User Experience
Protocol:
Nekotopia Technical Specifications
Protocol
| VPN Protocol | WireGuard (primary) |
| Config Delivery | Download .conf file from dashboard, import into any WireGuard |
| Endpoint | 193.143.16.14:13230 (MikroTik router) |
| Encryption | Curve25519 (key exchange), ChaCha20 (symmetric), Poly1305 (authentication) |
IPsec and PPP options
areexist in thedevelopmentcodebasepipeline) Config delivery: Pre-scripted configuration for download Endpoint: AWS EC2 Encryption: Standardbut WireGuard(Curve25519,isChaCha20,thePoly1305)recommended and supported protocol.
IP Addressing by Tier
| Tier | Private IP Range | Public IP | Internet Access |
|---|---|---|---|
| Torus Basic | 10. or 10.8.1.x |
None | No |
| Torus Standard | 10. |
Shared NAT | Yes |
| Torus Pro | 10.254.16. |
Dedicated 193.143.16.x |
Yes |
Pro IP Mapping
Your private IP 10.254.16.X maps 1:1 to public IP 193.143.16.X via NAT on the MikroTik. If your torus address is 10.254.16.42, your public IP is 193.143.16.42.
User Dashboard
VPN Management:Management
- View active VPN connections and status
- Download WireGuard config files
- Request new VPN connections
- See assigned IP addresses
Firewall/
Firewall & Access Controls (for Pro users):only)
-
Control Description Full Mesh toggle -Allow/deny traffic to/from other Torus members Public Inbound toggle -Allow/deny inbound connections from the internet to your public IP Bandwidth limitLimit-Configurable rate limit (default 512 Kbps, canadjustable)beincreased) - Create up to 5 custom hostnames
like(e.g.,yourname.torus.nekotopia.io) PointsA record points to your public IPAutomatically createsPTR (reverse DNS) record created automatically- Add/remove hostnames from
thedashboard - Update
name,name and email - Change password
- Web servers (HTTP/HTTPS)
- Game servers
- SSH access
- Mail servers (reverse DNS included)
- Anything else that listens on a port
DNS Hostnames (Pro only):
**Profile:
Profile
Network Configuration
| Setting | Value |
|---|---|
| DNS Server | 10.254.16.1 (pushed via VPN) |
| Default Route | 0.0.0.0/0 through VPN (Standard/Pro) |
| Split Tunnel | Possible by modifying AllowedIPs in config |
| Keepalive | 25 seconds (standard for NAT traversal) |
What You Can Host (Pro tier)
With a dedicated public IP and inbound access enabled, you can run publicly-accessible services on any port:
The automatic PTR record makes Pro accounts suitable for running mail servers without deliverability issues.