Wiretrustee: WireGuard-Based Mesh Network
github.com
github.com
- https://github.com/juanfont/headscale
- https://github.com/tonarino/innernet
- https://github.com/slackhq/nebula
Something I'm missing?
Not Wireguard based, but similar functionality.
Client intermittently had seizures (at least on Windows) and I couldn't join/unjoin networks properly. Would have to restart the service and close the program for it to begin to work again.
Sometimes the traffic just didn't flow ... at all. Randomly couldn't connect to other clients on the network.
I quit about 6 mo ago. Has it improved since?
I have tried to use it over mobile data and wasn't very lucky, and that's something that used to work great. I couldn't tell if it was due to ZT or the carrier. There's CGNAT on both ends, which could be getting in the way, although like I said it used to work great.
I have also noticed that it takes longer than I was used to get IP, find routes between nodes, etc but once those are up it works well.
Not associated with them in any way other than being a user.
It's not distributed, however.
https://github.com/gsliepen/tinc/tree/1.1
It isn't based on WireGuard, but is a true mesh network, unlike everything you've listed. No central coordination point, every node is equal.
Think of it as BitTorrent with a few initial peers you set up through a config file, and it learns of every other peer at runtime (like BitTorrent does through Peer Exchange).
It can forward traffic through other nodes (like Tailscale and unlike Nebula) and recomputes the most efficient route as peers become (un)available.
[1]: https://datatracker.ietf.org/doc/html/rfc3489 [2]: For instance, Rust: https://github.com/webrtc-rs/stun & Go:https://github.com/pion/stun, and see this HN comment listing a few WebRTC implementations (which include STUN): https://news.ycombinator.com/item?id=26739253
It might not be the best solution in terms of performance or security (peer reviewed crypto something something).
I remember there was talk about switching the backend for Wireguard for security and speed, but it seems to be on the backburner: https://github.com/gsliepen/tinc/issues/179
> An encrypted IPv6 network using public-key cryptography for address allocation and a distributed hash table for routing.
That said, Nebula feels way less popular, and I don't know if it's had a third party security audit. WG's popularity means it should presumably have had a lot of attention given to both its architecture and its code. This is one area where using a "niche" solution feels somewhat risky.
However, the Android client does not allow for specifying a DNS server and breaks the Android system DNS over TLS. Google thinks the VPN app/client should handle DNS and Nebula app development seems very slow. This means you cannot use adblocking DNS while using Nebula.
So neither is a compromise security-design wise.
> So neither is a compromise security-design wise.
Security involves much more than the crypto framework being used; just crypto requires much more than the framework. Noise could be implemented insecurely, as a basic example.
is a building block that can be used to achieve something similar, minus TURN-like NAT traversal fallback. The peer discovery leverages DNS and UDP hole punching uses WireGuard itself.
From the description, this tool isn't what I want. I have configured a simple version by hand with Wireguard, but it did seem like raw WireGuard is too low-level for my purpose and my networking knowledge. Setting up the keys does need some level of automation for anything larger than a sandbox. And I didn't figure out a way to resolve domains within the VPN without interfering with the DNS on the clients for everything else.
It has a Wireguard option that works
No VPN, DNS, IPs, and so on; and get to the same result: any device accessing resources in private networks, besides a few extra features.
https://github.com/tonarino/innernet
There are easier options around if all you wish is ssh access to your servers though. Personally I'd recommend gravitational teleport, mainly because the name is so hilarious
It also has some neat stuff around eBPF session recording if you want to be able to playback user sessions for high security environments. Teleport is good tech.
Also, I had issues to configure it for my situation with no static IP and behind a proxy. I have it working but not really exactly how I wanted it. Maybe its my lack of understanding, I'm sure it could be made to do exactly what I want somehow.
All said, it pretty nice but I reverted to using the FIDO2 based keys sticks directly.
ZeroTier should also be an option.
Router Nodes is what I would really like to have, I want a node that doesn't have internet connection, but in the local network with another node to get access to the internet through that node. Wasn't able to achieve it with plain Wireguard, my linux networking kungfu is weak.
EDIT: thanks, I'll try mentioned projects, Yggdrasil seems most interesting.
Wiretrustee seems to be for generating a private org network. Could be personal, work, circle of friends or anything. Most traditional work VPNs have one or more nodes that all traffic pass through and that all connect to. A mesh VPN instead allows VPN peers to send traffic directly to each other over the public Internet. There seems to be a central coordination/signaling server, as with tailscale, headscale and innernet. But that is mainly used to find where the traffic should be sent, not for sending all traffic through it.
Google just doesn’t cut it because there are so many spammy sites that dominate the search results when you search for alternatives.
I suppose the turn server support for nat hole punching is the biggest difference?
I've been using wg-meshconf[1] to assist in setting up Wireguard Mesh Networks on Linux for a while, works amazing!
A massive use case is to setup Kubernetes clusters, where end to end network encryption is quite important.
edit: Ah this was a dumb comment, it's trademark the creators of wireguard. These folks are using the name correctly. Nothing fishy or weird going on.
From the original website
There's no "real" network that they provide a gateway to, necessarily, just a bunch of nodes, potentially none of which are on the same physical or logical local network, aside from the mesh network itself, which is an overlay network—think of an overlay network like a virtual machine, but for networks, incidentally: a protocol stack built on top of, or within, if you prefer, another protocol stack. You feel like you're talking TCP/IP over it, but under the hood your TCP packets are carried in other packets (may or may not also be TCP—often it's UDP when possible) over the normal Internet, then reconstructed back into this virtualized, if you will, packet stream on the other end.
With a traditional VPN, you'd connect to a real device that provides a gateway to, say, a corporate network, which may have routing connecting multiple locations but is essentially a normal network. Mesh networks operate much more peer-to-peer than that, usually leveraging known peers to find routes to others that are (for whatever reason) unreachable or initially unknown. The "mesh" part refers to the routing, mainly, the job of which is to search out and find good paths to nodes. If "corporate" has fiber cut by a backhoe, "the VPN" isn't down—many, many nodes might be, but the network might survive in a useful form.
A) WireGuard works great when it's all set up! Config is a bear but it's a great protocol. Works well on lots of different devices in different usages - Android, laptops, desktops, headless servers, IoT.
B) I have even more respect for Tailscale for doing all of this in such a polished, seamless way.
There are some caveats though. We use a fixed mtu value of 1280 to be on a safe side while wg-quick dynamically detects the best value. We will improve it.
If the Wireguard kernel module isn't available (true for older Linux, Mac and Windows) then userspace implementation is used (wireguard-go) which is slower.