5 ms·
Thanks. I'll be taking a look at tunelling soon. The material around it is difficult to read and put together to be honest. I'm right now using Nord via their
by nstart 7y ago
Thanks. I'll be taking a look at tunelling soon. The material around it is difficult to read and put together to be honest.
I'm right now using Nord via their ovpn files. Somehow it made its way through one ISP ruleset.
For my digital ocean box, I asked someone else to use tunnelblick with the ovpn file I provided them to see if it worked (they were in another country) and it worked. This makes me believe it's most likely a country level issue.
In general though I'd like to learn about networking more thoroughly and set up a censorship resistant option which I can help others to setup and share as well later on. Any primers/pointers are appreciated too. I'll start with all the things you mentioned though.
- sjy 7y agoI suggest looking into WireGuard [1]. I found it easier to use than OpenVPN, and I think it will displace it as the de facto standard when it eventually gets merged into the Linux kernel. You'll have to use lower-level configuration tools to get started with it, which I am finding helpful to pursue the same goal of learning about networking more thoroughly. [1]: https://news.ycombinator.com/item?id=17659983 https://news.ycombinator.com/item?id=17659983
- pferde 7y agoWhile like Wireguard a lot, it won't displace Openvpn completely, for the simple reason that it only works over UDP, and cannot work over TCP, unlike Openvpn.
- zx2c4 7y agoTransforming generic layer 3 datagrams into traffic that looks like something else is the general domain of obfuscation. Making WireGuard traffic look like TCP is one form of such obfuscation. Making it look like TLS or DNS or HTTP are other forms. (Actually putting layer 3 traffic into framing inside a legit TCP stream is inefficient and the wrong way to think about the problem domain.) No promises, but I'm expecting some nice things to come in this domain of generic obfuscation mechanisms to punch through various forms of filtering.
- pferde 7y agoInefficient as it may be, it is something I simply need for my use case - connecting home from a certain network which only allows outgoing connections on a handful of TCP ports.
- zx2c4 7y agoNo. You need your traffic to look like TCP, for your particular network filtering. But you do not need to achieve that by using the naive and inefficient approach of, "stick the packets into a TCP stream prefixed by a length field." Rather, there are more clever tricks for making your traffic look like TCP, which generally fall into the same realm as other obfuscation mechanisms.
- snvzz 7y agossh -D1234 remotehost gives you a local SOCKS proxy at port 1234 that goes through remotehost. Other than that, do investigate DNS on HTTPS and DNS on TLS. I recommend setting up something like dnscrypt-proxy to serve as the DNS resolver for your LAN.