Skip to content

Six months on a NAT IPv4-only VPS

General Discussion by PacketpunkUma 28 replies 3.5K views
3 #1

Six months on a NAT VPS! Here is the real talk!

I got a €4/month plan from Hetzner with shared IPv4 and 20 forwarded ports! Expected pain! Got surprisingly little!

The good:
- wireguard out to my dedibox at Leaseweb works flawlessly! No port forwarding needed for the tunnel!
- selfhosted apps behind caddy reverse proxy on the shared IP! Lets Encrypt via DNS challenge! No problem!
- 2TB bandwidth for price of a coffee!

The bad:
- banking API blocked the entire CGNAT range! Could not pull transaction data for my invoice tool!
- had to spin up a €30/month forwarded port on Leaseweb just to proxy that one API call!
- so now I pay €34/month effectively! Still cheap but the principle!

Verdict: NAT is fine until corporate firewalls decide your IP is criminal! Then you pay the tax!

#2

Oh no banking api is basically the worst actually (´・ω・`)

I had same problem with my nat vps from InterServer my payment processor basically blocked me until I moved to proper ip now I pay more but sleep better actually

Kaomoji of shared ip sadness (´;д;`)

instant noodles, instant deploys
#3

@PacketpunkUma that's a solid workaround with the forwarded port! I ran similar setup on Vultr nat plans for about 8 months before I needed proper ip for mail delivery.

Sent ticket yesterday to Hetzner asking if they offer dedicated ip add-on - they said "not currently but on roadmap" so maybe soon!

For banking apis specifically, I made test order with KnownHost proxy service and it worked fine, but $2/month is basically same price. Cheers!

swimming upstream since 2019 🐟
#4

NAT VPS SECURITY NIGHTMARE.

SHARED IP MEANS SHARED REPUTATION. WHAT IF PREVIOUS TENANT WAS RUNNING SPAM OR C2? YOUR WIREGUARD TUNNEL IS NOW COMPROMISED VECTOR.

RECOMMENDATIONS:
- FAIL2BAN ON EVERY PORT FORWARDED
- FIREWALL DROP ALL NOT EXPLICITLY ALLOWED
- LOG ALL CONNECTIONS TO LEASEWEB ENDPOINT
- CONSIDER IF €30/MONTH SAVINGS WORTH THE RISK

ALSO BANKING API OVER TUNNEL TO CHEAP VPS? EXFILTRATION RISK!

airgapped, encrypted, faraday'd, still worried
#5

Shared reputation thing is overstated for wireguard tunnel though

42U and still growing
#6

Which 20 ports did you actually need

#7
nate_pad said:
Which 20 ports did you actually need

Honestly? 6 in active use. Wireguard UDP, SSH, Caddy 80/443, plus two custom app ports. Rest are spares I rotate through when testing. The 20 limit sounds tight but for a personal stack it is generous.

9 #8

This is really helpful, been looking at Hetzner for my first proper VPS. The NAT plans are tempting but I need to run a small mail server for a club, guessing that is a no-go?

#9
olespete said:
SHARED IP MEANS SHARED REPUTATION

Sure but Wireguard keys are ephemeral and the tunnel endpoint is your dedibox IP at Leaseweb (https://www.leaseweb.com), not the shared one. The NAT IP never appears in any handshake your peers validate. Different threat model than SMTP.

42U and still growing
4 #10
marcus_qc said:
Wireguard keys are ephemeral

KEYS ROTATE, REPUTATION DOES NOT. IF LEASEWEB IP GETS FLAGGED, TUNNEL IS USELESS. MY POINT STANDS: CHEAP INFRASTRUCTURE STACKS CHEAP RISKS.

airgapped, encrypted, faraday'd, still worried

Post a reply

You need an account to reply. Log in or register to join the conversation.

Post reply Preview Save draft