5 ms·
By far the best solution I've seen is wireguard. Easy to set up, super fast and secure. My little swarm of VMs, containers, and raspberry Pis is all meshed toge
by pinusc 6y ago
By far the best solution I've seen is wireguard. Easy to set up, super fast and secure. My little swarm of VMs, containers, and raspberry Pis is all meshed together by wireguard.
The only "hard" thing is that wireguard doesn't port forward automatically, you have to add an iptables rule. Took me 10 minutes to figure out how and now whenever I add a service I simply copypaste previous rules and add relevant ports...
Edit: plus once you set it up you also get to use it as a VPN for your devices.
- anderspitman 6y agoSeveral of the tools on the list are based on WireGuard, and I think we'll continue to see other useful abstractions over it in the future. It's an excellent technology. The main reason to use something other than WireGuard today is that it requires root to run, in order to change the network configuration, so you can't use it to tunnel out on machines where you don't have elevated privileges.
- sandos 6y agoMy workplace always had web-proxies and openvpn used to allow me to login at home to admin stuff if needed. Now I imagined wireguard would be perfect for this, but alas its only UDP which will never work on this network, sadly. Also my cell proider somehow makes wireguard impossible, not sure if they block UDP too. I was also sad when zerotier wouldn't work through the proxies. I know, I know, busting proxies is wrong. But for me using it between linux boxes on permanent connections works fine, but its a very small portion of what I want from my VPN. In the end it turns out Home Assistant on a dyndns HTTPs site solves most of my access problems. Even ssh can be solved using it!