Two small self-hosted EU nodes, run privately for friends and family. No datacenter, no colocation, no reselling — just a clean, well-monitored stack with flexible exit routing.
A primary gateway in Vilnius and a secondary exit in Frankfurt, linked by encrypted WireGuard tunnels.
| Location | Vilnius, LT (Hostinger) |
| Role | VPN gateway, DNS, mail, admin |
| Stack | WireGuard, VLESS/Xray, Pi-hole, Postfix/Dovecot |
| Exits | Direct (LT) · Cloudflare WARP |
| Location | Frankfurt, DE (Hostinger) |
| Role | Secondary exit + virtual desktops |
| Stack | Xray exits, LXD containers, noVNC desktops |
| Exits | Direct (DE) · Cloudflare WARP |
Every member chooses how their traffic leaves the network — switchable any time from the portal.
Exit straight from the Vilnius (LT) or Frankfurt (DE) node for a clean, stable European IP.
Route out through Cloudflare's WARP network on either node to blend in with everyday traffic and get past bot and CAPTCHA walls.
A pool of 25 rotating proxy exit IPs, health-checked every minute and auto-quarantined the moment one stops behaving.
Small, but looked after properly.
Each WireGuard peer and VLESS user gets its own exit policy — direct, WARP, or a specific proxy — enforced transparently by Xray.
The two nodes are joined by WireGuard tunnels — one for proxied traffic, one for management. Exits and SOCKS inbounds are firewalled to the tunnel only.
Health checks every few minutes restart anything that drops, failed exit IPs are quarantined automatically, and the admin gets a Telegram alert when something needs a look.