Live data from Hacker News

Build your own private WireGuard VPN with PiVPN

jeffgeerling.com

11–20 of 235 posts

Re: Build your own private WireGuard VPN with PiVPN

#11
post #9
post #6

Or just use a Mikrotik router which has Wireguard support built-in.

This is only for Mikrotiks that uses ARM processor. Some older that runs on MIPS doesn't get this update.

Wireguard support comes with RouterOS 7 (ros7). I'm running ros7 on a MIPS device (mAP) and it works fine. What device(s) are you talking about?

Re: Build your own private WireGuard VPN with PiVPN

#12
post #4

Before going to a long 3 month trip to Asia last year, I installed WireGuard on my Raspberry Pi 1 (original model B from 2012) which was running at home in US. I found PiVPN to be the easiest way to install Wireguard. I didn't know if I even needed a VPN but I was glad, and I was able to use internet as if I were at home. It was weird, but a lot of sites are blocked oversea, even though it shouldn't. For example, I c…

I don't know first hand, nor am I speaking for my employer (who happens to be one of the two companies you mentioned), but if it was me, I would assume that if my company doesn't do business outside of the United States, then may as well deny traffic for services that wouldn't be available outside of the United States, since it is more often than not problematic traffic. This means sometimes legit traffic would be inconvenienced, as you were, and sorry about that, but it is a realistic scenario that the small amount of legit pain is worth the incredibly reduced risk footprint. Of course, baddies could get VPNs, too, but that's all part of the game.

Re: Build your own private WireGuard VPN with PiVPN

#13

The one problem I encounter with Wireguard is the use of UDP. Some publicly accessible Wifi nets at shops don't allow UDP at all, and this effectively breaks use of the VPN. Yeah, there are utilities like setting up udptunnel or udp2raw and similar, but what a headache. I really don't agree with Wireguard's developers justification that it makes speeds terrible. Who cares? It'll be terrible using those utilities anyw…

Yeah, OpenVPN even supports authenticated web proxies, which is a really nice feature for tunneling. But I realize that I'm probably far from a typical user.

Re: Build your own private WireGuard VPN with PiVPN

#15
post #4

Before going to a long 3 month trip to Asia last year, I installed WireGuard on my Raspberry Pi 1 (original model B from 2012) which was running at home in US. I found PiVPN to be the easiest way to install Wireguard. I didn't know if I even needed a VPN but I was glad, and I was able to use internet as if I were at home. It was weird, but a lot of sites are blocked oversea, even though it shouldn't. For example, I c…

I don't know first hand, nor am I speaking for my employer (who happens to be one of the two companies you mentioned), but if it was me, I would assume that if my company doesn't do business outside of the United States, then may as well deny traffic for services that wouldn't be available outside of the United States, since it is more often than not problematic traffic. This means sometimes legit traffic would be in…

My Canadian stepfather died. Family is not close and I’m in the US. The Canadian newspaper where his obit would be doesn’t allow connections from the US.

More than a “small amount of legit pain” was the result.

Re: Build your own private WireGuard VPN with PiVPN

#16
post #4

Before going to a long 3 month trip to Asia last year, I installed WireGuard on my Raspberry Pi 1 (original model B from 2012) which was running at home in US. I found PiVPN to be the easiest way to install Wireguard. I didn't know if I even needed a VPN but I was glad, and I was able to use internet as if I were at home. It was weird, but a lot of sites are blocked oversea, even though it shouldn't. For example, I c…

Can’t access homedepot from Germany either. I guess it’s HD blocking pesky foreigners

Re: Build your own private WireGuard VPN with PiVPN

#17
post #3

I moved to Tailscale, until I find something simpler, I'm not moving back.

Why would that even look like?

When I set it up it promised a 10 minute install time. For me a fair portion of that 10 minutes was trying to work out if it was working as my line speed was higher than I thought possible. It’s scary how quick it is to configure.

Re: Build your own private WireGuard VPN with PiVPN

#18
It might be more of a rabbithole, but if you're going the 'self-hosting' homelab route, I'm a big fan of OPNsense to give you more freedom and control of your network (which has support for Wireguard [0]). While ARM support is lacking, it can be run on a cheap or spare x86-64 box if you had one.

Otherwise, I really like the premise of Tailscale for quick and easy implementation.

[0]: https://docs.opnsense.org/manual/how-tos/wireguard-client.ht...

Re: Build your own private WireGuard VPN with PiVPN

#19
post #3

I moved to Tailscale, until I find something simpler, I'm not moving back.

Have you tried Nebula (https://nebula.defined.net)? I set up a personal Nebula network a few months ago and have been very happy with it thus far. It has the ability to do mesh-style direct routing so you don't necessarily have to pay the out-and-back latency cost if you're connecting to a location that is closer.

Re: Build your own private WireGuard VPN with PiVPN

#20

Earlier quoted context omitted.

I don't know first hand, nor am I speaking for my employer (who happens to be one of the two companies you mentioned), but if it was me, I would assume that if my company doesn't do business outside of the United States, then may as well deny traffic for services that wouldn't be available outside of the United States, since it is more often than not problematic traffic. This means sometimes legit traffic would be in…

My Canadian stepfather died. Family is not close and I’m in the US. The Canadian newspaper where his obit would be doesn’t allow connections from the US. More than a “small amount of legit pain” was the result.

I'm sorry for your loss. Do they have a phone?
Post reply on HN