Right now, I am visiting Amsterdam. While Amsterdam is a nice city and I like my hotel, one of the worst parts is the hotel’s Wi-Fi.
The Wi-Fi is heavily firewalled. Meaning only mainstream TCP services are allowed. While SSH is allowed, Wireguard isn’t.
But I discovered Chisel, which lets you proxy TCP or UDP over HTTP and WebSocket.
So how do you run Chisel?
Installation
On a web server, download the latest version of Chisel.
While most of you are going to run Debian or Ubuntu, I run Rocky Linux as a server so Chisel can be installed with a single dnf command:
dnf install https://github.com/jpillora/chisel/releases/download/v1.11.8/chisel_1.11.8_linux_amd64.rpm
You can also install it as a Docker container.
Running Chisel as a Server
Assuming you aren’t running Docker or Windows:
chisel server --auth user:pass --port port --backend http://example.com
Replace the following:
userwith your desired usernamepasswith your desired passwordportwith the TCP port you want Chisel to listen on
You can also set up a systemd service. I am lazy so I used tmux.
I also recommend a reverse proxy. I use Caddy, so to do it, assuming you have the DNS name domain pointed to your server, add the following server block:
domain {
encode gzip
reverse_proxy 127.0.0.1:port
}
Make sure port is the Chisel port, and then restart Caddy.
If you use nginx or another reverse proxy, check the respective instructions.
Running Chisel as a Client
I am accessing Chisel on Fedora, so the dnf command also worked there.
To run Chisel as a client, run the following in your terminal:
chisel client --auth user:pass https://url local_port:remote_ip:remote_port/udp
userwith your chosen usernamepasswith your chosen passwordlocal_portwith the UDP port you want to listen on locallyremote_ipwith the remote IP you want to connect toremote_portwith the UDP port you want to connect to
You can also remove /udp to connect via TCP.
Conclusion
It always sucks when the expensive hotel your family booked blocks most TCP/IP services. But the good thing about open source is that you can tunnel raw UDP and TCP inside HTTPS.
Yes, China spends unlimited amounts of money on internet censorship. But for-profit hotels, workplaces, public libraries and ISPs who purposefully violate Net Neutrality cannot. And in the latter case, firewalling shouldn’t mean you shouldn’t be able to access your homelab.






