Hey is there any alternatives to CloudFlare reverse proxies? I want to hide my server IP but not share everything with CF...

all 50 comments

sorted by: hot top controversial new old
[–] 22 points 2 years ago (12 children)

What is your objective for ‘hide server IP’?

Privacy to disconnect your identity from the service? There is no solution to this. Full stop. Even with Tor, the state backed acronym entities will figure it out if you get on their radar.

If your objective is to keep your service online, you’re going to be hard pressed to find cost effective alternatives… Commercial solutions are expensive, like, “if you have to ask about the price, you can’t afford it” expensive.

Alternatively, you can try to roll your own by having many many proxy servers yourself… but if you’ve got a target on your back, you’ll never have enough instances; DDOS-as-a-Service is much cheaper than the amount of reverse proxies required to keep your service online.

There’s probably other use cases, but chances are, you’d still be hard pressed to find a solution that’s cost effective.

  • source
  • hideshow 12 child comments
  • load more comments (12 replies)
    [–] 20 points 2 years ago*

    Sucuri?

    Akamai?

    Kinda depends on what's going on, price point, etc. is this for DDOS purposes?

    You do not need a CDN, but you have users. So, is this for like, a Plex server, serving friends in a similar geographic region?

    What's the use case? That will greatly help us answer.

  • source
  • [+] 8 points 2 years ago* (last edited 2 years ago) (2 children)
  • [–] 1 point 2 years ago (3 children)

    I was looking into Tailscale, but it got me a little worried. I'm not very knowledgeable, so I hope someone can correct me

    They don't allow ssh, so you have to give your keys over them and they manage your ssh connection? That seems idiotic. Surely that can't be correct?

    I'm my use case, I was wanting to rsync to an off-site Synology from a Linux box. Synology also doesn't allow ssh over their VPN service - frustrating.

  • source
  • parent
  • hideshow 6 child comments
  • [–] 3 points 2 years ago*

    Pretty much the only thing I use Tailscale for is remotely SSHing from my phone to my home NAS, and they definitely don’t manage my keys. They do have a “Tailscale SSH” feature I don’t use…

  • source
  • parent
  • [–] 1 point 2 years ago

    You can always use something like SSHwifty It retains your logins through your browser's session data and never on your server, but it will allow you to remote into your local system from anywhere on the WWW if you desire to do so. With Tailscale, once you are connected into your Tailnet, you can pretty much SSH into any of your devices as long as the subnet sharing flag is turned on I believe. I've never had any issues with mine not allowing any SSH connections.

  • source
  • parent
  • [–] 8 points 2 years ago* (last edited 2 years ago) (4 children)

    @foremanguy92_@lemmy.ml ,

    Step 1: get a cheap VPS, or even a free one (https://www.oracle.com/cloud/free/)

    Step 2: If you've a static IP at home great, if you don't get a dynamic DNS from https://freedns.afraid.org/ or https://www.duckdns.org/

    Step 3: Install nginx on the VPS and configure it as reverse proxy to your home address. Something like this:

    server {
        listen 80;
        server_name example.org; # your real domain name you want people to use to access your website
        location / {
            proxy_pass http://home-dynamic-dns.freeprovider... # replace with your home server IP or Dynamic DNS.
            proxy_set_header Host $host;
            proxy_set_header X-Real-IP $remote_addr;
            proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
            proxy_redirect off;
        }
    }
    

    Step 4: Point your A record of example.org to your VPS.

    Step 5: there's a potential security issue with this option: https://nginx.org/en/docs/http/ngx_http_realip_module.html#set_real_ip_from and to get around this you can do the following on the home server nginx config:

    http {
    (...)
            real_ip_header    X-Real-IP;
            set_real_ip_from  x.x.x.x; # Replace with the VPS IP address.
    }
    

    This will make sure only the VPS is allowed to override the real IP of the client.

    Step 6: Once your setup works you may increase your security by using SSL / disabling plain HTTP setup letsencrypt in both servers to get valid SSL certificates for real domain and the dynamic DNS one.

    Proceed to disable plain text / HTTP traffic. To do this simply remove the entire server { listen 80 section on both servers. You should replace them with server { listen 443 ssl; so it listens only for HTTPs traffic.

    Step 7: set your home router to allow incoming traffic in port 443 and forward it into the home server;

    Step 8: set the home server's firewall to only accept traffic coming from outside the LAN subnet on port 443 and if it comes from the VPS IP. Drop everything else.


    Another alternative to this it to setup a Wireguard tunnel between your home server and the VPS and have the reverse proxy send the traffic through that tunnel (change proxy_pass to the IP of the home server inside the tunnel like proxy_pass http://10.0.0.2). This has two advantages: 1) you don't need to setup SSL at your home server as all the traffic will flow encrypted over the tunnel and 2) will not require to open a local port for incoming traffic on the home network... however it also has two drawbacks: you'll need a better VPS because WG requires extra processing power and 2) your home server will have to keep the tunnel connected and working however it will fail. Frankly I wouldn't bother to setup the tunnel as your home server will only accept traffic from the VPS IP so you won't gain much there in terms of security.

  • source
  • hideshow 4 child comments
  • load more comments (4 replies)
    [–] 6 points 2 years ago (2 children)

    Set up a VPS. Create a VPN tunnel from you local network to the VPS. Use the VPS as the edge router by opening ports on the VPS firewall and routing incoming traffic on those ports through the VPN tunnel to servers on your local network.

    I used to do this to get around CGNAT. I ran RouterOS in a Digital Ocean droplet and setting up a wire guard tunnel between it and my local Mikrotik router.

    It will obscure your local WAN IP and give you a static IP but that's about the only benefit. And you have to be pretty network savvy to configure it correctly.

    It does not make you immune to DDoS attacks and is honestly more headache to maintain (albeit just a small headache).

  • source
  • hideshow 4 child comments
  • [–] 1 point 2 years ago (1 child)

    Not heard of RouterOS before ... I didn't realise jad released firmware that would run in a normal VM... don't suppose you have anything to compare it to pfSense?

  • source
  • parent
  • hideshow 2 child comments
  • [–] 3 points 2 years ago* (last edited 2 years ago) (1 child)

    They do maintain an x86 build. I haven't used pfSense but I have used OpnSense so that's that closest thing I have to compare it to. I think the upside and downside to RouterOS/Mikrotik is the same thing: it allows very granular control over almost everything. Maybe to a fault. It's probably overkill for most home networks.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 5 points 2 years ago (1 child)

    Depends on why you want to hide your server ip, what's your use case? Is it to protect against DDOS?

    Cloudflare is evil, but is there any other party you would trust to share everything with?

  • source
  • hideshow 2 child comments
  • [–] [S] 2 points 2 years ago* (1 child)

    Do you something like a vps would be more secure? Paying some dollars a month

  • source
  • parent
  • hideshow 2 child comments
  • [–] 2 points 2 years ago (1 child)

    I like that idea.

    I'd suggest OVH or Digital Ocean.

    If you think a DDoS attack is possible I'd suggest azure for that.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 2 points 2 years ago* (1 child)

    I'd probably use a VPS myself.

    I seem to recall db0 saying that lemmy.dbzer0.com is behind some sort of reverse proxy. I assume that they're in the same boat as OP.

    looks

    $ host -t a lemmy.dbzer0.com
    lemmy.dbzer0.com has address 51.77.203.116
    $ whois 51.77.203.116
    [snip]
    role:           OVH Technical Contact
    address:        OVH SAS
    address:        2 rue Kellermann
    address:        59100 Roubaix
    address:        France
    admin-c:        OK217-RIPE
    tech-c:         GM84-RIPE
    tech-c:         SL10162-RIPE
    nic-hdl:        OTC2-RIPE
    abuse-mailbox:  abuse@ovh.net
    mnt-by:         OVH-MNT
    created:        2004-01-28T17:42:29Z
    last-modified:  2014-09-05T10:47:15Z
    source:         RIPE # Filtered
    
    % Information related to '51.77.0.0/16AS16276'
    
    route:          51.77.0.0/16
    origin:         AS16276
    mnt-by:         OVH-MNT
    created:        2018-03-07T09:24:45Z
    last-modified:  2018-03-07T09:24:45Z
    source:         RIPE
    $
    

    I don't know if that's a VPS, but looks like they're using OVH.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 3 points 2 years ago (1 child)

    a reverse proxy these days is pretty much just a requirement of any dynamic service. they often run on the same host as the software

  • source
  • parent
  • hideshow 2 child comments
  • [–] 2 points 2 years ago (1 child)

    Aight, but db0 had something about it obscuring the server location, IIRC.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 1 point 2 years ago

    it’s possible, but that would seem… odd… for such a large and tech-savvy instance. there’s a lot of reasons why this isn’t a good idea, and very few technical reasons why it is

    my guess is that it’s less about obscuring server location for privacy reasons as is the implications in this thread, and more about handling changes cleanly or something like that - in which case, sure it obscures the server location but more that it makes the server “location” (or hardware, etc) irrelevant and fungible

  • source
  • parent
  • [–] 4 points 2 years ago (1 child)

    Do you want something that also has CDN like Cloudflare? Bunny.net is good, but way more expensive than a cheap VPS if you use a lot of traffic.

  • source
  • hideshow 2 child comments
  • [–] 3 points 2 years ago (1 child)
  • [–] [S] 2 points 2 years ago (1 child)

    So I need to have always the same exit node, need to connect to the server via an other IP and only this server know my ip

  • source
  • parent
  • hideshow 2 child comments
  • [–] 4 points 2 years ago (1 child)

    AFAIK tor websites (onion service) doesn't require exit node, and no one knows your IP unless you are unlucky enough all nodes you connected are controlled by same entity.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 3 points 2 years ago

    If for personal access only, ZeroTier might solve your use case.

  • source
  • [–] 3 points 2 years ago

    VPS with Wireguard

  • source
  • [–] 2 points 2 years ago

    Perhaps NetBird, ZeroTier or Tailscale? If you want to make a service available publicly, check out Tailscale Funnel.

  • source
  • [–] [B] 2 points 2 years ago* (last edited 2 years ago)

    Acronyms, initialisms, abbreviations, contractions, and other phrases which expand to something larger, that I've seen in this thread:

    Fewer Letters More Letters
    CF CloudFlare
    CGNAT Carrier-Grade NAT
    DNS Domain Name Service/System
    HTTP Hypertext Transfer Protocol, the Web
    IP Internet Protocol
    NAS Network-Attached Storage
    NAT Network Address Translation
    Plex Brand of media server package
    SSH Secure Shell for remote terminal access
    SSL Secure Sockets Layer, for transparent encryption
    VPN Virtual Private Network
    VPS Virtual Private Server (opposed to shared hosting)
    nginx Popular HTTP server

    12 acronyms in this thread; the most compressed thread commented on today has 15 acronyms.

    [Thread #803 for this sub, first seen 15th Jun 2024, 10:35] [FAQ] [Full list] [Contact] [Source code]

  • source
  • [–] 2 points 2 years ago

    Very confused by the answers here. Anyway, check this list: https://github.com/anderspitman/awesome-tunneling

    I personally used frp many years ago and it worked great.

  • source
  • [–] 1 point 2 years ago

    I used boringproxy for years and I recomend you

  • source