WireGuard Archive on lore.kernel.org
 help / color / mirror / Atom feed
From: "Toke Høiland-Jørgensen" <toke@toke.dk>
To: Tim Weippert <weiti@weiti.org>, wireguard@lists.zx2c4.com
Subject: Re: WG load balancing?
Date: Thu, 10 May 2018 11:58:36 +0200	[thread overview]
Message-ID: <87d0y3ygqb.fsf@toke.dk> (raw)
In-Reply-To: <20180510093648.GA1674@weiti-p772>

Tim Weippert <weiti@weiti.org> writes:

> Hi Matthias,=20
>
>
> On Thu, May 10, 2018 at 11:21:44AM +0200, Matthias Urlichs wrote:
>> Hello list,
>>=20
>> Assume a branch office with two uplinks to the Internet that wants to
>> use WG to talk to the main office, using both of these uplinks in
>> parallel (assuming they're both up) for better uplink speed (and for
>> redundancy if they aren't). Now the obvious idea is to create two WG
>> interfaces on each side, and add a couple of firewall rules to make sure
>> that packets fwmarked 1 go out on the first uplink, and so on.
>>=20
>> That's the easy part. The hard part is how to teach the kernel to load
>> balance its default route between the WG interfaces. I tried to use a
>> libteam or bonding interface to tie them together, but apparently WG
>> isn't Ethernet, so that doesn't work.
>>=20
>> I thought about using a GRE tunnel, but tunnels have fixed endpoint
>> addresses =E2=80=93 somehow I don't think it'd be a good idea to create =
two
>> wireguard interfaces with the same IP address =E2=80=A6 and I don't real=
ly want
>> to do heavy-handed address mangling on every packet. Losing all
>> connectivity whenever I happen to flush my firewall tables doesn't
>> appeal to me.
>
> Maybe you can use some kind of dynamic routing approach here. Use FRR,
> Quagga or Bird with e.g. OSPF and ECMP ( Equal Cost Multipath) to utilize
> both links. (practically you can also have two default routes with the
> same metric and this should do a round robin fashioned loadbalancing)

You can add ECMP routes with 'ip route' via the 'nexthop' parameter. See
'man ip-route'.

-Toke

  reply	other threads:[~2018-05-10  9:56 UTC|newest]

Thread overview: 5+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2018-05-10  9:21 WG load balancing? Matthias Urlichs
2018-05-10  9:36 ` Tim Weippert
2018-05-10  9:58   ` Toke Høiland-Jørgensen [this message]
2018-05-10  9:55 ` Toke Høiland-Jørgensen
2018-05-10 10:01 ` Tim Sedlmeyer

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=87d0y3ygqb.fsf@toke.dk \
    --to=toke@toke.dk \
    --cc=weiti@weiti.org \
    --cc=wireguard@lists.zx2c4.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox