Skip to main content

User Experience

VPN Protocol

Protocol WireGuard (primary), IPSec and L2TPv3 (planned for 2026)
Config Delivery Download .conf file from dashboard, import into any WireGuard client
Encryption Industry-standard: Curve25519 key exchange, ChaCha20 symmetric encryption

You don't need to use the generated configuration; you can use your own client. Take the configuration details from the dashboard, add them to your router, and get online.

IPsec and PPP options are in development for legacy device support.


User Dashboard

VPN Management

  • View active VPN connections and status
  • Download WireGuard config files
  • Request new VPN tier
  • See your assigned IP address

Firewall & Access Controls

Control Description
Full Mesh Allow/deny traffic to/from other Torus members
Public Inbound (Pro only) Allow/deny inbound connections from the internet
Bandwidth Limit Configurable rate limit based on your tier

DNS Hostnames

  • Create custom hostnames like yourname.ring.nekotopia.io
  • Pro accounts can request public DNS records
  • Hostnames point to your Torus address
  • Manage hostnames directly from the dashboard

Profile

  • Update name and email
  • Change password

What You Can Host (Pro tier)

With a dedicated public IP address and inbound access enabled, you can run publicly-publicly accessible services on any port:. By default, 1:1 NAT is enabled, but inbound traffic is denied until you open the port(s). You have complete control for all ports (DMZ Mode) or specific ports only:

  • Web servers (HTTP/HTTPS)
  • Game servers
  • SSH access
  • Retro services (Telnet, FTP, Gopher, etc.)
  • Anything else that listens on a TCP/UDP port

Platform Technical Restrictions

The underlying platform restricts some activities:

  • Outbound email (SMTP) is blocked to the Internet by default for all account types.
  • Traffic forwarding/routing through the VPN is not permitted. Life may be a highway, but we don't want to be :)