Multi-tunnel WireGuardcoming
Today a gateway carries one WireGuard interface with ChaCha20-Poly1305, and none of IPsec’s ESP MTU headaches. Spreading traffic across several tunnels with CPU affinity is planned.
The open-source gateway data plane carries traffic over kernel WireGuard and enforces policy in eBPF programs at XDP and TC, with the kernel networking stack intact — no DPDK NIC takeover, no fragile userspace packet path. Throughput figures will be published once they are measured.
Today a gateway carries one WireGuard interface with ChaCha20-Poly1305, and none of IPsec’s ESP MTU headaches. Spreading traffic across several tunnels with CPU affinity is planned.
XDP sheds abusive traffic at the NIC, and a TC program on the WireGuard interface enforces policy after decryption. A TC egress hook for SD-WAN steering is coming.
Planned: microsegmentation that follows service and application identity. Today a policy names single hosts, and the gateway resolves identity from the packet’s address.
The data plane is Apache-2.0 licensed. Read it, audit it, build it yourself — the fast path is not a black box. Running it on bare metal is coming.
One secure fabric across every cloud — identity-aware policy, encrypted end to end, and no agents in your workloads. Start on the free Community tier; no sales call to get going.