Skip to content

My tunnel setup: 4 protocols nested because reasons

Networking by minh1987 4 replies 176 views
5 #1

My tunnel setup:

wireguard over openvpn over gre over ipsec, all on one vps in my country. Latency is bad but price is good. Provider is Hostinger, they dont ask questions.

Works somehow. Want add vxlan on top for lab. Anyone see problem? In my country we do this for bypass.

phở at 3AM, deploy at 4
#2

I had something kind of similar except mine was in 2019 and I was using a different provider called something like Contabo or maybe it was fibermouse I cant remember anymore and I had just eaten a bagel for breakfast and my cat was sitting on the router which was warm and she loved that and then the server went down and I thought it was the tunnel but actually it was the weather because there was a storm and the power flickered and I lost three hours of config work and I typed it all again and then someone in the discord said why not just use one protocol and I got so mad because they clearly didnt read the whole thing and I never use paragraph breaks because they are a lie invented by people who want to control how you read and my setup was wireguard over openvpn over something else I forget and it worked fine until it didnt and then I moved to a different city and the latency was better but the cat hated the new router because it was a different shape and didnt get as warm and I still think about that sometimes

#3

Minh1987: you want make a server up with vxlan on top? Maybe check mtu first. Each layer take bytes. I see this before, regards.

Bravomartha: I read all, is okay. Maybe use paragraph for help eyes? 😊

#4

When I started out we had a saying: every tunnel is a failure mode you haven't hit yet.

Believe me, this stack is going to break on a path MTU discovery edge case you can't predict. Four protocols deep means four places to fragment, four places to blackhole, four places a middlebox gets creative. I've been doing this 20 years. The "somehow works" phase lasts six months, then you get paged at 3am and you can't tell which layer dropped the SA.

It ends in tears. It always does.

IPv4, IRC, and irssi — fight me
#5

Minh1987: ticket said "user reports no connection to internal service, please investigate"

traceroute died at hop 3. Hop 3 was the openvpn instance. Hop 4 was the gre. Hop 5 was wireguard. Hop 6 was the actual vps. The abuse report came from the vps owner because the ipsec endpoint hit their ddos threshold. The "internal service" was a minecraft server.

I put wontfix. They opened a new ticket. Same text.

reported. resolved. repeat.

Post a reply

You need an account to reply. Log in or register to join the conversation.

Post reply Preview Save draft