WireGuard DNS Configuration for Systemd
procustodibus.com
procustodibus.com
wg-quick is really that - quickly get a simple tunnel up and running which works fine when you just want to route all IPs in a single subnet or 0.0.0.0/0 and nothing more, but anything more complex (split tunneling for example) and it quickly (!) becomes cumbersome.
Slightly OT but I personally very much prefer systemd-networkd over NetworkManager, which I find unpredictable.
https://elou.world/en/tutorial/wireguard
https://www.man7.org/linux/man-pages/man5/systemd.netdev.5.h...
$ networkctl up wg0
I’d you’ve changed the WireGuard config then:
$ systemctl reload systemd-networkd
https://www.philipdeljanov.com/posts/2019/05/31/dns-leaks-wi...
as for wireguard, a pretty brutal settings in all wireguard profiles:
PostUp = echo "nameserver <DNS IP in wireguard>" > /etc/resolv.conf
PostDown = echo "nameserver 127.0.0.1" > /etc/resolv.conf
and even a
dns=none
in /etc/NetworkManager/NetworkManager.conf
p.s. I am aware of the great discussion in https://news.ycombinator.com/item?id=19435631 especially usr1106 comment
Unless you have reasons to prefer BIND, I'd recommend dnsmasq (most popular lightweight) or coredns (intuitive straightforward conf, also lightweight).
You can set them as authoritative for your own domain and forward the rest to whatever you use for DNS otherwise.
The connection will auto-start; if you do now want that and you want manually start/stop ip, set ipv4.autoconnect=no.
Fedora uses systemd-resolved by default since the 33 release; if you installed older and then upgraded, check the network manager config if you are using it or not.
nmcli connection import type wireguard file wg0.conf