VPN options with obfuscation

Hi all,

I will be traveling to the country (from USA) that censors internet via DPI and other means. I just need to access my self-hosted stuff like VoIP, files in the US, nothing illegal of any kind. That country is Uzbekistan.

I’ve chatted with sales/support, and they recommended buying Beryl AX GL-MT3000 traveler router. They also mentioned that in order to utilize obfuscation I must flush it with betta firmware for Amnezia WireGuard support.

I love the idea that I can use hotel wi-fi as an uplink and establish a tunnel with my server in US and all my business devices will have access to my hosted things, so I’d like to stick to hardware option.

My own edge network device is Netgate 8200 that runs Pfsense. Sadly, Pfsense doesn’t support Amnezia WireGuard on a kernel level. So, I guess I cannot use it with my firewall.

I think I can either self-host Linux with Amnezia server on my host and then put config to Beryl AX GL-MT3000 for it to establish S2S VPN or even pay them to rent a VPS and do same to VPN out to US/EU and then run my own WG client on my devices to my Netgate 8200 (need to confirm it)!?!

So, would any kind people here be able to confirm the following:

  • Does GLINET/Beryl AX GL-MT3000 not support any other protocol with obfuscation other than Amnezia WireGuard? I wish it support OpenVPN for that!

  • If I self-host or rent VPN from Amnezia WireGuard, can I still dump a config file to connect that small router to that server from overseas and then my devices behind Beryl AX GL-MT3000 should see networks from that server’s region?

  • Can I run VPN client on my devices to my home network while Amnezia WireGuard tunnel is established?

Thank you!

Hi,

Please find our clarification below:

  1. The Beryl AX (GL-MT3000) supports WireGuard and OpenVPN. At present, only WireGuard supports obfuscation via Amnezia, and this feature is still in beta. OpenVPN does not currently offer an equivalent obfuscation option on our firmware.
    [Beta Release] Beryl AX (GL-MT3000) v4.8.2 with New WireGuard Obfuscation Support

  2. Yes. Whether you self-host or use a rented Amnezia WireGuard server, you can import the configuration into the Beryl AX and use it as a VPN client. Devices connected to the router will appear to be accessing the internet from the VPN server’s region.

  3. This is technically feasible. However, since it involves running one VPN connection inside another, you should expect some performance degradation, such as lower throughput or increased latency, depending on network conditions.