Alexandre Oliva (moving to @lxo@snac.lx.oliva.nom.br) (lxo@gnusocial.jp)'s status on Monday, 20-Jan-2025 13:46:18 JST
-
Embed this notice
aah, globally routable addresses? yeah, that requires some extra care indeed. now, this brought openswan (?) tunnels to mind; I recall reading some docs that IIRC were meant ot address this kind of scenario, but that was way too long ago (I guess 20+ years), the memory is too dim, I'm not even sure it would be useful any more :-(
I'd probably still go with openvpn, and add safeguards such as blackhole routes and firewalling on both ends to avoid leaks, if I had to deal with public IP addresses. but it would all be much safer without public IP addresses.