D&C GLug - Home Page

[ Date Index ] [ Thread Index ] [ <= Previous by date / thread ] [ Next by date / thread => ]

Re: [LUG] Macs & VPNs

 

On 25/10/2018 12:57, Martin Gautier wrote:

> In the end, I've gone with a Draytek modem, psfsense appliance and 
> OpenVPN. Seems to be running fine. The pfsense VPN wizard was very useful.
> 
> I'll have a play with Wireguard when I have some down time, it looks 
> interesting. pfsense with Wireguard bundled in an appliance would be 
> awesome.

Glad to help (if I did).

You weren't tempted by OpnSense instead of pfSense? Keep them on your 
list for next time you have do this (the pfSense holding company have 
always been a bit... weird for want of a better phrase).

Wireguard is the future however - in the space of a month I've changed 
all my stuff around so instead of having OpenVPN in service as usual 
with optional Wireguard for testing I'm now 100% Wireguard with OpenVPN 
relegated to the background just in case. The difference is night and 
day - ease of setup/admin, flexibility, resource consumption. On mobile 
clients it's even more unmistakable - less battery drain, instant 
reconnects as you roam between wifi or mobile networks. You can even set 
up a new client on the fly by SSH'ing into your Wireguard config box - 
which doesn't have to be the actual endpoint machine itself - generating 
the config and then running it through a QR code generator:

qrencode -t ansiutf8 < /etc/wireguard/clients/littlebird.wg0.conf

Point the new phone/tablet/laptop's camera at the pretty picture on the 
tty and you're done. You can also do multi-site to multi-site star 
topologies via Wireguard and route all clients through to a single flat 
VLAN - the sort of thing that used to give me nightmares via IPSEC or 
Open VPNs.

Looks like Wireguard won't be officially merged until the 4.20 (or 5.0 
depending on what Linus calls it) kernel for Linux but you can do a DKMS 
build already on most distros and stable clients are available for 
Windows, Mac and Android.

It's not that often that something new comes along and completely 
blitzes the standardized incumbent software but Wireguard is just such a 
thing.

Cheers
-- 
The Mailing List for the Devon & Cornwall LUG
https://mailman.dclug.org.uk/listinfo/list
FAQ: http://www.dcglug.org.uk/listfaq