Cloudron makes it easy to run web apps like WordPress, Nextcloud, GitLab on your server. Find out more or install now.


    Cloudron Forum

    • Register
    • Login
    • Search
    • Categories
    • Recent
    • Tags
    • Popular

    Wireguard VPN

    App Wishlist
    wireguard vpn cloudron security
    21
    72
    5581
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      Miggi last edited by

      Hi,

      Implementation of WireGuard would be awesome.
      Its a small but strong VPN Solution, based on newer Security Algorithms and is getting to build into Linux Kernel
      Wireguard looks like it takes OpenVPN and IPSec out of Business ^^
      Something about 4000 Lines of Code(instead of 400-600k) and open source
      Official Website
      Https://www.wireguard.com/

      murgero Mallewax 2 Replies Last reply Reply Quote 60
      • murgero
        murgero App Dev @Miggi last edited by

        @Miggi I love the idea, however - One issue I see with this is the claim of being better than OpenVPN, but no certification by a reputable security firm like OpenVPN. I have tried Wireguard though - amazing how fast and easy it was to configure. But just not old enough to be considered stable - yet.

        --
        https://urgero.org
        ~ Professional Nerd. Freelance Programmer. ~
        Matrix: @murgero:urgero.org

        W 1 Reply Last reply Reply Quote 2
        • yusf
          yusf last edited by

          Wireguard 1.0.0 is now audited, released and included in the Linux 5.6. Time to get the app going!

          imc67 murgero 2 Replies Last reply Reply Quote 8
          • imc67
            imc67 translator @yusf last edited by

            @yusf Wouldn't it be great to combine it with Pi-hole, then you have an all-in-one "always safe home" connection? The apps (ie. iOS and MacOS) of Wireguard are btw absolutely great, always connection, fast, never failes and even after reboot immediately connects.

            1 Reply Last reply Reply Quote 2
            • girish
              girish Staff last edited by

              Is there a wireguard UI in progress? We can probably re-purpose what @mehdi wrote for the OpenVPN app for wireguard as well.

              imc67 1 Reply Last reply Reply Quote 1
              • imc67
                imc67 translator @girish last edited by imc67

                @girish there are a lot (too many) initiatives for a web GUI none really mature IMHO. Currently I use PIVPN (can also be installed on Ubuntu) with commandline, very easy, very simple and also with QR code (from the command line!)

                1 Reply Last reply Reply Quote 0
                • W
                  will @murgero last edited by will

                  @murgero Wireguard has been audited many times now. It is even upstreamed into the kernel.

                  Replying to old comments is hard apparently.

                  murgero 1 Reply Last reply Reply Quote 0
                  • murgero
                    murgero App Dev @yusf last edited by

                    @yusf 100% this!! I actually already use it daily heheh

                    --
                    https://urgero.org
                    ~ Professional Nerd. Freelance Programmer. ~
                    Matrix: @murgero:urgero.org

                    1 Reply Last reply Reply Quote 0
                    • murgero
                      murgero App Dev @will last edited by

                      @will My original response to this post was almost a year ago - so of course stuff has changed since........

                      --
                      https://urgero.org
                      ~ Professional Nerd. Freelance Programmer. ~
                      Matrix: @murgero:urgero.org

                      W 1 Reply Last reply Reply Quote 1
                      • W
                        will @murgero last edited by

                        @murgero hahaah noted! I'll remove my reply!

                        murgero 1 Reply Last reply Reply Quote 1
                        • murgero
                          murgero App Dev @will last edited by

                          @will No worries mate ❤ cheers!

                          --
                          https://urgero.org
                          ~ Professional Nerd. Freelance Programmer. ~
                          Matrix: @murgero:urgero.org

                          1 Reply Last reply Reply Quote 1
                          • marcusquinn
                            marcusquinn last edited by marcusquinn

                            For interest I find this WG service decent. I have 1Gb fibre and it's able to achieve about 90% of that speed, whereas Open VPN (with pfSense on Vultr) I get about 20% of my bandwidth:

                            https://www.azirevpn.com/cfg/wireguard

                            And if any geeks are looking to relocate:

                            https://www.digital.je/choose-jersey/connectivity-and-network-infrastructure/

                            We're not here for a long time - but we are here for a good time :)
                            Jersey/UK
                            Work & Ecommerce Advice: https://brandlight.org
                            Personal & Software Tips: https://marcusquinn.com

                            1 Reply Last reply Reply Quote 3
                            • Mallewax
                              Mallewax @Miggi last edited by

                              @Miggi I am a big fan, too and are upvoting.

                              Please also see this thread:

                              https://forum.cloudron.io/topic/1355/pi-hole-network-wide-ad-blocking/17?_=1594947401156

                              Together it makes even more sense.

                              1 Reply Last reply Reply Quote 1
                              • D
                                dylightful last edited by

                                +1 - Been using WireGuard over OpenVPN for the past couple of months and prefer it!

                                1 Reply Last reply Reply Quote 4
                                • D
                                  dylightful last edited by

                                  @girish Now that Adguard has been implemented. Any future plans for Wireguard?

                                  imc67 1 Reply Last reply Reply Quote 2
                                  • imc67
                                    imc67 translator @dylightful last edited by

                                    @dylightful I really hope so, OpenVPN from iOS and MacOS is dramatic (maybe also on other platforms?) and WireGuard is really fast, stateless and always on.

                                    ruihildt 1 Reply Last reply Reply Quote 1
                                    • ruihildt
                                      ruihildt @imc67 last edited by

                                      Wireguard is also low on battery usage comparing to OpenVPN. (on Android at least)

                                      1 Reply Last reply Reply Quote 4
                                      • J
                                        JLX89 last edited by

                                        Yes, this would be incredible! +1

                                        1 Reply Last reply Reply Quote 0
                                        • D
                                          dylightful last edited by

                                          Quite and polite bump 🙏

                                          1 Reply Last reply Reply Quote 2
                                          • D
                                            dylightful last edited by

                                            @girish any update on Wireguard? has quite a few votes now

                                            girish 1 Reply Last reply Reply Quote 1
                                            • girish
                                              girish Staff @dylightful last edited by

                                              @dylightful not really, we haven't started working on it. We just finished releasing 6.2.

                                              1 Reply Last reply Reply Quote 1
                                              • K
                                                kallados last edited by kallados

                                                WG would be great! Absolutely. Openvpn is dead sorry (im mean Performance). Maybe for DSL fine, but if you have "normal " modern Conection >100mbit... WG ist almost alone, who can deliver really nice speed with pretty easy user friendly Installation.

                                                D 1 Reply Last reply Reply Quote 5
                                                • D
                                                  dylightful @kallados last edited by

                                                  @kallados The best option at the moment is Nyr's WG script. Obviously means you have to create a new VM if you want to keep your Cloudron 'clean'.

                                                  Nevertheless, i agree OpenVPN is old news. Hopefully soon 🙂

                                                  K 1 Reply Last reply Reply Quote 0
                                                  • K
                                                    kallados @dylightful last edited by kallados

                                                    @dylightful I like this OpenVPN which is included on Cloudron. I use it 24/7. Pretty stable, easy to install, nice Frontend- great Stuff. Im really happy with. WG is for me just something like "next Step 🙂 10 gbit server and 250mbit cable at home and im not able to get >150mbit with OpenVpn. If i connect with WG... 220-230 is no problem at all.

                                                    D 1 Reply Last reply Reply Quote 1
                                                    • D
                                                      dylightful @kallados last edited by

                                                      @kallados Oh absolutely! Cloudron's OpenVPN panel is great. However, have stopped using it since OpenVPN drains the hell out of my Android phone. Speed alongside with battery life WG is my daily driver!

                                                      ruihildt 1 Reply Last reply Reply Quote 0
                                                      • ruihildt
                                                        ruihildt @dylightful last edited by

                                                        @dylightful Yeah OpenVPN battery drain is unfortunately real.

                                                        1 Reply Last reply Reply Quote 1
                                                        • D
                                                          dylightful last edited by

                                                          B B B B Bump 😊

                                                          1 Reply Last reply Reply Quote 5
                                                          • S
                                                            sayedanowar9 last edited by

                                                            Please support Wireguard as well

                                                            D 1 Reply Last reply Reply Quote 4
                                                            • D
                                                              dylightful @sayedanowar9 last edited by

                                                              @sayedanowar9 i have broken 4 fingers crossing them too tightly...

                                                              K 1 Reply Last reply Reply Quote 5
                                                              • K
                                                                kallados @dylightful last edited by

                                                                @dylightful My Domain wireguar.de ist ready on my Cloudron. Just WG missing ^^

                                                                1 Reply Last reply Reply Quote 3
                                                                • D
                                                                  dylightful last edited by

                                                                  Can't be far away now right?

                                                                  K 1 Reply Last reply Reply Quote 3
                                                                  • K
                                                                    kallados @dylightful last edited by kallados

                                                                    @dylightful
                                                                    I hope. OpenVPN is pretty stable, also the connection with AdGuard, but for some Reason is the Speed really weak. 12 cores, nvme, 64 gig ram and dedicated 1 gig port... And I come not over 50-70 maps. If I connect few more devices every single one achieve 50-70 Mbps.

                                                                    N8N, Redash, SQL, Jellifin and Metabase are the Reasons why I'm happy to pay for Cloudron. If I get Wireguard... I don't need really more 🙏

                                                                    robi 1 Reply Last reply Reply Quote 1
                                                                    • robi
                                                                      robi @kallados last edited by

                                                                      @kallados can you tell us how you use Redash and Metabase and N8N?

                                                                      Life of Advanced Technology

                                                                      K 1 Reply Last reply Reply Quote 0
                                                                      • K
                                                                        kallados @robi last edited by

                                                                        @robi I'm Quality Specialist. We have over 10k Employees. Lot of Data 🙂

                                                                        Google Sheets are fine, but not really usable if you need to handle big Data. Big Query is fine to, but I can't expect from every single Worker, that he can work with. Actually, seems to be SQL the best way.

                                                                        Our Workers handle most time different Google Sheets. I use then N8N to import Data from these Sheets and running first optimization (like Format etc.)- then import to SQL. N8N handle also Minio S3 for me. My Workers importing some Data as *.csv to Minio and N8N handle them.

                                                                        Metabase is pretty easy if you want just simple analyse like a Time Range and some Filters. Nice easy understandable Dashboard. SQL is messy, but for easy Question is fine. If i need better Solution (complicated Questions or refresh Avery X second etc.) then i use Redash. Clean SQL.

                                                                        imc67 1 Reply Last reply Reply Quote 3
                                                                        • imc67
                                                                          imc67 translator @kallados last edited by

                                                                          @girish just for inspiration I found an easy way to configure and manage WireGuard in Docker:

                                                                          https://github.com/WeeJeWel/wg-easy

                                                                          This can make the long awaited WireGuard app on Cloudron also easy?

                                                                          timconsidine K 2 Replies Last reply Reply Quote 7
                                                                          • timconsidine
                                                                            timconsidine App Dev @imc67 last edited by

                                                                            @imc67 looks very interesting

                                                                            1 Reply Last reply Reply Quote 2
                                                                            • K
                                                                              kallados @imc67 last edited by

                                                                              @imc67 said in Wireguard VPN:

                                                                              @girish just for inspiration I found an easy way to configure and manage WireGuard in Docker:

                                                                              https://github.com/WeeJeWel/wg-easy

                                                                              This can make the long awaited WireGuard app on Cloudron also easy?

                                                                              Pretty nice 👌

                                                                              1 Reply Last reply Reply Quote 1
                                                                              • D
                                                                                dylightful last edited by

                                                                                The lone survivor
                                                                                773c16e7-1ce3-4688-a643-3807a5200b58-image.png

                                                                                girish 1 Reply Last reply Reply Quote 4
                                                                                • girish
                                                                                  girish Staff @dylightful last edited by

                                                                                  @dylightful We just pushed out jitsi last month or so and it's still stabilizing, so you know what's next then 🙂

                                                                                  K D 3 Replies Last reply Reply Quote 4
                                                                                  • K
                                                                                    kallados @girish last edited by

                                                                                    @girish Jitsi? What is this 😄 alt text

                                                                                    1 Reply Last reply Reply Quote 0
                                                                                    • robi
                                                                                      robi last edited by

                                                                                      This may be useful for connecting devices/apps via WgVPN - https://github.com/stv0g/wiretrustee

                                                                                      Life of Advanced Technology

                                                                                      1 Reply Last reply Reply Quote 1
                                                                                      • robi
                                                                                        robi last edited by

                                                                                        Another OSS project that has a nice Wireguard integration - Mistborn
                                                                                        https://gitlab.com/cyber5k/mistborn

                                                                                        Life of Advanced Technology

                                                                                        1 Reply Last reply Reply Quote 2
                                                                                        • D
                                                                                          dylightful @girish last edited by

                                                                                          @girish bump

                                                                                          K 1 Reply Last reply Reply Quote 0
                                                                                          • K
                                                                                            kallados @dylightful last edited by

                                                                                            @dylightful Ping ^^

                                                                                            A 1 Reply Last reply Reply Quote 1
                                                                                            • A
                                                                                              ApplegateR @kallados last edited by

                                                                                              @kallados
                                                                                              https://github.com/ngoduykhanh/wireguard-ui

                                                                                              Pretty neat on this one. Because it already made on web gui.

                                                                                              Richard Applegate
                                                                                              Anthem Coffee and Tea
                                                                                              The Joint Chiropractic
                                                                                              IT/Administrator Server/Network

                                                                                              1 Reply Last reply Reply Quote 2
                                                                                              • marcusquinn
                                                                                                marcusquinn last edited by

                                                                                                Even more useful now Contabo has a UK location, we can use this for our Hetzner Gemany hosted VDIs to tunnel out to the web in the UK for a better localised experience for our primarily UK users.

                                                                                                We're not here for a long time - but we are here for a good time :)
                                                                                                Jersey/UK
                                                                                                Work & Ecommerce Advice: https://brandlight.org
                                                                                                Personal & Software Tips: https://marcusquinn.com

                                                                                                jdaviescoates 1 Reply Last reply Reply Quote 3
                                                                                                • jdaviescoates
                                                                                                  jdaviescoates @marcusquinn last edited by

                                                                                                  @marcusquinn said in Wireguard VPN:

                                                                                                  we can use this for our Hetzner Gemany hosted VDIs to tunnel out to the web in the UK for a better localised experience for our primarily UK users.

                                                                                                  That's sounds interesting, could you please elaborate?

                                                                                                  As an aside, Contabo don't use renewable energy, which makes them climate criminals in my mind.

                                                                                                  Here are the cheapest renewably powered VPS in UK I've found so far (in order of cheapness)

                                                                                                  https://www.vpsserver.com/vps-london/
                                                                                                  https://krystal.uk/cloud-vps
                                                                                                  https://cloudabove.com/hosting/cloud-servers

                                                                                                  I use Cloudron with Gandi & Hetzner

                                                                                                  1 Reply Last reply Reply Quote 1
                                                                                                  • D
                                                                                                    dylightful @girish last edited by

                                                                                                    @girish said in Wireguard VPN:

                                                                                                    so you know what's next then

                                                                                                    Can we please get an update on Wireguard? Seems to be a lot of apps getting published that don't have anywhere near the number of votes as WG....

                                                                                                    girish 1 Reply Last reply Reply Quote 2
                                                                                                    • girish
                                                                                                      girish Staff @dylightful last edited by

                                                                                                      @dylightful Yes, on our list. After 7.2 is completely rolled out (should be out later today).

                                                                                                      Is your use case the same as the existing OpenVPN app use case? i.e a self service portal where Cloudron acts as the VPN server?

                                                                                                      marcusquinn D 3 Replies Last reply Reply Quote 0
                                                                                                      • marcusquinn
                                                                                                        marcusquinn @girish last edited by marcusquinn

                                                                                                        @girish Our use-case would be using some mini-Cloudrons as relays for traffic from VDIs, so the users appear to be browsing from the country they are in, as opposed to where the VDI VPS is hosted.

                                                                                                        We're not here for a long time - but we are here for a good time :)
                                                                                                        Jersey/UK
                                                                                                        Work & Ecommerce Advice: https://brandlight.org
                                                                                                        Personal & Software Tips: https://marcusquinn.com

                                                                                                        1 Reply Last reply Reply Quote 0
                                                                                                        • D
                                                                                                          dylightful @girish last edited by

                                                                                                          @girish Exactly like the OpenVPN app, Wireguard will provide MUCH better speed!

                                                                                                          1 Reply Last reply Reply Quote 3
                                                                                                          • T
                                                                                                            timka last edited by

                                                                                                            Ok, so this would be an alternative to the avaible OpenVPN App?
                                                                                                            Then I suggest a look into firezone, @git it seems like a nice slim manager with gui. But well it's quite new and I do not know about the license.

                                                                                                            1 Reply Last reply Reply Quote 2
                                                                                                            • marcusquinn
                                                                                                              marcusquinn last edited by

                                                                                                              For interest: ivpn.net comes recommended on privacytools.io with Wireguard very easily implemented and, formerly, I always found the Wireguard speed on azirevpn.com to be very fast.

                                                                                                              We're not here for a long time - but we are here for a good time :)
                                                                                                              Jersey/UK
                                                                                                              Work & Ecommerce Advice: https://brandlight.org
                                                                                                              Personal & Software Tips: https://marcusquinn.com

                                                                                                              1 Reply Last reply Reply Quote 2
                                                                                                              • D
                                                                                                                dylightful @girish last edited by

                                                                                                                @girish said in Wireguard VPN:

                                                                                                                After 7.2 is completely rolled out (should be out later today).

                                                                                                                Bump

                                                                                                                T 1 Reply Last reply Reply Quote 2
                                                                                                                • T
                                                                                                                  timka @dylightful last edited by

                                                                                                                  A nice list:
                                                                                                                  https://github.com/HarvsG/WireGuardMeshes

                                                                                                                  1 Reply Last reply Reply Quote 1
                                                                                                                  • robi
                                                                                                                    robi last edited by

                                                                                                                    An example config of WG-Easy deployment from:
                                                                                                                    https://github.com/WeeJeWel/wg-easy/wiki/Using-WireGuard-Easy-with-nginx-SSL

                                                                                                                    docker-compose.yml:

                                                                                                                    version: "3.8"
                                                                                                                    
                                                                                                                    services:
                                                                                                                      wg-easy:
                                                                                                                        environment:
                                                                                                                          # ⚠️ Change the server's hostname (clients will connect to):
                                                                                                                          - WG_HOST=wg-easy.myhomelab.com
                                                                                                                    
                                                                                                                          # ⚠️ Change the Web UI Password:
                                                                                                                          - PASSWORD=foobar123
                                                                                                                        image: weejewel/wg-easy
                                                                                                                        container_name: wg-easy
                                                                                                                        hostname: wg-easy
                                                                                                                        volumes:
                                                                                                                          - ~/.wg-easy:/etc/wireguard
                                                                                                                        ports:
                                                                                                                          - "51820:51820/udp"
                                                                                                                        restart: unless-stopped
                                                                                                                        cap_add:
                                                                                                                          - NET_ADMIN
                                                                                                                          - SYS_MODULE
                                                                                                                        sysctls:
                                                                                                                          - net.ipv4.ip_forward=1
                                                                                                                          - net.ipv4.conf.all.src_valid_mark=1
                                                                                                                    
                                                                                                                      nginx:
                                                                                                                        image: weejewel/nginx-with-certbot
                                                                                                                        container_name: nginx
                                                                                                                        hostname: nginx
                                                                                                                        ports:
                                                                                                                          - "80:80/tcp"
                                                                                                                          - "443:443/tcp"
                                                                                                                        volumes:
                                                                                                                          - ~/.nginx/servers/:/etc/nginx/servers/
                                                                                                                          - ./.nginx/letsencrypt/:/etc/letsencrypt/
                                                                                                                    

                                                                                                                    ~/.nginx/servers/wg-easy.conf:

                                                                                                                    server {
                                                                                                                        server_name `⚠️wg-easy.myhomelab.com`;
                                                                                                                    
                                                                                                                        location / {
                                                                                                                            proxy_pass http://wg-easy:51821/;
                                                                                                                            proxy_http_version 1.1;
                                                                                                                            proxy_set_header Upgrade $http_upgrade;
                                                                                                                            proxy_set_header Connection "Upgrade";
                                                                                                                            proxy_set_header Host $host;
                                                                                                                        }
                                                                                                                    }
                                                                                                                    

                                                                                                                    Life of Advanced Technology

                                                                                                                    D 1 Reply Last reply Reply Quote 5
                                                                                                                    • D
                                                                                                                      dylightful @robi last edited by

                                                                                                                      @robi lots of solutions/apps for WG on the web, not entitely sure whats stopping/preventing the CLoudron team packaging and deploying considerings it one of the most upvoted wishlist items currently, especially when plenty of low upvote apps are getting published before WG.

                                                                                                                      Care to enlight us? @girish

                                                                                                                      timconsidine robi 2 Replies Last reply Reply Quote 1
                                                                                                                      • timconsidine
                                                                                                                        timconsidine App Dev @dylightful last edited by

                                                                                                                        @dylightful possibly the low vote apps don't have the complexity of integration into the Cloudron 'opinionated' environment. But I don't know really.

                                                                                                                        1 Reply Last reply Reply Quote 1
                                                                                                                        • robi
                                                                                                                          robi @dylightful last edited by

                                                                                                                          @dylightful I hear you.. it has not been made clear yet.

                                                                                                                          I just managed to deploy wg-easy in fly.io and it's simple UI is great, doesn't need a username, and similar to our OpenVPN app, easily generates .conf files for download for the clients.

                                                                                                                          For some of the things we wanted to do with VPNs for Apps which were a lot more complex, a lot more integrations were needed, and the people who started doing those didn't manage to complete them and the chain of events stopped progress.

                                                                                                                          What we perceive being reality, this can affect much simpler things from being re-prioritized; and of course life happens.

                                                                                                                          Un/fortunately those are not blockers for Cloudron having a fast personal VPN experience via Wireguard.

                                                                                                                          As I have a bit more time this month, I may start packaging wg-easy, and if someone else is interested in lending a helping hand, many hands make short work. (Send a PM to collaborate)

                                                                                                                          Life of Advanced Technology

                                                                                                                          T 1 Reply Last reply Reply Quote 6
                                                                                                                          • T
                                                                                                                            timka @robi last edited by timka

                                                                                                                            @robi wg-easy seems to be a nice alternative to the openvpn solution, it's also dockered: https://hub.docker.com/r/weejewel/wg-easy but I'm not sure how stable it is?

                                                                                                                            robi D 2 Replies Last reply Reply Quote 2
                                                                                                                            • First post
                                                                                                                              Last post
                                                                                                                            Powered by NodeBB