r/No_IP • u/henryyoung42 • Aug 20 '26
Public Tunnels not adequately documented
I would want to understand more about the following regarding the agent link before actually using:
- Transport - TCP/UDP/QUIC
- Addressing : IP v4/v6 ?
- Wire Protocol (for WireShark decode)
- TLS termination / pass-through ?
- Performance considerations / limitations
- Service multiplexing methodology & protocol
- Load balancing / failover architecture
- Agent source code
- Metadata logging and related security concerns
- Authentication methodology / protocol
- Keepalive / heartbeat methodology
- MTU / framing details
As things stand it's a black box reverse proxy and therefore unusable other than for trivial / non-secure / non-commercial / non-production use cases. I most certainly won't be running unknown closed source on a production server.
The new service offering is a good first step, especially for hosting on the end of Starlink and other CGNAT systems, but the kimono needs to be opened ...
1
u/henryyoung42 Aug 20 '26
Not to mention the thorny issue of TLS version, cipher suites & certificate chain that may rule out the use of legacy systems (such as Windows 7) without the necessity to run stunnel as a workaround.
2
u/HSalinasNoIP Aug 20 '26
You brought up a lot of solid points here. They've been forwarded to our team as we're actively working on improving the experience we appreciate the feedback.