Development discussion of WireGuard
 help / color / mirror / Atom feed
* Why does 'allowed-ips' affect route selection behavior?
@ 2018-04-15 18:49 Patrick O'Sullivan
  2018-04-15 18:58 ` Roman Mamedov
  2018-04-15 18:58 ` mikma.wg
  0 siblings, 2 replies; 7+ messages in thread
From: Patrick O'Sullivan @ 2018-04-15 18:49 UTC (permalink / raw)
  To: wireguard

Hi Folks,

Getting my feet wet with wireguard and enjoying the simplicity and
performance thus far. Nonetheless, I have a question about how the
normal route selection process is being affected by what's configured
for 'allowed-ips'.

I set up a peer and configured 'allowed-ips' for 0.0.0.0/0, as I was
going to be sending multiple routes over the peer link via BGP and
didn't want to keep modifying it. However, even though my default
route was over a different interface, this seemed to result in Linux
trying to route default traffic over wg0 despite there not being a
default route pointing to wg0.

Specifically:

$ sudo ip route show
default via 10.199.199.1 dev wlan0
10.111.111.0/24 dev wg0 proto kernel scope link src 10.111.111.100
10.199.199.0/24 dev wlan0 proto kernel scope link src 10.199.199.131

By this route table, traffic to e.g. 4.2.2.1 should use 10.199.199.1.
Packet captures were showing traffic trying to instead use wg0. Then I
found this:

$ sudo ip route get 4.2.2.1
4.2.2.1 dev wg0 table 51820 src 10.111.111.100
    cache

Can someone please explain this behavior?

Obligatory... $ uname -rvm
4.14.30-v7+ #1102 SMP Mon Mar 26 16:45:49 BST 2018 armv7l

And... $ dpkg -l | grep wireguard
ii  wireguard                       0.0.20180413-1               all
       fast, modern, secure kernel VPN tunnel (metapackage)
ii  wireguard-dkms                  0.0.20180413-1               all
       fast, modern, secure kernel VPN tunnel (DKMS version)
ii  wireguard-tools                 0.0.20180413-1               armhf
       fast, modern, secure kernel VPN tunnel (userland utilities)

^ permalink raw reply	[flat|nested] 7+ messages in thread

end of thread, other threads:[~2018-04-16 12:14 UTC | newest]

Thread overview: 7+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2018-04-15 18:49 Why does 'allowed-ips' affect route selection behavior? Patrick O'Sullivan
2018-04-15 18:58 ` Roman Mamedov
2018-04-15 22:26   ` Jason A. Donenfeld
2018-04-16  1:06     ` Patrick O'Sullivan
2018-04-16  1:13       ` Jason A. Donenfeld
2018-04-16 12:29     ` Tim Sedlmeyer
2018-04-15 18:58 ` mikma.wg

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).