I seem to keep getting myself in a pickle, I can get it working but then I appear to break other things, like autofs mounts fail if I have Macvlan working, going to have to dig a little deeper, will take a look at that link.

Caddy is awesome, I’m using it as a reverse proxy, but it automatically handles getting let’s encrypt certificates and renewals, it’s considerably easier and more straightforward to configure than Nginx
Or apache.

The other solution is to allow the connections in, but use one of the plugins to deny access if the source was not an internal IP address.

Third solution, use one of my pi’s purely as a caddy proxy....I’m leaning towards this right now,

How you doing Mark? Hope you’re well.