TCP/UDP/ICMP traffic over UDP tunneling
github.com
github.com
You can tunnel TCP / IP / GRE, reasonably even Ethernet itself over UDP. This is actually really interesting for cases where you want layer 2 bridging over the internet without all the complexity and overhead of a VPN.
With an extra iptables rule should work though:
iptables -t nat -A PREROUTING -s my.server -p udp --sport 53 -d DNAT --to 127.0.0.1:5555
ip fou add port 5555 ipproto 4Of course, it only works if DNS resolution is allowed without auth, which can vary a lot.
Nonetheless, it's an awesome tool to help you get that beachhead and upgrade your connection from there.
These kind of tunnels allows custom, obfuscated protocols.
It's used to bypass DPI where known VPN softwares are already filtered.
My experience is, that UDP is also blocked like TCP. The only possible work around is then IP over DNS, which works but with very very limited bandwidth.
What about tunnel over HTTP? That can be much better obfuscated. Tunnel over DNS can be easily filtered out by just checking for the traffic amount (for example to block VoIP the ISP should just degrade DNS if traffic amount is above a treshold for a user)
"How it works
By default mobile provider blocks any packet but UDP packet, unless you pay for the service. My method consists in sending TCP/UDP/ICMP frames as payload of an UDP packet to a known host (your server). Your server reinjects these frames to Internet."