Running WireGuard over HTTPS via Chisel, or how to bypass your hotel’s firewall

Right now, I am visiting Amsterdam. While Amsterdam is a nice city and I like my hotel, one of the worst parts is the hotel’s Wi-Fi.

The Wi-Fi is heavily firewalled. Meaning only mainstream TCP services are allowed. While SSH is allowed, Wireguard isn’t.

But I discovered Chisel, which lets you proxy TCP or UDP over HTTP and WebSocket.

So how do you run Chisel?

Installation

On a web server, download the latest version of Chisel.

While most of you are going to run Debian or Ubuntu, I run Rocky Linux as a server so Chisel can be installed with a single dnf command:

dnf install https://github.com/jpillora/chisel/releases/download/v1.11.8/chisel_1.11.8_linux_amd64.rpm

You can also install it as a Docker container.

Running Chisel as a Server

Assuming you aren’t running Docker or Windows:

chisel server --auth user:pass --port port --backend http://example.com

Replace the following:

  • user with your desired username
  • pass with your desired password
  • port with the TCP port you want Chisel to listen on

You can also set up a systemd service. I am lazy so I used tmux.

I also recommend a reverse proxy. I use Caddy, so to do it, assuming you have the DNS name domain pointed to your server, add the following server block:

domain {
  encode gzip
  reverse_proxy 127.0.0.1:port
}

Make sure port is the Chisel port, and then restart Caddy.

If you use nginx or another reverse proxy, check the respective instructions.

Running Chisel as a Client

I am accessing Chisel on Fedora, so the dnf command also worked there.

To run Chisel as a client, run the following in your terminal:

chisel client --auth user:pass https://url local_port:remote_ip:remote_port/udp
  • user with your chosen username
  • pass with your chosen password
  • local_port with the UDP port you want to listen on locally
  • remote_ip with the remote IP you want to connect to
  • remote_port with the UDP port you want to connect to

You can also remove /udp to connect via TCP.

Conclusion

It always sucks when the expensive hotel your family booked blocks most TCP/IP services. But the good thing about open source is that you can tunnel raw UDP and TCP inside HTTPS.

Yes, China spends unlimited amounts of money on internet censorship. But for-profit hotels, workplaces, public libraries and ISPs who purposefully violate Net Neutrality cannot. And in the latter case, firewalling shouldn’t mean you shouldn’t be able to access your homelab.

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.