3 ms·
This looks really nice. I have set up something similar just recently with an OPNSense box running DNS, the WireGuard instance and getting a wildcard Let's Enc
by paffdragon 1y ago
This looks really nice.
I have set up something similar just recently with an OPNSense box running DNS, the WireGuard instance and getting a wildcard Let's Encrypt cert that it pushes to my Synology reverse proxy (Nginx). So from my clients I can enable the WG tunnel only on my internal IP range, setting the internal DNS, so I don't have to have my public cert pointing to my IP. It works once setup for my home net. But for multi-site, Pangolin looks very polished and probably easier to set up.
Is Newt a custom implementation of a WireGuard server? Has it been security audited in some way?
- paffdragon 1y agoEDIT: Sorry, I misread, Newt is the WireGuard client and is based on wireguard-go if I'm correct.
- fossorialowen 1y agoYep thats correct. All based on wireguard-go. It is growing in what it can do now but at its core its just a Wireguard wrapper that coordinates with Pangolin to get the tunnel up. It also runs in netstack user space so it does not need kernel permissions to open a port and it's only egress is proxied out with TCP/UDP reverse proxies built in to access what is needed on the network.