‹ BackHN Continuity

Thread

Making Tailscale Faster

250 points · 112 comments · yarapavan

  1. apenwarr · · focus · HN ↗
    (Tailscale cofounder) I see a few comments here that using kernel wireguard would make it faster; it’s not really that simple. In fact, for a while (and we wrote a blog post about it), our optimizations made wireguard-go faster than kernel wireguard because it was better optimized. They adopted some of those improvements and now we’re on to the next order of magnitude together.

    For really high bandwidth cases, things like DPDK are the long term best choice and are primarily userspace, for good reasons. Kernel mode is not the pure benefit it once was (if it ever was).

    Separately, wireguard itself has a problem that the crypto suite it uses is not supported by hardware accelerators. So if we want to get into the hundreds of gigabits range, we will possibly need to switch packet formats entirely. (But, wireguard also needs to update to support post-quantum so maybe they’ll fix both problems at the same time and we can join in.)

    1. xingped · · focus · HN ↗
      Hey why do you hard code certain android apps to be excluded from Tailscale with split tunneling without giving users any way to disable split tunneling for these apps? It doesn't matter how you think VPN does or does not affect these apps, it's really awful anti-user behavior.
      1. user3939382 · · focus · HN ↗

        [dead]

        1. close04 · · focus · HN ↗
          > Notice the no response, they know what they’re doing and they don’t care.

          I was with you in principle until this part. You gave them ~30 minutes before claiming "no answer".

          1. user3939382 · · focus · HN ↗
            Fair let’s see.
          2. tecleandor · · focus · HN ↗
            Also, if Apenwarr is in Quebec, it was like 2am when he launched his question. He might be sleeping and all that ...
          3. beng-nl · · focus · HN ↗
            Isn’t it a bit soon to call Tailscale a giant corporation?
        2. sauercrowd · · focus · HN ↗
          > Layer 2 VPN is where it’s at anyway. I want to be on my LAN not managing one device or app at a time, I never got the wireguard hype.

          You can do that though? Tailscale can as well. A device can advertise subnets, and can route them through tailscale, so you just need a single node in a LAN.

          1. soulbadguy · · focus · HN ↗
            > A device can advertise subnets, and can route them through tailscale

            This is still L3 layer though. One the main use case of L2 is proper DHCP propagation and avoid subnet collisions. I do not think that this matters in practices though. Only a limited amount of user facing service require proper L2 emulation (apple TVs ?)

            1. user3939382 · · focus · HN ↗
              Or anything that uses multicast. The idea is you want homoiconic networking behavior and portability between local and remote. Hacking in special routing and subnets in L3 doesn’t give you that.
              1. _bernd · · focus · HN ↗
                Or use multicast routes...
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.