12 ms·
Maybe a dumb question, but does anyone sets up their VPN server in the cloud? Could cheapest droplet on DigitalOcean [0] handle traffic for browsing or youtube?
by CubicsRube 7y ago
Maybe a dumb question, but does anyone sets up their VPN server in the cloud? Could cheapest droplet on DigitalOcean [0] handle traffic for browsing or youtube?
[0] https://www.digitalocean.com/pricing/#standard-compute-trigger https://www.digitalocean.com/pricing/#standard-compute-trigg...
- tprynn 7y agoYes and yes, the $5 droplet is perfect for wireguard.
- mikl 7y agoYeah, if you don’t have a home network you want access to, a cloud server would do just fine. Smallest droplet would probably be fine, if you’re not streaming 4K video. Same goes for the 1TB transfer limit.
- farss 7y agoNot dumb at all. I'm doing this on a $5 droplet and it's faster than any of the commercial VPN's I'm currently paying for. It's a little less privacy protective than many VPN providers however - Digital Ocean will for example forward DMCA violation nastygrams they receive from content owners.
- tgtweak 7y agoYou'll get recapcha'd like crazy. Also some e-commerce sites will refuse purchases when made from hosting-allocated IP ranges since it's commonplace for fraud.
- big_chungus 7y agoAt least for me on linode, it's less-bad than others I've seen. Google doesn't typically get nasty; I think I can only think of a few sites that are especially bad (linkedin and arstechnica forums are two that come to mind). That probably has to do with me using the same IP for ~2yrs now, so it doesn't have reputation problems.
- arriu 7y agoTried this, you will encounter a ton of sites that assume you are a bot. You will find it annoying to browse quite a few sites. Some will outright refuse to work.
- whiskeykilo 7y agoI've never heard of this. Is this exclusively a Digital Ocean issue?
- simcop2387 7y agoNo, I run into this with my Linode also. Basically any of the large VPS providers and some of the smallest are well known to other services for being used to automate scraping or other things. Linkedin is a great example of one that (used to anyway, haven't tried in a while) completely block any IP that was known to be from a VPS provider.
- chrsstrm 7y agoNope, this is pretty common. I found out the hard way that Delta doesn’t allow access to their servers from my cloud hosted VPN, which is shitty considering airports are pretty VPN-heavy locations for me. They don’t seem interested in reconsidering this stance either.
- 1996 7y agoGet an ASN, get some IP space, and the issue is no longer a problem.
- whiskeykilo 7y agoI set one up using a free GCP instance and it's been working great so far. Would definitely handle your described usage and save you $5 a month
- philshem 7y agoAren’t static IPs now excluded from the GCP free tier? https://github.com/rajannpatel/Pi-Hole-PiVPN-on-Google-Compute-Engine-Free-Tier-with-Full-Tunnel-and-Split-Tunnel-OpenVPN-Configs/issues/47 https://github.com/rajannpatel/Pi-Hole-PiVPN-on-Google-Compu... (I run OpenVPN and PiHole from a GCP micro instance)
- zrm 7y agoA VPN server doesn't strictly need a static IP, you can use dynamic DNS.
- philshem 7y agoCan you explain, or provide a link? I’m a networking novice, but in my .ovpn profiles I provide, the IP is hard-coded.
- icebraining 7y agoInstead of an IP, you can use a domain. Then you can use Dynamic DNS to keep that domain pointed at your current IP (essentially, you run a small program on the same computer as the VPN server, that updates the DNS provider every time the IP changes).
- whiskeykilo 7y agoNot quite yet. But also like another user said, DuckDNS "Note: Starting January 1st, 2020, GCP will charge for VM instance external IP addresses. However, under the Free Tier, in-use external IP addresses will be free until you have used a number of hours equal to the total hours in the current month. Free Tier for in-use external IP addresses apply to all instance types (not just f1.micro instances)."
- eximius 7y agoI got a special deal at a VPS provider for $1/mo for 1vCPU and 256MB RAM. With only Wireguard running, I experience no issues whatsoever. RAM usage is minimal, sub 100MB, I forget the particulars. I added unbound with a huge DNS blacklist and unbound must do some odd indexing or something because that blew it to around 400MB which required a swap drive. But even with that, the performance is more than fine. I notice no discernible performance loss on my phone and from my 1Gbps connection at home, I see speeds that are comparable with saturating the network of the VPS (~200Mbps).
- probst 7y agoI use a VPS at Hetzner, but a whole lot of traffic sites stop working when I am using the VPN. I bet in part it is due to the CloudFlare's efforts to "Cleaning up Bad Bots" [1]. In this article under how they detect bots they write: > Another model allows us to determine whether an IP address belongs to a VPN endpoint, a home broadband subscriber, a company using NAT or a hosting or cloud provider. It’s this last group that “Bot Cleanup” targets. I suspect when use a VPN hosted on a VPS, you often end up classified as a bot to be cleaned up... 1: https://blog.cloudflare.com/cleaning-up-bad-bots/ https://blog.cloudflare.com/cleaning-up-bad-bots/
- vbezhenar 7y agoIt should be absolytely enough. I'm using 256 MB extremely weak VPS (1 euro/month) for OpenVPN for few clients. It handles up to 100 Mb/s just fine.
- Skunkleton 7y agoMy wireguard gateway is in the cloud (linode fremont). When I connect to it, the eventual gateway is my home router. If I were to use the VPS as my gateway, then my traffic would be blocked by all sorts of services. Annoyingly, I have moved, and now have comcast so that brings problems. First, they tamper with DNS traffic. To combat this the resolver is unbound running on the Linode. This creates very occasional problems, usually in the form of a capcha. Additionally, comcast doesn't offer symmetric connections, so my VPN is slower than it should be (1Gbps/30Mbps is such a joke).
- citiguy 7y agoYes, I've been doing this for about a year on a $5 droplet and it's fine. I haven't had any issues with blocking (but maybe its the sites I visit)? In fact, I also run a pihole on the same droplet, and that's fine too.