[ Date Index ] [ Thread Index ] [ <= Previous by date / thread ] [ Next by date / thread => ]
On 25/10/2018 12:57, Martin Gautier wrote: > In the end, I've gone with a Draytek modem, psfsense appliance and > OpenVPN. Seems to be running fine. The pfsense VPN wizard was very useful. > > I'll have a play with Wireguard when I have some down time, it looks > interesting. pfsense with Wireguard bundled in an appliance would be > awesome. Glad to help (if I did). You weren't tempted by OpnSense instead of pfSense? Keep them on your list for next time you have do this (the pfSense holding company have always been a bit... weird for want of a better phrase). Wireguard is the future however - in the space of a month I've changed all my stuff around so instead of having OpenVPN in service as usual with optional Wireguard for testing I'm now 100% Wireguard with OpenVPN relegated to the background just in case. The difference is night and day - ease of setup/admin, flexibility, resource consumption. On mobile clients it's even more unmistakable - less battery drain, instant reconnects as you roam between wifi or mobile networks. You can even set up a new client on the fly by SSH'ing into your Wireguard config box - which doesn't have to be the actual endpoint machine itself - generating the config and then running it through a QR code generator: qrencode -t ansiutf8 < /etc/wireguard/clients/littlebird.wg0.conf Point the new phone/tablet/laptop's camera at the pretty picture on the tty and you're done. You can also do multi-site to multi-site star topologies via Wireguard and route all clients through to a single flat VLAN - the sort of thing that used to give me nightmares via IPSEC or Open VPNs. Looks like Wireguard won't be officially merged until the 4.20 (or 5.0 depending on what Linus calls it) kernel for Linux but you can do a DKMS build already on most distros and stable clients are available for Windows, Mac and Android. It's not that often that something new comes along and completely blitzes the standardized incumbent software but Wireguard is just such a thing. Cheers -- The Mailing List for the Devon & Cornwall LUG https://mailman.dclug.org.uk/listinfo/list FAQ: http://www.dcglug.org.uk/listfaq