Bungeecord security running on local host

Hey All, Was just wondering, whats the best way to secure a bungeecord network when all servers are running on the same machine. I have bungeeguard right now, but wnna be extra safe.
55 Replies
goosBanny
goosBanny2y ago
make sure that all ports are closed EXCEPT for the proxy oh and of course panel n stuff
Deleted User
Deleted UserOP2y ago
so im running my proxy on 25565
goosBanny
goosBanny2y ago
on public ip, yes.
Deleted User
Deleted UserOP2y ago
keep all others closed except 25565 then?
goosBanny
goosBanny2y ago
yeah
Deleted User
Deleted UserOP2y ago
Ah awesome
goosBanny
goosBanny2y ago
bungeeguard is not really needed in this case any plans on switching to velocity btw? bungeecord is uhh.. wack.
Deleted User
Deleted UserOP2y ago
I was going to! but i couldnt find a good tutorial haha Im actualy using waterfall, idk why i said bungeecord
goosBanny
goosBanny2y ago
same thing p much
Deleted User
Deleted UserOP2y ago
Ye
goosBanny
goosBanny2y ago
Getting Started | PaperMC Documentation
This page covers how to install and set up a minimal configuration of Velocity.
goosBanny
goosBanny2y ago
of course, you dont need to switch but the performance and stability is worth it
Deleted User
Deleted UserOP2y ago
I only started working on servers again from like a 5 year break
goosBanny
goosBanny2y ago
ahh back to torture yourself fun
Deleted User
Deleted UserOP2y ago
so i didnt know much about velocity Yea, and i still have trauma from getting backdoored because of dodgy bungee setup lmao
goosBanny
goosBanny2y ago
ouch
goosBanny
goosBanny2y ago
a knowledge base like https://setup.md/ might be useful to you
Welcome | setup.md
We are setup.md, a community focused around documenting the important parts of Minecraft server administration and ensuring everything can be found in one single place.
Deleted User
Deleted UserOP2y ago
Yea, thats why i wnna be ultra safe Oh awesome, il give it a read right now But yea, you think velocity is a better way to go?
goosBanny
goosBanny2y ago
how many players do you hope to hold at the same time its still worth it if its a very small amount but im mostly just curious
Deleted User
Deleted UserOP2y ago
Hm, id say up to 100 ideally, realistic maybe 20-30 consecutive so not giant
goosBanny
goosBanny2y ago
not going to notice any major change at that point fewer crashes i suppose. shit is STABLE switch to velo
Deleted User
Deleted UserOP2y ago
velocity?
goosBanny
goosBanny2y ago
yeah
Deleted User
Deleted UserOP2y ago
OK will do then! Im gonna read the link you sent, but is the setup similar to waterfall?
goosBanny
goosBanny2y ago
pretty much the same do keep in mind that it has a smaller plugin library than bungee though. you will have to make your own plugin (or snap! it in some cases)
Deleted User
Deleted UserOP2y ago
Ahhhh fair Stll sounds good though
goosBanny
goosBanny2y ago
just dont try to snap! any advanced plugins that'll surely break
goosBanny
goosBanny2y ago
GitHub
GitHub - Phoenix616/Snap: Experimental tool to run BungeeCord plugi...
Experimental tool to run BungeeCord plugins on Velocity - GitHub - Phoenix616/Snap: Experimental tool to run BungeeCord plugins on Velocity
goosBanny
goosBanny2y ago
dam wtf
Deleted User
Deleted UserOP2y ago
Maybe a bit off topic, but you seempretty knowledagble. Any idea of a good auto mover plugin between servers? Like if a server went down etc
goosBanny
goosBanny2y ago
did discord.. meh whatever Velocity does that by default - there is a "try [ list ]" section in the config you could use FallbackServer
Discount Milk
Discount Milk2y ago
But still recommended!
Deleted User
Deleted UserOP2y ago
Ah awesome Ok, yall convinced me haha Im doing it right now, so i might ask a question or two here if yall dont mind if theres an issue
Discount Milk
Discount Milk2y ago
That's the point ;)
Deleted User
Deleted UserOP2y ago
for reference, 127.0.0.1 can be used for localhost right? Sorry for any stupid questions, im really rusty
goosBanny
goosBanny2y ago
yeahp
Deleted User
Deleted UserOP2y ago
thanks!
goosBanny
goosBanny2y ago
actually @Señor Leche can you confirm that lol im not so sure 🤔
Deleted User
Deleted UserOP2y ago
try = [
"live","hub"
]
try = [
"live","hub"
]
Discount Milk
Discount Milk2y ago
Should be
Deleted User
Deleted UserOP2y ago
Is the formatting on that ok?
goosBanny
goosBanny2y ago
ye
Deleted User
Deleted UserOP2y ago
The wiki says this
In config/paper-global.yml, set proxies.velocity.enabled to true and proxies.velocity.secret, to match the secret in your forwarding.secret file. You must also set proxies.velocity.online-mode to the online-mode setting in your velocity.toml. Once you're done editing paper-global.yml, reboot your server.
In config/paper-global.yml, set proxies.velocity.enabled to true and proxies.velocity.secret, to match the secret in your forwarding.secret file. You must also set proxies.velocity.online-mode to the online-mode setting in your velocity.toml. Once you're done editing paper-global.yml, reboot your server.
In my global.yml i have this
proxies:
bungee-cord:
online-mode: true
proxy-protocol: false
velocity:
enabled: false
online-mode: false
secret: ''
proxies:
bungee-cord:
online-mode: true
proxy-protocol: false
velocity:
enabled: false
online-mode: false
secret: ''
goosBanny
goosBanny2y ago
set velocity.enabled to true, secret should be the secret key file in the velocity proxy's root folder forwarding.secret file
Deleted User
Deleted UserOP2y ago
will i leave online mode as false or set to true? I have true in my velcoity config and server properties is false
Discount Milk
Discount Milk2y ago
On the proxy true On the backend false in server.properties but true in paper.yml
Deleted User
Deleted UserOP2y ago
Awesome guys All seems to be setup!
ProGamingDk
ProGamingDk2y ago
why would u use that if u have the builtin feature of velocity?
goosBanny
goosBanny2y ago
bit more customizable
Deleted User
Deleted UserOP2y ago
Quick question, all players can do /server rn but they dont have the permission for it any idea why that would be? otherwise everythin gis perfect. Got forwarding etc. set up so ty for the suggestion and help
goosBanny
goosBanny2y ago
/lpv group default permission set velocity.command.server ig
Deleted User
Deleted UserOP2y ago
I moreso mean i dont want them being able to do /server, but by default it seems they can without having a permission
goosBanny
goosBanny2y ago
/lpv group default permission set velocity.command.server false :d you are using luckperms yes
Deleted User
Deleted UserOP2y ago
yee Not working. I think i might have luckperms setup incorrect with the move, databases etc. though so im gonna try figure itout myself first instead of bothering yall thanks for the help! Just incase anyone ever searches for the anser. You have to install LuckPerms proxy on the velocity server, and normal luck perms on all other servers. I was dumb and didnt install it on the proxy
goosBanny
goosBanny2y ago
uff

Did you find this page helpful?