3 ms·
Not so sure, as lonng as you can not disable logging: https://www.perfect-privacy.com/en/blog/wireguard-vpn-pros-and-cons https://www.perfect-privacy.com/en/bl
by niczem 7y ago
Not so sure, as lonng as you can not disable logging:
https://www.perfect-privacy.com/en/blog/wireguard-vpn-pros-and-cons https://www.perfect-privacy.com/en/blog/wireguard-vpn-pros-a...
- Hikikomori 7y agoTheir use case may require it, not true for others.
- blattimwind 7y agoWhat they want to do, cannot be done by Wireguard, because Wireguard does not have the concept of "VPN sessions / connections". What they probably need to do is to assign each customer a fixed private IP for use within their VPN, e.g. from 10.0.0.0/8. When those are not enough any more, they need to segment their VPN, so they can re-use the private IP space in each segment. w.r.t. to "NeuroRouting and TrackStop not possible", they could route their stuff through a TUN interface to do whatever they want to do in user space. With a performance cost.
- Znafon 7y agoThis is a common critic of WireGuard, but it looks like those service are looking for excuses to explain why they don't propose WireGuard yet. As far as I understang it: > What they probably need to do is to assign each customer a fixed private IP for use within their VPN, e.g. from 10.0.0.0/8. Actually, they can set a different IP for each session and rotate them by given it to the client out of band, for example when it authenticates to the service. > When those are not enough any more, they need to segment their VPN Like with all other VPNs right? They could also distribute IPv6 for the tunnel and this would not be an issue.
- blattimwind 7y ago> Actually, they can set a different IP for each session and rotate them by given it to the client out of band, for example when it authenticates to the service. Like I said, Wireguard does not have the concept of sessions. You could add your own proprietary "stuff" around Wireguard to add that concept, but then you don't need anything extra from Wireguard. You add the keys of the users as part of the session setup and remove them when the session is destroyed. Of course, this means that clients have to use a client tool provided by you.
- Znafon 7y agoThere is a handshake at most every two minutes. Is it not possible to say e.g. fetch a new key if the last handshake was an hour ago?