Hello everyone, I would need some advice on my setup.

I had an ISP with basic DSL 60/20Mbps and I was hosting my services at home with SWAG as a main proxy, opening the ports. I ordered 2 days ago a plan with a new ISP for a 1Gbps line, that offered port forwarding as well. The installation was done today and it turns out they retired the port forwarding on my offer yesterday.

I can see potentially 3 choices:

  1. stay with the old ISP and the slow-ish line. My main issue was the uplink speed that made off-site backup a pain
  2. go with the new ISP but order the higher speed plan that is £25/month more expensive, and without a proper guarantee that they will keep offering the port forwarding
  3. use the non-port forwarding option, but rent a small VPS that would act as a front-end (through zerotier/tailscale/direct wireguard), paying a small latency cost when accessing remotely.

I am not fully sure about the pros and cons of the different ways on the last option. I would be kin on keeping my home server fully capable, the point of me self-hosting being to cope with temporary disconnection at home. But then you can either have an IP table routing in the VPS to forward everything on the used port, or have another nginx proxy there to redirect everything. And I am not fully sure VPS providers are generally OK with this kind of use.

Has anyone got a similar setup to option 3 and would have some advices?

Edit 1:

I got a small VPS (not the cheapest one yet) and setup a wireguard tunnel following this principle and it seems to be working so far. I’ll monitor a bit the situation as I have 14 days to cancel my plan. I’ll also see how it works for gitea running in docker in the NAT and ssh forwarding, I suspect this will be a fun endeavour.

I decided to avoid using cloudflare tunnel. And I am avoiding using a nginx proxy at the moment as I would need to ensure the certificates are properly synced between the two (or maybe letsencrypt allows you to have two certificates for the same domain?)

  • richneptune@lemmy.fmhy.ml
    link
    fedilink
    arrow-up
    1
    ·
    1 year ago

    When you say “no port forwarding”, do you mean you aren’t given a public routable IP address and you’re behind Carrier Grade NAT? Does your router get an IP address starting with 100 or 10?

    If so just request a public IP, it might cost you extra but it’s worth it, that should open up the port forwarding option on your router.

    I imagine you’re with a new altnet provider in the UK, is it LilaConnect by any chance?