P2P Gaming: Avoiding CG-Strict NAT with VPN Datacenter Hosted IP

tl;dr: Help me, Obi-Wan, you’re my only hope.

Summary:

I am trying to play peer-to-peer games while streaming them on Twitch as an Affiliate. I have a degraded performance when I enter peer-to-peer areas, and it crushes the stream and the data output gets tanked until the stream stutters and even disconnects. If not p2p gaming, it’s stellar!

The Problem:

I am stuck with a CG-Strict NAT service provider. And so I try to use a VPN Datacenter-Hosted Static IP with Forwarded Ports in a different country using Wireguard with a Specified Domain List and full Port Forward setup in LuCI, including Custom Rules.

Key detail:

When I look at ssh output while gaming, I can see that 0 data flows through my intended peer-to-peer ports. :frowning: Seems I’m not setting myself up properly.

I have used Google Gemini LLM to try to get me setup and after a LOT of effort, my data still doesn’t flow through the VPN tunnel for my Specified Doman + Forwarded Ports using them.

My basic setup:

  • Router: GL-MT6000 4.9.1
  • 850 Mb Up/Down Fiber Optics in Viet Nam which has a Carrier-Grade Strict NAT
  • Max Cap of 880 Mbps Up and Down with LuCI’d cake SQM (A+ Bufferbloat Rating)
  • Windscribe Pro Static IP Datacenter with Forward Ports (imported into GL’s VPN Client)
  • VPN Dashboard Connected 1 Device (PC) to 7 Addresses (Domains like Steam.com)
  • Network > IPv6 Enable, LAN, Mode NAT6, DNS acquisition method Auto
  • Security > NAT Mode: Enable Full Cone NAT ON (just turned it on, haven’t tested yet)
  • Ports Forwarded From [wgclient1] to [this device] to Lan IP __ port __
  • Firewall - Custom Rules (currently, I tried iptables first, no data flowed)
    • nft add chain inet fw4 mangle_prerouting { type filter hook prerouting priority mangle; policy accept; } 2>/dev/null
    • nft flush chain inet fw4 mangle_prerouting 2>/dev/null
    • nft add rule inet fw4 mangle_prerouting ip saddr 192.xxx.x.xxx udp dport { 2456-2458, 4950, 4955, 27015, 27031-27036, 30640 } meta mark set 0x1000 counter
    • nft add rule inet fw4 mangle_prerouting ip saddr 192.xxx.x.xxx udp sport { 2456-2458, 4950, 4955, 27015, 27031-27036, 30640 } meta mark set 0x1000 counter
  • :backhand_index_pointing_up: none of this works, data do not flow
  • ip show rules normal, most all that stuff is well-formed, data still don’t flow

Attempts:

I have tried so many things beyond the obvious basics in LuCI, which are insufficient, including PREROUTING mangling with nft commands using –dport and –sport or else older-style iptable injections in the Custom Rules section. Big problem with all of this is that I’m not specialist in any way, I just try to vibe my way through it using LLMs. It’s brutal, hey!

P.S. I’d be willing to just put all my data through my Singapore Datacenter, but it seems like that extra couple of hops is something I’d better like to avoid since other than peer-to-peer gaming, I’m blazing and can multi-stream at 60FPS 1440p on four+ platforms at once.

Hi,

Often with p2p games they use a technique called port hole punching this essentially means that every source traffic to wan the firewall accepts connections and the other side can now also communicate back on this same line meaning a handshake is made.

Upon this trust, that connection what can communicate back can forward other connections and it should not be a issue.

^ that connection can be simply the server loading the server list, if they have a smart implementation they use some kind of hub/list style, that server becomes the middle man subscribing other peers to you and from you.

The degraded performance is more when you intend to host, people cannot directly join you if you did not iniated the connection first, but this depends on game implementation to, as stated above if they use a smart implementation the server connection still can advertise people to join you on the premise of the trusted line handshake it will be only a little slower, in gta online for me this happen often when ppl exit from jobs rather than a direct join.

To come back now to your vpn type of setup.

Alot of games also start to block vpn type of connections to prevent bypasses from the age verification which where heavy laws in the UK.

In my case I played alot gta online, and due my learning curve it is not always noticeable they blocked vpn in my case, but it happens when entering interiors a infinitive black screened loop happen which never ends, cayo perico map despawns at a certain location, all players leaving (sure modders can be a cause, but rockstars blocking mechanism too), sometimes it is obvious then logins give errors, in overall they give you the impression your connection is really bad and leave you in a extremely buggy game, so in my case i split routed only their domain logic but my p2p style traffic remained vpn because playing without it is kind of dangerous especially where this game is highly toxic with cheaters and hackers :face_savoring_food:

My guess is to either try a vpn with a residental ip or maybe try the same split route technique ive been using, it is however never 100% fail proof and less secure, but atleast something than nothing, if for some reason somebody connects to me with a amazon ip, and that same amazon ip appeared in the domain well i have a leak, but as currently there is no better work around at the moment, my performance never degraded only when i was a host.

As current rockstargames seem to use akamai and so far im not aware of people being able to use akamai ips, since it is just cdn.

Can you tell me which game this is?

Hi,

Thank you for providing the detailed configuration.

To help us better understand your actual network setup and determine whether the issue is related to VPN routing, port forwarding, or IPv6, could you please provide the following information?

  1. Which game is affected, and does the issue occur when you host a game, join another player, or in both situations?
  2. Could you please provide a screenshot of the Windscribe Static IP and port-forwarding settings, showing the VPN location, protocol, external port, and internal port?
  3. Could you also provide screenshots of the VPN policy and port-forwarding rule on the GL-MT6000?
  4. As a temporary test, could you please set the affected PC to use the Windscribe VPN tunnel for All Targets , reproduce the same issue, and whether the VPN traffic counter, game performance, or Twitch stream changes during this test?
  5. If it is convenient, could you please also temporarily disable IPv6 on the GL-MT6000, reconnect the VPN, and repeat the same test to see if there is any difference?

You may hide account details and part of the public IP address, and send the information to us via private message.

Thank you for your support and understanding.

How to send private messages:

So cool! I got around to all of your suggestions before coming back to give an sitrep. Problem solved. What a hot mess it was. This is a great router. Not ur fault. See other reply above. All the best, thanks.

-Rick

I have had these described issues with No Man’s Sky on PC.

Now, I continued efforting my situation in a big way, including monitoring Processes like a hawk in real-time as issue occurred and also the use of LatencyMonitor, to catch kernel, driver, and cpu issues.

I learned more after more testing and tinkering. In fact, my 16Gb GPU would start at 25% usage and ~50% RAM fill … now, as I began watching carefully, I saw that as peer-to-peer connections ramped up in No Man’s Sky PC game, my GPU would be be hit harder and harder, until max utilization and max GPU RAM fill, and then the streams would starve out … at the same time, I saw in LatencyMonitor that my CPU was getting hammered beyond belief and only my first core was even being used at a point, with brutal DPC counts (failure at kernel level in my Windscribe and nVidia card both).

So I switched off of Split Tunneling Inclusive within my GL iNet router and went into the Windscribe client instead, where apparently it works better (API level is essentially broken as reported by Windscribe users and even their tech support: damn, I wasted a lot of time, it was the reason for 0 data flow with my Windscribe VPN I set up inside router). That still went very very poorly in the Windscribe client, and so I just quit using Split and put everything through the VPN Static IP of mine in the datacenter … that fixed that, and mainly because (I read) the Windscribe analyzes every single packet that passes through against every domain and application (not only ones active), and I had many. No matter, I gave up on it: because even after no longer Split Tunneling, I still had the LatencyMonitor DPC meltdowns while streaming … wait, it gets interesting now!

So my nVidia can encode 8 streams max. At the time of the problem, I had 8 without realizing it, because Twitch Enhanced Broadcasting (TEB) spawns 5 total encodes, instead of what I thought was just 1 at my specified 1440p. So I already had 3 other encodes, and even arguably another one using Aitum Vertical (for mobile views on Twitch and YouTube both). So that’s 8 or 9, depending on how you slice it! So I went into my OBS main settings, since TEB requires the main encode, and switched off “Auto” (implicitly 5 by default) to Manual > 3. That made now 6 or 7 encodes (out of a max 5 on 50-series nVidia cards).

To make things worse, No Man’s Sky was crashing for folks, and it appeared that there was a memory leak (or two or three, who knows) to do with rendering and/or networking. Well, hey, that explains why I started ok and then it would wildly degrade over time, at least in part – this despite there being those gnarly DPC counts in nVidia and Windscribe drivers. So I’d leak memory because of No Man's Sky and also hemorrhage badly because of stressing my encoders too hard. With all this insight, I began tuning, including the above reduction in simultaneous encoders.

I realized that I was potentially experiencing IPv4 from my Service Provider being wrapped into IPv6 packets (since Windows Pro loves to do that) and then get sent as IPv6 to what only wants IPv4, the VPN tunnel. I’m no expert, as I have said numerous times, but I switched only IPv4 in OBS and in the router, and also disabled the IPv6 from IPv4 wrapper garbage in Windows. Then I also tweaked OBS like crazy, especially where cuda cores were being stressed (went to Bicubic 16 instead of Lanczos 32, esp. since “faster” games artifact less with the Bicubic, I discovered), and also dropped Video bitrates marginal amounts as well as some of the other bits and bobs that are known to always help with video RAM usage, and I kept 95% of apparent quality while streaming and gave myself tons of room in Video RAM.

It works now. No more pathology of any type. I did all of these in small batch steps, so I can tell you that removing Split Tunneling helped in and of itself quite a lot, and I think it’s because Windscribe does a poor job of splitting when the list of things to split is large or the UDP rate is exceptionally high over time. Next the encoder max count became tenable, and that was a HUGE reduction in DPC rate – masssssssively better – and also my encoder Process halved itself, tons of room to breathe now. Then, finally, after all that, No Man’s Sky got a patch: this made the leak happen less.

This all make sense?

The router is glorious and had nothing to do with the issue, that I could ascertain. It was a three-fold problem:

1.) As a multi-streamer, my OBS (streaming software) was set-up poorly given the Twitch Enhanced Broadcast’s implicit auto 5-encoder screw-over of my nVidia card (how stupid that they do that, honestly). I was at or even over my 8 encoder limit … my reward for becoming an affiliate was that I can longer record locally in 4k and their “Auto” setup defaults to 5 encodes.

2.) Windscribe’s API for Wireguard sucks beyond belief, and so importing the VPN protocol into the router works very well, except that the upstream Windscribe server listen poorly or not even at all to my router … utterly absurd. So even when using the Windscribe client, the Split Tunnel inclusion is mishandled by their code so poorly that it makes my DPC overrun like an 1 million man army passing through a 5-foot wide gate. Stupid.

3.) The No Man’s Sky game had a memory leak in one or more areas, and the result was my RAM getting eaten up … my core RAM and my video RAM. They fixed that, mostly.

Crazy, right? I hope this will help someone out there.

Hi,

Glad to hear that the game and streams are now running normally after the adjustments.

Thank you for following up and sharing what worked for you, your experience may help others with a similar setup.