tinc VS wg-meshconf

Compare tinc vs wg-meshconf and see what are their differences.

Our great sponsors
  • WorkOS - The modern identity platform for B2B SaaS
  • InfluxDB - Power Real-Time Data Analytics at Scale
  • SaaSHub - Software Alternatives and Reviews
tinc wg-meshconf
19 6
1,837 877
- -
5.6 0.0
19 days ago 15 days ago
C Python
GNU General Public License v3.0 or later GNU General Public License v3.0 only
The number of mentions indicates the total number of mentions that we've tracked plus the number of user suggested alternatives.
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.

tinc

Posts with mentions or reviews of tinc. We have used some of these posts to build our list of alternatives and similar projects. The last one was on 2023-10-13.
  • Would we still create Nebula today?
    14 projects | news.ycombinator.com | 13 Oct 2023
    But both Nebula and tinc max out at around 1 Gbit/s on my Hetzner servers, thus not using most of my 10 Gbit/s connectivity. This is because they cap out at 100% of 1 CPU. The Nebula issue about that was closed due to "inactivity" [2].

    I also observed that when Nebula operates at 100% CPU usage, you get lots of package loss. This causes software that expects reasonable timings on ~0.2ms links to fail (e.g. consensus software like Consul, or Ceph). This in turn led to flakiness / intermittent outages.

    I had to resolve to move the big data pushing softwares like Ceph outside of the VPN to get 10 Gbit/s speed for those, and to avoid downtimes due to the packet loss.

    Such software like Ceph has its own encryption, but I don't trust it, and that mistrust was recently proven right again [3].

    So I'm currently looking to move the Ceph into WireGuard.

    Summary: For small-data use, tinc and Nebula are fine, but if you start to push real data, they break.

    [1]: https://github.com/gsliepen/tinc/issues/218

    [2]: https://github.com/slackhq/nebula/issues/637

    [3]: https://github.com/google/security-research/security/advisor...

  • Which overlay network?
    6 projects | /r/selfhosted | 13 Jul 2023
    11 projects | /r/selfhosted | 28 Jan 2022
  • Tailscale/golink: A private shortlink service for tailnets
    10 projects | news.ycombinator.com | 13 Dec 2022
    From a purely networking perspective, there are far better solutions than tailscale.

    Have a look at full mesh VPNs like:

    https://github.com/cjdelisle/cjdns

    https://github.com/yggdrasil-network/yggdrasil-go

    https://github.com/gsliepen/tinc

    https://github.com/costela/wesher

    These build actual mesh networks where every node is equal and can serve as a router for other nodes to resolve difficult network topologies (where some nodes might not be connected to the internet, but do have connections to other nodes with an internet connection).

    Sending data through multiple routers is also possible. They also deal with nodes disappearing and change routes accordingly.

    tailscale (and similar solutions like netbird) still use a bunch of "proxy servers" for that. You can set them up on intermediate nodes, but that have to be dealt with manually (and you get two kinds of nodes).

  • Tunneling to Synology NAS without opening ports.
    3 projects | /r/synology | 3 Aug 2022
    Two other options are Tinc https://tinc-vpn.org/ or Nebula https://www.defined.net/nebula/
  • Port Forward Security & Alternatives
    9 projects | /r/selfhosted | 21 Jun 2022
    And there is Tinc; the OG overlay network. I don't have experience with this. Seemed a bit of a pain to setup. https://tinc-vpn.org
  • WireGuard multihop available in the Mullvad app
    3 projects | news.ycombinator.com | 12 Apr 2022
    For what its worth I have used the open source Tinc VPN [1] for mesh multihop routing for ages. It is nowhere near as fast as Wireguard but I could envision Tinc incorporating support for Wireguard if the author were so inclined. Like you mentioned Tinc does not mesh with other VPN's AFAIK.

    [1] - https://tinc-vpn.org/

  • You may not need Cloudflare Tunnel. Linux is fine
    1 project | news.ycombinator.com | 8 Apr 2022
    This is actually very simple in concept and is just as simple or even simpler to do with tinc (https://tinc-vpn.org).

    Since I can use tinc in bridge mode, I can run tinc on the upstream server and on a local machine which then provides access to several physical machines without running extra software on each of those machines, which is particularly useful for machines that are resource limited, like my Macintosh LC II and LC III+:

    http://elsie.zia.io/

    It'd be nice if it weren't so difficult to get public addresses.

  • Tinc Is Not Catan
    5 projects | news.ycombinator.com | 9 Feb 2022
    I clicked expected some broken analogy between https://tinc-vpn.org/ and the Catan board game, but instead it is a Catan implementation. Fair enough.
  • Graphviz: Open-source graph visualization software
    40 projects | news.ycombinator.com | 17 Jan 2022
    will generate a real-time network graph using the Graphviz DOT language. It's a cool feature that I find quite useful.

    [0] https://tinc-vpn.org/

wg-meshconf

Posts with mentions or reviews of wg-meshconf. We have used some of these posts to build our list of alternatives and similar projects. The last one was on 2022-09-03.
  • Wireguard mesh between 4 pc similar to Tailscale
    4 projects | /r/selfhosted | 3 Sep 2022
  • Updated MinIO NVMe Benchmarks: 2.6Tpbs on Get and 1.6 on Put
    3 projects | news.ycombinator.com | 4 Jan 2022
    my experience, i dont know if this is comparable, but from my memory (i have not made any notes on that), i've tried min.io in december and switched to seaweed a weeks ago, because my usecase was transition from local file storage to DFS + also enable our developers to transition from local filesystem to s3. Since my resources are limited (vsphere VM) with 3 hosts + different disks, i tried to set up a 3 vm cluster with minio first, after i did some research on different systems (ceph, longhorn.io, ..) i wanted to have an easy setup-able system, which supports s3. I relied a lot on what people measured and chose min.io first because it supported mount via s3. Then i tried to copy over about 34 million files (mostly few bytes, but can also be 1Gbyte), with a mass of about 4.2TB. I tried different methods, rsync, cp, cp with parallelism,.. and i took me about 3 days to copy over 300GB of data at best. Then i also found out that it was impossible to list files. We have one single folder with over 300k projects (guid) beneath (growing). After that i gave seaweed a shot. Why i did not used it firsthand was documentation was a bit confusing and it did not gave me all the answers i needed as fast as minio did.

    Now, my seaweed setup is a 3 vm cluster with 3 disks per vm (1TB) each. I configured a wireguard mesh (https://github.com/k4yt3x/wg-meshconf) between the VMs and configured master and volumes server to talk to each other via wireguard IPs securely. I also configured ufw to only allow communication between http/gRPC ports. I also configured a filer (using leveldb3) to use wireguard IPs (master and volumes) and let it communicate with some specific servers on the outside (ufw).

    After that i mounted the filer via weed.mount on that specific server and tried to copy over the same files/folders. after 2 days i copied over about 1.5 TB of the data via rsync. There was also no problem with file listing and accessing the filer from different machines while uploading stuff. But there is a overhead when reading and creating lots of small files. File listing is even faster than local btrfs file listing.

    chris is also very nice and fast fixing bugs.

  • Connect to wireguard server over a wireguard server -> client connection
    1 project | /r/WireGuard | 12 Aug 2021
    Hey you should post your wg0.conf If you would like to build a WireGuard mesh try this: https://github.com/k4yt3x/wg-meshconf
  • How to add new client to wireguard in VPS without getting public IP changed on the client?
    2 projects | /r/WireGuard | 30 Jul 2021
    There are two factors at play here. The client's public IP actually depends on the gateway they use on accessing the internet. You can disable routing and your clients will keep their public IP and general internet access won't go through the VPS. However, if you want the traffic between "clients" also skip the VPS, then you want a mesh network. wesher and wg-meshconf can help you on configuring them.
  • Wiretrustee: WireGuard-Based Mesh Network
    16 projects | news.ycombinator.com | 28 Jun 2021
    Looks great!

    I've been using wg-meshconf[1] to assist in setting up Wireguard Mesh Networks on Linux for a while, works amazing!

    A massive use case is to setup Kubernetes clusters, where network encryption is extremely important.

    [1]: https://github.com/k4yt3x/wg-meshconf

  • WireGuard full mesh configuration generator
    1 project | news.ycombinator.com | 29 Dec 2020

What are some alternatives?

When comparing tinc and wg-meshconf you can also consider the following projects:

OpenVPN - OpenVPN is an open source VPN daemon

wesher - wireguard overlay mesh network manager

Nebula - A scalable overlay networking tool with a focus on performance, simplicity and security

headscale - An open source, self-hosted implementation of the Tailscale control server

ZeroTier - A Smart Ethernet Switch for Earth

cjdns - An encrypted IPv6 network using public-key cryptography for address allocation and a distributed hash table for routing.

SoftEther - Cross-platform multi-protocol VPN software. Pull requests are welcome. The stable version is available at https://github.com/SoftEtherVPN/SoftEtherVPN_Stable.

netbird - Connect your devices into a single secure private WireGuard®-based mesh network with SSO/MFA and simple access controls.

tailscale - The easiest, most secure way to use WireGuard and 2FA.

Netmaker - Netmaker makes networks with WireGuard. Netmaker automates fast, secure, and distributed virtual networks.

dsnet - FAST command to manage a centralised wireguard VPN. Think wg-quick but quicker: key generation + address allocation.