ZeroTier - Simple Software Defined Networking
zerotier.com
zerotier.com
I'm an engineer for one of the projects over at ZeroTier. It's neat to see this pop up on HN. If anyone has any questions about our technology or services, let us know. We'll keep an eye on this thread!
Edit: I followed this blog post: https://www.zerotier.com/blog/?p=176
Have you tried turning it off and on again? ;) (restart zerotier-one)
I added the node id manually in the panel and the nodes saw each other within seconds of joining.
I was pleasantly surprised that I can just create a network with ipv6 and broadcast enabled and things like mdns/avahi "just work". Being able to enable "any protocol" rather than just ip4/6 is great too. In practice you get private encrypted network with non-colliding addressing, route optimizing (two hosts behind a nat will talk directly), mdns working out of the box. What else would you ever need? Android app is a cherry on top.
iOS app is shipping next week. Approved by Apple, just waiting on a DUNS number (sigh).
Edit: this is super exciting, btw. This will finally let me run some of my services exclusively on my ZT network instead of publicly.
It's approved. We're just waiting on a DUNS number for ZeroTier, Inc. :P
We also have experimented internally with network containers for iOS and Android apps, but that's a whole different use case:
https://www.zerotier.com/product-netcon.shtml
Network Containers is our experimental tech for allowing apps to join virtual networks with no kernel/OS involvement via a private mini IP stack. You can do P2P networking between instances of your app, other apps, servers, and anything else ("connect all the things") using standard network code, Posix network APIs, and familiar protocols like HTTP.
I'd be interested to know if it uses something like STUN/ICE to punch through two different NATs... don't have two NATs to try at the moment.
Also, one big concern we have is using the standard/default discovery servers to run our network. Is there any guidance on self-hosting the discovery servers ourselves?
Lastly, can ZT assign IPs for us automatically using some kind of DHCP? Is there any documentation about how it works in case of network partitions?
Separate from this you also have to option of running your own network manager. This will allow you to create and manage your own virtual networks, with your own GUI, billing etcetera. The Zerotier binary can be compiled with a special option to extend the build-in REST API for that.
See: https://github.com/zerotier/ZeroTierOne/tree/master/service
Turning off compression: noted. We also might permit a no-encryption mode for trusted backplane networks for data center SDN use in the future.
There's no federation for the root servers yet. We have numerous ideas on how to implement this but it's not a current priority. It has to be done with care to avoid sacrificing speed, security, or ability to upgrade.
You can read some of the reasoning behind ZeroTier's design here:
http://adamierymenko.com/decentralization-i-want-to-believe/
TL;DR: we chose a design that delivers instant-on zero-configuration operation, security, and very fast (<5s) connection setup between any two devices on Earth at the expense of adding a small amount of centralization to the system. We also avoided certain technologies like DHTs because we wanted the endpoint software to be small enough to run on small embedded devices with limited bandwidth, CPU, and memory and on mobile phones with bandwidth and power limits. Our root server based architecture achieves all this.
The root servers are two-times redundant. There are two root servers and each of these is geo-distributed across six nodes. These are also spread across four cloud hosting ISPs. Any combination of up to 11 roots total can fail without the system being significantly impacted since each root individually has enough power to carry the whole net. All roots are secured with physical two-factor authentication and only permit ssh access from a set of secret gateway IPs (also secured with 2fa).
Root locations are: San Francisco, New York, Dallas, Toronto, Amsterdam, Paris, Franfurt, Johannesburg (SA), Sao Paolo (BR), Tokyo, Sydney, and Singapore. Almost everyone on Earth gets <100ms ping to at least one.
BUT I really do not believe that this is the way a rpm package should look like. I know that it is not easy, especially for smaller companies, to provide packages for all the platforms. In this state, it would be much better to just provide .tar.gz archive. Its just my opinion ;)
We're working on better RPMs and DEBs and on getting into Debian itself and hopefully EPEL/Fedora. Right now the packages are minimal and not entirely correct (though they do work).
We offer a similar service to ZeroTier, but based on SoftEther. Needless to say, we LOVE ZeroTier, they've got a brilliant product. Keep up the good work!
Also keep in mind that we only use that range on our test "Earth" network. You can use any IP range you want on your own networks. ZeroTier is layer 2 (Ethernet).
BTW, it's not uncommon for cell networks and ISPs to use DOD IPs for hidden layers, leading to some interesting outbreaks of paranoia when people spot them in a traceroute: "why is all my traffic being routed through the DOD?!?!?!" (No, it's not.)
EDIT: I'd like to mention an interesting feature. If you run two hosts that are also connected in another way, for example on a LAN, or using private networking from your cloud provider, ZT will automagically find and use the fastest route for host to host traffic.
Was looking for such a things for quite some time
What are these use-cases all about? Not really getting the point of this right now.. curious since all my friends, family and servers are connected to the Internet already just fine, as I suspect were yours.
I have some servers in the cloud and some mac minis hosted at home. I'm using an ssh tunnel to connect them, but it's far from ideal, and not stable somehow. (tried ssh and autossh).
For a new project I'm using 8 raspberry pi's, which are set up in a remote location. They have static IP addresses, and I to be able to access them. Right now it's done by portmapping. If anything happens to te network config over there, I'll have to fix them.
With zerotier I can simply put them on dhcp, and connect them all to a virtual lan.