Firezone — a solution for creating VPN servers based on WireGuard

The Firezone project is developing a VPN server to provide access to hosts within an internal isolated network from user devices located in external networks. The project aims to achieve a high level of security and simplify the process of deploying a VPN. The project's code is written in Elixir and Ruby and is distributed under the Apache 2.0 license.

The project is being developed by a security automation engineer from Cisco, who sought to create a solution that automates host configuration management and avoids the problems encountered when providing secure access to cloud VPCs. Firezone can be seen as an open alternative to OpenVPN Access Server, built on top of WireGuard instead of OpenVPN.

Installation offers rpm and deb packages for various versions of CentOS, Fedora, Ubuntu, and Debian, which do not require external dependencies since all necessary dependencies are already included using Chef Omnibus. The only requirement is a Linux distribution with a kernel no older than 4.19 and a compiled kernel module with VPN WireGuard. According to the author, launching and configuring the VPN server can be done in just a few minutes. The components of the web interface run under a non-privileged user, and access is only possible via HTTPS.

Firezone - a solution for creating VPN servers based on WireGuard

Firezone uses WireGuard to organize communication channels. Firezone also includes built-in firewall features utilizing nftables. Currently, the firewall is limited to functionalities for blocking outgoing traffic to specific hosts or subnets in internal or external networks. Management can be done through the web interface or via command line using the firezone-ctl utility. The web interface is based on Admin One Bulma.

Firezone - a solution for creating VPN servers based on WireGuard

Currently, all components of Firezone are running on a single server, but the project is initially developed with modularity in mind, and in the future, plans to add the capability to distribute components for the web interface, VPN, and firewall across different hosts. The plans also mention the integration of an ad blocker operating at the DNS level, support for host and subnet blocking lists, authentication options through LDAP / SSO, and additional user management features.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster