4 ms·
Been using tinc for god knows how long... Perhaps 20 years? It's been fantastic. I really don't know why people are wax-lyrical about wireguard. tinc was doing
by buserror 3y ago
Been using tinc for god knows how long... Perhaps 20 years? It's been fantastic. I really don't know why people are wax-lyrical about wireguard. tinc was doing it 20 years ago. UDP? yeah. encryption, mesh, proxy ARP you name it. I've had countless install and it's been the best VPN.
You even get a 'dot' graph of your current network status if you want to. When 'git' was invented, I put my /etc/tinc/*/ into git with the public keys, and installing a new host to the mesh is one 'git clone' away.
Most underrated open source software ever.
- INTPenis 3y agoSo what exactly does mesh VPN mean in this context? Because my need is to ensure that three portable devices (2 laptops, 1 android phone) always have access to the same private LAN and any services hosted by the devices on that LAN. Today I use a hub-and-spoke design with wireguard to achieve this, because I never know where these devices will be so I can't guarantee that I can forward ports to them through a firewall. Does tinc solve that port forwarding problem? I've read the intro in the manual but it only says tinc is a regular VPN.
- detaro 3y ago"Mesh VPN" means that if two devices want to communicate, it will attempt to establish a direct VPN connection between them. E.g. if you have a central server X and 3 "mobile" devices A, B and C, it's enough that ABC can talk to X, they will automatically learn about each other and when e.g. A wants to talk to B it will attempt to establish a direct tunnel between them, coordinating through X, including attempting to punch holes through NAT if needed. If that fails, it falls back to sending traffic through X. (And X could be more than one device too)
- dspillett 3y ago> Does tinc solve that port forwarding problem? From the features list: “Regardless of how you set up the tinc daemons to connect to each other, VPN traffic is always (if possible) sent directly to the destination, without going through intermediate hops.” and “As long as one node in the VPN allows incoming connections on a public IP address (even if it is a dynamic IP address), tinc will be able to do NAT traversal, allowing direct communication between peers.” So yes, it gets around that problem if you have at least one publicly connectable node. How it does this if that node doesn't have a fixed address I've not looked into. Also there are no doubt NAT arrangements that it can't punch through meaning it'll have to fall-back to something akin to your hub model with nodes affected by such NAT talking to each other through another node.
- blueflow 3y ago> Does tinc solve that port forwarding problem? Yes. I use it in production for that exact purpose. It only requires that one node is reachable via public IP address. An advantage that tinc has over wireguard is that it can do local discovery and direct communication if your devices happen to be in the same local network.
- INTPenis 3y agoSo it's no different from the setup I have today with a hub VPS then. Since my portable devices are always on the move, I must have a VPS to remain publicly accessible. Just like tinc.
- admax88qqq 3y agoIt's different in that two portable devices can negotiate a direct connection without having to route all traffic through your VPS. The VPS is still used as a central discovery location, but remote devices can learn about each other and talk directly to eachother.
- api 3y agoHN has extreme recency bias. I've been on here forever and things definitely get reinvented over and over again, and if it wasn't built in the last six months it's not cool.
- goodpoint 3y agoYou really struck a nerve there.
- nvy 3y ago>if it wasn't built in the last six months it's not cool. I feel like the perennial posts about lisp pretty handily demonstrate this to be false.
- baq 3y agoLisp is old enough that only wizards still use it, basically. Cool kids talk about lisp but actually host react on kubernetes and think it’s a good thing. We poor folks in between just chug along with our bare metal esxis and a master-slave replicated Postgres because it gets the job done, not despite it.
- nvy 3y agoI'm neither cool nor a wizard but I still wrote my algorithmic trading bot in common lisp. Also a Todo list web app.
- vidarh 3y agoI'll add peervpn and n2n as other simple options for people to consider, depending tradeoffs. I now mostly use Wireguard, but mainly of the Linux kernel driver.
- generalizations 3y agoThe draw of wireguard, at least for me, is the performance. Otherwise I’d be all in on tinc or zerotier.
- webstrand 3y agoThe draw of wireguard, for me, is that I can build it into my kernel. No weird issues starting it at boot, no missing libraries, etc.
- LinuxBender 3y agoI am kindof curious if Tinc could leverage Wireguard for the encryption. Everything else is in user-space so I think it should just be wg vs tun and a config option and do all the dynamic mesh routing on top of wg, but it would be nice if the maintainer could chime in.
- rkeene2 3y agoI (not a tinc maintainer, but a tinc contributor) have replied to this in the past [0]. Summary: it's not really possible without giving up some flexibility. [0] https://news.ycombinator.com/item?id=19304624 https://news.ycombinator.com/item?id=19304624
- LinuxBender 3y agoMakes sense. Not sure how I missed your comment in the past as I've always been curious if it could be done. Thankyou for answering that. I'm fine with Tinc's performance for my use cases.
- JeremyNT 3y agoI used and still really adore tinc, it's been a joy to use. I will say however that development appears to have fizzled out. I was really looking forward to some of the changes in 1.1, but it's been in pre-release for years now and doesn't seem like it's closer to being officially released. I've largely replaced tinc with Nebula [0], but I still think fondly of it. [0] https://github.com/slackhq/nebula https://github.com/slackhq/nebula
- FL410 3y agoSame, Nebula (I prefer Defined though) works great. Rock solid.