Re: WireGuard over WireGuard

2020-05-31 Thread Mo Balaa
Hi All, Reporting back on my progress after modify MTUs. Still seeing significant intermittent stuck /hung connections on iOS in a Wireguard over Wireguard tunnel (most apparent when using Twitter app for iOS) Looking at getting Wireshark setup to do some debugging this afternoon and would also

Re: WireGuard over WireGuard

2020-05-12 Thread Justin Kilpatrick
Althea uses WireGuard over WireGuard for mesh routing. Each device maintains a link to peers using WireGuard and then also maintains it's connection to the exit over a multihop WireGuard connection. Building working WireGuard tunnels over fe80 ipv6 link local addresses was a real pain. Pa

Re: WireGuard over WireGuard

2020-05-11 Thread Dimitar Vassilev
Hi all, for my enlightenment can you please advise in which situation such setups are useful? Thanks! На чт, 7.05.2020 г. в 4:01 Derrick Lyndon Pallas написа: > > Note for the list: IPv6 has a minimum of 1280, which means 1360 in the > outer layer. ~Derrick > > > On 5/6/20 4:54 PM, Jason A. Do

Re: WireGuard over WireGuard

2020-05-10 Thread John Lauro
Wireguard is defaulting to 1420 MTU, the ethernet adapter is 1500 MTU, and I have IPv6 completely disabled. Can/should the MTU of wireguard be bumped to 1440? On Wed, May 6, 2020 at 6:26 PM Jason A. Donenfeld wrote: > > On Wed, May 6, 2020 at 4:24 PM Justin Kilpatrick wrote: > > > > > 1340 or 1

Re: WireGuard over WireGuard

2020-05-06 Thread Derrick Lyndon Pallas
Note for the list: IPv6 has a minimum of 1280, which means 1360 in the outer layer. ~Derrick On 5/6/20 4:54 PM, Jason A. Donenfeld wrote: On Wed, May 6, 2020 at 5:28 PM John Lauro wrote: Wireguard is defaulting to 1420 MTU, the ethernet adapter is 1500 MTU, and I have IPv6 completely disable

Re: WireGuard over WireGuard

2020-05-06 Thread Jason A. Donenfeld
On Wed, May 6, 2020 at 5:28 PM John Lauro wrote: > > Wireguard is defaulting to 1420 MTU, the ethernet adapter is 1500 MTU, > and I have IPv6 completely disabled. > > Can/should the MTU of wireguard be bumped to 1440? You could if you wanted. But if you don't do it perfectly on all sides with tot

Re: WireGuard over WireGuard

2020-05-06 Thread Jason A. Donenfeld
On Wed, May 6, 2020 at 4:24 PM Justin Kilpatrick wrote: > > > 1340 or 1360 > > Why two options? I've been using 1340 for a long time. WireGuard over IPv4 has a 60 byte overhead. WireGuard over IPv6 has an 80 byte overhead.

Re: WireGuard over WireGuard

2020-05-06 Thread Justin Kilpatrick
> 1340 or 1360 Why two options? I've been using 1340 for a long time. -- Justin Kilpatrick jus...@althea.net On Wed, May 6, 2020, at 6:00 PM, Jason A. Donenfeld wrote: > On Wed, May 6, 2020 at 3:37 PM Mo Balaa wrote: > > > > Was hoping setting them both to automatic would just work; but a

Re: WireGuard over WireGuard

2020-05-06 Thread Jason A. Donenfeld
On Wed, May 6, 2020 at 3:37 PM Mo Balaa wrote: > > Was hoping setting them both to automatic would just work; but after > some fiddling that appears to be the issue. > > What is the optimal MTU for the inner WireGuard tunnel if the outer > one is set 1420? 1340 or 1360

Re: WireGuard over WireGuard

2020-05-06 Thread Mo Balaa
d your MTUs? ~Derrick > > > On 5/6/20 9:57 AM, Mo Balaa wrote: > > We are running WireGuard over WireGuard. It appears to work well; > > however I am noticing some applications struggle to work reliably. > > Lots of failed page loadss / timeouts. Any pointers on how I c

Re: WireGuard over WireGuard

2020-05-06 Thread Derrick Lyndon Pallas
Have you checked your MTUs? ~Derrick On 5/6/20 9:57 AM, Mo Balaa wrote: We are running WireGuard over WireGuard. It appears to work well; however I am noticing some applications struggle to work reliably. Lots of failed page loadss / timeouts. Any pointers on how I could go about debugging

WireGuard over WireGuard

2020-05-06 Thread Mo Balaa
We are running WireGuard over WireGuard. It appears to work well; however I am noticing some applications struggle to work reliably. Lots of failed page loadss / timeouts. Any pointers on how I could go about debugging these issues? Any general pointers on running WireGuard over WireGuard? One