4 ms·
WireGuard is cool and we really like it at our company (a bunch of infosec consultants). The management of it for an even small number (20) of users is a no-go.
by bitexploder 7y ago
WireGuard is cool and we really like it at our company (a bunch of infosec consultants). The management of it for an even small number (20) of users is a no-go. OpenVPN is ultra reliable and provides legit 2FA options when set up well. I look forward to legit management tools and improvements. For personal use it has been great. Much simpler than OpenVPN for a few (3) users.
- core-questions 7y agoI got the feeling that it's presently aimed more as a replacement for IPSEC site-to-site VPN, which is annoying as hell to configure considering the number of implementations and likelihood that one messed up setting will cause an inscrutable problem. Cipher suite incompatibility, subnet export and routing issues, and there's always the delightful fact that it never seems completely clear that you've got a tunnel up and running. I welcome a clear alternative.
- tptacek 7y agoThe way you're managing WireGuard today is like directly configuring KAME IPSEC. The Linux WireGuard implementation is low-level and, from a systems perspective, unopinionated, which is as it should be. Getting a secure transport integrated safely into the kernel shouldn't be rocket surgery, but it is. That part is done. Getting IdP-managed WireGuard is not rocket surgery, and lots of teams will presumably do it. Those teams, by the way, stand to make a lot more money than Jason will off WireGuard, which is a very good reason to donate. Nobody who can reasonably avoid it should be using OpenVPN anymore. I get that it's burrowed far into some organizations and am not OpenVPN-shaming anyone. But WireGuard is leagues beyond OpenVPN in terms of nuts-and-bolts protocol and implementation security.
- zbrozek 7y agoI would dearly love to see it make its way into pfsense, at which point I could reasonably execute on that vision. Right now I'm using both OpenVPN and Wireguard, and I'd rather not be.
- pferde 7y agoI'm a big fan of Wireguard, and am using it in a few places, but OpenVPN still has its place - namely if you need a VPN tunnel from behind a firewall that only allows outgoing connections to small number of TCP ports, and no UDP ports.
- muldvarp 7y agoYou're not wrong. OpenVPN can be useful in that case, but in general you shouldn't use TCP as the underlying protocol for other TCP traffic, if you can avoid it. The better solution in this case would be to open a UDP port in the firewall.
- pferde 7y agoMy entire point was that in this case, I can not avoid it, it is my only option. Beggars can't be choosers and all that.
- BuildTheRobots 7y ago> But WireGuard is leagues beyond OpenVPN in terms of nuts-and-bolts protocol and implementation security. Could you recommend anything to read that explains this in more detail, please?
- tptacek 7y agoThe WireGuard paper is a good start.
- BuildTheRobots 7y agohttps://www.wireguard.com/papers/wireguard.pdf https://www.wireguard.com/papers/wireguard.pdf - thank you.
- stjohnswarts 7y agoThose will be widespread eventually, it's still relatively new, just hitting Linux mainstream kernel dev, so probably 2 or 3 years before tried and proven management tools come out.