Hey Rene, > I suggest to use a cryptographically generated IPv6 address (128-bit hash of Wiregurad public key with first n bits replaced by a Wireguard-specific IPv6 prefix) > for routing and management purposes. Adding a reverse-lookup IPv6-address -> Wireguard public key via DHT would allow a public IPv6 overlay network > with authorization via firewall rules. Nodes should also be able to announce their subnets via DHT. I agree. I plan to use the subnet ORCHID as defined by RFC 4843. See command `wh orchid`. Cheers, Gawen