logoalt Hacker News

iscoelhoyesterday at 10:52 PM1 replyview on HN

VXLAN over WireGuard is acceptable if you require a shared L2 boundary.

IPSec over VXLAN is what I recommend if you are doing 10G or above. There is a much higher performance ceiling than WireGuard with IPSec via hardware firewalls. WireGuard is comparatively quite slow performance-wise. Noting Tailscale, since it has been mentioned, has comparatively extremely slow performance.

edit: I'm noticing that a lot of the other replies in this thread are not from network engineers. Among network engineers WireGuard is not very popular due to performance & absence of vendor support. Among software engineers, it is very popular due to ease of use.


Replies

kosolamyesterday at 11:16 PM

How is IPSec performance better than wg? I never heard this before, it sounds intriguing.

show 2 replies