Posted: Sat May 24, 2025 23:46 Post subject: wireguard tunnel obfuscation for NordVPN client
I've spent a few hours looking for and reading info on this but no joy. I know NordVPN has a tunnel obfuscation option so I'd like to setup my NordVPN client to use this feature. But, it requires a key entered in the tunnel obfuscation field but I don't know where to get it. I doubt NordVPN will provide the info if I asked since this isn't their official wireguard (aka NordLynx). It can probably be extracted from somewhere but I don't know where. Neither the wireguard client config doc nor the advanced config doc has info on this. I did read somewhere where shadowsocks is used to achieve obfuscation on some platforms but Entware has shadowsocks-rust-* which is suppose to be a port of shadowsocks. So, is it possible to use obfuscation between the dd-wrt wireguard client and NordVPN server?
Unless this has changed, which it may have, the obfuscation was only on OpenVPN, I was able to get the obfuscation key out as well as there Adblocking DNS IP's from a Linux machine just by looking where it was installed in each folder. It uses a different tls key when using obfuscation in OpenVPN.
Not looked at there Wireguard (Nordlynx) for some time, I used it for 16+ months in DD-WRT but I switched to Surfshark save all the messing around. _________________ Main Router: Dynalink WRX36, PPPoE, Gateway Mode, Network IPV4 - Isolated Vlan's. Unifi AC-Pro x 3 AP's, Router Wi-Fi Disabled. Paid Commercial Wireguard Client's & WG server, DNSMasq, Static Leases with Cloudflare SmartDNS, DNSMasq Adblocking via egc script.
No one can build you the bridge on which you, and only you, must cross the river of life!
Unless this has changed, which it may have, the obfuscation was only on OpenVPN, I was able to get the obfuscation key out as well as there Adblocking DNS IP's from a Linux machine just by looking where it was installed in each folder. It uses a different tls key when using obfuscation in OpenVPN.
Not looked at there Wireguard (Nordlynx) for some time, I used it for 16+ months in DD-WRT but I switched to Surfshark save all the messing around.
Obfuscation is available for wireguard now but the docs in Advanced Networking doesn't say how to implement it. Other than that, once I got the configuration figured out the connection to the nordvpn servers has been working well. I don't know if obfuscation works as well as claimed but I'd like to try it. I've heard that there's another option for hiding VPNs called Cloak. I don't know if cloak can be used with commercial VPNs though.