<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[LDAP port (security considerations)]]></title><description><![CDATA[<p dir="auto">In a way I understood from the hints I've got, when I expose my LDAP to the outside, you are not spawning a separate process, but instead re-route 3004 port to the web service - ldapjs - <a href="https://github.com/ldapjs/node-ldapjs/" target="_blank" rel="noopener noreferrer nofollow ugc">https://github.com/ldapjs/node-ldapjs/</a></p>
<p dir="auto">I'm wondering if I can limit access to the port 3004 to a specific IP address? Or, even better, I would love to see limited access to some specific URLs - so that I could block access to 'ldapjs' only to my internal servers, as well as access to /well-known/' or other web services.</p>
<p dir="auto">It feels like a relatively easy thing to do at nginx side, unless I'm wrong or missing something?</p>
]]></description><link>https://forum.cloudron.io/topic/9730/ldap-port-security-considerations</link><generator>RSS for Node</generator><lastBuildDate>Fri, 17 Apr 2026 12:40:39 GMT</lastBuildDate><atom:link href="https://forum.cloudron.io/topic/9730.rss" rel="self" type="application/rss+xml"/><pubDate>Fri, 28 Jul 2023 16:53:05 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to LDAP port (security considerations) on Sun, 30 Jul 2023 20:00:50 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/imc67" aria-label="Profile: imc67">@<bdi>imc67</bdi></a> geo-block feels like a more feature-rich solution, that might be of help, but not exactly my cup of tea.</p>
<p dir="auto">I would guess, that Cloudflare doesn't prevent anyone from accessing your web service directly (should they figure out the IP address, for example, via e-mail you've sent)?</p>
]]></description><link>https://forum.cloudron.io/post/71084</link><guid isPermaLink="true">https://forum.cloudron.io/post/71084</guid><dc:creator><![CDATA[potemkin_ai]]></dc:creator><pubDate>Sun, 30 Jul 2023 20:00:50 GMT</pubDate></item><item><title><![CDATA[Reply to LDAP port (security considerations) on Sun, 30 Jul 2023 18:09:06 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/potemkin_ai" aria-label="Profile: potemkin_ai">@<bdi>potemkin_ai</bdi></a> IP block/allow on app level including Geo-block/allow might be a solution? I use Cloudflare for some (sub)domains for this but love to have it inside Cloudron!</p>
]]></description><link>https://forum.cloudron.io/post/71083</link><guid isPermaLink="true">https://forum.cloudron.io/post/71083</guid><dc:creator><![CDATA[imc67]]></dc:creator><pubDate>Sun, 30 Jul 2023 18:09:06 GMT</pubDate></item><item><title><![CDATA[Reply to LDAP port (security considerations) on Sun, 30 Jul 2023 17:43:05 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/girish" aria-label="Profile: girish">@<bdi>girish</bdi></a> agh, I meant some security gate that closes Cloudron from the outside and all of the traffic is coming from there - so I do know the IP address of all of the clients, as it's my security gate, and I want to make sure none from the outside world would reach specific app.</p>
<p dir="auto">Does it makes sense?</p>
<p dir="auto">Speaking about Cloudron build-in VPN integration - do you already have some plans how Wireguard integration &amp; managent would looks like?</p>
]]></description><link>https://forum.cloudron.io/post/71080</link><guid isPermaLink="true">https://forum.cloudron.io/post/71080</guid><dc:creator><![CDATA[potemkin_ai]]></dc:creator><pubDate>Sun, 30 Jul 2023 17:43:05 GMT</pubDate></item><item><title><![CDATA[Reply to LDAP port (security considerations) on Sun, 30 Jul 2023 04:21:26 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/potemkin_ai" aria-label="Profile: potemkin_ai">@<bdi>potemkin_ai</bdi></a> Ah ok. The VPN use case requires a lot more platform integration and cannot be achieved just using some iptable rules. That feature is planned for 7.6 - <a href="https://forum.cloudron.io/topic/9180/what-s-coming-in-7-5/2">https://forum.cloudron.io/topic/9180/what-s-coming-in-7-5/2</a> .</p>
]]></description><link>https://forum.cloudron.io/post/71067</link><guid isPermaLink="true">https://forum.cloudron.io/post/71067</guid><dc:creator><![CDATA[girish]]></dc:creator><pubDate>Sun, 30 Jul 2023 04:21:26 GMT</pubDate></item><item><title><![CDATA[Reply to LDAP port (security considerations) on Sat, 29 Jul 2023 07:19:21 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/girish" aria-label="Profile: girish">@<bdi>girish</bdi></a> thanks! I would like to be able to close some web apps to be only accessible from specific IP set.</p>
<p dir="auto">For example, Jitsi to be used by those who logged in via VPN.</p>
<p dir="auto">Does it make sense?</p>
]]></description><link>https://forum.cloudron.io/post/71047</link><guid isPermaLink="true">https://forum.cloudron.io/post/71047</guid><dc:creator><![CDATA[potemkin_ai]]></dc:creator><pubDate>Sat, 29 Jul 2023 07:19:21 GMT</pubDate></item><item><title><![CDATA[Reply to LDAP port (security considerations) on Sat, 29 Jul 2023 02:55:17 GMT]]></title><description><![CDATA[<p dir="auto">Couldn't find a good link but we do batteries included - <a href="https://en.wikipedia.org/wiki/Batteries_Included" target="_blank" rel="noopener noreferrer nofollow ugc">https://en.wikipedia.org/wiki/Batteries_Included</a> .</p>
]]></description><link>https://forum.cloudron.io/post/71040</link><guid isPermaLink="true">https://forum.cloudron.io/post/71040</guid><dc:creator><![CDATA[girish]]></dc:creator><pubDate>Sat, 29 Jul 2023 02:55:17 GMT</pubDate></item><item><title><![CDATA[Reply to LDAP port (security considerations) on Sat, 29 Jul 2023 02:52:19 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/potemkin_ai" aria-label="Profile: potemkin_ai">@<bdi>potemkin_ai</bdi></a> said in <a href="/post/71024">LDAP port (security considerations)</a>:</p>
<blockquote>
<p dir="auto">Is it possible to set this up for other services and web apps, including dashboard?</p>
</blockquote>
<p dir="auto">It's easier to discuss if you can give us concrete use cases (of what you are trying to achieve). Generally, anything is possible <img src="https://forum.cloudron.io/assets/plugins/nodebb-plugin-emoji/emoji/android/1f642.png?v=665e13d50c8" class="not-responsive emoji emoji-android emoji--slightly_smiling_face" style="height:23px;width:auto;vertical-align:middle" title=":-)" alt="🙂" /> but the way we go about Cloudron development itself is to be a solution and not a generic server management panel where a sysadmin can achieve all sorts of setups.</p>
]]></description><link>https://forum.cloudron.io/post/71039</link><guid isPermaLink="true">https://forum.cloudron.io/post/71039</guid><dc:creator><![CDATA[girish]]></dc:creator><pubDate>Sat, 29 Jul 2023 02:52:19 GMT</pubDate></item><item><title><![CDATA[Reply to LDAP port (security considerations) on Fri, 28 Jul 2023 17:15:18 GMT]]></title><description><![CDATA[<p dir="auto">Yes, I'm. It seems I forgot that I made that setting with my own hand.</p>
<p dir="auto">Is it possible to set this up for other services and web apps, including dashboard?</p>
]]></description><link>https://forum.cloudron.io/post/71024</link><guid isPermaLink="true">https://forum.cloudron.io/post/71024</guid><dc:creator><![CDATA[potemkin_ai]]></dc:creator><pubDate>Fri, 28 Jul 2023 17:15:18 GMT</pubDate></item><item><title><![CDATA[Reply to LDAP port (security considerations) on Fri, 28 Jul 2023 17:08:43 GMT]]></title><description><![CDATA[<p dir="auto">I guess you refer to <a href="https://docs.cloudron.io/user-management/#directory-server" target="_blank" rel="noopener noreferrer nofollow ugc">https://docs.cloudron.io/user-management/#directory-server</a> which is by default set up to only allow connections from the specified IPs/IP-ranges</p>
]]></description><link>https://forum.cloudron.io/post/71022</link><guid isPermaLink="true">https://forum.cloudron.io/post/71022</guid><dc:creator><![CDATA[nebulon]]></dc:creator><pubDate>Fri, 28 Jul 2023 17:08:43 GMT</pubDate></item></channel></rss>