8 ms·
Virtual private networks with WireGuard
- johnramsden 9y agoIncludes a nice description of how WireGuard works on Linux, and how it's different from other VPN implementations.
- adynatos 9y agocan wireguard work over tcp? many captive portals i encounter daily block most ports and almost always allow only tcp. so i set up openvpn on port 443 over tcp, which got through everything so far.
- jlgaddis 9y ago> Like many recent protocols, WireGuard is based on UDP.
- minus7 9y agoCouldn't you theoretically run traffic over pseudo-TCP. I.e. you send packets that look like TCP (IP packet type TCP + TCP header), but bypass the kernel's TCP stack and put arbitrary, packet-based data in it, like UDP. Theoretically speaking.
- charleslmunger 9y agoYes, but the same middle boxes would choke on that too, either corrupting it or blocking it.
- helper 9y agoThere's no reason why it couldn't, but doing that would kill all the performance that it currently provides. You could fairly easily tunnel wireguard over tcp using socat.
- Godel_unicode 9y agoYou might want to check whether they also allow UDP/53, that's a common exception.
- feelin_googley 9y agoI use one of the many non-OpenVPN "VPN" alternatives. The one I chose has fewer lines/words/characters of code than Wireguard. It does not require SSL/TLS, it can use Curve25519 and it is faster than OpenVPN. It is a userland daemon (using /dev/tap), so it may be slower than Wireguard. However I think it is more portable than WireGuard. (That is an important feature to me.) How portable is WireGuard to BSD, Minix, Plan9, etc?
- tptacek 9y agoWireGuard isn't simply a vanilla transport that uses Curve25519 for key agreement and some symmetric encryption construction for bulk encryption. It's an instantiation of Trevor Perrin's Noise Protocol Framework, with special protocol allowances for zero-allocation implementation and for DoS avoidance. It's easy to come up with something smaller than WireGuard if all you're doing is slapping some kind of encryption on a tun/tap device.
- feelin_googley 9y ago1. Easy is good. Example: The entire purpose of Noise is to simplify and make things easier for people. 2. I am not "slapping some kind of encryption" on tun/tap devices. Though it would be easy to do so, I have not required "bulk encryption" for this software to be useful. IMO, the flexibility to add this, easily, is indeed a feature worth mentioning (some users might need it), but not one I need right now. 3. Small, fast, flexible and portable are software virtues most useful and therefore most important to me. What I see here in this cheap, senseless comment is the act of trying to superimpose someone other user's virtues, e.g. encryption protocols. It is trying to impose one persons goals onto another persons goals without even knowing what are the other persons goals. The usual nerd web forum nonsense. Not all users need, or value, the same things. The authors of Curve25519 and the peer-to-peer software I use, both academics whose software is used by security consultants, do not spend time reading and interacting with the HN peanut gallery. In fact this is true of the authors of most software I use. I think there is a reason for that. Why do I waste my time reading this garbage? (Every time I respond to it I feel like I have been suckered/duped into playing a time-wasting game.) Because despite the garbage comments there are some interesting, unconventional end users who read HN. Not sure where else one would find this audience all checking the same website. How "easy" it was for any of these authors I mentioned to write the software I value is mildly intriguing but truthfully not something I really care about. The fact is that they were the only ones to write it and publish it. That is what is important to me. All of this is tangential to the question: Is Wireguard portable to BSD, Minix, Plan9, etc.? But I guess the fact that whatever I am using, for almost 10 years before WireGuard appeared, is smaller than WireGuard has irked someone into trying to dismiss that prior software. The reason apparently is that it might have been "easy" to avoid writing a large amount of code. It might have been easy to do for the original author, but for those 10 years, no one else did it. The alternatives chose significantly different (IMO, inferior) designs and were all much larger, stacked with "features" and complexity I did not need. The temptation to make things complicated and larger than they need to be is irresistable for most people writing software. It takes serious effort to find authors who can resist this temptation, effort most users will not make. I make that effort and reap the rewards. The author of the parent comment exploits that temptation and the larger number of undetected mistakes it produces as a business. It is easy to see the competing interests and inherent biases between a user that values relatively small, simple software and a security consultant who needs relatively large, complex software (the norm) to continue to exist in order to stay in business.
- pstadler 9y agoGood to see WireGuard getting some coverage. I‘ve been embracing it from the very beginning for small scale Kubernetes clusters running on virtually any cloud provider lacking isolated private networking[1]. It‘s been running stable in different environments for more than a year; set up and forget. Unlike similar software it‘s also dead simple to configure. Apparently, Linus wants it in the Kernel[2]. [1] https://github.com/hobby-kube/guide/blob/master/README.md https://github.com/hobby-kube/guide/blob/master/README.md [2] https://lkml.org/lkml/2018/2/13/752 https://lkml.org/lkml/2018/2/13/752
- rhn_mk1 9y agoIs WireGuard working as an IPv4 tunnel or can it transport arbitrary packets, like ipv6, becoming a tap interface? Does it work as a link between two devices, or one-to-many? Does it support peer-to-peer connections within the group?
- helper 9y agoIt is a layer 3 vpn that supports v4 and v6 payloads. It does not support any layer 2 connection like you would get from a tap interface. You can certainly make a mesh of connections between different hosts by adding the remote peer's public key and ip address to each host's configuration. There is nothing in wireguard that makes that automatic though.
- StavrosK 9y agoAh, so to connect N hosts together you need to configure N-1 connections in each of the hosts? That's a bit of a hassle, though not prohibitive. A VPN that's secure and easy to configure would definitely be useful in getting all the components in our infrastructure talking to each other. No need to worry about authentication or encryption, it'd all be handled for you by the VPN.
- mycall 9y agoI've been an long time advocate of tinc. I'd love to see a comparison with WireGuard.
- ktta 9y agoYou might find this interesting: https://news.ycombinator.com/item?id=16325394 https://news.ycombinator.com/item?id=16325394 There was a lot of discussion of wireguard there.
- zaarn 9y agoI've tried Tinc, Wireguard and OpenVPN. Currently I'm on OVPN via a pfSense box (doesn't support WG yet). Tinc is neat if you need a mesh network but it was an utter pain to properly setup (half the time I wouldn't get any connection, the other I would not get data over it). OVPN and WG have been fairly pleasant in that regard, though OVPN still suffers from some non-obvious failure cases when you stray away from a simple VPN connection. In my case, I only dial into a OVH instance to A) setup/config containers on it and B) use OVH as VPN. Tinc's mesh network is overkill, the clients are all behind X number of NATs or firewalls and without the central server there is no use for the VPN. I might think about Tinc again if I feel the urge to setup multiple boxes.
- rasengan 9y agoWireGuard is doing good things. PIA will be rolling out support shortly.
- DavidNielsen 9y agoAnd a citation. https://www.privateinternetaccess.com/blog/2018/01/private-internet-access-proud-supporting-wireguard-project/ https://www.privateinternetaccess.com/blog/2018/01/private-i... No timeline yet though but given the early state of WireGuard and the platform support that is understandable.