|
|
|
|
|
by commercialnix
713 days ago
|
|
Wireguard layer-3 tunneling identity (public key) is for machines, not human users. Rolling out Wireguard in an "enterprise environment" for over 600 user laptops and desktops (mix of Linux and some macOS* and Windows*) with our existing configuration management (SaltStack/GitOps) was extremely easy to do. Where additional layer-3 tunnels that were user or group specific were necessary, we did some very light scripting that any sophomore-level Sys Admin can handle. We already have BeyondCorp / ZeroTrust for any layer-4 and above authentication. >> Compare this with a commercial VPN that will directly plug into your identity system. This would be something out of the clicky-clicky industrial complex. |
|
How did you manage the IP assignment, keys revocation, ...?
How did your ZT environment worked with WG on the network level? (zScaler creates its own tunnels for instance)