3 ms·
I do something similar, with a router flashed with openwrt. If there's a physical router/ethernet port I can plug into great, if not I run one of the radios in
by DistractionRect 3y ago
I do something similar, with a router flashed with openwrt. If there's a physical router/ethernet port I can plug into great, if not I run one of the radios in client mode to connect to the wifi.
All traffic is secured with wireguard to my home router, and then goes through my ISP. The wireguard tunnel is wrapped in an error correcting tunnel; it makes a huge difference on the usability a lot of public APs.
- muppetman 3y agoEdit: I apologise I see you have answered this below. What is your error correcting tunnel? Given that Wireguard is UDP and that any tunneled TCP that gets dropped should just be handled by TCP, why encapsulate Wireguard in something else? I certainly find Wireguard itself improves many Public Wifi networks, I've never thought to encapsulate it further.
- DistractionRect 3y ago> any tunneled TCP that gets dropped should just be handled by TCP, why encapsulate Wireguard in something else? That's the thing, TCP doesn't really handle lossy connections well. A moderate lossy link might do udp traffic like video fine, but be practically unusable for TCP traffic.
- Helmut10001 3y agoI think these setups are fantastic. Here [1] I wrote about my IPSEC-setup on a portable private Wifi network based on a Protectli that I connected to someone's Wifi. [1]: https://du.nkel.dev/blog/2021-11-19_pfsense_opnsense_ipsec_cgnat/ https://du.nkel.dev/blog/2021-11-19_pfsense_opnsense_ipsec_c...
- bane 3y agoOut of curiosity how do you deal with situations where the public wifi has one of those middle pages that you have to type in or click something (captive portal?) before the access point grants access?
- DistractionRect 3y agoDnsmasq has a neat feature where you can populate ipsets/nftsets with responses to dns queries. So I have it populate a set with the IPs for sites like neverssl.com, and use a firewall rule to route requests to destinations in the set through wan without sending it through the VPN. Usually works.
- gumby 3y agoOne way is to change the MAC address of your laptop to that of the router, authenticate, and then connect the router (and change your laptop back)
- retrobox 3y agoCan you share more details on the setup of the error correcting tunnel? That sounds very interesting!
- DistractionRect 3y agoIt's been a while since I set it up, but iirc I ended up going with https://github.com/wangyu-/UDPspeeder https://github.com/wangyu-/UDPspeeder Pretty sure I used the suggested config and it's been working flawlessly in the background. Or something like that. With wireguard, it's just a matter of pointing the config at the local socket for the fec tunnel (or any other type of tunnel, there was a dicussion about making it look like TCP http traffic the other day), so it's pretty much plug and play.
- retrobox 3y agoThank you! That’s very helpful to know. First time I’ve even heard of things like this but when using low quality networks I can see how this would be great!