From: Bryce Allen <bryce@bda.space>
To: wireguard@lists.zx2c4.com
Subject: bind to specific ip address
Date: Tue, 5 Feb 2019 12:16:58 -0600 [thread overview]
Message-ID: <20190205121658.1973fd89@msi> (raw)
Hi,
I have run into several wifi networks that block almost all traffic,
allowing only 80/443 and 53. To work around this, I got a second IP
address for my linode server, intending to run ssh on port 80 and
wireguard on 53. This works for ssh, which I set up to bind on port 80
to the new IP only, so it doesn't interfere with nginx on my main IP.
It looks like wireguard doesn't support binding to a specific address?
I understand the security and routing do not require binding to a
specific address, but I think it is useful for scenarios like this.
When I try to bring up the wg interface with ListenPort 53 in my
config, with unbound already running on 53 at other addresses, I get
"RTNETLINK answers: Address already in use\nFailed to bring up
wg-server.". The interface is still created, but the tunnel doesn't
work. I also had to manually delete the interface with "ip link del
wg-server" before I could bring it back up with the config changed back
to the original port.
I'm guessing that doing deep packet inspecion is too expensive /
overkill for a mall wifi, so I do think this workaround of using
port 53 would work. Is this address binding a feature that you would
consider adding to wireguard, or would accept a patch for? Any other
ideas for working around obnoxious firewalls?
Thanks,
Bryce
_______________________________________________
WireGuard mailing list
WireGuard@lists.zx2c4.com
https://lists.zx2c4.com/mailman/listinfo/wireguard
next reply other threads:[~2019-02-28 18:24 UTC|newest]
Thread overview: 2+ messages / expand[flat|nested] mbox.gz Atom feed top
2019-02-05 18:16 Bryce Allen [this message]
2019-02-28 23:00 ` bind to specific ip address Ivan Labáth
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20190205121658.1973fd89@msi \
--to=bryce@bda.space \
--cc=wireguard@lists.zx2c4.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.