My ISP provide me with good IPv6 connection with support of opening ports how I like. But IPv4 is behind a CGNAT and makes me unable to host a service on the legacy Internet.

Unfortunetely some of my friends I want to host (Jellyfin and Nextcloud) for does not have modern Internet connection, so I have to put some proxy.

Now I need suggestions of a solution. VPN on some VPS they would need to connection to is one of them, but it should be as simple for them to use as possible.

  • slazer2au
    link
    English
    77 months ago

    I’d say running the VPS as a proxy or nat64 setup would be the way to go. Cgnat kinda messes everything up.

    • @[email protected]OP
      link
      fedilink
      English
      17 months ago

      What I want to do. But the question is how?

      VPS as a proxy… but when I point A record to VPS and AAAA record to server in my home, how would the VPS know which traffic to pass and how.

      • @TCB13
        link
        English
        4
        edit-2
        7 months ago

        how would the VPS know which traffic to pass and how.

        Install nginx in your VPS and configure it as reverse proxy to your home IPv6:

        server {
            listen 80; # listens only on IPv4 port 80
            server_name example.com; # your domain name
            location / {
                proxy_pass http://[2a03:2880:f003:c07:face:b00c::2] # replace with your home server IPv6. Keep the brackets.
                proxy_set_header Host $host;
                proxy_set_header X-Real-IP $remote_addr;
                proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
                proxy_redirect off;
            }
        }
        

        Point your A record to your VPS, and your AAAA to the home server.


        • @[email protected]
          link
          fedilink
          English
          47 months ago

          Be aware that doing it like this, the traffic from the VPS to your home will be unencrypted.

          • @TCB13
            link
            English
            2
            edit-2
            7 months ago

            Yes, and wouldn’t the traffic between his friend and his home server be encrypted as well? :)

            The OP should first figure out how to do this with basic HTTP and then once it works he can do a more fancy setup like setup letsencrypt on the local server in order to have his website protected with a valid certificate.

            Then he can configure the VPS Nginx instance to do SSL pass-thru on port 443. This makes it so the VPS will be able to receive HTTPS traffic and send it back to his home server without having to do SSL termination / decryption / dealing with SSL certificates. Only the home server will have the certificates thus be able to decrypt the traffic.

            Once the website can be accessed from both servers directly with SSL he can proceed to disable plain text HTTP traffic. To do this simply remove the entire server { listen 80 section on both servers. The home server should end up server { listen listen [::]:443 ssl; section so it listens in both IPv4 and IPv6 for HTTPs traffic. The VPS should only have the stream at /etc/config/nginx.conf as described above - make sure the previous server block entry is removed from the VPS as it is no longer needed.

            If the OP goes through all those steps then none of the servers will accept plain HTTP traffic and the VPS will only proxy encrypted data back to his home. The beauty of SSL pass-thru is that the VPS doesn’t have the means to decrypt the traffic, you won’t have to manage certificates in across two servers and it’s way easier to setup than a WG tunnel.

        • @[email protected]
          link
          fedilink
          English
          27 months ago

          Be careful with doing this. X-Real-IP and X-Forwarded-For are good for when the client is a trusted proxy, but can be easily faked if you don’t whitelist who’s allowed to use those headers. Somebody with IPv6 access could send “X-Real-IP: 127.0.0.1” or something and if the server believes it then you’ll see 127.0.0.1 in logs and depending on what you’re running the user may gain special permissions.

          Also be careful with the opposite problem. If your server doesn’t trust the proxy, it will show the VPS IP in logs, and if you’re running something like fail2ban you’ll end up blocking your VPS and then nobody will be able to connect over IPv4.

      • Matt The Horwood
        link
        fedilink
        English
        37 months ago

        A and AAAA records can have different IPs, the VPS will know it’s the host for your A and to forward AAAA to your home IP