Setting up a home VPN server with WireGuard
mikkel.hoegh.org
mikkel.hoegh.org
https://github.com/subspacecloud/subspace
This is a tool that helps you generate and manage configurations for WireGuard, generate qr code for configuring mobile devices and it even integrates into SAML for authentication.
It's not as fancy as some other VPN management tools but this is an easy way to get WireGuard set up without too much messing with configs
Does it handle IP assignment/configuration as well?
You will also likely need to make some changes to your iptables and/or sysctl depending on your server config and firewall.
Nothing too shocking per se; you need to do all that with any other kind of VPN as well.
I wrote a little script that creates the configuration files, and shows a QR code in the terminal to easily add new clients.
The problem I ran into is dynamic IP allocation, without extra logging, or storing the client config files after they’ve been distributed. If I want to avoid assigning a used IP, I need to know what I’ve already given out.
I mocked up a few things then decided the perfect was becoming the enemy of the good. Since I’ll only ever have a few peers, I ultimately just decided randomize the 4th octet, each time I create a new client config. Obviously, this opens me up to a potential conflict in the future (prayers to St. YAGNI for benevolence).
I suppose I could/should be pre-generating all the configs, handing one out at random, then deleting it.
0: https://gist.github.com/Belphemur/b014a11f9ae6c20203276f214e...
1: https://gist.github.com/judge2020/e9631be086ea105005614c70a8...
https://github.com/place1/wireguard-access-server
It's mostly a hobby project but it'll run a userspace wireguard implementation (boringtun) and a webapp to configure it.
You can run it in docker
docker run \
-it \
--rm \
--name wg \
--cap-add NET_ADMIN \
--device /dev/net/tun:/dev/net/tun \
-p 8000:8000/tcp \
-p 51820:51820/udp \
place1/wireguard-access-server:0.0.5The project consists of a grand total of 7 commits, which were posted 6 months ago. Since then there's been no activity, and pull requests opened since May have seen no maintainer activity either.
The project seems to have stagnated but in its current state it's usable enough. I probably wouldn't expose the web application itself to the outside world anyway (I usually only expose applications to my home + VPN networks) so in the limited context that I use it it's fine.
If you want, you can also use it to generate configs and QR codes once, copy the server config to an independent server and then shut down the application. It doesn't do anything special to WireGuard itself, it just generates config files and QR codes and that's it.
Kind of sad to see such a simple but practical application fall into the abandon ware hole, but such is life when dealing with open source side projects from small companies.
I'd rather have a simple script and push updates to a "read-only" webapp.
This project isn't much more than a script to generate and manage configs with an optional layer of SAML accounts on top. Especially with WireGuard's simple configuration it doesn't need to do any more than that. There are no security parameters with unsafe defaults, complicated configuration processes, certificate generation and signing process that other VPN systems fall victim to. There's a 6 line config file containing a private key generated by the official WireGuard tool and that's it.
While I've always avoided many complicated openvpn config tools like the plague (that of pfsense for one), I think WireGuard is simple enough to be configured like this.
To be fair, IPSec tunneling is quite common (unsure if its the predominant mode) because tunneling makes routing easier. And for road warrior setups where the peer is often behind a NAT gateway, IPSec VPNs will also tend to use UDP. In such cases there's no advantage to IPSec.
Wireguard is very lean and simple.
can wireguard do tunnel state detection? Can i do a hub and spoke topology with wireguard? or auto-vpn?
ipsec is complex because it is mainly designed as a tunnel protocol with encryption. (site-to-site), compared to the "road warrior" setup wireguard seems more useful for.
* bind a tunnel to a certain interface/ip
* use same port for different tunnels (with same ip or separate iface/ip)
* specify a fixed peer ip/port (or network, interface to use)
* use tunnel in tunnel (with kernel implementation, unless you get creative)
your encapsulation argument still holds true however.
Blocking ICMP may result in black holed connections. I experienced this just like you with websites not working, and with ssh freezing when doing an ll in a directory with a large number of files, or even when starting mc. In my case, an upstream server was blocking ICMP for no good reason (there’s never a good reason to do it permanently, really).
Many types of ICMP messages can be very nasty. ICMP and ICMPv6 RFCs actually describe which messages are importatnt and should not be blocked in any networks, which are dangerous and should be restricted, and varieties between.
There’s also a more plug-n-play tool called Algo that is highly spoken of, which automates a lot of this: https://github.com/trailofbits/algo
That being said, I think Algo is often preferable to OpenVPN and IPSec, especially when supporting macOS/iOS clients.
https://help.ubnt.com/hc/en-us/articles/115006567467-EdgeRou...
Disappointed to hear the performance hit with WireGuard. I was planning on trying it out, but I think I'll wait.
Wireguard is just as fast as hardware accelerated IPSec on both the Edgerouter X and Lite. With Openwrt on the Edgerouter Lite Wireguard is ~2x faster than hardware accelerated IPSec on EdgeOS.
If those benchmarks were with AES+GCM, then that would definitely be surprising. But the safe bet is that they were using AES+SHA256 (or something other than GCM for the MAC), in which case their benchmarks are not surprising, simply misleading.
IPSec can also do ChaCha20+Poly1305 (at least, OpenBSD's stack can). Any serious comparison should also include IPSec using the same crypto algorithms as Wireguard.
On the other hand I've yet to achieve sane battery lifetimes on my smartphone with a VPN active. I suspect it's because the VPN needs to reconnect whenever one of my messengers checks for new messages, or similar background services. Anyone have experience how to improve that?
I think, on Android at least, IPSec is impl in kernel space so technically a VPN based on that should be more efficient. Wireguard is being upstreamed into Linux, so there's a chance Android picks it up and the efficiency improves.
If you have a brain larger than your leg, you should consider configuring an IPSec endpoint to save power on your phone.
I wouldn't hold my breath for official WireGuard support in the manufacturer Android kernels until some big corporations start relying on it but custom ROMs are able to use kernel modules already[1].
Encryption itself should not be much overhead. WireGuard cryptography is based on ChaCha20. While I haven't encountered any hardware support for ChaCha, it's performance is quite good, so good even that Google is requiring manufacturers of very low power Android devices (running Android 10+ Go) to implement ChaCha-based encryption on budget devices [2].
[1]: https://git.zx2c4.com/android_kernel_wireguard/about/ [2]: https://security.googleblog.com/2019/02/introducing-adiantum...
The keepalive packets require keeping your phone's radios on. WiFi is pretty low power (<20 milliwatts iirc for the radio) so it has little effect, but mobile data is not low power. Apple & Google have put a lot of work into optimizing the OS to tweak usage to save power and the keepalive packets throw all of that out the window.
If keeping data off is a possibility for you, try that and see if the VPN still affects your battery life. If not, then you will have to set the VPN to only be active on WiFi or manually toggle it on/off whenever you want it.
i know ipsec has a ton of knobs in regards to keepalive, but i wonder if openvpn also supports such fine grained configuration.
[0] https://www.digitalocean.com/pricing/#standard-compute-trigg...
Smallest droplet would probably be fine, if you’re not streaming 4K video. Same goes for the 1TB transfer limit.
Also some e-commerce sites will refuse purchases when made from hosting-allocated IP ranges since it's commonplace for fraud.
Edit: did some reading [1]. Clearly it's not easy to get an ASN. Not something a private person would do.
I am personally looking at AFRINIC for their sweet IPv4 space :-)
But I only need one IP address, and I'm willing to pay $500 for it. Is there a way to make this happen?
[0] https://www.ipv4connect.com/products/-buy-ipv4-Arin-24/484
I know that VPC peering[0] is possible across separate AWS accounts, what I don't know is that:
1. Whether or not my /24 block is "compatible" with VPC peering or not
2. How to prove to Bob that I'm not potentially MitMing him (assign my /24 block to VPC1, peer with Bob using VPC2, and MitM between VPC1 and VPC2 since they're both under my control). Would creating an IAM user with read-only VPC permissions work for this?
AWS is just an example. I would be happy to do this at any major provider (AWS and GCP are the two I know that allows bring-your-own-ip).
[0] https://docs.aws.amazon.com/vpc/latest/peering/what-is-vpc-p...
You only need a good system administrator. I can get you in touch with friends who specializes in that. They will certainly recommend your /24 to be pointing to a more friendly provider of your choice, like one with a flat rate!
/24 with ASN -> friendly provider -> any ip goes where you want (digital ocean, aws, etc.)
But no, you can't prove you aren't MiM. Who has control of the /24 at any point could (ex: the 'friendly' provider)
https://github.com/rajannpatel/Pi-Hole-PiVPN-on-Google-Compu...
(I run OpenVPN and PiHole from a GCP micro instance)
I’m a networking novice, but in my .ovpn profiles I provide, the IP is hard-coded.
"Note: Starting January 1st, 2020, GCP will charge for VM instance external IP addresses. However, under the Free Tier, in-use external IP addresses will be free until you have used a number of hours equal to the total hours in the current month. Free Tier for in-use external IP addresses apply to all instance types (not just f1.micro instances)."
"1 GB network egress from North America to all region destinations per month (excluding China and Australia)"
I bet in part it is due to the CloudFlare's efforts to "Cleaning up Bad Bots" [1]. In this article under how they detect bots they write:
> Another model allows us to determine whether an IP address belongs to a VPN endpoint, a home broadband subscriber, a company using NAT or a hosting or cloud provider. It’s this last group that “Bot Cleanup” targets.
I suspect when use a VPN hosted on a VPS, you often end up classified as a bot to be cleaned up...
Annoyingly, I have moved, and now have comcast so that brings problems. First, they tamper with DNS traffic. To combat this the resolver is unbound running on the Linode. This creates very occasional problems, usually in the form of a capcha. Additionally, comcast doesn't offer symmetric connections, so my VPN is slower than it should be (1Gbps/30Mbps is such a joke).
In fact, I also run a pihole on the same droplet, and that's fine too.
For these, you can try DSVPN, which is even easier than Wireguard to set up: https://github.com/jedisct1/dsvpn
wg set wg0 listen-port 51820...Heck, running a VPN tunnel over TCP itself is already weird, considering the protocols inside the tunnel handle dropped packets if they need to.
It would just result in more inefficiency, a smaller mss/mtu and less throughput.
- my ISP can still see all of my traffic because my RPi would talk to my router which has to exit my network at some point, right?
- if I was on the East coast and wanted, say, YoutubeTV to believe I was on the West coast I would need to have my client (laptop, would be cool if I could get my Roku or TV to do this) pointed to my RPi on the other coast. Is that how it works?
2. Yes, but be wary about actually doing this; I can't find any cases but YouTube TV (or the Google session security system itself) might get suspicious about constantly jumping between the east and west coast.
It looks like it does...maybe I should stick my finger in there. I should probably monitor my CPU history a bit better, I'm just relying on pihole's panel at the moment.
This wasn't on a pi, but it'll look similar. Look at the Speed: line mostly, it'll say either 100MBit or 1000MBit depending on your router (some still only have 100MBit switches). Also look for Duplex: Full, I've had sometimes a config get set badly where it'll be half duplex and cause speed issues, usually due to a bad cable initially causing errors and bad autodetection.
> % sudo ethtool enp4s0
Settings for enp4s0:
Supported ports: [ TP ]
Supported link modes: 10baseT/Half 10baseT/Full
100baseT/Half 100baseT/Full
1000baseT/Full
Supported pause frame use: Symmetric
Supports auto-negotiation: Yes
Supported FEC modes: Not reported
Advertised link modes: 10baseT/Half 10baseT/Full
100baseT/Half 100baseT/Full
1000baseT/Full
Advertised pause frame use: Symmetric
Advertised auto-negotiation: Yes
Advertised FEC modes: Not reported
Speed: 1000Mb/s
Duplex: Full
Port: Twisted Pair
PHYAD: 1
Transceiver: internal
Auto-negotiation: on
MDI-X: off (auto)
Supports Wake-on: pumbg
Wake-on: g
Current message level: 0x00000007 (7)
drv probe link
Link detected: yes1. I have two unreliable ISP links to the internet. Is it possible to have dual redundancy WireGuard connections to the same server? I.e. each UDP packet is replicated (with the appropriate headers) and a copy sent over each link.
2. My ISP links have heavy throttling at peak hours with heavy packet losses. Is it possible to trade bandwidth for reliability and send each UDP packet twice (with the appropriate headers)? I don't mind halving my maximum theoretical bandwidth; I'd rather have a 1Mb/s reliable connection than a 10Mb/s unreliable connection.
For use to connect to home network drives, I've used ZeroTier https://www.zerotier.com/. I've never had an external IP for home internet, so I always ran in headaches trying to do a home VPN to channel my internet traffic while I'm out and about (and that's why I use a VPN on a VPS for that).
I can also recommend OpenVPN's virtual appliances: https://openvpn.net/virtual-appliances/ They work out-of-the-box and come with a web UI for configuration, if that's your thing.
That said, I've moved on to Wireguard lately and will be unlikely to use OpenVPN for personal VPN networks in the future.
Give wireguard a try. Had the same experience with OpenVPN, yet got wireguard to work pretty much immediately.
Works very well for me.
That being said I pay the $40 a year for PIA since I torrent all my movies and tv shows. I use that VPN 99% of the time.
Then you simply copy the .ovpn file from your server (the firewall) to your clients (phones, laptops), and open the file with an OpenVPN client on each device. It contains all info needed for them to connect to your new server.
https://github.com/rajannpatel/Pi-Hole-PiVPN-on-Google-Compu...
It works really good and is super easy to set up, this was also my first time setting up home VPN, so I didn't have any previous experience, and I still got it working easily.
To expand a little bit: it provides an (almost) zero-configuration way to set up a private 'layer 2' network that you can connect your home server to, and any other machines that you want to be able to connect to it or to each other. It handles NAT traversal completely transparently.
In practice, it means that if I have a (say) NFS server connected to a Zerotier network I control, I can connect to it transparently from anywhere from another machine on that network, no matter what NATs / firewalls either machine is behind, even if they change. Perfect for phones, roving laptops, etc. I've gone to a model where I do most of my development (over mosh/tmux) on my home machine, from wherever I happen to be.
No home firewall configuration needed at all.
> ZeroTier’s software is open source and free to use for most purposes including personal use, internal use within a business or academic institution, and evaluation for uses that require commercial licensing.
I was able to find this: https://github.com/zerotier/ZeroTierOne
Also, if you can't open ports outbound at all, there's https://samy.pl/pwnat/ but it makes things very slow.
[0]: https://staaldraad.github.io/2017/04/17/nat-to-nat-with-wire... - you can ignore 'NAT-B' in this one.
You can even bounce off or azure to set up the tunnel when your vpn server is behind a natted firewall. It supports 16-channel connections to max out line throughput even over very long distances between server and client. It can support native windows clients, has openvpn shim for legacy client's on that side. I'm not doing it justice - there's so many features (all gui-configurable) that are supremely thought out.
Truly one of the best examples of free software I can think of.
So is Wireguard?
I will say I've used softether on 10gbps links and hit 8gbps between two continents and that was nearly impossible with every other solution 5 years ago when I first set it up. It's been running flawlessly since then.
Configuring it is a pain done through their `vpncmd` command which gives you a shell with custom commands (not very automatable/reproducable)
Logging is also stuck between logging to a file or sending it to a syslog port, which, with the rise of systemd, leaves it logging to nowhere that journald can access
It's a pretty solid piece of software, but it definitely feels like it was developed for windows GUI admins
But other than that, there’s no big reason to switch if you have a setup you’re happy with.
Or maybe you do not care about the encryption, but care about the virtual and private part of VPN
There are many usecase. There is no one size fit all.
Setting up Wireguard is actually quicker than refreshing your memory with the OpenVPN man page.
Only limitation is that it has to be UDP, Wireguard doesn’t support TCP.
A lot slicker in my experience. Instead of support everything it assumes both sides speak wireguard. Increases speed, reconnects faster etc.
...whether I'd break an existing setup for it...probably not.
There are good, free clients for Windows, Android and Mac. The client for Android hat will handle both connecting to the shadowsocks server and establishing a local SOCKS proxy, and redirecting regular network requests over that proxy. I'm not sure if the clients for other platforms do that, or if they only work with apps that can use a SOCKS proxy.
One Tinc advantage is that it can run on an Openwrt router.
I wish wireguard could accept overlapping AllowedIPs ranges, appear as an L2 interface, and take a nexthop from the system routing table. Imagine multiple hosts each providing egress to each other - tinc can do this topology when setup to act as an ethernet segment. But wireguard is so trivial to setup, it's easy enough to run a parallel instance for each horizon.
- Having no DNS explicitly specified
- Having unbound DNS server run locally
- Using public facing DNS like 1.1.1.1
And none of them seem to make DNS resolve. Anyone else run into this?
I expect that any Asus router that can run Merlin should allow you to ssh in to install Wireguard. But you might need to cross-compile it on another system, and obviously the lower end models might struggle with CPU usage.
The Koolshare group (whose modified version of Asus Merlin is targeted at folks in China) have stopped development for the RT-AC68U, and IIRC this was before they started working on integrating Wireguard into their builds.
It looks like Asuswrt-Merlin uses different kernel version for different routers (probably because the use the kernel from Asus' own open source releases). I'm pretty sure the kernel for the AC68U is too old to support Wireguard.
This link has more info: https://github.com/RMerl/asuswrt-merlin.ng/issues/210
Documentation here: https://doc.turris.cz/doc/en/public/wireguard