Это видео недоступно.
Сожалеем об этом.

The Challenges With Wireguard Usage and Market Adoption

Поделиться
HTML-код
  • Опубликовано: 14 авг 2024
  • Connecting With Us
    ---------------------------------------------------
    + Hire Us For A Project: lawrencesystem...
    + Tom Twitter 🐦 / tomlawrencetech
    + Our Web Site www.lawrencesy...
    + Our Forums forums.lawrenc...
    + Instagram / lawrencesystems
    + Facebook / lawrencesystems
    + GitHub github.com/law...
    + Discord / discord
    Lawrence Systems Shirts and Swag
    ---------------------------------------------------
    ►👕 lawrence.video...
    AFFILIATES & REFERRAL LINKS
    ---------------------------------------------------
    Amazon Affiliate Store
    🛒 www.amazon.com...
    UniFi Affiliate Link
    🛒 store.ui.com?a_aid=LTS
    All Of Our Affiliates that help us out and can get you discounts!
    🛒 lawrencesystem...
    Gear we use on Kit
    🛒 kit.co/lawrenc...
    Use OfferCode LTSERVICES to get 5% off your order at
    🛒 lawrence.video...
    Digital Ocean Offer Code
    🛒 m.do.co/c/85de...
    HostiFi UniFi Cloud Hosting Service
    🛒 hostifi.net/?v...
    Protect you privacy with a VPN from Private Internet Access
    🛒 www.privateint...
    Patreon
    💰 / lawrencesystems
    blog.ipfire.or...

Комментарии • 55

  • @LAWRENCESYSTEMS
    @LAWRENCESYSTEMS  3 года назад +3

    Blog post from IPFire blog.ipfire.org/post/why-not-wireguard
    How To Build Your Own Wireguard VPN Server in The Cloud
    ruclips.net/video/7yC-gJtl9mQ/видео.html
    Testing Wireguard in the pfsense 2.5 Beta / Development Release
    ruclips.net/video/PinVqihuvBQ/видео.html

  • @SvenneKrap
    @SvenneKrap 3 года назад +30

    For me, the real killer feature of wireguard (and the reason we are moving all stuff to wireguard) is the non-discoverability of it. In a nutshell, if you don't know the secret you cannot determine that the server is there (by portscan.. network traffic analysis can of course spot it)... Also performance is around 2x in regards to openvpn even on hosts with aes hardware accel..

    • @thegorn
      @thegorn 3 года назад +3

      It’s actually not a killer feature. OpenVPN with a TLS key is also non discoverable. Performance doesn’t matter when it can’t be pinned to a particular interface, and can’t be QoS’ed as its in the kernel. OpenVPN isn’t going anywhere any time soon.

    • @bravofoxtrotllc6817
      @bravofoxtrotllc6817 2 года назад +1

      Well you can if you scan and port 51820 is open!

    • @m0rthaus
      @m0rthaus 2 года назад

      As pointed out by The Gorn - this 'killer feature' is already a feature that OpenVPN has had for the better part of a decade. As far as performance, OpenVPN is pretty solid too. The real improvement is in ease of configuration, OpenVPN is notoriously finicky to configure well. I say 'well' because a lot of home 'powerusers' want to use OpenVPN but just get frustrated during the set up and turn off a few security features or drop them back to insecure legacy-modes to get it running. In that regard, Wireguard is an improvement.

    • @m0rthaus
      @m0rthaus 2 года назад +2

      @@bravofoxtrotllc6817 You can't reliably scan for open UDP ports, as UDP is a stateless connection and will not offer handshake responses. I say reliable because in general a UDP port-scan will only determine if the port "might" be open because it didn't send an ICMP unreachable response, but most commercial and hardened services filter out ICMP responses outbound anyway to make scanning them for open ports much harder. A service-scan of that particular port (eg where a crafted Wireguard packet is sent hoping for a response if a service is listening) would also not gain a response unless the keys match. So no, you can't port scan for Wireguard.

  • @23Q19
    @23Q19 3 года назад +6

    Currently have our entire NOC running on wireguard.. All my teammates couldn't be happier.. It's a simple and more reliable solution.

    • @kittysreview9055
      @kittysreview9055 3 года назад

      That’s awesome!

    • @thegorn
      @thegorn 3 года назад +1

      I have not had a single reliability issue with OpenVPN or IPSec in like 15 years, barring one MTU issue that Cisco had soon after they introduced IPSec VTI’s in early 12.4 code but other than that - rock solid. It’s funny how people parrot “it’s more reliable” when their usage time is measured in weeks or months rather than years.

    • @ignaciocepeda6390
      @ignaciocepeda6390 3 года назад +2

      @@thegorn that was a sharp comment, I'm about to choose between the oldschool and the bleeeding-edge, wireguard community looks pretty optimistic, however I'm considering everything, about realiability, do you consider wireguard reliable for government infrastructure?

    • @23Q19
      @23Q19 3 года назад +3

      @@thegorn Running openVPN for hundreds of employees on firewall vendors hardware/software I don't control resolted is issues(I'm blaming the vendor not openVPN).. So it made sence to have my department switch to what I feel is a better solution, that I could troubleshoot. Ps I've running wireguard for a over a year and half so for me it's been "more reliable"

  • @jermainebrown8615
    @jermainebrown8615 3 года назад +12

    I will never go back openvpn network i use to have alot issue when traffic hit over 100mbps it becomes very slow 🐌 .now am using wireguard am doing 200mbps and is stable with no lag issues

    • @notsure7874
      @notsure7874 3 года назад

      You also don't have 100 simultaneous users, any of whom may have access revoked at any time. OpenVPN isn't going anywhere.

    • @jermainebrown8615
      @jermainebrown8615 3 года назад

      @@notsure7874 your right but it ain't for me since am moving 700mbps constantly over 4 wiregard tunnels

  • @MrRolloTamasi
    @MrRolloTamasi 3 года назад +2

    The beauty of wg are exactly these 'shortcomings': it is just a performant, unchatty and encrypted tunnel network interface. Which actually can be used as is, without pulling in a whole stack of stuff.

  • @gorfmaster1
    @gorfmaster1 3 года назад +1

    I was excited to see Wireguard on my Untangle (home license). I was dissapointed that it was an additional cost for home users. This was shortly before they came out with the Home Pro license.

  • @kittysreview9055
    @kittysreview9055 3 года назад +15

    Wireguard is so fast on pfsense that I’ll never go back. Ipsec is a pain to set up and openvpn is slow as heck

  • @ShikiByakko
    @ShikiByakko 2 года назад +1

    I get that for network professionals and some applications it is necessary for you to have many of those features you talk about, but those are not all of the use cases, and that's not Wireguard ideology.
    Wireguard just pretends to be the tunneling technology module, and if you want to add to that you need to create something else that manages the wireguard tunnel.
    But, for example, for someone like me that just wants an easy and fast way to connect to my network from the outside, Wireguard is without a doubt the best solution.

  • @praecorloth
    @praecorloth 3 года назад +5

    Regarding user management, specifically around LDAP/AD integration. I think that level of integration is something that we will (hopefully soon) look back on as being "RDP listening directly on the internet" levels of bad.

  • @andljoy
    @andljoy 3 года назад +3

    Why replace DOS with NT when DOS works fine ? Yes IPSec will be used for a very long time as the Palo and ASAs of this world will move in 20 years. Palo alto and Cisco being terrible is not a valid reason to not switch where you can. OpenVPN is not used in big industry anywhere near as much as IPSec.
    So IPSec will be around for a long time, OpenVPN will be replaced faster than you think.
    The fundamental design of Wireguard is just better.

  • @TomBabula
    @TomBabula 3 года назад

    I setup vpn server on my AWS cloudnspace. It’s hard to use on public wifi hotspot networks requiring signing on captive portal because it seems to already encapsulate and encrypt all traffic not allowing WiFi network to send login page. Some networks even block, because it uses non-standard ports while ikev2 work fine.

  • @aware24
    @aware24 3 года назад

    I was using wireguard on my Merlín router and anytime a file transfer would occur my CPU usage spiked, so went back to OpenVPN and the CPU spikes are gone but my speeds are a bit crap again, but at least it doesn’t slow down my whole home network or create lag spikes when gaming on consoles.

  • @BGraves
    @BGraves Год назад +1

    IMO, Wireguard is NOT easier to use. The client software on Android and Windows require manually entering text that you have to find on the internet and the documentation assumes you understand the concept of creating a tunnel on both ends and defining the peer (and some of them call it an endpoint!!!!) on both ends. Tailscale fixes this?

  • @magneticshrimp7429
    @magneticshrimp7429 3 года назад +1

    Everyone keeps saying WireGuard is faster than everything else. This is false of course. They are just comparing it to OpenVPN and other user-spacy solutions that are horribly inefficient. A modern IPSec setup is generally on par or faster than WireGuard. And in many cases hardware offloaded for even crazier efficiency. But this is just a pretty tiny gripe with messaging I guess :)
    IPSec has its share of issues of course. So. Much. Historical. Cruft.

  • @magneticshrimp7429
    @magneticshrimp7429 3 года назад

    My serious gripe with WireGuard (at least, every common implementation of it) is how much it sucks at dual stack transport. Roaming is completely broken if a dual stacked client moves to a single stack network, or moving between one type of single stack network to another. From a user experience POV this is just terrible with the VPN just randomly stop working when moving around. And this from a modern solution! Big oof.

  • @blackpietto
    @blackpietto 3 года назад +1

    Wireguard with pia VS openvpn with pia. Wireguard runs faster than openvpn in my situation. With openvpn I achieved max 200 Mbit download.. With wireguard I reached almost 420 Mbit.

  • @johnvillalovos
    @johnvillalovos 3 года назад +1

    Pretty good discussion (and quite a lot of negative comments) about that blog post at Hacker News: news.ycombinator.com/item?id=22591454 So I would take that blog post with a grain of salt.

  • @thegorn
    @thegorn 3 года назад +1

    The devil is in the details. I will only use wireguard for a VPN provider for an iPad or laptop. Single host to VPN with no QoS just FIFO for bursty interactive data type traffic like web, ssh. Wireguard is completely inappropriate when you want deterministic endpoints in a multiWAN environment where you’re running a dynamic routing protocol like OSPF, and where you might want to QoS the voice and RDP within the tunnel. Also wireguard is tunnel only and for some remote access support vpns you need tap interfaces so you can configure devices where no default gateway has been set or you’re migrating gateways so need to be on the same broadcast domain. Wireguard is just a new and very limited tool in the VPN arsenal. I’m glad it’s there but is by no means the be all and end all.

  • @email16v
    @email16v 3 года назад +1

    I love Sriracha!

  • @cpatras7302
    @cpatras7302 3 года назад +11

    Not sure why YT would recommend your video to me, but basically taking 9 minutes to say "read an article" and "because Cisco" is not good content mate.

    • @aaronchamberlain4698
      @aaronchamberlain4698 3 года назад +1

      Watch at 2x speed. Save hours of life.

    • @thegorn
      @thegorn 3 года назад +1

      All his videos are basically reading a press release or bug fix release notes - there’s actually not much in the way of content here.

    • @LAWRENCESYSTEMS
      @LAWRENCESYSTEMS  3 года назад +5

      lol clearly you have not spent much time going through all the content here. Lots of tutorials on this channel along with updates. ruclips.net/user/TheTecknowledgevideos?view=0&sort=p&flow=grid

  • @uncleskeetxxl
    @uncleskeetxxl 3 года назад

    Like # 43

  • @quwipyui6519
    @quwipyui6519 2 года назад

    wireguard can be stopped for a few minutes by simple police cop with mobile device and on the same time they're downloaded your data to check what you watching exactly the same about open vpn sorry vpn is great only for protection from local hackers and definitely not for the professional hackers