this post was submitted on 10 Jul 2023
9 points (90.9% liked)

Selfhosted

40201 readers
914 users here now

A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.

Rules:

  1. Be civil: we're here to support and learn from one another. Insults won't be tolerated. Flame wars are frowned upon.

  2. No spam posting.

  3. Posts have to be centered around self-hosting. There are other communities for discussing hardware or home computing. If it's not obvious why your post topic revolves around selfhosting, please include details to make it clear.

  4. Don't duplicate the full text of your blog or github here. Just post the link for folks to click.

  5. Submission headline should match the article title (don’t cherry-pick information from the title to fit your agenda).

  6. No trolling.

Resources:

Any issues on the community? Report it using the report flag.

Questions? DM the mods!

founded 1 year ago
MODERATORS
 

Hi guys! IN a bit of a rush, I installed a server on a place where I knew I'd have trouble reaching, as their router is behind CGNAT. I want now to start installing some VMs etc. At the moment all I have is a VM running Windows running Teamviewer for remote access (I know, I know). I have most of my services hosted on a local home server that runs rather well and has plenty of bandwidth. Among these, there's a PiVPN running on my home server that works rather well. Is there a way I could make that remote CGNAT server connect to my VPN and be reachable/pingable/show webpages locally?

Thanks!

top 13 comments
sorted by: hot top controversial new old
[–] chiisana@lemmy.chiisana.net 5 points 1 year ago (2 children)

Cloudflare tunnels can punch a hole through that. Get a reverse proxy setup for your apps and VMs, then create a cloudflare tunnel and you’re off to the races.

[–] ibroughtashrubbery@lemmy.ml 1 points 1 year ago (1 children)

Sorry, but I'm a bit lost with these specifics. I currently have a reverse proxy (nginx) publishing some of my apps running locally on my home server. Where should I put the reverse proxy? On the remote unreachable server, or? And how would the tunnel go?

[–] chiisana@lemmy.chiisana.net 2 points 1 year ago

On the server that’s behind CGNAT, install Cloudflare tunnel. The tunnel will create an out going connection to Cloudflare, with an open socket; when you try to hit your specified subdomain, Cloudflare will receive your request, send it through the tunnel, and thus allow you to connect to your service.

Cloudflare tunnels would be the easiest/cheapest way to go about it. But always be mindful that if you violate their terms and conditions, you could find yourself with a high bandwidth bill.

[–] TwinTurbo@lemmy.world 5 points 1 year ago (1 children)

Yes, you can connect the device behind CGNAT to your existing VPN as a client. Then, from inside the VPN, you would use the its virtual address to connect to it. You can use a systemd service or similar to have the VPN connect at boot.

[–] ibroughtashrubbery@lemmy.ml 2 points 1 year ago (1 children)

Oh wow, I'll have to try this! Can then the virtual IPs be pinged in Wireguard VPNs? (I mean, PiVPN is simplifying Wireguard anyway).

[–] TwinTurbo@lemmy.world 3 points 1 year ago (1 children)

Yes. All devices connected to the VPN will have a private IP inside the virtual network. You can use these to communicate as though they were public IPs, except that they can't be used from outside the VPN.

[–] ibroughtashrubbery@lemmy.ml 1 points 1 year ago (1 children)

That would be my problem right? In my understanding, if I get some remote device to dial into my home network through a PiVPN running in my home network, i believe the remote devices can access and ping home devices, but no home device other than the PiVPN can ping them back? Right?

[–] TwinTurbo@lemmy.world 1 points 1 year ago

You would need to set up routes on these other devices to tell them that VPN devices can be reached through the Pi. It’s possible, but I’ve never done it myself, so I don’t have any useful pointers.

[–] Leafimo@feddit.de 4 points 1 year ago (2 children)

you could use tailscale for that, it should be able to punch through the CGNAT

[–] Funwayguy@lemmy.world 3 points 1 year ago

As someone else who uses Tailscale behind a CGNAT, this indeed works. I use it for accessing my home server from the office for a year now. You can't quite self host anything public facing but anything on your tailnet can talk to it just fine.

Theoretically a VPS proxy into the server over the VPN could work for devices not capable of running tailscale but your mileage may vary.

WireGuard as well.

[–] 2xsaiko@discuss.tchncs.de 2 points 1 year ago

Do you have IPv6? That usually isn’t behind any kind of NAT and you can just let machines through the firewall.