Your thoughts on an OVH architecture with dedicated servers, vRack, and extra IPs

I have 2 dedicated SYS servers, a private vRack and an additional IP pack. I use my own mail server and my own DNS servers. I have two hosted domains and very few users and very, very few public connections (almost none) at this stage. Just my personal, private use and that of my close ones and a few professional clients/contacts/partners.

My goal:
The protection and confidentiality of the data stored and exchanged with total, maximum and direct control by each individual user, who can finely and securely share with whoever and whatever they want, most often without the files or data ever having to leave my servers. I have the necessary software solutions, exclusively open‑source, and I administer the servers myself.

What I’m trying to achieve:

I want to have, across my two servers, both redundancy and flexibility, as well as operational security and protection, confidentiality of several terabytes of data.

So I’d like to run one server in “production” and the other in “backup” (for example if the production server crashes or becomes unreachable via an IP, or an OVH shared public IP gets blacklisted because we can’t obtain its delisting as we’re not the owner – hence my additional IPs). The backup server should also store my backups and archive digital files over time when they are no longer needed “online”, and allow me to manage the performance of processing ever‑growing volumes of files.

If I understand correctly, the vRack should let me exchange data “in private”, i.e., with full confidentiality and security between my two servers, and “hide” my servers and their private IPs from the public, while providing a failover solution with rapid automatic or manual switchover.

My question:
How do I configure my two dedicated servers, the vRack and my additional IPs? OVH documentation is abundant, but it mainly describes the features and possible uses and how to install and configure each component via the Manager or OVH API. The detailed implementation, especially outside OVH’s commercial environment, is hard to piece together to build a clean architecture and configure everything correctly.

Do you have experience with vRack and additional IPs in this context?
Thanks in advance for your thoughts and advice.

The best solution remains to go through Proxmox and virtualize all that.

But a third server (Proxmox Backup Server) would be needed to back up the VM(s).

With regular replication of the production server’s VM to the secondary server.

The VM’s IP goes through the vrack or the external interface, it doesn’t matter, but if it goes through the external interface, you have to move the IPFO manually (or via API) if the VM moves to the second server.

Note, anyway, in a two‑server architecture there is no automatic failover from one host to another.

Thanks Sich for your answer.

Your response makes sense, but I have already been using a single dedicated server and virtual servers (Virtualmin) for a decade.

In fact, I don’t need high availability, nor an automatic fail‑over in a few seconds.

However, the experience of being unable to send e‑mails because an OVH IP block was blacklisted—without being able to get delisted and thus remaining blocked indefinitely—poses a real problem for me! And on my OVH KS server that I was using, unfortunately you can’t obtain an additional IP pack from OVH...

That led me to reconsider my architecture more deeply and to opt for two SYS servers with 2 × 4 TB disks each, because my context involves processing (very) large data volumes with multi‑decadal (and beyond) histories, for a very small number of users and application needs (outside of communication and collaboration tools) that do not require 24/7/365 availability.

Moreover, protection and confidentiality—hence total independence (non‑dependence), including international independence (which has become a strategic issue for everyone in today’s world)—mean that I implement exclusively open‑source solutions or those developed in‑house.

The additional IPv4 pack frees me from the dependency imposed by using OVH’s fixed‑IP block, and with a fail‑over solution I have full control and can change my IPs myself at any time (or have them delisted if needed, as a “direct registered owner”). I can also use two servers for redundancy in case of a major, long‑lasting issue or accident, such as when the OVH data centre in Strasbourg burned down, giving me more flexibility, storage scalability, development, processing and testing capabilities.

Thanks again for your answer and your responsiveness, and have a good week.
Finally, the vRack gives me a level of security and confidentiality against the public Internet and a private (internal) network between my servers that can be located in different regions or countries.

It's certain that the vRack is good, but not all bare metal have it.
Otherwise, a WireGuard VPN that is performant and fairly simple to set up works with any provider.

Thanks TTY for your answer.

For my part I have had the OVH vPack for years (now called the “Private vRack”) in the OVH catalogue. It is available for the SYS‑range servers I chose and the additional RIPE IP blocks.

A VPN (or a proxy) is a tool that, in a way, lets you anonymise yourself and makes it appear that you are using an IP address other than your own. But in fact your data, email contents, transmitted files, and conversations always pass through the public Internet (the Web), and moreover the contents are not always encrypted end‑to‑end—rarely. ISPs collect and can still know certain data about your connection. Moreover, on the destination site’s side, if you use a VPN or proxy to log into its apps, your subscription accounts (including your own sites) you will identify yourself (ID + password…) to access its content. You will therefore always be recognised and identified, even tracked, and your data and other readable information can be collected…

That said, in my case, for my needs, I am not trying to be anonymous, nor to make it look like I am somewhere else. However, I want to protect the data stored on my servers and therefore control access to that data, and as much as possible its outbound flow, diffusion to the outside, to third parties, the public via communication and exchange tools, collaboration (emails, social networks, messengers, video calls, etc.… especially the tools and servers of the GAFAMs and other clouds that have become almost systematic for any app, commercial solution).

The OVH vRack allows (internally within OVH) direct links between the Ethernet cards of servers and therefore runs over OVH cables, fibres between OVH sites, thus between my dedicated servers. Nothing therefore passes through the external public Internet. This direct link is also more performant than if it had to go through all the hops of the public Web. These links are not shared IP blocks with others and you can choose a guaranteed bandwidth. The result is safer, more performant and I can personally control the diffusion of data and end‑to‑end encryption.

Each tool has its purpose, strengths and weaknesses, limits. One must clearly know what one is looking for and find the tool(s) and solution(s) best suited to one’s needs, which also must be clear and precise to make the “right” choice.

Not always easy…

Thanks again for your answer and your suggested solution, even if it does not match my objectives and needs.

Exactly, a VPN is a tool for access and anonymity, and a vRack is the private network infrastructure. One serves to safely go out to the internet and the other to build your own internal network within OVV.

In the end, the best solution always depends on exactly what you want to protect, whether it’s your communications with the outside, or the communication between your own servers.

Thanks for sharing your opinion :wink:

Regarding IP blocking, however blacklists like UCEPROTECT seem to block entire IP ranges, so even with a second one, I’m not sure it will work if it’s in the same IP range.

It’s better to use an external relay (outside of OVH) to have peace of mind, or even better, not handle email at all; I’ve been using ProtonMail for years and it’s really great.

Furthermore, VRACK is not compatible with all services.

(I was writing “services” (in French, the word is very close), and I even had a nightmare during my nap (for real) because of my recent OVH tickets))

Well, not necessarily… A VPN is simply an encrypted connection between two servers…
Setting up a WireGuard between two servers allows encrypted communication between the two; anonymity isn’t the point here…
Incidentally, the vRack isn’t magical, it’s virtualized; we always go through the same OVH infrastructure.
When you connect two servers in two different data centers, they always at some point go through a shared infrastructure, but the traffic is isolated. It’s not a distinct magical network.

Exactly, if deliverability is critical (transactional emails), you have to use third‑party providers whose business is that. It’s not just the OVH IP problem, but the entire mail infrastructure becomes a nightmare with silent drops, being marked as spam even though everything is fine, and so on…

Exactly, I mentioned anonymity but, broadly speaking, I’m referring to privacy and network isolation :slight_smile:

Cheers @Sich :wink:

I have 2 Postfix relays on OVH VPS (2 different locations) with 2 FO IPs that I’ve had for 10 years and I don’t really have many deliverability issues.
Just occasionally the free Microsoft email addresses (Hotmail, Messenger…) act up.
I send roughly 60 K transactional emails per month with it and honestly it’s not that hellish to maintain.

Hello, bonjour to everyone.

The VPN‑vRack exchange is interesting in that it shows, through the comments, that we’re not always talking about the same thing and that, in the end, we don’t really know exactly how these “black boxes” that are the VPN and the vRack work.

Regarding the VPN (Virtual Private Network), the technical “architectural” definition states clearly what we’re dealing with, and indeed vRack also allows you to build a “private network”. Functionally you could say it’s virtual, hence the “v” in vRack. However, vRack creates a direct link between Ethernet cards in the servers, so it’s “physical”, and although it runs over an infrastructure, that infrastructure belongs to OVH between its own sites, meaning it does not go through the public Internet, public IPs, or web domains.

For VPNs, outside the corporate world, individuals and private users mainly use them to access their home‑country subscription when abroad, essentially pretending to be in their country of residence. As for data encryption, a VPN does not encrypt everything end‑to‑end, and VPN servers collect certain data such as the sites you connect to on the other end. It simply isn’t transparent throughout the whole chain. The topics of safety, privacy, and encryption are a whole other vast subject.

A brief addition:
1 – A VPN is somewhat like SSH, you could say, regarding the data—the message payload and its encryption.
2 – Email is probably the worst medium in terms of protection for both access and the content it carries. The best you can do is host your own mail server and, if possible, treat it like you would your bank or the finance ministry for taxes, etc., limiting the use of that vector to and through your own server. The problem is you usually need to communicate openly with everyone, not just in a personal, direct relationship, and your email is like your postal address—it’s public!
3 – It’s difficult, if not impossible, to avoid involving a third party at some point, but “third party” implies risk and a loss of control over what goes in and out of that party.

The Internet, by definition and its “architecture”, is an open, mesh‑networked tool composed of packets or blocks derived from messages that travel along paths we know nothing about. That’s its strength and its weakness!

As a bonus, for your consideration: on buses, subways, in offices, on our smartphones, with our credit cards, etc., we leave traces and information, sometimes even give them away and expose them to the whole world, to the public. All it takes is listening to people talk, expressing themselves, and spilling on social networks…