FireZone – Open-source VPN server and firewall
firezone.dev
firezone.dev
Firezone CEO here. Someone just clued me into this thread. Unfortunately I’m in and out of Internet service today but I’ll do my best to answer questions.
As noted by others, Firezone isn’t really aiming to be a mesh networking tool like Tailscale, but more of a classic east-west VPN similar to OpenVPN Access Server. We also expose simple controls for managing egress firewall rules.
We have a big release planned next week to bring OIDC auth and the ability to manage multiple WireGuard networks, plus Docker support and more firewall + multisite features in the pipeline for later this summer.
We have a one-line install script for Linux at our repo if you’d like to give it a whirl! Grateful for any and all feedback.
Unless user-tracking telemetry is blocked, in which case, apparently your CLI tools stop working?
https://news.ycombinator.com/item?id=31542047
Edit: dunno if that comment was deleted because the author was wrong about their PiHole blocking telemetry causing commands to fail, if they were harassed into deleting it, or what.
I guess I'll give you the benefit of the doubt that there was something else going on with their network that caused commands to fail, but you're still getting side-eye for engaging in telemetry/usage tracking.
One of my pihole blocklists includes telemetry.* which matches some network call made by the command you run to update the Firezone config. Pihole returns "0.0.0.0" for hostnames it blocks and the error that's raised ends up coming form openssl. Later I discovered there are 2 options at the bottom of the /etc/firezone/firezone.rb config file, commented out, that allow you to disable the telemetry. With these options turned on the error no longer occurs.
We could definitely clarify how to disable telemetry better and we should make sure nothing breaks when telemetry is blackholed instead of disabled. I've opened https://github.com/firezone/firezone/pull/658 to get these addressed.
I will say the big downside to using Elixir is that distributing releases is a bit cumbersome. `mix release` expects that you're building on the same OS / version as you'll be running on, though we're looking into using something like burrito [1] to help alleviate this.
"Please use the original title, unless it is misleading or linkbait; don't editorialize." - https://news.ycombinator.com/newsguidelines.html
As complaining commenters and the project creator agree, this is not a Tailscale alternative. Please don't do that! This was a case study on how small title perturbations end up dominating entire threads.
We use multiple WG interfaces with its own IPv6 subnet for access control so will be keeping an eye on the following issue. https://github.com/firezone/firezone/issues/549
Since then, I run my web and email servers on an old laptop in my home and the Internet POP is a $3.50 VM plus $1 for a static IP, at AWS Lightsail. This works for me but if I needed to connect a disparate office and devices together I might look at Tailscale or one of these packaged solutions, or maybe not.
Just to clarify this take, the source is available on Github [0] but licensed under the highly controversial Server Side Public License [1][2].
This license was originally written by MongoDB. They applied to get it recognised as an open source license with the OSI but later withdrew the application as it became clear it wouldn't have been approved.
OSI explained in 2019 [3] why it didn't consider the license to be open source.
[0] https://github.com/gravitl/netmaker
[1] https://github.com/gravitl/netmaker/blob/master/LICENSE.txt
[2] https://en.wikipedia.org/wiki/Server_Side_Public_License
It's also very much not a "Tailscale Alternative" – it explicitly describes itself as not being "a tool for creating mesh networks", which is the exact thing that Tailscale is all about.
Nebula (https://github.com/slackhq/nebula) is much closer to actually being a fully open-source and self-hostable Tailscale alternative as I understand it, though I've never used it myself.
I am currently researching this area and have found the following solutions in the mesh VPN space. In order of how locked down the source code is—which also seems to correlate with ease of use—there is Tailscale, ZeroTier, Netmaker, Nebula, and also Innernet (this last one is only mac/linux).
Tailscale could be blocked by the GFW [1]. I guess that's because it uses a central beacon node?
Also they are built on WireGuard, which is not obfuscated, so they can be detected by DPI?
[1] https://forum.tailscale.com/t/does-tailscale-work-in-mainlan...
The main issue with living in China is the fact that the connections to the outside world are so clogged that using something like Youtube is often so slow that it's not even worth trying; that was the case in the Beijing area between 2016-2018 at least.
It would be amazing if Tailscale can use ExpressVPN kind of services for handshaking so that it can work inside the GFW.
I've heard those conspiracy theories, but to be honest I just accepted that everything was monitored when I was in China anyway. Installing something like Wechat/微信 basically gives tencent permission to everything that's on your (Android) phone anyway. To me, the VPN was solely about granting access to what was otherwise blocked, not about privacy.
Everything except for Tailscale (and possibly ZeroTier) on that list can be entirely self-hosted.
I really like the design principles[1] of Wireguard. It does away with all the key-negotiation nonsense and eliminates a whole cluster of potential flaws right out of the gate. Also Jason Donenfeld's software development cycle is a skill level that can only be described as a 10000x-developer.
[1] https://securitycryptographywhatever.buzzsprout.com/1822302/...
If I understand correctly, it should do something what speedify does.