WireGuard

cjk, German
@cjk@chaos.social avatar

Just set up for company VPN, to replace OpenVPN 🥳

cjk,
@cjk@chaos.social avatar

@clarity We only have Linux clients, and I plan to distribute the config & keys via ansible. Every user has to bring in their device either way, because of the upgrade to 24.04

clarity,
@clarity@chaos.social avatar

@cjk ah for sure, thats a no-brainer. I also need to support Windows which makes to 1000x trickier...

tara,
@tara@hachyderm.io avatar

An excellent solution from @solene 👇 to protect tunnels on from attacks.

Have a closer look at the example about rdomain 0 and rdomain 1

https://dataswamp.org/~solene/2021-10-09-openbsd-wireguard-exit.html

lme, German
@lme@bsd.cafe avatar

Help needed.
I set up on according to @stefano's excellent journal entry at https://freebsdfoundation.org/our-work/journal/browser-based-edition/make-your-own-vpn-freebsd-wireguard-ipv6-and-ad-blocking-included/
While the wireguard connection between my clients (Android and Windows) is established, it is unusable slow. See screenshot.
Speedtest shows latency between 2 and 21 seconds. The server is hosted at @netcup, and both the connection there and my client's connection is of course much faster.
I tinkered with MTU on both server and client but no luck, either.

feld,
@feld@bikeshed.party avatar

@lme @stefano @netcup UDP getting dropped due to too small buffer sizes? Check for queue drops in sysctl. If it's nonzero that's probably an issue

mikael,
@mikael@hachyderm.io avatar

does it right: I configured hosted on my for my and my laptops, and it supports and out of the box without issues.

https://oxcrag.net/blog/2024/04/14/Connecting-to-Home-From-Abroad.html

mikael,
@mikael@hachyderm.io avatar

@vwbusguy sounds really good! I’ll definitely keep this in mind.

vwbusguy,
@vwbusguy@mastodon.online avatar
jbzfn,
@jbzfn@mastodon.social avatar

🎉 NetBSD 10.0 Released With Much Improved Hardware Support & Faster Performance | Phoronix

10 provides support, support for many newer platforms including for and newer boards, a new Intel Ethernet drive, support for Realtek 2.5GbE network adapters, performance improvements, automatic swap encryption, and an enormous amount of other hardware support improvements that accumulated over the past 4+ years 」

https://www.phoronix.com/news/NetBSD-10.0-Released

leetNightshade,
@leetNightshade@mastodon.social avatar

I had a docker ...VPN setup... w/ #wireguard working for a while, but no matter which image I used for the network bridge the wireguard part connects, but stopped working. Then I switched to OpenVPN, which is sadly a lot slower, but my 2 month broken setup started working!

Doomed_Daniel,
@Doomed_Daniel@mastodon.gamedev.place avatar

@leetNightshade
maybe that is because OpenVPN uses TUN, and WireGuard doesn't.
Haven't looked at the details (and docker is a plague :-p) but "glueTun" suggests that it does something TUN specific

leetNightshade,
@leetNightshade@mastodon.social avatar

@Doomed_Daniel You mean in terms of speed? I heard, I just don't have an idea of what TUN is yet. Oh user space instead of kernel space, makes sense!

I'm just disappointed Wireguard randomly broke out of the blue with no changes on my end as far as I can tell; many other docker VPN people affected by this across different images from what I'm reading.

I'm just sad while I got my setup working, it's not running the way "it's supposed to." 😅

aslmx,
@aslmx@chaos.social avatar

Am I doing something wrong or why does everyone hype so much? I don't think it is easy to setup. Maybe I a missing the go-to simple tutorial. All the tutorials I found don't work or are overly complicated.
I just want to try whether wireguard might be better than ssh-tunnels.

Shouldn't be too hard to setup wireguard on a blank ubuntu 22.04 server? Should it?
Also: the wg android app seems to just not connect and not even give a status?!?
Why does it say it is connected but its not?

danielsiepmann,

@aslmx My fritzbox offers it and I disables it after first try and stick to IPSec, because it just works.

I heard it is smaller, more secure and you can use QR code and less data to set it up. But that doesn't help if it doesn't work...

scudderfish,
@scudderfish@ohai.social avatar

and are ace! With a Gl-iNet AR-750S I'm connecting to any rando internet connection and appearing the rest of the world as if I'm sat on my sofa*

*I am, I'm testing it in prep for holiday by tethering my mobile over USB onto the giffgaff network; but there is no hint of the mobile network in the traceroute

peturdainn,
@peturdainn@mastodon.social avatar

@scudderfish indeed! I have the side switch set to enable/disable VPN so that I can first connect without VPN, enter whatever is needed on the captive portal of the hotel, then flick the switch so I don't even need to open the admin page again

bram,
@bram@gamedev.lgbt avatar

im in a public library, and i think they throttled my wifi, because Apparently, you're not allowed to push Gigabytes worth of data over your own connection :(

bram,
@bram@gamedev.lgbt avatar

okay, as it turns out:

Gitea behind Nginx as a reverse proxy, or god forgive me, multiple reverse proxies, behaves differently.

you need to make sure that Nginx allows for the payload to be big enough to send the data, makes sense. i thought git lfs worked over ssh as well, turns out that part goes over http :/

bobmagicii,
@bobmagicii@phpc.social avatar

@bram just rigged all this gitea up as well, but with apache instead. hopefully i remember you discovered this if i start running into weird post limit glitches.

cybersmog,
@cybersmog@phpc.social avatar

Versuche gerade, zu meiner FRITZ!Box einzurichten. Der WireGuard Client am Mac und auch am iPhone sagen jeweils, dass die Verbindung aktiv ist aber dann funktionieren jeweils keinerlei ausgehende Verbindungen mehr. Währenddessen wird in der FRITZ!Box auch nicht angezeigt, dass eine VPN Verbindung aktiv wäre.
Wo fange ich da an zu suchen?

kidney,

@cybersmog Gehen Pakete raus? Kommen Pakete an? etc.
AVM hat Paketmitschnitt integriert unter: fritz.box/support.lua

cybersmog,
@cybersmog@phpc.social avatar

@kidney Danke für den Tipp, das kannte ich noch nicht! Werde ich testen, aber leider nicht mehr heute.

kazaii,
@kazaii@noc.social avatar
kazaii,
@kazaii@noc.social avatar

@joy Thanks for the reply, Joy. The reason I tagged @zerotier is because it's hard to mention mesh VPNs without mentioning the notable incumbent in the industry.

I didn't mean to imply that ZeroTier uses WG or Noise protocol.

joy,
@joy@mastodon.social avatar

@kazaii @zerotier
Aww, thanks. I appreciate the clarification.

defguard,

The most beautiful Desktop Client has arrived in time for Saint Nicholas' Day!

Check it out and lots of new features in the 0.8 of defguard and platform.

More at: https://github.com/DefGuard/defguard

Full release notes: https://github.com/DefGuard/defguard/releases

zeroiee,
@zeroiee@techhub.social avatar

If you've followed our recent posts, you already know that we gave Shorewall a try to tidy up our VPN firewall rules and gain full overview about our configuration. Our migration to Shorewall has been successful and we'd like to share some insights in our configuration:

"Keeping the Wireguard VPN firewall clear with Shorewall" - https://blog.zero-iee.com/en/posts/vpn-firewall-shorewall/

Shorewall by Tom Eastep is just perfect for small to mid size firewall deployments that are mostly static and not too complex. One of our developers uses OpnSense and PfSense for more complex scenarios in his private projects.

Which firewall / configuration tool do you use and why?

#shorewall #firewall #wireguard #vpn #teamzero #zeroiee #blog #techblog #linux #debian

nextcloud,
@nextcloud@mastodon.xyz avatar

Nextcloud + Tailscale = 🥰

👩🏽‍💻 Interested in accessing your Nextcloud from anywhere, on any device, without being exposed to the public internet?

🔐 Increase your security and keep your users and data safe!

🕸️ @tailscale allows you to create a mesh network on your mobile, desktop, and servers - all protected by VPN and as user friendly as it gets.

Alex shows us how in this speedy less-than-10-minutes tutorial 🦾

https://youtu.be/sPdvyR7bLqI

zeroiee,
@zeroiee@techhub.social avatar

We're currently evaluating Shorewall 1 as a more sophisticated Firewall / iptables configuration tool.

Configuring iptables manually 2 works, but can get messy and thus is error prone. For our VPN server with its many customer VPNs, we are looking for a clearer solution that can be easily configured via configuration files. One of our developers has already used Shorewall and is impressed by the software. It was therefore a natural decision to take a look at it.

Initial experiments have gone well!

#wireguard #shorewall #foss #server #vpn #firewall

  • All
  • Subscribed
  • Moderated
  • Favorites
  • wireguard
  • kavyap
  • thenastyranch
  • GTA5RPClips
  • tester
  • InstantRegret
  • DreamBathrooms
  • ngwrru68w68
  • magazineikmin
  • everett
  • Youngstown
  • mdbf
  • slotface
  • rosin
  • cisconetworking
  • JUstTest
  • khanakhh
  • normalnudes
  • osvaldo12
  • tacticalgear
  • anitta
  • Durango
  • ethstaker
  • modclub
  • Leos
  • provamag3
  • cubers
  • megavids
  • lostlight
  • All magazines