https://www.perfect-privacy.com/en/blog/wireguard-vpn-pros-a...
https://www.perfect-privacy.com/en/blog/wireguard-vpn-pros-a...
When those are not enough any more, they need to segment their VPN, so they can re-use the private IP space in each segment.
w.r.t. to "NeuroRouting and TrackStop not possible", they could route their stuff through a TUN interface to do whatever they want to do in user space. With a performance cost.
> What they probably need to do is to assign each customer a fixed private IP for use within their VPN, e.g. from 10.0.0.0/8.
Actually, they can set a different IP for each session and rotate them by given it to the client out of band, for example when it authenticates to the service.
> When those are not enough any more, they need to segment their VPN
Like with all other VPNs right? They could also distribute IPv6 for the tunnel and this would not be an issue.
Like I said, Wireguard does not have the concept of sessions. You could add your own proprietary "stuff" around Wireguard to add that concept, but then you don't need anything extra from Wireguard. You add the keys of the users as part of the session setup and remove them when the session is destroyed. Of course, this means that clients have to use a client tool provided by you.