Phil,
I am currently doing this. I am announcing my subnet with BGP on a PFSENSE
VPS. I have half of it site to site to my house, and the other is a remote
access vpn for my mobile devices that I am doing HAM stuff with.
I will write up a HOW-TO at some point, but it is definitely possible.
There are even some ways to do OPENVPN with a null cipher, but I am about
to experiment a bit more with some other methods.
Just be weary on the site to site method...you are obviously going to be
using double bandwidth for anything. I am working on setting up caching
for linux packages.
Another thing that is kind of cool is that you can use cloudflare CDN for
free to reduce the load of your webserver if your home connection is slow
or data capped.
My HAM site is still kind of in shambles right now, I am trying to rebuild
it after some hardware difficulties so that's why you wont see much on that
subnet.
Here is a traceroute from one of the hosts on that site to site VPN to my
actual ISP provided network so you can get an idea of the route:
mike@status:~$ curl
icanhazip.com
44.20.4.14
mike@status:~$ traceroute HOMEIP
traceroute to HOMEIP (xx.xx.xx.xx), 30 hops max, 60 byte packets
1
router.kf5jxv.net (44.20.4.1) 1.285 ms 1.193 ms 1.126 ms
2 10.20.4.1 (10.20.4.1) 41.441 ms 41.321 ms 42.295 ms
3 * * *
4
vl199-ds1-j2-650.01.05.dal4.choopa.net (173.199.97.65) 57.796 ms
57.702 ms 57.625 ms
5
vl913-br1-cer.dal4.choopa.net (108.61.110.41) 43.415 ms 43.736 ms
44.116 ms
6
dls-b22-link.telia.net (62.115.149.44) 44.368 ms 42.816 ms 42.999 ms
7
dls-b21-link.telia.net (62.115.140.29) 43.874 ms
dls-b21-link.telia.net
(62.115.143.58) 42.200 ms
dls-b21-link.telia.net (62.115.120.88) 42.505 ms
8
qwest-ic-136700-dls-bb1.c.telia.net (213.248.84.198) 42.258 ms 41.628
ms 41.958 ms
9
hlrn-agw1.inet.qwest.net (208.168.140.73) 75.268 ms 74.908 ms 74.700
ms
10
hlrn-dsl-gw07-50.hlrn.qwest.net (71.217.188.50) 74.893 ms 74.663 ms
75.214 ms
Hop 1 is my local PFSENSE(VM)
Hop 2 is my VPS with the bgp session over the site to site
The only thing I have found with this is that the latency is kind of a
bummer(+40ms). I am trying to find somewhere a bit more local for this BGP
session. I also still do not have it setup to accept incoming IPIP from
the rest of 44net yet.
Going the other direction I have static routes pointing those subnets to my
44net VM router.
Hope this is of use to someone.
Cheers,
Mike KF5JXV
On Mon, May 1, 2017 at 11:29 AM, Tom Hayward <esarfl(a)gmail.com> wrote:
(Please trim inclusions from previous messages)
_______________________________________________
On Mon, May 1, 2017 at 10:18 AM, Phil Pacier <ad6nh(a)aprs2.net> wrote:
Hello all, and thank you for your assistance. I
have 44.10.10.0/24
allocated and announced via BGP. The subnet terminates to an Ubuntu
server in a data center. I want to allocate addresses from this subnet
via tunnels to other locations. For example, I would like to assign an
address or a block of addresses to my home location (Cisco 1900 router)
from this subnet. Is this possible, or do I need to look at a different
option? Thank you!
Hi Phil,
This was actually just discussed:
http://hamradio.ucsd.edu/mailman/private/44net/2017-April/006918.html
It can only be done manually by the portal maintainer.
Your other option is to create your own tunnel system (site-to-site
VPN) at your BGP endpoint.
Tom KD7LXL
_________________________________________
44Net mailing list
44Net(a)hamradio.ucsd.edu
http://hamradio.ucsd.edu/mailman/listinfo/44net