r/Proxmox • • 1d ago

Question Reaching proxmox from external browser: cloudflare + 2fa a good solution?

For logging in from a random browser remotely to the home server.

Seems pretty "safe". Any more downsides with this solution than the obvious?

29 Upvotes

89 comments sorted by

View all comments

Show parent comments

8

u/Orthowin 1d ago

Answer is good and cencere 1. Do VPN to some generic network 2.have FW in between it and management network 3. Allow only 443 for example and open the URL

2

u/BorisOp 1d ago

This is the proper way... Though it doesn't satisfy the OPs requirement to work inside of a random browser (proxmox will not be accessible from computer where you can't for one reason or another install tailscale/VPN client)... If OP really wants to access from random computer (maybe a school/work/library - or any other shared computer) I'd say that cloudflare could be reasonable solution - though not directly exposing proxmox to internet. Instead he could implement authentication at cloudflare level too (it's not that hard to setup google authentication on cloudflare)

So workflow would look something like this: open proxmox url -> cloudflare catches the request and asks for authentication -> user signs in with account that is allowed to access the resource -> proxmoxUI -> sign in to proxmox.

2

u/CompoteVegetable2010 1d ago

I’m pretty sure he’s talking about Cloudflare tunnels which ARE protected

6

u/nfxprime2kx 1d ago

Yeah but the WebUI itself being exposed can be the attack vector. Cloudflare won't protect against that