From: "Toke Høiland-Jørgensen" <toke@toke.dk>
To: Tim Weippert <weiti@weiti.org>, wireguard@lists.zx2c4.com
Subject: Re: WG load balancing?
Date: Thu, 10 May 2018 11:58:36 +0200 [thread overview]
Message-ID: <87d0y3ygqb.fsf@toke.dk> (raw)
In-Reply-To: <20180510093648.GA1674@weiti-p772>
Tim Weippert <weiti@weiti.org> writes:
> Hi Matthias,=20
>
>
> On Thu, May 10, 2018 at 11:21:44AM +0200, Matthias Urlichs wrote:
>> Hello list,
>>=20
>> Assume a branch office with two uplinks to the Internet that wants to
>> use WG to talk to the main office, using both of these uplinks in
>> parallel (assuming they're both up) for better uplink speed (and for
>> redundancy if they aren't). Now the obvious idea is to create two WG
>> interfaces on each side, and add a couple of firewall rules to make sure
>> that packets fwmarked 1 go out on the first uplink, and so on.
>>=20
>> That's the easy part. The hard part is how to teach the kernel to load
>> balance its default route between the WG interfaces. I tried to use a
>> libteam or bonding interface to tie them together, but apparently WG
>> isn't Ethernet, so that doesn't work.
>>=20
>> I thought about using a GRE tunnel, but tunnels have fixed endpoint
>> addresses =E2=80=93 somehow I don't think it'd be a good idea to create =
two
>> wireguard interfaces with the same IP address =E2=80=A6 and I don't real=
ly want
>> to do heavy-handed address mangling on every packet. Losing all
>> connectivity whenever I happen to flush my firewall tables doesn't
>> appeal to me.
>
> Maybe you can use some kind of dynamic routing approach here. Use FRR,
> Quagga or Bird with e.g. OSPF and ECMP ( Equal Cost Multipath) to utilize
> both links. (practically you can also have two default routes with the
> same metric and this should do a round robin fashioned loadbalancing)
You can add ECMP routes with 'ip route' via the 'nexthop' parameter. See
'man ip-route'.
-Toke
next prev parent reply other threads:[~2018-05-10 9:56 UTC|newest]
Thread overview: 5+ messages / expand[flat|nested] mbox.gz Atom feed top
2018-05-10 9:21 WG load balancing? Matthias Urlichs
2018-05-10 9:36 ` Tim Weippert
2018-05-10 9:58 ` Toke Høiland-Jørgensen [this message]
2018-05-10 9:55 ` Toke Høiland-Jørgensen
2018-05-10 10:01 ` Tim Sedlmeyer
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=87d0y3ygqb.fsf@toke.dk \
--to=toke@toke.dk \
--cc=weiti@weiti.org \
--cc=wireguard@lists.zx2c4.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.