Wireguard is blocked in my country, so I no longer can use Tailscale or other Wireguard-based solutions. My home server is behind a NAT. What other ways of secure private connection can I use?
I have successfully setup trojan / trojan-go on my server. It uses port 443 and will return a standard website if the connection is not recognized as an authorized trojan-go client. As stealth as it can get.
Self hosted networking! Legitimately one of my favourite topics
You won’t get around the requirement of a publicly reachable endpoint. That can either be a small server with a public ip or dynamic DNS to your home with port forwarding for the VPN.
A classic option is OpenVPN. You can run it on Port 443 in TCP mode and while it won’t be performant, it has a better chance of bypassing most simple blocks
Other than that I’m a fan of completely decentralized mesh VPNs.
The one I use and am most familiar with is Yggdrasil. Connections can be established over TCP, TLS or QUIC on any port you want.
I’ve written a somewhat lengthy comment under this post. One advantage to Yggdrasil would be its existing public network. If you can firewall of your home lab to the point where joining the public network doesn’t expose a security risk to your local network, you could use that to transport your traffic instead of having your own public node or port forwarding.The same post also mentions Anywherelan, it’s intended to have better NAT handling out of the box by using community nodes.
Then there’s also EasyTier mentioned at the bottom, it is a Chinese project and those tend to have good censorship resistance.
Finally I’ll mention Nebula, it requires at least one coordination server but might also be an option
Nebula might actually work as it doesn’t use Wireguard
Port forward your SSH-server. You can forward ports through SSH to access web services or others running on the server or anything else in the network.
But only allow access through keys. And maybe try to use a different port than 22. That usually gets hammered a lot, trying to find accounts with weak passwords.
Changing the port doesn’t actually accomplish much
Best practice is to just harden SSH so that not traffic gets nowhere
Wow. Do they block VPNs inside your country too?
Anyway, there’s openvpn and there’s nebula (I think nebula doesn’t use wireguard… do double-check), or you look into things built specifically to hide traffic (keyword: “vpn obfuscation”).
No idea if VPN protocols other than wireguard may be blocked too (probably?).
No idea if trying too hard to circumvent government policies may get you added to some list you’d rather not be in.Wireguard is effectively blocked in China, from my experience so far.
China uses deep packet inspection so that makes sense
I think the the great Firewall is less restrictive with QUIC traffic. It might be worth trying fragmented QUIC as from what I’ve read the GFW struggles to reconstruct the traffic
Possibly Tor? It supports TCP traffic so SSH should work
Outside of that I would look into censorship resistant protocols and techniques. What country are you in?
Tor is slow and… also blocked here 😁
I know of many working VPN protocols but I don’t know how to use them to route traffic through an intermediary VPS (bc my home server is behind a NAT)
You can use Tor snowflakes or bridges to bypass restrictions





