I live in a country where wireguard, openvpn and other vpn protocols have been blocked. Tailscale and Cloudflare Tunnels don’t wok either. I do have a public ip and my router supports DMZ and port forwarding. For security concerns I’m not willing to forward ports. Is there any other method to use my VPS to forward traffic to my home server?

17 points

I think your best bet is try to use OpenVPN via TCP over port 80 or 443. You could also try setting up an SSH VPN tunnel.

permalink
report
reply
5 points

That used to work but it doesn’t anymore. Openvpn over cloak still works apparently. I’ll give it a try.

permalink
report
parent
reply
4 points

A ssh tunnel probably is your best option

permalink
report
reply
4 points

I think so as well and it is sad that that the OP has to be in a place where internet is so heavily censored.

permalink
report
parent
reply
-12 points

Using OpenVPN will force you to open ports and do NAT on your local network.

I would suggest to install Tailscale… And you will never use anything else.

Lot me know how it goes!

permalink
report
reply
6 points

Please re-read the original post re: tailscale.

permalink
report
parent
reply
-4 points

Yup, Tailscale is perfect for that…

permalink
report
parent
reply
5 points

Tailscale works on WireGuard. WireGuard is blocked in OP’s nation. Tailscale does not work in his country.

permalink
report
parent
reply
2 points
*

SSH is an obvious thing to try, but I suppose it may get cut off by the same DPI.

Possibly, ShadowSocks or obfs4proxy might be of some help? E.g. you can wrap Wireguard traffic in ShadowSocks (AFAIK it supports UDP).

permalink
report
reply
1 point

SSH still works but I need to learn to set up a persistent , resilient tunnel. Just found this guide in using Wireguard over shadowsocks: https://errande.com/2021/07/obfuscate-wireguard/

permalink
report
parent
reply
6 points

Might I suggest Fast Reverse Proxy ( https://github.com/fatedier/frp )

It’s a great solution if you don’t have a public IP or can’t/don’t want to open any ports.

I found it super easy to setup and configure. I put caddy in front of the server side for mine to ssl offload there. But you could also route everything down the tunnel it makes and use a local reverse proxy to handle SSL offloading

permalink
report
reply

Selfhosted

!selfhosted@lemmy.world

Create post

A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don’t control.

Rules:

  1. Be civil: we’re here to support and learn from one another. Insults won’t be tolerated. Flame wars are frowned upon.

  2. No spam posting.

  3. Posts have to be centered around self-hosting. There are other communities for discussing hardware or home computing. If it’s not obvious why your post topic revolves around selfhosting, please include details to make it clear.

  4. Don’t duplicate the full text of your blog or github here. Just post the link for folks to click.

  5. Submission headline should match the article title (don’t cherry-pick information from the title to fit your agenda).

  6. No trolling.

Resources:

Any issues on the community? Report it using the report flag.

Questions? DM the mods!

Community stats

  • 3.6K

    Monthly active users

  • 3.3K

    Posts

  • 71K

    Comments