4.4 KiB
VPN transit via VM 213 and Vultr
Date: 2026-09-27 to 2026-09-28
Goal
Provide access from Russian residential/mobile networks to services restricted by Russian network filtering, while retaining the existing foreign egress on Vultr.
Verified network facts
- Test host
3060:46.39.251.163, connection from Khimki / Iskratelecom. - Transit VM
213:5.172.178.213, public egress observed as5.172.178.65; hosted in NUBES data centre. - Vultr addresses: primary
95.179.252.111; secondary104.238.177.67. 3060 -> 213: ICMP approximately 3 ms, 0% loss.213 -> Vultr: ICMP approximately 34 ms, 0% loss; HTTPS response returned in about 0.07-0.11 s.- Direct
213 -> Vultrtest file transfer: 10 MiB in 1.59 s, about 6.27 MiB/s / 50.2 Mbit/s. - Direct
3060 -> Vultrtest file transfer timed out / was throttled. - Direct
213 -> OVH proof endpoint: 10 MiB in 1.18 s, about 8.5 MiB/s. - Direct access from
213to YouTube and Telegram failed withHTTP=000and timeout/SSL errors, while OVH and Google returned HTTP 200. Therefore a foreign egress remains required for those services.
Persistent changes on VM 213
- Created backup:
/etc/nginx/sites-available/check.kube5s.ru.bak_vpn
- Modified:
/etc/nginx/sites-available/check.kube5s.ru
- Added an Nginx
/wsreverse-proxy location with:- upstream
https://95.179.252.111:443 - SNI
vipien.kube5s.ru - upstream Host header
vipien.kube5s.ru - WebSocket upgrade headers
- 3600-second proxy timeouts
- upstream
- Ran
nginx -tsuccessfully and reloaded Nginx. - Existing unrelated Nginx warnings about duplicate
contracts.kube5s.ruserver names remained.
Persistent/previously existing changes on Vultr
The following configuration was read or used during validation:
/etc/nginx/conf.d/vipien.conf: TLS/WebSocket endpoint forvipien.kube5s.ru./etc/v2ray-agent/xray/conf/08_VLESS_ws_inbound.json: VLESS WebSocket inbound on127.0.0.1:10086, path/ws./etc/systemd/system/hysteria-server.service: Hysteria service was stopped and disabled; it was not changed in this work.- Xray service was confirmed active.
- Nginx service was confirmed active.
- Cloudflared tunnel configuration was inspected earlier, but it is not used by the final working route.
- A temporary 10 MiB test file was created on Vultr and removed after testing.
Temporary files on test VM 3060
The following temporary client files were created under /tmp/xray-test/ for validation and are not repository files:
client-cf.jsonclient-213.jsonclient-directip.json- temporary log/test artifacts where applicable
The files contained test Xray client configurations. They were used only to verify the route from 3060; no permanent system service was installed there.
Final tested route
client in Russia -> 5.172.178.213:443 -> Nginx WebSocket proxy -> 95.179.252.111:443 -> Xray -> Internet
Final test from 3060 through the route:
- observed outbound IP:
95.179.252.111 - 10 MiB OVH download: 1.76-1.91 s
- measured speed: approximately 5.5-6.0 MiB/s
Final client parameters
- Address:
5.172.178.213 - Port:
443 - UUID: existing UUID used by the Vultr Xray inbound
- TLS SNI:
check.kube5s.ru - WebSocket path:
/ws - WebSocket Host:
vipien.kube5s.ru
The final direct-IP test used Xray 26.3.27. The client-side allowInsecure option was not used because this Xray version reports that the option was removed.
Secondary Vultr IP
Before removal, the Nginx upstream on VM 213 was switched from 104.238.177.67 to 95.179.252.111. A post-switch end-to-end test succeeded, with outbound IP 95.179.252.111 and approximately 6.0 MiB/s.
No Vultr IP deletion was performed in this work. The secondary address was only confirmed as no longer referenced by the transit configuration.
Scope audit
- No repository source/configuration files were edited before this record.
git statuswas clean before this documentation file was created.- This documentation file is the only workspace file created by the current documentation action.
- Server-side files were changed on VM 213 and earlier on Vultr; temporary test files were also created on VM 3060.
- No commit was created for this record.
Important limitations
The measurements prove the route worked at test time. They do not guarantee permanent availability: NUBES, Vultr, upstream providers, or network filtering policy can change independently.