logoalt Hacker News

kevin_thibedeautoday at 3:38 AM2 repliesview on HN

A public IP and DDNS can be impossible behind CGNAT. A VPN link to a VPS eliminates that problem.


Replies

digiowntoday at 3:51 AM

The VPS (using wg-easy or similar solutions) will be able to decrypt traffic as it has all the keys. I think most people self-hosting are not fine with big cloud eavesdropping on their data.

Tailscale really is superior here if you use tailnet lock. Everything always stays encrypted, and fails over to their encrypted relays if direct connection is not possible for various reasons.

hamandcheesetoday at 4:15 AM

When I said "you just need a single public IP" I figured it was clear that I wasn't claiming this works for people who don't have a public IP.