Step 1 of 5 · Reading · ~1 min
Read
VPN Fundamentals
TUN/TAP Interfaces
VPN code lives in userspace (mostly). To intercept network traffic, use TUN.
TUN (layer 3): userspace reads/writes IP packets. Kernel routes packets destined for the TUN's network there.
TAP (layer 2): same but Ethernet frames. For bridging Layer 2.
Linux setup:
sudo ip tuntap add dev wg0 mode tun
sudo ip addr add 10.0.0.1/24 dev wg0
sudo ip link set wg0 up
Now wg0 is a network interface. route add 10.0.0.0/24 dev wg0 makes the kernel send 10.0.0.x packets to wg0 → reads in userspace.
Userspace VPN process:
python
WireGuard runs in kernel for speed. OpenVPN classically runs in userspace (slower; new userspace WireGuard exists too).
Routing table: tells kernel which packets to send to wg0.
- Allowed-IPs in WireGuard: peer's allowed IPs are routes added to wg0.
- 0.0.0.0/0 routed to wg0 = full-tunnel VPN (all traffic through).
- Specific subnet routed = split-tunnel (only that subnet through VPN).
Up nextTunnel EncapsulationVPN Fundamentals
Discussion
Ask a question, share an insight, or help someone who’s stuck.
Sign in to post a comment or reply.
Loading…