4 ms·
I ran cjdns for 5 years but recently switched off it. For one, it seemed to have too much traffic over my limited outbound link when things should have been mor
by drewp 8y ago
I ran cjdns for 5 years but recently switched off it. For one, it seemed to have too much traffic over my limited outbound link when things should have been more idle. Also, the commit logs were a little unnerving to me for code I'm trusting with my network security:
All kinds of "oops" edits:
https://github.com/cjdelisle/cjdns/commit/3abe50b8e744f72696aa7ccd5ca5220b4570d020 https://github.com/cjdelisle/cjdns/commit/3abe50b8e744f72696...
https://github.com/cjdelisle/cjdns/commit/feabb1970fbaecf65c651f5b1ea0bf9b8d3b5077 https://github.com/cjdelisle/cjdns/commit/feabb1970fbaecf65c...
https://github.com/cjdelisle/cjdns/commit/c51d89431f1fa42955dc81652c079eb8ca7e814a https://github.com/cjdelisle/cjdns/commit/c51d89431f1fa42955...
https://github.com/cjdelisle/cjdns/commit/1b0c999bd2e5988c3f7e52232417edcab6f4cbb6 https://github.com/cjdelisle/cjdns/commit/1b0c999bd2e5988c3f...
https://github.com/cjdelisle/cjdns/commit/355d7d77cc82c52bf1c9a46408f5c5128f264b93 https://github.com/cjdelisle/cjdns/commit/355d7d77cc82c52bf1... (function args passed in the wrong order)
Some are about extra traffic:
https://github.com/cjdelisle/cjdns/commit/8bcfbf227a8702093114eda041cbd52d169b5fa2 https://github.com/cjdelisle/cjdns/commit/8bcfbf227a87020931...
https://github.com/cjdelisle/cjdns/commit/0ee9cb7f45b466232b02d5b826e3d5800d6573e5 https://github.com/cjdelisle/cjdns/commit/0ee9cb7f45b466232b...
Also it's ipv6 only, which took some fussing. Performance was fine, even on rpi. Reestablishing links was slow and sometimes required restarting of the daemon. Daemons would occasionally get wedged. Log output is unconventional and uses a special reader tool (a la adb for android). Occasionally routes wouldn't be chosen right (two home computers would route via an external cloud box), which I'd fix by restarting the right daemons.
I laboriously switched to openvpn (two networks) and haven't worked out all the routing and hotswitching for my roaming phone+laptop yet. Now I'm considering vita, tinc, zerotier, or wireguard. Probably I'll try out zerotier to see if it works out of the box, then try wireguard if I'm going to have to configure it a lot, since it seems like WG is the most unix-toolbox-do-one-thing out of all of them.
- neilalexander 8y agoCheck out Yggdrasil - https://yggdrasil-network.github.io/ https://yggdrasil-network.github.io/ - we've tried very hard to solve the problems that cjdns has, seem to be much more reliable in real world conditions and we send/receive much less idle traffic to do it. We also have Wireguard-like crypto-key routing for both IPv4 and IPv6. (I am one of the developers.)
- fiatjaf 8y agoWow, that's nice. I'm going to start using that now. cjdns always seems so intimidating when I look at it, Yggdrasil looks super friendly and easy.
- fiatjaf 8y agoThank you very much. Actually, I don't know what are people trying to achieve when they run these things. Did you had a problem cjdns was solving?
- drewp 8y agoYes, some machines on different networks in my house plus a roaming laptop all got to talk to each other without hassle. They got random-looking ipv6 addresses, so I don't know if 'subnet' is the right word here. Before, I had to act differently on the laptop based on where I was, and the raspi nodes on my guest wifi couldn't reach the influxdb server that was not exposed to the wifi net.