From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from mail.lang.hm (syn-045-059-245-186.biz.spectrum.com [45.59.245.186]) (using TLSv1.2 with cipher ADH-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by lists.bufferbloat.net (Postfix) with ESMTPS id B4E593B2A4 for ; Tue, 21 Jan 2025 10:45:32 -0500 (EST) Received: from [10.2.2.53] (unknown [10.2.2.53]) by mail.lang.hm (Postfix) with ESMTP id D6B051F1048; Tue, 21 Jan 2025 07:45:31 -0800 (PST) Date: Tue, 21 Jan 2025 07:45:31 -0800 (PST) From: David Lang To: Sebastian Moeller cc: David Lang , "b. angel" , Dave Taht via Starlink In-Reply-To: Message-ID: References: <269839o2-003o-1756-8r28-3on7q7nsrn54@ynat.uz> <36r7n950-4qs8-1p06-3595-95or55n5p181@ynat.uz> MIME-Version: 1.0 Content-Type: text/plain; charset=US-ASCII; format=flowed Subject: Re: [Starlink] starlink and VPN X-BeenThere: starlink@lists.bufferbloat.net X-Mailman-Version: 2.1.20 Precedence: list List-Id: "Starlink has bufferbloat. Bad." List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 21 Jan 2025 15:45:32 -0000 Sebastian Moeller wrote: > Hi David, > >> On 21. Jan 2025, at 16:22, David Lang via Starlink wrote: >> >> b. angel wrote: >> >>> David, >>> >>> I gave up on open VPN and starlink a while ago. I've implemented wireguard >>> tunnels with success and reliability. >> >> did you end up having to do anything with MTU? Did you use TCP or UDP for your transport? > > Wireguard itself only allows UDP IIRC, you would need an additional outer TCP tunnel if you want/need TCP on the outside... I agree UDP is preferred, I'm just trying to figure out what has successfully worked. In my google searches yesterday I saw posts from Starlink saying that they don't block VPNs (but won't help troubleshoot) and a lot of people saying that they didn't work David Lang >> >> David Lang >> >>> Keith >>> >>> On Mon, Jan 20, 2025, 23:25 David Lang via Starlink < >>> starlink@lists.bufferbloat.net> wrote: >>> >>>> has anyone done any work with openvpn over starlink (especially if they >>>> got the >>>> connectors to completely bypass the router)? >>>> >>>> I've got the basic connectivity working, but am having problems trying to >>>> get >>>> openvpn to work (especially for traffic back through the cgnat to the >>>> router on >>>> the starlink side) >>>> >>>> the logs on the client are reporting link local: (not bound) when trying >>>> UDP, >>>> when I try TCP (and clamp the mtu low) I can connect from the starlink >>>> side (st >>>> least sometimes) but cannot get the routing the other way to work >>>> >>>> David Lang >>>> _______________________________________________ >>>> Starlink mailing list >>>> Starlink@lists.bufferbloat.net >>>> https://lists.bufferbloat.net/listinfo/starlink >>>> >>> >> _______________________________________________ >> Starlink mailing list >> Starlink@lists.bufferbloat.net >> https://lists.bufferbloat.net/listinfo/starlink > >