TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Tinc, a GPLv2 mesh routing VPN

212 点作者 azalemeth将近 2 年前

20 条评论

buserror将近 2 年前
Been using tinc for god knows how long... Perhaps 20 years? It&#x27;s been fantastic. I really don&#x27;t know why people are wax-lyrical about wireguard. tinc was doing it 20 years ago. UDP? yeah. encryption, mesh, proxy ARP you name it. I&#x27;ve had countless install and it&#x27;s been the best VPN.<p>You even get a &#x27;dot&#x27; graph of your current network status if you want to. When &#x27;git&#x27; was invented, I put my &#x2F;etc&#x2F;tinc&#x2F;*&#x2F; into git with the public keys, and installing a new host to the mesh is one &#x27;git clone&#x27; away.<p>Most underrated open source software ever.
评论 #36498176 未加载
评论 #36496031 未加载
评论 #36493461 未加载
评论 #36493705 未加载
评论 #36494965 未加载
gcommer将近 2 年前
Tinc is incredible, it has worked flawlessly for me for 6+ years with exactly 0 maintenance.<p>As trustworthy as it is, I am sadly on the hunt to replace it. Compared to wireguard, the throughput ain&#x27;t great, and it takes way too much CPU on my low power nodes. I would pay good money for &quot;tinc, but with wireguard transport&quot; -- there&#x27;s of course projects purporting to do this but I haven&#x27;t found one I trust yet.
评论 #36494056 未加载
评论 #36498034 未加载
评论 #36493448 未加载
评论 #36492689 未加载
评论 #36493781 未加载
评论 #36493724 未加载
mgbmtl将近 2 年前
Aren&#x27;t there concerns around the encryption used by Tinc? (<a href="https:&#x2F;&#x2F;www.tinc-vpn.org&#x2F;documentation&#x2F;Security.html#Security" rel="nofollow noreferrer">https:&#x2F;&#x2F;www.tinc-vpn.org&#x2F;documentation&#x2F;Security.html#Securit...</a>)<p>It&#x27;s probably fine for personal projects though, and indeed simple and very flexible (maybe too much), well suited for connecting IoT devices.
评论 #36496436 未加载
评论 #36496515 未加载
评论 #36496389 未加载
johnklos将近 2 年前
One of the nicest things about tinc is how little attention it needs. It starts on boot, and no matter if the connection between two points drops, or one end gets a new address, or connects via IPv6 instead of IPv4, or restarts, the connection just always comes back up magically, without any futzing. There are many other tunneling methods that don&#x27;t do this.<p>I used to provide a tunnel using tinc via a MIPS-based Cobalt RaQ. Throughput was surprisingly good, even on an old 250 MHz CPU, so even though I hear people talking about needing something faster, I can&#x27;t imagine other tunneling methods being measurably faster, unless they&#x27;re using weaker encryption. I&#x27;d benchmark it some time, but the slowest NanoPis that I use for tunnels these days can push many times more traffic through tinc than their Internet connections will allow. I&#x27;d be curious to see anyone else&#x27;s comparisons, though.
wener将近 2 年前
Tinc can work on L2, which means works like switch, means it can works like an cable between any nodes.It doesn&#x27;t need an ip, you can make a bridge. There is no known good replacement for this.<p>The down side is<p>- single thread (perf has limits in 10gbe)<p>- userspace (wg can works in kernel)<p>- 1.1 is stable enough, but still may crash, be careful<p>You may also interested in n2n
评论 #36498455 未加载
评论 #36505367 未加载
LanternLight83将近 2 年前
Personally, I&#x27;ve been building my mesh network up over Yggdrasil[1]. A router can even hand out Ygg IP&#x27;s, resolve traffic for-, and firewall off- naive IOT devices (neccessary if you route through the public mesh, which isn&#x27;t the only way to set things up).<p>1: <a href="https:&#x2F;&#x2F;yggdrasil-network.github.io&#x2F;" rel="nofollow noreferrer">https:&#x2F;&#x2F;yggdrasil-network.github.io&#x2F;</a>
评论 #36496559 未加载
评论 #36496518 未加载
fhkdfjgh将近 2 年前
one killer feature tinc has is a poor man&#x27;s anycast<p>you can assign an ip to any number of nodes and tinc will talk to the one with the lowest latency. i&#x27;ve used this to run globally distributed dns on a tinc network
评论 #36494750 未加载
评论 #36494356 未加载
评论 #36495085 未加载
RainbowFriends将近 2 年前
Slack&#x27;s Nebula is another great open source mesh VPN application: <a href="https:&#x2F;&#x2F;github.com&#x2F;slackhq&#x2F;nebula">https:&#x2F;&#x2F;github.com&#x2F;slackhq&#x2F;nebula</a>
bvrmn将近 2 年前
Tinc is a perfect tool to make a VPN mesh across different clouds&#x2F;hosters. Been using it for 5 years. It&#x27;s so much easier in support comparing with ipsec madness.
guerby将近 2 年前
Switched from openvpn to tinc after openvpn certificate expired after 10 years (default duration of creation script) and I lost connection to my family computers, so I had to drive a few hundred kilometers<p>Nearly 8 years ago, still running:<p><pre><code> $ ls -l &#x2F;etc&#x2F;tinc&#x2F;guerby1&#x2F;tinc.conf -rw-r--r-- 1 root root 51 Jul 31 2015 &#x2F;etc&#x2F;tinc&#x2F;guerby1&#x2F;tinc.conf</code></pre>
aim4min将近 2 年前
Sounds very similar to how SyncThing. I would if the SymcThing discovery and NAT traversal could be combined with wireguard and the ease of tailscale, but distributed mesh and no headscale. And all the other things that tinc does.
jrm4将近 2 年前
It&#x27;s always odd to me when people point out lack of updates (without context) as evidence of a problem? I&#x27;m a regular user of Tinc and Openbox.<p>They&#x27;re mostly finished products. That&#x27;s why few updates. It&#x27;s nice.
dspillett将近 2 年前
Interesting, though I&#x27;m slightly concerned by the lack of activity in the last two years. Is the project still alive in that respect?
yuedongze将近 2 年前
Are there any good performance tests done between Tinc and WG? Curious to see how they perform and what there bottlenecks are.
FullyFunctional将近 2 年前
I’d love to understand how this compares to Zerotier, Wireguard, Tailscale, Nebula, …<p>I use Zerotier because simplicity, cost, and iOS support matters more for me than speed, but I’m curious about alternatives (WG seemed much easier for me to screw up)
Fizzadar将近 2 年前
Another huge Tinc fan here. Used it in prod for 5 or so years before switching to zerotier for easier management as we grew. Tinc is rock solid and dead easy to configure.
yonrg将近 2 年前
I used the 1.0 branch for years. It was just running and was there when needed. It never got in the way.<p>I see, 1.1 is still pre release.
jis将近 2 年前
Another tool to look at is vpncloud (<a href="https:&#x2F;&#x2F;github.com&#x2F;dswd&#x2F;vpncloud">https:&#x2F;&#x2F;github.com&#x2F;dswd&#x2F;vpncloud</a>). It also builds a mesh network over UDP. Key setup is a bit easier, static keys are only used for authentication. Encryption keys are dynamically generated and replaced on a schedule.<p>I combine it with an ansible script to push out the (minimal) configuration to end nodes.
评论 #36494461 未加载
account-5将近 2 年前
Noob question but how easy is this to set up? How does it compare to Nord meshnet?
renaudg将近 2 年前
Besides being free software, how does this differ from Tailscale ?
评论 #36495533 未加载