VPN gateway setup for home network

Hello. I think that in the coming months, heavy restrictions will be imposed on the use of VPN services due to all this age and identity verification madness. I’m not sure how effective the censorship circumvention methods of the VPN providers recommended on this platform really are. Still, it looks like we’ll have to resort to these methods one day.

According to Mullvad’s own statements, its censorship circumvention methods work only in its official apps.

The situation is the same for Proton, except for the Linux app.

IVPN’s censorship circumvention features are available for all desktop applications and iOS (Obfuscation with V2Ray on iOS - IVPN Help); for now, there are no similar features for Android. Additionally, special setups can be made for standalone “obfs” proxies that work on Linux and OpenWRT, and their guides mention these.

I’m looking for a setup that allows me to connect my entire home network to the internet using the official apps of the VPN providers I mentioned above, so that I can enable their censorship circumvention features if needed. Through my online research, I learned that an average user[1] like me can configure a simple Linux single board computer running 24/7 to function as a VPN gateway.

The ideas and recommendations of this community are still very precious to many people like me. Do you think there’s an easier and more functional method that works for everyone, or does the VPN gateway do the job well enough? Perhaps a guide could be created with contributions from expert members.


  1. I’m talking about people with limited networking knowledge who don’t host a server at home and don’t use virtualization or container technologies on a daily basis. ↩︎

1 Like

Well if you look at how everyone else in society is currently operating, it is crystal-clear, they do not bother with any technical setup, which means they also work out-of-the-box.

1 Like

Assuming you live in the UK, what made you believe that? O haven’t seen actual DPI systems rollouts/government contracts on them.

DPI will take years to deploy regardless.

True, but you can connect to their Wireguard servers with AmneziaWG 1.5

Same as with mullvad

obfs, tor obfuscation in general is unfortunately ineffective in today’s world. In restricted countries, people access tor over VPN.

ivpn, mullvad clients can be set up to be encapsulated by sing-box, xray, mihomo etc. Idk about Proton, haven’t tested it personally.

If you really want to learn about advanced networking and network censorship - go for OpenWRT + Mihomo/sing-box. If you just want things to work - vanilla Wireguard will work for any European/American.

2 Likes

Are their servers compatible with the AmneziaWG protocol, or are you referring to setting up a double VPN connection? As far as I know, Windscribe supports the AmneziaWG protocol. However, only their official apps can capable this feature.

I’ll look into this; thank you.

1 Like

TL;DR for you and others to understand what AmneziaWG is.

AmneziaWG was a born from Russian hackathon project. Initially it was relying on packet fragmentation techniques while striving to be compatible with Wireguard servers. You can download a vanilla AmneziaWG client, tweak your Jc, Jmin, jmax, h1-h4 while leaving other option at 0 in order to be Wireguard compatible. AmneziaWG is now funded by AmneziaVPN, a VPN service that develops and maintains a self-hosted one click to deploy set of containerized services for Russians, Iranians, Ukranians, Egyptians and so on to deploy on VPS services. They earn money by providing their hosted VPN subscription option.

AmneziaWG 2.0 introduced new obfuscation techniques because 1.5, similar to Mullvad’s LWO, is detectable by modern DPI systems and became incompatible with vanilla Wireguard servers.

blog suggests that they haven’t deployed 2.0, so it’s kind of irrelevant to stand out as AmneziaWG compatible. It’s nice that they offer AmneziaWG in-app though.

1 Like