# VPN transit via VM 213 and Vultr Date: 2026-09-27 to 2026-09-28 ## Goal Provide access from Russian residential/mobile networks to services restricted by Russian network filtering, while retaining the existing foreign egress on Vultr. ## Verified network facts - Test host `3060`: `46.39.251.163`, connection from Khimki / Iskratelecom. - Transit VM `213`: `5.172.178.213`, public egress observed as `5.172.178.65`; hosted in NUBES data centre. - Vultr addresses: primary `95.179.252.111`; secondary `104.238.177.67`. - `3060 -> 213`: ICMP approximately 3 ms, 0% loss. - `213 -> Vultr`: ICMP approximately 34 ms, 0% loss; HTTPS response returned in about 0.07-0.11 s. - Direct `213 -> Vultr` test file transfer: 10 MiB in 1.59 s, about 6.27 MiB/s / 50.2 Mbit/s. - Direct `3060 -> Vultr` test file transfer timed out / was throttled. - Direct `213 -> OVH proof endpoint`: 10 MiB in 1.18 s, about 8.5 MiB/s. - Direct access from `213` to YouTube and Telegram failed with `HTTP=000` and timeout/SSL errors, while OVH and Google returned HTTP 200. Therefore a foreign egress remains required for those services. ## Persistent changes on VM 213 - Created backup: - `/etc/nginx/sites-available/check.kube5s.ru.bak_vpn` - Modified: - `/etc/nginx/sites-available/check.kube5s.ru` - Added an Nginx `/ws` reverse-proxy location with: - upstream `https://95.179.252.111:443` - SNI `vipien.kube5s.ru` - upstream Host header `vipien.kube5s.ru` - WebSocket upgrade headers - 3600-second proxy timeouts - Ran `nginx -t` successfully and reloaded Nginx. - Existing unrelated Nginx warnings about duplicate `contracts.kube5s.ru` server names remained. ## Persistent/previously existing changes on Vultr The following configuration was read or used during validation: - `/etc/nginx/conf.d/vipien.conf`: TLS/WebSocket endpoint for `vipien.kube5s.ru`. - `/etc/v2ray-agent/xray/conf/08_VLESS_ws_inbound.json`: VLESS WebSocket inbound on `127.0.0.1:10086`, path `/ws`. - `/etc/systemd/system/hysteria-server.service`: Hysteria service was stopped and disabled; it was not changed in this work. - Xray service was confirmed active. - Nginx service was confirmed active. - Cloudflared tunnel configuration was inspected earlier, but it is not used by the final working route. - A temporary 10 MiB test file was created on Vultr and removed after testing. ## Temporary files on test VM 3060 The following temporary client files were created under `/tmp/xray-test/` for validation and are not repository files: - `client-cf.json` - `client-213.json` - `client-directip.json` - temporary log/test artifacts where applicable The files contained test Xray client configurations. They were used only to verify the route from `3060`; no permanent system service was installed there. ## Final tested route `client in Russia -> 5.172.178.213:443 -> Nginx WebSocket proxy -> 95.179.252.111:443 -> Xray -> Internet` Final test from `3060` through the route: - observed outbound IP: `95.179.252.111` - 10 MiB OVH download: 1.76-1.91 s - measured speed: approximately 5.5-6.0 MiB/s ## Final client parameters - Address: `5.172.178.213` - Port: `443` - UUID: existing UUID used by the Vultr Xray inbound - TLS SNI: `check.kube5s.ru` - WebSocket path: `/ws` - WebSocket Host: `vipien.kube5s.ru` The final direct-IP test used Xray 26.3.27. The client-side `allowInsecure` option was not used because this Xray version reports that the option was removed. ## Secondary Vultr IP Before removal, the Nginx upstream on VM 213 was switched from `104.238.177.67` to `95.179.252.111`. A post-switch end-to-end test succeeded, with outbound IP `95.179.252.111` and approximately 6.0 MiB/s. No Vultr IP deletion was performed in this work. The secondary address was only confirmed as no longer referenced by the transit configuration. ## Scope audit - No repository source/configuration files were edited before this record. - `git status` was clean before this documentation file was created. - This documentation file is the only workspace file created by the current documentation action. - Server-side files were changed on VM 213 and earlier on Vultr; temporary test files were also created on VM 3060. - No commit was created for this record. ## Important limitations The measurements prove the route worked at test time. They do not guarantee permanent availability: NUBES, Vultr, upstream providers, or network filtering policy can change independently.