5 ms·
Why not use a dynamic DNS service instead? I’ve been using dyn.com (now oci.dyn.com) for years and it has worked great. A bonus is many home routers have supp
by DougN7 1y ago
Why not use a dynamic DNS service instead? I’ve been using dyn.com (now oci.dyn.com) for years and it has worked great. A bonus is many home routers have support built in.
- mjg59 1y agoI have multiple devices on my internal network that I want to exist outside, and dynamic DNS is only going to let me expose one of them
- rkagerer 1y agoIf they don't all need distinct external IP addresses of their own, port forwarding is a typical approach.
- mjg59 1y agoThat doesn't work well if you want to run the same service on multiple machines. For some you can proxy that (eg, for web you can just run nginx to proxy everything based on either the host header or SNI data), but for others you can't - you're only going to be able to have one machine accepting port 22 traffic for ssh.
- chgs 1y agoSelect an isp that gives you multiple ip v4 addresses. Or host on ipv6.
- mjg59 1y agoYes, if I had multiple IPv4 addresses already it wouldn't be necessary to tunnel in additional IPv4 addresses, but since I don't and since there are no ISPs who will provide that to me at this physical address, tunneling is where I am.
- v5v3 1y agoIn many countries, unless you buy a business broadband package (more expensive),residential internet does not come with such options.
- herbst 1y agoYou can port forward SSH to other internal machines, just like nginx + web.
- mjg59 1y agoI can port forward port 22 to a single machine. I can't proxy port 22 in a way that directs the incoming connection to the correct machine, at least not without client configuration.
- koolba 1y agoYou only need one inbound machine as your bastion. Then hop from there to the rest using local address. Once you set up the proxy config in ssh it’s completely transparent.
- mjg59 1y agoRight yes but I (for various reasons) end up using a lot of different client systems and I don't want to have to configure all of them to transparently jumphost or use different port numbers and why are people spending so much time trying to tell me that I should make my life complicated in a different way to the one I've chosen?
- mindslight 1y agoIt's weird how much pushback you're getting for a few simple firewall rules, but I guess it's just another bikeshed. Basically all of the options for doing this are simple if you already know them, and have some annoying complexity otherwise. So everyone has a favorite. I've got a similar setup to what you've done here, with the policy routing and wireguard tunnels being part of a larger scheme that lets me granularly choose which Internet horizon each particular host sees. So I can have a browsing VM that goes out a rotating VPS IP, torrent traffic out a commercial VPN, Internet of Trash out a static VPS IP (why not separate from my infrastructure IP), visitors' devices going out a different rotating VPS IP (avoid associating with me), Windows VMs that can only access the local network (they have personal data), etc. I'm currently hosting email/etc on a VPS, but the plan is to bring those services back on-prem using VPS IPs with DNAT just like you're doing. Any day now...
- mvanbaak 1y agoipv6 has solved this. Too bad it's not yet a common thing.
- tialaramex 1y agoThe Google data strongly suggests that at this point it's probably available to a majority of home users. Corporate remains significantly worse. My employer, which paid me to do IPv6 stuff last century in a very different role, today has IPv6 for random outsiders but if you have a corporate issued laptop IPv6 is disabled and they cheerfully explained that it's "difficult" in a call this week right before I pointed out what I was paid to do and where a quarter century ago. Embarrassing for them.
- mvanbaak 1y agoA lot of consumer connections do indeed provide ipv6. But some are unstable, some change addresses every X days, some have weird routing etc etc.
- tialaramex 1y agoMeta IIRC is one of several outfits which unsurprisingly discovered that (as a corporation) the cure is just purchasing policy. When your new Doodad vendor sells you a product that is IPv4 only instead of saying "Oh, shame, OK, set all corporate systems to IPv4-only" you point them to the line in your purchase contract which says you require IPv6 and it's not your problem it's their problem, do they want to fix it or refund you ?
- mystified5016 1y agoYes, that's how it works when you only have a single IP. The standard way to deal with this is a reverse proxy for web requests. Other services require different workarounds. I have a port 22 SSH server for git activities, and another on a different port that acts as a gateway. From that machine I can SSH again to anywhere within my local network. It's really not onerous or complicated at all. It's about as simple as it gets. I'm hosting a dozen web services behind a single IP4 address. Adding a new service is even easier than without the proxy setup. Instead of dicking around with my firewall and port forwarding, I just add an entry to my reverse proxy. I don't even use IPs, I just let my local DNS resolve hostnames for me. Easy as.
- mjg59 1y agoThe entire point of this is that I don't want to deal with non-standard port numbers or bouncing through hosts. I want to be able to host services in the normal boring way, and this approach lets me do that without needing to worry about dynamic DNS updates whenever my public IP changes.
- mysteria 1y agoSame for me, I actually like having a reverse proxy as a single point of entry for all my web services. I also run OpenVPN on 443 using the port share feature and as a result I only need one IP address and one open port for everything.
- messe 1y agoOnly works if you're not behind CGNAT, which has problems in and of itself. I pay my ISP an extra 29 DKK (about 4.50 USD at the moment) for a static address; my IPv4 connections and downloads in-general became way more stable after getting out from behind CGNAT.
- neepi 1y agoCGNAT is hell. Here I had to choose between crap bandwidth or CGNAT. I chose crap bandwidth.
- immibis 1y agoHell for hosting, but if you're doing adversarial interoperability as a client, it does help you avoid being IP-banned. (At least in Western countries. I hear that Africa and Latin America tend to just get their CGNAT gateways banned because site operators don't give a shit about whether users from those regions can use their sites)
- neepi 1y agoNot quite. I'm in the UK and some of our customers get blocked by overzealous CDNs and they're all on CGNAT.
- dkjaudyeqooe 1y agoIt's not really overzealous since not banning the CGNAT IPs just gives the abusers safe harbor.
- immibis 1y agoAnd banning them makes an entire country unable to use your site. That might be tolerable (to the site owner, but not in general) if the country is Argentina. Not if the site is France. Which is why Argentina gets blocked a lot more than France and if you want to scrape things you'd do better on a CGNAT network in France.
- thedanbob 1y agoThis is what I do, except the dynamic DNS service is just a script on my server that updates Cloudflare DNS with my current external IP. In practice my address is almost static, I've never seen it change except when my router is reset/reconfigured.
- globular-toast 1y agoMany DNS registrars support updates via API these days. I use Porkbun and ddclient to update it. Slight rub is I couldn't get it to work for the apex domain. Not sure where the limitation lies.