M
M
Mnemonic02021-03-19 14:24:01
openvpn
Mnemonic0, 2021-03-19 14:24:01

VPN over a server in the cloud?

In the current realities, there are more and more questions about data privacy. Therefore, I want to protect the output of home devices to the Internet.

Due to the fact that we periodically try to pinch VPNs of one type or another, I don’t want to be tied to one vendor, but I also don’t want to fence a monstrous design.

What first of all suggests itself - mikrotik at home, pfsense / ubuntu (wireguard) in the cloud - in fact, it is not very difficult to set up. But there are several questions:
1. Setting up a default gateway on a remote network
2. Publishing internal resources to the outside (cascade of nginx servers?)
3. Routing all this happiness, but I think it needs to be solved together with the first question.

Obviously, options using VPN over SSL, by analogy with OpenVpn, are not particularly acceptable, but I would like some option with the ability to obfuscate traffic.

Answer the question

In order to leave comments, you need to log in

3 answer(s)
V
Valery, 2021-03-19
@heroul

perhaps amnesia will solve your problems in a few clicks

B
BasiC2k, 2021-03-19
@BasiC2k

1. Set up a VPN server on a remote hosting. There are many instructions on the net, for example .
2. Generate and export keys to your devices, install VPN clients on devices.
3. Use a completely closed channel.
It is possible to raise the VPN client immediately on the home router. In this case, you do not need to run the program on the device every time.

M
Mnemonic0, 2021-03-22
@Mnemonic0

All sorts of nonsense, ala set up a server and man for setting up - I myself know / can / practice.
To make it clearer:

  • Have Pfsense in the cloud
  • Site to Site from home with a gateway to the cloud for home devices
  • L2TP IPsec on phones

Pros - good speed. Cons - easy to block.
I would like some solution with the ability to disguise VPN traffic as something else. Again - now my Mikrotik is behind the provider's router, which ipsec loves so-so and I'm ready to change equipment (you can take a board with 4 gigabit ports on which to put Ubuntu and pick anything).
Valery looked at Amnesia - while the product is rather weak, it’s simply not convenient for me to use it on every device from home, since there are resources that are published outside - it’s easier to use Site to Site, but I still haven’t found how to implement it on Amnesia.

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question