Re: Wg source address is too sticky for multihomed systems aka multiple endpoints redux

2023-07-23 Thread Daniel Gröber
Hi John, On Fri, Jul 21, 2023 at 09:47:11AM -0400, John Lauro wrote: > I have a lots of multihomed routers setup for vpn site to site and > running bgp over the vpn mesh. > > First, make sure these are all 0 as are multihomed. > cat $( find /proc/sys/net/ipv4 -name rp_filter ) My routers are beh

Re: Wg source address is too sticky for multihomed systems aka multiple endpoints redux

2023-07-21 Thread John Lauro
I have a lots of multihomed routers setup for vpn site to site and running bgp over the vpn mesh. First, make sure these are all 0 as are multihomed. cat $( find /proc/sys/net/ipv4 -name rp_filter ) The other thing I do is I run a different wireguard interface and peer on a different port and int

Re: Wg source address is too sticky for multihomed systems aka multiple endpoints redux

2023-07-21 Thread Nico Schottelius
Good morning, Daniel Gröber writes: > [...] > I have a multihomed router [...] following up the thread from February, we migrated away from wireguard to openvpn on systems that have are multi homed. The main reason for that is the following type of connection to a high probability fails to wo

Wg source address is too sticky for multihomed systems aka multiple endpoints redux

2023-07-20 Thread Daniel Gröber
Hi wire-guard, :) tl;dr: I wan to implement mutliple peer endpoints to fix the only two problems haunting me with wireguard. I have a multihomed router with two public IPv4 addresses plus default routes in a failover configuration. The setup includes the two default routes with different metrics