4 ms·
I've had wireguard in a container for a few years, and it's never failed me. I will say it took me a long time to get the firewall part of the configuration rig
by cyphax 1y ago
I've had wireguard in a container for a few years, and it's never failed me. I will say it took me a long time to get the firewall part of the configuration right but the configuration is otherwise simple. When I'm on the road I can access all the things I self host, which I don't have to expose anything of to the outside world.
I also really like using qr codes to transfer a configuration to a phone (mostly used by me once when I replaced my phone): https://www.cyberciti.biz/faq/how-to-generate-wireguard-qr-code-on-linux-for-mobile/ https://www.cyberciti.biz/faq/how-to-generate-wireguard-qr-c...
- jazzyjackson 1y agowhoa that's super useful. I've been trying to figure out what I'm going to do to let my family access my server. What client do you recommend on the phone end? Or does the phone support connecting to wireguard out of the box?
- cyphax 1y agoI use the Android app from Wireguard: https://play.google.com/store/apps/details?id=com.wireguard.android https://play.google.com/store/apps/details?id=com.wireguard.... It's pretty basic, but it lets me scan the generated qr codes, and it has an icon in the drawer which makes it easy to access.
- neurostimulant 1y agoRethink DNS on fdroid is great. Way better than the official wireguard android app: https://github.com/celzero/rethink-app https://github.com/celzero/rethink-app
- zuhsetaqi 1y agoThe best client is from WireGuard. It’s super efficient in my experience. It even supports on demand VPN where you can define network it should activate or deactivate the VPN.
- SyrupThinker 1y agoThe amount of people here just exposing their network to Tailscale, and recommending others to do the same, is surprising, to say the least. I've set up Wireguard on a VPS once six years ago, and nothing needed adjustment since. It is as easy as you make it out to be, and depending on the use case the firewall rules can also be simple. If I need to add a new device, which is probably a rarity for the average user, and once a year for me, it takes two minutes to edit two files and restart a service. I can see reasons why one would want to use Tailscale, especially in an organization. But just uncritically recommending it for home-lab like setups seems as harmful as pushing people to Cloudflare for everything.
- FrankPetrilli 1y agoInter-node mesh with raw Wireguard is an exercise in patience to say the least; I have a few different colo sites, my house, my phone, LTE/5G hotspots, raspberry pi projects in the field, etc that I want to fully connect together. Raw Wireguard is fine for a road warrior or site-to-site VPN setup as is common, but when you want multipoint peer-to-peer connections without routing through what might be a geographically distant point, magic DNS, etc, Tailscale really shines through. If you're paranoid, enable https://tailscale.com/kb/1226/tailnet-lock https://tailscale.com/kb/1226/tailnet-lock or run https://headscale.net/ https://headscale.net/ on your own as a control server.
- SyrupThinker 1y agoFor P2P I can totally see the advantage. Although at that point I'm sure you, and any similar user, would not actually rely on ad-hoc advice like in this thread, and instead just evaluate what is needed. As an aside, personally speaking, headscale solves basically none of my concerns associated with introducing more software, complexity and third parties (the maintainers) into my network setup. Less so because of paranoia towards the software/product itself, and more so because of the increased surface area to attack. But I also think that anyone actually bothering to set headscale up probably falls into the aforementioned group of people that actually thinks about their requirements.
- robertlagrant 1y ago