Need a Network Expert for Reverse Port Forwarding via WireGuard (Bypassing 5G CGNAT)
Budget / Salary$10–25
TypeFreelance project
LocationRemote
Posted2 hours ago
I am looking for an experienced network engineer to help me access my 5G home router (Cudy 5G) and its local devices remotely from outside the network. My ISP uses Carrier-Grade NAT (CGNAT), so a direct connection is not possible.
Current Setup:
A Linux VPS hosted on Contabo with a static Public IP.
WGDashboard is installed on the VPS to manage the WireGuard server.
My home router is a Cudy 5G, with an active WireGuard Client connection to the VPS.
The WireGuard tunnel is successfully established (Ping is alive between the VPS 10.0.0.1 and the router 10.0.0.2).
The Problem:
I have attempted to set up Reverse Port Forwarding (using iptables PREROUTING/POSTROUTING with MASQUERADE) to forward traffic from VPS_IP:8080 to the Router’s Remote Management page or local devices. However, the connection is either timing out or dropping. It seems there is a routing conflict, a firewall block (UFW/iptables), or a specific policy in the Cudy router that drops incoming WAN/VPN traffic.
Scope of Work:
Diagnose the current iptables and routing configurations on the Linux VPS.
Correctly configure iptables to reliably forward traffic from the VPS public IP to the router via the WireGuard tunnel.
Assist in properly configuring the Cudy Router (Remote Management or Port Forwarding) to accept and route the incoming traffic from the VPN interface.
Ensure the setup is persistent after reboots.
Requirements:
Deep understanding of Linux routing, NAT, and iptables troubleshooting.
Experience with WireGuard and CGNAT bypass techniques.
Familiarity with Cudy or similar OpenWRT-based routers is a plus.
Must be able to test and prove the connection works before project completion.
If you know exactly how to fix this without blind guessing, please bid and let me know your approach.
WORK ON ANYDESK ONLY
Current Setup:
A Linux VPS hosted on Contabo with a static Public IP.
WGDashboard is installed on the VPS to manage the WireGuard server.
My home router is a Cudy 5G, with an active WireGuard Client connection to the VPS.
The WireGuard tunnel is successfully established (Ping is alive between the VPS 10.0.0.1 and the router 10.0.0.2).
The Problem:
I have attempted to set up Reverse Port Forwarding (using iptables PREROUTING/POSTROUTING with MASQUERADE) to forward traffic from VPS_IP:8080 to the Router’s Remote Management page or local devices. However, the connection is either timing out or dropping. It seems there is a routing conflict, a firewall block (UFW/iptables), or a specific policy in the Cudy router that drops incoming WAN/VPN traffic.
Scope of Work:
Diagnose the current iptables and routing configurations on the Linux VPS.
Correctly configure iptables to reliably forward traffic from the VPS public IP to the router via the WireGuard tunnel.
Assist in properly configuring the Cudy Router (Remote Management or Port Forwarding) to accept and route the incoming traffic from the VPN interface.
Ensure the setup is persistent after reboots.
Requirements:
Deep understanding of Linux routing, NAT, and iptables troubleshooting.
Experience with WireGuard and CGNAT bypass techniques.
Familiarity with Cudy or similar OpenWRT-based routers is a plus.
Must be able to test and prove the connection works before project completion.
If you know exactly how to fix this without blind guessing, please bid and let me know your approach.
WORK ON ANYDESK ONLY
Apply on Freelancer →
Project sourced from Freelancer.com. Applications happen directly on the original platform — we never collect your data.