Live data from Hacker News

In-kernel WireGuard is on its way to FreeBSD and the pfSense router

arstechnica.com

31–40 of 167 posts

Re: In-kernel WireGuard is on its way to FreeBSD and the pfSense router

#31
post #16

Earlier quoted context omitted.

Netgate is weirdly hostile to a lot of opensource stuff, which should be strange given what all their tech is built on top of. This has been going on for years. (see opnsense etc)

Netgate funds a lot of FreeBSD work, and employs FreeBSD committers. I certainly wouldn't describe them as hostile to open source.

Perhaps entitled is the right word then.

Re: In-kernel WireGuard is on its way to FreeBSD and the pfSense router

#32

I've been waiting for pfSense+Wireguard for a while. OpenVPN has been very good to me but I'm psyched to trade up.

pfSense has the only friendly admin GUI for OpenVPN that I know of, besides the proprietary Access Server. Will they do the same for Wireguard?

Wireguard is already in the latest version (2.5). UI is ok but you need to understand how wireguard works what the fields mean.

Re: In-kernel WireGuard is on its way to FreeBSD and the pfSense router

#34

Earlier quoted context omitted.

I can't find any logic in downvoting a declaration like this (and the parent Q). It really seems like lashing out at good-faith.

BSD adheres the POLA principle and is serving many PB of data in production at work. Rock solid and no sudden changes. The manual pages are to me of higher quality when compared to Linux. POLA Principle Of Least Astonishment

I can't argue with any of that.

Re: In-kernel WireGuard is on its way to FreeBSD and the pfSense router

#35

Earlier quoted context omitted.

The shade I occasionally see thrown toward pfSense is curious to me. This isn't push-back at the parent comment but me expressing a bit of confusion. I've used pfSense since 2009 or so. I was skeptical when Netgate entered the picture but since I've had no reason to complain. It's been a continuous and usually smooth timeline of serving me well. A relevant sidebar is that I've been part of different, stellar voluntee…

> The shade I occasionally see thrown toward pfSense is curious to me. Every last bit of it is deserved. They made a promise to keep pfSense open source and they broke it as soon as they could. I see them hiding behind it's the newly announced pfSense Plus that is closed source, not pfSense CE and it's pure weaseling. I still use pfSense but I feel bad for ever being excited about it and contributing to their popular…

However, you are directing your disdain (about pfSense) toward us. To what end? What is it you want to achieve?

Re: In-kernel WireGuard is on its way to FreeBSD and the pfSense router

#37

Link to relevant announcement email: https://lists.zx2c4.com/pipermail/wireguard/2021-March/00649... There's also Jason's reply to apparently not-nice feedback of someone from NetGate: https://lists.zx2c4.com/pipermail/wireguard/2021-March/00649...

Good read, I saved crypto.{c,h} for later use. Nice and tidy crypto code.

Re: In-kernel WireGuard is on its way to FreeBSD and the pfSense router

#38
post #29

Earlier quoted context omitted.

The opnsense fork has supported wireguard for a while, and has far less restrictive licensing. I highly recommend having a look.

OPNsense is criminally underrated. My main routers for my office are virtualized OPNsense VM's in high availability with CARP, DHCP, DNS, VPN endpoints, inter-vlan routing, gateway policies, outbound nat... I could go on. It all works extremely well I can't fathom why people still choose pfSense with all of the community shenanigans and closed source versions. My only gripe with it over 3 years has been the documenta…

> OPNsense is criminally underrated.

When I came into FW distros, my practical choices were MonoWall, SmoothWall and pfSense. IPfire wasn't even on the scene yet. pfSense won me early. I figure there are a lot of similar stories of pfSense being there for us when not much else was.

Re: In-kernel WireGuard is on its way to FreeBSD and the pfSense router

#39

Earlier quoted context omitted.

> The shade I occasionally see thrown toward pfSense is curious to me. Every last bit of it is deserved. They made a promise to keep pfSense open source and they broke it as soon as they could. I see them hiding behind it's the newly announced pfSense Plus that is closed source, not pfSense CE and it's pure weaseling. I still use pfSense but I feel bad for ever being excited about it and contributing to their popular…

However, you are directing your disdain (about pfSense) toward us. To what end? What is it you want to achieve?

> However, you are directing your disdain (about pfSense) toward us.

I don't think I am; who's us in that sentence?

> To what end? What is it you want to achieve?

I'm scratching an itch. If Netgate can screw the community that helped pfSense gain popularity then surely it is perfectly acceptable for a member of that community to express a little disdain.

Re: In-kernel WireGuard is on its way to FreeBSD and the pfSense router

#40
post #28
post #11

Earlier quoted context omitted.

Wow. Netgate come off as incredibly unprofessional. According to the article linked and the info here in that email you linked this is my conclusion: * Netgate tried to ship flawed code that has multiple security issues. * Jason Donenfeld, one of the lead Wireguard developers, went out of his way to work on rewriting it to be better in time for the 13.0 release of FreeBSD * This Netgate employee is angry that they we…

That was my impression too, then I went back a couple prior messages, and looked at the earlier announcement. Wihle Netgate looks to have overreacted (at least from the info we have), I can understand why they would be upset. This was in the original announcement: The first step was assessing the current state of the code the previous developer had dumped into the tree. It was not pretty. I imagined strange Internet…

Well if it's true, then they were trying to put flawed code into freebsd which they would then ship to customers in their security product.

They're not some random person but are representing their company with their code.

If there was a security exploit with their Wireguard implementation, would Netgate get blamed or Wireguard?

Post reply on HN