[0] https://www.digitalocean.com/pricing/#standard-compute-trigg...
[0] https://www.digitalocean.com/pricing/#standard-compute-trigg...
I bet in part it is due to the CloudFlare's efforts to "Cleaning up Bad Bots" [1]. In this article under how they detect bots they write:
> Another model allows us to determine whether an IP address belongs to a VPN endpoint, a home broadband subscriber, a company using NAT or a hosting or cloud provider. It’s this last group that “Bot Cleanup” targets.
I suspect when use a VPN hosted on a VPS, you often end up classified as a bot to be cleaned up...
Edit: did some reading [1]. Clearly it's not easy to get an ASN. Not something a private person would do.
I am personally looking at AFRINIC for their sweet IPv4 space :-)
But I only need one IP address, and I'm willing to pay $500 for it. Is there a way to make this happen?
[0] https://www.ipv4connect.com/products/-buy-ipv4-Arin-24/484
I know that VPC peering[0] is possible across separate AWS accounts, what I don't know is that:
1. Whether or not my /24 block is "compatible" with VPC peering or not
2. How to prove to Bob that I'm not potentially MitMing him (assign my /24 block to VPC1, peer with Bob using VPC2, and MitM between VPC1 and VPC2 since they're both under my control). Would creating an IAM user with read-only VPC permissions work for this?
AWS is just an example. I would be happy to do this at any major provider (AWS and GCP are the two I know that allows bring-your-own-ip).
[0] https://docs.aws.amazon.com/vpc/latest/peering/what-is-vpc-p...
You only need a good system administrator. I can get you in touch with friends who specializes in that. They will certainly recommend your /24 to be pointing to a more friendly provider of your choice, like one with a flat rate!
/24 with ASN -> friendly provider -> any ip goes where you want (digital ocean, aws, etc.)
But no, you can't prove you aren't MiM. Who has control of the /24 at any point could (ex: the 'friendly' provider)
Annoyingly, I have moved, and now have comcast so that brings problems. First, they tamper with DNS traffic. To combat this the resolver is unbound running on the Linode. This creates very occasional problems, usually in the form of a capcha. Additionally, comcast doesn't offer symmetric connections, so my VPN is slower than it should be (1Gbps/30Mbps is such a joke).
Also some e-commerce sites will refuse purchases when made from hosting-allocated IP ranges since it's commonplace for fraud.
In fact, I also run a pihole on the same droplet, and that's fine too.
Smallest droplet would probably be fine, if you’re not streaming 4K video. Same goes for the 1TB transfer limit.
https://github.com/rajannpatel/Pi-Hole-PiVPN-on-Google-Compu...
(I run OpenVPN and PiHole from a GCP micro instance)
I’m a networking novice, but in my .ovpn profiles I provide, the IP is hard-coded.
"Note: Starting January 1st, 2020, GCP will charge for VM instance external IP addresses. However, under the Free Tier, in-use external IP addresses will be free until you have used a number of hours equal to the total hours in the current month. Free Tier for in-use external IP addresses apply to all instance types (not just f1.micro instances)."
"1 GB network egress from North America to all region destinations per month (excluding China and Australia)"