Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Need Help in Choosing a VPN

    Scheduled Pinned Locked Moved Off-Topic & Non-Support Discussion
    34 Posts 20 Posters 3.9k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • johnpozJ
      johnpoz LAYER 8 Global Moderator
      last edited by

      Another freaking spammer dropped in this thread recommending that nord WTF? Talk about a spam magnet subject.

      An intelligent man is sometimes forced to be drunk to spend time with his fools
      If you get confused: Listen to the Music Play
      Please don't Chat/PM me for help, unless mod related
      SG-4860 24.11 | Lab VMs 2.8, 24.11

      1 Reply Last reply Reply Quote 2
      • KOMK
        KOM
        last edited by

        I just finished evaluating Wireguard from Mullvad on Linux Mint 19.1.

        Pros:

        • Simple config. Config generator page takes your acct number and desired endpoint and then spits out a Wireguard config file similar to OpenVPN config file generation that most ISPs use.
        • Fast connect. It connects in under a second.
        • No DNS leaks like you always get with NetworkManager & OpenVPN.

        Cons:

        • Initial config requires command-line use. This is not usually a problem for most Linux users.
        • Enabling/disabling Wireguard connection also requires command-line as there is no GUI or desktop widget.

        I didn't do any speed tests because those can be all over the place depending on several factors.

        Supposedly, NetworkManager 1.16.0 (in Ubuntu 19.04) natively supports Wireguard without plugins, but even then you still need to use nmcli to manually import the config file from terminal.

        I went from knowing literally nothing about Wireguard to having a functional connection with no leaking DNS in under 5 minutes.

        Pretty nice so far.

        1 Reply Last reply Reply Quote 0
        • demD
          dem
          last edited by

          If you want to be your own VPN provider and you're comfortable at the command line check out AlgoVPN, a set of scripts that will set up a private VPN server at one of the major cloud providers and generate the client config files for you. An AlgoVPN supports IPsec and WireGuard.

          With a few changes to your AlgoVPN you can even connect pfSense via IPsec, as I've documented here.

          Note that Netflix and others tend to block access from many cloud provider networks so running your own AlgoVPN won't meet the needs of some folks in this thread.

          1 Reply Last reply Reply Quote 0
          • johnpozJ
            johnpoz LAYER 8 Global Moderator
            last edited by

            ^ doesn't have to be a major cloud provider though... Pretty much can be anywhere you can setup a vps..

            Just have to be in line with their AUP... So quite often trying to hide your p2p shit from your isp via this method not going to fly..

            An intelligent man is sometimes forced to be drunk to spend time with his fools
            If you get confused: Listen to the Music Play
            Please don't Chat/PM me for help, unless mod related
            SG-4860 24.11 | Lab VMs 2.8, 24.11

            1 Reply Last reply Reply Quote 0
            • JeGrJ
              JeGr LAYER 8 Moderator
              last edited by

              Almost got trigger-happy with @dem's post - sorry - but amazing, how many spam-bots seem to run amok with spamming NordVPN et al services. Weird.

              @KOM If you have reliable data for Wireguard performance, it would be nice to know. We did a test with OVPN, IPSec and a quick one with some half-baked WireGuard package on OPNsense (just to have some values on FreeBSD at all) and were pretty baffled. Perhaps it was the version and/or FreeBSDs implementation but performance wise it wasn't impressive at all.

              Don't forget to upvote 👍 those who kindly offered their time and brainpower to help you!

              If you're interested, I'm available to discuss details of German-speaking paid support (for companies) if needed.

              KOMK 1 Reply Last reply Reply Quote 0
              • KOMK
                KOM @JeGr
                last edited by

                @JeGr If I get some time this weekend, I can try some speed tests raw vs OpenVPN / Wireguard with Mullvad.

                1 Reply Last reply Reply Quote 1
                • JeGrJ
                  JeGr LAYER 8 Moderator
                  last edited by

                  Thanks for that! Perhaps mention the hardware (on your side of course) you test with, too :)

                  Don't forget to upvote 👍 those who kindly offered their time and brainpower to help you!

                  If you're interested, I'm available to discuss details of German-speaking paid support (for companies) if needed.

                  1 Reply Last reply Reply Quote 0
                  • demD
                    dem
                    last edited by

                    On Linux, WireGuard runs in the kernel, but on FreeBSD, iOS, and macOS it uses a separate program written in Go. This will certainly affect performance.

                    1 Reply Last reply Reply Quote 0
                    • B
                      bjd223
                      last edited by

                      I have used PIA for years w/o issue. AFAIK they have been tested in court and were unable to provide any details to the authorities about usage.

                      1 Reply Last reply Reply Quote 0
                      • KOMK
                        KOM
                        last edited by

                        @JeGr My basic tests on my 150/15 connection showed:

                        Raw 133/12
                        OpenVPN 125/12
                        Wireguard 131/12

                        I have a Mikrotik hEX at home with some traffic-shaping enabled.

                        A 1 Reply Last reply Reply Quote 0
                        • A
                          ajmaltms @KOM
                          last edited by

                          @KOM mikrotik integrated with pfsense?

                          1 Reply Last reply Reply Quote 0
                          • KOMK
                            KOM
                            last edited by

                            What? No, there is no such thing.

                            1 Reply Last reply Reply Quote 0
                            • JeGrJ
                              JeGr LAYER 8 Moderator
                              last edited by

                              Thanks @KOM that's interesting. We got it no higher than around ~220-320Mbps (depending on sending or receiving) while OVPN would hit ~450-500 depending on config and IPSec going up in spikes to as high as 575Mbps on hardware that is equivalent to the SG-5100 (eg. Atom 3558 SOC). Could be the implementation of course.

                              Don't forget to upvote 👍 those who kindly offered their time and brainpower to help you!

                              If you're interested, I'm available to discuss details of German-speaking paid support (for companies) if needed.

                              1 Reply Last reply Reply Quote 0
                              • J
                                jagradang
                                last edited by

                                I have been using nordvpn for the best part of a year and found it to be great.

                                I did look at a lot of others but as someone said do your research, look at recommendations and check what meets your needs.

                                I have also used nordvpn support a couple of times as well and they were very good, contrary to what I read in most of the reviews.

                                Purevpn was the other one I was close togetting but nord had the edge for me. Works great with my pfsense and really good speeds.

                                1 Reply Last reply Reply Quote 0
                                • D
                                  dany001 Banned
                                  last edited by

                                  This post is deleted!
                                  1 Reply Last reply Reply Quote 0
                                  • B
                                    BAOZHAI
                                    last edited by

                                    Thanks Guys, thanks everyone for replying to my thread. However the thread is year old and there is no Black Friday to avail the deal☺ Anyways in the mean time I was doing my own research on Best VPN Services and after reviewing an article which gave me some very important insights such as logging policies and 5 eyes countries, where I was in a position to make an informed decision. I purchased ExpressVPN recently and it fit my purpose very well. Let me know what are your basis on choosing a VPN service.

                                    1 Reply Last reply Reply Quote 0
                                    • johnpozJ
                                      johnpoz LAYER 8 Global Moderator
                                      last edited by

                                      Thing I can say about this thread - it has been the biggest SPAM magnet thread I have ever seen here, in the like 12 years been here ;)

                                      An intelligent man is sometimes forced to be drunk to spend time with his fools
                                      If you get confused: Listen to the Music Play
                                      Please don't Chat/PM me for help, unless mod related
                                      SG-4860 24.11 | Lab VMs 2.8, 24.11

                                      B 1 Reply Last reply Reply Quote 0
                                      • B
                                        bjd223 @johnpoz
                                        last edited by

                                        @johnpoz I agree I'd just lock it as OP has said they found one.

                                        1 Reply Last reply Reply Quote 0
                                        • stephenw10S
                                          stephenw10 Netgate Administrator
                                          last edited by

                                          Locked 👍

                                          1 Reply Last reply Reply Quote 0
                                          • First post
                                            Last post
                                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.