Be your own VPN provider with OpenBSD
networkfilter.blogspot.com
networkfilter.blogspot.com
$ ssh -D 1080 myserver.myhost.net
Then configure Chrome or Firefox or whatever to use a SOCKS5 proxy on localhost, port 1080. (N.B. that this does not tunnel DNS lookups by default.)
The OpenVPN-based route is the way to go for something used regularly, but the above is sometimes super-convenient!
Very useful.
You can bundle all the configuration for a particular client into a .ovpn file - this includes the client and CA certificates.
I use this on iPhones and iPads, with the OpenVPN iOS app - works great for a family of iOS devices that need access to some geo-locked services.
In firefox you want to go to about:config page and turn on network.proxy.socks_remote_dns
I would think so, but everyone seems to be giving the about:config business, so maybe I am missing something.
network.proxy.socks_remote_dns
which you can toggle to prevent DNS leakage.See "-w" option
Here are a few guides. This is more involved than just adding the -D option and setting a "proxy" field in some applications but this is more general as well:
http://sleepyhead.de/howto/?href=vpn
I was just surprised it was there.
Also, if your connection to the VPN host is quite good, then the TCP-over-TCP issue does not apply as much. The bad cases happen when that connection has packet loss.
sshuttle --dns -r root@XX.XX.XX.XX 0/0 --exclude 192.168.0.0/9
Exclude as used here stops local addresses being tunneled.I hope someone is able to crank out a version that used pf soon.
If you don't trust us and prefer to do it on your own, that's fine too, it's open source: https://github.com/tinfoil/openvpn_autoconfig/blob/master/bi...
For example: http://lowendspirit.com/
Any VPS which provides 'only' IPv6 will typically support outbound IPv4 via NAT, with that IPv4 address being shared between all customers on the same node.
However, another big advantage to a VPN for me is anonimity, not directly giving the site information on who you are. If you were to set this up and use it just for you it's not unthinkable that government organisations like the NSA in Amerika and the AIVD in my homecountry of the Netherlands could identify you pretty easily.
For that I use Private Internet Access[1] right now, they claim to have patched a lot of the important software to have no logging, so they can't keep them. They also share IP addresses between customers which means the IP address is not a form of identification anymore. Their site looks like shit, I agree, but the service is pretty great.
They also have OpenVPN AMI.
Not stopping me, though. I use the VPN when using public WiFis, knowing that my data is protected but that I'm not anonymous.
I.e. Tor IPs typically have very poor 'credit' score.
"Streisand sets up a new server running L2TP/IPsec, OpenSSH, OpenVPN, Shadowsocks, sslh, Stunnel, and a Tor bridge. It also generates custom configuration instructions for all of these services. At the end of the run you are given an HTML file with instructions that can be shared with friends, family members, and fellow activists."
It's a bit easier to configure and supports multiple protocols, including OpenVPN.
I use SoftEther server/client for LAN access for work and home, and it works decently well. (Only thing is things like compression and certificate based authentication only works over SoftEther client, although support for certificate auth for other protocols are on its roadmap.)
[0]https://github.com/OpenVPN/easy-rsa
[1]https://community.openvpn.net/openvpn/wiki/EasyRSA3-OpenVPN-....
https://github.com/Nyr/openvpn-install
You can turn off logging on the server with
/etc/openvpn/server.conf
log /dev/null
status /dev/null
Remember to restart the openvpn service after that.That said, this wouldn't deal with the VPS provider's logging etc.
I use it along with the openvpn ios app on my phone when I'm on corporate wifi, or I connect to it with my laptop any time I'm in a coffee shop. Just note it's meant to tunnel traffic to a "safe" network, not anonymize you on the internet.
1. https://github.com/stephen-mw/raspberrypi-openvpn-auto-insta...
(I bet the roaming between wifi and cellular data could be a problem, though.)
https://pritunl.com https://medium.com/pritunl-tutorials/pritunl-tutorial-ed50a5...
Which is why I had to mention IPsec VPN and link to a good article on how to manage it on OpenBSD.
http://www.openbsd.org/cgi-bin/man.cgi/OpenBSD-current/man8/...
Last time I checked there were some nascent projects to do this in a FOSS way, but they weren't complete and most seemed abandoned. Any ideas?
Eventually this will break due to a) DNSsec, and b) encrypted netflix traffic.
Better come up with a more robust VPN solution. DNS hacks will work until Netflix actually cares enough to stop them.
That's why I pay for services, not because I can't follow a tutorial to set them up :)
http://frozenriver.net/SigmaVPN
Last talk on HN about it: https://news.ycombinator.com/item?id=7599091
There seems to be this similar project as well: