• 1 Post
  • 20 Comments
Joined 2 years ago
cake
Cake day: June 20th, 2023

help-circle





  • No i would only have one tunnel set up with an allowed range that was my local subnet at home (192.168.20.0/24) on the wireguard server you can set a dns for those connections and also in the client interface so when the laptop tried to ask the dns for an address it would talk to my home dns.

    If the ip it was given was an external ip, outside of my LAN then the laptop just went though local wifi or whatever outside of the vpn tunnel to find the resource, but if it was inside the home range it pulled the connection straight from home via the tunnel. The home dns had dnd records for all my local services pointing to my reverse proxy so if it got a request for lubelogger.local it just pointed the browser to the ip of the reverse proxy which knew to send a request for lubelogger.local to the correct ip:port on the lan.

    It meant I could use domain names safely without having them exposed to the world.

    Technitium let’s you do domain replication to as many other instance as you want so I always planned to set up a second dns at my mum’s house in case mine went down but never go around to it.

    Implementation was a wireguard server running on an old rpi1 Technitium running on a seperate machine Told the wireguard server to use technitium as it’s dns Wireguard on device with an allowed range of my local subnet. Add a dns record for any service you want accessible on technitium, use a tld that no one else uses online. I used.local, you’re supposed to use.apra but I didn’t like the look of it. Add your domain entry to your reverse proxy as normal.

    Note the more I think about this i may have just gotten lucky because I had already visited those domains at home so when I was off site and typed in the domain the laptops list of hosts knew to try the local ip and it was funnelled straight though the tunnel.

    I had some persistent network instability during a busy time and had to strip things back so don’t have this set up anymore. After exams I’ll try it again.

    Re the dhcp. It may be common now days. I use quite an old ISP supplied router so when it was handling dhcp I could only rarely use a devices host name to address it on my local network. Technitium never had that problem


  • Technitium is a fully fledged authoritative dns, i haven’t used pinhole for a long time but the best part for me was setting up a zone for just local domain names use the.local tld. I then told my wireguard server to use the technitium instance as it’s dns. Then I told my phone and laptop to send any ips from my local subnet though the wireguard tunnel. That meant that I could access these local resources anywhere via the tunnel but could use their domains instead of ip addresses. Traffic outside those up ranges just went to the internet like normal.

    Also the dhcp server on technitium can be set to automatically generate and propogate a domain name for any device that connects via dhcp so I could use them in place of ip addresses when I wanted to address the device.









  • Either you are splitting hairs or do not understand how precarious our way of life is.

    Running out of food, water or fuel is not some hypothetical future bad thing. It happens all around the world, sometimes even in western countries.

    In Australia we had a fire at one of the gas processing plants in the 90’s and the whole state was without gas (actual Liquid natural gas, for cooking and heating) for almost a month, back then literally everything was run on gas. hot water, ducted heating, ovens, many cars because it was so cheap and plentiful). It seems ridiculous considering we are one of the biggest producers in the world.

    You think you are tacking ‘real’ issues with your servers, but to the average user you seem just as crazy as a guy with a basement full of beans and piss jugs, screaming about the government is watching us constantly.

    But now we know that they are watching, and pushing people towards specific ideas using social media and many other things we though were just crazy talk.

    I’d have a bit more sympathy for the preppers if I was you.