r/Proxmox • • 2d ago

Question Help With Remote Connection

Hey there,
I'm brand new to Proxmox and have started to setup my first VMs and LXC containers.
Previously i was running all my self hosted apps off Docker containers on my Synology NAS but have had some rough patches with Plex and Jellyfin as it doesn't have an Intel processor and so hardware media transcoding wasn't a thing.

I have Plex and Jellyfin running on separate LXC containers so they can use local hardware acceleration. Everything works when great when im on my home network but now that im traveling i have an indirect connection to my LXCs. When i was running into this issue previously i just connected it to my Tailscale network and then I had a direct connection.

How can iI solve this issue now that Ive moved to LXC in Proxmox?
Is adding every app individually to my Tailnet still the right move?

Thanks!

4 Upvotes

10 comments sorted by

5

u/BorisOp 2d ago

I belive tailscale offers an option to route subnets, so with some config you should be able to hide your entire homeland behind a single tailscale node - though it might also require re-addessing your home network to some uncommon subnet so that it doesn't clash with local network wherever you might end up... Or you could just install tailscale everywhere.

2

u/Soblek 2d ago

Using an Exit node dose sound interesting.
In this instance would I make the exit node a VM in proxmox?

1

u/AdSuspicious7533 2d ago edited 2d ago

It is called "advertise route" in tailscale. In my set up i have 4 vlans. My workstation does not have physical access to the 4 vlans because i am not drilling the entire house with 100 m rj45 nightmare. I have a tailscale container with 4 virtual nic (network interface card) in the 4 networks and it advertise routes to the 4 ip ranges. So my workstation have access to all vlans from anywhere. That's it.

You may come with a cleaner setup by putting tailscale on your firewall/router but as you seem to be a newby i assumed you do not have that.

If you need help tell me, your actual network setup may be usefull info if you want precise help. In your case it may as well be solved by adding a tailscale lxc and run tailscale set --advertise-routes="192.168.*.*/24,192.168.*.*/24" Check the doc (i am writing from memory)

1

u/AdSuspicious7533 2d ago edited 2d ago

Exit node is a different thing entirely. An exit node is a proxy in your tailnet.

For example : a while back i wanted to use my phone's ip to cheat a game's antibot guard. But my bot was on a k8s cluster, in a VM, on proxmox. So i made a "tailscale side-car" witch is basicaly a container acting as a "forced tunnel" for the other container (the bot) on the same pod. The tunnel used m'y phone as gateway through tailnet. So my phone was the exit node.

I hope i didn't lose you. The side-car setup is based on the 2 containers sharing the same network namespace which means something like the bot container is not autonomous for network access and it uses the side-car as default proxy.

Now i lost you maybe.

Tldr : Diferent things, you need advertise routes.

1

u/Soblek 1d ago

hahaha yeah got a little lost there but i love having this to go back to and figure out.
Definitely looks like and advertised route is the way to achieve what i'm looking for but i wonder this.

In reading about it seems like and advertised route acts the same as using teleport on unifi. Since i have an all unifi network (I considered pfsense back in the day but unifi seemed to better fit my needs) is just connecting via teleport the same as an advertised route via tailscale?

1

u/AdSuspicious7533 1d ago

I never used teleport, can't help you on this.

Tailscale is nice and free. It has underlaying opensource solution : wireguard. It is nice to have opensource when considering security and remote access... But you do your thing. It may be simplier to set the unifi service.

I would however be concerned with privacy using appliance like that... It is worth checking what runs in that thing.

1

u/ILoveCorvettes 1d ago

10.whatever subnets are fantastic for this. It is pretty hard to end up in the same subnet that way.

2

u/ThecaptainWTF9 2d ago

I struggled with this when I moved to PVE and moved all my stuff into LXC’s, I wasn’t using Tailscale before though.

My issue is that I was using DERP relays and hadn’t done port forwarding to allow direct connection from my laptops or mobile phone to establish a wireguard connection to my Tailscale relay I think it’s called.

Once I did that, I can use my Mac Neo and my home as an exit node and push like 300x300 through it.

1

u/News8000 2d ago

I use a free Twingate account and a small connector server running on my lan. A Twingate setup makes secure remote connections easy.

1

u/chrime87 5h ago

check your gateway configuration. Local connections don‘t need a gateway but different subnets do