12 ms·
Tinc VPN: Secure Private Network Between Hosts
- LinuxBender 9y ago+1 for tinc. I've used it for years in VPS providers and from home to VPS to cloak DNS from the ISP eyes and tampering. It's not as fast as strongswan or wireguard, but it has dynamic mesh routing. If one of my nodes is down, I route through the others automagically, all in user space without having to enable forwarding on any nodes. This is handy when backbone providers are having issues.
- kitotik 9y agoMostly the same feedback, though I’m curious on the performance differences you’re seeing with strongswan. In my setups, strongswan seems to induce ~25% hit, compared to ~15% with tincd. I’m a noob with strongswan so I’m sure it’s something with my setup.
- LinuxBender 9y agoAre you also doing UDP encapsulation and any additional NAT's? I'm using transport mode on strongswan. I get about 3% overhead with strongswan and about 5% with tinc, but the throughput on tinc caps out much sooner for me than with strongswan when dealing with high RTT. It could be the tun driver in CentOS causing my issues, possibly.
- nh2 9y agoOverhead over what, and at which line speed? 1 Gbit/s, 10 Gbit/s? Tinc on bare metal hardware has pretty low CPU usage at 1 Gbit/s, but not so at 10 Gbit/s.
- arca_vorago 9y agoInteresting, I usually just ssh tunnel (I liked the idea of https://github.com/apenwarr/sshuttle/ https://github.com/apenwarr/sshuttle/) but I like the idea of making things a bit easier on myself, gonna have to checkout tinc.
- rsync 9y agoThe apenwarr/sshuttle is abandoned - the current sshuttle, which is under active development, is here: https://github.com/sshuttle/sshuttle https://github.com/sshuttle/sshuttle Highly recommended. Allows you to use any server running SSH as a VPN endpoint with no configuration necessary - you just need a working login.
- arca_vorago 9y agoThank you very much!
- crtasm 9y agoDo you know if it has leak protection built in (prevent traffic when sshuttle's connection drops)? I can't see it mentioned in the documentation.
- gruez 9y ago>I've used it for years in VPS providers and from home to VPS to cloak DNS from the ISP eyes and tampering. what's the logic behind that? are vps providers somehow more trustworthy than ISPs?
- ryanlol 9y ago>are vps providers somehow more trustworthy than ISPs? Random small providers from lowendtalk or whatever may not be, but yeah vast majority of hosting providers will be far more trustworthy than any residential ISP. However, life tends to be much easier if you avoid VPS providers and just get a cheap dedicated server from somebody like OVH instead.
- metalliqaz 9y ago> but yeah vast majority of hosting providers will be far more trustworthy than any residential ISP. [citation needed]
- ryanlol 9y ago1) Incentives, residential ISPs obviously have a far bigger incentive to try and monetize your traffic. 2) No lock-in for hosting products, way more competitive hosting market, hosting companies have incentive to provide better service than residential ISPs. 3) Residential ISPs tend to have a far bigger attack surface and less trained staff. I hacked many of the worlds biggest ISPs and hosting companies, the ISPs were always running Solaris from a decade ago.
- mirimir 9y agoOne reason is that you and your ISP are almost certainly under the same jurisdiction. So your ISP is more likely subject to coercion by your government, compared with VPS providers in other jurisdictions. Further, you can choose VPS providers in jurisdictions where such coercion will not likely be successful.
- jrnichols 9y ago"just get a cheap dedicated server " what does one consider to be "cheap" for a dedicated server these days?
- anshargal 9y agoIn my experience for a simple connection between two hosts a port forwarded over ssh was significantly faster than tinc VPN. Obviously ssh is port forwarding is not a network, but sometimes you don't need a network.
- whalesalad 9y agoI knew I would click on this thread and see a comment suggesting SSH. You are right – but SSH is certainly not a network. This technology is useful for folks who need to go down a layer in the stack.
- geek_at 9y agotrue there was a blog post here recently where the conclusion was that ssh tunnels were much faster (by a factor of 6 or 8) than vpns
- metalliqaz 9y agoBy a factor of 6 to 8??? I think you mean "by 6 to 8 percent".
- BlackLotus89 9y agoNo he meant factor https://news.ycombinator.com/item?id=15773466 https://news.ycombinator.com/item?id=15773466
- djrogers 9y agoThe thread you link to has one performance test, with a difference of 750MB for OpenVPN and 870MB for SSH - how is that a factor of 6 to 8? And that's just for iperf/UDP traffic, which is hardly a good indicator of real world performance.
- nh2 9y agoWhy would iperf-created traffic not be a good indicator of real world performance? On pretty much all sensible networks I've tested iperf3 on, performance of actual applications sending data was close to its results.
- anshargal 9y agoAnother interesting alternative to tinc is ZeroTier ( https://www.zerotier.com/ https://www.zerotier.com/ ). I am using it to remotely play Steam games over the Internet and it is surprisingly easy to set up. Probably due to existence of centralized hub.
- derekja 9y agoI also use zerotier. Is there an advantage to Tinc?
- NickBusey 9y agoYou can self host it for free. ZeroTier looks to charge $100/mo just to let you self host.
- derekja 9y agoAh, excellent! I have only used zerotier with them hosting. Would far prefer to self-host. Thanks for pointing that out!
- ivan4th 9y agoAFAIK you can run your own ZeroTier controller for free. It's just not documented too well and also it's missing the web UI for managing your networks.
- FrankPetrilli 9y agoI ended up writing a CLI to do it that's relatively full-featured. At some point, I intend to move functionality to a shared library between a CLI and a Web frontend, but for now, the CLI works tremendously well for my use cases: https://github.com/FrankPetrilli/ZeroTier-Controller-CLI https://github.com/FrankPetrilli/ZeroTier-Controller-CLI
- nine_k 9y agoThey charge for management of large networks on their controller. You can run your own controller fir free, and it's also open source iirc, but it's not as nice (no web ui) and you're fully on your own.
- Steltek 9y agoDoes anyone know if Tinc tunnels DNS requests on Android? The Android OpenVPN client does not and it introduces some problems.
- macawfish 9y agoIt's tricky to get it working on Android. I'll just say that much cause I don't know the answer!
- mathlizard 9y ago+1 for tinc, I can login to my server and see the other three computers, it's nice for ssh-ing or tunnelling. On tinc, I was only able to get a Windows Remote Desktop connection for about 45 seconds, then it loses the connection. I'm guessing OpenVPN might not have this issue. Tinc is way easier to configure than openvpn though. I recommend it :)
- subway 9y agoTinc is pretty amazing. My only beef with it is that once a node is connected to the network, if you ever wish to revoke access, you have to update all nodes on the network to ensure the revoked node is now gone.
- chatmasta 9y agoUnix philosophy says keys should be stored somewhere else, and you can write your own logic to update them on each node.
- billabul 9y agoon tinc each node could have a different public key configuration for the other nodes
- subway 9y agoRight -- the trouble is tinc only halfway adheres to this. It will happily distribute a key. This means if you delete a node from 3/4 of your network, eventually that node's key is redistributed across the network.
- samsk 9y agoSee https://github.com/samsk/ansible-tinc https://github.com/samsk/ansible-tinc
- subway 9y agoYeah, there are a number of out of band mechanisms available to manage keys, but the issue still remains that you have to rely on an out of band mechanism to revoke access. If nodes reside in multiple administrative zones the situation gets even more awkward.
- nimbius 9y agohttps://www.tinc-vpn.org/documentation/Generating-keypairs.html#Generating-keypairs https://www.tinc-vpn.org/documentation/Generating-keypairs.h... "Just press enter to accept the defaults." is there an expert mode? does this support ED_25519 keys or use open/libressl libs?
- subway 9y ago1.0 only supports RSA keys. In 1.1 (pre-release), 25519 keys are supported. Here's an example of the full output from `tinc -n foo init` on a node named `yarp` in Tinc 1.1, which is roughly the same as the command linked to: https://gist.github.com/anonymous/95cd556cfcb66119234ed142553d7871 https://gist.github.com/anonymous/95cd556cfcb66119234ed14255... "expert" mode would be to just generate those same keypairs with openssl, and configs by hand. With 1.0, you can only have RSA. With 1.1, you can have RSA and/or ED25519.
- gregoriol 9y agoHave been usinh Tinc to create a private network between a few servers for a hosting that has servers in the same datacenter but only public IPs, no private networking available. Transfers of quite large files as well as mysql/redis connexions work amazingly well. CPU gets loaded quite a bit, but overall it is fast (for such a setup) and easy to configure.
- dozzie 9y agoI cannot fathom why people who want VPN keep using Tinc with its hand-rolled protocol riddled with cryptographic errors.
- cyounkins 9y agoCitation?
- dozzie 9y agoHave you read the protocol and compared it with techniques used to build any widely used cryptographic transport? I did. Given that this is not point to point protocol, you cannot just assume that the author used stock protocol (TLS or IPsec), because there's no such thing. And unless there was an analysis that confirmed the protocol's strength or the author is a recognized cryptographer, you cannot assume he did a good job.
- avtar 9y agoThe parent rightfully asked for a citation for your claim: > hand-rolled protocol riddled with cryptographic errors It's fine if you know of examples but even better if you can provide them so others benefit.
- dozzie 9y agoIt was a few years ago, so I don't remember the details, but there were things like lack of integrity protection for control messages sent between nodes or keys with a very long life time shared by all the nodes.
- cat199 9y ago> And unless there was an analysis that confirmed the protocol's strength or the author is a recognized cryptographer, you cannot assume he did a good job. nor can you assume he did a bad job..
- 9y ago
- tptacek 9y agoThis is as good a time as any to point people in the direction of WireGuard, Jason Donenfeld's modernized VPN: * It inherits strong, modern crypto from Trevor Perrin's Noise Protocol Framework. * It's designed to be extremely simple to configure for the common case. * It has a microscopic trusted code base --- 4-5000 lines compared with hundreds of thousands for strongSwan --- and the protocol was specifically designed to enable that; for instance, the protocol makes specific allowances to enable implementations without any dynamic allocation. * It's probably the fastest available VPN. You can only use it on Linux at the moment, but that will change this year. WireGuard is so good people at my company spin up Vagrant images on their Macbooks to use it. Check it out: https://www.wireguard.com/ https://www.wireguard.com/ Benjamin Dowling and Kenny Paterson (a name you might be familiar with) just completed and published a formal analysis of WireGuard; the results are complicated (the eCK model WireGuard was proven under doesn't contemplate separate key exchange and data transport phases) but here's a TLDR from Kenny: https://twitter.com/kennyog/status/955884665801445377 https://twitter.com/kennyog/status/955884665801445377
- ktta 9y agoThe amazing thing about wireguard is its ease of use once you understand its concepts. Just read the part under 'Cryptokey Routing' on the homepage and you're good to go. Also the this page[1] you want more sophisticated setup (like remote ssh to your computer behind NAT without affecting your normal browsing) If anyone wants help with their setup, ask here[2]. I can help anyone out with questions. I didn't create the sub, but should be okay. [1]: https://www.wireguard.com/netns/ https://www.wireguard.com/netns/ [2]: https://www.reddit.com/r/WireGuard https://www.reddit.com/r/WireGuard
- zx2c4 9y agoThat's strange. Who made this sub-reddit? Not me (the creator). If you have questions, come to #wireguard on Freenode -- https://kiwiirc.com/client/irc.freenode.net/wireguard https://kiwiirc.com/client/irc.freenode.net/wireguard -- or ask the mailing list https://lists.zx2c4.com/mailman/listinfo/wireguard https://lists.zx2c4.com/mailman/listinfo/wireguard -- or just ask me here. We're a friendly bunch.
- WouterZ 9y agoI have SoftEther running at home - which is the opensource free enterprise version (development driven by Japanese university from what I gather). Which offer enterprise features and supports OpenVPN. This looks functionally rather poor compared so Softether...
- tgtweak 9y ago+1 softether is great. Highly underrated and very fast.
- qaq 9y agoI really like zeroTier
- samsk 9y agoI've made an ansible playbook, to simplify tinc nodes management. See https://github.com/samsk/ansible-tinc https://github.com/samsk/ansible-tinc
- asdfghj123 9y agoThe main feature that sets tinc apart from the competition is automatic and reliable upgrading of proxied connections to direct connections through NAT hole punching.
- cuckcuckspruce 9y agoThis is the number one reason that I use tinc, and something that competitors (including WireGuard as promoted at the top of this thread) don't have without additional work.
- deleted 9y ago[deleted]
- Tepix 9y agoHow does this compare to SigmaVPN[1] which is tiny and uses modern crypto instead of OpenSSL? -- [1] https://github.com/neilalexander/sigmavpn https://github.com/neilalexander/sigmavpn
- winkywooster 9y agoSigmaVPN doesn't seem to be in active development, plus there's no documentation.
- Tepix 9y agoThe documentation is there. Click on the "wiki" tab. https://github.com/neilalexander/sigmavpn/wiki https://github.com/neilalexander/sigmavpn/wiki
- skrowl 9y ago1.0 was 14 years ago and the latest release was 3 months ago. Any particular reason this was posted now? Great new feature / etc?
- hhanesand 9y agoIs this similar to Hamachi?
- skinnymuch 9y agoI’m guessing so? You’re the only one who brought up Hamachi. ZeroTier seems to be the preferred code. I might try that. Right now I use Hamachi.
- rsync 9y agoThis is as good a time as any to point people in the direction of sshuttle, which is a very simple and elegant VPN that can use any SSH server as an endpoint. * No configuration required for endpoints - any SSH server that you have a login on will work. * Works on Linux and FreeBSD and OSX * Tunnels DNS and UDP, etc. * I have no idea how fast it is. https://github.com/sshuttle/sshuttle https://github.com/sshuttle/sshuttle
- jaspervdj 9y agosshuttle does not tunnel UDP out-of-the-box. It only works on Linux and only if you are using the tproxy mode, which is not the default and a little more involved to set up. See: http://sshuttle.readthedocs.io/en/stable/requirements.html#linux-with-tproxy-method http://sshuttle.readthedocs.io/en/stable/requirements.html#l...
- majewsky 9y ago> It only works on Linux Absolutely not. My colleagues with Macs are using it on macOS just fine. > a little more involved to set up Either TPROXY is the default on Arch Linux, or this is false as well. I just installed sshuttle via pacman and it worked without any additional setup.
- rsync 9y ago"sshuttle does not tunnel UDP out-of-the-box. It only works on Linux ..." We (rsync.net) sponsored work to get UDP functionality working with sshuttle on FreeBSD. It is my understanding that it is committed to FreeBSD ... you might need to wait for 11.2 ?
- marmaduke 9y agoFrom the docs, it appears to redirect new TCP sessions through an established SSH session, so performance would be on par with a simpler SSH port forward.
- staunch 9y agoOpenVPN is still going to be the best choice for some time. There's nothing else as well supported across platforms and it does everything most people want, including allowing connected clients to communicate directly. It doesn't have mesh support but that's probably a good thing in my experience.
- segmondy 9y agoI currently run OpenVPN on a $5 raspberry pi. Powered off the computer's USB port. Works great. Haven't given Tinc or Wireguard a try but will experiment. I see a lot of suggestions for ssh. It's best to use a VPN. All incoming tcp traffic is blocked to my VPN, it doesn't respond to ICMP. Pretty much looks like a dead host unless you know there's a VPN. To connect, you need both the key and password. So it's quite secure. I can then ssh to my internal network. Nice way to access my home network without exposing it directly to the net.
- icelancer 9y agoDo you have good config files for this? I've tried all the prebuilt stuff and I have serious issues with it. Would love to have a cheap VPN termination point at my office and at home.
- aplorbust 9y ago"WireGuard Key Generation in JavaScript ====================================== Various people believe in JavaScript crypto, unfortunately. This small example helps them fuel their poor taste."
- lukaslalinsky 9y agoIf you need to securely connect servers that only have public network, I suggest you give Weave Net a try. It's developed for Docker and also runs on Docker, but the private IPs can be exported to the host machine so you can also use it as a VPN between the hosts. It's super easy to setup and reasonably fast since it uses ESP packets, which are encrypted on the kernel level.
- _Codemonkeyism 9y agoNot clear what is the difference between the OSS and paid version. Paid version starts at $30/month/node (=server?) - which looks very very expensive.
- slgeorge 9y agoWeave Cloud is the commercial service. It's a management platform for developers creating and operating Kubernetes-based applications. It helps you do CI/CD, observability, monitoring and networking/security[0]. It's across the whole 'developer experience' not just networking. Weave Net is completely OSS and usable to create overlay networks between docker nodes or hosts. There's an extensive user guide [1] and project on Github [2]. You wouldn't need the commercial service for this sort of usage. Business users buy a subscription to get support for complex networking. [0] https://www.weave.works/product/cloud/ https://www.weave.works/product/cloud/ [1] https://www.weave.works/docs/net/latest/overview/features/ https://www.weave.works/docs/net/latest/overview/features/ [2] https://github.com/weaveworks/weave https://github.com/weaveworks/weave
- buserror 9y agoI love tinc for another reason too. I've been using it for many, many years, and the one feature of the re-routing that always amazes me is: I'm on the laptop, connected to Gb ethernet--- I do work on remote servers (via tinc). I pull the cable, the lappy's network reconfigure to wifi, tinc re-connects and... my connections to the remote serves have not skipped a beat. As far as x2go, ssh or VNC, the 'ethernet' it's using is still up; might have lost a couple packets, but that's it. I just love it.
- wener 9y agoThanks bring me tinc, I just spend I whole day on this. Love it !! This will change what I want to do, with tinc, network become easier. ️
- rurban 9y agoWeren't the tinc developers caught adding NSA backdoors into it and getting paid to do it last year? I remember something like this remotely from the Snowden leaks.