Minutes 2025-02-20
Jump to navigation
Jump to search
- Allen's Awesome Wiregaurd/Openvpn talk!
- Used with pfsense
- Openvpn for admin's, Wireguard is better for users
- You have to manage your own keys in Wireguard
- Interfaces are where you define your subnets
- technically not a server when it comes to Wireguard (only "peers")
- Wireguard wants you to be active 24/7 unless you use keep-alive packets
- Can set a dynamic endpoint compared to a specified endpoint
- Set endpoint allow you to do full mesh
- dymanic is for floating client's such as cellular clients or laptops (cant port forward!)
- Wireguard uses two way asymetric cryptography (w/an optional symmetric shared key for quantum resistance)
- uses the idea of public and private keys but with packets instead
- Wireguard uses UDP, no TCP to be found
- when making a homelab, pick a random port for Wireguard which will make it invisible to port scans (does not respond to invalid traffic)
- Off topic stuff
- OpenMhz is a cool place to check out
- historically poor documentation for WMTU