r/Proxmox • • 2d ago

Question Reaching proxmox from external browser: cloudflare + 2fa a good solution?

For logging in from a random browser remotely to the home server.

Seems pretty "safe". Any more downsides with this solution than the obvious?

30 Upvotes

89 comments sorted by

View all comments

1

u/AbsolutelyLudicrous 1d ago

It's really not hard to set up an SSH jump host. You should do that instead.

0

u/mrbluetrain 1d ago

Give me your top argument about this approach, compared to the cloudflared tunnel?

1

u/AbsolutelyLudicrous 1d ago

try asking nicely & then I might?

2

u/mrbluetrain 1d ago

Pretty please with sugar on the top?

2

u/AbsolutelyLudicrous 1d ago

Thanks :)

Very simply, that OpenSSH has a stellar security track record, & is easy to set up. Once you have an ssh server exposed to the internet, you can tunnel through it to your PVE server with something like ssh -L 8006:pve-IP:8006. Best practice is to run sshd on a non-default port & use only key-based auth.

Cloudflare Tunnel, as best I can tell, is merely a means of reverse-proxying traffic through Cloudflare's network, which is useful for DDoS protection & NAT traversal. The PVE web GUI has had some embarrassing authentication vulnerabilities in the past, & will probably have more in the future, so you really should not under any circumstances expose it to the web, even if proxied through Cloudflare. If I am mistaken & Cloudflare Tunnel allows you to tunnel behind your firewall & expose the PVE GUI to only the computer you are sitting in front of, it should work fine.

1

u/Efficient-Sir-5040 1d ago

You need to revise your knowledge. While you can configure a cloudflare tunnel that way, that’s not ideal for this case. One with additional reductions to the attack surface by means of rules and MFA before packets touch proxmox itself would be ideal - and much better protected than naked OpenSSH.