27 ms·
Wireguard is not connection based, so a full-mesh VPN with n nodes essentially just means each node has n-1 peer keys and maintains a routing table with n-1 ent
by blattimwind 7y ago
Wireguard is not connection based, so a full-mesh VPN with n nodes essentially just means each node has n-1 peer keys and maintains a routing table with n-1 entries for the VPN.
- mindslight 7y agoThere are still 70x69/2 connections going on under the hood. You can't completely ignore that complexity - if there are underlying connectivity issues, specific host-host traffic will fail (eg due to NAT). My wireguard setup actually has n x (n-1) config files/instances (current n=8), as that's the only way to shuffle default-gateways over it. It's a little unwieldy, but still manageable. Whereas I can't imagine doing the same with OpenVPN.