symb Posted September 16 Posted September 16 (edited) Hello! I’ve made a small unofficial community tool that helps players with NAT/CGNAT-related connection problems when joining private IL-2 multiplayer/co-op sessions. How it works The host still creates a normal publicly visible multiplayer server, just as usual. The joining player runs the tool on their PC and selects their virtual-LAN connection (such as Radmin VPN). The tool then redirects the relevant IL-2 connection traffic through the virtual LAN connection to the host, allowing players who cannot establish a normal direct connection because of their NAT/CGNAT setup to join the session. The tool only needs to be run on the joining player's PC. Both the host and the joining player need to be connected to the same virtual LAN. What it does — and doesn't do Does not modify IL-2 or any of its files Does not modify servers or player accounts Does not provide any in-game advantage Does not collect, store, or transmit user data Is intended only to help with private co-op connection problems related to NAT/CGNAT This is an unofficial community tool. It is not affiliated with, endorsed by, or officially supported by 1C Game Studios or the IL-2 developers. The source code is freely available and the project is distributed under the GNU GPL v3.0 license. Download The latest release is available here: https://github.com/Symb-IL2/IL2-VPN-Redirect/releases/latest The download is around 70 MB and includes a README with setup instructions in four languages. If you have been experiencing the common issue where IL-2 takes several minutes to connect to a private server and eventually fails to download the mission, this tool may help. I hope it is useful to anyone else who has been running into this problem. 🙂 Edited September 18 by symb Initial public release — v1.0.0
symb Posted September 18 Author Posted September 18 I've actually made a v1.1 that adds configurable port support, but I need to test it properly first before I release it publicly.
symb Posted September 18 Author Posted September 18 Update — IL-2 VPN Redirect v1.1.3 The release has been updated to v1.1.3. Changes Added configurable TCP and UDP ports for each profile. New profiles use the standard IL-2 ports by default: TCP 28000 UDP 28000 TCP 28100 Added an option to anonymize IP addresses in logs, enabled by default. The latest release is available here: https://github.com/Symb-IL2/IL2-VPN-Redirect/releases/latest
Yenns Posted September 19 Posted September 19 Hey, really hopeful for this tool but didn't have any luck getting it to work. I believe I put in the correct public and host's radmin IP, but upon clicking start I lost internet access and was stuck on "No Internet, Secured" on all my networks until running through a long list of troublefixes. Eventually uninstalling my WiFi adapter in Device Manager and restarting restored it. Any idea what the issue is here? It's still absurd to me that there's no way to play co-op missions in this game if you're one of many stuck under CGNAT, so I'm desperately trying to find something that works. Would rly appreciate any help, I'm this close to giving up lol
symb Posted September 19 Author Posted September 19 (edited) 2 hours ago, Yenns said: Hey, really hopeful for this tool but didn't have any luck getting it to work. I believe I put in the correct public and host's radmin IP, but upon clicking start I lost internet access and was stuck on "No Internet, Secured" on all my networks until running through a long list of troublefixes. Eventually uninstalling my WiFi adapter in Device Manager and restarting restored it. Any idea what the issue is here? It's still absurd to me that there's no way to play co-op missions in this game if you're one of many stuck under CGNAT, so I'm desperately trying to find something that works. Would rly appreciate any help, I'm this close to giving up lol Thanks for reporting this — that definitely should not happen, and I’m sorry you ran into it. The tool should only affect the configured IL-2 ports, but its TCP forwarding option temporarily sets up a local compatibility route for the public server IP while the tool is running. On some Wi-Fi drivers or network setups, this may confuse Windows’ network detection or routing. For now, please do not run it again with TCP forwarding enabled. If you are willing to help test, try starting it with “TCP forwarding” unchecked first. That mode may not be sufficient for a full connection, but it will help confirm whether the issue is caused by the TCP forwarding component. If the network issue occurs again, please stop the tool, restart Windows, and send me an anonymized exported log together with a screenshot of the selected options. Do not uninstall network adapters again unless a normal reboot fails to restore the connection. PS If it works with TCP forwarding disabled, I’ll change the next release so that this option is disabled by default and add a clear warning explaining what it does. I want the safest configuration to be the default, with the compatibility mode available only when needed. PS Thanks again for reporting this — I took it seriously and have reworked the experimental TCP compatibility mode. The experimental build now uses a dedicated local TCP bridge for the two IL-2 TCP ports (28000 and 28100). It handles only connections intended for the configured public server IP, forwards them only to the host’s Radmin/ZeroTier address, and ignores unrelated connections. The bridge is also limited to the network path used by the game instead of listening broadly across the system. The normal redirect mode remains available as before. TCP compatibility mode is now clearly marked as an optional compatibility feature, disabled by default for new profiles, with an explanation in the tooltip. I’m running preliminary tests before sharing it publicly. If those go well, I’ll publish the experimental build and would really appreciate it if you could try it as well. Your report was very useful for identifying a network configuration that needs extra care. Edited September 19 by symb
Yenns Posted September 19 Posted September 19 Gave it a try with TCP forwarding enabled unchecked and didn't have any more network problems, but was back to the error #10019 that I've had from before using the tool. So I guess I can confirm that the TCP forwarding was the issue, but running the tool without it isn't enough for a proper connection. Let me know if there's any other testing I can do, and thanks for working on it!
symb Posted September 19 Author Posted September 19 (edited) 35 minutes ago, Yenns said: Gave it a try with TCP forwarding enabled unchecked and didn't have any more network problems, but was back to the error #10019 that I've had from before using the tool. So I guess I can confirm that the TCP forwarding was the issue, but running the tool without it isn't enough for a proper connection. Let me know if there's any other testing I can do, and thanks for working on it! Thanks a lot for the detailed feedback! That’s really useful and helps narrow down where the problem might be. I appreciate you taking the time to test it and report back! IL2 VPN Redirect v1.1.4 - Reworked TCP compatibility mode to use a safer, more isolated connection method. - It now handles only the required IL-2 TCP connections and avoids changing the system’s network configuration. - TCP compatibility mode is enabled by default for new profiles. Since TCP compatibility mode now uses a safer method, keeping it enabled is recommended. https://github.com/Symb-IL2/IL2-VPN-Redirect/releases/tag/v1.1.4 Edited September 19 by symb
Yenns Posted September 19 Posted September 19 Had much better luck with this iteration, was able to connect to, download mission files, and join the host's server with the tool running but wasn't able to select a plane once I loaded in. Had this same problem back when trying port forwarding, so not sure if it's at all related to your tool or what I should try next. Tried hosting myself and had my mate run the tool and join, but they only got error #10019. Have you gotten any coop games going yourself yet? I think I've exhausted all options to get this working in the past so really not sure what else to try from here. Either way, looks like the new TCP compatability mode works without network problems!
symb Posted September 20 Author Posted September 20 (edited) 9 hours ago, Yenns said: Had much better luck with this iteration, was able to connect to, download mission files, and join the host's server with the tool running but wasn't able to select a plane once I loaded in. Had this same problem back when trying port forwarding, so not sure if it's at all related to your tool or what I should try next. Tried hosting myself and had my mate run the tool and join, but they only got error #10019. Have you gotten any coop games going yourself yet? I think I've exhausted all options to get this working in the past so really not sure what else to try from here. Either way, looks like the new TCP compatability mode works without network problems! Thanks a lot for testing this and sharing your results! Glad to hear the TCP compatibility mode is working better for you. The plane selection issue and the #10019 error are a bit puzzling, especially since I haven't encountered either of them in my own co-op testing with v1.0 and later versions. I'll see if I can figure out what's causing these issues. For reference, I have tested the tool with two other players, and in our co-op sessions the connection works fully: players can select plane, spawn, and complete missions without any visible issues. The inability to select a plane may still be related to a missing or incomplete game-traffic path after the initial connection. Since the same symptom also occurred with normal port forwarding, it may involve a part of the host/client network setup that the tool does not yet cover, rather than the new TCP compatibility mode itself. Could you and your friend run one controlled test in each direction and post all four anonymized exported logs? Round 1: - Player A hosts. - Player B joins using the tool. - Player A also runs the tool in monitoring mode only. Round 2: - Player B hosts. - Player A joins using the tool. - Player B also runs the tool in monitoring mode only. For the joining player, use these settings: - Detailed packet log: ON - Match traffic by port: ON - Detect server IP automatically: ON - Diagnostic (no redirect): OFF - TCP compatibility (!): ON - Route through VPN: ON - Keep the default ports unless the host deliberately uses custom ports. - Keep “Anonymize IPs” enabled when exporting the log. For the host running in monitoring mode: - Public server IP: the same public IP that the joining player entered. - Game host VPN IP: the host’s own Radmin/ZeroTier IP. - Detailed packet log: ON - Match traffic by port: ON - Detect server IP automatically: ON - Diagnostic (no redirect): ON - TCP compatibility (!): OFF - Route through VPN does not matter in monitoring mode. Please label the four exported logs with who was hosting, who was joining, and which round they belong to. That should be enough to compare the outgoing and incoming traffic on both sides and determine whether the remaining problem is in the redirect path or outside the tool. Edited September 20 by symb
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now