3 ms·
Since a couple of years I've been running iked [0] on my VPSed OpenBSD. It took me around 5 minutes to setup and it "just works" since then with my iPhone and M
by 0ld 7y ago
Since a couple of years I've been running iked [0] on my VPSed OpenBSD. It took me around 5 minutes to setup and it "just works" since then with my iPhone and MacOS clients out of the box, not requiring any additional software.
But since WG is getting so high praise here, I'm now interested what are WG advantages and what does WG have to justify the effort to move away from iked and install/setup the client software everywhere?
I'm certainly going to find out and test it myself, but would really appreciate just a quick answer/explanation
[0] https://man.openbsd.org/iked.8 https://man.openbsd.org/iked.8
- mb7733 7y agoSame question here but using iked on on linux
- hwh 7y agoFor me it's just easier to get my head around having a new network interface presented rather than this pile of security associations and transform configurations. I can just re-use my firewalling and routing knowledge and do not have to put my mind into IPsec mode to manage this. That aside, I think it's still quite a lot easier to use IPsec tooling when you want something that plays along with certificate based multi-level trust models.