OverShifted/sahur

makeshift virtual switch/VPN

★ 0Forks 0RustGitHub ↗Compare

README

Sahur

A layer-2 centralized VPN, originally written in a single day.

Sahur is a dead-simple layer-2 VPN solution. Each instance, can run in two modes:

  1. NIC (clients)
  2. Switch (the server)

A NIC can either connect to another NIC directly, or to connect to a switch. All packets are encrypted with a pre-shared AES-256-CBC key using OpenSSL, and sent over UDP. The protocol is stateless. There is no handshake or whatsoever.

Limitations:

  1. No switch-to-switch connectivity (yet)
  2. No P2P mesh (like Tailscale, Netbird, ...)
  3. Having no handshake means the switch wont find it's connected NICs unless they send a packet first

Features:

  1. Broadcast!
  2. We were able to play CoD WWII's "LAN" mode with it!

Example Configuration

Server:

mode = "switch"
listen = "0.0.0.0:15480"
peer_keys = [
	"u14594xM85XOMTgEeoKFGd7p+METAWVC3E3tr0IzzLk=",
	"msl03QR7j1gx1ija/c6gNkIdhKpDq2Cq2nCIU/MoB6o=",
]

Client(s):

mode = "nic"
# port=0 tells the kernel to pick a port for us
listen = "0.0.0.0:0"

[interface]
name = "sahur0"
mtu = 1500
address = "10.15.48.1"
netmask = "255.255.255.0"

[peer]
type = "switch"
address = "12.34.56.78:15480"
key = "u14594xM85XOMTgEeoKFGd7p+METAWVC3E3tr0IzzLk="

To connect other clients, simply change their interface.address and peer.key!

to generate keys you can run either:

openssl rand -base64 32
# or
sahur keygen

Contributors

OverShifted

Issues