• Welcome to TechPowerUp Forums, Guest! Please check out our forum guidelines for info related to our community.

Want to setup machine on public static IP

Joined
Jan 13, 2016
Messages
110 (0.04/day)
Hi Guys,

Good day!

I want to setup my machine on public IP so that it can be accessed from any where in the world through Internet.

1. I asked about such static public IP to my Internet provider, he says that any IP address that starts with 74.*.*.* is static IP, thats means when I start my PC it dials in automatically to get IP and if it gets
74.*.*.* IP address that's means it static IP until I logout.

2.So can I setup my VMware server on that IP address just to check whether it works ? Will it work?

3. I want to build VMware server on Windows 7 machine and then install 4 to 5 virtual machines on that like Solaris, Linux. just like test lab.

Thanks.
 

Kursah

Super Moderator
Staff member
Joined
Oct 15, 2006
Messages
14,677 (2.29/day)
Location
Missoula, MT, USA
System Name Kursah's Gaming Rig 2018 (2022 Upgrade) - Ryzen+ Edition | Gaming Laptop (Lenovo Legion 5i Pro 2022)
Processor R7 5800X @ Stock | i7 12700H @ Stock
Motherboard Asus ROG Strix X370-F Gaming BIOS 6203| Legion 5i Pro NM-E231
Cooling Noctua NH-U14S Push-Pull + NT-H1 | Stock Cooling
Memory TEAMGROUP T-Force Vulcan Z 32GB (2x16) DDR4 4000 @ 3600 18-20-20-42 1.35v | 32GB DDR5 4800 (2x16)
Video Card(s) Palit GeForce RTX 4070 JetStream 12GB | CPU-based Intel Iris XE + RTX 3070 8GB 150W
Storage 4TB SP UD90 NVME, 960GB SATA SSD, 2TB HDD | 1TB Samsung OEM NVME SSD + 4TB Crucial P3 Plus NVME SSD
Display(s) Acer 28" 4K VG280K x2 | 16" 2560x1600 built-in
Case Corsair 600C - Stock Fans on Low | Stock Metal/Plastic
Audio Device(s) Aune T1 mk1 > AKG K553 Pro + JVC HA-RX 700 (Equalizer APO + PeaceUI) | Bluetooth Earbuds (BX29)
Power Supply EVGA 750G2 Modular + APC Back-UPS Pro 1500 | 300W OEM (heavy use) or Lenovo Legion C135W GAN (light)
Mouse Logitech G502 | Logitech M330
Keyboard HyperX Alloy Core RGB | Built in Keyboard (Lenovo laptop KB FTW)
Software Windows 11 Pro x64 | Windows 11 Home x64
You should use a VPN service so your traffic is managed and encrypted to your home network.

What are you using as a gateway/firewall? That should be giving out IP addresses to your virtual machines and connected devices rather than you connecting a PC directly to your modem. You are really asking for it if you have no filtering beyond the standard Windows firewall. It is fine as a supplement, but you need a gateway firewall between your LAN and WAN.

You want to be very careful allowing outside traffic in, so an encrypted VPN tunnel makes sense here. I would look into IPSec or OpenVPN. OpenVPN will probably be the easiest option, I recommend doing it under Linux (Ubuntu or Debian) or pfSense though. You could actually host the OpenVPN server as a VM once you get your VM core up. You will have to learn how to handle virtual NICs and switches, but that's pretty easy stuff to manage and there's a ton of articles and YouTube videos out there you can watch.

I run a PC (see my system specs) with home-grade parts as my Server 2012 R2 GUI core Hyper-V host. I run anywhere between 6-8 VM's on it, including a pfSense OpenVPN server.

Even if your public IP isn't static, you can use a Dynamic DNS service like Afraid.org and then use DNS-O-Matic.com to link it to your IP address and update the A-record for your DDNS address...I do that and run a script on my EdgeRouter Lite to automatically update. You can also run an app on Windows/Linux/Mac OSes iirc.
 
Joined
Jan 13, 2016
Messages
110 (0.04/day)
"You should use a VPN service so your traffic is managed and encrypted to your home network."

What kind of VPN software I can use? Is it free?

"You want to be very careful allowing outside traffic in, so an encrypted VPN tunnel makes sense here. I would look into IPSec or OpenVPN. OpenVPN will probably be the easiest option, I recommend doing it under Linux (Ubuntu or Debian) or pfSense though."

I want my Host machine to be Windows 7 then how can setup encrypted VPN tunnel under
Linux (Ubuntu or Debian) ?

What is your Hosting machine /software? Is it 2012 R2 GUI core Hyper-V host? I am not familiar with this.

This is very interesting but need to try/learn about it ->"Even if your public IP isn't static, you can use a Dynamic DNS service like Afraid.org and then use DNS-O-Matic.com to link it to your IP address and update the A-record for your DDNS address...I do that and run a script on my EdgeRouter Lite to automatically update. You can also run an app on Windows/Linux/Mac OSes iirc."
Does this mean that we don't require to buy Static Public IP?
 

Kursah

Super Moderator
Staff member
Joined
Oct 15, 2006
Messages
14,677 (2.29/day)
Location
Missoula, MT, USA
System Name Kursah's Gaming Rig 2018 (2022 Upgrade) - Ryzen+ Edition | Gaming Laptop (Lenovo Legion 5i Pro 2022)
Processor R7 5800X @ Stock | i7 12700H @ Stock
Motherboard Asus ROG Strix X370-F Gaming BIOS 6203| Legion 5i Pro NM-E231
Cooling Noctua NH-U14S Push-Pull + NT-H1 | Stock Cooling
Memory TEAMGROUP T-Force Vulcan Z 32GB (2x16) DDR4 4000 @ 3600 18-20-20-42 1.35v | 32GB DDR5 4800 (2x16)
Video Card(s) Palit GeForce RTX 4070 JetStream 12GB | CPU-based Intel Iris XE + RTX 3070 8GB 150W
Storage 4TB SP UD90 NVME, 960GB SATA SSD, 2TB HDD | 1TB Samsung OEM NVME SSD + 4TB Crucial P3 Plus NVME SSD
Display(s) Acer 28" 4K VG280K x2 | 16" 2560x1600 built-in
Case Corsair 600C - Stock Fans on Low | Stock Metal/Plastic
Audio Device(s) Aune T1 mk1 > AKG K553 Pro + JVC HA-RX 700 (Equalizer APO + PeaceUI) | Bluetooth Earbuds (BX29)
Power Supply EVGA 750G2 Modular + APC Back-UPS Pro 1500 | 300W OEM (heavy use) or Lenovo Legion C135W GAN (light)
Mouse Logitech G502 | Logitech M330
Keyboard HyperX Alloy Core RGB | Built in Keyboard (Lenovo laptop KB FTW)
Software Windows 11 Pro x64 | Windows 11 Home x64
Look up OpenVPN, it is free...this isn't a service you'd buy to connect out, but rather a service you would host and connect to from outside your network. Then you could have secure connections to your workstation from the Internet by providing keys and credentials to those you want to provide access.

There's a lot you need to learn before you go doing anything here, I would recommend looking into OpenVPN and reading up more on virtualization in general.

Windows Server 2012R2 is a Windows-based server OS, Hyper-V is the default virtualization client hosted on that OS...or native client I should say. Works well for my needs. VMWare is also great, Virtualbox is another option, Xen is another good option, and some users also go for KVM for virtualization. There's no easy answer to any of your questions if you don't have the technical know-how already on how to spool up a VM, manage your gateway/router/firewall, etc.

You don't need to buy a static IP if you use a DDNS service, some are free like Afraid.org, some cost money like DynDNS.

For more VPN info, I just recently created a post with links that I'll link you to: http://www.techpowerup.com/forums/threads/vpn-noobie.220462/#post-3424454

Hope that helps! :toast:
 
Joined
Jan 13, 2016
Messages
110 (0.04/day)
*Kursah, You mean to say I can go back home do some setting with afraid.org and keep the PC ON and come back to office and access my home PC, is that possible ? or simple ?
 

Kursah

Super Moderator
Staff member
Joined
Oct 15, 2006
Messages
14,677 (2.29/day)
Location
Missoula, MT, USA
System Name Kursah's Gaming Rig 2018 (2022 Upgrade) - Ryzen+ Edition | Gaming Laptop (Lenovo Legion 5i Pro 2022)
Processor R7 5800X @ Stock | i7 12700H @ Stock
Motherboard Asus ROG Strix X370-F Gaming BIOS 6203| Legion 5i Pro NM-E231
Cooling Noctua NH-U14S Push-Pull + NT-H1 | Stock Cooling
Memory TEAMGROUP T-Force Vulcan Z 32GB (2x16) DDR4 4000 @ 3600 18-20-20-42 1.35v | 32GB DDR5 4800 (2x16)
Video Card(s) Palit GeForce RTX 4070 JetStream 12GB | CPU-based Intel Iris XE + RTX 3070 8GB 150W
Storage 4TB SP UD90 NVME, 960GB SATA SSD, 2TB HDD | 1TB Samsung OEM NVME SSD + 4TB Crucial P3 Plus NVME SSD
Display(s) Acer 28" 4K VG280K x2 | 16" 2560x1600 built-in
Case Corsair 600C - Stock Fans on Low | Stock Metal/Plastic
Audio Device(s) Aune T1 mk1 > AKG K553 Pro + JVC HA-RX 700 (Equalizer APO + PeaceUI) | Bluetooth Earbuds (BX29)
Power Supply EVGA 750G2 Modular + APC Back-UPS Pro 1500 | 300W OEM (heavy use) or Lenovo Legion C135W GAN (light)
Mouse Logitech G502 | Logitech M330
Keyboard HyperX Alloy Core RGB | Built in Keyboard (Lenovo laptop KB FTW)
Software Windows 11 Pro x64 | Windows 11 Home x64
Yes, you keep your home PC on, setup your router/firewall to either act as the VPN server or your PC or virtual machine on PC to act as the VPN server, and then depending on what version you create, be it PPTP, L2TP, IPSec, OpenVPN, etc. etc. you will use the appropriate credentials and/or keys and/or software to connect from a remote location (Office).
 
Joined
Jan 13, 2016
Messages
110 (0.04/day)
Yes, you keep your home PC on, setup your router/firewall to either act as the VPN server or your PC or virtual machine on PC to act as the VPN server, and then depending on what version you create, be it PPTP, L2TP, IPSec, OpenVPN, etc. etc. you will use the appropriate credentials and/or keys and/or software to connect from a remote location (Office).
Let me try!
 

qubit

Overclocked quantum bit
Joined
Dec 6, 2007
Messages
17,865 (2.98/day)
Location
Quantum Well UK
System Name Quantumville™
Processor Intel Core i7-2700K @ 4GHz
Motherboard Asus P8Z68-V PRO/GEN3
Cooling Noctua NH-D14
Memory 16GB (2 x 8GB Corsair Vengeance Black DDR3 PC3-12800 C9 1600MHz)
Video Card(s) MSI RTX 2080 SUPER Gaming X Trio
Storage Samsung 850 Pro 256GB | WD Black 4TB | WD Blue 6TB
Display(s) ASUS ROG Strix XG27UQR (4K, 144Hz, G-SYNC compatible) | Asus MG28UQ (4K, 60Hz, FreeSync compatible)
Case Cooler Master HAF 922
Audio Device(s) Creative Sound Blaster X-Fi Fatal1ty PCIe
Power Supply Corsair AX1600i
Mouse Microsoft Intellimouse Pro - Black Shadow
Keyboard Yes
Software Windows 10 Pro 64-bit
You are really asking for it if you have no filtering beyond the standard Windows firewall.
Yeah you're not kidding! That machine would likely be rooted inside half an hour.

Ultimately, any internet-facing server is under constant threat, so there's no set it and forget it solution. Constant monitoring for suspicious behaviour and system logs is required. This security issue is exactly why I don't make my data available over the internet, as convenient as that would be, not even in read only mode.
 

Kursah

Super Moderator
Staff member
Joined
Oct 15, 2006
Messages
14,677 (2.29/day)
Location
Missoula, MT, USA
System Name Kursah's Gaming Rig 2018 (2022 Upgrade) - Ryzen+ Edition | Gaming Laptop (Lenovo Legion 5i Pro 2022)
Processor R7 5800X @ Stock | i7 12700H @ Stock
Motherboard Asus ROG Strix X370-F Gaming BIOS 6203| Legion 5i Pro NM-E231
Cooling Noctua NH-U14S Push-Pull + NT-H1 | Stock Cooling
Memory TEAMGROUP T-Force Vulcan Z 32GB (2x16) DDR4 4000 @ 3600 18-20-20-42 1.35v | 32GB DDR5 4800 (2x16)
Video Card(s) Palit GeForce RTX 4070 JetStream 12GB | CPU-based Intel Iris XE + RTX 3070 8GB 150W
Storage 4TB SP UD90 NVME, 960GB SATA SSD, 2TB HDD | 1TB Samsung OEM NVME SSD + 4TB Crucial P3 Plus NVME SSD
Display(s) Acer 28" 4K VG280K x2 | 16" 2560x1600 built-in
Case Corsair 600C - Stock Fans on Low | Stock Metal/Plastic
Audio Device(s) Aune T1 mk1 > AKG K553 Pro + JVC HA-RX 700 (Equalizer APO + PeaceUI) | Bluetooth Earbuds (BX29)
Power Supply EVGA 750G2 Modular + APC Back-UPS Pro 1500 | 300W OEM (heavy use) or Lenovo Legion C135W GAN (light)
Mouse Logitech G502 | Logitech M330
Keyboard HyperX Alloy Core RGB | Built in Keyboard (Lenovo laptop KB FTW)
Software Windows 11 Pro x64 | Windows 11 Home x64
I have no problem doing encrypted VPN tunnel access like IPSec or OpenVPN that requires keys or tokens along with credentials...but some form of packet inspection and monitoring should be enabled and regularly checked if said tunnel is going to be active 24/7.

The safest route as qubit said is to not do it at all. But where's the fun in that? Especially in a home lab. :) at least in my case its for a home lab.

:toast:
 
Joined
Jan 13, 2016
Messages
110 (0.04/day)
Well, I saw lot of videos on dynamic dns and how to do that, but I would like to have environment like everything opens through web browser just like console and not with RDP.
 
Joined
Oct 30, 2008
Messages
1,901 (0.34/day)
Processor 5930K
Motherboard MSI X99 SLI
Cooling WATER
Memory 16GB DDR4 2132
Video Card(s) EVGAY 2070 SUPER
Storage SEVERAL SSD"S
Display(s) Catleap/Yamakasi 2560X1440
Case D Frame MINI drilled out
Audio Device(s) onboard
Power Supply Corsair TX750
Mouse DEATH ADDER
Keyboard Razer Black Widow Tournament
Software W10HB
Benchmark Scores PhIlLyChEeSeStEaK
Sammy, see you are getting stuff done and almost solved your need! :toast:
 

OneMoar

There is Always Moar
Joined
Apr 9, 2010
Messages
8,747 (1.70/day)
Location
Rochester area
System Name RPC MK2.5
Processor Ryzen 5800x
Motherboard Gigabyte Aorus Pro V2
Cooling Enermax ETX-T50RGB
Memory CL16 BL2K16G36C16U4RL 3600 1:1 micron e-die
Video Card(s) GIGABYTE RTX 3070 Ti GAMING OC
Storage ADATA SX8200PRO NVME 512GB, Intel 545s 500GBSSD, ADATA SU800 SSD, 3TB Spinner
Display(s) LG Ultra Gear 32 1440p 165hz Dell 1440p 75hz
Case Phanteks P300 /w 300A front panel conversion
Audio Device(s) onboard
Power Supply SeaSonic Focus+ Platinum 750W
Mouse Kone burst Pro
Keyboard EVGA Z15
Software Windows 11 +startisallback
you don't need a vpn todo this,and connecting direct over ip via a web-browser is asking to get hacked
use a DNDNS server or just use team-viewer
 
Joined
May 13, 2010
Messages
5,712 (1.12/day)
System Name RemixedBeast-NX
Processor Intel Xeon E5-2690 @ 2.9Ghz (8C/16T)
Motherboard Dell Inc. 08HPGT (CPU 1)
Cooling Dell Standard
Memory 24GB ECC
Video Card(s) Gigabyte Nvidia RTX2060 6GB
Storage 2TB Samsung 860 EVO SSD//2TB WD Black HDD
Display(s) Samsung SyncMaster P2350 23in @ 1920x1080 + Dell E2013H 20 in @1600x900
Case Dell Precision T3600 Chassis
Audio Device(s) Beyerdynamic DT770 Pro 80 // Fiio E7 Amp/DAC
Power Supply 630w Dell T3600 PSU
Mouse Logitech G700s/G502
Keyboard Logitech K740
Software Linux Mint 20
Benchmark Scores Network: APs: Cisco Meraki MR32, Ubiquiti Unifi AP-AC-LR and Lite Router/Sw:Meraki MX64 MS220-8P
I suggest something like Meraki Systems manager for remote desktop access. It uses the VNC method and it's free. It also randomly generates a password each connection attempt, so it's super secure.Also no need for VPNs or having holes open. The agent by default will run on startup, so no user interaction is needed once executed.

Sample screenshot from one of my systems:

1)Note it keeps inventory of all systems that have the agent
2)It keeps location data in case your system gets stolen or violates a geofence you define
3)It keeps performance data like CPU/RAM/HDD/ETC
4)It keeps a connection log
5)It allows for management of installed applications
6)Also has quick power controls and other commands
7)Has a full remote desktop connection tab with a built in viewer in browser or has both links and credentials for other VNC apps. I recommend Tight VNC viewer.

sys-mgr-428-42516.png
 
Top