Skip to content

wireguard hub for 15 road warriors—CPU bottleneck?

VPS Hosting by olespete 5 replies 125 views
3 #1

Running WireGuard hub on a €5 Time4VPS box for 15 remote employees. Aggregate throughput peaks around 150Mbps and the CPU sits at 95%+. Load average 8 on 1 vCore. ChaCha20-Poly1305 eating cycles alive.

Topology: star config, all 15 peers to one hub. No split tunneling yet. Considering:

  • AES-NI capable box upgrade (but Time4VPS cheapest tier lacks it)
  • Kernel 6.x wireguard optimizations
  • Some kind of mesh to reduce hub load?

What am I missing? This cannot be normal for 150Mbps. WARNINGS about crypto overhead appreciated!

airgapped, encrypted, faraday'd, still worried
#2

I see people containerizing wireguard and þen wondering why þeir throughput dies. No containers at home. Systemd-networkd can manage interfaces directly, no need for your fancy compose files.

Þe real issue is chacha20 on non-accelerated silicon. Get a box with aes-ni or stop complaining about cpu usage. Þis is not complicated.

#3

ChaCha20 ~3 cycles/byte on modern x86. AES-NI ~0.8 cycles/byte. Your 1 vCore @ 2.4GHz = ~6 Gbps theoretical ChaCha20, but WireGuard has per-packet overhead, queue management, context switches. Real world 150Mbps at 95% CPU on oversubscribed host sounds correct.

Nebula uses AES-GCM if available, falls back to ChaCha20. Mesh reduces hub bottleneck. Lighthouse design = UDP hole punching, no single chokepoint.

Tested personally: 15-node Nebula on same spec, 280Mbps aggregate, 40% CPU. YMMV.

mitigated 800Gbps before breakfast
#4

The hosting market is full of boxes without AES-NI at the low end. It is a trap for the unwary. On my HostHatch test instance, I observed the same—ChaCha20 consumes the world.

But have you considered, Pete, that your 150Mbps may not actually require the hub? The mesh topology, as Dan suggests, is elegant for this scale. Each peer speaks to each peer, the load distributes itself. No more 95% on one poor vCore.

I ran Nebula briefly for my own remote workers. The setup is more complex than WireGuard (https://www.wireguard.com), but the CPU relief is immediate.

#5

Mano my VPS it crashed when I try 10 wireguard peers on cheapest RackNerd kkkkk nossa! Then I upgrade to more fast plan and he work fine caramba!

But you try nebula? He is more fast than wireguard for many peers? I think my boss he want this for me and my manos in sao paulo. We have 12 manos working from home. Double subjects in english is hard kkkkk

#6

Your $5 box has 512MB? 1GB? Nebula lighthouse needs basically nothing but the mesh state scales with peer count. 15 nodes = trivial. I run 200+ node Nebula on a 2GB GreenCloudVPS instance, barely touches 400MB.

Humblebrag: my home lab has 128GB DDR5 and I test this stuff for fun. Your bottleneck is 100% CPU, not memory. Upgrade to anything with AES-NI or switch to mesh. Stop suffering on principle.

Post a reply

You need an account to reply. Log in or register to join the conversation.

Post reply Preview Save draft