this post was submitted on 16 Jun 2025
22 points (100.0% liked)

Selfhosted

48299 readers
1213 users here now

A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.

Rules:

  1. Be civil: we're here to support and learn from one another. Insults won't be tolerated. Flame wars are frowned upon.

  2. No spam posting.

  3. Posts have to be centered around self-hosting. There are other communities for discussing hardware or home computing. If it's not obvious why your post topic revolves around selfhosting, please include details to make it clear.

  4. Don't duplicate the full text of your blog or github here. Just post the link for folks to click.

  5. Submission headline should match the article title (don’t cherry-pick information from the title to fit your agenda).

  6. No trolling.

Resources:

Any issues on the community? Report it using the report flag.

Questions? DM the mods!

founded 2 years ago
MODERATORS
 

First: I've tried Tailscale, for some reason it works awful for me so I'm avoiding that option if possible.

I am trying to have a single server that has a VPN port exposed to connect to it, but routes traffic through a comercial VPN (mullvad ideally) to privately share my linux ISOs. So far I haven't been able to achieve this, it sees I can't use the VPN server (wg-easy) + VPN (mullvad gui), only the one that start first work.

Has anybody achieve something like this?

top 13 comments
sorted by: hot top controversial new old
[–] [email protected] 1 points 2 minutes ago

Another option is virtualization.

Separate your sharing server from your remote access server, then have them each connect to a different VPN

This is how I do it.

I have several containers and a couple of VMs running on my one server. My router is also currently virtualized (OpnSense running in a Proxmox VM, works great) and it connects to tailscale and uses subnet routing to allow my LAN devices to be accessed from outside my home without putting them directly on the Internet.

Meanwhile, I have two more VPNs set up for two different sharing servers. All on one physical machine.

[–] [email protected] 3 points 3 hours ago* (last edited 2 hours ago) (1 children)

I've done exactly this with wg-easy.

My config here is for v14, you'll want to pin the image version: https://github.com/qdm12/gluetun/discussions/1192#discussioncomment-12973135 Note there's a small typo in the local network Down rule I added, I'm on mobile right now else I'd copy my current config instead that cleans it up a bit since this post.

In the same thread, someone posted a fantastic guide to get it working with v15. You'll need to add an iptables rule for full LAN access if you want to enable that: https://blog.bktus.com/en/archives/2918/

V15 was giving me issues because it didn't allow you to disable ipv6, but apparently the latest edge builds do. I haven't tried that yet

[–] [email protected] 2 points 3 hours ago (1 children)

I'll try it as soon as I have time!

V15 didn't work for me, might be the issue you mention, so I'll stick with 14 for the time being.

[–] [email protected] 1 points 2 hours ago

Yeah I feel like v15 released a bit too early outside of preview builds. It's a substantial improvement but doesn't feel quite ready.

[–] [email protected] 6 points 18 hours ago* (last edited 18 hours ago) (3 children)

Maybe give Zerotier a shot. Similar premise as Tailscale, but a simplified NAT and routing implementation.

My overall question though is...why??? If you have access to a VPN, why would you connect to another location to use it when you can just use it from anywhere?

[–] [email protected] 1 points 11 minutes ago

TS works better for me than ZT. I started with ZT first, and had random access issues between my android phone, my VPS, and all my local devices.

The local devices could all ping each other's Zerotier IP addresses, but the vps and phone had issues pinging them, but not each other.

Meanwhile, tailscale is working fine, and I've even set up subnet routing so I only need it on my phone, my VPS, and my OpnSense system.

With Zerotier, I couldn't get routing to work at all.

[–] [email protected] 1 points 11 hours ago

I had success using openVPN. I set it up, generated certificates, installed it on my phones, tablets, and laptops.

It won't work when using an external vpn like Express or Mulvad, but while using it, you have secure connection to home. Once done with the home network, turn off the vpn, turn on your commercial vpn.

[–] [email protected] 6 points 18 hours ago (1 children)

Two cases.

One to have my server connect to the internet without exposing my traffic.

The second is to not have to chose between be connected to my server or be connected behind a VPN.

Honestly, if if wasn't because tailscale is performing badly for the last few months, I wouldn't have problems using and even paying for it.

[–] [email protected] 1 points 9 minutes ago (1 children)

Tailscale can actually use a Mullvad exit point. I don't know if you knew that ..

[–] [email protected] 1 points 4 minutes ago

Yes, but it's working awful for me. Even without exit point lose connection for a long time, and there's a error on the app. I need to restart the connection for it to work again.

Even when it works it's much slower to connect to my server than VPN.

[–] [email protected] 5 points 18 hours ago

I did follow this guide to use WireGuard to connect to my homeserver and use my internal pihole and then connect to the internet with protonVPN.

https://www.linuxserver.io/blog/advanced-wireguard-hub

[–] [email protected] 1 points 19 hours ago

I use Zerotier. I have a rpi sharing my Linux isos through a commercial VPN. The RPI has Zerotier as well as my other devices, so I can connect to it from anywhere as if it was on my home network.

[–] [email protected] 1 points 19 hours ago

Tailscale has the funnel command which exposes services like how you describe, but that's off the table.

Not quite sure I understand your layout, but if these are separate VPNs, you could run one from the server with a port forward (guessing that's not through Mullvad as they don't offer forwards any longer - to my knowledge) and then setup the general VPN on your router perhaps so you don't have to change ip routes for the whole network. You would still probably need to setup an ip route specific to the server VPN traffic on the router at that point, but that would probably be less work.

If this all being done from the same device then you would need to separate them out by IP routes.