Custom Gaming VPN Optimization - WireGuard Specialist

Job ID: 40524270

Budget: $70 – $110 USD

# Senior Network Engineer Needed for Custom Low-Latency WireGuard VPN for Gaming

## Project Overview

I am looking for a highly experienced Senior Network Engineer to design, build, test, and document a custom WireGuard VPN optimized for real-time online gaming, specifically Call of Duty: Mobile.

This is not a basic VPN installation. I need someone who can analyze the complete path from my home in Sioux Falls, South Dakota, through my ASUS router and VPN server, to the game servers. The objective is to achieve the cleanest and most stable route possible by reducing packet loss, jitter, packet reordering, bufferbloat, route instability, unnecessary overhead, MTU/PMTU issues, UDP fragmentation, and latency spikes.

I am not looking for cheats, lag switching, artificial packet loss, traffic manipulation, or anything that violates game rules. I want legitimate, measurable network optimization.

## Current Setup

* Location: Sioux Falls, South Dakota, USA
* Internet: approximately 2 Gbps fiber
* Gaming device: iPad Pro M4
* Connection: wired Ethernet through USB-C adapter
* Router: ASUS RT-AX82U
* Router firmware: official ASUS firmware
* VPN client: ASUS VPN Fusion
* Protocol: WireGuard
* Current VPN server: Chicago VPS
* Current working tunnel MTU: 1280
* Main traffic type: real-time UDP
* Main problems: inconsistent hit registration, desynchronization, latency variation, and inconsistent close-range engagements

The router currently uses Adaptive QoS, device priority, custom packet marking, DSCP, Ethernet tuning, and WireGuard scripts. The engineer must audit the current setup before changing anything.

## Required Expertise

The ideal candidate must have advanced hands-on experience with:

### Linux Networking

* Linux routing, NAT, IP forwarding, policy routing, multiple routing tables, conntrack, reverse-path filtering, UDP state handling, source routing, persistent configuration, and safe rollback procedures
* Ubuntu or Debian server administration
* iptables, nftables, iproute2, tc, ethtool, ss, conntrack, and system logs

### WireGuard

* Secure WireGuard deployment from scratch
* Key management, AllowedIPs, PersistentKeepalive, full-tunnel and split-tunnel routing
* Tunnel MTU, encapsulation overhead, NAT, forwarding, monitoring, reconnection, and health checks
* Creating standard .conf files compatible with ASUS VPN Fusion
* Testing multiple VPS locations and providers

### Real-Time UDP and Gaming Traffic

* Jitter, packet loss, packet reordering, burst traffic, NAT behavior, route asymmetry, queueing, and session stability
* Understanding that average ping alone is not enough
* Ability to distinguish local network problems, ISP routing problems, VPS problems, and game-server-side behavior

### QoS and Queue Management

* CAKE, FQ-CoDel, HTB, SFQ, DSCP, packet marking, ingress/egress shaping, and bufferbloat control
* Correct classification of encrypted tunnel traffic
* Auditing conflicts between ASUS Adaptive QoS and custom Linux rules
* Measuring drops, backlog, latency under load, and CPU impact

### MTU and PMTU

* MTU black holes, PMTU discovery failures, ICMP filtering, fragmentation, UDP fragmentation, MSS clamping limits, and WireGuard overhead
* End-to-end testing through the tunnel, not only pinging the VPN endpoint
* Finding the largest stable MTU that works during actual game sessions

### Routing and Peering

* BGP, ASN analysis, transit providers, peering, anycast, route changes, forward/reverse path differences, and multihomed VPS networks
* Comparing Chicago, Dallas, Ashburn, New York, and other locations
* Using provider Looking Glass tools and route data to determine the best server location
* Comparing direct ISP routing against VPN routing using measurable data

### Diagnostic Tools

The engineer must be proficient with:

* tcpdump, Wireshark, tshark
* mtr, traceroute, tracepath, ping, iperf3
* tc, ip, ethtool, nft, iptables, conntrack
* vnStat, iftop, nload, bmon
* Simultaneous packet captures on the router and VPS
* Packet timestamp analysis and UDP-based path testing

### ASUS Router Experience

Strong experience with:

* ASUS RT-AX routers
* ASUS VPN Fusion
* ASUS Adaptive QoS and device prioritization
* ASUS stock firmware
* Asuswrt-Merlin or GNUton
* JFFS scripts, cron jobs, firewall rebuilds, startup persistence, wgc interfaces, LAN bridges, and Ethernet port diagnostics

Do not install third-party firmware without discussing compatibility, risk, recovery, and rollback first.

## Required Testing Method

The project must include structured testing of:

1. Direct connection without VPN
2. Current Chicago VPN without custom rules
3. Current Chicago VPN with optimized rules
4. Any recommended alternative VPS or location
5. Testing with the home network idle
6. Testing while other household devices are streaming or downloading
7. Testing during real COD Mobile sessions
8. Testing during close-range combat or private matches
9. Testing at different times of day and over multiple sessions

Measurements should include:

* Minimum, average, and maximum latency
* Jitter
* Packet loss
* Packet reordering
* Route changes
* WireGuard handshake stability
* Ethernet errors and drops
* QoS drops and backlog
* Router and VPS CPU load
* NAT/conntrack behavior
* MTU-related failures
* Before-and-after comparisons

Do not base conclusions on one speed test, one ping test, or one successful match.

## Expected Deliverables

* Complete network audit
* Final network diagram
* Clean WireGuard server configuration
* ASUS VPN Fusion client profile
* Secure firewall and NAT rules
* Recommended MTU with documented evidence
* Recommended QoS and queue-management configuration
* Recommended VPS provider, specifications, and server location
* Route, peering, jitter, and packet-loss analysis
* Persistent startup and recovery scripts
* One-command status-check script
* One-command rollback script
* Backup of original configurations
* Clear documentation of every change
* Before-and-after measurements
* Final report separating local, ISP, VPS, routing, and game-server issues

The system must be stable, reversible, secure, and easy to maintain.

## Security Requirements

* Use SSH keys when possible
* Never expose router administration to the public internet
* Use temporary credentials
* Protect WireGuard private keys
* Avoid unnecessary open ports and services
* Create backups before changes
* Document all installed software and commands
* Remove temporary accounts and access after completion

## Do Not Apply If

Do not apply if your experience is limited to:

* Installing commercial VPN apps
* Running generic WireGuard scripts without understanding them
* Changing DNS servers and running speed tests
* Selling “gaming VPS” packages without technical evidence
* Making unrealistic promises about hit registration
* Claiming a VPN can increase weapon damage
* Intentionally adding packet loss, delay, jitter, or desynchronization
* Applying random kernel tweaks without measuring the result

I need an engineer who measures, explains, documents, validates, and can reverse every change.

## Preferred Background

* 5+ years of professional network engineering experience
* Strong Linux administration
* Proven WireGuard deployments
* Experience with latency-sensitive UDP applications such as gaming, VoIP, streaming, or trading systems
* Knowledge of BGP, peering, VPS networks, and route optimization
* Strong packet-analysis and troubleshooting skills
* Clear written communication and documentation

Certifications such as CCNP, CCIE, JNCIP/JNCIE, Red Hat, Linux Foundation, or MikroTik are helpful but not mandatory. Demonstrated experience is more important.

## Questions Applicants Must Answer

1. What experience do you have optimizing WireGuard for latency-sensitive UDP traffic?
2. Have you worked with ASUS VPN Fusion or Asuswrt-Merlin?
3. How would you distinguish packet loss, jitter, packet reordering, and server-side desynchronization?
4. How would you test MTU end-to-end through the tunnel?
5. How would you determine whether Chicago is the best location?
6. Which tools would you use to compare direct routing and VPN routing?
7. How would you capture traffic simultaneously on the router and VPS?
8. How would you identify bufferbloat during household traffic?
9. How would you make every change reversible?
10. Can you provide an example of a similar real-time networking project?
11. What access and information would you need?
12. What can you realistically improve, and what remains outside your control?

## Project Structure

I want to begin with a paid 2–4 hour diagnostic phase.

After that phase, the engineer must provide:

* Initial findings
* Identified bottlenecks
* Recommended changes
* Estimated implementation time
* Realistic expected improvements
* Total project cost

Implementation should begin only after I review and approve the diagnostic results.