Show HN: Onetun – Access your WireGuard network from anywhere
github.com
github.com
So as long as you have a private key & peer IP dedicated for your roaming needs, you'll be able to forward a local port to a port on a secured peer.
This can be useful for a few other use-cases, like exposing services to the Internet from a separate server that doesn't have root access (like a non-privileged container).
I've also gotten feedback to enable reverse-tunneling (making a port accessible on a peer that forwards to a port running locally), which enables a few more use-cases. I'm looking for any more ideas or feedback that would fit in this tool!
I've described how the internals work in the README. It's still a proof-of-concept right now but I listed my little roadmap in the issues: reverse-tunneling, UDP support, multi-port-forwarding, etc. Happy to answer any questions.
Here's a demonstration of both a http-client and a http-server running over wireguard (a poor man's QUIC, if you will): https://github.com/WireGuard/wireguard-go/tree/master/tun/ne...
fly.io wrote about such a setup not long ago too: https://news.ycombinator.com/item?id=26315695
And tailscale.com similarly uses wireguard with netstack to impl functionality unavailable on non-Linux/xBSD platforms: https://news.ycombinator.com/item?id=28261683
[0] https://savannah.nongnu.org/projects/lwip/ [1] https://en.wikipedia.org/wiki/UIP_(micro_IP)
Or, is LwIP more capable than what I it give credit for?
(by the way, thank you for building orchid in the open! looking forward to the eventual team-up between orchid and helium :)
U wot m8?
In a thread about bananas userland TCP this Cat got a whole sundae.
https://www.google.com/search?q=won%20ton&tbm=isch&tbs=itp:c...
I have some illustrator and designer friends, I'll see if they want to cook up something!
- SSH uses TCP for transport, and tunneling TCP-over-TCP has considerable performance issues: http://sites.inka.de/~bigred/devel/tcp-tcp.html
- SSH doesn't support tunneling UDP out of the box (you need to either wrap UDP with TCP, or use SSH's -w option for creating a TUN interface, which requires root access).
WireGuard being a very simple UDP protocol has its advantages for things like this. The downside is you can't use onetun with the same private-key/assigned IP on multiple devices, since WG only supports 1 UDP endpoint per peer at a time.
Note: my tool doesn't support UDP in it's current state, but there's no technical reason it shouldn't be feasible (unlike SSH). I have a draft PR for it right now.
WireTrustee: https://news.ycombinator.com/item?id=27672715
Innernet: https://news.ycombinator.com/item?id=26628285
ZeroTier: https://news.ycombinator.com/item?id=28423466
Define.net: https://defined.net/
NetMaker: https://news.ycombinator.com/item?id=28147050
to name a few.