Live data from Hacker News

Algo: A set of Ansible scripts that simplify the setup of a personal IPSEC VPN

github.com

41–50 of 88 posts

Re: Algo: A set of Ansible scripts that simplify the setup of a personal IPSEC VPN

#42
post #31

Use Wireguard. It is wonderful and the community is friendly. `wg-quick` is easy to use but if you need it, I believe Streisand supports automatically provisioning a wireguard setup.

Wireguard is awesome, but the kernel module is so far a mess. If you're paranoid I wouldn't rely on it until the code has been cleaned up and perhaps audited.

you are not mistaken

Re: Algo: A set of Ansible scripts that simplify the setup of a personal IPSEC VPN

#43

Serious question, do people consider a cloud provider to be more trustworthy than a professional VPN company?

Perhaps? If you’re using a VPN to protect your internet traffic from being sold to ad companies, probably. The VPN industry has become a racket full of affiliate schemes that push people towards plans and services that don’t necessarily act in the user’s best interest. Figuring out the food from the bad can be difficult. And I’ve seen some services that when audited use outdated or insecure stacks. Of course, if you’…

> Figuring out the food from the bad can be difficult

Lol. Funny, good VPNs are like good fishing spots, the ones who know the difference tend not to share their favourites, keeping it for themselves :)

Re: Algo: A set of Ansible scripts that simplify the setup of a personal IPSEC VPN

#44
post #31

Use Wireguard. It is wonderful and the community is friendly. `wg-quick` is easy to use but if you need it, I believe Streisand supports automatically provisioning a wireguard setup.

Algo supports it as well although the docs currently make it sound like it's for Android clients only. But you can grab the generated config (and perhaps add a keepalive line to taste) and use it on other platforms.

Re: Algo: A set of Ansible scripts that simplify the setup of a personal IPSEC VPN

#45

Question - are there any guides available to help set up a home-brew router to route all outbound connections through an Algo VPN with exceptions for Netflix/etc.? Something like this (this is for OpenVPN): https://arstechnica.com/gadgets/2017/05/how-to-build-your-ow... I currently have a pfSense router set up with Algo, but I have to disable the IPSec policy whenever I want to use Netflix. (Discussion here: https://…

Try OPNsense Here is detailed tutorial https://forum.opnsense.org/index.php?topic=4979.0

VyOS is another good option

Re: Algo: A set of Ansible scripts that simplify the setup of a personal IPSEC VPN

#47
post #31

Use Wireguard. It is wonderful and the community is friendly. `wg-quick` is easy to use but if you need it, I believe Streisand supports automatically provisioning a wireguard setup.

Wireguard is awesome, but the kernel module is so far a mess. If you're paranoid I wouldn't rely on it until the code has been cleaned up and perhaps audited.

A mess in what way out of interest? (I've not looked at the source)

Re: Algo: A set of Ansible scripts that simplify the setup of a personal IPSEC VPN

#48
post #31

Use Wireguard. It is wonderful and the community is friendly. `wg-quick` is easy to use but if you need it, I believe Streisand supports automatically provisioning a wireguard setup.

Wireguard is awesome, but the kernel module is so far a mess. If you're paranoid I wouldn't rely on it until the code has been cleaned up and perhaps audited.

> a mess

by @mistaken, not Linus: http://lists.openwall.net/netdev/2018/08/02/124

Re: Algo: A set of Ansible scripts that simplify the setup of a personal IPSEC VPN

#49
post #31

Use Wireguard. It is wonderful and the community is friendly. `wg-quick` is easy to use but if you need it, I believe Streisand supports automatically provisioning a wireguard setup.

Wireguard is awesome, but the kernel module is so far a mess. If you're paranoid I wouldn't rely on it until the code has been cleaned up and perhaps audited.

You are mistaken

Re: Algo: A set of Ansible scripts that simplify the setup of a personal IPSEC VPN

#50
post #31

Use Wireguard. It is wonderful and the community is friendly. `wg-quick` is easy to use but if you need it, I believe Streisand supports automatically provisioning a wireguard setup.

Wireguard is awesome, but the kernel module is so far a mess. If you're paranoid I wouldn't rely on it until the code has been cleaned up and perhaps audited.

I'm not sure I've seen a more accurate handle before. I'd welcome any evidence to convince me otherwise though.
Post reply on HN