The Headscale project is developing an open server for the distributed VPN network Tailscale

The Headscale project develops an open-source implementation of the server component of the Tailscale VPN network, allowing the creation of Tailscale-like VPN networks on one's own infrastructure without relying on third-party services. The Headscale code is written in Go and distributed under the BSD license. The project is developed by Juan Font Alonso from the European Space Agency.

Tailscale enables the integration of any number of geographically dispersed hosts into a single network, designed in a mesh network structure, where each node interacts with other nodes directly (P2P) or through adjacent nodes, without traffic passing through centralized external servers. VPN-provider. It supports access and route management based on ACLs. To establish communication channels in the presence of Network Address Translators (NAT), it provides support for STUN, ICE, and DERP mechanisms (similar to TURN but based on HTTPS). In the event of a communication block between specific nodes, the network can reconfigure routing to direct traffic through other nodes.

The Headscale project is developing an open server for the distributed VPN network Tailscale

Tailscale differs from the Nebula project, also designed for creating distributed VPN networks with mesh routing, by using the Wireguard protocol for data transfer between nodes, whereas Nebula utilizes technologies from the Tinc project, which employs the AES-256-GCM algorithm for packet encryption (Wireguard uses the ChaCha20 cipher, which demonstrates higher throughput and responsiveness in tests).

Another similar project, Innernet, is also being developed, which uses the Wireguard protocol for data exchange between nodes. Unlike Tailscale and Nebula, Innernet employs a different access control system, based not on ACLs with tags assigned to individual nodes but on subnet segmentation and allocation of different ranges, akin to traditional Internet networks. Additionally, instead of Go, Innernet uses Rust. Three days ago, an update to Innernet 1.5 was released, enhancing support for NAT traversal. There is also a project called Netmaker, which allows the integration of networks with different topologies using Wireguard, but its code is released under the SSPL (Server Side Public License), which is not open due to discriminatory requirements. (the key to connect to is specified, and iroh finds the associated host and establishes an encrypted connection using the QUIC protocol). Direct P2P connections are established whenever possible, but if not, it falls back to using relays, which are also employed for host discovery by keys. You can run your own relay or connect to public relays supported by the community., similar to regular internet networks. Additionally, instead of the Go language, Innernet uses Rust. Three days ago, Innernet 1.5 was released with improved NAT traversal support. There is also a project called Netmaker that allows connecting networks with different topologies using Wireguard, but its code is distributed under the SSPL (Server Side Public License), which is not open due to its discriminatory requirements.

Tailscale operates using a Freemium model, allowing free use for individuals and paid access for businesses and teams. The client components of Tailscale, except for graphical applications for Windows and macOS, are developed as open projects under the BSD license. The server software running on Tailscale's side, which facilitates authentication when connecting new clients, coordinates key management, and organizes communication between nodes, is proprietary. The Headscale project addresses this shortcoming by offering an independent open implementation of the server components of Tailscale.

The Headscale project is developing an open server for the distributed VPN network Tailscale

Headscale takes on the functions of exchanging node public keys, as well as performing IP address assignments and distributing routing tables between nodes. Currently, Headscale implements all core functionalities of a management server, except for supporting MagicDNS and Smart DNS. Specifically, it supports features such as node registration (including via web), adapting the network for adding or removing nodes, subnet segmentation using namespaces (one VPN network can be created for multiple users), enabling node access to subnets across different namespaces, routing management (including assigning exit nodes to access the external world), access segmentation through ACLs, and operating a DNS service.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster