23 ms·
WireGuard is in net-next
- mangix 7y agoAbout time
- ikeboy 7y agoIs there a simple way to tunnel specific apps only through wireguard?
- ryanlol 7y agoOn linux you’d probably want to use network namespaces to accomplish this, there’s an example at https://www.wireguard.com/netns/ https://www.wireguard.com/netns/
- jchw 7y agoShould be possible to accomplish something like this using namespaces, under Linux.
- moreentropy 7y agoWG exposes a point to point / l3 network interface like any other to userspace, so an answer would not be specific to wireguard but about networking and routing in general. Network Namespaces and VRFs are the correct way to approach this I think: https://www.kernel.org/doc/Documentation/networking/vrf.txt https://www.kernel.org/doc/Documentation/networking/vrf.txt
- Agenttin 7y agoYou can choose to only have certain IP address ranges accessible through Wireguard, it also creates a wg0 interface that you should be able to bind software to: https://superuser.com/questions/241178/how-to-use-different-network-interfaces-for-different-processes https://superuser.com/questions/241178/how-to-use-different-...
- fffrantz 7y agoGreat news. They've been hard at work for a while and it's finally come to fruition. Congrats
- majewsky 7y agoWell, to be fair, it was already pretty straight-forward to run WireGuard in production (if your distribution of choice has a WireGuard DKMS package). What I'm more excited about is more people building products on top of WireGuard, thus making it more accessible for the non-sysadmins out there.
- dfcarney 7y agoThis is what we (https://tailscale.com https://tailscale.com) are working on! WireGuard is incredible, but adding some key management (that integrates with your IAM system) and NAT traversal really helps to round things out. I'd love to hear suggestions and feedback on what we're building.
- olah_1 7y agoSee this comment here: https://news.ycombinator.com/item?id=21742482 https://news.ycombinator.com/item?id=21742482 They make a good point about two-factor auth.
- iudqnolq 7y agoI am interested in using tailscale as an individual user. I'm essentially worthless as a user: I'm a college student and would be unwilling to pay much; I might possibly convert to a serious customer but that would be years and years down the line when everything is different. I'd also be massively underutilizing it to connect a handful of devices and max two or three users. I put my email address in your system, and am crossing my fingers.
- intpx 7y agoMy experience with dealing with the DKMS implementation of the Nvidia drivers left a sour taste in my mouth. Not fun when something goes sideways with an update and thousand nodes need to be recovered
- rswail 7y agoAwesome development!
- majewsky 7y agoIf I understand the kernel development process correctly, this means it's on track to land in 5.6 (since 5.4 is the current stable and the merge window for 5.5 is already closed). Correct?
- signa11 7y agoyes.
- nif2ee 7y agoThis will mean a lot for the future of WireGuard and VPNs if it catches Ubuntu 20.04
- yjftsjthsd-h 7y agoFWIW, as of 19.10, `apt-get install wireguard` already works on Ubuntu (using DKMS, which I grant isn't as nice as in-tree).
- amdavidson 7y agoThere is almost no way that occurs. 5.6 and the compatible wireguard-tools won't be out before the 20.04 freezes.
- curt15 7y agoBut its point updates will provide the option to update the kernel. https://wiki.ubuntu.com/Kernel/LTSEnablementStack https://wiki.ubuntu.com/Kernel/LTSEnablementStack
- zx2c4 7y agoRelease announcements are here: https://lists.zx2c4.com/pipermail/wireguard/2019-December/004704.html https://lists.zx2c4.com/pipermail/wireguard/2019-December/00... https://lists.zx2c4.com/pipermail/wireguard/2019-December/004711.html https://lists.zx2c4.com/pipermail/wireguard/2019-December/00... https://lkml.org/lkml/2019/12/8/257 https://lkml.org/lkml/2019/12/8/257
- MertsA 7y agoCongrats, hopefully you'll be able to port it back to Zinc sometime over 2020.
- zx2c4 7y agoWe merged "Frankenzinc" for 5.5, some sort of contorted compromise solution. I'll be working on fixing lingering warts during the 5.5 and 5.6 cycles there.
- loeg 7y agoIs there a way I can learn more about the compromises made in Frankenzinc / etc without reading LKML? I realize it might not be interesting to document if you hope to clean it up shortly, but I would be curious if you've already got something prepared. Congrats on getting in for 5.6 and thank you very much for your years of work on this project. It is extremely impressive.
- zamadatix 7y agoDoes this mean WG will no longer be considered a WIP or are there still more steps?
- loeg 7y agohttps://news.ycombinator.com/item?id=21742102 https://news.ycombinator.com/item?id=21742102
- baybal2 7y agoHow it fares against IPSec?
- pilif 7y agoway simpler (and thus, I would argue, way more secure). way faster. On the other hand: No built-in client in any of the mobile OSes, so a third-party client install is required.
- tssva 7y agoIt may be way simpler for basic setups but it quickly becomes as or more complex than ipsec for more advanced setups such as those involving dynamic routing and/or fail over routes. The additional complexity is due to the fallout of allowed-ips and how they are used. What you essentially end up with is that a wireguard interface represents a point to multipoint non-broadcast network. Any one that has dealt with Frame Relay or ATM can tell you what a headache dealing with dynamic routing over such a network can be. Fun things like having to hand configure your OSPF neighbors. This can be overcome by configuring each Wireguard peer to a separate interface essentially making the interface a point to point network or using another tunneling protocol overtop of Wireguard such as GRE or L2TP. But you quickly lose any simplicity advantage. Even for something like a static floating route for backup Wireguard can be more complex because a Wireguard interface once turned up will not show as down unless manually turned down. This means the connection has to be monitored and the backup route installed based upon the monitoring criteria. Again nothing that can't be overcome but doing so raises the complexity. Unless you are assigning each peer to a different Wireguard interface and setting allowed-ips to all ips you also have to figure out how to update the allowed-ips for peers to be updated as the routing changes. Personally I would have preferred if allowed-ips didn't exist and each peer was assigned to a sub-interface whose status could change based upon keepalives. Then the normal ip routing and filtering facilities of the kernel could have been used instead of the current situation where you have some amount of filtering and routing effectively being done by the Wireguard interface and then some being handled by the kernel. I used to contribute quite a bit to the Wireguard package for Ubiquity routers but stopped when I switched to ipsec. It was apparent that Wireguard was more complex to setup and troubleshoot for even slightly advanced scenarios. As for your statement that it is faster that greatly depends upon the platform being used. It is faster than OpenVPN almost everywhere but many network devices have SoCs that provide slow CPUs and acceleration for ipsec or at least the crypto underlaying it. On those platforms it often is not faster than ipsec. Don't get me wrong despite my comments overall I think Wireguard is pretty darn nifty and am happy to see it included in the kernel. I just think it needs more tooling developed around it before it can be a less complex replacement for ipsec in even some fairly basic scenarios. This doesn't even cover the enterprise road warrior VPN scenarios where Wireguard currently lacks many of the more advanced enterprise features of OpenVPN or proprietary offerings from the likes of Cisco, Pulse Secure or Citrix. Hopefully development of the additional protocols and tools needed to add support for more advanced scenarios is accelerated now that Wireguard will be in the kernel. Of course once these are added there is the risk that a Wireguard based feature comparative implementation ends up just as bloated and complex to audit as any of the current alternatives.
- funkyshit 7y agowhat does this mean for users of wireguard? An explanation for linux noobs?
- zx2c4 7y agoIt means that WireGuard will be included in your distro's kernel, which will ease installation. Before, you had to do some ugly kernel module compilation steps, usually using dkms, which was prone to failure and was a general nightmare to deal with. Moving forward, you'll just run "apt install wireguard-tools", and you'll be all set. To temper expectations, though, this is slated for 5.6, which won't be released for another ~120 days or so. After that point it will trickle down to distros. So there's some time yet before users start seeing the direct consequences of this exciting announcement, but it'll be coming.
- funkyshit 7y agoI installed wireguard via ppa on my ubuntu based distro, which wasn't too much of a pain. Are you referring to the "hacks" needed in your install section on the website for e.g. Red Hat/Cent OS? very happy with the performance and stability, thanks a lot for your work!
- zx2c4 7y agoNo, I'm referring to that PPA, which includes the error-prone DKMS stuff. I'm glad it worked for you. Indeed we've put a lot of effort into ensuring that our DKMS stuff mostly _does_ work properly. Sometimes it doesn't though, and then it's a huge hassle. It's this hassle, for people less lucky than yourself with DKMS, that will go away with Linux 5.6.
- funkyshit 7y agoI see. Thanks again, have a great day!
- axismundi 7y agoIt works mostly without problems, but be careful relying on it as a sole means of accessing your server. I've locked myself out (luckily it was just a test server) by closing SSH port on public IP and allowing it only on Wireguard interface. One day I updated the kernel, dev headers got mixed up and my wg0 interface didn't come up after reboot.
- 7ewis 7y agoDoes this mean WireGuard will be moving to stable? My VPN provider has said they won't support WireGuard until it hits 1.0
- zx2c4 7y agoYes. A 1.0 is now on the horizon.
- fmajid 7y agoGet a better VPN provider. Or better yet, run your own.
- kemonocode 7y agoThis is what I've advising people with a little bit of know-how to do. Using Algo [0] (If you only need Wireguard and little else) or Streisand [1] (If you need Wireguard in addition to many other things) makes it pretty much trivial. [0] https://github.com/trailofbits/algo https://github.com/trailofbits/algo [1] https://github.com/StreisandEffect/streisand https://github.com/StreisandEffect/streisand
- coldpie 7y agoI don't think it's fair to say "better" here. Waiting for stable software releases is a perfectly valid approach. It may not be your approach, which is also fine, but neither approach is better than the other.
- eeZah7Ux 7y agoThe end goal here is security. Wireguard has an excellent track record, having a tiny, simple and clean codebase and having been reviewed by many skilled eyes. Most of other solutions don't come close to that.
- yjftsjthsd-h 7y agoI actually do trust WG here, but it is explicitly pre-release software and I would really struggle to fault a provider from avoiding pre-release software. I mean, the WG main page still contains the following (https://www.wireguard.com/ https://www.wireguard.com/): > WireGuard is currently working toward a stable 1.0 release. Current snapshots are generally versioned "0.0.YYYYMMDD" or "0.0.V", but these should not be considered real releases and they may contain security quirks (which would not be eligible for CVEs, since this is pre-release snapshot software). This text will be removed after a thorough audit.
- Havoc 7y agoYes! Hoping this will will have a pervasive effect like https in the networking world, esp for point to points that glue things together behind the scene. Encrypt all the things!
- datenwolf 7y agoOne would wish so! I recently had to start using PulseSecure. For authentication that damn thing loads a full blown webpage in the background, actually executes the JavaScript therein, fills some forms and submits that via POST. There's a PulseSecure module for openconnect, but it's unable to send the keepalive reauthentications, because it's unable to correctly associate the presented form inputs with the credential fields, so I'd have enter them manually, on each keepalive. I can only hope that WireGuard is going to drive a solid piece of hardwood through every "commercial grade" VPN appliance out there, and then desintegrates their heads, too, just to be sure. But given the inertia of big orgs, and the that public and governmental institutions for one reason or another seem to trust "BIG" names with "BIG" (i.e. bloated) products and marketing more, than small, easily auditable stuff, I don't see it happening… sadly.
- thequailman 7y agoWireGuard is actually pretty awful from an IT security org perspective. There are no logs when someone connects or is trying to connect, so auditing or troubleshooting becomes extremely difficult short of packet captures. Additionally, there is no concept of two step auth, so if your key is compromised, anyone can connect without anyone knowing about the compromise. If security companies adopt WireGuard, expect things like PulseSecure to remain as a wrapper around WireGuard. They'll at least standardize on a performant and verifiable VPN solution.
- inetknght 7y ago> WireGuard is actually pretty awful from an IT security org perspective. There are no logs when someone connects or is trying to connect, so auditing or troubleshooting becomes extremely difficult short of packet captures. Additionally, there is no concept of two step auth, so if your key is compromised, anyone can connect without anyone knowing about the compromise. WireGuard's open source. Also you should bring these points up on the mailing lists. Even if you're not the one who writes it, mentioning it should put it on peoples' radar.
- crawshaw 7y agoIf you haven't given WireGuard a try yet, now is a good time. Securely and reliably connecting all my devices with WireGuard was a big reminder to me that there's a much better internet hiding under the hub-and-spoke consumer services model. The internet can be so much more than our phones connecting to large data centers.
- seriesf 7y agoCan you give us an illuminating example of the fulfillment you’ve gained from ... ip-over-udp tunneling? It doesn’t really sound that revelatory?
- ajphdiv 7y agoNot OP. I have a wireguard server setup on my home network. Client installed on my mobile devices. The always on UDP connection seems to use less battery than my previous setup of a TCP VPN. I use this setup to allow my mobile devices to use my home recursive DNS server, which blocks tons of domains for tracking, ads, etc.
- heavyset_go 7y agoIt has a relatively seamless setup and is far from bloated, encryption is efficient on low-powered ARM devices and it works surprisingly well in environments where internet connections are shoddy at best.
- F00Fbug 7y agoThis is a big step forward! I'm hoping that the 1.0 release will prompt Netgate to consider inclusion in pfSense.
- LeoPanthera 7y agoYes! The fact that it's not in pfSense is pretty much the only reason why I'm still using openvpn.
- vocatus_gate 7y agoSame with OPNSense.
- chrissnell 7y agoWireguard is available as a plugin in Opnsense. I use it regularly.
- loeg 7y agopfSense is a FreeBSD downstream, right? First you'd have to port Wireguard to FreeBSD. Or you could run the userspace server, but expect poor performance.
- amarshall 7y agoUserspace already has a package https://www.freshports.org/net/wireguard/ https://www.freshports.org/net/wireguard/
- stock_toaster 7y agoBoringtun (cloudflare's rust implementation of wireguard in userspace) also has work in progress FreeBSD support apparent[1]. [1]: https://github.com/cloudflare/boringtun/pull/35 https://github.com/cloudflare/boringtun/pull/35
- loeg 7y ago
- ralala 7y agoI'm running wireguard in production on ~50 VMs for over a year (centos). Zero problems yet.
- Agenttin 7y agoSo, it scales well with multiple peers? Are all peers aware of each other or are you using some sort of hub and spoke topology?
- ralala 7y agoI created a script to distribute the configuration to all relevant VMs. A network configuration is basically: a port, a name, a set of peers(public key, external ip, wireguard ip). If you want, you can distinguish between master and slave peers (=the slaves do not know/trust each other; master knows everyone)
- middleclick 7y agoWhat is the maximum number of peers you have scaled it to per Wireguard server?
- ralala 7y agoI don't have "user" peers. I just use it to connect the VMs. So around 50 I guess.
- samgranieri 7y agoThis is very welcome news! I had a seamless time using wireguard (via a streisand installation) on my honeymoon in Italy on my phone and more importantly, my wife's phone. It worked seamlessly. Next up I'd like to see this be an easy config option in Unifi's network managment tools
- chadlavi 7y agoAfter switching to wireguard I've been really blown away at how much better the experience is on a phone than other VPN methods. It's always on on my phone as long as I'm not using my home wifi, and I just never need to think about it.
- ndarilek 7y agoDo you have an automated way for turning it off when you're on home wifi? Trying a similar setup, and it isn't immediately clear other than via manual activation how to not use Wireguard in that situation. Thanks.
- kylek 7y agoThe built-in "on-demand activation" is quite good. Can set it to specific SSIDs (white or blacklist) or cellular. I've it on for everything except my home SSID. Edit: I'm talking about the iOS version, not sure what platform you're using.
- 416chad 7y agoNo such luck on Android, you need to use tasker or similar. Really a nuisance but not a deal breaker. It would be dreamy to set up the client to not use specific SSIDs.
- forbiddenlake 7y agoI want to point out that the intents on the official Wireguard Android app are not exposed, so I, not being rooted, can't use Tasker to automate it. However, there are other Android apps that implement Wireguard that do expose their intents. I use Viscerion with Tasker quite happily.
- loxias 7y agoI'm excited by this, but I'd really love a userspace C or C++ implementation. I know that context switching syscalls take time, but I've enjoyed the trend of the last 10 years towards more userspace services, not less. (I'm particularly thinking of filesystems in userspace and block devices in userspace) Still, cool. cool, cool cool. I wonder how long until it's in debian.
- sascha_sl 7y agowireguard-go https://git.zx2c4.com/wireguard-go/about/ https://git.zx2c4.com/wireguard-go/about/
- bauerd 7y agoThere is also https://github.com/cloudflare/boringtun https://github.com/cloudflare/boringtun Edit: Someone running wg in userspace and can share some experiences with either implementation?
- loeg 7y agoThe userspace wireguard-go implementation is slower than the kernel one. Some (I don't know how much) of that is the userspace <-> kernel barrier, but they're also totally different implementations (Go vs C).
- jeltz 7y agoI use BoringTun, it is written in Rust and runs entirely in user space.
- loxias 7y agoCool, thanks, I'll have to check that out!! I've sorta been itching for an excuse to learn rust. Go left me underwhelmed, but that's probably due to me having misplaced expectations. (it's not a better C or C++, it's a better Perl/Python/Shell)
- jlgaddis 7y ago
- haywirez 7y agoGreat experience with WireGuard so far, but does anyone know a simpler way to use it over networks where UDP is blocked (e.g. university Wi-Fi)? I've only found this comment[1]. [1] https://news.ycombinator.com/item?id=17847008 https://news.ycombinator.com/item?id=17847008
- yusefnapora 7y agoYou could try setting up a WireGuard server that listens on udp port 53, which is typically used by DNS and unlikely to be blocked. I haven't used it, but algo recently added a configuration option to do so[1]. Of course WireGuard traffic will look much different than DNS, so they could still block it if they really care to. [1]: https://github.com/trailofbits/algo/pull/1594 https://github.com/trailofbits/algo/pull/1594
- thijsvandien 7y agoI would say DNS is more likely to be blocked than other UDP ports, to force the use of a specific DNS server (not uncommon on public networks).
- kazen44 7y agoeither that or port 53 is simply DNATted to an internal DNS server. Which will make your wireguard VPN unreachable.
- kortilla 7y agoBlocking DNS to arbitrary IPs is very common in locked down environments. They force you to use their resolver handed out by DHCP.
- GhettoMaestro 7y agoJust a word of warning: Stuffing X inside a TCP wrapper can get nasty fast... VPNe are UDP for a reason.
- 7y ago
- _verandaguy 7y agoThis is great news! I've been a wg user on an EdgeRouter for a little over a year now, and the experience is always just so _seamless_. The architecture of this thing's a beaut. That news aside, this is an outstanding commit message. The kernel never disappoints on those.
- wyldfire 7y agoNext stop: NT and XNU?
- tbrock 7y agoWhen will we see support for this built into iOS?
- talkingtab 7y agocomedy?
- habitue 7y agoWhenever so many networks are deployed with this that Apple becomes interested in supporting it for their users. Being in the kernel should help with this, but obviously there's no actual timeline. Maybe never
- brian_herman__ 7y agoProbably never because it is licenced under GPLv2. Apple has a history of removing non gpl code from their operating system.
- doctoboggan 7y agoI recently started using OpenVPN (My router comes with it pre-installed). Does anyone know how this compares with OpenVPN? Is is worth setting up my own wiregaurd machine?
- Avamander 7y ago> Does anyone know how this compares with OpenVPN? Much nicer to use in pretty much every aspect.
- doctoboggan 7y agoIt can't be easier to setup that OpenVPN was on my router (just clicking a checkbox), but I am very interested in switching to a new VPN as I would like to be able to stay continuously connected from my mobile phone, and I understand that OpenVPN isn't great for this. What is your preferred method for getting a WireGuard server installed on your home network?
- Avamander 7y ago> What is your preferred method for getting a WireGuard server installed on your home network? Have a Linux machine that listens for incoming WireGuard connections, then it only takes generating server keys (private, public) and then adding your client's keys to the WireGuard configuration file. Setting up an OpenVPN server on a Linux box is quite a bit more involved.
- tptacek 7y agoWireGuard is much faster than OpenVPN, much simpler to set up than OpenVPN (except for having to set up IP addresses it's approximately as easy to get working as SSH), and it's much, much more secure than OpenVPN.
- doctoboggan 7y agoThanks for the information. What is your recommended way to set up a wireguard server on a home network? Some quick googling tells me it is possible to do it with a raspberry pi, but I would be worried about that being a bottleneck.
- nikisweeting 7y agoIf anyone wants some more docs and examples for Wireguard usage, I made some here: https://github.com/pirate/wireguard-docs https://github.com/pirate/wireguard-docs - how it works internally - how the routing works in different topologies - a few complex and simple example setups - performance expectations - security model, key & config distribution - setting up wireguard for, or inside of docker - GUI tools and other wireguard-related software - links to other tutorials, references, guides
- AceJohnny2 7y ago> (they do have docs, they're just hidden away in the manpages) I feel old and obsolete.
- nikisweeting 7y agoFor most users, if it's not Google-able and in nice HTML format it doesn't exist ;)
- vectorEQ 7y agothis is a really nice resource, thanks a lot!
- gukov 7y agoThanks for the repo! PS Are you an actual pirate?
- nikisweeting 7y agoI am not haha, I just snagged the cool username through a dormant username transfer request.
- pedrocr 7y agoI've been using tinc[1] as a way to get a mesh VPN on all my machines that works even if some of them are behind restrictive firewalls. It works really well and I've automated the setup with puppet so I just deploy it automatically any time I bring up a machine. Highly recommended. Anyone know if there has been any recent work on making wireguard cover this use case? I'm not really worried about security as I treat this overlay network as just as insecure as any other (running ssh over it) and mitigate exploits by running the tinc daemon as a normal user. But it would still be nice to get more performance and security from an in-kernel quality solution like wireguard. [1] https://tinc-vpn.org/ https://tinc-vpn.org/
- ldng 7y agoThe site mention compression. I was under the impression that encryption and compression don't always play well together ?
- wolrah 7y agoProperly encrypted data is basically impossible to compress. Lossless compression requires repeating patterns in the data and lossy compression requires an ability to understand the content. Since properly encrypted data should be indistinguishable from random noise, neither of these things apply. Compressing first and then encrypting the compressed data works fine though.
- e12e 7y agoI use zerotier[1] in a similar fashion, and I don't think there's any out of box solution to get wireguard to do "smart" routing (have two hosts on same switch talk directly, still be able to talk to server in a remote datacenter and a client roaming on cellular - with multicast and mDNS/bonjour working seamlessly). It should be possible to set something up - but I believe you'd need some kind of managing daemon that helped nodes rendevouz and set up routes. [1] https://www.zerotier.com https://www.zerotier.com
- Daegalus 7y agoI use zerotier in a similar fashion. It has been great.
- finchisko 7y agoSorry for off topic, but is there any way, how to setup wireguard (or any VPN) to be used for just single app (lets say Firefox) and not system wide on macOS? Something similar to https://github.com/darkk/redsocks https://github.com/darkk/redsocks with ssh and setting up proxy in Firefox?
- Diagon 7y agoLooks like this might help you: https://superuser.com/a/241200 https://superuser.com/a/241200 Redsocks is a transparent proxy, though. That'll redirect system-wide. I think you're thinking of your basic socks proxy - `ssh -D`.
- hsivonen 7y agoDoes there exist an effort encapsulate WireGuard in HTTP/3 or, when UDP is blocked, in HTTP/2?
- novok 7y agoWhat is the timeline for making wireguard viable for commerical VPNs? """ There's a few fundamental issues with wireguard that make it relatively unsuitable for commercial VPNs with many customers. For a start, if you want to offer customers multiple concurrent devices, each device needs it's own key, and all keys for all customers' devices need to be loaded into kernel memory and cross checked against every packet received, which as you might imagine gets incredibly unwieldy and could savagely impact the performance of PIA servers. When wireguard has the ability to hook a userspace daemon when it receives a valid-looking packet with unrecognised encryption, it'll be a lot closer to usable in commercial contexts, as the daemon could poke a database or cache to load the required keys on demand """ https://www.reddit.com/r/PrivateInternetAccess/comments/d1blo2/wireguard_update/ezk41ix/ https://www.reddit.com/r/PrivateInternetAccess/comments/d1bl...
- boobePhuu7iet7i 7y agoMullvad VPN already supports wireguard fyi