3 ms·
I saw a github project that tries to make wireguard+netns more easy to setup: https://github.com/kalken/eznetns https://github.com/kalken/eznetns
by isodude 2y ago
I saw a github project that tries to make wireguard+netns more easy to setup: https://github.com/kalken/eznetns https://github.com/kalken/eznetns
- rnewme 2y agoWhat would be the opposite approach, to make sure all traffic goes through VPN, and only VPN, even if user didn't start the VPN connection (default to no connectivity)? Is there better approach then just disabling all other network interfaces?
- isodude 2y agoAFAIK Wireguard will always listen in the default namespace, thus you need to isolate everything else. A fun way of doing it though is to do an ip rule that uses the VRF table, and matches on the user id. That way all traffic from certain users will always end up in the same routing table. You can go further and match on everything except the Wireguard endpoint. With iptables you can MARK the traffic you want to be differently and then catch that traffic with ip rule.
- rnewme 2y agoCool, thank you!