5 ms·
I also use zerotier. Is there an advantage to Tinc?
by derekja 9y ago
I also use zerotier. Is there an advantage to Tinc?
- NickBusey 9y agoYou can self host it for free. ZeroTier looks to charge $100/mo just to let you self host.
- derekja 9y agoAh, excellent! I have only used zerotier with them hosting. Would far prefer to self-host. Thanks for pointing that out!
- ivan4th 9y agoAFAIK you can run your own ZeroTier controller for free. It's just not documented too well and also it's missing the web UI for managing your networks.
- FrankPetrilli 9y agoI ended up writing a CLI to do it that's relatively full-featured. At some point, I intend to move functionality to a shared library between a CLI and a Web frontend, but for now, the CLI works tremendously well for my use cases: https://github.com/FrankPetrilli/ZeroTier-Controller-CLI https://github.com/FrankPetrilli/ZeroTier-Controller-CLI
- nine_k 9y agoThey charge for management of large networks on their controller. You can run your own controller fir free, and it's also open source iirc, but it's not as nice (no web ui) and you're fully on your own.
- grumblez 9y agoIt's $100/month for licensing our web interface for controller management. You're free to set up your own network controller and write your interface for managing it :)
- ktta 9y agoEvery other VPN is different from ZeroTier. I would say a large additional job of ZeroTier is direct connection facilitation between two endpoints rather than route all traffic through a server. If you have two computers behind NAT, the ZeroTier will help you punch through your NAT and let the computers talk to each other directly. It does it extremely well, and I haven't seen anything like it. Cool thing is, it can do everything that a normal VPN can. When the other commenters talk about them hosting the 'server'. They're talking about configs, etc. Traffic doesn't usually go through their servers. Just in rare cases where your ISP is really hell bent of preventing you from UDP hole punching.
- cormacrelf 9y agoPeople always forget about ZeroTier's network flow rules. In a little text file/field, you have a full-on software-defined networking appliance, with filters on any kind of Layer 3-4 information, and a capability model. You could regulate a medium corporate network in about 50 lines, giving people capabilities as required or segmenting areas with tags. And it would work exactly the same whether laptops were inside the building or not. And you can do mad stuff like 'copy all TCP traffic with dport X to some machine running tcpdump'. The whole thing is a dream. I love it. I personally use it as a replacement for AWS VPN Gateway using a ZT managed route and a couple of VPC route table entries. I detail that setup in my ZeroTier Terraform plugin: https://github.com/cormacrelf/terraform-provider-zerotier https://github.com/cormacrelf/terraform-provider-zerotier
- ktta 9y agoI haven't looked at ZeroTier since they made those feature additions. I'll have to check them out. EDIT: Just did. This[1] is amazing. [1]: https://www.zerotier.com/manual.shtml#3_4 https://www.zerotier.com/manual.shtml#3_4
- book_mentioned 9y agoHow we moved to Google Cloud using Consul and ZeroTier with zero downtime | https://news.ycombinator.com/item?id=15548642 https://news.ycombinator.com/item?id=15548642 (Oct 2017)
- carlhjerpe 9y agoI know this is old, but there's one thing that is a big advantage for tinc, and it's that it supports TCP P2P If you're behind a restrictive firewall ZeroTier won't be able to punch through it, and will fall back to forwarding packets (encrypted) through ZeroTier servers, Even if a connection could've been made over TCP to the other client (because his firewall supports UPnP or is port forwarded) which creates a tunnel directly between them. Note that UDP connections are always better for encapsulating TCP, but P2P TCP is better then TCP through an external server with limited bandwidth. I'm a ZeroTier user though, and i've only encountered this to be a problem once. It's nice to know it'll always work well though. Configuration & ease of use: ZT > Tinc Connectivity: Tinc > ZT I know ZeroTier people are looking into solving this, so this might soon be obsolete information :) Also tinfoilhats might prefer Tinc considering there's no central service anywhere.