STRICT RULES - READ BEFORE APPLYING
1. ZERO-TOLERANCE HARDWARE RULE:
DO NOT APPLY if you do not have direct, hands-on experience with ALL of these specific devices:
Cudy P2 5G Router
DrayTek Vigor 2915 Router
Yeastar S20 PBX
We are a live production business, NOT a testing ground or a network engineering academy. If you do not know these exact models inside out, do not waste our time. We will not teach you how our network works.
2. THE CORE AUTOMATION GOAL (MANDATORY):
We demand a 100% seamless, automated experience for the end-user. Moving in and out of the office must require ZERO manual network adjustments.
Smart VPN (Always-On): It must run 24/7. When a user walks into the KSA office and connects to the local Wi-Fi, the routing must automatically prioritize local traffic without conflicts. When outside on 5G, it must route to the remote sites smoothly. No manual ON/OFF switching.
Linkus App: It must auto-switch instantly. It must use the Local PBX IP when inside the office, and automatically switch to the DDNS endpoint when outside, bypassing the VPN completely to avoid latency.
3. STRICTLY ANYDESK OR ULTRAVIEWER ONLY:
ALL work MUST be done remotely via AnyDesk or UltraViewer. No direct access, VPN credentials, SSH keys, or passwords will be handed over.
4. MANDATORY BACKUPS:
You must take full configuration backups of all devices to my local PC before making a single change.
5. NO TIME-WASTING:
Do NOT message me asking "What is the problem?" or "What is your budget?". The scope is below. Your expected rate is your final price. Violating this results in an immediate BLOCK.
--- PROJECT DETAILS & TECHNICAL SCOPE ---
We need an expert to troubleshoot and optimize our site-to-site network and VoIP infrastructure between Saudi Arabia (5G behind CGNAT) and Egypt (Fiber).
Current Infrastructure:
KSA Site: DrayTek Vigor 2915 router cascaded behind a Cudy P2 5G router.
Egypt Site: Yeastar S20 PBX on stable Fiber (NO modifications needed here).
Cloud VPS (Contabo, Germany): Used as a relay to bypass the KSA 5G CGNAT. It runs Docker, Caddy (reverse proxy) with a No-IP DDNS.
Tunnels: WireGuard is ALREADY SET UP and working perfectly on the Contabo server for the site-to-site link. Remote users currently use DrayTek's Smart VPN (SSL VPN).
The Issues to Fix via AnyDesk / UltraViewer:
Port 443 Conflict: The previous developer mapped port 443 on the VPS (via Caddy) directly to the DrayTek Web GUI. This conflicts with DrayTek's SSL VPN. You must resolve this and forward the necessary Yeastar S20 PBX ports directly through the VPS so users can register Linkus natively via the DDNS hostname.
Smart VPN (Always-On Split Tunnel): Reconfigure the DrayTek remote dial-in VPN to IPsec/IKEv2. You MUST configure pure Split-Tunneling to route BOTH the remote Egypt subnets (192.168.10.0/24 & 192.168.2.0/24) AND the local KSA subnets (192.168.100.0/24 & 192.168.50.0/24) to achieve the seamless transition mentioned above.
VoIP Instability: Fix the random drops and choppy audio on the Linkus app. Configure and enforce lightweight codecs (e.g., Opus, as we do not have a G.729 license) on the Yeastar S20.
Minor WireGuard Tweaks: Verify/adjust MTU/MSS clamping to prevent packet fragmentation over 5G, and ensure "PersistentKeepalive" is active.
Network & Security Engineer - Cairo
Alnafitha
Network Engineer with Python
CodiLime
Senior Network Solutions Engineer – Enterprise Networking & Wireless (Remote – International (Non-US))
GigaKOM
Principal Full Stack Engineer – AI Systems & Engineering Automation
IgniteTech
Conversational AI Engineer
Novagates Official
Oracle Cloud GTM Functional Consultant
ScaleneWorks People Solutions LLP