User Experience
VPN Protocol
| Protocol | WireGuard (primary) |
| Config Delivery | Download .conf file from dashboard, import into any WireGuard client |
| Encryption | Industry-standard: Curve25519 key exchange, ChaCha20 symmetric encryption |
You don't need to use the generated configuration; you can use your own client. Take the configuration details from the dashboard, add them to your router, and get online.
IPsec and PPP options are in development for legacy device support.
User Dashboard
VPN Management
- View active VPN connections and status
- Download WireGuard config files
- Request new VPN tier
- See your assigned IP address
Firewall & Access Controls
| Control | Description |
|---|---|
| Full Mesh | Allow/deny traffic to/from other Torus members |
| Public Inbound | (Pro only) Allow/deny inbound connections from the internet |
| Bandwidth Limit | Configurable rate limit based on your tier |
DNS Hostnames
- Create custom hostnames like
yourname.ring.nekotopia.io - Pro accounts can request public DNS records
- Hostnames point to your Torus address
- Manage hostnames directly from the dashboard
Profile
- Update name and email
- Change password
What You Can Host
(Basic tier) - With a private IP address, you can run and provide accessible services on any port within the Torus ring. Inbound and outbound traffic for the public internet is denied.
(Plus tier) - With a shared public IP address, outbound Internet access enabled. You can run privately accessible services on any port within the torus.
(Pro tier) - With a dedicated public IP address, inbound access permitted. You can run publicly accessible services on any port. By default, 1:1 NAT is enabled, but inbound traffic is denied until you open the port(s). You have complete control over all ports (DMZ Mode) or specific ports only:
- Web servers (HTTP/HTTPS)
- Game servers
- SSH access
- Retro services (Telnet, FTP, Gopher, etc.)
- Anything else that listens on a TCP/UDP port
Platform Technical Restrictions
The underlying platform restricts some activities:
- Outbound email (SMTP) is blocked to the Internet by default for all account types.
- Traffic forwarding/routing through the VPN is not permitted. Life may be a highway, but we don't want to be :)