It would be nice to have a single binary that can run traffic through a VPN and something I have not see done before.
It would be nice to have a single binary that can run traffic through a VPN and something I have not see done before.
You can route network of exatorrent through network/VPN .
Also, wireguard implemented in Linux kernel is faster than userspace implementation of wireguard-go . No?
that always comes with the danger of not going through VPN if the connection somehow drops or you've restarted the machine its running on and the vpn started after the torrent client.
and the linux kernel implementation isnt necessarily available if its running in a docker container of some NAS or even on a windows machine.
it would also make it easier to use, allowing more people to utilize the tech.
I will consider this.
My current setup uses namespaces to avoid this issue. Basically, one can create a wg interface in the default namespace and then move it to a new namespace and run applications there. The wg interface keeps routing the encrypted traffic through the interfaces in the default namespace, but as there is only the wg interface in the new namespace, there is no risk of leaking any traffic. It also doesn't need a network bridge and doesn't disturb the network configuration of the host.
I use lxc, but there are probably more lightweight options to just start an application in a different network namespace.
This relieves me having to manage restarts when the VPN connection issues for example a new IP. I currently just allow some scripts to refresh things when the uplink changes.
Here's an overview https://fly.io/blog/ssh-and-user-mode-ip-wireguard/
That currently just creates an interface, but that is just for raw packets. The kernel is the one that is still handling the IP connections.
To have a process do what you are implying would require an entire userspace TCP/IP stack.
These are pretty rare. Slip4netns is an example of one.
See also https://fly.io/blog/ssh-and-user-mode-ip-wireguard/ which has already done this for SSH through wireguard-go