4 ms·
> Unless like OP your ISP has put CGNAT on you. I run Wireguard on a VPS and route public traffic with it over Wireguard to my home machine. Are you saying my
by selfhoster 2y ago
> Unless like OP your ISP has put CGNAT on you.
I run Wireguard on a VPS and route public traffic with it over Wireguard to my home machine.
Are you saying my ISP must not be CGNAT or else it wouldn't work?
- aborsy 2y agoHow is this a good solution, when traffic is decrypted in the cloud, all traffic goes through one node, there is no ACL, key distribution, static IP, …? Tailscale addressed those issues.
- selfhoster 2y agoI guess I'm not clear what "when traffic is decrypted in the cloud" means but, here's how it works...public traffic comes in on port 80 to the VPS, Wireguard is configured to route it over the VPN to a VM on my home machine. I control the VPS and the peer receiving the traffic.
- aborsy 2y agoIf the Wireguard server is run on VPS, the encryption is not end to end from the client in public internet to your home. It’s encrypted from client to VPS, then from VPS to home. The VPS sees the traffic inside of tunnel. That’s the first problem.
- codetrotter 2y agoNo. I was talking specifically about the case where you want to host the Wireguard VPN server at home. See earlier in the comment where I said: > opening up a port for it for inbound connections if you host it from your home connection rather than a rented server Although I can see how it might not be clear that in the end where I’m mentioning CGNAT I am still specifically talking about hosting the VPN server from your home connection.
- selfhoster 2y agoThat makes sense, I forgot people also expose a server at home the way I do on the VPS then route to a peer at home. Appreciate the insight.