Nebula is not the fastest mesh VPN, but neither are the others
defined.net
defined.net
https://www.defined.net/blog/nebula-is-not-the-fastest-mesh-...
This is in response to this oft-cited benchmark post by Netmaker:
https://medium.com/netmaker/battle-of-the-vpns-which-one-is-...
Previous discussions on encrypted overly mesh networks here:
"Would we still create Nebula today?" (Oct 2023) https://news.ycombinator.com/item?id=37871534
A proper test would be done with bare metal machines with 10/40/100G NICs and a controlled network plane free of other traffic.
https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/general-...
Note how some types have "up to X Gigabit", some are just "X Gigabit", and for t2.micro that netmaker used the docs say just "low to moderate" :D
But all that being said, I think it is valuable to benchmark things in noisy real-world conditions too and not only in pristine lab conditions. It definitely requires bit more effort in the analysis side to understand whats going on. And benchmarking without good analysis is pretty bad regardless if it was done in public cloud or some dedicated lab.
Finally EC2 has controls for instance "tenancy" and "placement"; you can ensure that your instances are run on hosts dedicated to your account, again avoiding host-level noisy neighbours. Of course both of these aspects only control the physical host, the networking infra outside the host is afaik almost completely out of control. But at the same time I'd be surprised if there is any significant level of congestion within an AZ.
This is all to say that there is whole spectrum of things between "using random public instances with no consideration" and "set up private dedicated hardware lab", its not just binary choice.
I just wish there was a kubernetes operator to easily set up mesh sidecars like with tailscale and it would be perfect!
https://choosealicense.com/no-permission/
Sad optimism of the commentor to get a PR going if that was all it needed.
so i have been checking https://github.com/slackhq/nebula/issues/6 every time im reminded nebula exists, for the last few years, without success
I personally use only ipv4 on my overlay but I understand why people want it.
I never really looked at tailscale and zerotier because they're too commercial. Nebula I did try once but I didn't really like it. A bit too complex for what I need.
But even with them both using Wireguard, there are choices involved that affect performance, for instance whether to use the Wireguard kernel model or userspace implementation, how to configure routing, packet filtering, firewalls, etc.
What is purpose of mesh on one physical segment?
The only real difference here is how the vpn product implements wireguard: userspace or kernel space, and how well tuned that implementation is. It might make sense to compare wireguard implementations, but (afaik) all are using one of several open source ones. Tailscale did some work to improve performance that they blogged about here https://tailscale.com/blog/more-throughput
What they compare in the article are systems that provide some form of ACL, which is why bare Wireguard is not included. That means there are features in the data path that could have significant performance implications versus a simple tunnel. The impact of using ACL features isn't really a focus of the presented benchmarks, but they do mention a separate test of using iptables to bolt on access controls.
The title suggests that different VPNs are fastest in different measures/tests, so no single VPN is clearly "fastest" in aggregate.
The equivalent title for your analogy would be "Runner A is not the fastest runner, but neither are the others"
If I have all hosts on 10G physical segment why would I use mesh vpn between them?
IMHO, interesting case for mesh vpn is very heterogeneous setup: fir example, 2 hosts in different DCs, 2 hosts on assymetrical ove4subscribed domestic links (ADSL/DOCSIS), 2 mobiles in different ends of the world (lte at best) and 2 laptops on cafee wifis (again, in different countries).
Then it IS mesh network.