bufandatlB
You basically need a router between the networks. I would recommend pfsense or opnsense or if you like cli vyOS. I run a pfsense that has my ISP router on the WAN port and a network interface for all VLANs and then I configured the firewall to allow specific traffic to specific devices in specific VLANs. For example my PC can reach the smart home controller website but no other device. And the samrthome devices only can reach the DNS in the ISP network (my kinda DMZ) and the router to reach the internet. And for every VLAN there are own rules where goes what communication.
You also can setup that on the managed switch which you would need for setting up VLANs.
2 days for most hosts as they had a kernel update. Other hosts about 30 days (no updates pending). And the winner is my core switch with 750 days up time.
Hm. Lag spikes in Tarkov and you check your server? I mean Tarkov.
But yeah I can feel your misconception here. But I am also the other way around I uninstalled firewalld and do all on iptables level. I am just more used to iptables. And so the sole controlling instance is iptables. In the end it’s all netfilter in kernel space.
Yea don’t use enterprise stuff and build servers yourself with lowpower hardware. Less power less heat also can be cooled easier with Noctua Low RPM low noise fans.
Nope. No VMs. Don’t know why would I if I have a dedicated XCP-NG pool for that.
Moving your gaming PC as client makes no sense no. But gaming servers like a Minecraft or whatever severer can make sense.
I can recommend XCP-NG as Hypervisor. I have over 25 VMs running my whole home from DHCP/DNS over media servers to game servers for CS2 and DayZ. And it’s stable and performant.
Don’t use NTFS either Linux as 24/7 file system. Use Linux natives like ext4, xfs or zfs. And share the drive via samba. If it’s a drive that needs to travel between systems use EXFat.
I use rdiff-backup to backup the volumes directory of my VPS to a local machine via VPN. Containers are stored in some public registry anyways. Also use ansible with all the configurations and container settings.
Free electricity for everyone.
So you know how to do it securely and analyze what may go one when it is attacked. Or what else do you want with cybersecurity? It’s about securing services on the global network and local. And webhosting is one of those service.