ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    ZeroTier and DNS issues

    Scheduled Pinned Locked Moved IT Discussion
    zerotierdnsvpn
    176 Posts 10 Posters 112.6k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • DashrenderD
      Dashrender
      last edited by

      Hhuh? So there are enterprises that do this? They install Pertino everywhere? literally every last machine?

      scottalanmillerS 1 Reply Last reply Reply Quote 0
      • scottalanmillerS
        scottalanmiller @adam.ierymenko
        last edited by

        @adam.ierymenko said:

        @scottalanmiller Agreed for greenfield SDN deployments, but greenfield is hard to achieve in enterprise. Part of what's hard about enterprise as I'm sure you're well aware is that it's hard to undo or un-provision anything, ever. I've seen enterprise houses running 1980s Ultrix software in a modified KVM Alpha emulator on a VM in the cloud because the software is binary-only, the maker of the software is gone, and it's mission critical.

        It's not an enterprise product. It was designed solely as SDN for the SMB market. It's only designed to be meaningful in a 100% full mesh deployment. Using it in any other role would be weird and completely not what it is designed for. Certainly not for the majority of deployments.

        1 Reply Last reply Reply Quote 0
        • A
          adam.ierymenko
          last edited by

          ZeroTier officially support bridging but our documentation on it stinks or is nonexistent. We're going to be fixing that fairly soon.

          We have a user in Germany using it to provide a backplane to stitch together hundreds of local mesh access points for a community meshnet project. He says bridging with ZT works fine with dozens of bridges with hundreds of clients behind each bridge, albeit with a bit of traffic overhead... but it's Germany so they get real fiber Internet connections.

          1 Reply Last reply Reply Quote 0
          • DashrenderD
            Dashrender
            last edited by

            OOOOOOO K!

            Well I can say I've never considered it for that type of use. I've also never read any of their literature either.

            That changes a lot.

            1 Reply Last reply Reply Quote 0
            • scottalanmillerS
              scottalanmiller @Dashrender
              last edited by scottalanmiller

              @Dashrender said:

              Hhuh? So there are enterprises that do this? They install Pertino everywhere? literally every last machine?

              Um, yeah, if by enterprises you mean companies. Basically every Pertino client you have ever heard of. That is its one and only purpose. You are thinking of it as a VPN replacement and that is confusing you into looking at it from an old model. It's a full mesh SDN, not a VPN. It uses VPN technology to make the SDN happen. I've never heard of someone wanting to run anything without Pertino on it, that would break everything about it.

              Of course things like your SAN are not part of the LAN itself and would not be part of it. Only the normal LAN would be on Pertino.

              And yes, this is how NTG operates.

              DashrenderD 1 Reply Last reply Reply Quote 0
              • scottalanmillerS
                scottalanmiller
                last edited by

                Pertino's target market is the California startup market specifically where this works beautifully. You'd be surprised how much their 100% mesh completely fits the model used by the west coast IT market. It's the non-west coast's approaches that make it seems strange and impossible. I've dealt with a lot of companies out there where they are like "of course, that just works". It doesn't seem foreign to them at all.

                1 Reply Last reply Reply Quote 0
                • DashrenderD
                  Dashrender
                  last edited by

                  If you're running Pertino as a full SDN, then why would they need to do anything special for DNS? I would think that it would be a large flat (say \23 or \22 network) and the DNS servers would only respond on the Pertino network.

                  Heck in that situation, I'd setup DHCP on the local business network from the firewall only so they have a way to have the underlying network (hardware layer) working.

                  Question - how do they get to the internet? Does the local machine send DNS queries to AD's DNS via Pertino, then the local clients use the local hardware network to find a route to the internet?

                  scottalanmillerS 4 Replies Last reply Reply Quote 0
                  • DashrenderD
                    Dashrender @scottalanmiller
                    last edited by

                    @scottalanmiller said:

                    @Dashrender said:

                    Hhuh? So there are enterprises that do this? They install Pertino everywhere? literally every last machine?

                    Um, yeah, if by enterprises you mean companies. Basically every Pertino client you have ever heard of. That is its one and only purpose. You are thinking of it as a VPN replacement and that is confusing you into looking at it from an old model. It's a full mesh SDN, not a VPN. It uses VPN technology to make the SDN happen. I've never heard of someone wanting to run anything without Pertino on it, that would break everything about it.

                    Of course things like your SAN are not part of the LAN itself and would not be part of it. Only the normal LAN would be on Pertino.

                    And yes, this is how NTG operates.

                    I knew this was how NTG operated, but I knew that only because NTG is a physically diverse network.

                    1 Reply Last reply Reply Quote 0
                    • DashrenderD
                      Dashrender
                      last edited by

                      @hubtechagain has Pertino at a few of his clients.. I wonder if he runs an all or nothing approach.

                      1 Reply Last reply Reply Quote 0
                      • scottalanmillerS
                        scottalanmiller @Dashrender
                        last edited by

                        @Dashrender said:

                        If you're running Pertino as a full SDN, then why would they need to do anything special for DNS? I would think that it would be a large flat (say \23 or \22 network) and the DNS servers would only respond on the Pertino network.

                        Because you don't want your NFS traffic for two servers sitting next to each other traversing your WAN link. It still needs to understand how to hit the cloud or not for traffic. No matter how much you abstract your traffic the realities of congestion still exist.

                        1 Reply Last reply Reply Quote 1
                        • A
                          adam.ierymenko
                          last edited by

                          We've had the same experience with ZeroTier which does the same thing in this use case minus some of the bundled hacks for things like AD. Greenfield is easy. "Brownfield" as they call it -- namely anywhere other than California -- is a lot harder because you have to still connect to the 1990s Windows NT server that is mission critical or the printers that can't run SDN software or the ancient Solaris box that talks via 1200 baud modem bank to the store PoS systems or the IP over carrier pigeon (RFC1149) deployment.

                          Right now we've elected to focus more on other uses of SDN, but yes we do eventually want to go there.

                          So... if Pertino is often used all-or-nothing then why is the DNS mangling needed? I understood it with mixed installs but I don't understand it if you're doing greenfield all-in SDN.

                          scottalanmillerS 1 Reply Last reply Reply Quote 0
                          • scottalanmillerS
                            scottalanmiller @Dashrender
                            last edited by

                            @Dashrender said:

                            Heck in that situation, I'd setup DHCP on the local business network from the firewall only so they have a way to have the underlying network (hardware layer) working.

                            How does DHCP do that?

                            DashrenderD 1 Reply Last reply Reply Quote 0
                            • scottalanmillerS
                              scottalanmiller @Dashrender
                              last edited by

                              @Dashrender said:

                              I would think that it would be a large flat (say \23 or \22 network) and the DNS servers would only respond on the Pertino network.

                              It IS a huge flat network. /22 now, they just updated.

                              1 Reply Last reply Reply Quote 0
                              • scottalanmillerS
                                scottalanmiller @Dashrender
                                last edited by

                                @Dashrender said:

                                Question - how do they get to the internet? Does the local machine send DNS queries to AD's DNS via Pertino, then the local clients use the local hardware network to find a route to the internet?

                                Anyway you want, typically direct since the Internet is not part of your LAN. But you could put a proxy on the pLAN somewhere.

                                Obviously the route to the Internet is handled normally since that is also how you get the route to your Pertino gear.

                                1 Reply Last reply Reply Quote 0
                                • A
                                  adam.ierymenko
                                  last edited by

                                  @scottalanmiller ZeroTier just connects directly over LAN if two devices are in the same physical network (if possible). So in-building traffic goes in-building, albeit with the overhead of an extra 28 byte header and encryption/authentication. Overhead is somewhat comparable to IPSec.

                                  For high performance stuff where you don't want any encapsulation overhead it makes more sense to just physically wire thing together on private special purpose backplane networks. You will never beat that with SDN because... well... it's just a wire.

                                  scottalanmillerS DashrenderD 2 Replies Last reply Reply Quote 0
                                  • scottalanmillerS
                                    scottalanmiller @adam.ierymenko
                                    last edited by

                                    @adam.ierymenko said:

                                    So... if Pertino is often used all-or-nothing then why is the DNS mangling needed? I understood it with mixed installs but I don't understand it if you're doing greenfield all-in SDN.

                                    If you have 100 machines in a single office, you don't want them talking to each other through an Amazon hosted switch.

                                    1 Reply Last reply Reply Quote 0
                                    • A
                                      adam.ierymenko
                                      last edited by

                                      @scottalanmiller Sure, but why wouldn't you handle that a layer down? Are you saying Pertino uses DNS to route traffic?

                                      scottalanmillerS 1 Reply Last reply Reply Quote 0
                                      • scottalanmillerS
                                        scottalanmiller @adam.ierymenko
                                        last edited by

                                        @adam.ierymenko said:

                                        @scottalanmiller ZeroTier just connects directly over LAN if two devices are in the same physical network (if possible). So in-building traffic goes in-building, albeit with the overhead of an extra 28 byte header and encryption/authentication. Overhead is somewhat comparable to IPSec.

                                        How is ZeroTier determining how to address a machine in one place or another? Say a laptop is communicating with a server that is remote and then becomes local. How does it know when to switch?

                                        1 Reply Last reply Reply Quote 1
                                        • H
                                          hubtechagain
                                          last edited by

                                          we use pertino only on our laptops and "out of office" computers. not installed on every workstation, that would be silly. We use pertino essentially as a vpn, a means for those geographically separate devises to still use LAN resources securely and easily (doctors, nurses, etc)

                                          1 Reply Last reply Reply Quote 0
                                          • scottalanmillerS
                                            scottalanmiller @adam.ierymenko
                                            last edited by

                                            @adam.ierymenko said:

                                            @scottalanmiller Sure, but why wouldn't you handle that a layer down? Are you saying Pertino uses DNS to route traffic?

                                            Yes. DNS is used to determine where to send traffic. Because it gives different addresses out under different circumstances.

                                            1 Reply Last reply Reply Quote 0
                                            • 1
                                            • 2
                                            • 3
                                            • 4
                                            • 5
                                            • 6
                                            • 7
                                            • 8
                                            • 9
                                            • 6 / 9
                                            • First post
                                              Last post