SoylentNews
SoylentNews is people
https://soylentnews.org/

Title    WireGuard Imported Into OpenBSD
Date    Monday June 29 2020, @04:21AM
Author    Fnord666
Topic   
from the dept.
https://soylentnews.org/article.pl?sid=20/06/28/2217228

t-3 writes:

http://undeadly.org/cgi?action=article;sid=20200622052207

The WireGuard VPN protocol has been available on OpenBSD as a port for a while, first as the wireguard-go implementation in Go, but later also as the wiresep port in C, both using tun(4) devices, much like OpenVPN and others, which incurs a slight penalty for crossing the kernel/userspace border for each packet.

WireGuard is a layer3 tunnel that can be run in passive mode, only sending packets when something needs to reach the other side (unless you enable heartbeats). It only allows selected modern crypto algorithms and hashes, chosen to be performant on CPUs which lack crypto accelerators, while still being secure. WireGuard packets are sent over UDP, and can run over and transport both IPv4 and IPv6. It handles NAT/port redirects and endpoints changing IP addresses, which is very nice when changing from wired to wifi or vice versa.

https://man.openbsd.org/wg


Original Submission

Links

  1. "t-3" - https://soylentnews.org/~t-3/
  2. "Original Submission" - https://soylentnews.org/submit.pl?op=viewsub&subid=41806

© Copyright 2024 - SoylentNews, All Rights Reserved

printed from SoylentNews, WireGuard Imported Into OpenBSD on 2024-04-20 01:17:34