Live data from Hacker News

NetMaker: Connect Everything with a WireGuard VPN

netmaker.io

21–30 of 172 posts

Re: NetMaker: Connect Everything with a WireGuard VPN

#21
post #17

First question I have: On what devices/OSs is it supported? The only resource I find is this: https://docs.netmaker.io/architecture.html#compatible-system... No mobile, no NAS yet?

How can I connect my Android or IOS device to my Netmaker VPN? Currently meshing one of these devices is not supported, however, it will be soon. For now, you can connect to your VPN by making one of the nodes an Ingress Gateway, then create an Ext Client for each device. Finally, use the official WG app or another WG configuration app to connect via QR or download the device’s WireGuard configuration.

So no mobile for now.

Re: NetMaker: Connect Everything with a WireGuard VPN

#22
I've been using Netmaker for a few months now and it is incredible. Bastion VPN management for all our enviornments.

The only thing we havne't gotten to work is full 0.0.0.0 forwarding. Docs say it's possible (tho not fully common use case), but we always get hangs when attempting. Usually we have to use sshuttle

Other than that - incredible.

Re: NetMaker: Connect Everything with a WireGuard VPN

#23

A pain point I still haven't resolved with WG is this. From my phone, I want to access my homelab through the WG server at home, but everything else through an external WG VPN somewhere else. My homelab ip range is 10.10.0.0/24 or whatever, but the external VPN is some other range. Wireguard doesn't seem to like this. The alternative is to route my phone to home for 100% of traffic, and my home router would egress th…

Assuming your Wireguard server at home is running Linux, you can achieve this by adding a second routing table and adding routing policies.

Re: NetMaker: Connect Everything with a WireGuard VPN

#25

Earlier quoted context omitted.

Tinc is dormant these days. Very little development going on. Cool concept, but limited performance and limited uptake. Their approach to mesh was neat at the time.

Dormant, or stable? I've been running a tinc mesh network for eons w/ my systems and it's never given me any trouble. I use git to check in the 'hosts/' folder and add/remove hosts as needed, pull down to all the nodes, and they can all connect. I do wish the encryption + transport could be as performant as wireguard, but for my needs, I haven't been pushing it hard enough that it's a concern for me.

I somewhat agree with you.

I went with Dormant as 1.1 has been in development for years and no official stable release. Changes to 1.1 are the odd PR here and there, nothing really from the main author anymore.

Yeah things like improving the encryption I would expect even with a stable but active product like this. Especially given ChaCha20’s widespread adoption and optimisation these days. Likewise I would have liked to have seen decent tinc phone clients (ios, Android). But this is a failing of a lot of VPN clients.

Just look at the release interval on their news page.

Honestly I think the likes of WireGuard, Tailscale, etc took the steam out of the developer. It’s a shame because I do prefer to have a diverse range of VPNs rather than just OpenVPN, IPsec, WireGuard.

1. https://www.tinc-vpn.org/news/

Re: NetMaker: Connect Everything with a WireGuard VPN

#26
post #2

The feature list reminded me of Tailscale so I went looking and found this on their website: https://www.netmaker.io/resources/tailscale-vs-zerotier Their comparison graph at the bottom seems to indicate that the differentiating features between their product and Tailscale is that you can't self-host (ignoring the existence of headscale) and that WireGuard support is limited. I believe the latter point refers to the…

Is the kernel module how they claim the 5x performance over tailscale? I haven't really done any real tailscale performance metrics but can't see how else they can claim this (unless there is infrastructure performance differences).

Afaik, tailscale recently made changes to their go user space implementation that actually made their version faster than the kernel implementation, at least in some cases.

I remember reading a blog post on tailscacles' website about it and how they are pushing their changes upstream (wg kernel and official wg go user space implementation).

Can't find the post now though.

Re: NetMaker: Connect Everything with a WireGuard VPN

#28
post #2

The feature list reminded me of Tailscale so I went looking and found this on their website: https://www.netmaker.io/resources/tailscale-vs-zerotier Their comparison graph at the bottom seems to indicate that the differentiating features between their product and Tailscale is that you can't self-host (ignoring the existence of headscale) and that WireGuard support is limited. I believe the latter point refers to the…

1. thanks for linking that 2. the comparison: - protocol: wireguard is now baseline - speed: netmaker is faster because it uses kernel wg - this is not going to hold true for all system configurations, certainly doesn't for macos - flexibility: feels like it does the same as tailscale, marketed slightly different as they list common use-cases – egress and ingress gateways; network shaping with acls is also possible i…

What’s your approach to routing the mesh? Static? BGP? Something else?

Re: NetMaker: Connect Everything with a WireGuard VPN

#29

I've been using Netmaker for a few months now and it is incredible. Bastion VPN management for all our enviornments. The only thing we havne't gotten to work is full 0.0.0.0 forwarding. Docs say it's possible (tho not fully common use case), but we always get hangs when attempting. Usually we have to use sshuttle Other than that - incredible.

you're using it for office network or server infra?

did you compare it to others, what made you go with netmaker?

Re: NetMaker: Connect Everything with a WireGuard VPN

#30
post #24

[flagged]

your not the first to complain about it[0], the tone is uncalled for - you can just cmd + w that tab and move on + use it as a signal when picking your service provider [0] https://news.ycombinator.com/item?id=37143046

I can close the tab easily enough, yes. If I was a prospective customer though, he just lost a potential sale.

Also, flagging? I'm not surprised, of course; this place is as left as it gets.

Post reply on HN