Wireguard is blocked in my country, so I no longer can use Tailscale or other Wireguard-based solutions. My home server is behind a NAT. What other ways of secure private connection can I use?

  • nikki@lemmy.blahaj.zone
    link
    fedilink
    English
    arrow-up
    0
    ·
    13 days ago

    I had luck with zerotier before switching to wireguard, but I imagine it has similar issues as talescale. Worth a try

  • Björn@swg-empire.de
    link
    fedilink
    English
    arrow-up
    0
    ·
    14 days ago

    Port forward your SSH-server. You can forward ports through SSH to access web services or others running on the server or anything else in the network.

    But only allow access through keys. And maybe try to use a different port than 22. That usually gets hammered a lot, trying to find accounts with weak passwords.

    • alexquiniou@lemmy.zip
      link
      fedilink
      English
      arrow-up
      0
      ·
      13 days ago

      Yep, that a good option. But only with a key ! Not with a password.

      Bot from everywhere will try to forcebrut attack with many password attempt.

      I got in this situation in the past. Nothing wrong happened, but it was stressfull.

    • Possibly linux@lemmy.zip
      link
      fedilink
      English
      arrow-up
      0
      ·
      13 days ago

      Changing the port doesn’t actually accomplish much

      Best practice is to just harden SSH so that not traffic gets nowhere

    • shininghero@pawb.social
      link
      fedilink
      English
      arrow-up
      0
      ·
      13 days ago

      OpenVPN is my current method. Got it running on port 443 with user certificate authentication, and tls-crypt on top of that to completely mask the protocol from VPN detectors.

      Also technically prevents DoS attacks, but that wasn’t my primary goal.

    • myszka@lemmy.mlOP
      link
      fedilink
      English
      arrow-up
      0
      ·
      9 days ago

      Wow, wstunnel seems to be a very elegant solution, thanks! However I still need to figure out how to get to my server behind a NAT

    • myszka@lemmy.mlOP
      link
      fedilink
      English
      arrow-up
      0
      ·
      9 days ago

      Yes it’s what I use for normal VPN, but I need to get around the NAT somehow. There’s been a PR for NetBird that implements AWG but it was never merged

    • xthexder@l.sw0.com
      link
      fedilink
      English
      arrow-up
      0
      ·
      13 days ago

      Neat, I might have to set this up for myself. It sounds like it could get around some of the VPN blocking I’ve seen while traveling through airports.

  • Decronym@lemmy.decronym.xyzB
    link
    fedilink
    English
    arrow-up
    0
    ·
    edit-2
    13 days ago

    Acronyms, initialisms, abbreviations, contractions, and other phrases which expand to something larger, that I’ve seen in this thread:

    Fewer Letters More Letters
    DNS Domain Name Service/System
    ISP Internet Service Provider
    NAT Network Address Translation
    SSH Secure Shell for remote terminal access
    TLS Transport Layer Security, supersedes SSL
    VPN Virtual Private Network
    VPS Virtual Private Server (opposed to shared hosting)

    [Thread #84 for this comm, first seen 21st Aug 2026, 16:20] [FAQ] [Full list] [Contact] [Source code]

  • talkingpumpkin@lemmy.world
    link
    fedilink
    English
    arrow-up
    0
    ·
    14 days ago

    Wow. Do they block VPNs inside your country too?

    Anyway, there’s openvpn and there’s nebula (I think nebula doesn’t use wireguard… do double-check), or you look into things built specifically to hide traffic (keyword: “vpn obfuscation”).

    No idea if VPN protocols other than wireguard may be blocked too (probably?).
    No idea if trying too hard to circumvent government policies may get you added to some list you’d rather not be in.

      • Possibly linux@lemmy.zip
        link
        fedilink
        English
        arrow-up
        0
        ·
        13 days ago

        China uses deep packet inspection so that makes sense

        I think the the great Firewall is less restrictive with QUIC traffic. It might be worth trying fragmented QUIC as from what I’ve read the GFW struggles to reconstruct the traffic

    • FedX@quokk.au
      link
      fedilink
      English
      arrow-up
      0
      ·
      14 days ago

      From what I can tell, the issue with Wireguard is that the traffic is quite obvious. Other options might be blocked, but technically harder to implement said blocks.

  • Auli@lemmy.ca
    link
    fedilink
    English
    arrow-up
    0
    ·
    13 days ago

    OpenVPN on port 443 would be my guess. Just regular nat or carrier grade nat.

  • exu@feditown.com
    link
    fedilink
    English
    arrow-up
    0
    ·
    14 days ago

    Self hosted networking! Legitimately one of my favourite topics

    You won’t get around the requirement of a publicly reachable endpoint. That can either be a small server with a public ip or dynamic DNS to your home with port forwarding for the VPN.

    A classic option is OpenVPN. You can run it on Port 443 in TCP mode and while it won’t be performant, it has a better chance of bypassing most simple blocks

    Other than that I’m a fan of completely decentralized mesh VPNs.

    The one I use and am most familiar with is Yggdrasil. Connections can be established over TCP, TLS or QUIC on any port you want.
    I’ve written a somewhat lengthy comment under this post. One advantage to Yggdrasil would be its existing public network. If you can firewall of your home lab to the point where joining the public network doesn’t expose a security risk to your local network, you could use that to transport your traffic instead of having your own public node or port forwarding.

    The same post also mentions Anywherelan, it’s intended to have better NAT handling out of the box by using community nodes.

    Then there’s also EasyTier mentioned at the bottom, it is a Chinese project and those tend to have good censorship resistance.

    Finally I’ll mention Nebula, it requires at least one coordination server but might also be an option

  • mushroommunk@lemmy.today
    link
    fedilink
    English
    arrow-up
    0
    ·
    14 days ago

    Can you switch to IPv6? My ISP NATs me on IPv4 but I’m clear through on IPv6 and so that’s how I run everything.

    I’m assuming the NAT is your ISP’s, if it’s yours then ignore me.

  • FedX@quokk.au
    link
    fedilink
    English
    arrow-up
    0
    ·
    14 days ago

    That’s quite fascinating, didn’t realize Wireguard could be blocked in that way (although the WG traffic is pretty obvious looking, so it makes sense). The only solution I know of without a need for a VPS is hosting everything on Tor. Wildly private and secure, but also wildly slow. Beyond that, there are a number of ways of using a VPS to similar effect, I know people have used Cloudflare Tunnel to similar effect in the past.

    Also, there are apparently quite a number of wiregaurd derivatives which protect better against detection and blocking methods. amnezia and wstunnel are the two that came up. Likewise, you will need a VPS, and might even be able to set up a tailscale-like coordination server that way (maybe with headscale, or maybe with one of its competitors like NetBird).

    ZeroTier might also get the job done, but I really don’t know much about it.

    Hope this helps, and good lucks!

    • myszka@lemmy.mlOP
      link
      fedilink
      English
      arrow-up
      0
      ·
      9 days ago

      Thanks! I do have a VPS. Can amnezia or wstunnel be used with headscale? That’d be amazing

  • Possibly linux@lemmy.zip
    link
    fedilink
    English
    arrow-up
    0
    ·
    13 days ago

    Possibly Tor? It supports TCP traffic so SSH should work

    Outside of that I would look into censorship resistant protocols and techniques. What country are you in?

    • myszka@lemmy.mlOP
      link
      fedilink
      English
      arrow-up
      0
      ·
      9 days ago

      Tor is slow and… also blocked here 😁

      I know of many working VPN protocols but I don’t know how to use them to route traffic through an intermediary VPS (bc my home server is behind a NAT)

  • black0ut@pawb.social
    link
    fedilink
    English
    arrow-up
    0
    ·
    13 days ago

    OpenVPN in TCP mode wrapped around Stunnel. That’s the thing that works.

    I have it set up to bypass VPN restrictions in some networks, but it also serves to bypass a lot more stuff if you know what you’re doing.

    DPI will only see TLS traffic, and assume it’s HTTP. You can even try to fool it by modifying the packet headers, so dumb enough DPI will think you’re connecting to the site you choose.

    • purplemonkeymad@programming.dev
      link
      fedilink
      English
      arrow-up
      0
      ·
      12 days ago

      We have had success with this on port 443 and it appears to do a good job on networks that only allow browsing. Usual problems with TCP based VPN still apply.