Networking Expert for Secure Site-to-Site Connectivity
Budget: $8 – $15 USD
We're looking for an experienced network engineer or VyOS specialist to help us troubleshoot and finalize a NAT/port forwarding issue in our infrastructure stack.
Current Setup:
Cloudflare as the public entry point (DNS & Proxy)
VyOS (1.4+, nftables) router with firewall, DNAT/SNAT rules
WireGuard tunnel from VyOS to internal application server
Traefik load balancer running on a private server (10.100.0.7)
Target: Access Traefik dashboard (:8080) externally via http://PUBLIC_IP:8080 or proxied via CF
What’s Working:
WireGuard tunnel is up between VyOS and Traefik
Traefik dashboard is accessible from WireGuard clients
TCP packets reach VyOS from public IP (confirmed via tcpdump)
DNAT/SNAT rules are defined and active in VyOS
What's Failing:
Public requests via http://PUBLIC_IP:80 or :8080 are not reaching Traefik
No response is returned despite NAT rules and firewall zones appearing correct
MSS clamp has been applied and remote firewall was disabled temporarily to test — still no success
Skills Needed:
Deep experience with VyOS 1.4+ (nftables)
Strong understanding of WireGuard routing and NAT
Debugging complex NAT and hairpin routing cases
Familiarity with Cloudflare proxy behavior (bonus)
Deliverable:
Diagnose the root cause
Apply or suggest the correct NAT/firewall/forwarding changes
Help validate that CF → VyOS → WG → Traefik access works cleanly
Current Setup:
Cloudflare as the public entry point (DNS & Proxy)
VyOS (1.4+, nftables) router with firewall, DNAT/SNAT rules
WireGuard tunnel from VyOS to internal application server
Traefik load balancer running on a private server (10.100.0.7)
Target: Access Traefik dashboard (:8080) externally via http://PUBLIC_IP:8080 or proxied via CF
What’s Working:
WireGuard tunnel is up between VyOS and Traefik
Traefik dashboard is accessible from WireGuard clients
TCP packets reach VyOS from public IP (confirmed via tcpdump)
DNAT/SNAT rules are defined and active in VyOS
What's Failing:
Public requests via http://PUBLIC_IP:80 or :8080 are not reaching Traefik
No response is returned despite NAT rules and firewall zones appearing correct
MSS clamp has been applied and remote firewall was disabled temporarily to test — still no success
Skills Needed:
Deep experience with VyOS 1.4+ (nftables)
Strong understanding of WireGuard routing and NAT
Debugging complex NAT and hairpin routing cases
Familiarity with Cloudflare proxy behavior (bonus)
Deliverable:
Diagnose the root cause
Apply or suggest the correct NAT/firewall/forwarding changes
Help validate that CF → VyOS → WG → Traefik access works cleanly