Building a Simple VPN with WireGuard with a Raspberry Pi as Server
snikt.net
snikt.net
The following article has an example of using policy based routing. Your setup isn't all that different, you don't need to have more than one default route in each routing table is all and you also might only need one additional route table.
https://help.ubnt.com/hc/en-us/articles/204952274-EdgeMAX-Po...
set protocols static table <table-number> interface-route 0.0.0.0/0 next-hop-interface wg1The ER-4 has been great with the Cavium hardware. No hardware offload issues like this.
Edit: The ER-X tops out around 500 Mbit with hardware offload turned off.
I get about 900 megabit on my gigabit fiber.
https://help.ubnt.com/hc/en-us/articles/115006567467-EdgeRou...
but i’d assume it should handle fast rates like this if hw offloading was on.
Then the pole outside my house got hit by lightning and fried the thing, and I replaced it with something from mikrotik.
I migrated from Wireguard to ipsec quite a long time ago because it was less complicated for my particular needs. It has probably been close to 2 years. No one else seems to have taken up resolving the lingering problems with the configuration issues.
I'll give it another shot at some point, but it was more just to try out. I've also got ipsec set up on that router and that continues to work just fine.
If you do attempt it again there are "generate" commands which will generate they keys needed and place them in the proper area in the file system. Most of the guides to configuring Wireguard on edgeos seem unaware these exist and have people using the "wg" command directly instead to generate keys.
I think part of my issue is just that I need to do some more reading around what IPs should be what. It's usually clear what's going on in WireGuard-land, but not clear how that interacts with the other interfaces or the networks on either side.
Works great for secure access from anywhere when working remotely or travelling.
The major advantage to using Streisand instead of Algo is that it comes with lots of obfuscation goodies to help get around restrictive firewalls, like shadowsocks.
Also, if you're on a restrictive firewall and you need to quickly assess what ports are even open for egress, you can do `nmap --open allports.exposed` to find them. Then use one of streissand's VPN options and connect.
I've been considering setting up WireGuard so I can keep my mobile phone always connected to my home network.
Will I experience degraded network performance (either latency or bandwidth) if I have my mobile phone always connected to a VPN 24/7?
My phone is an iPhone 11 Pro and I would be running WireGuard on a Pi4
Imagine these 2 use cases:
#1. You do not use/touch your iPhone for 24 hours. Wireguard will now show 40% of the total battery that was used.
#2. You play the game Tetris for 24 hours. Wireguard will now show less than 1% of the total battery that was used. Because Tetris used the other 99,9%.
I’ve had to turn it off a few times when some apps do geo-ip lookup and give me errors about not knowing whether I’m in the US. Otherwise the main drawback is battery usage.
If you want all your network traffic to go via your home network instead of normally over the internet, you will experience degraded network performance and it'll mostly depend on how fast your home network is & how far it is network-topologically from your phone.
This is normally fine since you most people download way more than they upload and don't run servers in their homes, but when you route everything through your home, you may be limited by upload speeds.
Being a VPN and a DNS server are both extremely light weight tasks that use (mostly) orthogonal resources (VPN = IO, DNS ~ fairly small IO and CPU).
Full data (iPhone 11 client at work):
<VPN>: <down Mbps> / <up Mbps> / <RTT ms>
No VPN: 145 / 139 / 5
Router OpenVPN: 25 / 6 / 82
pi4 wireguard: 24 / 27 / 24
If the former is true, that seems like quite a significant penalty to pay for using wg.
RK3399 based boards are interesting but there is only 1x NVME on the Rockpi4 NVME extender.
The Nvidia Jetson nano extenders use USB3, which is not acceptable for the usecase
"A commercial license is only needed if you want to offer a paid network management service or embed it into a proprietary device or app."
I would stay away from software that wants to restrict how you use it.
> commercial license is only needed if you want to offer a paid network management service or embed it into a proprietary device or app.
A cursory look suggests that it's open source, with restrictions that they clearly list on their site here[0]. I get your point, but I personally don't mind if a business open sources their software and allows free use of it for non commercial cases.
Open source implies nearly unlimited rights for the developer, like BSD, MIT, or Apache.
With these idiosyncratic restrictions (noncommercial, research only, do no evil, etc) we typically say “disclosed source.”
Wrong: the GPL for example is defined as open-source by the Open Source Initiative (source: https://opensource.org/licenses) -- a fact that has not changed since the coining of the term "open source" over 20 years ago.
No it doesn't. You're thinking of copyleft licenses. FOSS is not synonymous with copyleft; many FOSS licenses (recognized as such by RMS and the FSF) are not copyleft.
No, that is "source-code available". "Open source" was defined over 20 years ago by this document and that is still how most software people still use the term: https://opensource.org/osd
https://www.gnu.org/philosophy/open-source-misses-the-point....
"Free software" is also an absolutely awful term because for 99.9% of the population "free" means it didn't cost them any money. This will never change no matter how hard RMS tries because its a very common and understood word.
> The terms “free software” and “open source” stand for almost the same range of programs.
and he definitely doesn't claim that open source is proprietary.
Many closed source programs and libraries allow the users to see and modify the source code for their own use but that doesn't make them open source.
Your parent's comment didn't even mention the open source issue here. Stop harassing startups with open source products just because you make 6 figure merely doing nothing all year.
The 4 is supposed to be actual gigabit, but I have not yet tried it out to confirm.
3 is only 100mbit eth, but I’ve had almost no issues with it. Connects fast, no problem streaming HD video or cloning huge git repos. Maybe when I get home today I’ll take some measurements.... But my biggest issue is the trash Powerline Ethernet between my router and rest of my network.
I run OpenHAB and Pi-Hole all on a RPi3 on ethernet, no issues so far.
It does seem pretty good though. I'm having trouble getting past 25 Mb/s in, 100 Mb/s out on my Edgerouter X.
Edit: 3B+. My bad.
Edit: It doesn't.
(The Pi 3 also is 4 years old now and you wouldn't want to buy it today)
I might give this a try!
The luci-app-wireguard package is a bit quirky at times though.
You'll run into cpu bottlenecks with some of the lower end hardware though.
Not sure why the RPi is so lauded for this and Pi-Hole (which is just a fancy DNS blocklist) when OpenWrt is just as simple and powerful for both (and more) tasks.
But when setting up new custom zones from scratch (like this VPN subnet/zone), I never feel quite as home as I do with the traditional Linux command-line and iptables.
Basically OpenWRTs abstractions don't map cleanly to the underlying Linux-primitives I know fairly well. The impedance mismatch there is what make me consider the RPi-based solution more preferable, because I understand how and why it works.
Isn't there also some missing host/RPI system so that the 10.200.200.0/24 can route to the public internet?
If someone has an example of a full VPN configuration I'd love to see them so I can try it out.
Not sure what your issue is with the address line.
As for the AllowedIPs, that's intentional. From the first lines of the article:
> An Linux Laptop that should use the VPN only accessing network services that are exposed to the VPN
VPNs aren't just for routing your public traffic through some trusted host.
I think there is definitely a market for it.