3 ms·
I can only assume the people who describe existing VPN technologies as "too hard" are the people hired to do things badly in infomercials. Setting up IPSec sit
by LIV2 8y ago
I can only assume the people who describe existing VPN technologies as "too hard" are the people hired to do things badly in infomercials.
Setting up IPSec site-site tunnels can be a frustrating experience but setting up IPSEC/L2TP is piss easy with any router I have worked with, maybe it's hard to bang together a working config on a Linux server but I wouldn't know.
- vetinari 8y agoIPSEC with Linux is actually easier than with Windows. It's windows that has the special requirements (oh, you have NAT somewhere on the way? You are going to deploy a registry key to all your clients to allow UDP encapsulation. And you have your gateway behind NAT? Now you cannot have your hostname in your Subject Alternate Name (otherwise mandatory), you gotta have the external IP there, potentially breaking all the non-windows clients).
- akerl_ 8y agoI'm not sure where you're quoting "too hard" from; it doesn't occur in the comment you're replying to or in the WinTun site. The complexity folks are referring to is the volume of code, number of config options, and the equivalent increase in "wrong but functional" ways the code could work. As an end user, one of the worst possible outcomes is that I set up a VPN and the tunnel works for my traffic, but due to an error on my part or a bug in the code, the connection is not secure. Wireguard's codebase is designed to be small, easily auditable, and expose the minimum necessary config choices. This is specifically to guard against these risks.