7 ms·
Given the occasion, could someone write a paragraph about what downstream effects are expected by wireguard existing? So far I’ve seen mostly technical argument
by xal 7y ago
Given the occasion, could someone write a paragraph about what downstream effects are expected by wireguard existing? So far I’ve seen mostly technical arguments for it. VPNs have become a more important piece of infrastructure now. The most significant approachability increase really came from mobile based solutions and auto pilot systems like Google’s Outline.
Will WG make a marked difference in stability, speed, approachability for normal users, or what can we expect?
- myu701 7y agoSomeone else can give a much better comparison than me, this is just to get you started. Compared to the 80% use case of OpenVPN, Wireguard is: 1. Much less code. A few thousand lines of code vs lots more for OpenVPN 2. Speedier. WG does UDP traffic so there is less overhead on the protocol level for syncs acks etc. 3. Easier on mobile battery life due to decreased complexity For one example use case comparing them side by side, see PiVPN, which I use to setup a Raspberry Pi Zero W on my home network, create a client key for my phone, open a single port forward to the pivpn server, download the wireguard app, scan the qr code the pivpn key generated, and poof, I can check a box and 'be' on my home network, behind my pihole, and with access to my LAN resources. OpenVPN can do that usecase with pivpn as well but its more processor intensive and a little more setup vs wireguard.
- middleclick 7y agoOn that note, I wish and hope Wireguard did TCP as well. Some countries block UDP traffic or at least throttle it.
- jeltz 7y agoMaybe the best solution is to use a tool like https://github.com/wangyu-/udp2raw-tunnel https://github.com/wangyu-/udp2raw-tunnel.
- middleclick 7y agoI know, but the performance takes a massive hit. Have you tried it? Maybe it was something I did wrong.
- labawi 7y agoNative wireguard is kernel-only. Udp2raw creates a detour via userspace, so more CPU time, delay, jitter .. Was it worse than you would expect? Worse than say openvpn or wireguard-rs/wireguard-go?
- RcrdBrt 7y agoIt's not that bad. Overhead is less than a full TCP encapsulation. I use it all the time
- api 7y agoISPs or countries?
- fnordsensei 7y agoIn some cases, countries. In the country I'm thinking of (name omitted on purpose), you have an effective choice of two ISPs, both government-controlled.
- api 7y agoDo they actually block/throttle all UDP? What about encrypted TCP? Do they block/throttle everything but web and recognized traffic? If that's the case wrapping WG or ZeroTier or whatever in TCP would do nothing since it would still look like a weird unrecognized protocol with a max entropy (encrypted) data stream.
- kertis 7y agoAs I know WireGuard team have no plans and desire for that.
- djsumdog 7y agohuh .. OpenVPN is UDP by default but you can force it to TCP (we had to do that at one University site that would only open limited tcp ports for us). I also discovered Wireguard cannot bind to a specific adapter or IP address if you have multiple address on a server. That might not seem like as a big a deal since it only responds to fully authenticated packets, but it does mean that outgoing packets could be leaving from a different IP address than incoming packets. It's weird that something that's now making it into mainline can't do this very simple kind of bind that almost every other userlevel service, and OpenVPN, can do.
- RcrdBrt 7y agohttps://github.com/wangyu-/udp2raw-tunnel https://github.com/wangyu-/udp2raw-tunnel
- alexellisuk 7y agoHave you taken a look at inlets / inlets PRO? Might be a suitable replacement for your use-case where UDP is not available. https://docs.inlets.dev/ https://docs.inlets.dev/
- kertis 7y ago> little more setup A lot more! PKI infrastructure, chiphersuites and so on and so forth... By the way OpenVPN also can work with UDP, even it's default mode.
- K0SM0S 7y agoIt's a lot more if you do it all manually, however for most "common" use cases, one should probably go with automatically generated config files. For instance pfSense provides you with single-click configs for any target platform, with certs, credentials etc. properly tied to some ACL or ID management system, etc. It's neat and pain-free and just works. You could learn all the theory underneath (I mean systems, IT, not the crypto!) and do it manually (and you probably should for a big-enough infra, or specific-enough use-case), but that will be premature optimization I think. Basic VPN is easy (take a weekend to learn / implement and you'll have all the great benefits of VPNs). Wireguard is "just" more efficient by an order of magnitude as I see it, it'll become the de facto low-profile implementation me thinks.
- kertis 7y agoFirst setup always needs to be manual.
- K0SM0S 7y ago... yes, obviously? : ) We might not be using the word "manual" to mean the same here. I meant not writing the whole xml json yaml or whatever yourself, manually copying certs and credentials etc — you're likely to make mistakes, it's tedious and useless most of the time. You rather use tools like Viscosity. Just efficient / best practice sysadmin. You obviously need access to the target machine in the first place... it's a VPN setup.
- vbezhenar 7y agoI wonder how WireGuard compares to IPsec with regards to the mobile battery. AFAIK IPsec implemented in kernel while WireGuard uses user-space implementation on mobile devices, at least for now.
- packetlost 7y agoThe code has been merged into the kernel as of 5.4(?) I believe, but we won't see that on mobile for quite awhile. I'm guessing IPSec will still have a lead on mobile for awhile for that reason, not that it has sort of majority on there anyway.
- fullstop 7y agoIt was merged in 5.6, which was tagged less than 24 hours ago.
- packetlost 7y agoAh, I remember reading about it like a month ago or so but I though it had already been released
- cyphar 7y agoYou're not misremembering -- Linux has releases every 6-7 weeks. WireGuard was merged into 5.6-rc1 a little over a month ago and the story was posted to HN from memory.
- yjftsjthsd-h 7y agoI'm pretty sure some ROMs already have kernel support, although I don't know details.
- kertis 7y agoFor some Android kernels official WireGuard application supports in-kernel module. Fox example for pixel 3.
- AnIdiotOnTheNet 7y agoWiregard may be speedier (I've never used it so I can't say for certain), but OpenVPN can also use UDP.
- api 7y agoWG is much faster in our tests than OpenVPN, and a bit faster than IPSec depending on the system. OpenVPN uses UDP too but OpenVPN is kind of slow.
- zajio1am 7y agoOr much slower on systems with AES-NI, but relatively slow CPU. Like are used in some hi-end SOHO routers. I did not test IPSec vs WireGuard, but scp from/to my home router/NAS is about three times faster with AES (used by IPSec) than with Chacha20 (used by WG).
- api 7y agoGood point. AES hardware acceleration makes a massive difference. It's why ZeroTier 2.x will use AES. Tiny boxes that lack HW acceleration are generally not used in cases where they're pushing enough bandwidth to matter anyway.
- bjoli 7y agoi did test it. in my setup we couldn't get IPsec to not drop a lotmof packages, so the benefits of aes-ni was lost in retries. switching that IPsec setup to chacha20-poly1305 actually made most of the drops go away. I have no idea what was going on, but wireguard and IPsec was comparable in that test, with ispec being sliiiightly faster. the network has almost no latency, so if the retries remain on slower networks, that would change.
- Brakenshire 7y agoMakes a good argument for having a mobile phone on the mainline kernel, rather than on some ancient kernel with a thousand hacks layered on top. Something like Pinephone should get access to this more quickly than a standard Android device.
- kertis 7y agoAmong other features WireGuard has roaming mode, it's fantastic for mobile devices. Just try it, it's easy and quick!
- tw04 7y agoIn my experience the problem with roaming mode is it blocks the login page for wireless networks. IE: in a coffee shop. Maybe that's been fixed recently, but it was a giant PITA in the past.
- kertis 7y agoI suppose because of DNS servers. Shops give you own "correct" dns for showing you adds on any first request.
- yencabulator 7y agoYou could run a portal login helper in a network namespace that doesn't go through the vpn. https://www.chromium.org/chromium-os/chromiumos-design-docs/network-portal-detection https://www.chromium.org/chromium-os/chromiumos-design-docs/...
- igetspam 7y agoAnecdotally: I have run ipsec based VPNs, openvpn, SSH tunnel based VPNs, etc. Almost all have been a bit of a PITA. I walked someone through setting up a WG based VPN two weeks ago, at a wework in Jakarta. Took 10m via slack. The machine is behind a NAT and I haven't had a single problem connecting. I've done tests where I rolled a new server and as soon as it was up, the tunnels were back. It's a thing up beauty.