See if you can use ZeroTier. It doesn’t use wire guard but rather their own protocol as far as I know.
Selfhosted
A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.
Rules:
-
Be civil.
-
No spam.
-
Posts are to be related to self-hosting.
-
Don't duplicate the full text of your blog or readme if you're providing a link.
-
Submission headline should match the article title.
-
No trolling.
-
Promotion posts require active participation, with an account that is at least 30 days old. F/LOSS without a paywall has exceptions, with requirements. See the rules link for details. Tags [CBH] or [AIP] are required, see the links in Rule 8 for details.
-
AI-related discussions and AI-involved promotional posts have additional requirements for tagging, as noted in Rule 7 and the AI & Promotional Post Expanded Rules post, and find example disclosures here.
Resources:
- selfh.st Newsletter and index of selfhosted software and apps
- awesome-selfhosted software
- awesome-sysadmin resources
- Self-Hosted Podcast from Jupiter Broadcasting
Any issues on the community? Report it using the report flag.
Questions? DM the mods!
That's quite fascinating, didn't realize Wireguard could be blocked in that way (although the WG traffic is pretty obvious looking, so it makes sense). The only solution I know of without a need for a VPS is hosting everything on Tor. Wildly private and secure, but also wildly slow. Beyond that, there are a number of ways of using a VPS to similar effect, I know people have used Cloudflare Tunnel to similar effect in the past.
Also, there are apparently quite a number of wiregaurd derivatives which protect better against detection and blocking methods. amnezia and wstunnel are the two that came up. Likewise, you will need a VPS, and might even be able to set up a tailscale-like coordination server that way (maybe with headscale, or maybe with one of its competitors like NetBird).
ZeroTier might also get the job done, but I really don't know much about it.
Hope this helps, and good lucks!
Acronyms, initialisms, abbreviations, contractions, and other phrases which expand to something larger, that I've seen in this thread:
| Fewer Letters | More Letters |
|---|---|
| CGNAT | Carrier-Grade NAT |
| DNS | Domain Name Service/System |
| ISP | Internet Service Provider |
| NAT | Network Address Translation |
| SSH | Secure Shell for remote terminal access |
| TLS | Transport Layer Security, supersedes SSL |
| Unifi | Ubiquiti WiFi hardware brand |
| VPN | Virtual Private Network |
| VPS | Virtual Private Server (opposed to shared hosting) |
[Thread #84 for this comm, first seen 21st Aug 2026, 16:20] [FAQ] [Full list] [Contact] [Source code]
I had luck with zerotier before switching to wireguard, but I imagine it has similar issues as talescale. Worth a try
Can you switch to IPv6? My ISP NATs me on IPv4 but I'm clear through on IPv6 and so that's how I run everything.
I'm assuming the NAT is your ISP's, if it's yours then ignore me.
If you get a Mikrotik router it comes with a back to home VPN server and a dedicated DDNS.
You need to know a bit about network configuration, although the setup wizard is sufficient for most use cases.
When you enable to BTH VPN, it does all of the configuration for you. And it works for me behind a double NAT
I believe the back to home VPN from MikroTik is also wireguard. At least it is on mine. No idea if you can use a different VPN solution with it.
Possibly Tor? It supports TCP traffic so SSH should work
Outside of that I would look into censorship resistant protocols and techniques. What country are you in?
OpenVPN on port 443 would be my guess. Just regular nat or carrier grade nat.
Run ssh on an Onion Service.
I'll recommend this new VPN thing :
Its new so its evolving quickly with weekly releases and nightly builds.
Lots of people have told me about their grievance list due to AI having a big part in the development. It's a bunch of guys in the team, so there's the human element there.
As for my opinion, it's the only VPN I've managed to get working on my own.
I lost connection yesterday and I am not sure what happened but my home computer and my phone were on the same VPN constantly for a week. Jumping from the house WiFi to 5g didn't break the VPN connection but it did take a few seconds the first time I did it.
My other option would be Tailscale.
Update on the lost connection. I had restarted my computer and that changed my firewall device name for the VPN. So it was not rayfish related. It's been pretty steady since.