A layer-2 centralized VPN, originally written in a single day.
Sahur is a dead-simple layer-2 VPN solution. Each instance, can run in two modes:
- NIC (clients)
- Switch (the server)
A NIC can either connect to another NIC directly, or to connect to a switch. All packets are encrypted with a pre-shared AES-256-CBC key using OpenSSL, and sent over UDP. The protocol is stateless. There is no handshake or whatsoever.
Limitations:
- No switch-to-switch connectivity (yet)
- No P2P mesh (like Tailscale, Netbird, ...)
- Having no handshake means the switch wont find it's connected NICs unless they send a packet first
Features:
- Broadcast!
- We were able to play CoD WWII's "LAN" mode with it!
Server:
mode = "switch"
listen = "0.0.0.0:15480"
peer_keys = [
"u14594xM85XOMTgEeoKFGd7p+METAWVC3E3tr0IzzLk=",
"msl03QR7j1gx1ija/c6gNkIdhKpDq2Cq2nCIU/MoB6o=",
]Client(s):
mode = "nic"
# port=0 tells the kernel to pick a port for us
listen = "0.0.0.0:0"
[interface]
name = "sahur0"
mtu = 1500
address = "10.15.48.1"
netmask = "255.255.255.0"
[peer]
type = "switch"
address = "12.34.56.78:15480"
key = "u14594xM85XOMTgEeoKFGd7p+METAWVC3E3tr0IzzLk="To connect other clients, simply change their interface.address and peer.key!
to generate keys you can run either:
openssl rand -base64 32
# or
sahur keygen