4 ms·
A pain point I still haven't resolved with WG is this. From my phone, I want to access my homelab through the WG server at home, but everything else through an
by joeframbach 3y ago
A pain point I still haven't resolved with WG is this. From my phone, I want to access my homelab through the WG server at home, but everything else through an external WG VPN somewhere else. My homelab ip range is 10.10.0.0/24 or whatever, but the external VPN is some other range. Wireguard doesn't seem to like this. The alternative is to route my phone to home for 100% of traffic, and my home router would egress through the external VPN. But I don't want my home network to be the bottleneck, I don't exactly have the best Internet service at home. From a cursory search through NetMaker docs, I didn't see anything that explicitly shows how to configure vpns, or, I don't know what to call it, bridging multiple wireguard networks.
- winecamera 3y agoAssuming your Wireguard server at home is running Linux, you can achieve this by adding a second routing table and adding routing policies.
- _rs 3y agoIs it not possible to configure this on the phone itself?
- WirelessGigabit 3y agoNo as on most phones you cannot set up static routes.
- rudasn 3y agoWhat's your setup right now? A single wg interface/config on your phone, with two peers, one for home wg and one for remote vpn, with AllowedIPs on the home peer as 10.10.0.0/24 and AllowedIPs on the remote vpn peer as 0.0.0.0/24? Have you tried excluding the cidr of your home wg from the AllowedIPs of the remote vpn? Like not having 0.0.0.0/24, but one or more entries that end up excluding local cidrs.
- joeframbach 3y agoThe external VPN provider dictates what my interface's IP range is. I generated a new WG config using the UI, and it comes with interface IP 10.66.123.123/32. If I want my home ip to be 10.10.0.2/32, then I'll have to set it as 10.0.0.0/8, and the VPN provider didn't seem to agree with that. I have two wg interfaces and I manually switch between them.
- zeroflow 3y agoYou should be able to have two peers. The only thing I see is, that you may need to explicitly define the routing. The first peer is easy, with allowed IPs of 10.10.0.0/8. The 2nd peer will need more configs, as it should route everything else. See this answer for an example where all ranges that are not RFC1918 are listed: https://serverfault.com/a/304791 https://serverfault.com/a/304791 I expect, that you need to enter those ranges as AllowedIPs for the peer that should route to the public internet.
- winecamera 3y agoThere's this handy website that calculates the allowed CIDRs with exclusions https://www.procustodibus.com/blog/2021/03/wireguard-allowedips-calculator/ https://www.procustodibus.com/blog/2021/03/wireguard-allowed...
- cpach 3y agoSemi-related: I really like the typeface/layout on that site!
- Modified3019 3y agoYeah same. I'm new to trying to find fonts, but it looks like it's "Forum" font family for the header and "Proza Libre" for the body https://fonts.google.com/specimen/Forum https://fonts.google.com/specimen/Forum https://fonts.google.com/specimen/Proza+Libre https://fonts.google.com/specimen/Proza+Libre
- erinnh 3y agoWhy not have a standing WG connection between your home and external WG server and connect only to the external server? You then route your home traffic through the home wg connection and all other traffic will exit the external server directly.
- afeiszli 3y agoNetmaker may help with this. You configure an "Egress Gateway" to 0.0.0.0/0 as your internet VPN, inside of a Netmaker network of 10.10.0.0/24. We do our routing rules differently and it is meant to be compatible. However, I'm a bit surprised you have this issue with regular WireGuard, as it tends to be quite stable for this sort of setup in my experience.