Wireguard VPN: Typical Setup (2017)
ckn.io
ckn.io
it almost feels too easy compared to the openvpn monstrosity.
now that they have an iphone app (in beta) I switched to using it everywhere and not looking back.
And this morning, I connected to the bus WiFi, I turned on WireGuard, and kept a constant connection throughout my commute to work. It just works so well.
I could never do that with my OpenVPN connections.
after an experience like this you look back and wander how you ever put up with the previous solution
You might be able to make several of these connections between 2 machines and trunk/bond them on each side into a combined interface for even more throughput. 10Gbe and 40Gb fiber cards are getting pretty cheap.
The encryption is parallelised, Jason Donenfield talks about how the parallelism is designed in most of his talks about WireGuard.
Effectively the problem is that network processing is done using "flows" and generally you want to pin a single flow to a single CPU -- but that would result in bad performance (especially if related packets were encrypted on separate CPUs). So instead, WireGuard pretends to support hardware packet offloading -- so the rest of the net infrastructure figures out what packets are related and gives WireGuard a coalesced packet which can then be split and encrypted in one go.
If I want ssh-alike I'll harden my ssh and PAM configuration and use ssh (+ tunneling/forwarding and socks5).
It's already absolutely fantastic compared to any other solution I can think of (_especially_ OpenVPN, which requires generating a bunch of x.509 certs).
This article has a ton of steps which aren't even WireGuard specific like server firewall rules.
The actual configuration of WG is basically 'generate a private and public key on server and client, stick it in a config file, run wg-quick up, done'.
I think I wasn't doing something right, though, since I was getting very weird errors that I wasn't able to google. Also I think my issue was like more with the macOS client rather than the server.
I think Wireguard is still at the same level that git was about 10 years ago: powerful, elegant, but absolutely not user-friendly. But nobody is claiming that it is (same with git).
I suspect in the next couple of years, you'll see an explosion of really nice tools to make this setup even easier than it is now.
Until then, I'll keep fiddling and try to get wireguard running on my macOS client/ubuntu server setup.
[Interface]
PrivateKey = redacted
Address = 10.100.0.3/24
[Peer]
PublicKey = redacted
AllowedIPs = 10.100.0.0/24
Endpoint = 18.xxx.xxx.xxx:51820
PersistentKeepalive = 25
and then doing sudo wg-quick up foo
You should see something like INFO: (utun2) 2018/12/16 18:43:24 Starting wireguard-go version 0.0.20181018
[+] Interface for foo is utun2
[#] wg setconf utun2 /dev/fd/63
[#] ifconfig utun2 inet 10.100.0.3/24 10.100.0.3 alias
[#] ifconfig utun2 up
[#] route -q -n add -inet 10.100.0.0/24 -interface utun2
[+] Backgrounding route monitor
That's assuming you have a matching server config set up on your Ubuntu...Yeah, the non-Linux clients are all a faff.
It's pretty user friendly on Linux. Everywhere else it's alpha level. IMO.
> It's already absolutely fantastic compared to any other solution...
I don’t think that this means there’s no room for improvement.
As someone else stated, the config process is pretty standard procedure so I guess there's not a lot of "improvements" one can do on that side :)
WireGuard could certainly present those options as a default and automatically do them, but that would be above and beyond what a tool usually does.
WireGuard works just fine like this.