this post was submitted on 29 Jul 2025
29 points (100.0% liked)

technology

23902 readers
236 users here now

On the road to fully automated luxury gay space communism.

Spreading Linux propaganda since 2020

Rules:

founded 5 years ago
MODERATORS
 

Hello comrades! In light of the fucked up state of the UK govt I'm looking at some VPN options to further harden my homelab.

Right now, I have zero VPN coverage for my seedbox/jellyfin server which of course means a major security hole, even if my ISP hasn't shit over me for it yet.

I had a few questions about selfhosting a VPN versus a third party service.

  1. How does a self hosted VPN actually do anything? I was under the impression that VPNs had to be off-site to give the benefits of, say, location spoofing.

  2. Do I need to pay any subscriptions to other services for a self hosted VPN? At least in order to access features such as location spoofing.

  3. We use Cloudflare WARP at work to access internal services. Will a LAN-VPN Fuck this up even if I explicitly avoid spoofing my location to ensure my IT guy doesnt shit a brick?

thanks cumrades!

you are viewing a single comment's thread
view the rest of the comments
[–] PorkrollPosadist@hexbear.net 5 points 1 week ago* (last edited 1 week ago)

These goals won't work well on the same setup. A commercial VPN provider will make you (more) anonymous to third parties like copyright snitches by mixing your traffic with other customers emerging from the same endpoint. A self hosted VPN can be useful for accessing your home network from outside, accessing the Internet from the location of your VPS, or hosting services from behind your ISP's firewall, but does nothing for anonymity. The IP of the endpoint is leased exclusively to you.

A VPN itself is just a means of tunneling traffic from one location (e.g. your home) to another (e.g. some office or data center). You would want two separate VPNs to cover these use cases. A commercial (not self-hosted) one for piracy, and a self-hosted one on a VPS for the homelab to bypass the ISP firewall (and potentially non-pirate web browsing emerging from one specific location outside UK).

Be careful with the routing! Funny and unexpected things can happen when you activate or deavtivate network interfaces. The traffic WILL be sent over the wrong interface (I.e. unencrypted torrents to your home ISP, bank transactions to the "anonymous" torrent VPN) unless there is a firewall preventing it, and IPv6 traffic will not be blocked by rules explicitly written for IPv4 address ranges. :)