VPS hosting directing to homeserver

Wendel talked about this in a recent video, I believe it was last week when he talked about Nextcloud. What I would love to happen is I spin up a VPS which host redirects to my home services. That way when I want to connect to my self hosted services I am connecting to the VPS which will direct to my home server. Basically I am wanting to create a buffer between myself/internet and my home network. I’ve heard this could also be achieved by setting up a DMZ on my network which would separate my services to a separate part of the network, yet I am not sure how to go about this.

I’ve toyed with reasons why I want to do this but mostly I feel I am missing out on security by not having an SSL cert for all of my services, yet I am not clear on how to setup each service with its own separate domain/subdomain.

The services I am currently running that I want accessible from outside my network are:
Emby
Subsonic
Nextcloud
(Soon to include OpenOffice Document Server)

All of these services are running inside of a jail environment and accessible outside the network by using my public IP address and a port open on the router. Inside the network they all have their own assignable IP address per jail.

I’d love to just type in Nextcloud.domain.tech or something of the sort but I’m still hazy on how this works with Apache24. I’ve just poked around Apache24 here the last few days and installed some web-apps (DokuWiki and Firefly-iii) so It’s still very fresh and I’m definitely a new kid on the block with it.

You need to have a vpn connection between your home network and the vps so that you can access your servers from the vps over the VPN. Once you have that working you need to configure iptables on the vps to do NAT and forwarding (ie routing) so that you can create port forwards of the public IP of the vps to point to your local servers.

As for Apache on your webserver you want to create virtual hosts for each subdomain and configure them to redirect to each server.

Okay, I’ve started to work down this road to get the services all set up. I have gotten as far as getting my domain name registered and having a simple wiki loaded along with a reverse proxy for an additional service. The issue I am having now is the additional service, subsonic, operates off of port 4040. I want to map this in the reverse proxy, in order to type: mydomain.com/subsonic and it go directly to subsonic. Currently I can only get it to work if I type mydomain.com:4040. Here is the code for my reverse proxy as it stands:

< VirtualHost 4040:80>
ServerName mydomain.com/subsonic
ServerAlias mydomain.com/subsonic
ProxyPreserveHost On
RequestHeader set Host ^http://mydomain.com/subsonic (not sure I even need this part)
ProxyRequests Off
ProxyPass / http://192.168.0.44:4040
ProxyPassReverse / http://192.168.0.44:4040
< /VirtualHost>

I can tell you how to get it so if you go to subsonic.mydomain.com it will work, I’m not 100% sure about how to get it to work with mydomain.com/subsonic. I’m sure it’s possible but I’ve never tried.

if you want to get it working with subsonic.mydomain.com this is how you do it:

First you’ll need to create a subdomain on your DNS for subsonic.mydomain.com that points to the server IP (or use CNAME anf just set it to mydomain.com, if it’s the same address).

Then create this config file for apache under /etc/apache/sites-avaliable/subsonic.conf

<VirtualHost *:80>
ServerName subsonic.mydomain.com
RewriteEngine on
RewriteRule  ^(.*)$ http://192.168.0.44:4040/$1 [P]
</VirtualHost>

then run these commands on your webserver

sudo a2enmod rewrite
sudo a2ensite subsonic
sudo systemctl reload apache2 (or sudo service apache2 reload if you're not using systemd)

and that should work.

What’s the method to make this work outside of my network? Do I need to add in a revere proxy element to it?

You just need to forward port 80 to the webserver and use your public IP for the DNS record. You don’t need a reverse proxy. If you want to use your VPS’s IP address then you need to have a VPN connecting your local network to the VPS and configure port forwarding back to your local network.

I did set the DNS record up with my public IP and set port80 to forward to apache yet when viewed from outside the network the page is blank. I added in the reverse proxy stuff again and it directed fine yet with the reverse proxy I am having trouble with getting the pages to direct and follow correctly to serve the content.

Could it be that my DNS records are not set correctly and that is why the method you showed me isn’t working correctly? I have a feeling I didn’t setup subdomains right.

I don’t know if your subdomain is set up properly, just make sure it points to your public IP.

Try this, I googled apache subsonic redirect

<VirtualHost *:80>
    ServerName subsonic.mydomain.com
    <Location />
        ProxyRequests off
        RequestHeader unset Accept-Encoding
        ProxyPass http://192.168.0.44:4040/
        ProxyPassReverse http://192.168.0.44:4040/
        Order allow,deny
        Allow from all
    </Location>
<VirtualHost>

Man, that worked! I’ve been beating my head against the wall the last few days just searching the internet reading everything I can get my hands on about this stuff. Subsonic is 1 down now 3 more to figure out. Do you think the same code will work for other services as well? I’ve been really trying to read through the apache documentation on how to set this stuff up. I don’t like being the guy who runs into the forums asking for someone else to fix my problems. Thanks for helping me out.

I think the key part for this config is setting things apart in the location tags and getting the requestheader tags set correctly. I’ll try and read up on that and see what I can find. It’s the one section I didn’t try yesterday.

Edit: It’s never as easy as copy and paste to another virtual host…

Any suggestion to get PHP based applications to proxy correctly? I have an application built heavily around PHP and it doesn’t seem to want to forward correctly. I’ve been using simple ProxyPass parameters to get it to forward without a subdomain yet it doesn’t want to direct correctly.

I’m not sure, just google the specific thing you’re trying to redirect and usually someone else has already done it

I reached out to the developer. I found some info on it and it seems there are some issues with it. Next step for me is getting certificates for all my sites and securing them with SSL. Thank you with your help so far.

SSL is easy. Once you get your certificates change your apache files to add this to the top:

<VirtualHost *:80>
ServerName something.mydomain.com
RewriteEngine on
RewriteCond %{SERVER_PORT} !^443$
RewriteRule ^/(.*) https://%{HTTP_HOST}/$1 [NC,R,L]
</VirtualHost>

Change servername to whatever subdomain it is for. This will take any incoming connection to the webserver on port 80 and redirect it to port 443 and force it to use ssl. If you don’t want that then don’t add this, and instead have two virtualhost entries, one for port 80 and the other for port 443.

Then bellow that modify your original virtual host entry, first changing it from *:80 to *:443 then adding the lines for ssl. So for the one for subsonic it should look like this:

<VirtualHost *:80>
    ServerName subsonic.mydomain.com
    RewriteEngine on 
    RewriteCond %{SERVER_PORT} !^443$
    RewriteRule ^/(.*) https://%{HTTP_HOST}/$1 [NC,R,L]
</VirtualHost>
<VirtualHost *:443>
    ServerName subsonic.mydomain.com
    SSLEngine on
    SSLCertificateFile /path/to/cert
    SSLCertificateKeyFile /path/to/key
    SSLCertificateChainFile /path/to/CA
    <Location />
        ProxyRequests off
        RequestHeader unset Accept-Encoding
        ProxyPass http://192.168.0.44:4040/
        ProxyPassReverse http://192.168.0.44:4040/
        Order allow,deny
        Allow from all
    </Location>
<VirtualHost>

Where the CA is the CA for wherever you got your certificate from or the intermediate CA (they will probably give you one of these when you get the certificate, just use that. It may work fine without this but for me at least I needed to add it)

This is another version with the SSL settings I use to harden the SSL security but the above version is the default that should work fine.

<VirtualHost *:80>
    ServerName subsonic.mydomain.com
    RewriteEngine on 
    RewriteCond %{SERVER_PORT} !^443$
    RewriteRule ^/(.*) https://%{HTTP_HOST}/$1 [NC,R,L]
</VirtualHost>
<VirtualHost *:443>
    ServerName subsonic.mydomain.com
    SSLEngine on
    SSLProtocol ALL -SSLv2 -SSLv3
    SSLHonorCipherOrder on
    SSLCipherSuite ECDH+AESGCM:DH+AESGCM:ECDH+AES256:DH+AES256:ECDH+AES128:DH+AES:ECDH+3DES:DH+3DES:RSA+AESGCM:RSA+AES:RSA+3DES:!aNULL:!MD5:!DSS
    SSLCertificateFile /path/to/cert
    SSLCertificateKeyFile /path/to/key
    SSLCertificateChainFile /path/to/CA
    SSLCompression off
    Header always set Strict-Transport-Security "max-age=15768000"
    <Location />
        ProxyRequests off
        RequestHeader unset Accept-Encoding
        ProxyPass http://192.168.0.44:4040/
        ProxyPassReverse http://192.168.0.44:4040/
        Order allow,deny
        Allow from all
    </Location>
<VirtualHost>

SSLUseStapling on
SSLStaplingReturnResponderErrors off
SSLStaplingCache "shmcb:logs/stapling-cache(15000)"

Awesome! That worked out well. Fit right into my setup. Now all that’s left is fixing up Nextcloud to work. My DNS is all setup and SSL is correct it’s something to do with a handshake issue or my Nextcloud config.php settings. Not sure which. I’ll have to continue searching.

I would leave nextcloud (and everything else) configured to just use http, then configure ssl on Apache for the proxy/redirect. That way it’s encrypted between the user and the server and it’s just the connection between Apache and the service which is http, which is fine. That’s a lot easier than trying to proxy an ssl connection.

Is nextcloud the thing you were having trouble with getting to work with Apache? Because I can share my config if you like.

It is. I’ll have to dig through the config in nextcloud to turn it back to http instead of HTTPS. That’s probably the rub right now.

My apache configuration for next cloud looks like this.

On the nextcloud server I use the default apache configuration except that I change the alias from /nextcloud (or whatever it is) to just / .That way nextcloud is at the root of the server. This is the whole configuration:

Alias / "/var/www/owncloud/"
<Directory "/var/www/owncloud">
  Options +FollowSymLinks
  AllowOverride All

  <IfModule mod_dav.c>
        Dav off
  </IfModule>

  SetEnv HOME /var/www/owncloud
  SetEnv HTTP_HOME /var/www/owncloud
</Directory>

<Directory "/var/www/owncloud/data/">
  # just in case if .htaccess gets disabled
    Require all denied
</Directory>

Then on the main apache server, the one that is web facing, I use this configuration to redirect to nextcloud and enable ssl

<VirtualHost *:80>
        ServerName nextcloud.mydomain.com

        RewriteEngine on
        RewriteCond %{SERVER_PORT} !^443$
        RewriteRule ^/(.*) https://%{HTTP_HOST}/$1 [NC,R,L]
</VirtualHost>

<VirtualHost *:443>
        ServerName nextcloud.mydomain.com
        SSLEngine On
        SSLProtocol ALL -SSLv2 -SSLv3
        SSLHonorCipherOrder On
        SSLCipherSuite ECDH+AESGCM:DH+AESGCM:ECDH+AES256:DH+AES256:ECDH+AES128:DH+AES:ECDH+3DES:DH+3DES:RSA+AESGCM:RSA+AES:RSA+3DES:!aNULL:!MD5:!DSS
        SSLCertificateFile    /path/to/cert
        SSLCertificateKeyFile /path/to/key
        SSLCertificateChainFile /path/to/CA
        SSLCompression off

        Header always set Strict-Transport-Security "max-age=15768000"

        RewriteEngine on
        RewriteRule ^/(.*)$ http://10.1.3.32/$1 [P,L]
</VirtualHost>

SSLUseStapling on
SSLStaplingReturnResponderErrors off
SSLStaplingCache "shmcb:logs/stapling-cache(150000)"

Obviously use the IP of your nextcloud server in the rewrite rule

1 Like

I’m a dummy… I have been putting in the wrong internal IP address…could have worked from the begining, but now I am generating HTTPS from my reverse proxy and NC works communicates through HTTP. Oh well live and learn to check things multiple times.

Thank you for your help man. You have been great responding. How did you learn so much about apache? Trial and error or formal training?

1 Like

Yeah, trial and error and google