A WireGuard Mesh Overlay Resisting Internet Provider Port Policing
Keywords:
WireGuard, overlay network, network address translation, hole punching, port policing, peer-to-peer, mesh networkAbstract
Overlay networks built on WireGuard can make dispersed devices appear to share one local network, but two obstacles remain: endpoints behind address translation are not directly reachable, and WireGuard's fixed default port is an obvious target for provider traffic discrimination. This study aims to design and empirically evaluate a hybrid overlay that mitigates both. We built WireGuard Manager, a single-binary Windows application combining a hub-and-spoke baseline with an opportunistic direct mesh over an in-process WireGuard data plane and host-orchestrated hole punching, and evaluated it on three physical nodes across two cities and three providers using throughput, latency, and packet-loss measurements. Results show that carrying the tunnel over the default port collapsed throughput to roughly 1–4% of a control port over the identical link (from 7.6–22.1 Mbps to at most 0.33 Mbps), while a randomized stealth port restored it; direct and relayed paths were validated independently through the observed time-to-live, and a live trace captured the automatic failover between them. A secondary result is that a direct path is not always superior to a well-provisioned relay. We conclude that provider port discrimination is a decisive, reproducible factor for such overlays and that a stealth-port strategy is an effective, low-cost mitigation, within the limits of a three-node case study.
Downloads
References
J. A. Donenfeld, "WireGuard: Next generation kernel network tunnel," in Proc. Netw. Distrib. Syst. Secur. Symp. (NDSS), San Diego, CA, USA, 2017, doi: 10.14722/ndss.2017.23160.
V. Kjorveziroski, C. Bernad, K. Gilly, and S. Filiposka, "Full-mesh VPN performance evaluation for a secure edge-cloud continuum," Softw., Pract. Exper., vol. 54, no. 8, pp. 1543–1564, 2024, doi: 10.1002/spe.3329.
J. Anyam, R. R. Singh, H. Larijani, and A. Philip, "Empirical performance analysis of WireGuard vs. OpenVPN in cloud and virtualised environments under simulated network conditions," Computers, vol. 14, no. 8, art. no. 326, 2025, doi: 10.3390/computers14080326.
S. T. Oktavia, D. F. Priambodo, N. Trianto, and R. Purwoko, "Comparative quality of service analysis of VPN protocols on IPv6," J. Nasional Pendidikan Teknik Informatika (JANAPATI), vol. 12, no. 3, pp. 461–471, 2024, doi: 10.23887/janapati.v12i3.69264.
A. F. Gentile, D. Macrì, E. Greco, and P. Fazio, "Overlay and virtual private networks security performances analysis with open source infrastructure deployment," Future Internet, vol. 16, no. 8, art. no. 283, 2024, doi: 10.3390/fi16080283.
B. Ford, P. Srisuresh, and D. Kegel, "Peer-to-peer communication across network address translators," in Proc. USENIX Annu. Tech. Conf. (ATC), Anaheim, CA, USA, 2005, pp. 179–192.
A. Keränen, C. Holmberg, and J. Rosenberg, "Interactive Connectivity Establishment (ICE): A protocol for Network Address Translator (NAT) traversal," IETF, RFC 8445, 2018, doi: 10.17487/RFC8445.
M. Petit-Huguenin, G. Salgueiro, J. Rosenberg, D. Wing, R. Mahy, and P. Matthews, "Session Traversal Utilities for NAT (STUN)," IETF, RFC 8489, 2020, doi: 10.17487/RFC8489.
T. Reddy, A. Johnston, P. Matthews, and J. Rosenberg, "Traversal Using Relays around NAT (TURN): Relay extensions to Session Traversal Utilities for NAT (STUN)," IETF, RFC 8656, 2020, doi: 10.17487/RFC8656.
D. Trautwein, C. Ihle, M. Schubotz, and B. Gipp, "Challenging tribal knowledge: A large-scale measurement campaign on decentralized NAT traversal," arXiv, 2025, doi: 10.48550/arXiv.2510.27500.
F. Li, A. M. Niaki, D. Choffnes, P. Gill, and A. Mislove, "A large-scale analysis of deployed traffic differentiation practices," in Proc. ACM SIGCOMM, Beijing, China, 2019, pp. 130–144, doi: 10.1145/3341302.3342092.
A. Molavi Kakhki et al., "Identifying traffic differentiation in mobile networks," in Proc. ACM Internet Meas. Conf. (IMC), Tokyo, Japan, 2015, pp. 239–251, doi: 10.1145/2815675.2815691.
D. Xue et al., "Throttling Twitter: An emerging censorship technique in Russia," in Proc. 21st ACM Internet Meas. Conf. (IMC), 2021, pp. 435–443, doi: 10.1145/3487552.3487858.
D. Xue, R. Ramesh, A. Jain, M. Kallitsis, J. A. Halderman, J. R. Crandall, and R. Ensafi, "OpenVPN is open to VPN fingerprinting," in Proc. 31st USENIX Secur. Symp., Boston, MA, USA, 2022, pp. 483–500.
M. C. Tschantz, S. Afroz, Anonymous, and V. Paxson, "SoK: Towards grounding censorship circumvention in empiricism," in Proc. IEEE Symp. Secur. Privacy (S&P), San Jose, CA, USA, 2016, pp. 914–933, doi: 10.1109/SP.2016.59.
M. Claypool and K. Claypool, "Latency and player actions in online games," Commun. ACM, vol. 49, no. 11, pp. 40–45, 2006, doi: 10.1145/1167838.1167860.
D. Halbhuber, P. Schauhuber, V. Schwind, and N. Henze, "The effects of latency and in-game perspective on player performance and game experience," Proc. ACM Hum.-Comput. Interact., vol. 7, no. CHI PLAY, art. no. 424, 2023, doi: 10.1145/3611070.
ESnet, "iPerf3: A TCP, UDP, and SCTP network bandwidth measurement tool," Lawrence Berkeley National Laboratory. [Online]. Available: https://software.es.net/iperf/
J. Postel, "Internet Control Message Protocol," IETF, RFC 792, 1981, doi: 10.17487/RFC0792.
J. Postel, "Internet Protocol," IETF, RFC 791, 1981, doi: 10.17487/RFC0791.











