• Welcome to Hurricane Electric's IPv6 Tunnel Broker Forums.

Dealing CGNAT to using Tunnelbroker with Wireguard

Started by rifqisugoi, June 14, 2022, 05:18:54 AM

Previous topic - Next topic

rifqisugoi

Hello there,

Is there any possibility to supporting Wireguard? Because, most of the ISPs here use CGNAT to deal with IPv4 exhaustion. Not all people can rent a VPS, and the average specifications offered are very "unreasonable" here. And on average, they also overselling it, very poor international connections, etc.

I'm really hoping HE.NET will supporting Wireguard VPN protocol to boosting IPv6 users, and if i'm not forgot, in the past, HE.NET also offering Tunnelbroker using PPTP :)

Thanks

tjeske

You could use Route48 instead of HE. They do offer IPv6 tunnels over Wireguard.

sixdev

Quote from: tjeske on January 23, 2023, 01:11:30 AMYou could use Route48 instead of HE. They do offer IPv6 tunnels over Wireguard.

I found myself in the same situation and I followed your advice up until recently (thanks by the way!)

Unfortunately Route48 shut down due to abuse, any alternatives out there?

brianjmurrell

So, I just moved to a location where I am forced behind CGNAT.  I was so bummed to learn that 6-in-4 (which is what HE.net Tunnelbroker is) can't work with CGNAT.

But due to having CGNAT whereas my previous provider gave me my own IP address, and I ran services (mail, web, Nextcloud, etc.) for family and friends on that IP address I decided to go down the route of getting a (free) Oracle Cloud VPS so that I could have an IPv4 address that I could forward connections from over WireGuard to my homelab server (i.e. the server that used to have it's own IPv4 address).

Well, in all honesty I had the Oracle VPS for a longer time as my external domain's nameserver.  But now it was going to come in handy to forward IPv4 connections to my homelab (which is now behind CGNAT) to.

It did occur to me that I could also run HE.net's Tunnelbroker on that Oracle VPS host and delegate and route (real routing, no NAT!!) an IPv6 subnet to my homelab also over that WireGuard connection.  But I was dreading adding yet another latency in the form of my_homelab->Oracle_VPS->HE.net_PoP.

But boy was I ever happy to discover that my Oracle VPS must be hosted in the same facility as my HE.net PoP since the latency from that VPS host to the HE.net PoP was sub-millisecond.  So in the end even though I was adding my Oracle VPS into the path, the latency was the same as when I had an IPv4 address on my homelab and used HE.net Tunnelbroker from there.

SO the moral of the story is to find a VPS, hopefully at the free tier (you don't need much to simply run HE.net and WireGuard) that is in the same facility as your nearest HE.net PoP to avoid adding another latency to your connection.

As an aside, as much of an abomination as CGNAT is, what is even worse is ISPs that use it for IPv4 and don't also deploy GUA IPv6 along side it.