From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: tth@rfa.cz Received: from krantz.zx2c4.com (localhost [127.0.0.1]) by krantz.zx2c4.com (ZX2C4 Mail Server) with ESMTP id 0cdb8e2c for ; Wed, 20 Jun 2018 18:12:36 +0000 (UTC) Received: from vodka.rfa.cz (vodka.rfa.cz [88.86.120.134]) by krantz.zx2c4.com (ZX2C4 Mail Server) with ESMTP id fb8f5cc4 for ; Wed, 20 Jun 2018 18:12:36 +0000 (UTC) Received: from localhost (localhost [127.0.0.1]) by vodka.rfa.cz (Postfix) with ESMTP id 1772890CD3 for ; Wed, 20 Jun 2018 20:17:24 +0200 (CEST) Received: from vodka.rfa.cz ([127.0.0.1]) by localhost (vodka.rfa.cz [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id qmydYqbWZmwJ for ; Wed, 20 Jun 2018 20:17:23 +0200 (CEST) Subject: Re: listen on specific IP only To: "Jason A. Donenfeld" References: <8d3124af-de51-3253-8b89-02233566c4f9@rfa.cz> From: Tomas Herceg Message-ID: Date: Wed, 20 Jun 2018 20:17:21 +0200 MIME-Version: 1.0 In-Reply-To: Content-Type: text/plain; charset=utf-8; format=flowed Cc: WireGuard mailing list List-Id: Development discussion of WireGuard List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Thanks works like a charm =) interface: wg0-default public key: (no no no) private key: (hidden) listening port: 51820 fwmark: 0xca6c peer: GUUrqy95QclZQZ9zxMkX+5G6HklnSaqhIAJpf7naSFI= endpoint: PUBIP1:53 allowed ips: 192.168.11.0/24, 172.16.16.6/32 latest handshake: 12 seconds ago transfer: 532 B received, 1.12 KiB sent persistent keepalive: every 25 seconds peer: 4H52v5z94+LtLaiSw47V4/1zc8TiaQ05+kI63ESY12Q= endpoint: PUBIP2:53 allowed ips: 0.0.0.0/0, ::/0 latest handshake: 36 seconds ago transfer: 440.24 KiB received, 109.24 KiB sent persistent keepalive: every 25 seconds On 06/20/2018 07:50 PM, Jason A. Donenfeld wrote: > We don't allow this in WireGuard by design. > > However, you can easily work around this with iptables: > > $ wg set wg0 listen-port 11153 > $ iptables -t nat -A PREROUTING .... -p udp --dport 53 -j REDIRECT > --to-port 11153 > > Fill in the ... with --destination or --in-interface or whatever you want. > > Jason >