Skip to main content

User Experience

VPN Protocol

VPN Protocol WireGuard (primary)
Config Delivery Download .conf file from dashboard, import into any WireGuard client
EndpointMikroTik CHR router in AWS
Encryption Industry-standard: Curve25519 (key exchange),exchange, ChaCha20 (symmetric),symmetric Poly1305 (authentication)encryption

IPsec and PPP options are in development for legacy device support.


IP Addressing by Tier

TierPrivate IP RangePublic IPInternet Access
Torus Basic10.254.16.128/25NoneNo — mesh only
Torus Plus10.254.16.128/25Shared NATYes — outbound only
Torus Pro10.254.16.64/28Dedicated 1:1 NATYes — inbound & outbound

User Dashboard

VPN Management

  • View active VPN connections and status
  • Download WireGuard config files
  • Request new VPN connections
  • See your assigned IP addressesaddress

Firewall & Access Controls (Pro only)

Control Description
Full Mesh Allow/deny traffic to/from other Torus members
Public Inbound Allow/deny inbound connections from the internet to your public IP
Bandwidth Limit Configurable rate limit (defaultbased 512on Kbps,your adjustable)tier

DNS Hostnames

  • AllCreate Toruscustom usershostnames have access to createlike yourname.ring.nekopia.nekotopia.io
  • Pro Accountsaccounts can AWSrequest Route53public FQDNsDNS as yourname.torus.nekotopia.io)records
  • AHostnames record pointspoint to your Torus private or public IPaddress
  • PTR (reverse DNS) records are created automatically for Pro DNS
  • Add/removeManage hostnames directly from the dashboard

Profile

  • Update name and email
  • Change password

Network Configuration

SettingValue
DNS Server10.254.16.1 (pushed via VPN)
Default Route0.0.0.0/0 through VPN (Plus/Pro)
Split TunnelPossible by modifying AllowedIPs in config
Keepalive25 seconds (standard for NAT traversal)

What You Can Host (Pro tier)

With a dedicated public IP and inbound access enabled, you can run publicly-accessible services on any port:

  • Web servers (HTTP/HTTPS)
  • Game servers
  • SSH access
  • Retro services (Telnet, FTP, Gopher, etc.)
  • Anything else that listens on a TCPTCP/UDP port

What You Cannot Host (Pro tier)Restrictions

TheSome hubactivities providesare accessrestricted to and fromby the internet.underlying However,cloud living within the AWS platform does offer some functional safety.platform:

  • Outbound Emailemail (SMTP) is blocked by default
  • Traffic forwarding/routing through the VPN is not allowed (without using the AWS SES service)
  • Forwarding of traffic is not allowed (without permissible filters in and out of the VPC).permitted