Release of Nebula 1.9, a system for creating overlay P2P networks

The release of the Nebula 1.9 project has been published, offering tools for building secure overlay networks that allow geographically distributed hosts to be combined into a separate isolated network operating over the global network. The project is designed for creating your own overlay networks for various needs, such as uniting corporate computers in different offices, servers in various data centers, or virtual environments across different cloud providers. The code is written in Go and is distributed under the MIT license. The project is developed by Slack, the company behind the eponymous corporate messenger. It supports operation on Linux, FreeBSD, macOS, Windows, iOS, and Android.

Nodes in the Nebula network communicate directly with each other in P2P mode — as the need to transfer data between nodes arises, direct connections are dynamically created. VPN-connections. The identity of each host in the network is validated by a digital certificate, and connecting to the network requires authentication — each user receives a certificate confirming their IP address in the Nebula network, name, and membership in host groups. Certificates are signed by an internal certification authority deployed by the creator of each individual network on their own infrastructure and used to attest the credentials of hosts authorized to connect to a specific overlay network tied to the certification authority.

To create an authenticated secure communication channel in Nebula, a proprietary tunneling protocol is used, based on the Diffie-Hellman key exchange protocol and the AES-256-GCM cipher. The implementation of the protocol is based on ready-made and tested primitives provided by the Noise framework, which is also used in projects such as WireGuard, Lightning, and I2P. It is claimed that the project has undergone an independent security audit.

To discover other nodes and coordinate connections to the network, special 'lighthouse' nodes are created, whose global IP addresses are fixed and known to members of the network. Participant nodes have no binding to external IP address, they are identified by certificates. Host owners cannot independently modify signed certificates and, unlike traditional IP networks, cannot impersonate another host by simply changing the IP address. When creating a tunnel, the host's identity is confirmed by an individual private key.

A specific range of intranet addresses is allocated to the created network (for example, 192.168.10.0/24) and binds internal addresses to host certificates. Various mechanisms are provided to bypass address translators (NAT) and firewalls. It is possible to organize routing through an overlay network of third-party hosts not included in the Nebula network (unsafe route). Groups may be formed from the participants of the overlay network, for example, to separate servers and workstations, to which separate traffic filtering rules apply.

The creation of firewalls is supported to separate access and filter traffic between nodes in the Nebula overlay network. ACLs with tag bindings are used for filtering. Each host in the network can define its own filtering rules based on hosts, groups, protocols, and network ports. In this case, hosts are filtered not by IP addresses, but by verified digitally signed host identifiers that cannot be forged without compromising the certificate authority coordinating the network's operations.

In the new release:

  • A new setting, default_local_cidr_any, has been added, which changes the behavior when processing the 'local_ip' subnets in firewall rules to prevent unjustified traffic permissions to hosts listed in the unsafe_routes block. In version 1.9, the setting is set to 'true', but in the following release 1.10, it will be changed to 'false', which will take local subnets into account when applying firewall rules to hosts accessible through unsafe routes (access to such hosts will require mandatory specification of local_cidr).
  • An official image for the Docker system has been provided, allowing for the swift deployment of an overlay network based on Nebula or a node for it.
  • Experimental builds for the Loong64 architecture have been added.
  • A service script for the OpenRC initialization system has been implemented.
  • SSH background process now supports certificate-based authentication with trusted certificate authorities (sshd.trusted_cas). The ability to embed host keys in the sshd.host_key settings block has been implemented.
  • Support for reloading the settings for "tun.unsafe_routes" has been ensured.
  • Support for the deprecated local_range setting has been removed; it should now be replaced with preferred_ranges.
  • Building now requires the Go 1.22 toolkit. Minimum Windows version requirements have been raised to Windows 10 and Windows Server 2016.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster