bolt Valebyte VPS from $4/mo — NVMe, 60s deploy.

Get a VPS arrow_forward

Multi-Hop VPN: Set Up Traffic Transit on Your Own Servers

calendar_month August 24, 2026 schedule 23 min read visibility 26 views
person
Valebyte Team
Multi-Hop VPN: Set Up Traffic Transit on Your Own Servers
summarize

TL;DR

  • A multi-hop VPN uses two VPS servers (transit + exit) for enhanced privacy & geo-block bypassing.
  • Traffic passes through two encrypted tunnels: nearby transit VPS to remote exit VPS.
  • Bypass DPI, IP blocking, and overcome high ping/low speed issues of single VPNs.
  • Achieve stable speeds up to 500 Mbps, even with an unstable direct internet connection.
  • Configure using modern, censorship-resistant protocols like Sing-box and Xray.

A multi-hop setup using two VPS servers—a nearby transit node and a remote exit node—effectively bypasses geo-blocks and censorship, offering enhanced privacy and stable speeds up to 500 Mbps even with an unstable direct connection.

In an era of increasingly stringent internet censorship and geographical restrictions, coupled with growing demands for privacy, a direct connection to a single VPN server often proves insufficient. ISPs and government agencies actively block known IP addresses and protocol signatures, while low speeds or high latency to a single remote server make internet use uncomfortable. This is precisely where an advanced architecture—a two-VPS chain—comes into play.

This article from Valebyte.com will thoroughly examine the concept of double tunneling, where one VPS acts as a transit node and the second as an exit server. We will explore why this is necessary, how to choose optimal locations, and provide step-by-step instructions for configuring such a setup using modern, censorship-resistant protocols based on Sing-box and Xray. You will learn how to minimize speed loss and when the investment in two servers is justified.

Why Use a Two-VPS Multi-Hop Setup and How Does It Work?

In a world where access to information and services is becoming increasingly fragmented, a standard VPN server on a single VPS often proves vulnerable. A direct connection to a server located in a "free" country can be easily blocked at the ISP or national firewall level, especially if the traffic exhibits characteristic VPN protocol signatures. Furthermore, the physical distance to a single server can cause significant delays (ping) and reduced speeds, making online gaming, video conferencing, or streaming virtually impossible.

This is where the main value of a two-VPS chain becomes apparent. Instead of connecting directly to a single remote server, you first connect to a nearby transit VPS, located in a geographically neutral or less censored country (e.g., Kazakhstan, Turkey, Finland, UAE). This transit server, in turn, establishes an encrypted connection with a second, exit VPS, which is located in a country with completely free internet (e.g., Germany, Netherlands, USA). Your traffic passes through two independent encrypted tunnels before exiting to the global network.

When a Regular VPN Isn't Enough: Blocking and Speed Issues

Typical scenarios where a single VPS is insufficient:

  • Deep Packet Inspection (DPI): Many ISPs use DPI to detect and block VPN traffic based on protocol signatures. A single server operating on standard ports becomes an easy target.
  • IP Address Blocking: If the IP address of your single VPN server is blacklisted, it becomes inaccessible. This is especially true for popular commercial VPN services whose IP pools are well-known.
  • High Ping and Low Speed: If you are, for example, in Kazakhstan, and your only VPN server is in the USA, a physical distance of over 10,000 km will inevitably cause delays. This is critical for interactive applications.
  • Insufficient Privacy: Although a VPN encrypts traffic, your ISP still sees that you are connecting to a VPN server's IP address. In some jurisdictions, this can raise questions.

How It Works: Nearby Transit + Distant Exit

The essence of the "nearby transit + distant exit" scheme is as follows:

  1. Your device connects to the first VPS (Transit Server), which is relatively close to you and has a stable, but potentially censored, connection. This connection is encrypted.
  2. The transit server, having received your encrypted traffic, forwards it (also encrypted) to the second VPS (Exit Server), located in a country with free internet.
  3. The exit server decrypts the traffic and sends it to the target resource on the internet.
  4. Return traffic follows the same chain in reverse.

This architecture makes detection and blocking significantly more difficult. Your internet provider only sees a connection to the transit server, which can be disguised as regular web traffic. And the exit server, being in a "free" zone, guarantees access to any resources. Learn more about how to set up a VPN on your own VPS in our detailed guide.

Understanding How a Multi-Hop VPN Transit Server Works

The concept of a VPN transit server is key in the context of multi hop own server configurations. It's not just an intermediate node; it's a strategically placed component that significantly enhances both resistance to blocking and anonymity. Instead of directly accessing the internet, your traffic makes a "jump" through two independent servers, each of which can use its own protocol and settings.

The Double Tunneling Mechanism

Double tunneling, or "VPN over VPN," means that your internet traffic is first encapsulated and encrypted by one VPN protocol, then this already encrypted packet is encapsulated and encrypted again by another VPN protocol (or the same one) for transmission to the second server. This creates a "matryoshka doll" of encrypted layers.

In our scheme with a two-VPS chain, this looks like:

  1. Device -> Transit VPS: Here, a protocol highly resistant to DPI and blocking is used, such as Sing-box with VLESS/XTLS-Reality or Hysteria2. This protocol aims to mask traffic as regular HTTPS to avoid suspicion from your internet provider.
  2. Transit VPS -> Exit VPS: Another encrypted connection is established between your two servers. This can be VLESS/XTLS-Reality, WireGuard, OpenVPN, or even Shadowsocks. The main goal here is stability and speed, as this channel is less susceptible to external blocking.
  3. Exit VPS -> Internet: The exit server decrypts the traffic and sends it to the final resource.

The advantage of this scheme is that even if the channel to the transit server is compromised or blocked, an attacker will only see encrypted traffic going to the transit server but will not be able to determine its final destination or decrypt the content without access to the second tunnel. Furthermore, to your provider, the transit server appears as a regular web server, not a VPN.

Looking for a reliable server for your projects?

VPS from $10/month and dedicated servers from $9/month with NVMe, DDoS protection, and 24/7 support.

View offers →

Advantages Over a Single VPS

  • Increased Resistance to Blocking: Two exit points and two layers of encryption significantly complicate blocking. If one of the servers or protocols is compromised, there is always a second layer of protection. To enhance protection, you can also use Shadowsocks on a VPS.
  • Enhanced Privacy: Your real IP address is hidden behind two nodes. Neither the transit nor the exit provider has a complete picture of your traffic. The exit server only sees the IP of the transit server, and the transit server sees your IP and encrypted traffic going to the exit server.
  • Bypass Geo-restrictions: The exit server can be located in any country, providing access to content blocked in your region or in the transit server's country.
  • Optimized Speed and Ping: Choosing a nearby transit server with a good connection to you can significantly reduce ping compared to a direct connection to a distant exit server. Then, from the transit server, traffic is routed to the exit VPS via high-speed backbones.
  • Configuration Flexibility: You can use different protocols at each stage, selecting optimal solutions for your specific situation (e.g., Xray/Sing-box for DPI bypass in the first stage and WireGuard for speed in the second).

Choosing Optimal VPS Locations for Your Multi-Hop Chain: Strategic Planning

The success and effectiveness of your two-VPS chain directly depend on the correct selection of geographical locations for the transit and exit servers. This is not just "nearby" and "distant," but a strategic decision considering political stability, legislation, network infrastructure, and cost. For bypassing the most stringent blocks, for example, a VPS for bypassing blocks in China requires a special approach to location selection.

Selection Criteria for Transit and Exit Servers

Transit VPS (First Node):

  • Geographical Proximity: Should be as close to you as possible to minimize ping. Ideally, a neighboring country or a country with good network backbones to your region.
  • Neutral Jurisdiction: The country should be relatively free from strict censorship and not exert direct pressure on internet providers. Examples: Kazakhstan, Turkey, Finland, UAE, Baltic states.
  • Stable Network Infrastructure: High-speed channels and reliable data centers.
  • Protocol Availability: Ability to install and run modern blocking bypass protocols (Sing-box, Xray, Hysteria2) without restrictions from the VPS provider.
  • Reasonable Cost: Since this is only an intermediate node, there's no need to overpay for excessive resources if the main traffic will pass through the exit server.

Exit VPS (Second Node):

  • Internet Freedom: A key criterion. The country should have minimal censorship and no blocking. Examples: Netherlands, Germany, USA, Canada, Switzerland, Sweden.
  • Reliability and Privacy: The VPS provider should have a good reputation for privacy and not store logs.
  • High Bandwidth: Since all your internet traffic will pass through this server, it needs a wide and stable channel. 1 Gbps is a desirable minimum.
  • IP Address Diversity: Some providers offer additional IP addresses, which can be useful for changing your "fingerprint" in case of blocking.
  • Reasonable Cost: Given that this is the final exit point, it makes sense to invest in a more powerful and reliable server here.

Examples of Optimal Location Combinations

If you're in a region facing strict internet censorship:

  1. Option 1 (Basic, price/performance):
    • Transit: Finland, Latvia, Kazakhstan. These countries have good connections to your region, are relatively neutral, and affordable.
    • Exit: Germany, Netherlands. Classic locations with high levels of internet freedom and excellent infrastructure.
  2. Option 2 (Maximum Privacy/Bypass):
    • Transit: UAE, Turkey. A bit further, but can be useful for bypassing specific regional blocks.
    • Exit: Switzerland, Iceland (if available). Known for strict privacy laws.
  3. Option 3 (For Specific Services):
    • Transit: Poland, Czech Republic.
    • Exit: USA (West Coast) — if you need access to American streaming services or game servers.

Always check the ping to potential locations from your device before choosing. Use utilities like ping or online services to check for latency. Remember that the best choice is one that provides the best performance and reliability for your specific needs.

rocket_launch Quick pick

Need a dedicated server?

Compare prices from top providers. Configure and order in minutes.

Browse dedicated servers arrow_forward

How to Set Up a Multi-Hop Two-VPS Chain with Sing-box and Xray: A Step-by-Step Guide

To create a reliable and resilient two-VPS chain, we will use a combination of Sing-box on the transit server and Xray on the exit server. Sing-box is a modern, multi-functional proxy client/server supporting many protocols, including VLESS/XTLS-Reality, which is excellent for DPI bypass. Xray is a V2Ray fork, also featuring a wide range of protocols and high performance. This combination will provide you with a multi hop own server setup with maximum flexibility and resilience.

Prerequisites: OS Selection, Domains

  1. Two VPS: One for transit, one for exit. Ubuntu 22.04 LTS or Debian 11/12 is recommended.
  2. Two Domain Names:
    • transit.yourdomain.com for the transit server (mandatory for Reality).
    • exit.yourdomain.com for the exit server (recommended for TLS).
    Set up A records for each domain, pointing to the respective IP addresses of your VPS.
  3. SSH Access: To both servers with root privileges.
  4. Disable Firewall: For simpler setup, temporarily disable UFW or Firewalld on both servers. Rules can be configured after setup.

Server 1 (Transit): Sing-box Installation and Configuration

On the transit server, we will configure Sing-box to accept incoming connections from the client (you) using the VLESS/XTLS-Reality protocol and forward them to the exit server using the VLESS/TCP/TLS protocol.

1. Install Sing-box

Execute the commands to install Sing-box:


sudo apt update && sudo apt upgrade -y
wget -qO- https://raw.githubusercontent.com/SagerNet/sing-box/master/install.sh | sudo bash
sudo systemctl enable sing-box

2. Generate Reality Keys (for Transit Server)

Reality requires a public and private key, as well as a shortId. Generate them on the transit server:


sing-box generate reality-key

You will get something like:


Private key: KXXXXXXXXX
Public key: YYYYYYYYYY

Save the Public key and shortId (which you will choose, e.g., #12345678) — they will be needed for the client.

3. Sing-box Configuration (/etc/sing-box/config.json)

Replace transit.yourdomain.com with your domain, YYYYYYYYYY with your Reality public key, ZZZZZZZZZZ with the private key, and #12345678 with your shortId. Also, specify the IP address and port of the exit server.


{
  "log": {
    "level": "info"
  },
  "inbounds": [
    {
      "type": "vless",
      "tag": "vless-in",
      "listen": "0.0.0.0",
      "listen_port": 443,
      "uuid": "YOUR_UUID_HERE",
      "flow": "xtls-rprx-vision",
      "tls": {
        "enabled": true,
        "server_name": "transit.yourdomain.com",
        "reality": {
          "enabled": true,
          "handshake_server": "www.google.com",
          "handshake_port": 443,
          "private_key": "ZZZZZZZZZZ",
          "short_id": [
            "12345678"
          ]
        }
      }
    }
  ],
  "outbounds": [
    {
      "type": "vless",
      "tag": "vless-to-exit",
      "server": "EXIT_SERVER_IP",
      "server_port": 443,
      "uuid": "YOUR_UUID_HERE",
      "tls": {
        "enabled": true,
        "server_name": "exit.yourdomain.com",
        "insecure": false
      }
    },
    {
      "type": "direct",
      "tag": "direct"
    },
    {
      "type": "block",
      "tag": "block"
    }
  ],
  "route": {
    "rules": [
      {
        "port": 53,
        "outbound": "direct"
      },
      {
        "network": "udp",
        "port": 53,
        "outbound": "direct"
      },
      {
        "outbound": "vless-to-exit"
      }
    ]
  }
}

Replace YOUR_UUID_HERE with a generated UUID (e.g., using uuidgen in the terminal or online). Replace EXIT_SERVER_IP with the IP address of your exit server. exit.yourdomain.com should be the domain you linked to the exit server.

4. Restart Sing-box


sudo systemctl restart sing-box
sudo systemctl status sing-box

Ensure the service is running and there are no errors.

Server 2 (Exit): Xray Installation and Configuration

On the exit server, we will configure Xray to receive connections from the transit server (via VLESS/TCP/TLS) and exit to the internet.

1. Install Xray

Use the Xray installation script:


sudo apt update && sudo apt upgrade -y
bash -c "$(curl -L https://raw.githubusercontent.com/XTLS/Xray-install/main/install-release.sh)" @ install
sudo systemctl enable xray

2. Obtain SSL Certificate for exit.yourdomain.com

For a TLS connection between the transit and exit servers, a valid SSL certificate is required. We will use Certbot:


sudo apt install certbot -y
sudo certbot certonly --standalone -d exit.yourdomain.com

Follow the instructions. Provide your email. Certificates will be located in /etc/letsencrypt/live/exit.yourdomain.com/.

3. Xray Configuration (/usr/local/etc/xray/config.json)

Replace YOUR_UUID_HERE with the same UUID used on the transit server. Specify the paths to your SSL certificates.


{
  "log": {
    "loglevel": "info"
  },
  "inbounds": [
    {
      "port": 443,
      "protocol": "vless",
      "settings": {
        "clients": [
          {
            "id": "YOUR_UUID_HERE",
            "flow": "xtls-rprx-vision"
          }
        ],
        "decryption": "none"
      },
      "streamSettings": {
        "network": "tcp",
        "security": "tls",
        "tlsSettings": {
          "alpn": [
            "h2",
            "http/1.1"
          ],
          "certificates": [
            {
              "certificateFile": "/etc/letsencrypt/live/exit.yourdomain.com/fullchain.pem",
              "keyFile": "/etc/letsencrypt/live/exit.yourdomain.com/privkey.pem"
            }
          ]
        }
      }
    }
  ],
  "outbounds": [
    {
      "protocol": "freedom",
      "settings": {},
      "tag": "direct"
    },
    {
      "protocol": "blackhole",
      "settings": {},
      "tag": "block"
    }
  ],
  "routing": {
    "rules": [
      {
        "type": "field",
        "ip": [
          "geoip:private"
        ],
        "outboundTag": "block"
      }
    ]
  }
}

4. Restart Xray


sudo systemctl restart xray
sudo systemctl status xray

Ensure Xray is running without errors.

Client Configuration (Sing-box)

On your local device (Windows, macOS, Android, iOS), use the Sing-box client. You will need the following information:

  • Protocol Type: VLESS
  • Server Address: IP address or domain transit.yourdomain.com of the transit server
  • Port: 443
  • UUID: The same one you used on both servers
  • Flow: xtls-rprx-vision
  • TLS: Enabled
  • Reality: Enabled
  • Public Key: Reality public key generated on the transit server (YYYYYYYYYY)
  • Short ID: Your shortId (#12345678)
  • SNI: www.google.com (or another popular site used as handshake_server)

In the Sing-box client (e.g., NekoBox for Android or the official client for other platforms), you can create a new connection by specifying these parameters. Once connected, all your traffic will pass through this two-VPS chain.

Multi-Hop VPS Performance and Speed Loss: How to Minimize Impact

Any chain of proxy servers or VPN tunnels inevitably introduces additional latency and can reduce overall throughput. In the case of a two-VPS chain, your traffic passes through two network nodes, each adding its own overhead. However, these losses can be minimized with smart selection and configuration.

Factors Affecting Speed

  1. Physical Distance: The longer the path between you, the transit, and the exit servers, the higher the ping.
  2. Channel Congestion: Channels between data centers, as well as to your provider, can be overloaded.
  3. VPS Power: Insufficient CPU or RAM on either server can become a bottleneck when processing traffic, especially with a large number of simultaneous connections or high speeds.
  4. Protocol Choice: Some protocols are more resource-intensive or have higher overhead for encryption/decryption.
  5. Protocol Settings: Incorrect or non-optimal settings (e.g., outdated encryption algorithms) can slow down performance.
  6. Network Card/Ports: 1 Gbps ports on a VPS are standard, but sometimes 100 Mbps ports are encountered, which would be a bottleneck.

Optimization: Protocols, Settings, Provider Choice

  • Protocol Selection: For the first segment (client -> transit), use protocols optimized for DPI bypass and obfuscation, such as VLESS/XTLS-Reality (Sing-box, Xray) or Hysteria2. These provide high speed and resilience. For the second segment (transit -> exit), you can use less "obfuscating" but faster and lighter protocols, such as WireGuard, or the same VLESS/XTLS without Reality but with TLS.
  • VPS Power: Ensure both your VPS instances have sufficient resources. For individual use or a small group, 2 vCPU, 4 GB RAM, and an NVMe disk are usually enough. For more intensive traffic or many users, more will be required.
  • Transit Server Proximity: Choose a transit VPS as close as possible to your physical location. This is critically important for minimizing ping.
  • Backbone Quality: Choose VPS providers known for good international connectivity. Valebyte.com offers VPS in various locations with high-speed channels, which is an excellent starting point.
  • TCP Optimization: On both servers, ensure TCP optimization algorithms like BBR are enabled and configured (sudo sysctl -w net.core.default_qdisc=fq && sudo sysctl -w net.ipv4.tcp_congestion_control=bbr).
  • UDP Usage: If the protocol supports UDP (e.g., Hysteria2), this can offer a speed advantage for some types of traffic, but may also be more susceptible to blocking.
  • Monitoring: Regularly monitor CPU, RAM, and network traffic on both servers. This will help identify bottlenecks.

For 200 GB of monthly traffic, 2 vCPU, 4 GB RAM, and a 60 GB NVMe disk are sufficient.

Monthly Traffic vCPU RAM Disk (NVMe/SSD) Port Approx. Price ($/month)
Up to 100 GB 1 2 GB 30 GB NVMe 1 Gbps from $5
100-300 GB 2 4 GB 60 GB NVMe 1 Gbps from $10
300-800 GB 4 8 GB 120 GB NVMe 1 Gbps from $20
800+ GB / Multiple Users 6-8 16 GB+ 200 GB+ NVMe 1-10 Gbps from $40

Note that these are approximate prices for two VPS combined. For an accurate calculation of how much traffic a VPN server consumes and to choose a plan, use our recommendations.

Cost Analysis: When is a Two-VPS Multi-Hop Setup Justified?

It's clear that maintaining a two-VPS chain will cost more than a single one. Instead of one monthly payment, you will have to pay for two servers, and possibly two domain names (although the second is not always strictly necessary). However, in certain scenarios, these additional costs are more than justified, offering unparalleled advantages in stability, speed, and privacy.

Price Comparison with a Single VPS

Let's look at typical expenses:

  • Single VPS: A basic plan with 1-2 vCPU, 2-4 GB RAM, 50-80 GB NVMe disk, and a 1 Gbps port can cost from $5 to $15 per month. This is sufficient for most individual users in "calm" conditions.
  • Two-VPS Chain:
    • Transit VPS: Can be less powerful if it only forwards traffic. For example, 1 vCPU, 2 GB RAM, 30 GB NVMe for $5-$8/month.
    • Exit VPS: Should be more powerful and located in a "premium" location. For example, 2 vCPU, 4 GB RAM, 60 GB NVMe for $8-$15/month.
    • Total: The total cost for two VPS will be approximately $13-$23 per month.
  • Domain Names: Around $10-$15 per year for two domains, or approximately $1-$1.5 per month.

Thus, a two-VPS chain will cost approximately 1.5-2 times more than a single VPS. This is a significant difference, but it is offset by the benefits.

ROI Calculation and Use Cases

When are these additional costs justified?

  1. Under Strict Blocking Conditions: If your internet provider actively blocks standard VPN protocols and IP addresses, a single VPS might simply be unworkable. In such a case, an extra $10-$15 for stable internet access is a minimal price for freedom and functionality. This is especially relevant for regions with active censorship, for example, a VPS for bypassing blocks in Iran.
  2. For Mission-Critical Tasks: If you need constant, stable, and high-speed access to international resources for work, study, or business (e.g., video conferencing, access to cloud services, remote work), then disruptions to a single VPN server can lead to significantly greater financial and time losses than the cost of a second VPS.
  3. For Enhanced Privacy and Anonymity: If your activities require maximum anonymity and stealth, double tunneling provides an additional layer of protection that a single server cannot. Your actions become significantly harder to trace.
  4. For Speed and Ping Optimization: If a direct connection to a distant server results in unacceptably high ping (e.g., >150-200 ms), which interferes with online gaming, high-quality streaming, or voice communication, a nearby transit server can significantly improve the situation, reducing latency to 50-80 ms.
  5. For Shared Use: If you plan to use the chain for multiple users (family, small team), load distribution and reliability become even more important. In this case, the cost per user decreases, and the benefits remain.

Ultimately, a two-VPS chain is an investment in the reliability, speed, and security of your internet connection. If you face serious blocking issues, low speeds, or heightened privacy requirements, such a solution is not just justified but becomes a necessity.

rocket_launch Quick pick

Need a dedicated server?

Compare prices from top providers. Configure and order in minutes.

Browse dedicated servers arrow_forward

Choosing the Best VPS for Your Multi-Hop Setup

Selecting the right hosting provider and VPS configuration for your two-VPS chain is crucial for its effectiveness and stability. Given that you are using two servers, it's important to approach each one carefully.

  1. Check Geography and Ping:
    • For the transit VPS: Choose a location that has minimal ping to you. Use online services or the ping command to test IP addresses of providers.
    • For the exit VPS: Choose a location in a country with free internet and good backbones, even if it's further away.
  2. Assess Resources:
    • For the transit VPS: Usually 1-2 vCPU and 2-4 GB RAM are sufficient if it won't handle huge volumes of traffic.
    • For the exit VPS: 2-4 vCPU and 4-8 GB RAM are recommended for stable operation with multiple users or high traffic.
  3. Disk Type: NVMe or SSD.
    • Always prioritize NVMe disks. They are significantly faster than regular SSDs, which is critical for server performance, especially with intensive logging or high system load.
  4. Bandwidth:
    • Both VPS should have at least a 1 Gbps port. Some providers offer 10 Gbps, which is ideal for the exit server. Also, clarify traffic limits (TB/month) or unmetered.
    • Pay attention to guaranteed throughput, not just peak.
  5. Provider Reliability:
    • Choose providers with a good reputation, high uptime, and responsive technical support. Valebyte.com offers reliable VPS with guaranteed uptime and 24/7 support.
    • Research reviews of the provider in your chosen locations.
  6. Privacy and Logs:
    • Especially for the exit VPS, choose a provider that states minimal log collection and is located in a jurisdiction that respects user privacy.
  7. Cost:
    • Compare plans from different providers. Remember that the lowest price doesn't always mean the best quality. Consider the balance between price and features offered.

Frequently Asked Questions

Can I use the same protocol for both stages of the chain?

Yes, you can. For example, VLESS/XTLS-Reality can be used between the client and the transit server, as well as between the transit and exit servers. However, for the second stage, where bypass is less critical, you might choose a lighter and faster protocol, such as WireGuard, to optimize performance. This offers configuration flexibility.

Will a two-VPS chain affect internet speed?

Yes, any chain of nodes increases latency and can reduce throughput. Your traffic passes through two servers instead of one, which adds time for encryption/decryption and routing. However, with proper location selection and sufficiently powerful VPS, losses can be minimized, and for users with an unstable direct connection, such a setup can even improve perceived speed by providing a more stable channel.

What are the domain name requirements for Reality?

For the VLESS/XTLS-Reality protocol, a valid domain name pointing to the IP address of your transit server is required. This domain will be used to mask traffic as regular HTTPS. Reality does not require an SSL certificate for your domain, but it must be registered and have an A record. In our example, this is transit.yourdomain.com.

How much traffic will I need on each VPS?

The amount of traffic on each VPS will be approximately the same and equal to your total internet traffic. If you consume 100 GB per month, each of the two VPS will also pass approximately 100 GB. When choosing plans, remember that providers usually count traffic in both directions (inbound + outbound), so 100 GB of your consumption might mean 200 GB of billed traffic on each server. For 200 GB of monthly traffic, 2 vCPU and 4 GB RAM are sufficient.

Can I use different providers for the transit and exit VPS?

Yes, and it is even recommended to enhance reliability and privacy. Using different providers in different jurisdictions reduces the risk of both servers being compromised or blocked by the same authority. This also gives you greater flexibility in choosing optimal characteristics and prices for each node in your chain.

Conclusion

Setting up a two-VPS chain with a nearby transit node and a remote exit node is a powerful and flexible solution for those facing strict internet blocks, requiring enhanced privacy, or aiming to optimize connection speed. While this solution demands more resources and initial setup effort, its advantages in stability and resistance to censorship often outweigh the additional costs.

We recommend carefully choosing locations for each server and investing in reliable providers, such as Valebyte.com, to ensure maximum performance and security. With the right configuration, your double tunneling setup will provide you with free and fast access to the global network, minimizing risks and enhancing your digital independence.

Ready to choose a server?

VPS and dedicated servers in 72+ countries with instant activation and full root access.

Get Started Now →
support_agent
Valebyte Support
Usually replies within minutes
Hi there!
Send us a message and we'll reply as soon as possible.