Northlab Notes

WireGuard roaming between home and a VPS

September 2026 · 6 min

My home connection changes IP every few days, which used to break my tunnel to a small VPS. The fix was boring on purpose: the VPS side keeps no fixed endpoint for the home peer, and a persistent keepalive of 25 seconds keeps NAT mappings warm.

Two things actually mattered. First, I match peers by key, never by IP, so a renumbered home router reconnects without any config change. Second, I pin the tunnel MTU to 1280 after a week of mysterious stalls on one mobile carrier — smaller packets pass, big ones silently didn't.

Uptime since: four months, zero manual fixes. The most reliable network is the one you stop touching.