12 ms·
WireGuard support in Mikrotik RouterOS v7.1beta2
- dgemm 6y agoThat was actually really fast considering how long wireguard has(n't) been around. We don't even have it in stable Linux distributions yet. I guess there is some significant demand for it from Mikrotik's customers. I'll probably use it.
- zamadatix 6y agoNote this in the development tree not the stable release tree. No 7.x has not been released as stable yet and probably won't be for a while. The stable 6.x is still based on an ancient 3.X kernel.
- a012 6y agoMikrotik users were requesting support of Wireguard since 2018 but Mikrotik didn't do it because Wireguard wasn't v1.0. At that time, wireguard.com listed dozen of OS/distributions you can use with wg. Mikrotik thread: https://forum.mikrotik.com/viewtopic.php?t=134093 https://forum.mikrotik.com/viewtopic.php?t=134093
- deleted 6y ago[deleted]
- the8472 6y agoFedora 32 has wireguard. So does any rolling release distro. And for distros with older kernels there are loadable modules that retrofit it. Openwrt has had it for quite some time now.
- nullify88 6y agoIndeed. Official packages exist for Centos / RHEL 7 & 8 for those that need it.
- duhast 6y agoUbuntu 20.04 LTS ships with Wireguard.
- zx2c4 6y agoAnd it was backported to 18.04 and 16.04. And the Debian backports kernel. And SUSE enterprise. And... So indeed GP's comment isn't totally accurate.
- jlgaddis 6y ago> We don't even have it in stable Linux distributions yet. MikroTik users don't have it in stable RouterOS releases either. This is a development ("beta") release for testing purposes.
- chromedev 6y agoThere are lots of stable Linux distros running the stable kernel which is 5.8. it is just distros like RHEL that call themselves stable, but are actually antiquated and honestly just give users a bad experience because most of the software is outdated. Wouldn't expect anything less from IBM.
- gsich 6y agoRedhat did that before they were bought by IBM.
- chromedev 6y agoI was never a fan of RHEL even before they got purchased. They've done some great things lately with Podman, Buildah, Skopeo, etc but never really been an innovator when it comes to desktop Linux. I see Arch and Alpine being the real innovators, and projects like wlroots.
- deleted 6y ago[deleted]
- fomine3 6y agoJust "not for me". It's for enterprise as the name says.
- chromedev 6y agoSo is Alpine Linux. Almost no enterprise I've worked at lately wants to deal with antiquated software as long as their Kubernetes distro is working well.
- silly-silly 6y agoHow did Arch and Alpine innovate ?
- chromedev 6y ago
- seba_dos1 6y agoI think it's more thanks to the fact that WireGuard recently got merged to upstream Linux, so all you need to do is to update the kernel and enable it in defconfig.
- jlgaddis 6y agoHas MikroTik ever made any source code available?
- m463 6y agowho knows, but I run openwrt on my mikrotik rb2011* switches.
- stragies 6y agoDo you happen to know, if the RB2011 will be stuck on the (dead-end) ar71xx release, or whether somebody is working on porting it to the newer ath79 platform with LTS?
- q3k 6y agoIt doesn't seem like porting new devices to ath79 is very involved [1]. I would highly encourage you to make a project out of porting RB2011. [1] - https://git.openwrt.org/?p=openwrt/openwrt.git;a=commit;h=7a705c067f729e1f6edf4945985ec4f5761ca0ab https://git.openwrt.org/?p=openwrt/openwrt.git;a=commit;h=7a...
- m463 6y agoThis is the first I've heard of this. I didn't know it could map to a new platform. I have two and just got them working and haven't updated in maybe a year. I use them as internal switches and only really use vlans + dhcp. It might be interesting to see if porting is a big deal. I have one annoying weirdness where ports are labeled sfp,1-5,6-10, but the logical mapping is really screwed up switch0:6, switch0:1,2,3,4,5, then switch1:5,4,3,2,1 (reversed)
- btgeekboy 6y agoA cursory Google search says yes. Not as a public repo or anything, but if you ask them, you'll get it. Examples here: https://forum.openwrt.org/t/mikrotik-gpl-source/6750/10 https://forum.openwrt.org/t/mikrotik-gpl-source/6750/10
- ac29 6y ago
- BeefySwain 6y agoWe have been waiting for years for UDP OpenVPN, but we get WireGaurd before most major distros. That's something
- znpy 6y agoI don't follow, open on does work on UDP.
- izacus 6y agoRouterOS 7 finally supports UDP OpenVPN so at least that's something.
- zx2c4 6y agoActually, WireGuard has first class support now on a large number of distros, without the need for any additional compilation: Ubuntu 16.04, 18.04, 20.04, Fedora, Debian, OpenSUSE, Arch, Mandriva, Alpine, Nix, Void, OpenWRT, and others. Check out www.wireguard.com/install/ for the whole list.
- chromedev 6y agoOpenWRT has support for WireGuard as well.
- jvolkman 6y agoAs does VyOS.
- kube-system 6y agoAnyone have any experience here with getting wireguard running on pfsense?
- 867-5309 6y agoI don't think *BSD supports wg yet. would love to see this
- cpach 6y agoAFAIU OpenBSD has official support for Wireguard: https://man.openbsd.org/wg https://man.openbsd.org/wg
- rjsw 6y agoIt was added to NetBSD yesterday.
- cpach 6y agoNice :)
- floatboth 6y agoFreeBSD kernel module in review: https://reviews.freebsd.org/D26137 https://reviews.freebsd.org/D26137 thanks to Netgate (pfSense)
- SnaKeZ 6y agoDD-WRT too
- ghostpepper 6y agoThe ball's in your court, Ubiquiti
- pa7ch 6y agoNot ubiquiti's doing but this repo has pre-built kernel modules of wireguard and vyatta integration for I think most of the edgerouter series: https://github.com/WireGuard/wireguard-vyatta-ubnt https://github.com/WireGuard/wireguard-vyatta-ubnt I haven't updated/tested in awhile but last I remember I was seeing 800+ mbit/s on my dinky mips ER-X. Pretty amazing and easy to use.
- holmb 6y agoWe built an Ansible role to install and configure Wireguard on EdgeOS. It works well on EdgeRouter Infinity ER-8-XG and EdgeRouter X. https://github.com/dynamist/ansible-role-wireguard-vyatta https://github.com/dynamist/ansible-role-wireguard-vyatta
- zx2c4 6y agoThis repo appears to use Lochnair's old builds, which are unmaintained/deprecated and replaced with the official ones linked to by GP.
- merlinscholz 6y agoCan confirm, way back I wrote a small guide on how to install and configure Wireguard on the ER-X (and other EdgeRouters), and to date this article is still by far the most read one: https://merlinscholz.name/post/wireguard-on-erx/ https://merlinscholz.name/post/wireguard-on-erx/
- ac29 6y agoUnfortunately 3rd party software installs are lost on updates, so you need to be local to the router before upgrading (or have a secondary VPN available). Development of EdgeOS has really slowed down though, there hasnt been a stable firmware update in 6 months (and that was just a small hotfix).
- floatboth 6y ago> added Layer3 hardware offloading support for CRS309-1G-8S+IN, CRS312-4C+8XG-RM, CRS326-24S+2Q+RM and CRS354-48G-4S+2Q+RM The Marvell switch chip supports IPv6 but for now Mikrotik only implemented support for v4 offload.. :/