I want my VPN to find another way through when a route stops working. Because that’s how the Internet is supposed to work, right? I don’t want every retry to introduce me to the same service from another address.
My provider blocks some resources I use. A working third-party proxy gets me through, but I may know little about its country, IP address, or reputation. Switch proxies, and my connection has recovered while my account appears to have gone travelling.
So I want two hops with different jobs. The first punches through the filters and blocks of a heavily controlled network. The second is the exit I chose in advance.
One Hop for Reachability, One for the Address
The entry is replaceable. I need to reach it through my network’s restrictions, and it needs to reach the exit. Whether its address is accepted by the final service is irrelevant: that connection comes from the exit.
The exit is a VPS I choose for its location and address reputation. Separating the roles lets me keep using it even when I cannot reach it directly.
The address services see needs to stay stable, not just the server I connect to. Reputation needs checking against those services; it isn’t included in the VPS invoice.
Build the Chain on the Client
The client holds the configuration for both hops. It connects to the entry and asks it to open a connection to the exit. Through that connection, the client establishes an authenticated, encrypted proxy session with the exit. It then asks the exit to connect to the final service.
The entry sees the client, the exit endpoint, and traffic timing and volume. The inner session keeps the exit credentials and final destination requests encrypted between client and exit.
Putting both nodes in a fastest-node pool doesn’t build this chain: the client would pick one. The connection to the exit must itself travel through the entry.
Change the Entry, Keep the Exit
Suppose the selected route is entry A → exit. When A stops working, the client reconnects through entry B → the same exit. It doesn’t promote B into the exit, and it doesn’t choose a different country because the ping looks nicer there.
The client checks complete routes to the selected exit from the user’s network. Reaching an entry alone doesn’t prove the chain works.
If no route to the selected exit works, traffic assigned to it stops. Choosing another exit is my decision.
Some Traffic Doesn’t Need Both Hops
For selected local and regional sites, the ordinary connection can be faster and avoids foreign addresses they may reject. The client sends these requests outside the tunnel, saving tunnel bandwidth and forwarding work. A Direct rule on the VPS would still give them the VPS’s address.
The client decides which destinations stay local. The exit also blocks local-only destinations it recognises, in case a stale client rule sends one through the tunnel.
VPS-direct traffic uses the chosen address without another relay. The same choice must cover the service’s sign-in and API requests; splitting them between exits defeats the point.
For untrusted recipients, including hosters and sites collecting proxy addresses, the VPS forwards through WARP. They see Cloudflare’s egress instead. Unknown destinations get the same treatment until approved for VPS direct.
WARP adds a third leg for those destinations. If it fails, their traffic stops; falling back to VPS direct would expose the address.
Keep Names and Lists Consistent
Domain lists and IP ranges aren’t interchangeable: a shared address may serve unrelated sites. DNS lookups need the same local/remote split as the traffic they serve.
Updating these lists can change a route without changing the rules. Client and exit must agree on what’s local-only, so both take those definitions from one source.
The Subscription Is a Set of Chains
A subscription generator takes entry and exit lists and builds compatible pairs. Three compatible entries and two exits give six chains: two exit groups with three paths each. I choose the group; the client chooses a working path inside it.
Where allowed, a direct connection to the exit can join the group as “No entry relay.” It skips the first hop while keeping the chosen exit.
Conversion must preserve both nodes’ settings and their place in the chain. A refresh can change entries, but must preserve the chosen exit and local split. Remove that exit and the selection becomes unavailable. The generator distributes configuration; packets don’t pass through it.
I choose where my traffic comes out. The client finds a way there. Same exit, another way in.






