DEV Community

Discussion on: tinc-boot - full-mesh VPN without pain

Collapse
 
cheshmghermezi profile image
چشم قرمزی

Hi there,
Thank you so much for creating this.
I am living in Iran and as you may know government is totally shutdown the internet here. Only few datacenters have internet access (of course with censorship applied) and we can access those datacenters via INTRANET through home connections.
Home Connection -----> iran dc (node1 and node2 in different dcs) -------> internet (node3 , node4 in abroad dcs)
I have some questions:

  1. Why not running it on port 80/443 ? how to change ports?
  2. How to route some ips through node1 and node 2 only? The nodes in Iran dcs are under heavy monitoring and I should route all Iran geo IPs through these nodes. So their traffic will look much normal.
  3. How to setup and add pfsense as the client?
  4. Can I donate via BTC to you for this great effort and how? Sorry for my bad english and thanks for supporting freedom.
Collapse
 
reddec profile image
reddec • Edited

I heard about it and would like to wish your country good luck in this hard situation!

  1. There are no restrictions. You may use flag --port during configuration by tinc-boot
  2. You may restrict connections from home to node 1, from node 1 to node 2 and so on by removing ConnectTo parameter in host file. However you also should to disable tinc-boot because it will overwrite configuration. So in this case tinc-boot will be used only as configuration wizard) However, I should remind, that it could be useful only in case you are caring of traffic detection, because tinc by itself can detect blocked connections (edges) and re-route traffic automatically.
  3. Not sure that I can help with it, however you only need to allow udp and tcp traffic for specified port chosen on step 1
  4. Donating always welcome)
  • ETH: 0xA4eD4fB5805a023816C9B55C52Ae056898b6BdBC
  • BTC: bc1qlj4v32rg8w0sgmtk8634uc36evj6jn3d5drnqy