r/i2p • • 11d ago

Guide/Tutorial Instruction how to create secret tunnel inside I2P network

My old post here https://www.reddit.com/r/i2p/comments/1pxv52a/instruction_how_to_create_secret_tunnel_inside/ was deleted by reddit as well as my other posts on Reddit and more important my own subreddit too. By the way I try to restore knowledge for all our community reposting from my logs. If something happens again with this post, feel free to post this instruction by yourself, I don't need glory or anything like this keeping this text under my name.

Here is the instruction how to create SECRET tunnel between computers, computer and phone, phone and phone.

I didn't find posts about this topic here. This instruction will explain how to create secret i2p tunnel between server(computer with Linux) and client(Android phone) for all people and for myself so I can access to it from anywhere in case I have new phone/laptop or purged all data on it for crossing the state borders.

Firstly, you need to have binaries on server from there github.com/PurpleI2P/i2pd-tools/ You can build them and save. And for sure you should have already installed i2pd on your computer and phone.

Let's start create a secret tunnel:

  1. Now we generate file of secret tunnel for server(computer with Linux):

./keygen yourserver.dat 11

  1. Copy this file to i2pd folder on server(computer with Linux):

sudo cp yourserver.dat /var/lib/i2pd/

  1. Now we should find destination address for client(Android phone) config:

./keyinfo -b yourserver.dat (we should save address in the string which starts "b33 address:" for step 6)

  1. Now we should find public and private keys for server and client configs:

./x25519 (save both strings, we will need them later in step 5 and 6)

  1. Now we create config for server(computer with Linux) in tunnels.conf file located in /etc/i2pd/tunnels.conf

[anynameforserverconfig]

type = server

host = 127.0.0.1

port = 22 (for example we create a secret i2p tunnel for ssh service, so we chose port 22)

inport = 22666 (can be any number, just remember to use the same number in client config too)

inbound.length = 1 (1 for faster speed, for more anonymous traffic choose 2,3, etc)

outbound.length = 1 (1 for faster speed, for more anonymous traffic choose 2,3, etc)

inbound.quantity = 4

outbound.quantity = 4

inbound.backupQuantity = 2 (reduce traffic when inactive)

outbound.backupQuantity = 2 (reduce traffic when inactive)

i2cp.reduceOnIdle = true

keys = yourserver.dat

signaturetype = 11

i2cp.leaseSetType = 5

i2cp.leaseSetAuthType = 1

i2cp.leaseSetClient.dh.001 = anyname:publickey (insert here public key from step 4)

  1. Now we create config for client(Android phone) in file which should be copied to /sdcard/i2pd/tunnels.conf on Android phone:

[anynameforclientconfig]

type = client

host = 127.0.0.1

port = 22666 (same number as in server config, so your ssh client should use port 22666 for connection)

inbound.length = 1 (1 for faster speed, for more anonymous traffic choose 2,3, etc)

outbound.length = 1 (1 for faster speed, for more anonymous traffic choose 2,3, etc)

inbound.quantity = 4

outbound.quantity = 4

inbound.backupQuantity = 2 (reduce traffic when inactive)

outbound.backupQuantity = 2 (reduce traffic when inactive)

i2cp.dontPublishLeaseSet = true

destination = xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx.b32.i2p (insert address saved from step 3)

keys = yourclient.dat

i2cp.leaseSetPrivKey = privatekey (insert here private key from step 4)

  1. Now restart i2pd on server(computer with Linux), wait for 5-10 minutes, restart i2pd on client(Android phone). All should work now.
18 Upvotes

4 comments sorted by

2

u/sys370model195 11d ago edited 11d ago

It is only "secret" while nobody is looking for it. If a network is running a decent IDS or properly configured firewall, the traffic will stand out.

4

u/decentralize999 11d ago

Yes, let's say better to name it "unannounced". any i2p traffic can be detected but it is not easy task.

3

u/sys370model195 11d ago

Traffic that is unusual in any aspect for the network or the endponts is very easy to detect.

For example, port 22 traffic towsrds an end user device is unusual. Our IDS will send alarms when it sees this. And a great many other ports.

Unsolicited traffic toward en end-user device is another red flag. Something initiating a connection to an end-user device instead of the device initiating the connection? Nope.

There are SOOO many ways to monitor end user device network activity for abnormalities.

2

u/technikaffin 10d ago

Sure, and on top of that, you get time correlation, which you basically can't protect against depending on the enemy you're facing. Traffic patterns alone can reveal a lot and have successfully uncovered hidden .onion services in the past. See "Operation Onymous", "PETS 2011" and "I2PERCEPTION", among others.