Live data from Hacker News

NetMaker: Connect Everything with a WireGuard VPN

netmaker.io

81–90 of 172 posts

Re: NetMaker: Connect Everything with a WireGuard VPN

#81

Related, from earlier this year: https://news.ycombinator.com/item?id=35584533 Wherein the author compares Yggdrasil, tinc, Tailscale, Zerotier, Netmaker, Nebula, and ends up prefering Yggdrasil. Actually, it was this comparison that made me look into Netmaker and prefer it and I've been running it without issue for experimentation. I hope the author revisits NM. I agree that the project is moving quickly, which resu…

> Docs are written for self-hosters. These are all good signs. Except at the time of writing, netmaker isn't FOSS: https://github.com/gravitl/netmaker/blob/16d5b5807/LICENSE.t...

I'm surprised they went for the SSPL, though. Its terms are too vague about the distinction between hosting and just using, and also at the time I read this entry in HN about how it might actually be unenforceable anyway:

https://news.ycombinator.com/item?id=18301116

Re: NetMaker: Connect Everything with a WireGuard VPN

#82

Wouldn’t it be better if companies invested more in improving Wireguard and other open source solutions? How can you trust another company for such an important security service like VPN? What if one of their employees sells you out to the best offer? In the build vs buy equation, often people forget that if you don’t own the keys of your door, you risk someone locks you out.

> How can you trust another company for such an important security service like VPN?

It’s pretty easy, you just look at Gartner’s Magic Quadrant and pick one in the upper right hand corner. Any VPN solution can have vulnerabilities and any (same) company would keep it up to date. A lot of hardware firewalls have ASICS to accelerate VPN traffic and this may be a requirement to handle the amount of traffic a company might have.

Re: NetMaker: Connect Everything with a WireGuard VPN

#83

I have to connect a Mac on latest OS to a Windows 7 PC on the same LAN to get access to an established VPN (L2TP/IPsec) on that machine. I have never seen a confusing space as the VPN world. While I can connect e.g. to a SoftEther VPN Server on the windows box just fine, the installation breaks the established VPN connection to the external L2TP VPN. Installed Wireguard and have absolutely no idea on how to configure…

This should be a simple problem to solve without an additional VPN. On the Mac, you should be able to add a static route for the VPN destination and point it to the IP if the Windows box. This is assuming that Windows firewall isn’t blocking the incoming connection from your Mac.

Re: NetMaker: Connect Everything with a WireGuard VPN

#85

Related, from earlier this year: https://news.ycombinator.com/item?id=35584533 Wherein the author compares Yggdrasil, tinc, Tailscale, Zerotier, Netmaker, Nebula, and ends up prefering Yggdrasil. Actually, it was this comparison that made me look into Netmaker and prefer it and I've been running it without issue for experimentation. I hope the author revisits NM. I agree that the project is moving quickly, which resu…

> Docs are written for self-hosters. These are all good signs. Except at the time of writing, netmaker isn't FOSS: https://github.com/gravitl/netmaker/blob/16d5b5807/LICENSE.t...

Thanks for pointing this out - a major negative for this project.

For now, Nebula is still my choice in this space.

Re: NetMaker: Connect Everything with a WireGuard VPN

#86

Related, from earlier this year: https://news.ycombinator.com/item?id=35584533 Wherein the author compares Yggdrasil, tinc, Tailscale, Zerotier, Netmaker, Nebula, and ends up prefering Yggdrasil. Actually, it was this comparison that made me look into Netmaker and prefer it and I've been running it without issue for experimentation. I hope the author revisits NM. I agree that the project is moving quickly, which resu…

> Docs are written for self-hosters. These are all good signs. Except at the time of writing, netmaker isn't FOSS: https://github.com/gravitl/netmaker/blob/16d5b5807/LICENSE.t...

Why isn’t SSPL considered FOSS but AGPL is?

Re: NetMaker: Connect Everything with a WireGuard VPN

#87
post #86

Earlier quoted context omitted.

> Docs are written for self-hosters. These are all good signs. Except at the time of writing, netmaker isn't FOSS: https://github.com/gravitl/netmaker/blob/16d5b5807/LICENSE.t...

Why isn’t SSPL considered FOSS but AGPL is?

The short answer is SSPL has field-of-use restrictions, the AGPL does not.

Re: NetMaker: Connect Everything with a WireGuard VPN

#88

Maybe a dumb question, but what are the advantages of such products compared to just configuring a "plain" wireguard server i.e. on OpenBSD? I'm not a network expert and still it was pretty simple. Do these products offer more features? What kind of features?

tl;dr: you don't have to configure wireguard yourself and it can help you meet acronym compliance

Re: NetMaker: Connect Everything with a WireGuard VPN

#89

Earlier quoted context omitted.

> Docs are written for self-hosters. These are all good signs. Except at the time of writing, netmaker isn't FOSS: https://github.com/gravitl/netmaker/blob/16d5b5807/LICENSE.t...

Thanks for pointing this out - a major negative for this project. For now, Nebula is still my choice in this space.

Same here. Nebula might not be wireguard based, but it is open source and very stable.

Though, I have to say that if you are using Nebula within a LAN it sometimes takes minutes for two nodes to realize they are within each other's reach. In the mean time, they talk through the lighthouse which can severely affect performance.

Re: NetMaker: Connect Everything with a WireGuard VPN

#90
post #55

Earlier quoted context omitted.

Or maybe, just maybe, posting a comment that is egregiously outside the guidelines of the site means that people will see it and appropriately flag it. Not everything is political and it’s showing that that is what you immediately jumped to. > Be kind. Don't be snarky. Converse curiously; don't cross-examine. Edit out swipes. > Please don't use Hacker News for political or ideological battle. That tramples curiosity.…

Seeing as this service(?) is, quote, "Backed by Y Combinator" I decided being nice about it on Y Combinator isn't worth my time nor that of any readers passing by. Not to mention websites breaking my scroll bar and disrespecting my time are so common these days they indeed really aren't interesting, which is all the more reason to call them out nicely or otherwise.

> I decided being nice about it on Y Combinator isn't worth my time nor that of any readers passing by.

That’s great and all, but the guidelines are there for a reason. Break them enough and you will eventually be banned. And once again, breaking them is a valid reason to get flagged and downvoted, whether you like it or not.

> Not to mention websites breaking my scroll bar and disrespecting my time are so common these days they indeed really aren't interesting, which is all the more reason to call them out nicely or otherwise.

The logic here really doesn’t follow. Like even remotely. If the topic isn’t interesting then your comment is even less so.

Post reply on HN