Files
tf_provider/HISTORY/2026-09-28_vpn-transit-213-vultr.md
T

4.4 KiB

VPN transit via VM 213 and Vultr

Date: 2026-09-27 to 2026-09-28

Goal

Provide access from Russian residential/mobile networks to services restricted by Russian network filtering, while retaining the existing foreign egress on Vultr.

Verified network facts

  • Test host 3060: 46.39.251.163, connection from Khimki / Iskratelecom.
  • Transit VM 213: 5.172.178.213, public egress observed as 5.172.178.65; hosted in NUBES data centre.
  • Vultr addresses: primary 95.179.252.111; secondary 104.238.177.67.
  • 3060 -> 213: ICMP approximately 3 ms, 0% loss.
  • 213 -> Vultr: ICMP approximately 34 ms, 0% loss; HTTPS response returned in about 0.07-0.11 s.
  • Direct 213 -> Vultr test file transfer: 10 MiB in 1.59 s, about 6.27 MiB/s / 50.2 Mbit/s.
  • Direct 3060 -> Vultr test file transfer timed out / was throttled.
  • Direct 213 -> OVH proof endpoint: 10 MiB in 1.18 s, about 8.5 MiB/s.
  • Direct access from 213 to YouTube and Telegram failed with HTTP=000 and timeout/SSL errors, while OVH and Google returned HTTP 200. Therefore a foreign egress remains required for those services.

Persistent changes on VM 213

  • Created backup:
    • /etc/nginx/sites-available/check.kube5s.ru.bak_vpn
  • Modified:
    • /etc/nginx/sites-available/check.kube5s.ru
  • Added an Nginx /ws reverse-proxy location with:
    • upstream https://95.179.252.111:443
    • SNI vipien.kube5s.ru
    • upstream Host header vipien.kube5s.ru
    • WebSocket upgrade headers
    • 3600-second proxy timeouts
  • Ran nginx -t successfully and reloaded Nginx.
  • Existing unrelated Nginx warnings about duplicate contracts.kube5s.ru server names remained.

Persistent/previously existing changes on Vultr

The following configuration was read or used during validation:

  • /etc/nginx/conf.d/vipien.conf: TLS/WebSocket endpoint for vipien.kube5s.ru.
  • /etc/v2ray-agent/xray/conf/08_VLESS_ws_inbound.json: VLESS WebSocket inbound on 127.0.0.1:10086, path /ws.
  • /etc/systemd/system/hysteria-server.service: Hysteria service was stopped and disabled; it was not changed in this work.
  • Xray service was confirmed active.
  • Nginx service was confirmed active.
  • Cloudflared tunnel configuration was inspected earlier, but it is not used by the final working route.
  • A temporary 10 MiB test file was created on Vultr and removed after testing.

Temporary files on test VM 3060

The following temporary client files were created under /tmp/xray-test/ for validation and are not repository files:

  • client-cf.json
  • client-213.json
  • client-directip.json
  • temporary log/test artifacts where applicable

The files contained test Xray client configurations. They were used only to verify the route from 3060; no permanent system service was installed there.

Final tested route

client in Russia -> 5.172.178.213:443 -> Nginx WebSocket proxy -> 95.179.252.111:443 -> Xray -> Internet

Final test from 3060 through the route:

  • observed outbound IP: 95.179.252.111
  • 10 MiB OVH download: 1.76-1.91 s
  • measured speed: approximately 5.5-6.0 MiB/s

Final client parameters

  • Address: 5.172.178.213
  • Port: 443
  • UUID: existing UUID used by the Vultr Xray inbound
  • TLS SNI: check.kube5s.ru
  • WebSocket path: /ws
  • WebSocket Host: vipien.kube5s.ru

The final direct-IP test used Xray 26.3.27. The client-side allowInsecure option was not used because this Xray version reports that the option was removed.

Secondary Vultr IP

Before removal, the Nginx upstream on VM 213 was switched from 104.238.177.67 to 95.179.252.111. A post-switch end-to-end test succeeded, with outbound IP 95.179.252.111 and approximately 6.0 MiB/s.

No Vultr IP deletion was performed in this work. The secondary address was only confirmed as no longer referenced by the transit configuration.

Scope audit

  • No repository source/configuration files were edited before this record.
  • git status was clean before this documentation file was created.
  • This documentation file is the only workspace file created by the current documentation action.
  • Server-side files were changed on VM 213 and earlier on Vultr; temporary test files were also created on VM 3060.
  • No commit was created for this record.

Important limitations

The measurements prove the route worked at test time. They do not guarantee permanent availability: NUBES, Vultr, upstream providers, or network filtering policy can change independently.