Recent Discussions

Behind CGNAT + Tailscale + TCPSHIELD?

Unanswered
Champagne D’Argent posted this in #questions
Messages51 messages
Views0 views
Champagne D’ArgentOP
Hello everyone,

I'm planning to ship my extra computer to the Philippines, and after doing some research it seems like public IPv4 is only available for business clients on ALL internet providers.

I want to host a few minecraft servers on the computer I am shipping, as right now I'm in Canada and most of my players are from the Philippines.

What is the best way forward?

Do I need to rent a vps as an exit node and do portforwarding there? Or can I use TCP shield behind my cgnat server?

Thanks!
Champagne D’ArgentOP
Yes, sorry
being behind cgnat is basically a nono meaning you wont be able to host it. Getting a cheap mc plan from #service-providers would do you easier then finding an alternate. If youa re willing to pay money on it
Champagne D’ArgentOP
Yes, I understand. I am planning to tunnel it using tailscale or pangolin on a vps I rent so I can do port forwarding
@Ruddy Ground-Dove this seems like ur knowledge area
Champagne D’ArgentOP
I'm just looking for better ways, if any. I also have a pterodactyl panel and I want to be able to access sftp through it because I heard you can't use sftp when tunneled?
Champagne D’ArgentOP
Or ovhcloud vps and use their anti ddos and save on tcp shield?
Champagne D’ArgentOP
I should add I plan to get a 400mbps up and down plan in the Philippines just for this.
Masai Lion
Oof
Kinda slow
@Masai Lion Kinda slow
Champagne D’ArgentOP
really? dang
Ruddy Ground-Dove
You want an exit node if you can’t do port forwarding.
@Ruddy Ground-Dove You want an exit node if you can’t do port forwarding.
Champagne D’ArgentOP
yes, will be using tailscale probably or pangolin (but i'd have to remove caddy and use traefik)
What is the best way forward?

Do I need to rent a vps as an exit node and do portforwarding there? Or can I use TCP shield behind my cgnat server?
Ruddy Ground-Dove
Already told you, exit node.
TCPShield still needs port forwarding, it's just a network external proxy.
Personally I wouldn't use Pangolin or Tailscale, I'd either use GRE or Wireguard since both are fairly low overhead, you don't need encryption for this.
But I mean if you wanna full send Pangolin which is overkill as fuck then you can, it's a good idea if you can be fucked doing this properly.
Champagne D’ArgentOP
Thanks a lot man, how about 400 mbps upload and download speed? Since I'm already going to use an exit node AND tcpshield proxy how will it go?
Loading...