Simple WireGuard Docker network setup
eisfunke.com
Simple WireGuard Docker network setup
1–10 of 21 posts
Re: Simple WireGuard Docker network setup
#2OpenVPN config files can be pretty small once you remove all the comments (my server is 22 lines)
That being said, I like WireGuard. I've switched over a lot of stuff to it. It does have some issues though:
* Road warrior configurations aren't easy. If you use a DNS name as an endpoint, and that DNS entry changes, you have to refresh it. They have a contrib script in the repo that you can put in cron and do this for you, but it's still not built in.
* You might need keep-alives in certain configurations
* You can't bind Wireguard to an IP address. It listens on all adapters. The devs argue it doesn't matter since WG won't respond via UDP unless it gets a valid key, but this does put WG into a weird state where it might send on an IP it's not receiving on.
There are others I'm probably forgetting. I do like it though. It's faster, the setup is clear. If you have one setting wrong in OpenVPN the connection could fail and you not get useful stuff in the logs.
Re: Simple WireGuard Docker network setup
#3Re: Simple WireGuard Docker network setup
#4Re: Simple WireGuard Docker network setup
#5> take a look at an OpenVPN config file and you will appreciate this shortness OpenVPN config files can be pretty small once you remove all the comments (my server is 22 lines) That being said, I like WireGuard. I've switched over a lot of stuff to it. It does have some issues though: * Road warrior configurations aren't easy. If you use a DNS name as an endpoint, and that DNS entry changes, you have to refresh it. T…
This is really frustrating for me. If you put a DNS name as a peer endpoint, wg-quick will resolve the name and then _replace the name with the ip address_. My IP address changes frequently and I have a script to update the A record when it does, but wireguard didn't have built in support for just keeping the domain name around when I last looked.
Re: Simple WireGuard Docker network setup
#6> take a look at an OpenVPN config file and you will appreciate this shortness OpenVPN config files can be pretty small once you remove all the comments (my server is 22 lines) That being said, I like WireGuard. I've switched over a lot of stuff to it. It does have some issues though: * Road warrior configurations aren't easy. If you use a DNS name as an endpoint, and that DNS entry changes, you have to refresh it. T…
> If you use a DNS name as an endpoint, and that DNS entry changes, you have to refresh it. This is really frustrating for me. If you put a DNS name as a peer endpoint, wg-quick will resolve the name and then _replace the name with the ip address_. My IP address changes frequently and I have a script to update the A record when it does, but wireguard didn't have built in support for just keeping the domain name aroun…
Re: Simple WireGuard Docker network setup
#7I appreciate the write up, but you can't just put "simple" in a title to and expect it to be simple for everyone. It's simple for what audience? I know there are plenty of developers (especially Mac/Windows users) who would read this and be put off. Simple for me would be running one command like "docker-compose up" and be up and running.
"docker-compose up" is not quite as bad as "curl | sudo" , but it's pretty darn close.
Re: Simple WireGuard Docker network setup
#8 ip netns add vpn
ip link add wg0 type wireguard
ip link set wg0 netns vpn
# configure wireguard as usual, prefix commands with ip netns exec vpn
podman run --network=ns:/var/run/netns/vpn ...
When I tried this was not yet possible with rootless containers, but in newer Podman versions you can tell slirp4netns to use a specific network interface with --network=slirp4netns:outbound_addr=INTERFACE.Re: Simple WireGuard Docker network setup
#9https://github.com/pirate/wireguard-docs#example-client-cont...
Re: Simple WireGuard Docker network setup
#101. Complex implementation: lots of moving parts with a lot of room for defects
2. Complex configuration: lots of configuration settings with a lot of room for misconfiguration
3. Complex protocols: overcomplicated handshaking and key negotiation
All these things leave a lot of flexibility for backdooring, binary exploitation, etc. aka "capabilities" in spook-speak.