Problem establishing a connection with a client

Hey all,

I'm trying to setup ssh over pangolin.

currently pangolin is installed on my vps and I want to ssh to my homelab from my laptop.

I installed newt on my homelab and connected it as a new site in pangolin.

Also I installed the client on my laptop and logged in.

now when I try to connect using 'pangolin up' I get an error about making sure port 21820 is open and stuff like that.

I opened 21820 in ufw in my laptop, VPS, and server. Also the firewall on the VPS accepts all ports.

I consulted with an LLM and it wrote something about being behined a cgnat (and I am behined one) but I still don't understand why that stops me from making a p2p connection?

can anyone enlighten me maybe I'm missing something?

thanks

reddit.com
u/manman43 — 3 days ago

Small porcelain cup with perferated top and a spout on the bottom. Found in a flea market

u/manman43 — 2 months ago

Identity Providers Explanation

Hello,

I was wondering if anybody can help me understand IdP. I'm currently setting up Pangolin, and was wondering if it's a problem to add google as an IdP for my friends and family. Me personally, I'm more privacy oriented and don't really use google for anything, I was wondering if by adding Google IdP I give up some of my privacy?

Also, what are the benefits of hosting my own IdP, and what are the differences between the options?

Thanks

reddit.com
u/manman43 — 2 months ago

Bypass rules in Pangolin question.

Hello,

I recently started using Pangolin and was wondering, aren't bypass rules an inherent security vulnerability?

I'm currently setting up vaultwarden on my vps, the same machine running pangolin. And I figured I will put it behined authentication. But to access the site from the app, I need to add some bypass rule to some paths like /api and others. I'm curious if this isn't a security threat, and if it is what can I do about it

thanks

reddit.com
u/manman43 — 2 months ago

Bypass rules question

Hello,

I recently started using Pangolin and was wondering, aren't bypass rules an inherent security vulnerability?

I'm currently setting up vaultwarden on my vps, the same machine running pangolin. And I figured I will put it behined authentication. But to access the site from the app, I need to add some bypass rule to some paths like /api and others. I'm curious if this isn't a security threat, and if it is what can I do about it

thanks

reddit.com
u/manman43 — 2 months ago

Help with authentication and access

Hello,

This is yet another post about accessing your homelab from the internet.

Basically what I'm looking for is a way to access my services from the public internet without a VPN but with authentication and ACLs.

Preciously I used tailscale but it's a bit tough on non tech savvy folk, so I'm trying to find another solution.

Currently I'm hosting a couple services on a VPS with caddy as a reverse proxy. Also a couple services in my homelab.

I wanted to ask if I should switch to pangolin, or should I use authelia or something like that. And I wanted to ask if there is a problem with authentication in apps, like if I try to use bitwarden via vaultwarden, how will I verify in authelia/pangolin? Or immich or other services that have apps.

Also how would ACLs be managed? Is it via IP? Mac? SSO? Or by other means?

Thanks

reddit.com
u/manman43 — 2 months ago

Help with authentication and access

Hello,

This is yet another post about accessing your homelab from the internet.

Basically what I'm looking for is a way to access my services from the public internet without a VPN but with authentication and ACLs.

Preciously I used tailscale but it's a bit tough on non tech savvy folk, so I'm trying to find another solution.

Currently I'm hosting a couple services on a VPS with caddy as a reverse proxy. Also a couple services in my homelab.

I wanted to ask if I should switch to pangolin, or should I use authelia or something like that. And I wanted to ask if there is a problem with authentication in apps, like if I try to use bitwarden via vaultwarden, how will I verify in authelia/pangolin? Or immich or other services that have apps.

Also how would ACLs be managed? Is it via IP? Mac? SSO? Or by other means?

Thanks

reddit.com
u/manman43 — 2 months ago