5 ms·
I set up Wireguard with this script [0] and made the jump from OpenVPN earlier this week (using Testflight). Has worked wonderfully throughout (once I added a D
by 0xADEADBEE 8y ago
I set up Wireguard with this script [0] and made the jump from OpenVPN earlier this week (using Testflight). Has worked wonderfully throughout (once I added a DNS server to my client config - that one bit me!) and I'm now a convert.
[0] - https://github.com/l-n-s/wireguard-install https://github.com/l-n-s/wireguard-install
- nissarup 8y agoThank you for that link. I tried manually setting up a VPN for my phone. It didn't work. After deleting my old wg0.conf (and adding the DNS to the client) it worked.
- 0xADEADBEE 8y agoYou’re so welcome! Thrilled to have saved someone else the debugging time. Enjoy!
- singularity2001 8y agojust a reminder that for Linux you can use SSH connections to any server as VPN via SSHuttle. 100% simple and easy
- cyphar 8y agoSure, but WireGuard has several other benefits (security-wise and operation-wise to sshuttle). sshuttle is a "poor man's VPN", WireGuard is a next generation VPN.
- kortilla 8y agoThat’s a nice sound bite but it isn’t really convincing for people that don’t know what wireguard brings. Is there a short comparison article you could point to that highlights the differences?
- cyphar 8y agohttps://www.wireguard.com/ https://www.wireguard.com/ lists several of the features, and https://lwn.net/Articles/748582/ https://lwn.net/Articles/748582/ is an LWN article on WireGuard which lists some of the features. One of the most obvious features is that you get roaming with WireGuard (like Mosh) which I don't think you can get from sshuttle (it might be technically possible to add, but I don't think it supported it last time I used it). It also allows for management of the VPN interface like a regular interface (so you can set iptables rules and other complicated network setups using it), rather than relying purely on proxying. And you don't need to give people SSH access in order to use it.
- e12e 8y agoOne major point over ssh is that: "WireGuard securely encapsulates IP packets over UDP." - so you avoid all the issues of tcp-over-tcp;wireguard is a "real" VPN.
- cyphar 8y agosshuttle doesn't pass TCP over TCP, it does some work on the "local" side before sending it over TCP so it's actually just "data-over-TCP"[1]. [1]: https://sshuttle.readthedocs.io/en/stable/how-it-works.html https://sshuttle.readthedocs.io/en/stable/how-it-works.html
- e12e 8y agoCool, I wasn't aware of that. Still ends up doing udp over tcp, though.
- beagle3 8y agoBut still doesn’t do udp or ip, only let’s you connect out (not in, which is often desirable but still a limitation). Also, you lose information about where connections originate - to the recipient, it all looks like it came from the sshuttle host.
- apexalpha 8y ago
- yjftsjthsd-h 8y agoAgreed that sshuttle is probably the easiest VPN I've ever seen, but from my experience its performance leaves a lot to be desired. WG is a little bit more involved to set up, but is extremely high performance.
- beagle3 8y agoPoor’s man vpn, not real vpn: only tcp (no udp, Ping etc) and only one way