Skip to content

A VPN Out of Parts: PPP, Tap Devices and Netcat

A VPN is two jobs: something that makes a virtual link, and something that carries the bytes. PPP has done the first since 1994 and does not care what the second is — which is why PPTP, L2TP and every dial-up line you ever used are the same protocol over different carriers. Netcat is a carrier. This builds it both ways. First pppd: the pty option and what it does with a pseudo-terminal, the TCP version everyone tries first, why running a stream protocol inside TCP melts under loss, the UDP version that is the one to use, the async HDLC framing and the ACCM that decides how much bandwidth goes on escaping control characters, addressing and routing and IPV6CP, and keeping the link up when the carrier dies without telling you. Then the same tunnel with no PPP at all — a tap device, one datagram per frame over UDP, the length prefix you have to invent yourself over TCP, tun against tap, and bridging. Then the part netcat has no answer for: wrapping the carrier in TLS with ncat, stunnel and openssl, and in DTLS with socat, which is the shape you actually want. It is never really the right tool, and that is the point: it shows how egress behaves once an attacker has root inside your network and outbound access was not blocked by default, and why default-deny at the border is the only control that was ever real.

14th September 2026 · 60 min · 13122 words · Damien Dye

The Firewall Is Eleven Hops Away

“Port 445 is blocked somewhere” is not a diagnosis, and it is why firewall tickets bounce between you and your provider for a week. Every router on the path owes you an ICMP Time Exceeded when your hop budget runs out, and that turns a timeout into a distance. I walked the TTL up on my own line and found three faults I did not know I had: an SMB drop eleven hops out, forged SMTP resets one hop away, and an IPv4 rule with no IPv6 twin.

28th August 2026 · 38 min · 8038 words · Damien Dye