Thanks for the great sarcasm mate
operator
Using Pi's to run services in my homelab which I want to keep separate from my server (to have some sort of failover in case the server goes down). Status/Monitoring, VPN server and so on
That - good sir - is a very valid argument
Saved me about 15 mins thank you kind sir
Looks smooth, I am running Homer (different to Homerr or others). Super easy to configure in yml and looks clean. No fancy features as weather however… or maybe haven’t found it ^^
I do think I’ll give Homarr another try after looking at yours
Unfortunately not at the moment, as all is kinda fiddled and setup manually, but I’m redoing my home lab in a couple of weeks. Send me a message and I’ll send you the docker image or script!
But basically I did the following:
- enable ipv4 forwarding
- configure and start VPN tunnel
- set the default route to the tunnel
- set the gw for reaching the remote vpn server to the local gw
- sets routes for the local network to the local gw
If your vpn goes down, the default route shall still point to the remote gw, but as it isn’t there you also have a kill switch. Voila!
I am looking into gluetun but haven’t tried it yet.
Edit: this doesn’t protect you from someone snooping the traffic inside your local net, but protects it starting from the point where it leaves the local vpngw. The traffic is unencrypted between that and your client.
That’s becoming interesting once I’m setting up a slaves for failover & local proximity ^^ looking forward to deep diving into it
Appreciate it!
That be amazing! I am currently not using anything (took down my homelab a while back) and planning on completely starting over fresh now.
I am most likely going with unbound! So if you could, that be great!
Thanks! That was really insightful. I guess I'll give it a try some day, for now everything runs in ipv4 and that runs well haha!
Apologies accepted, seems like I missed something:)