4 ms·
> I also saw nothing anywhere about how if you modify your config file and down/up with wg-quick it'll delete anything you entered in your config as the 'down'
by Hello71 8y ago
> I also saw nothing anywhere about how if you modify your config file and down/up with wg-quick it'll delete anything you entered in your config as the 'down' will write back the current state of the interface. It's not a big deal, but it messes with the usual workflow of editing the config file of a service (you don't want to down it while updating your config, which could take time).
`down` only writes the state of the interface if you put SaveConfig = true in your configuration file. If so... you asked for it.
> I'd like to see an easier way of doing the exclusions, inverse CIDRs are not my forte
WireGuard uses the standard Linux routing infrastructure. wg-quick uses the powerful Linux policy routing functions along with the suppress_prefixlength policy routing rule in order to use your main routing table for exclusions. Therefore, the command to exclude an IP is simply "ip route add 10.0.1.0/24 via 10.0.0.1 dev eth0". Obviously you should replace the example subnets and interface, and this is not permanent. The beauty of wg-quick is that you don't need to add this rule every time you bring up your VPN, but can instead add it as a temporarily redundant static route.
- alias_neo 8y ago> `down` only writes the state of the interface if you put SaveConfig = true in your configuration file. If so... you asked for it. Nope, it's not in my config file. I didn't even know the option existed until you mentioned it, again, nothing on the Quick Start about it. > WireGuard uses the standard Linux routing infrastructure... I meant more in terms of the Android app, not really a WG issue, but it has a check box to add exclusions to the allowed ip list, by basically adding ranges inverse to what you'd input if you were saying "exclude these". What's the inverse of 192.168.0.0/16? I have no idea without looking it up.
- zx2c4 8y ago> I meant more in terms of the Android app, not really a WG issue, but it has a check box to add exclusions to the allowed ip list, by basically adding ranges inverse to what you'd input if you were saying "exclude these". The Android app now has a little checkbox to toggle a common set complement operation ("Exclude private IPs"). If you want to do something wild and include or exclude very particular ranges, then you can compute that yourself and put it in there, since ostensibly you have a very particular networking idea in mind.