Greetings,

my current ISP refuses to provide me a static IP and they also blocks incoming connection to my ipv6 so I can’t host services on just ipv6 too. I will be changing my ISP when the plan expires.

without public IP I can host my own IRC bouncer but I would like to know what else can I self host? Thanks in advance!

  • Petter1@lemm.ee
    link
    fedilink
    English
    arrow-up
    11
    ·
    6 days ago

    You can self host anything like this, all you need is buying a domain and set something up like DynDNS which updates the entry of the domain with your new IPv4 as soon as it changes.

    I would recommend to not open your services to public, but set up a wireguard (or other VPN) endpoint in your home, which you then use to access all your services.

    I think, an alternative to that would be some servicees from tailscale or cloudflare, I suppose

  • StaticFlow@feddit.uk
    link
    fedilink
    English
    arrow-up
    21
    ·
    7 days ago

    Self host all your stuff and use tailscale if you just want to provide private services to yourself

  • ikidd@lemmy.world
    link
    fedilink
    English
    arrow-up
    15
    ·
    edit-2
    7 days ago

    Put everything behind Tailscale or another VPN and use it that way from outside devices. There should be very little need to have a public IP, and if there’s something that has to be exposed, use ngrok, cloudflared or Tailscale Funnel.

  • Voroxpete@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    12
    ·
    7 days ago

    I just use a DDNS updater. That’s honestly good enough for most purposes.

    Alternatively, you could use a service like Zerotier, Tailscale or Netbird to create a virtual private LAN connection to a free Oracle VPS, then route the traffic from the VPN to your home network.

  • Shimitar@downonthestreet.eu
    link
    fedilink
    English
    arrow-up
    15
    arrow-down
    1
    ·
    7 days ago

    Rent a VPN, setup a wire guard tunnel and fuck your ISP!

    Anyway having a real public IP on a residential block is basically impossible anywhere but in the USA, I guess.

  • _cryptagion [he/him]@lemmy.dbzer0.com
    link
    fedilink
    English
    arrow-up
    11
    ·
    7 days ago

    Literally anything you want. You don’t need a static IP, any dynamic IP with a software updater will work. For example, I have some public sites proxied through Cloudflare, and I use the DDNS updater for Docker that keeps my DNS correct.

        • Shimitar@downonthestreet.eu
          link
          fedilink
          English
          arrow-up
          2
          ·
          7 days ago

          In my country no ISP will offer you a real IP address anymore. Not on IPv4 at least. So doesn’t matter if your ports are blocked or not, you are CG-NATted in any case.

      • Darkassassin07@lemmy.ca
        link
        fedilink
        English
        arrow-up
        1
        ·
        edit-2
        7 days ago

        Should check which ports.

        Mine blocks 80 inbound and 25 outbound, but everything else I’ve tried works. (so no default http, and no outbound email)

        I only really want 443 for simplicity, everything else can be random ports.

  • ѕєχυαℓ ρσℓутσρє@lemmy.sdf.org
    link
    fedilink
    English
    arrow-up
    11
    ·
    edit-2
    7 days ago

    The best way would be to use a VPS to proxy your traffic to you. You can achieve this for pretty cheap, just set up an wireguard tunnel to a cheap VPS. That’s exactly how I access all my services from outside my home. As long as the VPS has a publicly accessible IP (most of them do), you being behind CGNAT should not be an issue.

  • hendrik@palaver.p3x.de
    link
    fedilink
    English
    arrow-up
    11
    ·
    edit-2
    7 days ago

    I mean you can host anything. It’s just not reachable from the outside. And Fediverse or anything that gets data pushed in, won’t work. The common method to handle all of this is to use some tunnelling solution.

  • qaz@lemmy.world
    link
    fedilink
    English
    arrow-up
    10
    ·
    edit-2
    7 days ago

    You can use Tailscale, you can access your personal services with it but also expose public services with their Funnels system.

    Keep in mind that while the clients are open source, their servers are running proprietary software.

    • lorentz@feddit.it
      link
      fedilink
      English
      arrow-up
      7
      ·
      7 days ago

      I started using headscale (the opensource reimplementation of tailscale server) on a private vps. It is incredibly better compared to plain wireguard. I regret waiting so much before switching.

      Something that really made my life easier: wireguard is poor at roaming: switching to and from my wifi created issues because the server wasn’t reachable anymore from its public ip and wireguard didn’t bother to query the DNS again to check the new IP. Also, configuration is dead simple because it takes care of iptables for you (especially good when you enables forwarding to a node).

      Since the server just sends small messages for the control plane and all the traffic is p2p between the devices, the smallest vps with the smaller connectivity is more than enough to handle it.

  • Destide@feddit.uk
    link
    fedilink
    English
    arrow-up
    10
    ·
    7 days ago

    If this is just for personal use, I’d see if you can put their router in modem mode and go get a better router, then I’d just use tail-scale or WireGuard.

      • Destide@feddit.uk
        link
        fedilink
        English
        arrow-up
        1
        ·
        7 days ago

        It’s amazing additionally you can run Mullvad through it that might solve your public IP issues but I only run my services for me and my house

  • Xanza@lemm.ee
    link
    fedilink
    English
    arrow-up
    9
    ·
    7 days ago

    my current ISP refuses to provide me a static IP

    So then use dynamic dns? HurricaneElectric offers DynDNS now and it’s great. You can update it right over curl if you want. I have it mapped to a cli function;

    ~\downloads
    ❯ ddns
    HTTP/1.1 200 OK
    Cache-Control: no-cache, must-revalidate
    Content-Length: 18
    Content-Type: text/html
    Date: Tue, 25 Feb 2025 09:24:18 GMT
    Email: DNS Administrator <[email protected]>
    Expires: Wed, 25 Feb 2026 09:24:18 GMT
    Server: dns.he.net v0.0.1
    
    nochg {ip}
    
    • whoareu@lemmy.caOP
      link
      fedilink
      English
      arrow-up
      2
      arrow-down
      1
      ·
      7 days ago

      It’s not only not static It’s firewalled too! I can’t ping it from outside the network

      • mbirth@lemmy.ml
        link
        fedilink
        English
        arrow-up
        2
        ·
        7 days ago

        Did you configure NAT to the service(s) and/or DMZ to your internal server in your ISP’s router?

        Not allowing even ping seems like it is against any sane networking configuration.

      • Xanza@lemm.ee
        link
        fedilink
        English
        arrow-up
        2
        ·
        7 days ago

        Oh, damn. Not much you can do then. You may be eventually be able to get something outrageously complicated to work, but honestly it’s just plain not worth it. Just get a cheap VPS.

        Best you could do is a forward server with tailscale and a reverse_proxy, but I’ve never had any real luck getting that type of setup to work reliably.