์ผ๋‹จ ํ•˜๊ณ  ๋ณด๋Š” ์‚ฌ๋žŒ

๋‚˜์ค‘๋ณด๋‹จ ์ง€๊ธˆ์— ์ง‘์ค‘ํ•˜๋˜, ์ง€๊ธˆ๋ณด๋‹จ ๋‚˜์ค‘์— ์™„๋ฒฝํ•ด์ง€์ž๐Ÿ’ช๐Ÿป

๐ŸŒ Network ๊ธฐ๋ณธ๋ถ€ํ„ฐ ์ฐจ๊ทผ์ฐจ๊ทผ

[VPN]: OpenVPN vs WireGuard

JanginTech 2024. 11. 29. 16:08

1. OpenVPN ๋˜๋Š” WireGuard? ์ž์„ธํ•œ ์„ฑ๋Šฅ ๋ถ„์„(OpenVPN or WireGuard? A Detailed Performance Breakdown)

https://thenewstack.io/openvpn-or-wireguard-a-detailed-performance-breakdown/

 

OpenVPN or WireGuard? A Detailed Performance Breakdown

OpenVPN, while reliable, struggles with performance and complexity compared to WireGuard.

thenewstack.io

 

 

[์š”์•ฝ์ •๋ฆฌ]

OpenVPN๊ณผ WireGuard์˜ ์„ฑ๋Šฅ ๋ถ„์„์— ๋Œ€ํ•œ ๋‚ด์šฉ์„ ๋ณด๊ธฐ ์ „์— VPN์— ๋Œ€ํ•ด ๊ฐ„๋‹จํžˆ ์งš๊ณ  ๋„˜์–ด๊ฐ€๋Š” ๊ฒŒ ์ข‹๊ฒ ๋‹ค.

VPN(Virtual Private Network)๋Š” ๋ณด์•ˆ๊ณผ ํ”„๋ผ์ด๋ฒ„์‹œ๋ฅผ ๋ณด์žฅํ•˜๋ฉฐ, ์›๊ฒฉ ์ ‘์†๊ณผ ๋ฐ์ดํ„ฐ ๋ณดํ˜ธ๋ฅผ ์œ„ํ•ด ํ•„์š”ํ•œ ํ•„์ˆ˜์ ์ธ ๋„๊ตฌ๋‹ค.

์ด ์ค‘์—์„œ๋„ ํŠนํžˆ OpenVPN๊ณผ WireGuard๊ฐ€ ๊ฐ€์žฅ ๋„๋ฆฌ ์“ฐ์ด๋Š” VPN ๊ธฐ์ˆ ์ด๋‹ค.

OpenVPN๊ณผ WireGuard์— ๋Œ€ํ•œ ์ด๋ก  ๊ฐœ๋…๊ณผ ๊ฐ๊ฐ์˜ ์žฅ๋‹จ์ , ๊ทธ๋ฆฌ๊ณ  ์ฐจ์ด๋ฅผ ๋น„๊ต ๋ถ„์„ํ•ด ๋ณด๊ฒ ๋‹ค.

 

 

 


1. OpenVPN? WireGuard?


1.1. OpenVPN

https://openvpn.net/

 

Business VPN For Secure Networking | OpenVPN

OpenVPN is a network security company serving the secure remote access needs of small businesses to the enterprise. Our on-prem and cloud-based products offer the essentials of zero trust network access and are built on the leading OpenVPN tunneling protoc

openvpn.net

 

  • 2001๋…„์— ์ถœ์‹œ๋œ ์˜ค๋žœ ๊ธฐ๊ฐ„ ๊ฒ€์ฆ๋œ ์‹ ๋ขฐํ•  ์ˆ˜ ์žˆ๋Š” VPN ํ”„๋กœํ† ์ฝœ
  • SSL/TLS ์•”ํ˜ธํ™”๋ฅผ ๊ธฐ๋ฐ˜์œผ๋กœ ํ•˜๋ฉฐ, ๋‹ค์–‘ํ•œ ์•”ํ˜ธํ™” ์•Œ๊ณ ๋ฆฌ์ฆ˜์„ ์ง€์›ํ•œ๋‹ค
  • ์‚ฌ์šฉ์ž ์ •์˜ ๋ฐ ํ™•์žฅ์ด ๊ฐ€๋Šฅํ•˜์ง€๋งŒ ์„ค์ •์ด ๋ณต์žกํ•˜๋‹ค
  • ์ฃผ๋กœ ์—”ํ„ฐํ”„๋ผ์ด์ฆˆ ํ™˜๊ฒฝ์ด๋‚˜ ์‚ฌ์šฉ์ž ์ง€์ • ๋ณด์•ˆ ์š”๊ตฌ์‚ฌํ•ญ์„ ์ดํ–‰ํ•ด์•ผ ํ•  ๋•Œ OpenVPN์„ ์‚ฌ์šฉํ•œ๋‹ค.

 

 

1.2. WireGuard

https://www.wireguard.com/

 

WireGuard: fast, modern, secure VPN tunnel

WireGuard® is an extremely simple yet fast and modern VPN that utilizes state-of-the-art cryptography. It aims to be faster, simpler, leaner, and more useful than IPsec, while avoiding the massive headache. It intends to be considerably more performant th

www.wireguard.com

 

  • 2015๋…„์— ๋น„๊ต์  ๋Šฆ๊ฒŒ ์ถœ์‹œ๋œ ๊ฒฝ๋Ÿ‰ํ™”์™€ ์„ฑ๋Šฅ์„ ๋ชฉํ‘œ๋กœ ์„ค๊ณ„๋œ ํ˜„๋Œ€์ ์ธ VPN ํ”„๋กœํ† ์ฝœ
  • UDP ๊ธฐ๋ฐ˜์œผ๋กœ ์ž‘๋™ํ•˜๊ณ , ์ฝ”๋“œ๋ฒ ์ด์Šค๊ฐ€ OpenVPN๋ณด๋‹ค ํ›จ์”ฌ ์ž‘๋‹ค๊ณ  ํ•œ๋‹ค(~4,000์ค„ ์ •๋„)
  • ์„ค์ •์ด ๊ฐ„๋‹จํ•˜๋ฉฐ, ๋†’์€ ์„ฑ๋Šฅ์„ ์ œ๊ณตํ•œ๋‹ค.
  • ์†๋„์™€ ํšจ์œจ์„ฑ์ด ์ค‘์š”ํ•œ ๊ฐœ์ธ ๋ฐ ํด๋ผ์šฐ๋“œ ํ™˜๊ฒฝ์ด๋‚˜ ๋‹จ์ˆœ์„ฑ, ์†๋„, ์‚ฌ์šฉ ํŽธ์˜์„ฑ์ด ๊ฐ•์ ์ธ๋งŒํผ ์ตœ์‹  DevOps ํ™˜๊ฒฝ์— ์ด์ƒ์ ์œผ๋กœ ๋ถ€ํ•ฉํ•˜๋‹ค.

 

 

 

 


2. OpenVPN vs WireGuard


2.1. OpenVPN vs WireGuard ์„ฑ๋Šฅ ๋น„๊ต

  OpenVPN WireGuard
์ถœ์‹œ ์—ฐ๋„ 2001๋…„ 2015๋…„
์ฃผ์š” ํ”„๋กœํ† ์ฝœ SSL/TLS ๊ธฐ๋ฐ˜ UDP ๊ธฐ๋ฐ˜
์•”ํ˜ธํ™” ์•Œ๊ณ ๋ฆฌ์ฆ˜ ๋‹ค์–‘ํ•œ ์•”ํ˜ธํ™” ์•Œ๊ณ ๋ฆฌ์ฆ˜ ์ œ๊ณต(AES-256 ๋“ฑ) ์ตœ์‹  ์•”ํ˜ธํ™” ์•Œ๊ณ ๋ฆฌ์ฆ˜ ๊ธฐ๋ณธ ํƒ‘์žฌ๋˜์–ด์žˆ์Œ
(ChaCha20, Poly1305 ๋“ฑ) 
์†๋„ ์ƒ๋Œ€์ ์œผ๋กœ ๋А๋ฆผ (ํŠนํžˆ, ๊ณ ์† ๋„คํŠธ์›Œํฌ ํ™˜๊ฒฝ์—์„œ ์„ฑ๋Šฅ ์ €ํ•˜๊ฐ€ ๋‘๋“œ๋Ÿฌ์ง) ๋น ๋ฆ„ (๊ฒฝ๋Ÿ‰ ์„ค๊ณ„๋กœ ๊ณ ์† ๋„คํŠธ์›Œํฌ์—์„œ๋„ ๋›ฐ์–ด๋‚œ ์„ฑ๋Šฅ์„ ๋ณด์—ฌ์คŒ)
CPU ์‚ฌ์šฉ๋Ÿ‰ ์•”/๋ณตํ˜ธํ™” ๊ณผ์ •์—์„œ ๋†’์€ CPU ๋ฆฌ์†Œ์Šค ์†Œ๋ชจ CPU ์‚ฌ์šฉ๋Ÿ‰์ด ๋‚ฎ์•„ ํšจ์œจ์ 
๋ฉ”๋ชจ๋ฆฌ ์‚ฌ์šฉ๋Ÿ‰ ๋” ๋งŽ์Œ ๋” ์ ์Œ(๊ฒฝ๋Ÿ‰ ์„ค๊ณ„)
์„ค์ • ๋ณต์žก์„ฑ ์„ค์ • ํŒŒ์ผ ๊ด€๋ฆฌ ๋ฐ ์ธ์ฆ์„œ ์„ค์น˜ ํ•„์š” ๊ฐ„๋‹จํ•œ ์„ค์ •, ํ‚ค ๊ตํ™˜ ๋ฐฉ์‹์œผ๋กœ ๋น ๋ฅธ ์„ค์ • ๊ฐ€๋Šฅ
๋ณด์•ˆ์„ฑ ์šฐ์ˆ˜( SSL/TLS ๊ธฐ๋ฐ˜์ด๋‹ˆ๊นŒ) ํ˜„๋Œ€์  ์•”ํ˜ธํ™” ๊ธฐ์ˆ ๋กœ ๊ฐ„๋‹จํ•˜์ง€๋งŒ ๊ฐ•๋ ฅํ•œ ๋ณด์•ˆ ์ œ๊ณต
์ฝ”๋“œ๋ฒ ์ด์Šค ํฌ๊ธฐ ์•ฝ 100,000์ค„ ์•ฝ 4,000์ค„(์ทจ์•ฝ์  ๋ถ„์„ ๋ฐ ์œ ์ง€๋ณด์ˆ˜ ์šฉ์ด)
ํ˜ธํ™˜์„ฑ ๋‹ค์–‘ํ•œ ํ”Œ๋žซํผ์—์„œ ํญ๋„“์€ ํ˜ธํ™˜์„ฑ(Windows, macOS, Linux ๋“ฑ) ์ €์‚ฌ์–‘ ํ•˜๋“œ์›จ์–ด์—์„œ๋„ ๋†’์€ ์„ฑ๋Šฅ ์ œ๊ณต
์‚ฌ์šฉ ์˜ˆ์‹œ 1. ์—”ํ„ฐํ”„๋ผ์ด์ฆˆ ํ™˜๊ฒฝ
2. ์ปค์Šคํ…€ ๋„คํŠธ์›Œํฌ ์„ค์ •
1. ๊ฐœ์ธ ์‚ฌ์šฉ์ž
2. ํด๋ผ์šฐ๋“œ
3. ์†๋„ ๋ฐ ํšจ์œจ์„ฑ์ด ์ค‘์š”ํ•œ ํ™˜๊ฒฝ
์˜คํ”ˆ์†Œ์Šค ์—ฌ๋ถ€ O O

 

 

 

2.2. OpenVPN vs WireGuard ๋ถ„์„ ํฌ์ธํŠธ

4๊ฐ€์ง€ ํฌ์ธํŠธ๋ฅผ ๊ธฐ์ค€์œผ๋กœ ๋น„๊ต๋ถ„์„ํ•ด ๋ดค๋‹ค.

 

1. ์†๋„์™€ ์„ฑ๋Šฅ:

  • OpenVPN์€ ์•”ํ˜ธํ™” ๋ฐฉ์‹์ด ๋ณต์žกํ•ด์„œ ๊ณ ์† ๋„คํŠธ์›Œํฌ์—์„œ ์„ฑ๋Šฅ์ด ์ œํ•œ๋  ์ˆ˜ ์žˆ๋Š” ๋ฐ˜๋ฉด์—,
  • WireGuard๋Š” ๊ฒฝ๋Ÿ‰ํ™”๋œ ์„ค๊ณ„๋กœ ์†๋„๊ฐ€ ๋” ๋น ๋ฅด๋ฉฐ, ํŠนํžˆ ๊ณ ์† ๋„คํŠธ์›Œํฌ ํ™˜๊ฒฝ์—์„œ ๊ฐ•๋ ฅํ•œ ์„ฑ๋Šฅ์„ ๋ฐœํœ˜ํ•œ๋‹ค.

2. ๋ณด์•ˆ์„ฑ:

  • OpenVPN์€ ๋‹ค์–‘ํ•œ ์•”ํ˜ธํ™” ์˜ต์…˜์„ ์ œ๊ณตํ•˜์—ฌ ๋ณด์•ˆ์„ฑ์€ ๋†’์ง€๋งŒ ์„ค์ •์ด ๋ณต์žกํ•œ ๋ฐ˜๋ฉด์—,
  • WireGuard๋Š” ์ตœ์‹  ์•”ํ˜ธํ™” ์˜ต์…˜์„ ์ œ๊ณตํ•˜์—ฌ ๊ฐ„๋‹จํ•˜๋ฉด์„œ๋„ ๋†’์€ ๋ณด์•ˆ์„ฑ์„ ์ œ๊ณตํ•ด ์ค€๋‹ค.

3. ์‚ฌ์šฉ ํŽธ์˜์„ฑ:

  • OpenVPN์€ ์„ค์ •, ์œ ์ง€๋ณด์ˆ˜ ๊ณผ์ •์ด ๋ณต์žกํ•˜์—ฌ, ์‚ฌ์šฉ์ž๊ฐ€ ์‚ฌ์šฉํ•˜๋Š”๋ฐ ์–ด๋ ค์›€์„ ๋А๋‚„ ์ˆ˜ ์žˆ๋Š” ๋ฐ˜๋ฉด์—,
  • WireGuard๋Š” ๊ฐ„๋‹จํ•œ ์„ค์ • ํ”„๋กœ์„ธ์Šค๋ฅผ ์ œ๊ณตํ•˜๋ฏ€๋กœ ์ดˆ๋ณด์ž๋„ ์‰ฝ๊ฒŒ ์„ค์น˜ํ•  ์ˆ˜ ์žˆ๋‹ค.

4. ๋ฆฌ์†Œ์Šค ํšจ์œจ์„ฑ:

  • OpenVPN์€ CPU์™€ ๋ฉ”๋ชจ๋ฆฌ ์‚ฌ์šฉ๋Ÿ‰์ด ๋†’์•„ OpenVPN์„ ์‚ฌ์šฉํ•  ๊ฒฝ์šฐ ๊ณ ์‚ฌ์–‘ ํ•˜๋“œ์›จ์–ด๊ฐ€ ํ•„์š”ํ•œ ๋ฐ˜๋ฉด์—,
  • WireGuard๋Š” ์ €์‚ฌ์–‘ ํ™˜๊ฒฝ์—์„œ๋„ ์•ˆ์ •์ ์ธ ์„ฑ๋Šฅ์„ ์ œ๊ณตํ•ด ์ค€๋‹ค.

 

 

 

 


3. OpenVPN? WireGuard? ์„ ํƒ ๊ธฐ์ค€


3.1. OpenVPN์„ ์„ ํƒํ•ด์•ผ ํ•˜๋Š” ๊ฒฝ์šฐ:

  • ์—”ํ„ฐํ”„๋ผ์ด์ฆˆ ํ™˜๊ฒฝ: ๋ณต์žกํ•œ ๋ณด์•ˆ ์ •์ฑ…์„ ์„ค์ •ํ•ด์•ผ ํ•˜๋Š” ๋Œ€๊ทœ๋ชจ ์กฐ์ง(๊ธฐ์—…)
  • ๊ด‘๋ฒ”์œ„ํ•œ ํ˜ธํ™˜์„ฑ: ๋‹ค์–‘ํ•œ OS์™€ ๋„คํŠธ์›Œํฌ ํ™˜๊ฒฝ์—์„œ ์ž‘๋™ํ•ด์•ผ ํ•˜๋Š” ๊ฒฝ์šฐ
  • SSL/TLS ๊ธฐ๋ฐ˜ ์•”ํ˜ธํ™” ํ”„๋กœํ† ์ฝœ ํ•„์š”

 

3.2. WireGuard๋ฅผ ์„ ํƒํ•ด์•ผ ํ•˜๋Š” ๊ฒฝ์šฐ:

  • ์†๋„์™€ ํšจ์œจ์„ฑ์ด ์ค‘์š”: ํด๋ผ์šฐ๋“œ ํ™˜๊ฒฝ, ๊ณ ์† ๋„คํŠธ์›Œํฌ ํ™˜๊ฒฝ์—์„œ ์‚ฌ์šฉ
  • ๊ฐ„๋‹จํ•œ ์„ค์ •: ๊ฐœ์ธ, ์†Œ๊ทœ๋ชจ ์กฐ์ง
  • ์ตœ์‹  ๋ณด์•ˆ ๊ธฐ์ˆ  ์„ ํ˜ธ: ์ตœ์‹  ์•”ํ˜ธํ™” ๊ธฐ์ˆ ์„ ๊ธฐ๋ณธ์œผ๋กœ ์‚ฌ์šฉํ•˜๊ณ  ์‹ถ์€ ๊ฒฝ์šฐ

 

 

 

 

 


 

๐Ÿค” ์ด์— ๋Œ€ํ•œ ๋‚˜์˜ ์ƒ๊ฐ

์˜ค๋Š˜์˜ ์•„ํ‹ฐํด์„ ํ†ตํ•ด OpenVPN๊ณผ WireGuard์˜ ๋น„๊ต๋ฅผ ํ†ตํ•ด ๋‘ VPN ๊ธฐ์ˆ ์˜ ๊ฐ•์ ๊ณผ ์•ฝ์ ์„ ๋ช…ํ™•ํžˆ ์ดํ•ดํ•  ์ˆ˜ ์žˆ์—ˆ๋‹ค.
ํŠนํžˆ, OpenVPN์€ ์‹ ๋ขฐ์„ฑ๊ณผ ์œ ์—ฐ์„ฑ ๋ฉด์—์„œ ๋›ฐ์–ด๋‚˜์ง€๋งŒ ์„ค์ •์ด ๋ณต์žกํ•˜๊ณ  ์„ฑ๋Šฅ ๋ถ€๋ถ„์ด ๋‹จ์ ์ธ ๋ฐ˜๋ฉด,

WireGuard๋Š” ๋น ๋ฅธ ์†๋„์™€ ํŽธ๋ฆฌํ•œ ์„ค์ •๋ฒ•์ด ๊ฐ•์ ์ด๋ฉฐ, ํ˜„๋Œ€์ ์ธ ๋„คํŠธ์›Œํฌ ํ™˜๊ฒฝ์— ์ ํ•ฉํ•œ ์†”๋ฃจ์…˜์ด๋ผ๋Š” ์ ์ด ์ธ์ƒ์ ์ด์—ˆ๋‹ค.

์†๋„์™€ ์„ฑ๋Šฅ์ด ์ค‘์š”ํ•˜๋ฉด WireGuard๋ฅผ, ๋” ์ •๊ตํ•œ ์„ค์ •์„ ํ†ตํ•œ ๋ณด์•ˆ์„ฑ ๊ฐ•ํ™”๊ฐ€ ํ•„์š”ํ•œ ๊ฒฝ์šฐ์—๋Š” OpenVPN์„ ์„ ํƒํ•˜๋ฉด ๋˜๊ฒ ๋‹ค.

์•ž์œผ๋กœ๋„ ์ด ๋‘ ๊ธฐ์ˆ ์„ ํ™œ์šฉํ•˜์—ฌ ๋‹ค์–‘ํ•œ ๋„คํŠธ์›Œํฌ ํ™˜๊ฒฝ์—์„œ ์ตœ์ ์˜ ๋ณด์•ˆ์„ ์ œ๊ณตํ•˜๋Š” ๋ฐฉ๋ฒ•์„ ๋” ๊ณต๋ถ€ํ•˜๊ณ  ์‹ถ๋‹ค๋Š” ์ƒ๊ฐ์ด ๋“ ๋‹ค. ์ง์ ‘ ๋‹ค๋ค„๋ณด๊ณ  ์‹ถ์€๋ฐ.. ๋‹น์žฅ ๊ฐ€๋Šฅํ• ์ง€ใ… ใ… ใ… 

์ด ๋‘ ๊ฐœ๋ฅผ ๋‹ค๋ค„๋ณผ ๋‚ ์ด ๊ผญ ์™”์œผ๋ฉด ์ข‹๊ฒ ๋‹ค(๊ทธ๋Ÿฌ๋„๋ก ๋‚ด๊ฐ€ ๋งŒ๋“ค์–ด์•ผ๊ฒ ๋‹ค).