this post was submitted on 21 Aug 2026
149 points (99.3% liked)

Selfhosted

61708 readers
717 users here now

A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.

Rules:

Detailed Rules Post

  1. Be civil.

  2. No spam.

  3. Posts are to be related to self-hosting.

  4. Don't duplicate the full text of your blog or readme if you're providing a link.

  5. Submission headline should match the article title.

  6. No trolling.

  7. Promotion posts require active participation, with an account that is at least 30 days old. F/LOSS without a paywall has exceptions, with requirements. See the rules link for details. Tags [CBH] or [AIP] are required, see the links in Rule 8 for details.

  8. AI-related discussions and AI-involved promotional posts have additional requirements for tagging, as noted in Rule 7 and the AI & Promotional Post Expanded Rules post, and find example disclosures here.

Resources:

Any issues on the community? Report it using the report flag.

Questions? DM the mods!

founded 3 years ago
MODERATORS
 

Wireguard is blocked in my country, so I no longer can use Tailscale or other Wireguard-based solutions. My home server is behind a NAT. What other ways of secure private connection can I use?

top 50 comments
sorted by: hot top controversial new old
[–] alienghic@slrpnk.net 7 points 3 days ago (2 children)

Can you set your NAT to port forward a port to your ssh host?

I'm currently using yggdrasil to deal with this problem, though I've also used tor hidden services.

[–] myszka@lemmy.ml 1 points 14 hours ago (1 children)

Unfortunately I'm behind CGNAT and yggdrasil is also partly blocked here (works super slow)

[–] alienghic@slrpnk.net 1 points 9 hours ago

You might try adding more gateways to the conf file?

Or if you've got a host your trying to connect to I think I've seen people get a VPN connection through ssh? https://wiki.archlinux.org/title/VPN_over_SSH

[–] Feathercrown@lemmy.world 2 points 3 days ago* (last edited 3 days ago)

This is what I do. For best security practice, make sure to use public key authentication and disable password authentication so nobody can even try to guess your password.

[–] Evil_Incarnate@sopuli.xyz 5 points 3 days ago (1 children)

Zerotier. They have their own protocol, and there's a free tier that lets you connect up to ten machines to make a network.

Also possible to selfhost, although I haven't done it.

[–] myszka@lemmy.ml 1 points 14 hours ago

Thanks! But zerotier is also blocked here 😅

[–] sundaylab@lemmy.ml 3 points 2 days ago (1 children)

I have successfully setup trojan / trojan-go on my server. It uses port 443 and will return a standard website if the connection is not recognized as an authorized trojan-go client. As stealth as it can get.

https://azadzadeh.github.io/trojan-go/en/

[–] myszka@lemmy.ml 1 points 14 hours ago

Thanks! Will look into it

[–] kugmo@sh.itjust.works 33 points 4 days ago (2 children)

AmneziaWG is a Wireguard fork built against deep packet inspection, try that.

[–] myszka@lemmy.ml 1 points 14 hours ago

Yes it's what I use for normal VPN, but I need to get around the NAT somehow. There's been a PR for NetBird that implements AWG but it was never merged

[–] xthexder@l.sw0.com 9 points 4 days ago

Neat, I might have to set this up for myself. It sounds like it could get around some of the VPN blocking I've seen while traveling through airports.

[–] hendrik@palaver.p3x.de 41 points 4 days ago* (last edited 4 days ago) (6 children)

https://github.com/erebe/wstunnel seems like the obvious solution.

Or maybe OpenVPN over normal TLS on port 443.

You could try to run Wireguard on a different port which would be otherwise used by some very common service, maybe there's some general exemption for port 21, 22, 53, 80, 443...

[–] myszka@lemmy.ml 2 points 14 hours ago

Wow, wstunnel seems to be a very elegant solution, thanks! However I still need to figure out how to get to my server behind a NAT

[–] shininghero@pawb.social 11 points 4 days ago

OpenVPN is my current method. Got it running on port 443 with user certificate authentication, and tls-crypt on top of that to completely mask the protocol from VPN detectors.

Also technically prevents DoS attacks, but that wasn't my primary goal.

load more comments (4 replies)
[–] carrylex@lemmy.world 22 points 4 days ago

Wireguard is blocked in my country

RIP

[–] moldy_rice@piefed.keyboardvagabond.com 15 points 4 days ago (4 children)

Best solution is to organize revolution to kick out the fascist that censored the internet by protocol

[–] myszka@lemmy.ml 1 points 14 hours ago

Well you'd still depend on someone else's will to provide you with robust and uncensored internet connection. The actual solution is to build a decentralised people-owned network using Reticulum for example. Reticulum over WiFi HaLow already works very well for small-scale local networks.

[–] zbyte64@awful.systems 8 points 3 days ago

That's an ideal solution. The best solution is what works immediately and within your capabilities.

[–] derin@lemmy.beru.co 9 points 3 days ago (1 children)

So helpful! Bet you're fun at parties.

load more comments (1 replies)
[–] jumping_redditor@sh.itjust.works 2 points 3 days ago (1 children)

that is neither easy nor quick.

[–] MrNobody@lemmy.dbzer0.com 7 points 3 days ago

Nothing worth having ever is.

[–] sandwichsaregood@lemmy.world 14 points 4 days ago* (last edited 4 days ago)

Sing-box is a VPN tool built to evade censorship https://github.com/SagerNet/sing-box . It is extremely resilient and stealthy.

See also, xray and v2ray, which are similar, but in my experience sing-box is a bit better documented (at least in English) and has better maintained client apps.

Setting any of these up can be complicated, but LLMs can get you pretty far if you have safe access.

[–] exu@feditown.com 33 points 4 days ago (2 children)

Self hosted networking! Legitimately one of my favourite topics

You won't get around the requirement of a publicly reachable endpoint. That can either be a small server with a public ip or dynamic DNS to your home with port forwarding for the VPN.

A classic option is OpenVPN. You can run it on Port 443 in TCP mode and while it won't be performant, it has a better chance of bypassing most simple blocks

Other than that I'm a fan of completely decentralized mesh VPNs.

The one I use and am most familiar with is Yggdrasil. Connections can be established over TCP, TLS or QUIC on any port you want.
I've written a somewhat lengthy comment under this post. One advantage to Yggdrasil would be its existing public network. If you can firewall of your home lab to the point where joining the public network doesn't expose a security risk to your local network, you could use that to transport your traffic instead of having your own public node or port forwarding.

The same post also mentions Anywherelan, it's intended to have better NAT handling out of the box by using community nodes.

Then there's also EasyTier mentioned at the bottom, it is a Chinese project and those tend to have good censorship resistance.

Finally I'll mention Nebula, it requires at least one coordination server but might also be an option

load more comments (2 replies)
[–] iocase@lemmy.zip 5 points 3 days ago (2 children)

I haven't tried it myself but I've been looking at NetBird.

Elevator pitch page

Maybe others who've used it or know more can chime in on if this is a good idea or not?

[–] myszka@lemmy.ml 2 points 14 hours ago (1 children)

Yes, that's what I used to use! Love it, but wireguard is blocked

[–] iocase@lemmy.zip 1 points 14 hours ago

Have you tried replacing your country?

[–] alphabethunter@lemmy.world 14 points 3 days ago (1 children)
[–] black0ut@pawb.social 19 points 4 days ago (1 children)

OpenVPN in TCP mode wrapped around Stunnel. That's the thing that works.

I have it set up to bypass VPN restrictions in some networks, but it also serves to bypass a lot more stuff if you know what you're doing.

DPI will only see TLS traffic, and assume it's HTTP. You can even try to fool it by modifying the packet headers, so dumb enough DPI will think you're connecting to the site you choose.

We have had success with this on port 443 and it appears to do a good job on networks that only allow browsing. Usual problems with TCP based VPN still apply.

[–] dogdeanafternoon@lemmy.ca 8 points 4 days ago (1 children)

Could use SSH tunnel to an entry point

[–] myszka@lemmy.ml 2 points 14 hours ago

Yes, I've tried that, but it's not robust enough. This is what I'll eventually resort to, if I don't find a better solution.

[–] MuttMutt@lemmy.world 15 points 4 days ago

First, you need to verify whether you actually have a public IP or if your ISP has you stuck behind CG-NAT, because that dictates your options.

​If you're behind CG-NAT, ​Cloudflare Tunnel (cloudflared): This is usually the easiest path if you are mostly trying to access web-based services (HTTP/HTTPS) on your server. Your home server initiates the outbound connection to Cloudflare, so CG-NAT doesn't matter. You just set up a domain (or subdomains) for each service you want to reach. If you need full network-level or SSH access rather than just web apps, check out ZeroTier.

​If you have a direct public IP (even a dynamic one), you can run a reverse proxy like Caddy paired with a free DDNS provider like DuckDNS or FreeDNS. One nice thing about Caddy is that it handles getting and renewing real, valid Let's Encrypt SSL certificates automatically, so you don't have to deal with manual or self-signed certs at all.

​Dealing with the WireGuard block, if your country's ISP is using Deep Packet Inspection (DPI) to identify and drop WireGuard traffic, traditional VPNs like OpenVPN might get blocked pretty quickly too. If you still want a true VPN setup, look into AmneziaWG (it's a fork of WireGuard specifically modified to scramble packet signatures and bypass DPI) or obfuscated proxy protocols like V2Ray / Xray or Shadowsocks.

[–] bjoern_tantau@swg-empire.de 17 points 4 days ago (2 children)

Port forward your SSH-server. You can forward ports through SSH to access web services or others running on the server or anything else in the network.

But only allow access through keys. And maybe try to use a different port than 22. That usually gets hammered a lot, trying to find accounts with weak passwords.

load more comments (2 replies)

Tor Hidden Services, easy to set up on the server side, can be annoying on the client side but HTTP and SSH are fine. Can be a bit slow but IMHO still usable.

[–] Myraculix@feddit.nl 1 points 3 days ago

Based on what you planning to do, maybe mTLS could be a solution.

[–] Squizzy@lemmy.world 7 points 4 days ago (2 children)

I'm new to all this, how is wireguard banned and enforced? Seems odd

[–] sandwichsaregood@lemmy.world 6 points 4 days ago* (last edited 4 days ago)

WG is not meant to be a stealthy protocol and is easy to detect at the ISP level. It has distinct characteristics that packet inspection tools can use to identify it by examining the traffic and block or flag it. Blocking it completely is trivial for any ISP, much less a nation.

There are modified versions like AmneziaWG that make it stealthier, or alternative protocols built to evade traffic inspection like xray or sing-box (these two are really more like protocol frameworks that have multiple protocols you can use). It's a bit of an arms race for packet inspection tools to be able to reliably identify these intentionally stealthy protocols, but the advantage is generally in your favor as long as you are using your own servers and not public VPNs. Though even then you need to take care to camouflage your traffic to be truly safe, like if you are shoving all of your traffic through one remote server that has approximately the same amount of traffic going out immediately etc that is something that can also be identified.

How much precaution is actually warranted depends on where you are and what the potential consequences are. You don't have to go to a full tinfoil hat paranoia level setup to avoid most blocking.

load more comments (1 replies)
[–] q7mJI7tk1@lemmy.world 5 points 4 days ago* (last edited 4 days ago) (1 children)

So this has been interesting to me as I'm travelling at the moment and wireguard has been blocked on the guest wifi I've been on across the hotels, I've had to rely on cellular instead.

I've just tried Teleport on my Unifi router and that works. I believe it uses wireguard, and it is taking up to 20secs to connect, but I'm now curious as to what it's doing to bypass the VPN restrictions that are blocking plain wireguard.

load more comments (1 replies)
[–] talkingpumpkin@lemmy.world 9 points 4 days ago (4 children)

Wow. Do they block VPNs inside your country too?

Anyway, there's openvpn and there's nebula (I think nebula doesn't use wireguard.. do double-check), or you look into things built specifically to hide traffic (keyword: "vpn obfuscation").

No idea if VPN protocols other than wireguard may be blocked too (probably?).
No idea if trying too hard to circumvent government policies may get you added to some list you'd rather not be in.

load more comments (4 replies)
[–] gooeyglob@lemmy.world 8 points 4 days ago (1 children)

Big Netbird fan, and they support a fully self hosted version.

load more comments (1 replies)
load more comments
view more: next ›