Skip to content

A VPN Out of Parts: PPP, Tap Devices and Netcat

A VPN is two jobs: something that makes a virtual link, and something that carries the bytes. PPP has done the first since 1994 and does not care what the second is β€” which is why PPTP, L2TP and every dial-up line you ever used are the same protocol over different carriers. Netcat is a carrier. This builds it both ways. First pppd: the pty option and what it does with a pseudo-terminal, the TCP version everyone tries first, why running a stream protocol inside TCP melts under loss, the UDP version that is the one to use, the async HDLC framing and the ACCM that decides how much bandwidth goes on escaping control characters, addressing and routing and IPV6CP, and keeping the link up when the carrier dies without telling you. Then the same tunnel with no PPP at all β€” a tap device, one datagram per frame over UDP, the length prefix you have to invent yourself over TCP, tun against tap, and bridging. Then the part netcat has no answer for: wrapping the carrier in TLS with ncat, stunnel and openssl, and in DTLS with socat, which is the shape you actually want. It is never really the right tool, and that is the point: it shows how egress behaves once an attacker has root inside your network and outbound access was not blocked by default, and why default-deny at the border is the only control that was ever real.

14th September 2026 Β· 60 min Β· 13122 words Β· Damien Dye