Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!


Shells Virtual Desktop
BMail.ag - Secure Email Service
Server.net
CPLicense.net
VPS Server
Buy VPN
Vultr
VMs for AI
HostDare
ReliableSite White-Label Dedicated Hosting for Resellers
InterServer VPS
BMail.ag - Secure Email Service
Best VPN
High-Performance Bare Metal Server Solutions
Karvl.com
Server Mania Cloud Hosting
DataWagon Hosting
AlphaVPS Hosting
Evoxt.com
Clouvider
VPS Hosting with NVMe
Residential IPs in the US & 4G Mobile Proxies in EU & US with Unlimited Bandwidth
ReliableSite White-Label Dedicated Hosting for Resellers
Rabisu - Hosting Solutions
Shells Virtual Desktop
New on LowEndTalk? Please Register and read our Community Rules.

All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.

VPS provider recommendations for personal VPN tunnel with non-standard egress

I'm looking for a small VPS to run as the server end of a personal VPN tunnel. I'm based in Iran and the tunneling techniques that currently work from my side require the server to send packets with non-standard source addressing, so I need a provider whose network doesn't enforce strict source address validation (BCP38) at the edge.

To be very clear about what this is and isn't:

  • Use case: A single tunnel, just for me, connecting my client to this VPS. Low volume. Destination is my own infrastructure only.
  • Not: reflection, amplification, spoofed traffic aimed at third parties, or anything that would generate abuse complaints. Zero interest in that.
  • Restrictions are fine. If the provider wants to rate-limit egress, whitelist destinations, or otherwise put guardrails on the account to prevent misuse, I'm happy to work within that. The goal is a working tunnel, not unrestricted spoofing.

Requirements:

  • KVM, full root, IPv4. IPv6 a bonus.
  • ~$5–10/month range, monthly billing preferred for initial testing.
  • Turkey or Europe preferred for latency from Iran, but other locations are fine if the network policy is right.
  • Payment method flexibility appreciated (Iranian cards don't work with most providers; crypto is fine on my end).

Has anyone here set up something similar in the last 6 months? Happy to take DMs if you'd rather not name providers publicly. I understand this topic is sensitive and I'm not looking to burn anyone's working provider — just looking for a starting point.
Thanks.

Thanked by 1MAXKO_Hosting
«1

Comments

  • conceptconcept Member
    Thanked by 1oloke
  • GPoeGPoe Member

    @servers_guru @RIYAD I recommend for those provider.

    Thanked by 1RIYAD
  • @GPoe said: recommend

    Will they agree to what OP is asking though?

    Thanked by 1tentor
  • k2evilk2evil Member

    @GPoe said:
    @servers_guru @RIYAD I recommend for those provider.

    Thanks! Is BCP38 disabled by default on their networks, or should I ask when ordering?

  • k2evilk2evil Member

    Thanks! Is that user a provider themselves? Would they be open to the kind of setup I described?

  • MurvMurv Member, Megathread Squad

    @k2evil said:

    Thanks! Is that user a provider themselves? Would they be open to the kind of setup I described?

    Hello, no.
    I'm just an anime gooner, or an important asset of the state depending on who you ask.

    Thanked by 2rpqu drow
  • WebProjectWebProject Veteran, 🚩 Host Rep Tag Suspended

    doesn't enforce strict source address validation (BCP38)

    Very unusual request, what kind of legal activity requires BCP38 to be disabled?

  • k2evilk2evil Member

    @WebProject said:

    doesn't enforce strict source address validation (BCP38)

    Very unusual request, what kind of legal activity requires BCP38 to be disabled?

    @k2evil said: I'm based in Iran and the tunneling techniques that currently work from my side require the server to send packets with non-standard source addressing,

  • conceptconcept Member
    edited April 19

    @WebProject said:

    doesn't enforce strict source address validation (BCP38)

    Very unusual request, what kind of legal activity requires BCP38 to be disabled?

    Not unusual given circumstances

    @Murv said:

    The gov't here whitelists certain IPs even during the shutdowns, people spoofage such IP from both inside and outside to send UDP/ICMP packets.

    Thanked by 3oloke k2evil Hayzee
  • k2evilk2evil Member
    edited April 19

    @Murv said:

    @k2evil said:

    Thanks! Is that user a provider themselves? Would they be open to the kind of setup I described?

    Hello, no.
    I'm just an anime gooner, or an important asset of the state depending on who you ask.

    Lol... I see now :D
    Do you have any suggestions though?

  • MurvMurv Member, Megathread Squad
    edited April 19

    @k2evil said: Lol... I see now :D
    Do you have any suggestions though?

    It's prolly over your budget but maybe ask @MAXKO_Hosting

  • k2evilk2evil Member
    edited April 19

    @Murv said:

    @k2evil said: Lol... I see now :D
    Do you have any suggestions though?

    It's prolly over your budget but maybe ask @MAXKO_Hosting

    I know... I kinda low-balled on the budget, but as long as it's in a reasonable range, I'll be down for that.
    Thank you very much

    Thanked by 1oloke
  • rpqurpqu Member
    edited April 19

    OOT @k2evil @Murv I read owning starlink equipment in IR carries a death penalty, is it true ?

  • k2evilk2evil Member

    @concept said: Not unusual given circumstances

    Wait till they find out we're using DNS resolvers to shatter our packets into a million pieces, ship 'em out, and catch 'em on the other side. XD

  • MurvMurv Member, Megathread Squad

    @rpqu said:
    OOT @k2evil @Murv I read owning starlink equipment in IR carries a death penalty, is it true ?

    Nah, not death penalty.
    If it's your first time you prolly won't even get jailed, they'd just have you take a written pledge to not get one again.

    Thanked by 1forest
  • k2evilk2evil Member
    edited April 19

    @rpqu said:
    OOT @k2evil @Murv I read owning starlink equipment in IR carries a death penalty, is it true ?

    It's not an automatic execution but it can lead to death penalty under some circumstances. If they suspect you were spying on them using starlink

  • olokeoloke Member, Host Rep

    @k2evil said:

    @Murv said:

    @k2evil said: Lol... I see now :D
    Do you have any suggestions though?

    It's prolly over your budget but maybe ask @MAXKO_Hosting

    I know... I kinda low-balled on the budget, but as long as it's in a reasonable range, I'll be down for that.
    Thank you very much

    I think @MAXKO_Hosting mentioned (in a now removed thread) that Bulgaria (location with IPHM enabled) is out of stock currently due to high demand (i wonder what that might be)...

  • MurvMurv Member, Megathread Squad

    @oloke said: Bulgaria

    Their Serbia location can do spoofage too

  • MurvMurv Member, Megathread Squad

    @k2evil do you happen to know a provider on IR side?

    Thanked by 1oloke
  • k2evilk2evil Member

    @Murv said:
    @k2evil do you happen to know a provider on IR side?

    Nope, that's even a harder task to find one and probably much more expensive, but I was thinking to use dns tunnel for uplink for now

  • rpqurpqu Member

    @Murv said:

    @rpqu said:
    OOT @k2evil @Murv I read owning starlink equipment in IR carries a death penalty, is it true ?

    Nah, not death penalty.
    If it's your first time you prolly won't even get jailed, they'd just have you take a written pledge to not get one again.

    @k2evil said:

    @rpqu said:
    OOT @k2evil @Murv I read owning starlink equipment in IR carries a death penalty, is it true ?

    It's not an automatic execution but it can lead to death penalty under some circumstances. If they suspect you were spying on them using starlink

    I see

    # Imagine in Farsi
    Officer: Okay, please sign this pledge. Meanwhile, let me check whether you're spy or not.
    @Murv : Yes Sir
    Officer: Good God, why do you have 4TB of Japanese cartoon porn
    @Murv: >_<
    
  • WebProjectWebProject Veteran, 🚩 Host Rep Tag Suspended
    edited April 19

    @k2evil said: @k2evil said: I'm based in Iran and the tunneling techniques that currently work from my side require the server to send packets with non-standard source addressing,

    Are you aware that without BCP38 verification allow forge the IP addresses, so I don't think any provider be able to provide such service and nothing to do where you based!

    Definition:

    BCP38 (RFC 2827) verification ensures that network providers implement ingress filtering to drop packets with forged source IP addresses, preventing IP spoofing and reducing Distributed Denial of Service (DDoS) amplification attacks.

    @concept said: Not unusual given circumstances

    So they need to be allowed to hack? I don't think so, as such service is commonly is used for hacking and DDOS attacks.

  • forestforest Member

    @WebProject said: Are you aware that without BCP38 verification allow forge the IP addresses, so I don't think any provider be able to provide such service and nothing to do where you based!

    That's exactly the point, and there are providers here who are willing to support that.

    @WebProject said: So they need to be allowed to hack? I don't think so, as such service is commonly is used for hacking and DDOS attacks.

    There are legitimate reasons to want to spoof IPs, such as bypassing internet censorship. @Murv is literally doing that right now and he's not hacking or DDoSing anyone. In an age of frequent internet shutdowns in countries at war, sometimes the only way around it involves spoofing the IP address of a whitelisted service.

  • sshboxsshbox Member

    We literally already had this discussion. How about merging these threads?

    Thanked by 1k2evil
  • forestforest Member

    @sshbox said:
    We literally already had this discussion. How about merging these threads?

    It comes up over and over as new people post questions looking for the same thing.

    Thanked by 2mans_xd rpqu
  • sshboxsshbox Member

    Fixing search sure would be a good first step to get people to use search...

    Thanked by 3forest tentor k2evil
  • MurvMurv Member, Megathread Squad

    @sshbox said:
    We literally already had this discussion. How about merging these threads?

    Previous thread was nuked

  • forestforest Member

    @Murv said:

    @sshbox said:
    We literally already had this discussion. How about merging these threads?

    Previous thread was nuked

    Why? It's not for blackhat purposes, so it's not against the rules.

    Thanked by 2384_cz k2evil
  • MurvMurv Member, Megathread Squad

    @forest said: Why? It's not for blackhat purposes, so it's not against the rules.

    Because some reguarded guy was pissing and moaning while tagging jbiloh about how people shouldn't be taught to break laws of their countries or something.

    I guess a country's laws precedes morals and human rights.

  • forestforest Member

    @Murv said:

    @forest said: Why? It's not for blackhat purposes, so it's not against the rules.

    Because some reguarded guy was pissing and moaning while tagging jbiloh about how people shouldn't be taught to break laws of their countries or something.

    I guess a country's laws precedes morals and human rights.

    Well that's stupid. It's not going to stop these threads, of course. It's a shame that jbiloh is pro-blackout, though.

Sign In or Register to comment.