←back to thread

196 points bratao | 1 comments | | HN request time: 0s | source
Show context
c0l0 ◴[] No.41085314[source]
This would have been such a great resource for me just a few weeks ago!

We wanted to have finally encrypt the L2 links between our DCs and got quotes from a number of providers for hardware appliances, and I was like, "no WAY this ought to cost that much!', and went off to try to build something myself that hauled Ethernet frames over a wireguard overlay network at 10Gbps using COTS hardware. I did pull it off after a tenday of work or so, undercutting the cheapest offer by about 70% (and the most expensive one by about 95% or so...), but there was a lot of intricate reading and experimentation involved.

I am looking forward to validate my understanding against the content of this article - it looks very promising and comprehensive at first and second glance! Thanks for creating and posting it.

replies(2): >>41085350 #>>41085983 #
pgraf ◴[] No.41085983[source]
If I may ask, what is your use case so that a L3 tunnel does not suffice?
replies(1): >>41092312 #
1. c0l0 ◴[] No.41092312[source]
We have a number of proprietary network appliances present in all connected locations that require unhampered L2 communication (for mostly dumb reasons I think, but what can you do...), unfortunately.