this post was submitted on 26 Dec 2025
21 points (83.9% liked)

Selfhosted

61103 readers
374 users here now

A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.

Rules:

Detailed Rules Post

  1. Be civil.

  2. No spam.

  3. Posts are to be related to self-hosting.

  4. Don't duplicate the full text of your blog or readme if you're providing a link.

  5. Submission headline should match the article title.

  6. No trolling.

  7. Promotion posts require active participation, with an account that is at least 30 days old. F/LOSS without a paywall has exceptions, with requirements. See the rules link for details. Tags [CBH] or [AIP] are required, see the links in Rule 8 for details.

  8. AI-related discussions and AI-involved promotional posts have additional requirements for tagging, as noted in Rule 7 and the AI & Promotional Post Expanded Rules post, and find example disclosures here.

Resources:

Any issues on the community? Report it using the report flag.

Questions? DM the mods!

founded 3 years ago
MODERATORS
 

Well, hello there.

I run several services on my NAS at home.

I have a domain which always points at home and redirects port 80 to wikipedia.

Almost all ports are not forwarded, only for those which i want to have access to.

Example:

  • Paperless
  • Syncthing
  • FreshRSS

Now i work on my corporate computer and i cant access my services.

Why?

It blocks connections which go to a specific port.

Now i would love to access freshrss on adress:

Www.domainexample.com:1234

Which gets blocked.

Any ideas?

Messing with the local pc is of course forbidden.

you are viewing a single comment's thread
view the rest of the comments
[–] jeena@piefed.jeena.net 36 points 7 months ago (3 children)

Just use port 443 or 80 and use sub domains and a reverse proxy for each of your services.

For example:

https://rss.example.com/ goes to port 443 on your server where you run a nginx with letsencrypt. You set up a vhost for this subdomain which then internally proxies to your IP adress and port for freshrss.

I have it like that: https://rss.jeena.net/ and https://piefed.jeena.net/ and https://toot.jeena.net/ and so on.

[–] stratself@lemdro.id 9 points 7 months ago

Beat me to it. This is likely the best way as 443 is ubiquitously unblocked on most networks

[–] jeena@piefed.jeena.net 2 points 7 months ago (1 children)

If you don't want to mess with SSL you can do the same with port 80.

[–] ChapulinColorado@lemmy.world 4 points 7 months ago* (last edited 7 months ago)

But then you are sending credentials in clear text over the network. That will get logged on the corporate access logs ensuring a quick permanent vacation once they notice how careless the employee is, not to mention the mixing personal and work resources.

Edit: forgot to mention, most work devices also decrypt SSL traffic by using man-in-the-middle approach (unless they are very incompetent). Even stuff like personal email and shopping should not be accessed on a work device if you don't want your work to have your passwords.

[–] k4j8@lemmy.world 1 points 7 months ago

I do this too plus block all IPs via firewall except my work and home IP addresses.