Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!


New on LowEndTalk? Please Register and read our Community Rules.

All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.

Cheap Reverse Proxy / Shield VPS – Budget ~$1–$2/mo ($10–$15/yr)

Hi LET community,

Looking for a reliable, low-cost VPS to use purely as a reverse proxy shield (Nginx + WireGuard) in front of my backend application server.

Requirements:

vCPU: 1 Core
RAM: 512 MB – 1 GB
Storage: 10 GB – 20 GB (SSD/NVMe)
Bandwidth: 2 TB+ per month on 1 Gbps port
Location: US East (New York, New Jersey, Ashburn) or Western Europe (UK, NL, Germany) to keep latency minimal.

Virtualization: KVM (WireGuard support required)
OS: Ubuntu 22.04 / 24.04 or Debian 12

Budget:
~$1.00 – $2.00 / month (or $10 – $15 / year paid annually).

Please share your active promos, direct checkout links, and looking glasses / test IPs.
Thanks!

Thanked by 1JasonM

Comments

  • DDOS protection?

  • @Shubham14 said: Virtualization: KVM (WireGuard support required)

    Just in case, WG works on OpenVZ as well.

  • @Shubham14 said: New York
    @Shubham14 said: Budget: ~$1.00 – $2.00 / month (or $10 – $15 / year paid annually).

    @DediRock - https://billing.dedirock.com/index.php/store/promo-vp

    They support all of your requirements. But I do think if ur doing something like this, you need DDoS protection, like @rpqu said, right?

    Thanked by 1DediRock
  • NolimitHostNolimitHost Member, Patron Provider
    edited September 10

    @Shubham14 said:
    Hi LET community,

    Looking for a reliable, low-cost VPS to use purely as a reverse proxy shield (Nginx + WireGuard) in front of my backend application server.

    Requirements:

    vCPU: 1 Core
    RAM: 512 MB – 1 GB
    Storage: 10 GB – 20 GB (SSD/NVMe)
    Bandwidth: 2 TB+ per month on 1 Gbps port
    Location: US East (New York, New Jersey, Ashburn) or Western Europe (UK, NL, Germany) to keep latency minimal.

    Virtualization: KVM (WireGuard support required)
    OS: Ubuntu 22.04 / 24.04 or Debian 12

    Budget:
    ~$1.00 – $2.00 / month (or $10 – $15 / year paid annually).

    Please share your active promos, direct checkout links, and looking glasses / test IPs.
    Thanks!

    Hello,

    Based on the requirements you’ve listed, we would be able to offer you the following server:

    Budget VPS – Special Offer

    • 1 vCore
    • 1 GB RAM
    • 10 GB NVMe
    • 1 IPv4 + IPv6 /64
    • DDoS Protection + Firewall Manager included
    • 500 Mbit/s Connection
    • 2 TB Bandwidth
    • Frankfurt, Germany
    • Promotional Price: €18.99/year
    • Click to Order!

    Looking Glass: https://lg.nolimithost.cc/

    If you purchase the VPS and reach out to me afterward, I can upgrade the connection to 1 Gbit/s port free of charge.

  • DediRockDediRock Member, Patron Provider

    @itzsenu said:

    @Shubham14 said: New York
    @Shubham14 said: Budget: ~$1.00 – $2.00 / month (or $10 – $15 / year paid annually).

    @DediRock - https://billing.dedirock.com/index.php/store/promo-vp

    They support all of your requirements. But I do think if ur doing something like this, you need DDoS protection, like @rpqu said, right?

    thx for the mention @itzsenu :)

  • @Shubham14 said:
    Looking for a reliable, low-cost VPS to use purely as a reverse proxy shield (Nginx + WireGuard) in front of my backend application server.

    One thing I've noticed from some of my providers is that wireguard is occasionally mysteriously blocked for up to a day at a time for no obvious reason and without all that much traffic, so I'm guessing that UDP scores highly on their suspicious packet analysis.

    I've started to forward encrypted HTTPS traffic to my dedis over TCP instead (so the reverse proxy is literally just load balancing tunnels) and firewall off those ports so that they're only accepted from whitelisted IPs (iptables and reject on fail, so that they look like they're not even open to anyone who scans).

  • @ralf said:
    One thing I've noticed from some of my providers is that wireguard is occasionally mysteriously blocked for up to a day at a time for no obvious reason and without all that much traffic, so I'm guessing that UDP scores highly on their suspicious packet analysis.

    This is useful information, which providers do this?

    Possibly related, I've also noticed that wireguard does sometimes just hang, too, and has to be restarted. (Easy enough to make a script to automate this check)

  • try Racknerd. I'm using them for revese proxy shield in NY and Atlanta

  • @WyvernCo said:

    @ralf said:
    One thing I've noticed from some of my providers is that wireguard is occasionally mysteriously blocked for up to a day at a time for no obvious reason and without all that much traffic, so I'm guessing that UDP scores highly on their suspicious packet analysis.

    This is useful information, which providers do this?

    Possibly related, I've also noticed that wireguard does sometimes just hang, too, and has to be restarted. (Easy enough to make a script to automate this check)

    Off the top of my head, I can't remember which provider it was now, but it was definitely filtering out UDP packets by port, and it was only filtering one-way. I tried switching wireguard to a different port and it was getting blocked on the new port within about a minute. At the time the amount of traffic was basically just pings and a couple of tests myself over the connection, so maybe a megabyte max before getting blocked.

    It's happened a couple of times, and I gave up trying to fix the wireguard connection and then it just mysteriously went back to normal a day later, only to happen again a few months later. TCP was completely fine throughout. The last time it happened was probably a month or two ago.

    My guess is that the provider just had a low threshold for UDP packets to consider it a DDoS. I also run my wireguard on nonstandard ports, so maybe that was an issue.

    Thanked by 1WyvernCo
  • SKRIMESKRIME Member, Patron Provider

    Hey @Shubham14,

    Thanks for the tag @Michal212.

    Our EPYC 1G is 1.49€/mo, so 17.88€ for the year. That's above your 10 to 15 dollar target, and I'd say that upfront. What you get is 1 core on AMD EPYC Zen 3 Milan with ECC DDR4, 1 GB RAM, 10 GB NVMe in RAID 1, one IPv4 plus an IPv6 /64, in Eygelshoven, NL.

    For a reverse proxy shield the relevant parts are that it's full KVM with your own kernel so WireGuard works out of the box, DDoS protection is included and not extra, and there's no bandwidth allowance at all - no counter, no per-GB overage, so your 2 TB plus isn't a number you'd watch.

    Test IPv4 is 77.90.60.30 and test IPv6 is 2a09:3f00:3000::cafe if you want to measure latency to your backend first.

    Order: skri.me/epyc
    Looking Glass: skrime.eu/network / AS215365

  • zedzed Veteran

    @WyvernCo said:

    @ralf said:
    One thing I've noticed from some of my providers is that wireguard is occasionally mysteriously blocked for up to a day at a time for no obvious reason and without all that much traffic, so I'm guessing that UDP scores highly on their suspicious packet analysis.

    This is useful information, which providers do this?

    Possibly related, I've also noticed that wireguard does sometimes just hang, too, and has to be restarted. (Easy enough to make a script to automate this check)

    i've never had wireguard "just hang", but yea there's a few providers i've dealt with whose overzealous fucking annoying ddos protection blocks wireguard. i don't use any of them anymore because don't annoy me.

  • HostVDS_comHostVDS_com Member, Patron Provider

    Hi @Shubham14,

    We have a plan that fits your requirements pretty closely:

    1 vCPU
    1 GB RAM
    10 GB NVMe
    1 Gbit/s port
    Unlimited traffic

    With the network configuration matching your requirements, the price is $1.98/month.

    KVM virtualization is used, and both Debian 12 and Ubuntu 22.04 / 24.04 are available.

    Kansas City is currently available to order as well and could also be a good fit for your setup.

    Looking Glass: https://ping-mkc1.hostvds.com/
    Order: https://hostvds.com/control/servers/new

    Should work well for a lightweight Nginx + WireGuard reverse proxy setup.

Sign In or Register to comment.