A practical learning path for operating BGP safely before requesting public Internet number resources or a FreeTransit tunnel.
A public ASN, an IP prefix and a BGP session are production Internet resources. They are not a first BGP laboratory. A mistake can make your own network unreachable, leak routes learned from one provider to another, or announce address space that does not belong to you.
FreeTransit helps community networks obtain and use Internet number resources. We also expect applicants to understand the basic operational responsibility that comes with those resources. You do not need to be an expert, but you should be able to build, filter, verify and monitor a simple BGP setup before it is connected to a public network.
Free non-commercial IP transit by tunnel or IXP, plus RIPE sponsorship for people who need an ASN or independent resources first.

fully automated tunnelbroker, peering and transit platform - happy networking
based on sponsors, the great community and love - get it for free!

So I’m about to teach you a bunch of tricks for efficiently tunneling whatever you want over seemingly innocuous openings in a customer’s firewall. These tricks will culminate with the most cursed trick of all, which is tunneling inbound SSH connections inside of outbound HTTPS requests. This will grant you full command-line access to your on-premises hosts using the most benign firewall permission that a customer can grant. Moreover, this post is accompanied by a repository named holepunch containing NixOS modules automating this ultimate trick which you can either use directly or consult as a working proof-of-concept for how the trick works.
Algo VPN is a set of Ansible scripts that simplify the setup of a personal IPSEC and Wireguard VPN. It uses the most secure defaults available, works with common cloud providers, and does not require client software on most devices. See our release announcement for more information.
stunnel - universal SSL tunnel
The stunnel program is designed to work as an SSL encryption wrapper between remote client and local (inetd-startable) or remote server. It can be used to add SSL functionality to commonly used inetd daemons like POP2, POP3, and IMAP servers without any changes in the programs' code. Stunnel uses the OpenSSL library for cryptography, so it supports whatever cryptographic algorithms are compiled into the library.