StartOS on Oracle VM, is there a way to run a VPN to hide my IP from my ISP when running a node on clearnet?

Hi, I have a bitcoin knots running on Oracle VM, I want to make sure my ISP doesn’t know that I run a bitcoin node, this is very important for my safety and security as it’s extremely prohibited to use bitcoin where I live, they can easily throw me in jail if the government somehow was informed.
I synced the node while my IP was exposed but now after sync I really want to run in as privately as possible, I use TOR but it’s so slow and I never find peers. I was thinking maybe VPN is an option?

If I can’t do it privately unfortunately I can’t do it at all as it’s too risky. I’d really appreciate your help.

In your situation I really would not recommend moving away from Tor-only peers. When you say that it never finds peers, do you mean literally never any peers and the blockchain gets out of sync, or just that it takes a very long time to bootstrap when first starting? Could you share the specific config tweaks you made in Knots?

If you do try a VPN on the Windows machine, then I would configure Knots to not accept incoming connections, and make sure you have NAT for the network config (not bridged adapter) in VirtualBox (which means you will only be able to connect to your server from the Windows host machine, or via Tor browser). A better VPN setup (though more technically challenging to set up) is to configure the VPN on your router or on a dedicated bridge adapter, which the Windows computer connects to for internet. This would reduce the chances for accidental leaked traffic over your residential IP.

I disabled clearnet in the config of my Knots node

In my situation bootstrapping a TOR connection stalls for hours, it keeps failing and retrying and this is the TOR log:

2026-07-18T11:03:39+03:00  Starting tor@default.service - Anonymizing overlay network for TCP...
2026-07-18T11:03:39+03:00  Jul 18 08:03:39.377 [notice] Tor 0.4.8.9 running on Linux with Libevent 2.1.12-stable, OpenSSL 3.0.11, Zlib 1.2.13, Liblzma 5.4.1, Libzstd 1.5.4 and Glibc 2.36 as libc.
2026-07-18T11:03:39+03:00  Jul 18 08:03:39.377 [notice] Tor can't help you if you use it wrong! Learn how to be safe at https://support.torproject.org/faq/staying-anonymous/
2026-07-18T11:03:39+03:00  Jul 18 08:03:39.377 [notice] Read configuration file "/usr/share/tor/tor-service-defaults-torrc".
2026-07-18T11:03:39+03:00  Jul 18 08:03:39.377 [notice] Read configuration file "/etc/tor/torrc".
2026-07-18T11:03:39+03:00  Configuration was valid
2026-07-18T11:03:39+03:00  We compiled with OpenSSL 300000b0: OpenSSL 3.0.11 19 Sep 2023 and we are running with OpenSSL 300000b0: 3.0.11. These two versions should be binary compatible.
2026-07-18T11:03:39+03:00  Jul 18 08:03:39.421 [notice] Tor 0.4.8.9 running on Linux with Libevent 2.1.12-stable, OpenSSL 3.0.11, Zlib 1.2.13, Liblzma 5.4.1, Libzstd 1.5.4 and Glibc 2.36 as libc.
2026-07-18T11:03:39+03:00  Jul 18 08:03:39.421 [notice] Tor can't help you if you use it wrong! Learn how to be safe at https://support.torproject.org/faq/staying-anonymous/
2026-07-18T11:03:39+03:00  Jul 18 08:03:39.421 [notice] Read configuration file "/usr/share/tor/tor-service-defaults-torrc".
2026-07-18T11:03:39+03:00  Jul 18 08:03:39.421 [notice] Read configuration file "/etc/tor/torrc".
2026-07-18T11:03:39+03:00  Jul 18 08:03:39.421 [warn] You specified a public address '0.0.0.0:9050' for SocksPort. Other people on the Internet might find your computer and use it as an open proxy. Please don't allow this unless you have a good reason.
2026-07-18T11:03:39+03:00  Jul 18 08:03:39.421 [notice] Opening Socks listener on 0.0.0.0:9050
2026-07-18T11:03:39+03:00  Jul 18 08:03:39.421 [notice] Opened Socks listener connection (ready) on 0.0.0.0:9050
2026-07-18T11:03:39+03:00  Jul 18 08:03:39.421 [notice] Opening Control listener on 127.0.0.1:9051
2026-07-18T11:03:39+03:00  Jul 18 08:03:39.421 [notice] Opened Control listener connection (ready) on 127.0.0.1:9051
2026-07-18T11:03:39+03:00  Tor 0.4.8.9 running on Linux with Libevent 2.1.12-stable, OpenSSL 3.0.11, Zlib 1.2.13, Liblzma 5.4.1, Libzstd 1.5.4 and Glibc 2.36 as libc.
2026-07-18T11:03:39+03:00  Tor can't help you if you use it wrong! Learn how to be safe at https://support.torproject.org/faq/staying-anonymous/
2026-07-18T11:03:39+03:00  Read configuration file "/usr/share/tor/tor-service-defaults-torrc".
2026-07-18T11:03:39+03:00  Read configuration file "/etc/tor/torrc".
2026-07-18T11:03:39+03:00  You specified a public address '0.0.0.0:9050' for SocksPort. Other people on the Internet might find your computer and use it as an open proxy. Please don't allow this unless you have a good reason.
2026-07-18T11:03:39+03:00  Opening Socks listener on 0.0.0.0:9050
2026-07-18T11:03:39+03:00  Opened Socks listener connection (ready) on 0.0.0.0:9050
2026-07-18T11:03:39+03:00  Opening Control listener on 127.0.0.1:9051
2026-07-18T11:03:39+03:00  Opened Control listener connection (ready) on 127.0.0.1:9051
2026-07-18T11:03:39+03:00  Parsing GEOIP IPv4 file /usr/share/tor/geoip.
2026-07-18T11:03:39+03:00  Parsing GEOIP IPv6 file /usr/share/tor/geoip6.
2026-07-18T11:03:39+03:00  Bootstrapped 0% (starting): Starting
2026-07-18T11:03:39+03:00  Starting with guard context "default"
2026-07-18T11:03:39+03:00  Started tor@default.service - Anonymizing overlay network for TCP.
2026-07-18T11:03:39+03:00  Signaled readiness to systemd
2026-07-18T11:03:40+03:00  New control connection opened from 127.0.0.1.
2026-07-18T11:03:40+03:00  Opening Control listener on /run/tor/control
2026-07-18T11:03:40+03:00  Opened Control listener connection (ready) on /run/tor/control
2026-07-18T11:03:40+03:00  Bootstrapped 5% (conn): Connecting to a relay
2026-07-18T11:03:40+03:00  Bootstrapped 10% (conn_done): Connected to a relay
2026-07-18T11:03:42+03:00  Bootstrapped 14% (handshake): Handshaking with a relay
2026-07-18T11:03:44+03:00  Problem bootstrapping. Stuck at 14% (handshake): Handshaking with a relay. (No route to host; NOROUTE; count 2; recommendation warn; host BB004C7F4C5C9FAE5E001864537F89388444F572 at 85.221.38.93:1312)
2026-07-18T11:03:44+03:00  1 connections have failed:
2026-07-18T11:03:44+03:00  1 connections died in state handshaking (TLS) with SSL state SSLv3/TLS write client hello in HANDSHAKE

I haven’t installed or setup a VPN on my PC or home router yet, will look into that soon but want to figure out why TOR doesn’t work most of the time, it sometimes works for a couple of hours or so and fails again.

I tried using NAT instead of Bridged Adapter and the issue is basically the same