4 ms·
It's not. Why would one want that workload on their router when they can offload it to a $35 Pi?
by Proven 6y ago
It's not.
Why would one want that workload on their router when they can offload it to a $35 Pi?
- jvolkman 6y agoBecause then you don't have to run an additional $35 Pi.
- hackmiester 6y agoAnd apply updates to it...
- redis_mlc 6y agoI understand that amateurs love the Pi and other underpowered, junk hardware, but not everybody wants yet another science project in their life.
- sJ646U9k6c6gME9 6y ago"It's free!" they say, if you can get it to run The Geeks say, "Hey, that's half the fun!" Yeah, but I got a girlfriend, and things to get done The Linux OS SUCKS (I'm sorry to say it, but it does.) https://genius.com/Three-dead-trolls-in-a-baggie-every-os-sucks-lyrics https://genius.com/Three-dead-trolls-in-a-baggie-every-os-su...
- keeganpoppen 6y agoI was about to be annoyed by this comment until I saw it in the context of a song about how every operating sucks, which, when framed like that, I can't help but agree with. ;) (although I will say that I've been having a better time w/ arch linux + dwm lately than any OS / setup I've ever used-- but then again I also love raspberry pis, have like 3 of them, and am, in fact, using one to run dnsmasq / wireguard, so... xD)
- angry_octet 6y agoIDK if you know, but it seems you're shadow banned. Which I find annoying because I wanted to reply to another post you wrote.
- redis_mlc 6y agoMention it to dang if you like my posts. He's not too bright, but he's all we got. :)
- 10000truths 6y agoOne of the main selling points of Wireguard is that it runs much leaner than OpenVPN or IPSec tunnels, especially on embedded hardware, so there isn’t much of a workload in the first place.
- vetinari 6y agoCrypto used by IPSec (aes, sha) is often accelerated by hardware - and the above mentioned Ubiquiti has hardware for that. Chacha/Poly used by Wireguard are not.
- 10000truths 6y agoThere’s a benchmark done with the EdgeRouter that shows that Wireguard’s throughput exceeds that of hardware accelerated AES + IPSec: https://an.undulating.space/post/181227-er_alternate_firmware_vpn_benchmarks/ https://an.undulating.space/post/181227-er_alternate_firmwar... Of course, benchmarks from random strangers are not gospel, and the results aren’t particularly damning. But even then, you’re assuming that you have the luxury of running on a chip that comes with a hardware crypto engine. Good luck trying to get AES encryption/decryption speeds at anywhere near line rate with a Raspberry Pi or a run-of-the-mill router.
- fulafel 6y agoIPsec is pretty light.
- sgt 6y agoDoesn't feel light to setup if you're trying to get a tunnel working between different providers. We had a strange dead peer issue between Fortigate and Mikrotik and could never figure it out as it happened so rarely. All phase 1 and phase 2 settings were identical. I can imagine that happens elsewhere too.
- blankusername 6y agoTry enabling Dead Peer Detection (DPD).
- blibble 6y agoeverything's a lot easier if you can do routing on the router
- ghostpepper 6y agoThere are also benefits to running your VPN endpoint on your network gateway - otherwise it can be difficult to configure routing tables to allow a user connecting from outside the network to access both internal and Internet IPs from the tunnel endpoint.