Build your own private WireGuard VPN with PiVPN
jeffgeerling.com
jeffgeerling.com
Also, unrelated, I just decided I don't like the sentiment of "PiMyProjectName" branding. I know most projects don't just run on a Pi, and that the intent is to say "you can self-host thing", but at this point if you want to run a home server sort of thing, just buy some cheap 100-200 dollar minipc thing. That's how much you'd pay for a Pi now anyway, and it comes with such great features as:
* just establishing an ssh connection doesn't take multiple seconds
* the ethernet doesn't go over a usb hub
* it doesn't run on an sd card that is going to fail within a year
I'm pretty dismissive of ARM chips for homelab stuff at this point. There's super cheap minipcs with "real" processors that will just destroy even an expensive ARM board.
Pi's shine with their ability to run both a real/full Linux and also do gpio type stuff that otherwise is usually an arduino board. I don't have anything against low-level programming but damn is it just a lot more fun to do in python. I love the Rpi zero w 2 products for this, just enough juice to run wifi and a python loop, plus the gpio pins. Too bad they've been sold out for literally years.
This looks great, thank you! My current home router(s) fortunately support Wireguard natively, but I'll look into this if I'm ever again forced to use a shitty CPE.
> I'm pretty dismissive of ARM chips for homelab stuff at this point. There's super cheap minipcs with "real" processors [...]
What makes an ARM SoC a "non-real processor"? I'm typing this on a laptop with an ARM CPU, and it's the fastest hardware I've ever worked on.
Is it all down to the file system? Is the CPU just in interrupt overload all the time? I wish I had a better understanding of the issue here.
The small boards also typically have much slower I/O and less memory. On a PC with 16GB of RAM running as a server, usually the whole OS will end up cached in memory. A Raspberry Pi with less RAM is more likely to have to evict from the page cache, and then read it back from a slow SD card.
Most BIOSes have an option for that. Did you check?
- additional energy savings
- more or less eliminated need to clean out dust or eventually replace a fan
- no fan noise, a massive boon if you live in a small apartment and don't have a closet or basement you can toss the server into for noise insulation
I suppose if I did serious number crunching on my home server, I'd need something beefier... but I've been running a VPN, a Minecraft server, a streaming media server, and a DNS server on my Pi4 for more than 3 years now. Only during media scans do I feel any slowness.
PCs also support arbitrary amounts of memory, so you can often avoid needing multiple devices by using virtualization.
Raspberry Pi chip sets are always older (less efficient lithography/structure size) ones, as they take over the ones currently being phased out for industrial use (so they get them cheap). Those have a hard time to compete with e.g., a modern Intel N100 CPU which has a TDP of 6W but at the same time 4 cores with a max freq. of 3.5 GHz and can even use DDR5 (or LPDDR5 for low power) and is available in many form factors, often fanless with a metal body as cooler at about 150€ (if lucky) to 200€ and those models then even including (often multiple) 2.5Gb Ethernet ports and NVMe M.2 slot.
That makes it at least for me an easy choice, and I am indeed looking out for using less power but still getting stuff done somewhat quickly.
The best part is it's easier to scale to your needs. E.g. if a single $200 box can get the latest generation CPUs that will absolutely demolish these cheap ARM boards in perf/watt, come with PCIe m.2 drives, support higher RAM limits, and have GPUs that are more on the usable side of things. As a result it can do the work of multiple devices (if you don't need them to be physically separate of course) and will last significantly longer in terms of usability.
Everything I need is supported by Ubuntu server. Excellent little machines.
What about Mac Mini? The latest version runs on M2
One of the better options if you don't need a lot of internal storage is old laptops. They're cheap, low power, have a built-in monitor and keyboard and you don't need a separate UPS (who cares if the internal battery "only" lasts an hour).
The Raspberry Pi Compute Module 4 has variants with eMMC, which is better than using an SD-card.
Additionally, there are adapters to use NVMe drives and you can boot from them. I’ve done so with a few RPi CM4, to varying degrees of luck. One of them works perfectly, another one did not. Currently waiting for more of the same adapter I used for the first one and hopefully this will allow the additional ones to work as well as the first one is doing.
About 8 years ago, I switched my home server from a pi to an Intel baytrail based system. I put it all together myself in a cube shaped case. It is passively cooled and runs off a 12V 2A power brick. I filled the space for the PSU with two 3.5" hard drive hot swap bays. I keep one drive in and synchronized to my desktop over the network, and pop another one in when it's time to make a cold backup. It's served me very well.
I use the Argon case with ssd over usb, since the sd cards failed like after 2 weeks. For me it is perfect, I get to host all my minimal things (vpn, ssh over it, host photos, videos, run a few services) and it is like super energy efficient, although that efficiency is more of an ego boost than actual use.
I think there are a lot of atom mini pcs which have normal ethernet and m2 connectors that are a better alternative.
Are these still readily available somewhere? All I can find are a tiny handful of $300+ listings and RAM upgrade spam.
1. Eleven years and counting
https://www.aliexpress.us/item/3256804116114245.html
There are a few suppliers, but the 4x Intel NICs open up lots of possibilities. They're very lower power, but still fast enough to handle a lot of traffic.
I run VMWare ESXi on mine and use openwrt for my router on two ports and then a general purpose server in another VM.
I've never bought off of AliExpress. I'm in the U.S. Do people take precautions when ordering from them? I'm not so worried about the products, themselves. I'm worried about the use and security of my financial data.
Worried as in, I just don't know whether they are safe stewards. No experience, no one to ask. Except maybe you guys. Give them my credit card #? Generate a one time #? PayPal?
Sorry to go a bit OT, but this is yet again where I've been tempted to order from them.
My experience has always been a good one. Just be prepared to wait a while for delivery, the business cards were about three weeks.
Now, maybe the setup I choose is more difficult on one OS than on another. This is where RPi shines, IMO. As a project creator, I can use an OS I choose from among a variety that have been ported to the RPi, including non-popular ones, and I know every RPi user can easily run it because it's been already been pre-installed on SDCard; the RPi is not OS-specific. No pre-installtion of OS! (This pre-installation practice enabled Microsoft to stifle competition and hold back progress in computing for decades.)
Prior to RPi, many SBC only had GNU/Linux as an OS choice because that's what's popular. For example, prior to the RPi port running Plan9 required careful hardware purchasing choices. Choosing RPi, a well-known brand, is arguably much easier.
> just establishing an ssh connection doesn't take multiple seconds
That's almost certainly power saving on the WiFi. Annoying but fixable. Seems to be on by default, and a `/sbin/iwconfig wlan0 power off` line in rc.local should fix it.
Also, the original Pi (2012) was able to run Wireguard well enough for light VPN, although I didn't push it too much since I didn't use it for anything heavy like video streaming.
More than a “small amount of legit pain” was the result.
Also, plenty of people live far away from family and have to deal with death (I’m in the same boat). It sucks but I’m also curious why the obit was particularly important to you because as far as I understand that’s topically just a small blurb in the newspaper? My family doesn’t do obits so I’m curious.
Not to minimize what you went through at all, but it’s interesting in today’s times how we expect so much immediacy. My immediate family escaped the USSR just before it collapsed but my dad’s was family was stuck in Russia and couldn’t leave even after it fell. My father had to deal with his brother, father, and mother dying within 5 years or so with no visits in between that time (a combination of finances + probably fear about traveling back). Comparatively I personally have a much easier time in that I at least get to see my family once a year or so. Again, in no way a comparison as dealing with loss and living far away from family is always hard. Just a reflection of how much technology has changed and made maintaining more closeness easier (eg video calling).
Well, I guess it depends on the type of attacks one experiences, but hackers and spammers who target US-based businesses are not idiots, they know how to use vpns and tor and proxies. So on a technical level you get close to nothing security-wise. You reduce a number of bots and worms randomly accessing your servers, can stop some script kiddies who don't know better and make life a bit harder to web scrapers (but not much) - and that's it.
You forgot to consider "any of my company's existing US-resident customers temporarily traveling outside of the US".
For Homedepot to comply with GPDR, they would have to treat EU and non-EU users differently, or they could just block EU. Since you're not trying to sell anything to EU users, blocking them makes things easier.
But EU has less of the leverage if company refuses to do business in EU — that's true.
on the other hand, CCPA is still a thing
This part of GDPR has always seemed completely unpracticable/unenforceable to me. How would a non-EU company even know that one of their customers is an EU resident and only temporarily visiting? Most services in the US aren't asking for my passport, at least.
Practically, I'd assume that this will be interpreted by courts to only apply to companies "intentionally doing business with/commercially targeting EU residents", which is already the case for similar scenarios (e.g. that's how, to my understanding, German law requiring all sites to provide an imprint has been interpreted by courts).
In any case, I suppose we'll have to wait for precedent; I'm not aware of any at the moment.
Err, or treat everyone in a compliant way?
It's not like you don't already see this within the US anyway - particularly California.
And if you decide to treat everyone the same way, you likely end up with a higher bounce rate for the existing US customers. Hence, blocking.
> (a) the offering of goods or services, irrespective of whether a payment of the data subject is required, to such data subjects in the Union; or
> (b) the monitoring of their behaviour as far as their behaviour takes place within the Union
Did I quote the correct section? Doesn't collecting all the analytics fall under section B? I'm not a lawyer of course, but it seems pretty reasonable to me that if you have interest in the EU market, blocking them is easier than figuring out if GDPR applies to you or not.
Or you could just not spy on your users of course, but I guess I'm too pessimistic to see that as an option a company would choose.
You need to not sell goods and services to EU citizens for the law to not be in effect.
Even if said citizens are in the US. You don't cease being a EU citizen when you're traveling.
I can understand that an American company does not want to make such an investment when there is literally 0 added business value, as EU customers don't shop at that company.
If McDonalds and Aldi can work on multiple continents I'm sure it's not logistically impossible.
Blocking users on a two-level-deep assumption is wrong.
Even though blocking by traffic source is not always accurate, I’d expect that it would still greatly help show that the site did not envisage offering goods and services to people in the EU.
I don’t outright block them because I myself travel, and some foreign laws apply to their citizens wherever they are.
I can completely see why you might want to ban overseas IP connections though, and I’ll probably do it soon.
Lesson learned: configure the UPS to communicate with the servers and shut them down in a controlled manner when batteries are dying.
There are commands to enable/disable read-write mode, so you can still make changes and do upgrades.
I've had 0 problems with SDcard death after I started using it.
I am French. What I find fascinating is that there are local US newspapers (that server a tiny community) that went through the effort to do a geoblock from the EU and put a page along the lines "we cannot be compliant to Privacy laws in the EU so we must block you".
Why do they care at all? How is the EU law relevant to their small, local business?
Large companies are different - there could be some litigation against their footprint in the EU etc. - but for thosewho just live in the US (or anywhere outside the EU) going the extra mile to block because of non compliance is really weird.
If I was issued a fine by the US, China, India or Japan it would directly go to the trashbin. It is their law, and their problem, not mine.
Of course this means that I will not be able to do business there, if I travel I may be in trouble etc. But again - we are talking about small local newspapers (and similar businesses).
A. [re-]architect in in GDPR compliance;
B. deal with incoming legal documents, likely can't just discard;
C. block country representing tiny share of viewership,
option C seems to present the least hassle
Not sure whether C or D would be more complicated long term (you need to manage the geoloc somehow, or outsource and pay for the service)
The US does do that kind of thing though. As a dev, break some law, step foot in the US for a conference, get arrested (ex: Sklyarov 2001 case, for breaking PDF encryption).
Although for most financial things, it's common in US/CA to block non-local IPs. Heck, I was in Mexico and I couldn't login to my provincial government tax portal. There are constant security issues with those sites.
They can tell whatever they want, but it would need to be a US court (in that case) who would do the litigation. Which they won't.
> The US does do that kind of thing though. As a dev, break some law, step foot in the US for a conference, get arrested
yes, this is why I mentioned that my point is only for local businesses. Travel or business in the EU can/will be problematic.
> Heck, I was in Mexico and I couldn't login to my provincial government tax portal. There are constant security issues with those sites.
Blocking for security is another thing. Maybe a good idea, maybe not - but that's another story.
That's a pretty incomplete view of how jurisdiction works. You do probably need a US court ruling to enforce a claim against a US entity – but if that entity has any EU subsidiaries or assets, you can bet that European courts will come after those.
> Blocking for security is another thing. Maybe a good idea, maybe not - but that's another story.
As a customer/taxpayer that needs access to a service from abroad, I really don't care why I have to jump through hoops to cancel a subscription/order or pay my taxes owed.
I am not sure you read my post in details - I explicitly mentioned that I am talking about local services, without any international footprint. And mentioned that in case of this footprint - yes, they will be sought after.
This is also exactly waht the US does to enforce their "extraterritoriality"
And they can be enforced not only from assets, but also from travel or various financial tools at their disposal. (it would be surprising, but for many businesses, it's not worth the hassle)
The golden days of global network accessibility are closing little by little.
Exactly, except that it is just simpler to do nothing.
Do you (I assume you are not in either of the countries I give an examples, nor travel there) worry about laws in, say, China when you state "Taiwan is an independent country", or Russia when you say "Russia invaded Ukraine", or North Korea when you say "NK is a tyranny", or France when you say "Retirement should be at 60 and not 64". No. Because the local laws that forbid these statements are, well, local. Nobody cares outside of these countries. They could send you letters informing that you did wrong and that you have to pay 1M USD and you would just put that to trash.
> I guess my question to you is why do YOU care if they're accessible or not? If a (local) business really just wants to sell within their own (local) country (or even smaller municipality such as state/county/city), is there something wrong with blocking everything outside it out and just not worrying about it?
I do not care - it is just that I ended serendipitously on a few of these places and was wondering why they care (I would not care about the cookie law in Zimbabwe or Patagonia if I had a web site).
> They could send you letters informing that you did wrong and that you have to pay 1M USD and you would just put that to trash.
I think it's just better to not get those letters in the first place (any more than spam phone calls or texts) and have to waste time reading them, or having to possibly consult an attorney over them to see if they have merit. It's just not something I want to be bothered with, nor should I. It has nothing to do with the company, what we do or our customers.
> Do you (I assume you are not in either of the countries I give an examples, nor travel there) worry about laws in, say, China when you state "Taiwan is an independent country", or Russia when you say "Russia invaded Ukraine", or North Korea when you say "NK is a tyranny", or France when you say "Retirement should be at 60 and not 64".
We don't say anything like that on our company sites.
Not that I disagree with you on the 'it seems stupid' front. But that doesn't change the risk profile for the company.
Yes, and it's infuriating. For example, it was (and probably still is) impossible to access the NY MTA's OMNY portal from many, but curiously not all, European countries. The OMNY system itself works using foreign cards, but this makes it very annoying to download receipts for expense reports.
Another fun one was not being able to cancel some streaming service from outside of the US due to the service geoblocking their account management site as well. I actually had to use a VPN to cancel!
There are countless other examples.
You can buy a travel router like the GL.iNet GL-SFT1200 (Opal) for $39.99. All of Gl.iNet's devices run OpenWRT already. Setting up Wireguard on OpenWRT is easy, and using Tailscale is even easier!
Edit: Jeff's been creating awesome Raspberry Pi content for a long time and I'm glad that he's not stopping given the current circumstances. I hope that his audience has an abundant supply of unused RPis looking to be utilized.
In Jeff's shoes I'd want to speak to those in his audience who DON'T have a Raspberry Pi and save them from paying scalpers prices until things return to normal--assuming that they ever do.
According to https://docs.gl-inet.com/en/4/tutorials/tailscale/ the GL-SFT1200 (Opal) does not support Tailscale but different models from GL.iNet do.
> PiVPN, luckily, runs on any other Pi-like device, though, as long as it's running a Debian or Pi-OS-like distro.
* Doesn't need to be a Raspberry Pi™, It runs on any x86_64 system
Any Debian isn't too bad though.
It’s true that a lot of chips are made in China. Nevertheless, the question remains.
But the nice thing is PiVPN works great on any little PC. Or even a VM.
Presently my “home server” is only used for home assistant, and it runs on a 2011 MacBook Pro with a bad keyboard, running Debian. It actually runs so well on Linux that the fan doesn’t even spin, at least not audibly.
I use it on my system and it works flawlessly on restarts.
It served me well on my trip and I was able to see all the things from local media that are geo restricted out of the US.
There's a nice UI that generates the QR codes or config files ready for import into client devices.
1: https://openwrt.org/docs/guide-user/services/vpn/wireguard/b...
What pivpn (and similar tooling wrapping lower level commands) bring along is this client management and even some network topology/routing management : https://docs.pivpn.io/wireguard/ and https://github.com/pivpn/pivpn/tree/master/scripts/wireguard
I think it's a interesting spectrum between wg-cli and tailscale.
When I set it up it promised a 10 minute install time. For me a fair portion of that 10 minutes was trying to work out if it was working as my line speed was higher than I thought possible. It’s scary how quick it is to configure.
I still run Wireguard proper on my iOS device... it switches automatically when I am off my home SSID.
But I run Tailscale everywhere else.
Yeah, there are utilities like setting up udptunnel or udp2raw and similar, but what a headache. I really don't agree with Wireguard's developers justification that it makes speeds terrible. Who cares? It'll be terrible using those utilities anyway. Give us the option, JFC.
With quic on the way, this problem will diminish with time anyway.
443 is much more likley to be let past, with the popularity of QUIC.
53 is my go to port when the network is wonky.
From my experience UDP 53 like another commenter suggested does not always work as some firewalls forcibly route all UDP 53 packets to their own local DNS server in order to prevent people from using their own.
As a bonus OpenVPN has the "port-share" option which allows you to share the port with other services like an SSL web server. SSLH is also an option if you want to host both your VPN and a HTTPS site on TCP 443.
Otherwise, I really like the premise of Tailscale for quick and easy implementation.
[0]: https://docs.opnsense.org/manual/how-tos/wireguard-client.ht...
Outline/Shadowsocks has better chances to keep working (though it is not a true vpn, more like a private proxy) https://getoutline.org/
wireguard is fingerprintable. it's trivial to look at packets and see "this is wireguard". and block the packets
Outline traffic looks much more like noise (pre-shared keys, lack of handshake, …)
I'm not familiar with the software, but according to Wikipedia it's a client to connect to a SOCKS5 proxy:
> Shadowsocks is not a proxy on its own, but (typically) is the client software to help connect to a third-party SOCKS5 proxy, which is similar to a Secure Shell (SSH) tunnel.
Are you saying that's incorrect?
shadowsocks puts a solid cryptolayer on top of it, designed specifically to be hard to detect. its Chinese origin gives a hint here: it is created to circumvent detection by "great firewall"
outline builds a user-friendly toolset on top of it
Not that it massively matters if you are happy with PiVPN of course, but understanding more may help you diagnose issues should PiVPN ever fail.
> Rosenpass is a key-exchange protocol using techniques that are secure against attacks from quantum computers. It achieves the same security guarantees as WireGuard, using two strong post-quantum key exchange methods – Classic McEliece and Kyber.
> To use Rosenpass, you don't have to get rid of WireGuard; Rosenpass handles post-quantum security, WireGuard handles pre-quantum security and high-speed data transmission.
But after that, key and config management becomes a bit more challenging.
I have a bout 14 devices on a VPN, so that uses ansible to make sure all the keys are where they should be, and can be rotated if needs be.
I piggybacked onto the original configuration file format and built myself https://github.com/WolleTD/wg-setup, which helps me validating the correctness and uniqueness of new entries, hacks names into the entries and even updates an internal DNS zone.
I really don't have to care much for key rotation, though. As most of the devices are out of our control anyway, they aren't allowed to connect to anything inside the VPN. It's just for us to connect to them.
I do wish Tinc had a slightly easier onboarding process, but once it's up, there's a great deal of stuff that I see people dealing with that Tinc users don't have to much think about, especially, e.g. the Mesh deal.
If you can enumerate all your endpoints into wireguard, and squint, it'll kinda-sorta act like a mesh.
And if you want to go a little crazy with it, You can run https://github.com/m13253/VxWireguard-Generator + babeld, and get routing around failures in the mesh.
Pihole is really a great piece of work. It uses standard components (dnsmasq, standard lists) and does it well. I used to have it in a docker container but moved it to the ISP box when I got a new one (a French ISP called Free provides you with an Internet box that has a built-in VPN (WG or OpenVPN) and allows you to create VMs - this is where I ultimately moved Pihole because it is my DNS and DHCP server)
Or I could just set it up on one tiny server (doesn't have to be a pi, but I happen to have one that isn't doing anything else), point my gateway at it for DNS, and give my whole family + any VPN connections filtering for free.
Works well for testing stuff remotely or messing with VPN configurations on the server itself without leaving it stranded for good.
I still find some websites will block you as your traffic will be originating from a datacenter (if going cloud option like me), but most work. I find this setup also works for some services that do not work via VPNs such as Mullvad.
If you want to talk to other devices check out the `BetweenClients_DROP` setting ("road warrior")
It may appear a bit more flexible option, especially if forwarding all traffic to VPN entirely is undesirable.
One thing that tripped me up on arch linux with KDE Plasma was that importing the downloaded WireGuard configuration didn't work in NetworkManager using the gui. After a bit of tinkering, I finally discovered that you can download the conf file to your computer and then run the following command:
nmcli connection import type wireguard file [CONF_FILE]
That adds it to NetworkManager, making it easy to connect to from the gui.Very early and no docs to speak of yet, but raise an issue if interested. Works with standard WireGuard app on computers/phones, but an integrated app using the API might be in the works …
Zerotier is the arm/arm64-only package that you probably had on your mind.
While possible, many people already give access to their home networks via multi-homed devices they carry in their pockets everywhere they go.
Relying on anything below the application layer for security is not very good these days.
If you use cloudflare for your domain you can use cloudflare-ddns[0] to automatically update your ip if/when it changes.
[1]: https://lists.zx2c4.com/pipermail/wireguard/2018-September/0...
[2]: https://gfw.report/publications/usenixsecurity23/en/#sec:res...
I tried setting up a Wireguard site-to-site tunnel for $WORKs Chinese office to access EU office- it stopped working within a day.
[0] https://en.wikipedia.org/wiki/Cybersecurity_Law_of_the_Peopl...
Mostly used to connect few Linux boxes behind NAT or double NAT without opening ports on router. Also running on macOS.
You know you can just do apt install wireguard right?
My requirements for comfortably working from home were:
1. Nothing special needs to be done at work. I don't have to ask for anything new to be installed there, or firewall rules to be changed, or anything like that.
2. I wanted to be able to refer to work machines by the same names they had on the internal network at work, and I wanted to access things on the same ports. A script that worked when run from my office should work with no changes when run from my living room.
3. It only needed to support host:port combinations that were explicitly specified.
Here's what I did. Let's say I've got 3 machines I need to use:
db.example.com: MySQL server
mail.example.com: mail server
web.example.com: web server
I need to use MySQL on the first (port 3306), IMAPS on the second (port 993), and HTTP/HTTPS on the third (ports 80 and 443), and I want to use ssh (port 22) on all of them.I'd ssh to the machine at work that I have ssh access to, with my ssh config file including this:
Host poor_vpn
Hostname ssh.example.com
User tzs
UserKnownHostsFile ~/.ssh/poor_vpn.hosts
LocalForward 7777 db.example.com:22
LocalForward 7778 db.example.com:3306
LocalForward 7779 mail.example.com:22
LocalForward 7780 mail.example.com:993
LocalForward 7781 web.example.com:22
LocalForward 7782 web.example.com:80
LocalForward 7783 web.example.com:443
I'd add this to /etc/hosts: 10.10.10.1 db.example.com
10.10.10.2 mail.example.com
10.10.10.3 web.example.com
(My LAN used 192.168.0.x addresses)Finally, a little ipfw fiddling on my Mac to bring it all together:
ipfw add 100 fwd 127.0.0.1,7777 tcp from any to 10.10.10.1 22
ipfw add 101 fwd 127.0.0.1,7778 tcp from any to 10.10.10.1 3306
ipfw add 102 fwd 127.0.0.1,7779 tcp from any to 10.10.10.2 22
ipfw add 103 fwd 127.0.0.1,7780 tcp from any to 10.10.10.2 993
ipfw add 104 fwd 127.0.0.1,7781 tcp from any to 10.10.10.3 22
ipfw add 105 fwd 127.0.0.1,7782 tcp from any to 10.10.10.3 80
ipfw add 106 fwd 127.0.0.1,7783 tcp from any to 10.10.10.3 443
On Linux that would have been something like this: iptables -t nat -A OUTPUT -p tcp -d 10.10.10.1 --dport 22 REDIRECT --to-port 7777
iptables -t nat -A OUTPUT -p tcp -d 10.10.10.1 --dport 3306 REDIRECT --to-port 7778
iptables -t nat -A OUTPUT -p tcp -d 10.10.10.2 --dport 22 REDIRECT --to-port 7779
iptables -t nat -A OUTPUT -p tcp -d 10.10.10.2 --dport 993 REDIRECT --to-port 7780
iptables -t nat -A OUTPUT -p tcp -d 10.10.10.3 --dport 22 REDIRECT --to-port 7781
iptables -t nat -A OUTPUT -p tcp -d 10.10.10.3 --dport 80 REDIRECT --to-port 7782
iptables -t nat -A OUTPUT -p tcp -d 10.10.10.3 --dport 443 REDIRECT --to-port 7783
That worked great for several years. I've got a script that can take a list of files that describe host:port combination and generate the ssh config, hosts, and ipfw or iptabes rules so it was easy to add or remove machines.It broke in late 2014 when I switch to MacOS Yosemite. Apple had switched to using PF in Lion in 2011 and deprecated ipfw, and removed it in Yosemite. By then we had an openvpn setup at work and I switched to using that.