I am trying to setup a wireguard server on freebsd using this guide. the only thing i’ve done different is make the AllowedIPs 0.0.0.0/0
I seem to have messed something up because when I have wireguard running, i cannot ping or curl anything from the server. It doesn’t take down the machine though, I am still able to ssh into the server.
I still have yet to get the client to actually connect, but i assume this networking issue is a potential cause. googling doesn’t seem to help me find anyone with my same issue.
my wg0.conf is as follows
[Interface] Address = 10.96.100.1/32 # address the server will bind to
ListenPort = 51820 # listener port
PrivateKey = [redacted]
[Peer] #phone
AllowedIPs = 0.0.0.0/0
PreSharedKey = [redacted]
PublicKey = [redacted]
By setting AllowedIPs = 0.0.0.0/0 you configure the server to route everything over your phone. It should only be set to the VPN ip of the phone.
Well ill be darned. Thank you
Yeah I’ve always found that
AllowedIPs
name a little bit misleading. It is mentioned in the manpage:A comma-separated list of IP (v4 or v6) addresses with CIDR masks from which incoming traffic for this peer is allowed and to which outgoing traffic for this peer is directed.
But I think it’s a little funny how setting
AllowedIPs
also configures how packets are routed. I dunno.
Slightly off-topic: I’m not too familiar with FreeBSD (I use OpenBSD), but others may be interested to know you may be able to configure wireguard interfaces without installing any packages. It probably just involves running some
ifconfig
commands at boot via some entries in/etc/rc.conf
. See https://docs.freebsd.org/en/books/handbook/network/Acronyms, initialisms, abbreviations, contractions, and other phrases which expand to something larger, that I’ve seen in this thread:
Fewer Letters More Letters Git Popular version control system, primarily for code IP Internet Protocol VPN Virtual Private Network
[Thread #177 for this sub, first seen 1st Oct 2023, 04:35] [FAQ] [Full list] [Contact] [Source code]
@dadarobot@lemmy.sdf.org you need to change the Iptable rules to the packages are redirected somewhere