mrh, mrh@mander.xyz
Instance: mander.xyz
Joined: 2 years ago
Posts: 1
Comments: 8
GNU/Lisp Enthusiast!
Posts and Comments by mrh, mrh@mander.xyz
Comments by mrh, mrh@mander.xyz
I love ipv6 but I don’t see how it is related to anything here
Yes your description is just right and is the heart of my question. To use your terminology:
Currently: - Away from home: Phone -> VM -> Home Server - At home: Phone -> VM -> Home Server (inefficient!)
Ideally: - Away from home: Phone -> VM -> Home Server - At home: Phone -> Home Server
In the ideal case, I would never have to change anything about the wireguard config/status on the Phone, nor would I have to change the domain name used to reach the resource on the Home Server.
Oh hm I didn’t think about your last point, maybe it’s not really an issue at all. I think I’m not 100% on how the wireguard networking works.
Suppose I tunnel all of my traffic through wireguard on the remote server. Say that while I am home, I request foo.local, which on the remote server DNS maps to a wireguard address corresponding to my home machine. The remote will return to me the wireguard address corresponding to the home machine, and then I will try and go to that wireguard address. Will the home router recognize that that wireguard address is local and not send it out to the remote server?
Yes that would work, but it feels a bit cumbersome to have 2 fqdns per service, which I would have to switch between using depending on on whether I’m local or not.
Right but I want to be connected to wireguard always, I just want the DNS/routing to be different based on home vs foreign network.
And so when away do you just directly connect to the external IP and do port forwarding?
So you have a public DNS record pointing to your home IP?
Häagen-Dazs
“Häagen-Dazs” is an invented pseudo-Scandinavian phrase coined by the American Reuben Mattus, in a quest for a brand name that he claimed was Danish-sounding. However, the company’s pronunciation of the name ignores the letters “ä” and “s”, and letters like “ä” or digraphs like “zs” do not exist in Danish.
His daughter Doris Hurley reported in the 1996 PBS documentary An Ice Cream Show that her father sat at the kitchen table for hours saying nonsensical words until he came up with a combination he liked.
hyper2
I love ipv6 but I don’t see how it is related to anything here
Yes your description is just right and is the heart of my question. To use your terminology:
Currently: - Away from home: Phone -> VM -> Home Server - At home: Phone -> VM -> Home Server (inefficient!)
Ideally: - Away from home: Phone -> VM -> Home Server - At home: Phone -> Home Server
In the ideal case, I would never have to change anything about the wireguard config/status on the Phone, nor would I have to change the domain name used to reach the resource on the Home Server.
Oh hm I didn’t think about your last point, maybe it’s not really an issue at all. I think I’m not 100% on how the wireguard networking works.
Suppose I tunnel all of my traffic through wireguard on the remote server. Say that while I am home, I request
foo.local, which on the remote server DNS maps to a wireguard address corresponding to my home machine. The remote will return to me the wireguard address corresponding to the home machine, and then I will try and go to that wireguard address. Will the home router recognize that that wireguard address is local and not send it out to the remote server?Yes that would work, but it feels a bit cumbersome to have 2 fqdns per service, which I would have to switch between using depending on on whether I’m local or not.
Right but I want to be connected to wireguard always, I just want the DNS/routing to be different based on home vs foreign network.
And so when away do you just directly connect to the external IP and do port forwarding?
So you have a public DNS record pointing to your home IP?
How to Use Local IP for Services when at Home?
So I have some services and wireguard running locally on a “home” network. I also have wireguard, a DNS resolver, and a reverse proxy set up on a remote server. Since I don’t want to expose the home IP to the public, to access my services I connect to the VPN on the remote, which then forwards my request home. But this means that when I’m at home, connecting to my local services requires going out to the remote. Is there some way to have the traffic go over the switch when at home, but go over wireguard when away, without having to manually switch the VPN on/off?
Häagen-Dazs