User avatar
Norm (ノーム) CastoriceBlushing @norm@shrimp.biribiri.dev
1mo
people who host publicly-facing servers at home (not on a VPS), do you just directly use your home IP address w/ port forwarding or use a tunnel to a VPS (or a service like CF tunnels) with a reverse proxy?
:black_sparkling_heart@fire.asta.lgbt:1
11
5
4
1

User avatar
purple 💜 @purple@nya.social
1mo
@norm i use a wireguard tunnel to a vps running traefik for ingress. everything other than a landing page is hosted off the cluster at home 😌
0
0
1
0
User avatar
mirabilos @mirabilos@toot.mirbsd.org
1mo
@norm wdym port forwarding for ?
1
0
0
0
User avatar
Norm (ノーム) CastoriceBlushing @norm@shrimp.biribiri.dev
1mo
@mirabilos I mean like just hosting directly off your home connection's public IP. I know port forwarding isn't strictly necessary with IPv6, but I'd imagine some people are on IPv4 only setups where you do have to deal with NAT
1
0
0
0
User avatar
mirabilos @mirabilos@toot.mirbsd.org
1mo
@norm yes, I do that, but the home server does the NAT for v4 for the devices on LAN, so…
1
0
0
0
User avatar
Norm (ノーム) CastoriceBlushing @norm@shrimp.biribiri.dev
1mo
@mirabilos not sure what you're asking about then...
1
0
0
0
User avatar
mirabilos @mirabilos@toot.mirbsd.org
1mo
@norm there is no NAT or port forwarding for the services
1
0
0
0
User avatar
Norm (ノーム) CastoriceBlushing @norm@shrimp.biribiri.dev
1mo
@mirabilos I mean well there would be NAT/port forward on v4 unless you somehow have multiple v4 external IPs
1
0
0
0
User avatar
mirabilos @mirabilos@toot.mirbsd.org
1mo
@norm no, there is no port forward on v4, the PPPoE terminates directly in the home server
2
0
1
0
User avatar
mirabilos @mirabilos@toot.mirbsd.org
1mo
@norm you’d only need port forwarding if you had one of those stupid cheap plastic routers in between, which is a good thing to get rid of
1
0
0
0
User avatar
Norm (ノーム) CastoriceBlushing @norm@shrimp.biribiri.dev
1mo
@mirabilos I do think there's still a usecase for a separate router from a server, but I do agree with ditching consumer-grade routers or the ISP provided stuff
1
0
0
0
User avatar
mirabilos @mirabilos@toot.mirbsd.org
1mo
@norm if the server is either running all the time or cheap enough power-wise to keep running all the time, I’ll argue it makes a better router anyway since you can run BSD with a proper firewall on it and are much better network-wise than with a separate router
1
0
1
0
User avatar
Norm (ノーム) CastoriceBlushing @norm@shrimp.biribiri.dev
1mo
@mirabilos fair enough, I kinda like having the two separate in case my server stuff goes down for some reason
1
0
1
0
User avatar
mirabilos @mirabilos@toot.mirbsd.org
1mo
@norm fair, though in my experience it’s the Fritzbox stuff that goes down much more often ;)
1
0
1
0
User avatar
Norm (ノーム) CastoriceBlushing @norm@shrimp.biribiri.dev
1mo
@mirabilos hence the "ditching [...] ISP equipment" in the other reply neocat_wink_blep
1
0
1
0
User avatar
mirabilos @mirabilos@toot.mirbsd.org
1mo
@norm Fritzbox stuff is what people bought here for decades to ditch ISP stuff…
2
0
0
0
User avatar
mirabilos @mirabilos@toot.mirbsd.org
1mo
@norm (ofc now some bundle those instead, but not all)
0
0
1
0
User avatar
Norm (ノーム) CastoriceBlushing @norm@shrimp.biribiri.dev
1mo
@mirabilos the ISP stuff must be really bad if that is considered an upgrade...
2
0
1
0
User avatar
Norm (ノーム) CastoriceBlushing @norm@shrimp.biribiri.dev
1mo
@mirabilos (then again people here buy TP-Link Decos and amazon eeros to replace ISP routers...)
0
0
1
0
User avatar
mirabilos @mirabilos@toot.mirbsd.org
1mo
@norm oh it is, even some people from the same telco say so
0
0
1
0
User avatar
Norm (ノーム) CastoriceBlushing @norm@shrimp.biribiri.dev
1mo
@mirabilos I mean I suppose you could do that, but I would imagine most wouldn't do that
0
0
0
0
User avatar
Fop Aly FireflyNotBad american_megatrans @ezio@akko.wtf
1mo
@norm I should probably use a tunnel but I'm lazy so using just cloudflare's proxy with DNS thi g
1
0
1
0
User avatar
Norm (ノーム) CastoriceBlushing @norm@shrimp.biribiri.dev
1mo
@ezio the caveat to using cloudflare's reverse proxy is that it only proxies inbound connections, so if the server you are running makes outbound connections, those will use your regular internet access

using a VPN tunnel means both inbound and outbound connections go through a different IP

just something to be aware of
1
0
1
0
User avatar
Fop Aly FireflyNotBad american_megatrans @ezio@akko.wtf
1mo
@norm yeah ik just lazy
0
0
1
0
User avatar
Toast @toast@donotsta.re
1mo
@norm back when I did this I had a Linux box as my router so I had a reverse proxy running on that proxying over to the server at home (so it can have a dhcp lease and everything), which came with the extra funny added benefit of being able to reverse proxy direct to containers if THEY go through dhcp and get picked up by dnsmasq etc, though I think what allowed that to work has been broken since
0
0
1
0
User avatar
Alex Bissessur @alexb@alexbissessur.dev
1mo
@norm
I used to expose my home IP w/ port forwarding, but
@eleboucher made Towonel (codeberg.org/towonel/towonel) and I run it on a small VPS
0
0
1
0
User avatar
mldkyt @mldkyt@pl.mldkyt.com
1mo
@norm I run everything on a bare metal server at home, since it's way easier to do, I have a few other things tho
Discord bots run outside of the Wireguard connection because of connectivity issues. Those have a separate server. The nginx on the main server can direct traffic to there if needed.
Status page and mail server runs on the VPS.

This setup kind of allows me to have almost no loss of data when e.g. my VPS gets terminated over a failed transaction
0
0
1
0
User avatar
stefan (stefbun) @stefan@akko.lightnovel-dungeon.de
1mo
@norm Its kinda mixed here lol. I tunnel through a VPS but not for privacy.

My privacy is fucked by having that imprint (government mandated) on my sites. I tunnel I can have IPv4 Traffic to my home. Otherwise I would just the IP at home as is.
1
0
1
0
User avatar
Norm (ノーム) CastoriceBlushing @norm@shrimp.biribiri.dev
1mo
@stefan do you have cgnat?
1
0
0
0
User avatar
stefan (stefbun) @stefan@akko.lightnovel-dungeon.de
1mo
@norm DS-lite basically yeah. Though tbh I never. checked if the new ISP does give me an actual IPv4 instead...
0
0
1
0
User avatar
Oha @Oha@pobierz.net
1mo
@norm Mix of both. IP gets tunneled in from a friends router bc my provider only gives me a single dynamic /64. Im lucky enough to not sit behind CGNAT so my Legacy IP is native
0
0
1
0
1mo
@norm why would you tunnel unless you don’t have a public IP, or you can’t be arsed to setup a ddns resolver? there are very few reasons not to just use your IP…
2
0
0
0
User avatar
Norm (ノーム) CastoriceBlushing @norm@shrimp.biribiri.dev
1mo
@domi at least in my case I am somewhat paranoid about exposing my home IP and also my ipv4 address changes whenever I reboot my router or modem.

I might just go down the port forwarding route with a ddns setup soon though
0
0
0
0
User avatar
Wolf480pl @wolf480pl@mstdn.io
1mo
@domi
eg. you live in a small town and your revdns reveals which small town
@norm
1
0
0
0
@wolf480pl @norm @snow with this sort of threat model you should be tunneling ALL of your traffic through a vpn of some sort. there’s plenty of ways an attacker can discover your home IP otherwise.
0
0
0
0
User avatar
freek🔸 @freek@kubes.cloud
1mo
@norm (nice hostname btw) I am using @eleboucher 's instance of towonel on his VPS: it gives me the convenience and comfort of Cloudflare Tunnel, without giving them data or allowing any decryption of the traffic outside my home (it stays encrypted until it gets to my hardware), and I am supporting an important open source project!
0
0
1
0