Development discussion of WireGuard
 help / color / mirror / Atom feed
* The plan for road warrior access?
@ 2017-09-09 15:33 Wang Jian
  0 siblings, 0 replies; only message in thread
From: Wang Jian @ 2017-09-09 15:33 UTC (permalink / raw)
  To: Jason A. Donenfeld, WireGuard mailing list

Hi Jason,

Wireguard is great for site to site VPN, even in current early stage.
We will replace our IPSec deployment with wireguard, after the
multihome issue fixed. Thanks for your outstanding work.

For road warrior access, I think it's quite straghtforward to build an
SSL VPN around wireguard, to address these issues:
1. integration into existing authentication system (ldap, radius, oauth2, saml)
2. address pools, allocation of client address; multiple connections per user
3. pushing address, routing and dns config to client; split or full tunnel
4. ACLs

(The client.sh demo is an example)

But wireguard is in early stage, the mentioned functionalities can be
designed as part of wireguard and tools, protocols.

Wireguard is meant to obsolete IPSec and likes. How about your plan on
road warrior access?

^ permalink raw reply	[flat|nested] only message in thread

only message in thread, other threads:[~2017-09-09 15:07 UTC | newest]

Thread overview: (only message) (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2017-09-09 15:33 The plan for road warrior access? Wang Jian

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).