!tCyGickeVqkHsYjWnh:nixos.org

NixOS Networking

918 Members
Declaratively manage your switching, routing, wireless, tunneling and more.275 Servers

Load older messages


SenderMessageTime
13 Jun 2021
@joerg:bethselamin.deMic92 (Old)Everything should be there16:28:33
14 Jun 2021
@hpfr:matrix.orghpfr I followed the wireguard page on the wiki to connect a nixos client to my LAN (point-to-site), but I had to go to the arch wiki to find ip route add 192.168.35.0/24 dev wg0 (where the CIDR is the LAN subnet) to get it to work. is there a nixos configuration value for this? 07:54:25
@n0emis:noemis.men0emis
In reply to @hpfr:matrix.org
I followed the wireguard page on the wiki to connect a nixos client to my LAN (point-to-site), but I had to go to the arch wiki to find ip route add 192.168.35.0/24 dev wg0 (where the CIDR is the LAN subnet) to get it to work. is there a nixos configuration value for this?
if you have networking.wireguard.interfaces.<name>.allowedIPsAsRoutes set to true, you can just add the subnet to networking.wireguard.interfaces.<name>.peers.*.allowedIPs
08:09:55
@hpfr:matrix.orghpfrweird, that should have worked then because that option is true for me08:11:27
@n0emis:noemis.men0emis otherwise you could add the command to networking.wireguard.interfaces.<name>.postSetup 08:12:33
@hpfr:matrix.orghpfrmight've just been a one time issue08:13:50
@hpfr:matrix.orghpfrI'm trying to set up a wg network where I have road clients that connect to my home network (which is behind CGNAT) via a VPS with a public IP. I just got the VPS able to talk to hosts inside my home network, but my laptop which connects to the VPS over wireguard can't see hosts inside my home network08:14:05
@n0emis:noemis.men0emis well, you probably wan't to do something like ip route add 192.168.35.0/24 via $ROUTER, since the lan-subnet is not directly on the wg-link. then also allowedIPs is not the right option 08:14:16
@hpfr:matrix.orghpfr🤔 all the guides I've seen suggest adding your LAN to allowedIPs is the way to go08:16:35
@hpfr:matrix.orghpfralso, in the server setup in the wireguard wiki it enables NAT from the external interface to the wg interface, why is this done?08:21:35
@dandellion:dodsorf.asDandellion changed their profile picture.14:48:16
15 Jun 2021
@jdyg:matrix.orgjdyg joined the room.19:12:00
16 Jun 2021
@leons:is.currently.onlineLeon joined the room.13:22:56
18 Jun 2021
@noah:matrix.chatsubo.cafeChurchHmm anyone had issue with postUp and postShutdown commands in wireguard not running correctly and setting up and tearing down your rules?07:34:44
19 Jun 2021
@hpfr:matrix.orghpfr uh, is the wireguard module missing a dns option? 18:17:35
@hpfr:matrix.orghpfrI guess I'm supposed to use the wg-quick module instead18:25:43
@hpfr:matrix.orghpfrseems weird that they overlap a lot and that the wireguard module is apparently missing options?18:26:21
20 Jun 2021
@joerg:bethselamin.deMic92 (Old)the wireguard module was introduced before wg-quick existed06:55:54
@joerg:bethselamin.deMic92 (Old)Otherwise there would be no wireguard module06:56:20
@noah:matrix.chatsubo.cafeChurchSo what's preferred? Wireguard or wg-quick?22:47:22
21 Jun 2021
@eyjhb:eyjhb.dkeyJhb^ would like to know that as well, since I am currently using wireguard, and not wg-quick08:32:30
@andreas.schraegle:helsinki-systems.deAndreas SchrägleI just generate systemd-networkd files for my wireguard interfaces 🤷‍♂️ 11:28:52
@leons:is.currently.onlineLeon Yup, the networkd module works pretty flawlessly 11:31:07
@leons:is.currently.onlineLeonAlso, it doesn’t do as much magic as do the wireguard or wg-quick modules, for instance derive routes from the Allowed-IPs11:32:07
@leons:is.currently.onlineLeon(At least by default)11:32:33
@hexa:lossy.networkhexawhich is favorable when you want to do dynamic routing on top of them 😀11:35:15
@leons:is.currently.onlineLeon Exactly. I run OSPF+BGP on top so unconditionally routing ::/0 doesn’t do any good :D 11:38:01
@hexa:lossy.networkhexaBabel https://datatracker.ietf.org/doc/html/rfc8966 :)11:49:48
@anodae:matrix.organodae joined the room.20:52:21
22 Jun 2021
@joerg:bethselamin.deMic92 (Old)Also I added wireguard support to networkd, I never really used it much afterwards.08:53:47

Show newer messages


Back to Room ListRoom Version: 6