Good FOSS software and reliable service providers? Etc.

      • Andres Salomon@social.ridetrans.it
        link
        fedilink
        arrow-up
        3
        ·
        16 hours ago

        @chronicledmonocle @sugar_in_your_tea This is why I love yggdrasil. Thanks to having a VPS running it that all of my hosts globally can connect to, I can just use IPv6 for everything and reverse proxy using those IPv6 addresses where I need to. Once hosts are connected and on my private yggdrasil network, I stop caring about CGNAT or IPv4 at all other than to maybe create public IPv4 access to a service.

      • sugar_in_your_tea@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        1
        ·
        16 hours ago

        IPv6 doesn’t help anything if you’re behind CGNAT, you can have internal-only IPv6. There are good reasons to not have every household directly accessible to the outside world, so I’m sympathetic to that, but they also seem to love charging extra for it.

        • chronicledmonocle@lemmy.world
          link
          fedilink
          English
          arrow-up
          1
          ·
          edit-2
          13 hours ago

          CGNAT only applies to IPv4. You cannot NAT IPv6 effectively. It’s not designed to be NATed. While there IS provisions for private IPv6 addressing, nobody actually does it because it’s pointless.

            • chronicledmonocle@lemmy.world
              link
              fedilink
              English
              arrow-up
              1
              ·
              3 minutes ago

              Network Prefix Translation isn’t the same thing. That’s used for things like MultiWAN so that your IPv6 subnet from another WAN during a failover event can still communicate by chopping off the first half and replacing the subnet with the one from the secondary WAN. It is not NAT like in IPv4 and doesn’t have all of the pitfalls and gotchas. You still have direct communications without the need for things like port forwarding or 1:1 NAT translations.

              I’m a Network Engineer of over a decade and a half. I live and breath this shit. Lol.

    • Shimitar@feddit.it
      link
      fedilink
      English
      arrow-up
      2
      ·
      1 day ago

      Yeah, there are workarounds… And who knows, maybe its just safer than public ip… But definitely require some external fixture.

      • kchr@lemmy.sdf.org
        link
        fedilink
        English
        arrow-up
        3
        ·
        1 day ago

        I guess you already know about the options, but for others:

        Find the cheapest VPS out there and have a Wireguard tunnel between it and your home network. Run ddclient or similar on the VPS in case the public IP changes.

        • sugar_in_your_tea@sh.itjust.works
          link
          fedilink
          English
          arrow-up
          1
          ·
          16 hours ago

          Yup, that’s what I did. I even have my TLS servers running on my LAN as well, so once my ISP no longer puts me behind CGNAT, I just need to change my DNS settings and set up some port forwards on my router.