3 ms·
Tinc is difficult to setup and uses a custom protocol which may not be thoroughly vetted.
by codexon 12y ago
Tinc is difficult to setup and uses a custom protocol which may not be thoroughly vetted.
- p8952 12y agoI can't comment on the protocol, but tinc is very easy to set up. You just need to generate pub/priv keys and then add your routes in /etc/tinc/vpn/tinc-up. We're running it in production with ~30 nodes worldwide and using puppet to dynamically add/remove nodes on the fly. What is great is it's able to re-route around any peering issues suffered by local ISPs. Say you have three nodes in the US, UK, JP and your JP ISP loses routing to your US ISP. If both can still route to the UK then tinc will automatically keep traffic flowing.
- codexon 12y agoOf course if you manage to get a template setup it is easy. But now that I haven't setup tinc for awhile I have no idea how to do it again and the examples are horrible. Every node needs to have a copy of every other node's configuration file and it is annoying to add a file to N servers when you are adding the N+1th server.
- kh_hk 12y agoFor the setup I will say it is on the same level of difficulty as it would be to setup iptables and routes manually. Yes, tinc does not abstract any of these things from you. But if you know what you are doing (not saying I always know what I am doing) it can be a powerful tool to build the exact network you want without any provider lock-in. Now, I must agree on that, it might not be a friendly solution for dead easy routing to an exit node as a proxy with dns-tunneling built in. I just wanted to know why tinc does not get enough love, and you answered accordingly. But if you are building a serious network I do think tinc hits the sweet spot between being easy and allowing for any network you can think of without being tied to a particular server provider that might offer private IPs. As for the configuration I use git, which makes it super easy to setup the N+1th server. None of the private keys are committed to the repo, of course. My infrastructure is not that big so I am still doing some things by hand, but it should be easy to automate some parts by using git hooks + puppet|ansible|chef. About the protocol I do not understand why it would be a problem, other than not being ssh or the possibility of being filtered over the network. Doesn't most VPN solutions have their own protocol?