2026-09-22
FTPS and SFTP differ by a single letter, and they are often confused. In fact they are two different protocols with different designs. FTPS is regular FTP with TLS encryption added. SFTP is a standalone protocol that …
Read more2026-09-22
Certificates protect the tunnel well, but are a poor tool for managing human access. When there are dozens of employees, certificates have to be issued and revoked manually, and a dismissed person can continue to connect …
Read more2026-09-22
OpenVPN is a VPN protocol and at the same time an open-source program that implements it. The project has existed since 2001 and runs on almost any system: Linux, Windows, macOS, BSD, Android, iOS, as well as on …
Read more2026-09-22
Tailscale, cloud NetBird and ZeroTier are convenient, but network control in them remains with a third-party company: it verifies users, issues keys and access rules. If that is unacceptable — for security requirements, …
Read more2026-09-22
ZeroTier and NetBird are services for creating a private network between your devices over the Internet, main alternatives to Tailscale. All three solve the same problem: computers, servers and phones see each other by …
Read more2026-09-22
What is Tailscale Tailscale is a service that unites your computers, servers and phones into a single private network over the Internet. Devices get stable internal addresses and connect to each other directly using the …
Read more2026-09-22
Mesh VPN — is a private network in which devices connect to each other directly rather than through a single central server. A laptop, a home server, an office computer and a phone see each other by internal addresses …
Read more2026-09-22
Why a VPN client on the router Configuring a VPN on each device is inconvenient, and TVs, game consoles and smart home devices often don’t support it at all. If the router becomes the VPN client, the tunnel can be …
Read more2026-09-22
A firewall, Fail2ban and CrowdSec respond to attacks that are already underway. An audit solves a different task: to find weak spots in the server configuration in advance — extra services, permissive SSH settings, …
Read more2026-09-22
Firewall — the first thing you set up on a new server, even before Fail2ban, CrowdSec, and auditing. Its job is simple: allow only the traffic needed by running services and drop everything else. The fewer open ports, …
Read more