New Hampshire Crossing
  • FAQ
  • Login
  • Public

    • Public
    • Groups
    • Recent tags
    • Popular
    • Directory

Conversation:

Notices

  1. kat (boneidol)'s status on Tuesday, 04-Jun-2019 08:32:19 EDT kat kat
    Remote profile options...
    I am thinking of changing my VPN to use wireguard on OpenWRT and Streisand on the server.  Currently I use ipsec, but think it would make more sense to automate the process of deploying the remote end with some scripts, and I don't feel like writing my own.   Also wireguard seems like it would take a lot of the complexity out of building a ipsec configuration, so.. that's why I…
    Tuesday, 04-Jun-2019 08:32:19 EDT from indy.im permalink

    Attachments

    1. boneidol-20190604-ostatus-xtyc.html
    1. kat (boneidol)'s status on Tuesday, 04-Jun-2019 08:40:02 EDT kat kat
      Remote profile options...
      Also I might reflash the router to the some more modern version of OpenWRT/LEDE ... if only I can remember what router it is, and how to do it.
      Tuesday, 04-Jun-2019 08:40:02 EDT from indy.im permalink
    2. kat (boneidol)'s status on Friday, 07-Jun-2019 09:19:15 EDT kat kat
      Remote profile options...
      I went with algo eventually - thanks _sizeofcat@mastodon.social , and transitioned over to using wireguard instead of ipsec. I tried to get the algo ipsec implementation working against openWRT 18.06.2 https://nhcrossing.com/url/88846 BUT ... As far as I could tell the strongswan implementation in OpenWRT has no support of elliptic curves, and the certificates and keys generated …
      Friday, 07-Jun-2019 09:19:15 EDT from indy.im permalink

      Attachments

      1. boneidol-20190607-ostatus-vcug.html
      1. kat (boneidol)'s status on Friday, 07-Jun-2019 09:19:36 EDT kat kat
        Remote profile options...
        I would have liked to use ipsec. Because previously I was doing a site to site ipsec so all hosts connected via that subnet could get use of the vpn.

        Anyway.. re-engineered the solution to use double NAT and wireguard PtP. Setting that up via Algo and OpenWRT was easy https://danrl.com/blog/2017/luci-proto-wireguard/ helped, and adding the new wireguard interface to the WAN zone on the openWRT firewall.
        Friday, 07-Jun-2019 09:19:36 EDT from indy.im permalink
        1. kat (boneidol)'s status on Friday, 07-Jun-2019 09:20:12 EDT kat kat
          Remote profile options...
          The only thing left to do then was set up a bunch of port forwards from the VPN endpoint AND on the OpenWRT router, so I can get my bittorrent and SSH into the home LAN to work. The FW rule set on Algo seemed simpler to work with than the one that came with Streisand too. Streisand used UFW ( uncomplicated Fw) to wrap te IPTables config which I found quite complicated. ????♀️ …
          Friday, 07-Jun-2019 09:20:12 EDT from indy.im permalink

          Attachments

          1. boneidol-20190607-ostatus-hhvj.html

Feeds

  • Activity Streams
  • RSS 2.0
  • Atom
  • Help
  • About
  • FAQ
  • Privacy
  • Source
  • Version
  • Contact

New Hampshire Crossing is a GNU social hub. It runs version 1.1.3-beta3, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All New Hampshire Crossing content and data are available under the Creative Commons Attribution 3.0 license.

Switch to mobile site layout.