4 ms·
Good news (rare) in Jan 2020 ;-) Using WireGuard to establish a mesh network seems good to start with but it does not scale well (even with the help of subspac
by terrywang 7y ago
Good news (rare) in Jan 2020 ;-)
Using WireGuard to establish a mesh network seems good to start with but it does not scale well (even with the help of subspace web UI). Nebula (from Slack) seems to be a better option which is simple, secure and scales well so far, docs are not that well at this stage but usable.
My main use case of WireGuard is to secure network traffic on Laptop/Workstations, replacing old-school complicated IPsec (strongSwan) and OpenVPN, can't be happier with its simplicity, user experience (seamless switching networks like strongSwan client for Android, per network on-demand, etc) and performance, battery life on mobile devices, etc. Anyway, non of the traditional VPN solutions (including WireGuard) work inside the Chinese GFW when travelling to China Mainland (won't go there until the 2019-nCoV is under control or a vaccine is available). So I am exploring V2ray (TLS + WebSocket + Web) and Trojan at this stage (working ones to my knowledge).
Gravitational folks even implemented a WireGuard based overlay network plugin for k8s, super excited to replace flannel with wormhole (I have to admit it is a bad name) in use cases where encryption is required for overlay networking, which flannel does not offer.
Many thanks to the WireGuard development team for the good work! Jason and many others, wow, I see the name of a long-time-no-see frined Herbert Xu (crypto subsystem maintainer).
- terrywang 7y agoForgot to mention a potential problem with WireGuard, server keeps the list of clients' virtual IPs (AllowedIPs used for routing/ACLs), not ideal for VPN service providers in terms of privacy. It's not a problem for overlay network (e.g. Nebula) though, as it is considered a `requirement`.