What would be the best setup for my situation?

Right now I own a proxmox server, and a custom domain name (through cloudflare), and am able to buy a VPS if necesary. My goal is to run a whitelisted but public server (so that no one needs to download a client, though they can download minecraft mods if any of you know how to use modflared, but I can't port forward. What do I do? tl;dr: - i have custom domain name - i have server - need to host publicly-ish without port forwarding - can buy VPS if required
97 Replies
Admincraft Meta
Admincraft Meta7mo ago
Thanks for asking your question!
Make sure to provide as much helpful information as possible such as logs/what you tried and what your exact issue is
Make sure to mark solved when issue is solved!!!
/close !close !solved !answered
Requested by maxbuddyroo#0
Jenkins
Jenkins7mo ago
You can get a VPS from OVH to port forward from there via WireGuard or HAProxy with Gate Lite You won't forward on the actual Proxmox machine, instead traffic will be forwarded to your main machine from OVH They have very good Anti-DDoS infastructure too @MaxBuddyRoo
maxbuddyroo
maxbuddyrooOP7mo ago
is there a tutorial on how to do that somewhere? and why OVH and not other VPS services?
Jenkins
Jenkins7mo ago
and why OVH and not other VPS services?
1- They have a very good deal right now, a 2 GB 1 Core server for 97 cents per month 2- Their support is good 3- Their Anti-DDoS infrastructure is one of the best. Most major providers use OVH as their pops, because they are very reliable. I was able to mitigate many large attacks with OVH just fine, and I never had issues.
Jenkins
Jenkins7mo ago
A bit old screenshot
No description
maxbuddyroo
maxbuddyrooOP7mo ago
sounds good, what are the steps on how to do what you mentioned in your first message?
Jenkins
Jenkins7mo ago
https://gist.github.com/adog1314/97bf494d74f56bfff51da9bb4bff8ed0 https://superuser.com/questions/1777082/using-vps-to-give-public-ip-to-on-home-network/1777106?noredirect=1#comment2772486_1777106 This should work, I'm pretty sure. Just do for port 25565. You may need additional changes if you want to forward the IPs, though, just say here and I'll help you out.
maxbuddyroo
maxbuddyrooOP7mo ago
so basically the VPS connects to my home server through wireguard, and then just port forwards itself so my own ip isnt exposed?
Jenkins
Jenkins7mo ago
Yes Your main IP will not be exposed, and you'll have the full Anti-DDoS infrastructure of OVH on your home server
maxbuddyroo
maxbuddyrooOP7mo ago
wait how do i connect the domain name
Jenkins
Jenkins7mo ago
wdym A record to the VPS IP
Alien
Alien6mo ago
I recommend Hetzner OVH has decent specs for what they are, but with how oversold they are. The only way I could ever recommend OVH is if you were to buy a dedi, or if you found a reseller willing to set you up a VDS. Hetzner has amazing performance, and is very cheap. You can get a 2 core dedicated AMD EPYC 7000 series CPU for about 11 euros. I was using SparkedHost for a while, but with how hard they oversell even a player simply joining my server made the CPU skyrocket. Ever since I switched to the VDS's to Hetzner I've had no real issue. If you do not want to go to hetzner for what ever reason, find a host willing to offer a dedicated CPU
Skullians
Skullians6mo ago
if you’re in the EU* and don’t mind the bad ddos prot*
ProGamingDk
ProGamingDk6mo ago
vps have US, SG, and EU locations only SG has different pricing
Skullians
Skullians6mo ago
mmm didn't realise
Alien
Alien6mo ago
um, they have USA locations? and i suggest using their VDS's
Skullians
Skullians6mo ago
um?
Alien
Alien6mo ago
their dedis are only EU tho
Skullians
Skullians6mo ago
yeah as I said, didn’t realise
Alien
Alien6mo ago
i forgive u
Skullians
Skullians6mo ago
also out of interest what server host do you represent
Jenkins
Jenkins6mo ago
They're more expensive + don't have DDoS prot + worse networking, too
Alien
Alien6mo ago
I disagree.
Jenkins
Jenkins6mo ago
It's fine, you can't always have the correct opinion
Alien
Alien6mo ago
They're dedi's and server auction has one of the best prices, i do agree with you on their ddos protection. But if you use something like TCPShield or NeoProtect then that no longer becomes an issue.
Jenkins
Jenkins6mo ago
sir the whole point is that they're going to spend very little money
Alien
Alien6mo ago
Almost all of these MC server sellers are heavily overselling their hardware
Jenkins
Jenkins6mo ago
and not have to fuck with external ddos prot he's hosting at home... OVH is used as a proxy
Alien
Alien6mo ago
No description
Alien
Alien6mo ago
i SUGGESTED, hetzner if he were to purchase a vps
Jenkins
Jenkins6mo ago
yes, and he should buy OVH an OVH VPS because they have good networking and ddos prot they aren't going to host the server from the VPS
Alien
Alien6mo ago
their hardware is not as good
Jenkins
Jenkins6mo ago
VPS will be used as a PROXY
Alien
Alien6mo ago
as OVH heavily oversells as well
Jenkins
Jenkins6mo ago
proxy to FORWARD traffic It's a PROXY
Alien
Alien6mo ago
thats still relying on external ddos protection....
Jenkins
Jenkins6mo ago
no???
Alien
Alien6mo ago
at that point, setup TCPShield. They have firewalls specifcally for minecraft
Jenkins
Jenkins6mo ago
OVH has its own ????????????
Alien
Alien6mo ago
yeah, not configured
Jenkins
Jenkins6mo ago
OVH has java protection built in I don't get what your point is. OVH will be used as a proxy, and it's perfect for that because of DDoS protection and good networking
Alien
Alien6mo ago
and TCPShield is free, takes seconds to setup, can be used on his own hardware, and is specfically built for minecraft.
Jenkins
Jenkins6mo ago
And it's less than a dollar for month He can't port forward.
Alien
Alien6mo ago
i simply suggested a VPS provider.
Jenkins
Jenkins6mo ago
the whole point is that they can't port forward my man
Alien
Alien6mo ago
yes, which is why i suggested a VPS. im not understanding what your issue with that is
Jenkins
Jenkins6mo ago
he doesn't want to host the server on the VPS he already has one the VPS is for a proxy??? You can host it on a 500mb 0.5 core server as long as it has good networking
Alien
Alien6mo ago
all of those issues can be fixed by simply buying a $11 vps from hetzner, or what ever provider he chooses. I gave my recommendation for a VPS if he wants to buy one which he said hes willing to do so, ur fighting with me over absolutely nothing...
Jenkins
Jenkins6mo ago
what host do you even own I'm curious you have the hosting role
Alien
Alien6mo ago
thats not relevant to this
Jenkins
Jenkins6mo ago
what host do you own either way do you even own one
Alien
Alien6mo ago
its not important
Jenkins
Jenkins6mo ago
it's important, because the role is only for those that own one
Alien
Alien6mo ago
i gave my suggestion and youre livid over it
Jenkins
Jenkins6mo ago
How can you be sure the "11EUR Hetzner VPS" is better than what he already has? how do you know the server @ home isn't running on a 5950x lmao why would you migrate everything to a VPS that has worse performance when you can buy a server for less than a dollar and use wireguard to proxy it home
Alien
Alien6mo ago
Im not sure what he has at home, but the reason i suggest hetzner is because their VDS's are really nice. And their routing is amazing, i actually connect to my server faster connecting directly to my hetzner's IP, and I have a few different proxies setup, one with TCPShield, one with CosmicGuard, and another one that im not going to mention. Soon im going to setup NeoProtect and see how they are, i may only use them for my bedrock players The routing will be different for everyone as maybe my ISP has good routing with hetzner's servers and some others may not
Jenkins
Jenkins6mo ago
and can you please remove your hosting role if you don't own a legally registered company
Alien
Alien6mo ago
i will not be removing the role i do own a hosting serivce, its not very popular like OVH or SparkedHost or pebblehosting or something like that
Jenkins
Jenkins6mo ago
staff will, so feel free not to ¯\_(ツ)_/¯
Alien
Alien6mo ago
right now im waiting for the new 9950x to drop next week but i may not even get that one for a server at least. sure, if they want me to remove the role i will i really dont know why you are so emotional right now, all i was doing was giving him a suggestion
Jenkins
Jenkins6mo ago
giving him a suggestion
That doesn't help at all and isn't related...
Alien
Alien6mo ago
it will help theres many options they can go with, i gave them one of them, one i think would be good
AeonRemnant
AeonRemnant6mo ago
@Jenkins Man can you please just not be like this? :husk:
Jenkins
Jenkins6mo ago
...
AeonRemnant
AeonRemnant6mo ago
Just... man...
Jenkins
Jenkins6mo ago
what's wrong
AeonRemnant
AeonRemnant6mo ago
Try not to be a needless asshole. Rich coming from me, I know, but if anyone can spot when you're being a needless asshole it would be me.
Jenkins
Jenkins6mo ago
It's a worse solution for like 11 times the price he'd normally pay... And it goes up even more if you actually want a good VPS
AeonRemnant
AeonRemnant6mo ago
Amazing, but try not to be a needless asshat about it.
Alien
Alien6mo ago
Their VDS's are only 11 euros a month maybe some providers have better prices in here? i havent taken much of a look at them
AeonRemnant
AeonRemnant6mo ago
Honestly I wouldn't use OVH. While their DDOS prot is technically good, in execution it's shit to actually use. For a small server I'd sooner just TCPShield or NeoProtect free it.
Alien
Alien6mo ago
Exactly! Thats all I was trying to say lol
AeonRemnant
AeonRemnant6mo ago
Like not only at that stage do I get DDOT prot, but I get edge routing. But I should take an OVH system because...? Reasons ig? OVH has it's place, but this isn't it imo.
Alien
Alien6mo ago
i wish minecraft was UDP UDP > TCP
AeonRemnant
AeonRemnant6mo ago
I don't hate it being TCP, tbh.
Jenkins
Jenkins6mo ago
I'm not sure how any other solution will work here All the server will run is WireGuard For tunneling home
AeonRemnant
AeonRemnant6mo ago
I know, I did read it.
Jenkins
Jenkins6mo ago
That'd cause so many issues
AeonRemnant
AeonRemnant6mo ago
Oh for sure.
Alien
Alien6mo ago
like what
AeonRemnant
AeonRemnant6mo ago
So much shit would break overnight.
Jenkins
Jenkins6mo ago
Minecraft Java wasn't meant to be a UDP game ever
AeonRemnant
AeonRemnant6mo ago
But Jenkins. Imagine if it was.
Alien
Alien6mo ago
UDP on top lol
Jenkins
Jenkins6mo ago
I love QUIC Server Authoritative Movement 🤤
AeonRemnant
AeonRemnant6mo ago
That'd be the fuckin' dream...
Jenkins
Jenkins6mo ago
Only if done correctly Spoiler: it sucks on Bedrock so much that it's unusable
AeonRemnant
AeonRemnant6mo ago
Average Mojang moment.
Alien
Alien6mo ago
Lmao Eventually, I will co locate with a datacenter near me. Although Im having a hard time deciding if I want to co locate with Path or Cosmic Probably cosmic. Path ewww
AeonRemnant
AeonRemnant6mo ago
Both kinda suck as DDOS prot. NeoProtect is based though.
Alien
Alien6mo ago
Path has AMAZING ddos protection, they've patched A LOT of attacks But, their just a shitty company Cosmic has nice routing, DDoS protection is okay
AeonRemnant
AeonRemnant6mo ago
Eeeh. Their history has been dropping like nuts recently. Bad reputation these days.
Alien
Alien6mo ago
For my MC server customers I could offer TCPShield or NeoProtect, but for other things I will be hosting it will be nice to have either path or cosmic Path has always been a bad company, marshal is a interesting person lol One issue I will have, is if my servers receive a lot of DDoS attacks path will drop me and most likely charge me
ProGamingDk
ProGamingDk6mo ago
speed wise not really its 20 gbit every region except singapore getting sued for unpaid bills, and loosing over a tb of bandwidth is a real issue
Alien
Alien6mo ago
yup owners are also known DDoSers and extorters, their staff are also DDoSers. Lmao, im surprised you know about this site

Did you find this page helpful?