch to mbin If it can browse Lemmy content.

https://piefed.zip/comment/3963955
$$4289
https://fedia.io/u/atro_city posted on Feb 25, 2026 20:17
In reply to: https://piefed.zip/comment/3963955

For sure !piefed_meta@piefed.social is in the list of “magazines” (communities as they are known on mbin) and more communities too.

https://fedia.io/m/fediverse@lemmy.world/t/3493667/-/comment/14192089

Jake Johnson to Play Private Investigator in Dan Goor, Luke Del Tredici’s NBC Comedy Pilot With Akiva Schaffer Directing

$$4290
https://piefed.social/u/Skavau posted on Feb 25, 2026 20:12
https://piefed.social/c/television/p/1816899/jake-johnson-to-play-private-investigator-in-dan-goor-luke-del-tredicis-nbc-comedy-pilo

Public Domain Recipes

$$3610
https://lemmus.org/u/Beep posted on Feb 24, 2026 11:09
https://lemmus.org/post/20407122

10 posts in conversation

$$3983
https://lemmy.world/u/FauxPseudo posted on Feb 25, 2026 05:50
In reply to: https://lemmus.org/post/20407122

Take that oatmeal cookie recipe and leave out the cinnamon and optional nuts or fruit. Add 2 teaspoons of fresh ground star anise.

https://lemmy.world/comment/22334335
$$4280
https://lemmy.dbzer0.com/u/azerial posted on Feb 25, 2026 19:56
In reply to: https://lemmus.org/post/20407122

Digging into this deeper. I love this project. Publicly sourced on GitHub and codeberg. Super cool!

https://lemmy.dbzer0.com/comment/24626240

2006 called, they said we need better memes and left this

$$2641
https://lemmy.world/u/DarrinBrunner posted on Feb 22, 2026 16:47
https://lemmy.world/post/43455821

$$2742
https://lemmy.today/u/TheImpressiveX posted on Feb 22, 2026 20:37
In reply to: https://lemmy.world/post/43455821

Well, the jerk store called, they’re running out of you!

https://lemmy.today/comment/22439934
$$4275
https://lemmy.sdf.org/u/lessthanluigi posted on Feb 25, 2026 19:43
In reply to: https://lemmy.world/post/43455821

I remember 2018 being the worst year for memes. Then agaim, it was also when I was surrounded by assholes as well.

https://lemmy.sdf.org/comment/26237782

Conversation

$$4263
https://lemmy.world/u/Cloudstash posted on Feb 25, 2026 19:29
In reply to: https://lemmy.piracy.social/comment/153

And movies, tv shows, game servers and what not. Kindly stop beliving your source needs to provide at 10001000, thats just a sales gimmic from the operators.

https://lemmy.world/comment/22345160

‘Industry’ Renewed for Fifth and Final Season at HBO

$$4178
https://piefed.social/u/Skavau posted on Feb 25, 2026 17:11
https://piefed.social/c/television/p/1816244/industry-renewed-for-fifth-and-final-season-at-hbo

$$4262
https://lemmy.world/u/Jhex posted on Feb 25, 2026 19:25
In reply to: https://piefed.social/c/television/p/1816244/industry-renewed-for-fifth-and-final-season-at-hbo

I find this show’s plot/story laughably bad but the style is amazing!… like a Lambo with a chevy engine hahaha.

https://lemmy.world/comment/22345089

Conversation

$$4227
https://lemmy.world/u/stiffyGlitch posted on Feb 25, 2026 18:33
In reply to: https://sh.itjust.works/post/55184328

Ok, so it’s actually good that you are noticing that part of yourself that is afraid of abandonment. That is very common with people that have a bit of a tough background. It is also possible that she had some fear of abandonment when she was a child, so she may be doing a kind of trauma-reenactment. To an extent, I understand where you’re coming from and how you feel. Sometimes when people say “Oh, I totally understand!” doesn’t really help. It sounds like you might have had a bit of a rough childhood, due to social standards, such as hiding mental disabilities. I ask you to not turn to drugs, alcohol, or sex when you’re struggling. It might feel hard. It might feel impossible. But if you ignore it, then you can’t help yourself help yourself. Hurt people hurt people, because they were hurt by hurt people. And the cycle continues. This isn’t just directed to you, but anybody that needs help and doesn’t know how to ask for it in person. A river can only flow after the storm.

https://lemmy.world/comment/22344150

Create New Post