Leanpub Header

Skip to main content

Modern Linux Home Lab for Self-Hosters Behind CGNAT

Design, Implement, and Troubleshoot Robust Self-Hosted Infrastructure on the Real Internet

Modern Linux Home Lab for Self-Hosters Behind CGNAT
This book is 100% completeLast updated on 2026-09-29

Self-hosting from home sounds simple until CGNAT, changing IPv6 prefixes and double NAT get in the way. This book shows you how to build Linux infrastructure that actually works on the real Internet, with practical architectures, working configurations and troubleshooting techniques that help you understand what is really happening to your packets.

Minimum price

$25.00

$35.00

You pay

Author earns

$

Also available for 1 book credit with a Reader Membership

PDF
EPUB
WEB
APP
176
Pages
About

About

About the Book

This book explains how to design, build, and run self-hosted services on Linux that are accessible from anywhere on the Internet despite the constraints of modern residential broadband: carrier-grade NAT, missing inbound IPv4 connectivity, changing IPv6 prefixes, ISP firewalling, and double NAT. It treats networking as engineering rather than configuration: you will learn how packets move through interfaces, bridges, tunnels, firewalls, and reverse proxies; how Linux makes routing decisions; how WireGuard selects and encrypts traffic; how DNS interacts with routing and service discovery; and how to build architectures that survive real-world connectivity problems using outbound-only tunnels, VPS relays, IPv6 when stable, VPNs for secure access, and reverse proxies as ingress control planes. The book provides complete, internally consistent reference architectures with full working configurations for WireGuard, nftables, systemd-networkd, BIND and CoreDNS, nginx and Caddy, Docker, and SSH, plus systematic troubleshooting methods based on packet-path analysis rather than guesswork.

Author

About the Author

Steve Publications

Steve is a technology professional with more than 20 years of experience in software development, server infrastructure, cybersecurity, vulnerability research and reverse engineering. Throughout his career, he has designed, secured, analyzed and tested complex software and infrastructure, with a particular focus on understanding how systems fail and how they can be made more secure.

Outside of work, Steve enjoys sharing knowledge with the technology community. He collaborates with researchers, industry experts and technology professionals to write practical books covering software development, cybersecurity, cloud computing, networking, DevOps, artificial intelligence and enterprise technologies. His books focus on practical learning through clear explanations, real-world examples and hands-on exercises. With more than two decades of industry experience, his goal is to help IT professionals, students and technology enthusiasts build useful skills and stay current in a rapidly changing industry.

We believe readers deserve to know how our books are created. Most of our authors are not native English speakers, so we use AI to help translate, proofread manuscripts, fix grammar, improve sentence structure and make technical explanations easier to read. AI is used as an editing tool only. It does not replace the research, technical knowledge or hands-on experience behind our books. Some of our authors also prefer to remain anonymous for privacy or professional reasons. In those cases, we publish their work under a different name. The author's name may be different, but the quality of the content and our review process remain the same.

Every book is written, reviewed and maintained by experienced technology professionals, with contributions from our private technical community of more than 420 engineers and researchers. We spend far more time validating technical accuracy and keeping our content up to date than generating text. We are always interested in working with experienced professionals who have deep expertise in a particular technology or domain. If you would like to publish a book with us or help review an existing manuscript, we'd love to hear from you. Send us a message describing your area of expertise. We are especially interested in niche technologies, specialized skills and emerging topics that are underrepresented in existing technical literature.

If you look through the contents of our books, you'll see practical examples, detailed explanations and material that is regularly updated. Our goal is to publish books that professionals can actually rely on, not low-effort AI-generated content. If you ever feel that one of our books does not meet that standard, Leanpub offers a 60-day money-back guarantee. Feel free to request a refund if you are not satisfied with your purchase.

Contents

Table of Contents

Design, Implement, and Troubleshoot Robust Self-Hosted Infrastructure on the Real Internet

Introduction: Why Self-Hosting Is a Networking Problem

Chapter 1: The Self-Hosting Connectivity Problem

  1. The Promise and the Gap: Why Self-Hosting Is Harder Now Than Five Years Ago
  2. Residential Internet Topologies: What Your ISP Actually Gives You
  3. The Three Core Problems: No Inbound IPv4, Unstable IPv6, Broken DNS Assumptions
  4. What This Book Will Not Assume
  5. How to Use This Book

Chapter 2: How the Internet Connects to Your Home

  1. The ISP Edge: Broadband Network Gateways, DSLAMs, OLTs, and Cable Modems
  2. Customer Premises Equipment: Routers, Modems, and the Home Gateway Problem
  3. Your LAN Topology: Single Router, Multiple Routers, and Double NAT
  4. Packet Path from Your Server to the Internet and Back
  5. Where Restrictions Happen: ISP-Imposed Constraints on Inbound Traffic
  6. Identifying Your Actual Topology: Discovery Techniques

Chapter 3: IP Addressing, IPv4 Exhaustion, and CGNAT

  1. Public vs Private IP Addresses and RFC 1918
  2. IPv4 Exhaustion: Timeline, Impact, and Why It Matters to You
  3. Carrier-Grade NAT: How It Works and What It Hides
  4. CGNAT vs Double NAT: How to Tell the Difference
  5. The Self-Hosting Impact: Why Port Forwarding Fails Under CGNAT
  6. Living With CGNAT: Options and Trade-Offs

Chapter 4: Linux Networking Fundamentals

  1. Network Interfaces: Physical, Virtual, Loopback, and Tunnel Interfaces
  2. IP Address Configuration: Interfaces, Addresses, and Scope
  3. The Routing Table: How Linux Decides Where to Send Packets
  4. Forwarding, Connection Tracking, and the Netfilter Stack
  5. Network Namespaces: Isolation, VRFs, and Virtual Routers
  6. Inspecting State: ip, ss, route, and the /proc/net Interface

Chapter 5: DNS as Infrastructure

  1. Recursive vs Authoritative DNS and the Resolution Chain
  2. Local DNS Resolution on Linux: systemd-resolved, NetworkManager, and resolv.conf
  3. DNS Record Types That Matter: A, AAAA, CNAME, SRV, TXT, PTR
  4. Caching, TTLs, and Stale DNS Problems
  5. Split-Horizon DNS: Resolving Internally and Externally Differently
  6. DNSSEC: Concepts and Practical Reality for Self-Hosters
  7. DNS, Certificates, and SNI: The Trust Chain

Chapter 6: Firewalls, nftables, and Connection Tracking

  1. Netfilter: Hooks, Chains, and the Packet Path Through the Kernel
  2. nftables Syntax: Tables, Chains, Sets, Maps, and Rules
  3. Connection Tracking: States, Expectations, and Stateful Filtering
  4. Default Policies: Deny, Allow, and Reasonable Middle Ground
  5. NAT in nftables: SNAT, DNAT, Masquerade, and Hairpin
  6. Logging, Rate Limiting, and Detecting Reconnaissance
  7. Firewall Design for Self-Hosted Environments

Chapter 7: Linux Routing Engineering

  1. Route Selection: Longest Prefix Match and Route Metrics
  2. Multiple Routing Tables: Main, Local, and Custom Tables
  3. Policy-Based Routing: fwmark, Sources, and Destinations
  4. Asymmetric Routing: Causes, Symptoms, and Solutions
  5. VRFs and Network Namespaces for Traffic Separation
  6. Debugging Routing Problems: tracepath, traceroute, and tcpdump Correlation
  7. Common Routing Mistakes in Self-Hosting

Chapter 8: IPv6 for Self-Hosting

  1. IPv6 Addressing: Global Unicast, Link-Local, Unique Local, and Special Ranges
  2. SLAAC, Router Advertisements, and Stateless Address Assignment
  3. DHCPv6 and Stateful IPv6 Configuration
  4. IPv6 Prefix Delegation: How It Works and Why It Matters
  5. Stable Addresses: DHCPv6-PD with Static Lease, Stable SLAAC, and Trade-Offs
  6. Firewalling IPv6: Common Mistakes and Complete Policies
  7. IPv6, DNS, and Certificates: AAAA Records and SNI
  8. When Your ISP Changes the Prefix: Detection, Reaction, and Automation

Chapter 9: NAT and Port Forwarding Mechanics

  1. How NAT Works: Packet Rewriting, State Tables, and Port Mapping
  2. Port Forwarding: Configuration, Topology, and Packet Flow
  3. Hairpin NAT and NAT Loopback: Why It Fails by Default
  4. NAT Traversal Assumptions: Cone NAT, Symmetric NAT, and Endpoint Independence
  5. When Port Forwarding Fails: CGNAT, ISP Blocking, and Port Conflicts
  6. NAT and IPv6: The Fundamental Incompatibility

Chapter 10: WireGuard Fundamentals

  1. WireGuard Protocol: Noise Framework, Encryption, and Handshake
  2. Key Generation and Identity: The Public-Key Model
  3. Configuration Semantics: ListenPort, Endpoint, and AllowedIPs
  4. How AllowedIPs Works: Routing Decisions and Traffic Selection
  5. WireGuard and the Linux Kernel: Tunnel Interfaces and Routing
  6. Persistent Keepalives: Why They Exist and When You Need Them
  7. Common Configuration Mistakes and Their Symptoms
  8. WireGuard Monitoring with wg and wg-queue

Chapter 11: VPN Architectures for Self-Hosting

  1. Road-Warrior Access: Remote Client to Home Network
  2. Full-Tunnel vs Split-Tunnel: Security, Performance, and Convenience
  3. Site-to-Site VPNs: Connecting Segments and Branches
  4. Hub-and-Spoke vs Mesh Topologies
  5. Subnet Routing Through WireGuard: AllowedIPs as Route Control
  6. WireGuard with NAT Behind the VPN: Client and Server Considerations
  7. Comparing WireGuard, IPsec, and OpenVPN for Self-Hosting

Chapter 12: Reverse Tunnels and Outbound-Only Connectivity

  1. The Outbound-Only Strategy: Why Tunnel Out Instead of Waiting Inbound
  2. SSH Reverse Tunnels: Local Port Forwarding in Reverse
  3. Reverse WireGuard: Client-Initiated Connections to a VPS Server
  4. Relay Architectures: VPS as Public Ingress, Tunnel Back Home
  5. Rendezvous and Hole Punching: When and Why They Work
  6. Managed Reverse Tunnel Services: Tailscale, ZeroTier, Cloudflare Tunnel, and Alternatives
  7. Designing a CGNAT-Safe Architecture Using Reverse Tunnels

Chapter 13: Dynamic DNS and Name Resolution for Self-Hosters

  1. Dynamic DNS: How It Works and Provider Options
  2. Self-Hosted Authoritative DNS: BIND, CoreDNS, and dnsmasq
  3. Split-Horizon DNS Implementations: Internal vs External Records
  4. Service Discovery in Homelabs: mDNS, DNS-SD, and Simple DNS-Based Approaches
  5. Wildcard Certificates and Dynamic DNS: Combining Them
  6. Handling IPv6 Prefix Changes with DNS: Automation and Scripting
  7. DNS over TLS and DNS over HTTPS for Resolver Privacy

Chapter 14: Reverse Proxies as Internet Ingress

  1. The Reverse Proxy Role: Ingress Control, TLS Termination, and Backend Routing
  2. HTTP Reverse Proxying: Host Headers, Paths, and Upstream Routing
  3. TCP Proxying: Exposing Non-HTTP Services Through a Single Ingress
  4. SNI and Multi-Domain TLS Termination
  5. TLS Certificates: ACME, Certbot, Let’s Encrypt, and Automation
  6. Authentication, Headers, and Trust: Forwarding Auth and Preserving Client Info
  7. Rate Limiting, Access Control, and Protection at the Edge
  8. Comparing nginx, Caddy, and HAProxy for Self-Hosting Ingress

Chapter 15: Container Networking for Self-Hosted Services

  1. Docker Networking Drivers: Bridge, Host, None, and Overlay
  2. Docker Bridge Networks: NAT, Port Publishing, and Packet Flow
  3. Container-to-Host Communication and Host Firewall Interactions
  4. Docker Compose Networking: Services, Internal Networks, and DNS
  5. Network Policies and Container Isolation
  6. Running WireGuard and Tunnels in Containers
  7. Container Networking Best Practices for Self-Hosting

Chapter 16: Reference Architecture One: Single Machine Home Server

  1. Requirements and Design Decisions
  2. Network Topology and Addressing
  3. Base System: Interfaces, Routing, and nftables Firewall
  4. DNS Configuration: Domain, Records, and Resolution
  5. Reverse Proxy: nginx or Caddy with TLS Automation
  6. Service Deployment: Example Services and Exposure
  7. Security Hardening: SSH, User Accounts, and Least Privilege
  8. Operational Checklist and Troubleshooting Hints

Chapter 17: Reference Architecture Two: Multi-Host Homelab with VPN Access

  1. Requirements: Segmentation, Remote Access, and Internal Communication
  2. Network Topology: Subnets, Gateways, and Addressing Plan
  3. WireGuard VPN: Road-Warrior and Hub-and-Spoke Configuration
  4. Internal DNS: Authoritative Resolution Across Subnets
  5. Inter-Subnet Routing and Firewall Policy
  6. Reverse Proxy Across Multiple Backend Servers
  7. Container Host Integration: Docker on the Homelab Network
  8. Complete Working Configuration: All Components Integrated

Chapter 18: Reference Architecture Three: CGNAT Survival With VPS Relay

  1. Requirements: No Inbound IPv4, Unreliable IPv6, Full Public Access
  2. VPS Selection and Cost Considerations
  3. Reverse WireGuard Tunnel: Server on VPS, Client at Home
  4. Route Propagation: Which Traffic Goes Through the Tunnel
  5. DNS and Dynamic DNS With the VPS as Authoritative Edge
  6. Reverse Proxy on VPS: Terminating TLS and Forwarding Through Tunnel
  7. IPv6 as Primary When Available: Failover and Dual-Stack Strategy
  8. Security Model: Trust Boundaries, Tunnel as Perimeter, and Risk Assessment
  9. Complete Working Configuration

Chapter 19: Reference Architecture Four: IPv6-Enabled Homelab With Dynamic Prefix

  1. Requirements: Stable Self-Hosting With a Changing Delegated Prefix
  2. Prefix Delegation Configuration: systemd-networkd, radvd, and DHCPv6
  3. Stable Address Assignment: DHCPv6-PD With Static Leases
  4. DNS Automation: Updating Records When the Prefix Changes
  5. nftables Policies for IPv6: Matching Both Families
  6. Reverse Proxy With IPv6 and AAAA Records
  7. IPv6 Firewalling Mistakes to Avoid
  8. Complete Working Configuration

Chapter 20: Security Architecture for Self-Hosted Infrastructure

  1. Threat Modeling for Self-Hosters: What You Are Protecting Against
  2. Attack Surfaces: Internet-Facing Services, VPNs, and Internal Services
  3. Network Segmentation as Defense: Isolating Critical Services
  4. Least Privilege: Services, Users, Containers, and Tunnels
  5. SSH Hardening: Keys, Configuration, and Access Patterns
  6. VPN Key Management: Rotation, Revocation, and Multi-Peer Policies
  7. TLS Lifecycle: Certificate Renewal, Revocation, and Monitoring
  8. Secrets Management in Self-Hosting: Avoiding Hardcoded Credentials
  9. Logging, Monitoring, and Intrusion Detection
  10. IPv6 Exposure: The Forgotten Attack Surface
  11. Supply Chain and Container Image Security
  12. The Difference Between Being Reachable and Being Secure

Chapter 21: Observability and Systematic Troubleshooting

  1. Troubleshooting Methodology: From Symptom to Packet Path
  2. Essential Tools: ip, ss, tcpdump, dig, nft, conntrack, traceroute, curl, openssl
  3. Reading tcpdump Output: Filtering, Decoding, and Following Connections
  4. Diagnosing DNS Problems: dig, resolvectl, and Cache Issues
  5. Diagnosing Firewall Blocks: nft Logs, conntrack State, and Rule Tracing
  6. Diagnosing Routing Problems: ip route, Policy Routing Checks, and Asymmetry
  7. Diagnosing WireGuard Problems: wg Show, Endpoint Reachability, and AllowedIPs
  8. Diagnosing Reverse Proxy Issues: Upstream Failures, SNI, and Protocol Mismatch
  9. Common Failure Scenarios and Their Diagnoses
  10. Building Observability: Logging, Metrics, and Alerting for Self-Hosted Networks

Chapter 22: Operations, Reliability, and Future-Proofing

  1. System Updates: Patching Without Downtime for Critical Services
  2. Configuration Management: Git, Ansible, or Script-Based Approaches
  3. Backups: Configuration, Data, Keys, and Recovery Procedures
  4. Monitoring: Uptime Checks, Service Health, and Alerting
  5. Handling ISP Changes: Address Changes, Prefix Changes, and Topology Changes
  6. Disaster Recovery: When the Home Server Is Unreachable
  7. Documentation: Documenting Your Architecture While It Is Fresh
  8. Future Trends: What Self-Hosters Should Watch

Conclusion

References

Get the free sample chapters

Click the buttons to get the free sample in PDF or EPUB, or read the sample online here

The Leanpub 60 Day 100% Happiness Guarantee

Within 60 days of purchase you can get a 100% refund on any Leanpub purchase, in two clicks.

See full terms...

Earn $8 on a $10 Purchase, and $16 on a $20 Purchase

We pay 80% royalties on purchases of $7.99 or more, and 80% royalties minus a 50 cent flat fee on purchases between $0.99 and $7.98. You earn $8 on a $10 sale, and $16 on a $20 sale. So, if we sell 5000 non-refunded copies of your book for $20, you'll earn $80,000.

(Yes, some authors have already earned much more than that on Leanpub.)

In fact, authors have earned over $15 million writing, publishing and selling on Leanpub.

Learn more about writing on Leanpub

Free Updates. DRM Free.

If you buy a Leanpub book, you get free updates for as long as the author updates the book! Many authors use Leanpub to publish their books in-progress, while they are writing them. All readers get free updates, regardless of when they bought the book or how much they paid (including free).

Most Leanpub books are available in PDF (for computers) and EPUB (for phones, tablets and Kindle). The formats that a book includes are shown at the top right corner of this page.

Finally, Leanpub books don't have any DRM copy-protection nonsense, so you can easily read them on any supported device.

Learn more about Leanpub's ebook formats and where to read them

Write and Publish on Leanpub

You can use Leanpub to easily write, publish and sell in-progress and completed ebooks and online courses!

Leanpub is a powerful platform for serious authors, combining a simple, elegant writing and publishing workflow with a store focused on selling in-progress ebooks.

Leanpub is a magical typewriter for authors: just write in plain text, and to publish your ebook, just click a button. (Or, if you are producing your ebook your own way, you can even upload your own PDF and/or EPUB files and then publish with one click!) It really is that easy.

Learn more about writing on Leanpub