wireguard.lists.zx2c4.com archive mirror
 help / color / mirror / Atom feed
* TCP Tunneling (again sorry)
@ 2018-08-30 10:54 Ryan Walklin
  0 siblings, 0 replies; only message in thread
From: Ryan Walklin @ 2018-08-30 10:54 UTC (permalink / raw)
  To: wireguard

[-- Attachment #1: Type: text/plain, Size: 1805 bytes --]

Hi,

I appreciate this is a bit of a noob question not directly related to WireGuard and has been covered before, but I’m just hoping for a bit of advice and clarity. I’ve got a WireGuard tunnel up and running nicely between my MBP laptop and my Debian server at home and am hoping to use it as a VPN while travelling. 

However I’ve found an issue when my laptop is behind work firewalls which block UDP, and not wanting to be encountering this issue overseas have been looking at tunnelling options. I have been using a SOCKS proxy generated with OpenSSH up until now, but it’s difficult to route all my laptop’s traffic via the proxy.

I’m aware of SSF (https://securesocketfunneling.github.io/ssf <https://securesocketfunneling.github.io/ssf>) and udp2raw (https://github.com/wangyu-/udp2raw-tunnel/blob/master/doc/openvpn_guide.md <https://github.com/wangyu-/udp2raw-tunnel/blob/master/doc/openvpn_guide.md>) which has been covered on this list before (https://lists.zx2c4.com/pipermail/wireguard/2018-May/002915.html <https://lists.zx2c4.com/pipermail/wireguard/2018-May/002915.html>) but just wonder if anyone could comment on the specific security implication of using minimal or no security on the TCP tunnel mechanism (which seems poorly implemented by udp2raw particularly), and relying on the underlying WireGuard encryption? Or is this crazy? Is there any other satisfactory Unix-based mechanism to tunnel UDP over TCP?

I feel like if I run a WireGuard tunnel through an encrypted SSF tunnel I may as well just be using SSF by itself, however the ease of setting the default route on my laptop with wg-quick is a great feature and I am very impressed by the quality of WireGuard and the focus on security so would like to continue using it if possible.

Thanks,

Ryan

[-- Attachment #2: Type: text/html, Size: 2370 bytes --]

^ permalink raw reply	[flat|nested] only message in thread

only message in thread, other threads:[~2018-08-30 10:40 UTC | newest]

Thread overview: (only message) (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2018-08-30 10:54 TCP Tunneling (again sorry) Ryan Walklin

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).