It will work for a bit, then they will detect VPN traffic and just block the destination ip for good. Any ip you will use will be shortly unreachable for you, so be prepared to that.
Shimitar
LOL you madre me laugh...
Anyway being security conscious is important, and better be safe than sorry...
100% agree.
One point: use an SSO like authelia or authentic. Way better than basic auth and you get the fancy login form too preserving all the benefits, and you can also use OIDC with those services that require more complex setup for proper auth
Yes. The fearmongering of the security freaks is not necessarily true. We selfhosters are not big targets and nobody cares about our files or our devices.
Of course, until you get hacked.
But beside SMTP and ssh and known services like WordPress or PrestaShop there is little actual brute force bots trying hard.
Thank you! This is exactly why I do my wiki, so that people can use and benefit from the work I did before.
Mmm as for the admin console, I will add that, it had slipped from my wiki it seems!
My personal experience with conduwuit is very positive.
Everything worked including sliding sync for Element X.
Bridges works fine. Threads too (limited to client support ofc), session verification works fine, element call never tried, you need to install a dedicated server anyway, but that's true also for synapse.
I was replying to the links post, must have got it wrong :)
So yes, I ended up thanking myself. Well, I always thanks myself anyway for not having screwed up too badly anyway so... ;)
Currently just setup conduwuit, tuwunel will require some more time to be up and ready, but they promised full compatibility upgrade.
See my wiki https://wiki.gardiol.org/doku.php?id=matrix%3Aconduwuit
There are also instructions for all main bridges.
Synapse is meant for heavy duty and is a pretty resource intensive python implementation.
Conduwuit and derivate is in rust and blazing fast on small footprint.
Tuwunel, the sequel of conduwuit.
Go with conduwuit today, then upgrade to tuwunel as soon as they release.
There is a post about that in this community.
Why synapse?
Its a good choice for max stability, but its by far the heaviest and most resource intense server out there, and probably overkill for a few user installation.
Deep level packet inspection, they detect patterns or whatever in encrypted traffic (and the lack of thereof) and ban the destination ip china-wide.
How they do I have no idea, but they do, on my direct first hand experience. Its not based on domain names, directly straight and total ip ban. All ports, all domains on that ip get banned forever just because you started using a VPN (OpenVPN in my case, it was a few years ago).