Skip to content

A VPN Out of Parts: PPP, Tap Devices and Netcat

A VPN is two jobs: something that makes a virtual link, and something that carries the bytes. PPP has done the first since 1994 and does not care what the second is — which is why PPTP, L2TP and every dial-up line you ever used are the same protocol over different carriers. Netcat is a carrier. This builds it both ways. First pppd: the pty option and what it does with a pseudo-terminal, the TCP version everyone tries first, why running a stream protocol inside TCP melts under loss, the UDP version that is the one to use, the async HDLC framing and the ACCM that decides how much bandwidth goes on escaping control characters, addressing and routing and IPV6CP, and keeping the link up when the carrier dies without telling you. Then the same tunnel with no PPP at all — a tap device, one datagram per frame over UDP, the length prefix you have to invent yourself over TCP, tun against tap, and bridging. Then the part netcat has no answer for: wrapping the carrier in TLS with ncat, stunnel and openssl, and in DTLS with socat, which is the shape you actually want. It is never really the right tool, and that is the point: it shows how egress behaves once an attacker has root inside your network and outbound access was not blocked by default, and why default-deny at the border is the only control that was ever real.

14th September 2026 · 60 min · 13122 words · Damien Dye

Your Firewall Takes Instructions From Strangers. Turn Off the Protocol Helpers.

A protocol helper — SIP ALG, FTP helper, H.323 ALG, conntrack helper, call it what your vendor calls it — reads the payload of a connection, finds an address and a port written in the text, and opens an inbound pinhole for them. It cannot tell whether that text came from a real FTP client or from a hidden form on a web page, because there is nothing in it to tell. Samy Kamkar proved the browser case in 2010. NAT Slipstreaming proved it again in 2020, and Armis extended it in 2021 to reach any device on your network, not just the machine that clicked. The IETF asked for these off by default in 2007, Linux turned them off in 2016, and the browser vendors ended up shipping a blocked-port list that reads like a directory of conntrack modules. This post walks the mechanism diagram by diagram — the expectation table, the segment-alignment trick, H.323 call forwarding, the IRC helper that fires on somebody else’s message — takes in the IPsec pass-through helper, which cannot read ESP at all and steers inbound packets on an SPI it watched go past in the clear, sets the lot against the Cyber Essentials firewall control it plainly fails, and gives the commands to turn it all off on Linux, Cisco, Juniper, FortiGate and MikroTik.

14th September 2026 · 54 min · 12564 words · Damien Dye

IPsec Was a Good Idea. It Is Time to Turn It Off.

IPsec was right in 1995: encrypt below the application, bind the security association to the IP address, let every protocol inherit it. Then NAT arrived, carrier-grade NAT finished the job, and the fix was to wrap the whole thing in UDP and keep a timer running so a translation table would not forget you. This post shows how it falls down, diagram by diagram — the security association that cannot survive a rewritten header, the two translators every CGNAT line now has, the NAT64 standard that names IPsec as out of scope, the tunnel that cannot use a second link because ESP has no ports, the MTU nobody owns, and L2TP and PPTP as the two protocols that were never fit to be here. It carries the vendor documentation from Cisco, Juniper and Microsoft that admits every one of those, the eighteen pieces that call themselves an IPsec VPN including the two that were never standards at all, why the Fisher-Price OS has never truly interoperated with an open stack, a working method for diagnosing IPsec while you still run it, and the case for retiring the lot with dates.

13th September 2026 · 68 min · 16979 words · Damien Dye
A browser connecting through Cloudflare Access to Windows VMs on a Proxmox host with Intel Arc Pro GPU virtual functions

Zero Trust VDI Without the Cloud Bill — Proxmox, Intel Arc Pro and Cloudflare Access

Part one: the architecture and the cost argument for replacing Azure Virtual Desktop with Proxmox, Intel Arc Pro SR-IOV and Cloudflare Access. On-prem OAuth for identity, browser-rendered RDP, a firewalled LXC tunnel on its own VLAN, KSM for memory density, and profiles on Ceph. The next post builds it.

2nd September 2026 · 17 min · 3677 words · Damien Dye

Ping: The Diagnostic Tool That Opens a Whole Lot More

Ping, not the rest of ICMP, is the liability: echo is a channel every host must answer with your own bytes, so a network that ‘only allows ping’ already has a full VPN out. This walks the threat first — what it costs your egress, and how a visitor on your WiFi or an unlocked ethernet port can open one — then three working tunnels built on ping alone (Hans, icmptunnel, and a short Python one with AES-128), the MTU and IPv6 catches, and the rule that shuts it: drop echo, keep the errors, in nftables, pf, Cisco, Junos, MikroTik and Windows.

1st September 2026 · 36 min · 7657 words · Damien Dye

The Firewall Is Eleven Hops Away

“Port 445 is blocked somewhere” is not a diagnosis, and it is why firewall tickets bounce between you and your provider for a week. Every router on the path owes you an ICMP Time Exceeded when your hop budget runs out, and that turns a timeout into a distance. I walked the TTL up on my own line and found three faults I did not know I had: an SMB drop eleven hops out, forged SMTP resets one hop away, and an IPv4 rule with no IPv6 twin.

28th August 2026 · 38 min · 8038 words · Damien Dye

We Never Ran Out of Addresses. We Ran Out of Effort.

IPv6 has been finished, free and switched on by default in every operating system for the best part of twenty years. The UK’s answer was carrier-grade NAT, a law about logging, and a £5 a month charge to give you back the address you used to have. I counted every UK network in the global routing table to find out who has actually turned IPv6 on — 1,200 of them have not, and 463 of those are sitting on address space they asked for and never used.

27th August 2026 · 69 min · 14518 words · Damien Dye