9 ms·
VPNCloud: Open-source peer-to-peer VPN written in rust
- jsilence 6y agoGreat to have more Open Source options in this software segment! Some sort of configuration interface would be nice. Wondering whether there is business opportunity in offering beacons as a service.
- njacobs5074 6y agoIt is great, I totally agree. The fact that it's OSS is awesome even if just from a learning standpoint. Regarding your latter thought, it seems to me that if I'm running a service like this on my servers, I probably don't want to connect to unknown/untrusted peers. Open to use cases where that make sense, though. [Edit] Just found the documentation on beacons that explains the trust model. So sounds like there is merit to your idea :)
- ranguna 6y agoThe problem with these kind of things is that now I need to ask around some IPs to connect to, as I see there's no automatic peer discovery. Sounds awesome nonetheless.
- Galanwe 6y agoWhat would automatic discovery even do? Add you to some worldwide IP overlay on top of internet? What would be the use of that? I did had a use case in the past for peer to peer VPNs, mainly because in the 2000s, most hosting companies would only provide you crappy VMs with a single public interface. If you needed some control over the network, subnets, etc, then you would need some kind of overlay. This, added with the fact that you would typically have dozens of heterogeneous boxes at different providers, made maintaining a traditional host to host ipsec full mesh nightmarish. I used n2n (a peer to peer VPN) to reconciliate these various internet facing boxes in a single private IP network. Nowadays, cloud providers are much more evolved, and offer you full configuration of multiple public/private interfaces, so recreating subnets over public facing boxes is not really a concern, which is why IMHO peer to peer VPNs do not serve much purpose in 2021.
- mynameisvlad 6y agohttps://tailscale.com https://tailscale.com for instance will show all the peers on the network in the menu bar of the app.
- dividuum 6y ago> [..] as I see there's no automatic peer discovery. Actually there is, but it's not immediately obvious: https://vpncloud.ddswd.de/docs/beacons/ https://vpncloud.ddswd.de/docs/beacons/ It's seems really simple to use as well: The linked implementation in PHP on https://vpncloud.ddswd.de/docs/beacons/php-service/ https://vpncloud.ddswd.de/docs/beacons/php-service/ is only around 80 lines of code and extremely simple and due to the beacon design doesn't compromise the security of your setup if anything goes wrong.
- skanga 6y agoWhat platforms does it support? Linux, Mac, Windows?
- janandonly 6y agoDifferent packages for Linux available... No Mac or Windows support ad far as I can see :(
- GekkePrutser 6y agoNo mobile ones either :(
- guerby 6y agoFrom github README: "Help with other platforms: If you are a Rust developer with experience on Windows or MacOS your help on porting VpnCloud to those platforms is very welcome."
- janandonly 6y agoBasically a re-invention of the early 2000's Hamachi app? I think I might have used Hamachi once or twice to play a network version of Age of Empires over_the_internet long before this was a standard function in games :) I just Ducked for Hamachi VPN and it still exists, see https://vpn.net https://vpn.net
- ivanstegic 6y agoLogMeIn owned
- someperson 6y agoIs that a bad thing?
- hedora 6y agoYeah; they slowly de-feature and increase the price of everything they acquire.
- Galanwe 6y agoI believe Hamachi was mainly a level 2 VPN, perfect for transporting IPX, which was really mainstream for LAN games of the 90s. This seems to handle layer 2/3 since they mention support for TUN/Tap interfaces, but I guess 99% of people will just create IP tunnels, layer 2 is not the hot thing anymore. Also, Hamachi was not decentralized from what I remember. What is presented here reminds me a lot of n2n.
- GekkePrutser 6y agoSome other apps in this category can also do layer 2, like tinc. It does layer 3 by default but you can switch it.
- Haemm0r 6y agoWhat would you use for layer 2 transport today(in spefific for playing ild games)?
- unixhero 6y agoCool! Does this bring any benefits that WireGuard does not?
- robert_foss 6y agoYes, wireguard is a point-to-point transport layer. VPNCloud includes a management layer about that. And for example deals with NATs, network management etc.
- senorsmile 6y agoI have heard this before (that wireguard does p2p), but have yet to see any examples of how to run this. Is it theoretical or just not fully implemented...?
- senorsmile 6y agoI found this: https://github.com/gawen/wirehub https://github.com/gawen/wirehub but it doesn't look like it's still active.
- deleted 6y ago[deleted]
- ohmyblock 6y agoI am a happy user of https://tailscale.com https://tailscale.com which I think solves the same problem
- meibo 6y agoWhy do they not support email + password signups? I'm not super averse to Google SSO but I would not tie my critical infrastructure to it in any way.
- spockz 6y agoThey support GSuite and azure AD it appears. So it is not limited to just gmail. When you pay for GSuite I think it will be a bit less risky than when using their free gmail offering. Regardless, it would have been nice if you could use your own identity provider.
- _joel 6y agoThis is the reason why I've not used them, it's an instant turn-off needing to use Google SSO
- GekkePrutser 6y agoYes I looked at that one also but it was an insta-dealbreaker for the same reason. There's many options around, luckily. So no need to go for something as compromised as this. Another dealbreaker for me is hosted configuration and access management. I want to be the only one managing it.
- jsilence 6y agoTailscale is not Open Source, nor?
- huzaif 6y agoThey are: https://github.com/tailscale/tailscale https://github.com/tailscale/tailscale A fair bit of the client code is also on the repo. Things like role based access control that require a backing store on tailscale side aren't open.
- kenmacd 6y agoAny advantages to this over https://www.zerotier.com/ https://www.zerotier.com/? Being p2p and using one PSK seems to make firewalling more difficult. ZeroTier's 'capability-based + tagging' rule engine is pretty amazing in that I can easily allow just one peer to connect on a port.
- Anunayj 6y agozerotier runs into problems when two NATs are involved, this claims to not have any problems with that?
- dividuum 6y agoOnce you have two NATs, you can either try to punch holes (ZeroTier tries that), use UPnP (ZeroTier does - see below) or relay traffic using dedicated machines (ZeroTier does that as fallback). I successfully used ZeroTier to connect multiple devices behind NATs. VPNCloud seems to only do UDP hole punching and doesn't have the ability to relay via a third party. At least in theory, ZeroTier should handle cases that VPNCloud doesn't.
- Anunayj 6y agoI think zerotier does UPnP too (read somewhere), though I could not get zerotier to work reliably with 2 NATs. I'll try this and tell if I see any success with this.
- dividuum 6y ago> I think zerotier does UPnP too I think you're correct. Thanks. My information was from an old blog post from 2014 [1] but they seems to have added support since then: https://github.com/zerotier/ZeroTierOne/commit/bf193dd3 https://github.com/zerotier/ZeroTierOne/commit/bf193dd3. Edited my post. [1] https://www.zerotier.com/2014/08/25/the-state-of-nat-traversal/#:~:text=UPnP https://www.zerotier.com/2014/08/25/the-state-of-nat-travers...
- kenmacd 6y ago
- sneak 6y agohttps://github.com/dswd/vpncloud/blob/master/src/crypto/core.rs https://github.com/dswd/vpncloud/blob/master/src/crypto/core... https://github.com/dswd/vpncloud/blob/master/src/crypto/common.rs https://github.com/dswd/vpncloud/blob/master/src/crypto/comm... This implements a novel cryptosystem. Default to not trusting novel cryptosystems until you have sufficient reason to begin believing that they are trustworthy.
- nh2 6y agoThis looks like the much older Tinc VPN (https://www.tinc-vpn.org https://www.tinc-vpn.org), but in Rust. It would be great to have a comparison between the two. I've been using Tinc for many years; it's been working quite well, but about once a year I get a segfault (and then it gets restarted). It might be appealing to reduce the chances of that via Rust. One commonality I found is that both are single-threaded. I believe I've also heard of the idea of a future version of Tinc potentially using Wireguard as the underlying transport, and building its meshing on top of it. I wonder if that's on the table for VPNCloud as well.
- CloselyChunky 6y agoIMO tinc is really awesome. I've been using it for years to connect my servers, laptops and desktops into a VPN. Including my RPI (running PiHole in my LAN) into the tinc VPN gave me an easy way to access my home network from anywhere in the world. One of my dedicated servers would automatically take care of routing the traffic and I can just `ssh foo@10.0.0.42` to connect to the RPI and be inside my home network. IIRC tinc implements some tricks like TCP/UDP hole punching. So best case I end up with an actual p2p connection between my remote device and home network after connecting via tinc.
- linsomniac 6y agoIIRC ZeroTier borrowed the NAT hole punching code.
- rkeene2 6y agoTinc is even more awesome than that -- if you are using it on the same LAN as other nodes on the VPN it will try to make sure traffic between those nodes stays on the same LAN (it has a special broadcast beacon it sends out to find these). It ALSO supports arbitrary commands for connecting, like ProxyCommand in OpenSSH so you can proxy through any kind of thing manually if you need to. Tinc is really awesome !
- GekkePrutser 6y agoYes I use tinc too. The only problem I have with it is that it's not very performant. For example video streaming through it always causes hiccups. There's other options I've looked at too: Zerotier (discounted it because it uses cloud-based configuration that's hard to self-host). And Nebula. The latter I still have to try. I have an added requirement of needing a mobile client too (which tinc now has) so I don't think VPNCloud will work for me :(
- linsomniac 6y agoIt feels recently like we're living in a bit of a VPN renaissance. Wireguard, OpenVPN Cloud, ZeroTier, Tailscale, Pritunl, VPNCloud, Nebula. I've been playing with ZeroTier and liking it quite a lot.
- deleted 6y ago[deleted]
- lwhsiao 6y agoNice to see another one of these tools. Tonari also recently released innernet in this space, written in Rust as well: https://blog.tonari.no/introducing-innernet https://blog.tonari.no/introducing-innernet
- canada_dry 6y agoThis looks great! The "CIDR" peer grouping is bloody brilliant.
- aloknnikhil 6y agoThere was some discussion on this here: https://news.ycombinator.com/item?id=26628285 https://news.ycombinator.com/item?id=26628285