3 ms·
It's worth noting that Tailscale runs WireGuard in userspace, which negates many (all?) of the performance benefits. I wonder if it will ever be possible for no
by anderspitman 4y ago
It's worth noting that Tailscale runs WireGuard in userspace, which negates many (all?) of the performance benefits. I wonder if it will ever be possible for nonroot users to create WireGuard devices. They're just so useful.
- rollcat 4y agoOut of curiosity, what kinds of performance benefits are kernelspace-exclusive, in terms of VPN apps? I've seen arguments go both ways for different applications, with full usermode TCP/IP stacks, unikernels, even running apps directly on the NIC (snabb switch); historically there were also efforts like khttpd that ultimately failed.
- anderspitman 4y agoI don't know much about what where specific gains come from. Generally avoiding copies and syscalls go a long way. I suspect in many cases WireGuard performance isn't going to be your bottleneck, but in those cases you're still reducing power consumption.