Sounds like you did a decent job. Why would you connect the Proxmox host to the VPN? Typically you’ll route certain local addresses (or whole subnets) via chain forwarding. That way, when you connect to the VPN it’s as if you’re on the local network. The way you’re describing it, you would need to know it’s VPN IP which is usually dynamic. And you don’t typically want VPN clients to be able to access each other - just the local network. It really all depends how you set everything up.
gwicksted
VPNs are complicated enough that security experts are the only ones typically working on them… and they have a relatively small surface area with few 3rd party dependencies. So it’s about the best you could hope for. I agree there’s still a deep amount of trust. Your OS is generally a greater threat though… and your network gear probably a lesser one.
Where something like synology’s web admin involves a webserver running their software on a runtime (php? Python?) possibly with a database where the webserver, runtime, db drivers, db engine, orm, web framework, and all their third party modules are under continuous development and may not be patched. Plus they’re a targeted system because of their popularity. And they’re meant to be user friendly more than secure.
But having a Cloudflare reverse proxy helps a little. So would running something like fail2ban on the logs or a software level firewall configured to detect abnormal data.
Better would be to simply require a client certificate that you generate and distribute from an offline CA and have cloudflare do tls termination then whitelist only their IP(s) and your intranet IPs on the synology firewall.
Or.. just use a VPN lol
I have a camera outside, I’m a pretty big guy, and my rack was built inside my office so it can’t be moved quickly.
Oh, you mean digital security? Lol I have a lot of subnets and don’t forward in much traffic. The WiFi password I give out gets you on my kids network. Plus I run DPI and IDS. I use cloudflare DNS (sometimes operating an internal pihole too). And I don’t browse social media on PCs only on mobile. The only holes punched from WiFi to internal are for printing. And even the wired clients are segregated from my work network.
I’m about 21-22 year round (also in Canada) and my server room isn’t much warmer than the rest of the house but it isn’t closed off either. The larger air space you can give it, the better.