3 ms·
I found it too complex for a lay person. On a regular computer or server its not too bad. I can send someone a config file with the certs and keys already built
by discardedrefuse 4y ago
I found it too complex for a lay person. On a regular computer or server its not too bad. I can send someone a config file with the certs and keys already built in. That's easy enough. But on mobile it requires a back and forth exchange of keys over a different medium.
Compare that to ZeroTier where I can just tell someone, "install this app and punch in this Network ID". Also, ZT lets me control the entire network firewall from a centralized place. Where Nebula is doing it on a per-client basis and requires new certs if device groups change.
I don't want to talk up ZT too much though. Their self-hosted option is a joke. There is no webui. You have to do everything via the API...including the firewall rules; And you have to write those rules in the non-human readable format that their webui abstracts away. Worse still, their mobile apps won't work with the self-hosted option. I used them to get something up and running quickly, but I'll probably end up on Nebula anyways.
- api 4y ago> Their self-hosted option is a joke. There is no webui. There's a community developed one: https://github.com/key-networks/ztncui https://github.com/key-networks/ztncui
- discardedrefuse 4y agoI had looked at this. It doesn't seem like they've implemented anything to handle firewall rules. They may not even be able to, seeing as how that part of ZT is closed source. Also, this doesn't solve the problem with mobile apps, so the whole thing was a moot point for me.
- benoliver999 4y agoThe mobile app does work with the self hosted option, we use it at work.
- discardedrefuse 4y agoThe official ZT docs* say, "The mobile apps don't support custom roots." And I don't see any setting in the Android app to point it to any server. * https://docs.zerotier.com/self-hosting/introduction https://docs.zerotier.com/self-hosting/introduction
- benoliver999 4y agoAh, that's because we run a controller node not a root. So you just add an ID as normal. The software linked in the parent works with the mobile apps.