Subspace – A simple WireGuard VPN server GUI
github.com
github.com
If you are looking for user friendly web UI for quickly building a VPN for remote access (encrypting traffic / data path between the device and Internet), with easy client management (scan the QR code for client profile thingy) try
- wg-access-server [1]
- wg-gen-web [2]
- wg-ui [3]
They all work well in a containerized fashion, all created around the same time when WireGuard was merged into Linux kernel mainline ;-)
Simple script worked better for my remote access use case for now, for use cases at scale I'd seriously take Tailscale into account (100 clients for personal - free account).
[1]: https://github.com/Place1/wg-access-server
Specifically it written not try to manage your firewall and whatnot (how to do that is explained, though).
I realized that I didn't want to ever deal with port-forwarding, NAT, or dynamic DNS and decided to create this. Message me if you want a signup link.
Then I need to do documentation, figure out pricing/billing.
How do you deal with the global scarcity of IPv4-addresses that you would need to scale your service? I think this can only work long term if you own the address space yourself and are not dependent on some specific provider or cloud.
Also very important is a local endpoint to get a reasonable end to end latency.
Or do I have to add a peer that's out of my control, which you use for routing between the two that are under my control?
1) I saw that you're basically using one OVH box per IP. How do you plan to ever monetize this then?
What prevents a user from creating their own VPN instance on their own box and port forwarding from there? Granted this process is somewhat involved, but the kind of user who needs to do this is likely to be somewhat technically inclined anyway. (Some ideas: negotiate long-term deals for IP addresses and try to map > 1 IP per box / remove the static IP guarantee and keep a rotating pool of addresses – public IPs are more valuable than static IPs anyway IMO and you can integrate dynamic DNS into your service)
2) How do I know that you're not sniffing my traffic? Granted that most traffic being encrypted these days is a thing, but still I think it's a genuine concern.
3) I live in Asia, so latency was off-the-charts for me. (On the order of 500ms). But this problem could easily be solved by introducing servers in more locations.
2) that's a hard question, mainly because if I was using this service I would ask the same thing. Personally, I think a strong mission statement, privacy policy, and maybe a warrant canary would be good enough. At least with a strong privacy statement, I would be legally bound to never sell/peek at your data which is loads better than current ISPs.
I can't do much better than promise I wouldn't.
3) Did the Chicago server fare any better?
Also, thank you for the comments! I really appreciate them.
I think two tiers with a cheaper roaming IP + dynamic DNS plan and a more expensive static IP plan would be smart. But that's for you to decide.
3) Only the Canada server was available when I signed up ~2 weeks ago unfortunately. I'll take a look again.
You might want to sort out the Subspace name and trademark, sooner than later.
Alternatively, their VPSs are dirt cheap. $3.35/month.
How does this work? I thought WireGuard encrypts the traffic?
They support plaintext tunnels for free, and encrypted tunnels starting at eight dollars a month.
I cam across the service when learning how to accept incoming traffic on kubernetes.
I use it to develop a lot with twilio and salesforce callbacks.
Is there any concern over people using your service for illegal/unfavorable activities like torrenting? Or are you planning to keep logs to provide to law enforcement requests?
I don't get how this helps me "build" a service. Can't find source code anywhere.
On a related note the whole reason I self host is so I don't have to rely on things I don't control so there is no way I would use something like this. Defeats the purpose of self hosting IMO.
..that might go something like this...
Raspberry Pi at home running docker containers with a reverse proxy like Nginx or Caddy. The Pi is set to automatically connect to the wireguard service once it has a network connection. The hosting server with the external public IP forwards port 80/443 browser traffic to the Pi sitting in your home LAN. Your domains can be mapped through Cloudflare to the public IP of your external server for an extra layer of privacy and caching. Requests to your Pi webserver reverse proxy through other containerized services on the Pi or to other hosts within your private home network running services like Wordpress, GOGS, Express Node app, Verdaccio (npm cache/proxy,) pretty much anything. Things get even more interesting if you run a reverse proxy on the remote server. It's also great to have a static public address by which to reach and manage your internal servers via ssh.
dsnet is a simple wiregard management command that manages key generation and IP allocation, generating config files. I'm using it for a few networks at the moment.
I recently tried to add decent documentation and a blog post in the hope that it's useful to someone. I should so a Show HN really.
Here's the blog post: https://callanbryant.co.uk/blog/how-to-set-up-a-wireguard-vp...
Side note, any particular reason for having `user-select: none` set on your blog? That seems somewhat counterproductive for a blog with code examples...
I'm glad you like it.
> Side note, any particular reason for having `user-select: none` set on your blog? That seems somewhat counterproductive for a blog with code examples...
Ah -- that's not intentional. Thanks for letting me know, I've pushed a fix!
I developed the hugo theme for something else where it made sense (a portal) then converted it for use with my blog and missed that.
Originally released on HN. The game was abandoned by the developer. Entire thing was rewritten by the community and refuses to die.
Lots of fun and great people involved. Keyboards can take a bit of a beating though.
It's not fair nor feasible to reserve names permanently.
I got back into Extreme Games (30-flag CTF) for 6 months last year. Good times all over again.
Is there a simple way to work around this issue? Can I include the keys from a 3rd party file for instance? I guess I could always just pre-process the config file to generate the final one from multiple sources.
I have it grabbing a key from AWS Secret Manager, haven't had a problem with that.
I might be the only one who confused myself :)
Seriously. This is cool. CLI rules all, but man, sometimes it's nice to use a GUI.
You might want to check WireGuardStatusBar - https://github.com/aequitas/macos-menubar-wireguard
I like it over wg-quick (which requires sudo, and prompts for password all the time). The WireGuardStatusBar uses a privileged helper, so you only need to authorize it once and use it all the time.
Cheers.
I am only one version behind the latest Mac, so what could be the problem?
What kind of magic can I use it for to pipe data around securely in my AWS fortress?
- simplicity
- sound crypto
- minimal attack surface
- high performance
- well defined
The biggest issue I have with Wireguard is that it's not set up for Roadwarriors. If you have an endpoint with a dynamic IP address (like your home router), but you give wireguard a DNS name, it doesn't store the DNS name. It only stores the resolved IP address.
The official solution is a script they have in their contrib repo that you stick in cron and it scans for changes and resets the endpoint if your DNS changes.
Wireguard also can't bind to a specific adapter on a multi adapter server. Since it doesn't respond with anything with unauthenticated packets, the official solution is that is shouldn't matter. Just iptables on everything and only accept packets on the adapter you want public.
The problem is, the egress packets will just go over the default adapter, so now you have incoming and outgoing packets taking different routes.
Overall thought, I like wireguard way more than OpenVPN. They still need to fix those and other issues though.
Am I misunderstanding the limitation you're claiming?
I’m in the same boat, but my ISP almost never changes IPs.
In my experience, Comcast IPs aren't contractually static, but they very rarely change. Months or years of having the same IP doesn't seem to be uncommon.
I like how many choices there are for off-the-shelf configuration generators.