As the title says, I want to know the most paranoid security measures you’ve implemented in your homelab. I can think of SDN solutions with firewalls covering every interface, ACLs, locked-down/hardened OSes etc but not much beyond that. I’m wondering how deep this paranoia can go (and maybe even go down my own route too!).

Thanks!

  • ipipipEnglish
    arrow-up
    8
    arrow-down
    0
    ·
    8 months ago
    link
    fedilink

    Always on wireguard kills battery life on mobile for me so I guess that’s a no.

    • ErwinLottemannEnglish
      arrow-up
      6
      arrow-down
      0
      ·
      8 months ago
      link
      fedilink

      that should not be the case because wireguard only ‘runs’ when it sends or receives packets. try setting the keepalive time a bit higher, 5 minutes maybe.