this post was submitted on 11 Feb 2024
8 points (83.3% liked)
homelab
6646 readers
33 users here now
founded 4 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
The reverse-proxy is usually the place where you terminate the TLS connections and also where you generate your let's encrypt certificates. Depending on your network stack and software used, it can be a bit inconvenient to have that on the router.
One way that is interesting though is to have a load-balancer + reverse-proxy combination on the router that can also do SNI based forwarding and then have a second application reverse-proxy that also acts as the TLS termination point on the actual server. However setting that up is a bit more involved and the documentation for it on OPNsense isn't great (I tried this before and failed, even though the docs say it should be possible).