Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The idea of Phase3 is that you have multiple node routers connected to a VPN hub. Think branch offices. When one node starts to talk to another node, the Hub initially facilitates the traffic, but it sends a NHRP(Next Hop Resolution Protocol) packet to the nodes telling them the public IPs of eachother, the nodes then negotiate their own VPN tunnel and start communicating directly without passing all traffic through the hub.

If I understand wireguard correctly it seems NHRP could be run using wiregard for transport, but it would cool if a separate NHRP daemon wasn't required, especially since wiregard is already tracking the mapping of internal to public IPs.



Just as a dumb spectator: that sounds a lot like https://en.wikipedia.org/wiki/Interactive_Connectivity_Estab..., but below the application layer. Neat!




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: