- https://github.com/juanfont/headscale
- https://github.com/tonarino/innernet
- https://github.com/slackhq/nebula
Something I'm missing?
- https://github.com/juanfont/headscale
- https://github.com/tonarino/innernet
- https://github.com/slackhq/nebula
Something I'm missing?
https://github.com/gsliepen/tinc/tree/1.1
It isn't based on WireGuard, but is a true mesh network, unlike everything you've listed. No central coordination point, every node is equal.
Think of it as BitTorrent with a few initial peers you set up through a config file, and it learns of every other peer at runtime (like BitTorrent does through Peer Exchange).
It can forward traffic through other nodes (like Tailscale and unlike Nebula) and recomputes the most efficient route as peers become (un)available.
[1]: https://datatracker.ietf.org/doc/html/rfc3489 [2]: For instance, Rust: https://github.com/webrtc-rs/stun & Go:https://github.com/pion/stun, and see this HN comment listing a few WebRTC implementations (which include STUN): https://news.ycombinator.com/item?id=26739253
It might not be the best solution in terms of performance or security (peer reviewed crypto something something).
I remember there was talk about switching the backend for Wireguard for security and speed, but it seems to be on the backburner: https://github.com/gsliepen/tinc/issues/179
Not Wireguard based, but similar functionality.
Client intermittently had seizures (at least on Windows) and I couldn't join/unjoin networks properly. Would have to restart the service and close the program for it to begin to work again.
Sometimes the traffic just didn't flow ... at all. Randomly couldn't connect to other clients on the network.
I quit about 6 mo ago. Has it improved since?
I have tried to use it over mobile data and wasn't very lucky, and that's something that used to work great. I couldn't tell if it was due to ZT or the carrier. There's CGNAT on both ends, which could be getting in the way, although like I said it used to work great.
I have also noticed that it takes longer than I was used to get IP, find routes between nodes, etc but once those are up it works well.
Not associated with them in any way other than being a user.
> An encrypted IPv6 network using public-key cryptography for address allocation and a distributed hash table for routing.
is a building block that can be used to achieve something similar, minus TURN-like NAT traversal fallback. The peer discovery leverages DNS and UDP hole punching uses WireGuard itself.
It's not distributed, however.
That said, Nebula feels way less popular, and I don't know if it's had a third party security audit. WG's popularity means it should presumably have had a lot of attention given to both its architecture and its code. This is one area where using a "niche" solution feels somewhat risky.
However, the Android client does not allow for specifying a DNS server and breaks the Android system DNS over TLS. Google thinks the VPN app/client should handle DNS and Nebula app development seems very slow. This means you cannot use adblocking DNS while using Nebula.
So neither is a compromise security-design wise.
> So neither is a compromise security-design wise.
Security involves much more than the crypto framework being used; just crypto requires much more than the framework. Noise could be implemented insecurely, as a basic example.