this post was submitted on 21 Aug 2026
149 points (99.3% liked)

Selfhosted

61708 readers
697 users here now

A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.

Rules:

Detailed Rules Post

  1. Be civil.

  2. No spam.

  3. Posts are to be related to self-hosting.

  4. Don't duplicate the full text of your blog or readme if you're providing a link.

  5. Submission headline should match the article title.

  6. No trolling.

  7. Promotion posts require active participation, with an account that is at least 30 days old. F/LOSS without a paywall has exceptions, with requirements. See the rules link for details. Tags [CBH] or [AIP] are required, see the links in Rule 8 for details.

  8. AI-related discussions and AI-involved promotional posts have additional requirements for tagging, as noted in Rule 7 and the AI & Promotional Post Expanded Rules post, and find example disclosures here.

Resources:

Any issues on the community? Report it using the report flag.

Questions? DM the mods!

founded 3 years ago
MODERATORS
 

Wireguard is blocked in my country, so I no longer can use Tailscale or other Wireguard-based solutions. My home server is behind a NAT. What other ways of secure private connection can I use?

(page 2) 35 comments
sorted by: hot top controversial new old
[–] damnthefilibuster@lemmy.world 7 points 4 days ago

See if you can use ZeroTier. It doesn’t use wire guard but rather their own protocol as far as I know.

[–] FedX@quokk.au 6 points 4 days ago* (last edited 4 days ago) (1 children)

That's quite fascinating, didn't realize Wireguard could be blocked in that way (although the WG traffic is pretty obvious looking, so it makes sense). The only solution I know of without a need for a VPS is hosting everything on Tor. Wildly private and secure, but also wildly slow. Beyond that, there are a number of ways of using a VPS to similar effect, I know people have used Cloudflare Tunnel to similar effect in the past.

Also, there are apparently quite a number of wiregaurd derivatives which protect better against detection and blocking methods. amnezia and wstunnel are the two that came up. Likewise, you will need a VPS, and might even be able to set up a tailscale-like coordination server that way (maybe with headscale, or maybe with one of its competitors like NetBird).

ZeroTier might also get the job done, but I really don't know much about it.

Hope this helps, and good lucks!

load more comments (1 replies)
[–] Decronym@lemmy.decronym.xyz 5 points 4 days ago* (last edited 7 hours ago)

Acronyms, initialisms, abbreviations, contractions, and other phrases which expand to something larger, that I've seen in this thread:

Fewer Letters More Letters
CGNAT Carrier-Grade NAT
DNS Domain Name Service/System
ISP Internet Service Provider
NAT Network Address Translation
SSH Secure Shell for remote terminal access
TLS Transport Layer Security, supersedes SSL
Unifi Ubiquiti WiFi hardware brand
VPN Virtual Private Network
VPS Virtual Private Server (opposed to shared hosting)

[Thread #84 for this comm, first seen 21st Aug 2026, 16:20] [FAQ] [Full list] [Contact] [Source code]

[–] Nikki@lemmy.blahaj.zone 5 points 4 days ago

I had luck with zerotier before switching to wireguard, but I imagine it has similar issues as talescale. Worth a try

[–] tlekiteki@lemmy.dbzer0.com 4 points 4 days ago (1 children)
load more comments (1 replies)
[–] mushroommunk@lemmy.today 4 points 4 days ago (1 children)

Can you switch to IPv6? My ISP NATs me on IPv4 but I'm clear through on IPv6 and so that's how I run everything.

I'm assuming the NAT is your ISP's, if it's yours then ignore me.

load more comments (1 replies)
[–] village604@adultswim.fan 2 points 4 days ago* (last edited 4 days ago) (1 children)

If you get a Mikrotik router it comes with a back to home VPN server and a dedicated DDNS.

You need to know a bit about network configuration, although the setup wizard is sufficient for most use cases.

When you enable to BTH VPN, it does all of the configuration for you. And it works for me behind a double NAT

[–] Scrath@lemmy.dbzer0.com 1 points 3 days ago

I believe the back to home VPN from MikroTik is also wireguard. At least it is on mine. No idea if you can use a different VPN solution with it.

[–] possiblylinux127@lemmy.zip 2 points 4 days ago (2 children)

Possibly Tor? It supports TCP traffic so SSH should work

Outside of that I would look into censorship resistant protocols and techniques. What country are you in?

load more comments (2 replies)
[–] Auli@lemmy.ca 2 points 4 days ago

OpenVPN on port 443 would be my guess. Just regular nat or carrier grade nat.

Run ssh on an Onion Service.

[–] somehacker@lemmy.world 1 points 4 days ago
[–] altphoto@lemmy.today -3 points 4 days ago* (last edited 6 hours ago) (3 children)

I'll recommend this new VPN thing :

https://rayfish.xyz/

Its new so its evolving quickly with weekly releases and nightly builds.

Lots of people have told me about their grievance list due to AI having a big part in the development. It's a bunch of guys in the team, so there's the human element there.

As for my opinion, it's the only VPN I've managed to get working on my own.

I lost connection yesterday and I am not sure what happened but my home computer and my phone were on the same VPN constantly for a week. Jumping from the house WiFi to 5g didn't break the VPN connection but it did take a few seconds the first time I did it.

My other option would be Tailscale.

Update on the lost connection. I had restarted my computer and that changed my firewall device name for the VPN. So it was not rayfish related. It's been pretty steady since.

load more comments (3 replies)
[–] BCsven@lemmy.ca 0 points 4 days ago (2 children)

Can you port forward on the router?

[–] chewypoops@lemmy.world 1 points 3 days ago (1 children)
[–] BCsven@lemmy.ca 1 points 3 days ago (1 children)

Why? wireguard doesn't respond if the keys are wrong.

load more comments (1 replies)
load more comments (1 replies)
load more comments
view more: ‹ prev next ›