2
submitted 11 months ago by moontear@alien.top to c/main@selfhosted.forum

With my zoo of docker containers and multiple servers hosted locally or on some cloud providers, I feel the need more and more to understand what kind of network traffic is happening. Seeing my outbound traffic on some cloud providers I'm sometimes wondering "huh-where did that traffic come from?".

And honestly I have to say: I don't know. Monitoring traffic is a real hurdle since I'm doing a lot via tunnels / wireguard in between servers or to my clients. When I spin up a network analysis tool such as ntopng, I do see a lot of traffic happening that is "Wireguard". Cool. That doesn't help me one bit.

I would have to do some deep package inspection I suppose and SSL interception to actually understand WHAT is doing stuff / where network traffic comes from. Honestly I wouldn't be sure what stuff would be happening if there were some malicious thing running on the server and I really don't like that. I want to see all traffic and be able to assign it to "known traffic" or in other words - "this traffic belongs to Jellyfin", "That traffic is my gitea instance", "the other traffic is syncthing" or something along those lines.

Is there a solution you beautiful people in this subreddit recommend or use? Don't you care?

you are viewing a single comment's thread
view the rest of the comments
[-] AnApexBread@alien.top 1 points 11 months ago

I do. I monitor it in a lot of ways.

  1. IDS at the router
  2. Anomoli Detection at the router
  3. Host based agents on everything I can
  4. L7 Firewalls on everything I can
  5. DNS based monitoring for everything

Wireguard and Cloudflare Tunnels make network traffic monitoring difficult because it's all encrypted traffic.

[-] NGL_ItsGood@alien.top 1 points 11 months ago

What do you use for l7 firewalls?

this post was submitted on 22 Nov 2023
2 points (100.0% liked)

Self-Hosted Main

504 readers
1 users here now

A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.

For Example

We welcome posts that include suggestions for good self-hosted alternatives to popular online services, how they are better, or how they give back control of your data. Also include hints and tips for less technical readers.

Useful Lists

founded 1 year ago
MODERATORS