News: 1628003371

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

WireGuard VPN gets native port to the Windows kernel

(2021/08/03)


WireGuard, a high performance and easily configured VPN protocol, is getting a native port from Linux to the Windows kernel, and the code has been published as experimental work in progress.

A WireGuard implementation for Windows already exists and can be found [1]here , based on what Jason A Donenfeld, the creator of WireGuard, [2]called "a generic TUN driver we developed called Wintun" and a cross-platform Go codebase called wireguard-go.

This current implementation "lives in userspace, and shepherds packets to and from the Wintun interface," Donenfeld said. The goal with the new implementation, called WireGuardNT, is that the whole protocol implementation will be in the Windows networking stack, "in the same way that it's done currently on Linux, OpenBSD, and FreeBSD."

[3]

Donenfeld went into detail about how the existing version compromises performance, even though he said it is "decently fast." He also said there are serious problems with WireGuard's current Windows performance when the VPN is connected over Wi-Fi. "Users commonly see massive slowdowns," he explained, because of latency. One user of the experimental code reported the following figures:

Wireguard-go/Wintun over wired Ethernet: 600Mbps

Wireguard-go/Wintun over Wi-Fi: 95Mbps

WireGuardNT over Wi-Fi: 600Mbps

The [4]WireGuardNT repository is full of warnings about "experimental, unfinished, work in progress... Do not use it!... a wheel or two are likely missing, in addition to, perhaps, the entire crankshaft." However, Donenfeld said that WireGuard for Windows (the official implementation using wireguard-go, as linked above) already includes WireGuardNT, as an optional alternative. He said he envisages three phases of deployment. Currently users have to set an ExperimentalKernelDriver registry key in order to use WireGuardNT. In phase two it will be on by default, but possible to disable, while in phase three, wireguard-go/Wintun will be removed.

[5]

It works: Activating a WireGuard tunnel using the new experimental driver

Donenfeld stated that "for the Windows platform, this project is a big deal to me, as it marks the graduation of WireGuard to being a serious operating system component, meant for more serious usage."

Users have praised WireGuard's ease of setup as well as its performance and the fact that the protocol has undergone [6]formal verification . In August 2018, Linus Torvalds [7]said : "Can I just once again state my love for it and hope it gets merged soon? Maybe the code isn't perfect, but I've skimmed it, and compared to the horrors that are OpenVPN and IPSec, it's a work of art." He then merged WireGuard into the Linux kernel [8]in January last year for version 5.6.

[9]

With Torvalds quick to embrace WireGuard for Linux, where is Microsoft when it comes to Windows? "I've never seen the built-in Windows VPN protocols exceed ~70Mbps in any scenario," [10]said a user on Hacker News, asking why volunteers have come up with something that is "ONE HUNDRED TIMES faster than the best Microsoft can offer to their hundreds of millions of enterprise customers that are working from home." ®

Get our [11]Tech Resources



[1] https://git.zx2c4.com/wireguard-windows/about/

[2] https://lists.zx2c4.com/pipermail/wireguard/2021-August/006887.html

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/oses&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YQloOoqNa1iZ0UmOwEg2zQAAAMM&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[4] https://git.zx2c4.com/wireguard-nt/about/

[5] https://regmedia.co.uk/2021/08/03/wireguard.png

[6] https://www.wireguard.com/formal-verification/

[7] https://lkml.org/lkml/2018/8/2/663

[8] https://www.theregister.com/2020/01/29/wireguard_vpn_will_be_in_linux_56_kernel/

[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/oses&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YQloOoqNa1iZ0UmOwEg2zQAAAMM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[10] https://news.ycombinator.com/item?id=28044020

[11] https://whitepapers.theregister.com/



Ace VPN!

John Sager

I've been using it for some years now on Android and Linux in a road-warrior setup, and after messing about with IPSec on Linux and Cisco, WireGuard is a lot easier to set up. Reading the mailing list it's getting lots of use by others for secure virtual networks over the top of the Internet.

Dear Emily, what about test messages?
-- Concerned

Dear Concerned:
It is important, when testing, to test the entire net. Never test
merely a subnet distribution when the whole net can be done. Also put "please
ignore" on your test messages, since we all know that everybody always skips
a message with a line like that. Don't use a subject like "My sex is female
but I demand to be addressed as male." because such articles are read in depth
by all USEnauts.
-- Emily Postnews Answers Your Questions on Netiquette