John Goerzen · @jgoerzen
1026 followers · 2843 posts · Server floss.social

@vesto Glad it was helpful! I don't use iOS much, so that battery drain sounds aallying. It sounds like you're having firewall out things that aren't coming from ZeroTier? That's interesting. I use firehol to do such things. Another option is to have your servers bind to a specific interface, in which case they won't even listen on the other interfaces in the first place. I didn't go as deep with that part of ZeroTier.

#tailScale #zerotier

Last updated 1 year ago

John Goerzen · @jgoerzen
976 followers · 2675 posts · Server floss.social

I wrote a deep dive about solutions, with traversal and such. Featured: , , , , , . "Easily Accessing All Your Stuff with a Zero-Trust Mesh VPN" at changelog.complete.org/archive

Thanks to those that participated in the previous thread, and particularly @tailscale .

There are some interesting options these days and I hope to see them continue to gain traction!

#mesh #VPN #nat #Yggdrasil #tinc #tailScale #zerotier #nebula #netmaker

Last updated 2 years ago

John Goerzen · @jgoerzen
976 followers · 2675 posts · Server floss.social

@bogosian Hi @tailscale folks! I have a question about the threat model for . If somebody compromises either your control plane, or my account/identity provider, what is the potential damage? I gather an intruder would not be able to sniff my traffic, but they might be able to add additional machines to my network and thus penetrate the network that way, correct? Are there best practices to mitigate that risk? Thanks!

#tailScale

Last updated 2 years ago

John Goerzen · @jgoerzen
976 followers · 2669 posts · Server floss.social

Update: Looks like some candidantes include: (sort of the OG mesh network VPN, which I didn't realize can do NAT traversal), (fully Open Source if the frontend is used), , (not entirely clear but I THINK this is also open source). Thanks for the suggestions everyone!

#tinc #tailScale #headscale #nebula #netmaker

Last updated 2 years ago

John Goerzen · @jgoerzen
976 followers · 2669 posts · Server floss.social

@tc Thank you - yeah, that Open Source implementation sounds interesting! Has anyone compared , , , and/or ?

#tailScale #nebula #zerotier #netmaker

Last updated 2 years ago

John Goerzen · @jgoerzen
976 followers · 2665 posts · Server floss.social

There are few options where I live. Fiber is 2 years out. I may need to use an ISP that uses , which means no open ports at all. I see that and both use (or something like it) to solve this problem. Are there any pure Open Source tools that can do this? is great, but is TCP based, so can't do direct P2P with blocked ports (it can communicate, but via a public or private intermediary.) Perhaps packages?

#Internet #cgnat #tailScale #zerotier #stun #Yggdrasil #Debian #askFedi

Last updated 2 years ago